The European Commission’s AI Office switched on its formal enforcement powers on August 2, 2026, activating Article 50 transparency obligations and general-purpose AI oversight with fines reaching €15 million or 3% of worldwide annual turnover, whichever is higher. EU institutions face a lower ceiling of €750,000. The legal architecture that governments spent three years arguing about is now operational.

Article 50 is the visible layer. Chatbots, voice assistants, and AI agents must disclose that users are talking to a machine. Deepfakes require labels. Generated or altered content must carry machine-readable provenance marks. Guidelines adopted July 20 clarified the scope, and providers already on the market have until December 2, 2026 to bring marking and detection systems into compliance.

The quieter shift is jurisdictional. Wilson Sonsini notes that the AI Office can now request documentation, access models for evaluation, and impose corrective measures directly on GPAI providers, while national authorities handle other systems and the EDPS covers EU bodies. The AI Omnibus deferred high-risk obligations to a later phase but left the August 2 triggers intact.

For US labs, geography isn’t a shield. “A U.S. address does not put a lab outside the EU regulator’s reach,” said Elisabetta Righini, partner at Sidley Austin, who notes that non-EU providers must appoint an EU-based authorised representative and that refusing an information request or blocking a model evaluation is independently fineable. Reuters reports the EU is already in talks with OpenAI and Anthropic following recent cyber incidents; OpenAI confirmed contact with the AI Office.

The Office says “technical compliance dialogues” remain its preferred initial tool, with formal powers held in reserve. That’s the GDPR playbook: quiet letters first, headline fines later. Brussels has done this before, and it took its time.

Sources

Sources