The European Commission’s AI Office switched on active enforcement of the AI Act on August 2, 2026, moving in concert with national competent authorities and the European Data Protection Supervisor. Brussels is now the only major jurisdiction on the planet with live regulatory powers over frontier AI labs, and it has already opened lines with the two American companies most exposed.

The toolkit is broader than the headline penalty schedule suggests. The AI Office can issue information requests, order model evaluations, and fine providers for refusing, misleading, or blocking access, separately from any substantive breach. Transparency obligations kicked in the same day: chatbots must disclose they’re AI, and deepfakes and generated content must carry machine-readable marks. Non-EU providers are required to appoint an EU-based authorised representative.

Extraterritorial reach is the point. “A U.S. address does not put a lab outside the EU regulator’s reach,” said Elisabetta Righini, partner at Sidley Austin. Per Reuters, the EU is already in talks with OpenAI and Anthropic over recent cyber attacks by their models; OpenAI has confirmed contact with the AI Office. Further milestones follow: prohibitions on non-consensual intimate imagery and CSAM generation apply December 2, 2026, with high-risk Annex III system rules a year later.

Washington isn’t close. The Great American Artificial Intelligence Act, negotiated by Reps. Jay Obernolte and Lori Trahan, remains a discussion draft that hasn’t been introduced. Its central fight is a preemption clause overriding state laws specifically regulating model development, sunsetting December 2029. Public Citizen, Public Knowledge, and the AFL-CIO oppose it; BSA and ITIC back it.

Lawfare called GAAIA “the best federal frontier AI safety framework yet proposed” but “net-negative as written,” because preemption would block state laws expected in 2027–2029. The regulatory vacuum in Washington isn’t neutral. It’s a decision, and Brussels is filling it.

Sources

Sources