YFarmX logoYFarmX

EU AI Act: general-purpose AI rules

the obligations, and the Commission now enforcing them

8 min readPolicy & Regulation

Editorial collage: a bound regulation volume carrying the EU's circle of gold stars, headlined AI ACT, enforced, 3% or €15m, with the Berlaymont building behind and a GPAI tag tied to the spine

Key facts

2 Aug 2025Articles 51 to 56
Obligations from
2 Aug 2026AI Office, Art 101 fines
Enforced from
3% / €15mwhichever is higher
GPAI fines
10^25training FLOP presumption
Systemic risk
2 Aug 2027on market before Aug 2025
Legacy models

Model makers selling into Europe have lived with the AI Act's paperwork since August 2025. Since 2 August 2026 the AI Office can fine them for ignoring it: up to 3% of worldwide turnover or €15m, whichever is higher. The Digital Omnibus of July 2026 moved other deadlines and left these standing.

Since 2 August 2026 the European Commission has been able to fine the companies behind large AI models for breaking the AI Act’s rules. The obligations themselves are a year older: providers of general-purpose AI models, the category that covers GPT, Claude, Gemini, Llama and every other model built to serve many purposes, have been required to comply since 2 August 2025. What changed this August is enforcement. The Commission’s AI Office can now demand documents, order measures and impose fines of up to 3% of a provider’s total worldwide turnover or €15m, whichever is higher.

What the rules require, who enforces them, what the fines are, and where the timetable stands as of 18 September 2026, from the legal texts themselves.

The rules arrived in two stages

The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and switches on in phases set by its Article 113. The general-purpose AI chapter took effect on 2 August 2025, with one deliberate carve-out: Article 101, the fines article, was held back a further year. The Act’s own words: “Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101.”

That design gave providers a year of binding obligations with no fining power behind them, and it ended on 2 August 2026. The Commission announced the start of enforcement on 31 July 2026, in press release IP/26/1714: “From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.”

Screenshot of the European Commission's enforcement of the AI Act page, showing the three fine tiers, up to €35m or 7% of worldwide turnover for prohibited practices, up to €15m or 3% for other obligations including those on general-purpose AI providers, and up to €7.5m or 1% for supplying incorrect information, with the split of enforcement roles beneath
The Commission's own enforcement page, last updated 24 August 2026, with the three fine tiers and the split of enforcement roles. Source: European Commission.

What every model maker must do

Article 53 carries the baseline duties, and they bind every provider placing a general-purpose model on the EU market. Each provider has to:

Duty What it requires
Technical documentation Draw up and keep current documentation of the model, for the AI Office and national authorities on request
Downstream information Give the companies building on the model the documentation they need to comply themselves
Copyright policy Put in place a policy to comply with EU copyright law, including reservations of rights
Training-data summary Publish a “sufficiently detailed summary” of training content, on the AI Office’s template

The first two duties are waived for free and open-source models that publish their weights, architecture and usage documentation. The waiver has a hard edge, in the Act’s own words: “This exception shall not apply to general-purpose AI models with systemic risks.”

Screenshot of Article 53 of the AI Act on EUR-Lex, headed Obligations for providers of general-purpose AI models, listing the duties to draw up and keep up-to-date technical documentation, to make information available to downstream providers, to put in place a copyright policy, and to make publicly available a sufficiently detailed summary of training content
Article 53 as it stands on EUR-Lex: the four duties every general-purpose model provider carries. Source: Regulation (EU) 2024/1689.

The biggest models carry extra duties

Article 51 draws the line for the heavier tier. A model is presumed to have “high impact capabilities”, and so to carry systemic risk, “when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25”. The Commission can also designate a model by decision, on its own initiative or after a qualified alert from the Act’s scientific panel.

Providers of systemic-risk models take on Article 55 as well: model evaluation on standardised protocols including documented adversarial testing, assessment and mitigation of systemic risks at Union level, reporting of serious incidents to the AI Office without undue delay, and “an adequate level of cybersecurity protection” for both the model and its physical infrastructure. The Commission’s enforcement announcement names the risk categories it has in mind for this tier: chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation and threats to fundamental rights.

Fines reach 3% of worldwide turnover

Article 101 is what became applicable on 2 August 2026. Its operative sentence: “The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher.” The trigger is an intentional or negligent infringement of the obligations, failure to supply or correct requested information, failure to comply with a requested measure, or failure to give the AI Office access to the model for evaluation.

The GPAI tier sits in the middle of the Act’s three fine bands. Prohibited practices, banned outright since February 2025, reach €35m or 7% of worldwide turnover; supplying incorrect or incomplete information to authorities reaches €7.5m or 1%.

Screenshot of Article 101 of the AI Act on EUR-Lex, headed Fines for providers of general-purpose AI models, with paragraph 1 stating the Commission may impose fines not exceeding 3% of annual total worldwide turnover or EUR 15 000 000, whichever is higher, and listing the infringements that trigger them
Article 101, the fining power the Commission gained on 2 August 2026. Source: Regulation (EU) 2024/1689.

Who enforces what

Enforcement splits three ways, and the Commission’s announcement draws the lines. The AI Office enforces the general-purpose model rules across the board, and also polices AI systems “offered by the same provider as the underlying general-purpose AI model”, plus systems on very large online platforms already regulated under the Digital Services Act. National competent authorities in each member state enforce the rules for other AI systems. The European Data Protection Supervisor covers AI used by the EU’s own institutions.

The July 2026 Digital Omnibus widened the AI Office’s exclusive lane: it now also covers systems built on a general-purpose model where the system and model providers belong to the same corporate group.

Alongside the powers, the Commission launched machinery for hearing about breaches: a complaint tool, a whistleblower channel, and a dedicated route for downstream providers who build on general-purpose models. A 60-expert scientific panel advises the AI Office, with Professor Alessandro Abate of Oxford named as lead scientific adviser in the Commission’s announcement; the panel can trigger the systemic-risk designation of a model through a qualified alert.

Chatbots must say they are AI

The same 2 August 2026 date switched on the Act’s transparency rules, Article 50. In the Commission’s own summary: “chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human. Deepfakes… will have to be labelled. AI-generated or altered content will also have to carry machine-readable marks so it can be detected more easily.” Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty.

Two codes of practice, and who signed

Two separate codes sit under the Act, and they are often confused. The General-Purpose AI Code of Practice, published in July 2025, is the compliance vehicle for model providers: signing it and keeping to it is a recognised way to demonstrate compliance with Articles 53 and 55 until harmonised standards exist. Its signatories include Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed only its Safety and Security chapter, which the Commission notes means it “will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means”. Meta declined to sign, a refusal reported at the time by CNBC; the Commission’s signatory pages record the absence by listing the company nowhere.

The second code is the Code of Practice on Transparency of AI-generated Content, supporting Article 50. The Commission published its first signatory list on 31 July 2026 with more than 180 organisations on it, drawn from well beyond the model labs.

Screenshot of the European Commission's page on the contents of the General-Purpose AI Code of Practice, showing its three chapters, Transparency, Copyright, and Safety and Security, each with a description of what it requires and which providers it binds
The three chapters of the General-Purpose AI Code of Practice. Transparency and Copyright bind every signatory; Safety and Security binds the systemic-risk tier. Source: European Commission.

The Digital Omnibus moved the high-risk dates and left these alone

On 27 July 2026, days before enforcement began, the Digital Omnibus on AI entered into force as Regulation (EU) 2026/1744. Headlines called it a delay to the AI Act, and for high-risk systems it is: obligations for the Annex III high-risk categories moved from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to 2 August 2028. It also added new prohibitions, applying from 2 December 2026, on AI systems that generate non-consensual sexually explicit content and child sexual abuse material.

The general-purpose track was untouched. The amending regulation rewrites Article 113’s points on prohibited practices and high-risk systems and leaves point (b), the clause carrying the GPAI dates, exactly as it was. The obligations have applied since August 2025, the fines since August 2026, and both survived the renegotiation.

The dates still to come

Date What applies
2 December 2026 New prohibitions on AI-generated non-consensual intimate imagery and CSAM; marking deadline for pre-existing systems
2 August 2027 Compliance deadline for models placed on the market before 2 August 2025
2 December 2027 Annex III high-risk system obligations, as moved by the Omnibus
2 August 2028 High-risk AI embedded in regulated products

The 2 August 2027 row is the one for the incumbent labs: Article 111(3) gives models already on the market before the obligations began a two-year runway, so the full weight of the documentation and copyright duties reaches the back catalogue next summer. As of 18 September 2026 the AI Office’s own news pages list no fine and no formal proceeding against a general-purpose model provider; the enforcement era is seven weeks old and the record so far is the machinery, the codes and the powers described above.