On August 2, 2026, the European Commission’s AI Office gains full authority to investigate, order corrective measures, and fine general-purpose AI providers up to €15 million or 3% of worldwide annual turnover, whichever is higher. The same day, Article 50 transparency obligations become binding across the bloc. A year of paper compliance turns operational.

GPAI obligations technically began applying in August 2025, but sat inert without an enforcement mechanism. That gap now closes. Chatbots must disclose they aren’t human, deepfakes must be labelled, and synthetic content has to carry machine-readable marks. EU institutions face a separate ceiling of €750,000. Enforcement splits across the AI Office, national market surveillance authorities, and the European Data Protection Supervisor.

The AI Omnibus, in force since July 27, pushed Annex III high-risk use cases to December 2, 2027 and Annex I embedded systems to August 2, 2028. It didn’t touch GPAI or Article 50. Brussels chose which deadlines to defend.

Industry has been reading the signals. Over 180 organisations signed the Code of Practice on Transparency of AI-generated Content, published in June. Amazon, Anthropic, Google, Microsoft, Mistral AI, and OpenAI have all signed the voluntary GPAI Code of Practice, a familiar pre-enforcement choreography reminiscent of the DSA’s run-up, when platforms front-loaded voluntary commitments to shape how binding rules would land.

A Commission official told Tech Policy Press the AI Office intends to maintain a “constructive dialogue” with providers while monitoring national regulators and citizen complaints. A grace period runs until December 2026 for marking obligations on generative systems already on market. The Commission is also preparing a call to expand EU model-evaluation capacity, targeting operational third-party assessment by 2027, the point at which frontier oversight stops depending on providers evaluating themselves.

Sources

Sources