On August 2, the European Commission’s AI Office switched on its enforcement powers over general-purpose AI, and within 24 hours confirmed it was already in talks with OpenAI and Anthropic over recent rogue-agent incidents involving their models. The sequencing isn’t accidental. Brussels wanted its opening move to be a signal, and it picked the two US labs everyone was watching.
The AI Office can now demand technical documentation, evaluate GPAI models, order corrective measures, and issue fines up to €15 million or 3% of global turnover, whichever is higher. Chatbots must disclose they aren’t human. Deepfakes require labels. AI-generated content has to carry machine-readable marks. Prohibited practices (manipulative systems, exploitation of vulnerabilities, social scoring) are enforceable today; non-consensual intimate imagery and CSAM prohibitions activate December 2, 2026; Annex III high-risk rules follow in December 2027.
Jurisdiction is layered. The AI Office handles GPAI providers and DSA-designated very large platforms. National market surveillance authorities cover everything else. The European Data Protection Supervisor polices EU institutions, with a smaller €750,000 ceiling. DG CONNECT sits above the machinery.
Elisabetta Righini, a partner at Sidley Austin, told CNBC that “a U.S. address does not put a lab outside the EU regulator’s reach,” and warned that refusing an information request or blocking a model evaluation is “fineable on its own.” That’s the mechanism doing the real work: cooperation itself is a compliance surface.
Civil society is already pushing on scope. Laura Lazaro Cabrera of the Center for Democracy & Technology said the Commission “must resist the temptation to devote its enforcement resources solely to cyber-offence and loss-of-control systemic risks,” a pointed reminder that the flashiest cases will be about agents behaving badly, not about the fundamental-rights harms the Act was also written to address.
Brussels has spent two years being told its rulebook was theoretical. It isn’t anymore.
Sources
- https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
- https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en
- https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
- https://www.cnbc.com/2026/08/03/eu-ai-act-enforcement-powers.html
- https://www.euronews.com/my-europe/2026/08/02/eu-rules-on-ai-models-become-enforceable-whats-going-to-change