The European Commission’s AI Office became formally empowered on August 2 to investigate, evaluate, and fine providers of general-purpose AI models, turning a year-old set of paper obligations into the first live enforcement regime for frontier models anywhere in the world. Penalties top out at €15 million or 3% of worldwide annual turnover per violation, whichever is higher.

The GPAI rules themselves have applied since August 2, 2025. What changed Sunday, as Wilson Sonsini notes, is that the AI Office finally has teeth: information requests, model evaluations, and market-entry restrictions are now enforceable instruments rather than diplomatic asks.

The timing isn’t subtle. Reuters reported Friday that the EU is already in talks with OpenAI and Anthropic over recent cyber incidents involving their models, and OpenAI confirmed contact with the AI Office to CNBC. Article 50 transparency rules also activated: chatbots must disclose they’re AI, and generative outputs must carry machine-readable provenance marks. Providers already on the market have until December 2, 2026 to comply, per Cooley.

Sidley Austin partner Elisabetta Righini put the extraterritorial point bluntly: “A U.S. address does not put a lab outside the EU regulator’s reach.” Non-EU providers must appoint an EU-based authorised representative, and Righini notes that refusing an information request, giving misleading answers, or blocking an evaluation is independently fineable.

The geopolitical backdrop is already hostile. Google was fined $1 billion in July under separate EU rules, prompting President Trump to threaten a “substantial” tariff. The AI Office says “technical compliance dialogues” remain its preferred first step, per a recent FAQ cited by Wilson Sonsini, which is the language regulators use when they’d rather not test their new powers on week one. They now have the option either way.

Sources

Sources