On August 2, the European Commission’s AI Office switched from advisory posture to enforcement authority, activating the binding phase of the EU AI Act alongside the Article 50 transparency duties governing chatbots, deepfakes, and generative outputs. Within twenty-four hours, Reuters had reported and CNBC confirmed that the Office was already in talks with OpenAI and Anthropic over cyber-attack risks tied to their models. OpenAI acknowledged the contact.

The fine structure is the part Silicon Valley will read first. General-purpose AI breaches cap at €15 million or 3% of worldwide annual turnover, per JURIST; prohibited-practice violations scale to €35 million or 7%. National market-surveillance authorities can order non-compliant systems corrected, withdrawn, or recalled generally within 15 working days.

The jurisdictional reach is the part that matters longer-term. “A U.S. address does not put a lab outside the EU regulator’s reach,” said Elisabetta Righini, a partner at Sidley Austin. Non-EU providers must appoint an authorised representative inside the bloc. Wilson Sonsini notes the AI Office’s toolkit now includes information requests, model access for evaluation, and corrective orders. Refusing an information request or blocking a model evaluation, Righini added, “is fineable on its own.”

Brussels is signalling a graduated posture. “Technical compliance dialogues” are the stated first tool, and signatories to the voluntary Code of Practice on AI-Generated Content receive a presumption of conformity. Non-signatories don’t. Generative systems already on the market have until December 2, 2026 to comply with marking and detection duties, per Cooley, and the Commission has opened confidential channels for employees and users to report suspected violations.

The GDPR template is now visible in AI governance: extraterritorial scope, turnover-linked fines, and enforcement that begins with dialogue and ends with disclosure.

Sources

Sources