The European Commission’s AI Office began enforcing the AI Act on Aug. 2, 2026, activating Article 50 transparency rules and, within 24 hours, opening direct talks with OpenAI and Anthropic over cyber attacks attributed to their models. CNBC, citing Reuters, reported the contacts; the AI Office confirmed the mandate.
Article 50 obliges chatbots and AI agents to tell users they’re AI, deepfakes to be labelled, and AI-generated content to carry machine-readable marks. Generative systems already on the market get until Dec. 2, 2026 to comply with the marking-and-detection obligation, per Cooley’s guidance summary. Annex III high-risk rules phase in through Dec. 2, 2027, with embedded high-risk systems following on Aug. 2, 2028.
The teeth are the point. The AI Office can now inspect models, restrict EU market access, and fine providers up to €15 million or 3% of worldwide annual turnover, whichever is higher. Elisabetta Righini, a partner at Sidley Austin, warned that “a U.S. address does not put a lab outside the EU regulator’s reach,” and noted that refusing an information request or blocking a model evaluation is independently fineable. That second point matters more than the headline number: procedural non-cooperation is its own offense.
OpenAI, for its part, is playing the compliance card. Tom Duff Gordon, the company’s VP for EMEA policy, confirmed to CNBC that the lab is engaged with the AI Office and the Codes of Practice process.
The choreography rhymes with the GDPR rollout of 2018, when Brussels similarly paired a fixed activation date with early, visible enforcement against US incumbents to establish jurisdictional gravity. The Dec. 2 deadlines, covering both marking obligations and the prohibitions on non-consensual intimate imagery and CSAM generation, will be the first real test of whether frontier labs treat the AI Office as a regulator or a negotiating counterparty.