EU AI Act: general-purpose AI rules
the obligations, and the Commission now enforcing them

Key facts
- 2 Aug 2025Articles 51 to 56
- Obligations from
- 2 Aug 2026AI Office, Art 101 fines
- Enforced from
- 3% / €15mwhichever is higher
- GPAI fines
- 10^25training FLOP presumption
- Systemic risk
- 2 Aug 2027on market before Aug 2025
- Legacy models
Model makers selling into Europe have lived with the AI Act's paperwork since August 2025. Since 2 August 2026 the AI Office can fine them for ignoring it: up to 3% of worldwide turnover or €15m, whichever is higher. The Digital Omnibus of July 2026 moved other deadlines and left these standing.
Since 2 August 2026 the European Commission has been able to fine the companies behind large AI models for breaking the AI Act’s rules. The obligations themselves are a year older: providers of general-purpose AI models, the category that covers GPT, Claude, Gemini, Llama and every other model built to serve many purposes, have been required to comply since 2 August 2025. What changed this August is enforcement. The Commission’s AI Office can now demand documents, order measures and impose fines of up to 3% of a provider’s total worldwide turnover or €15m, whichever is higher.
What the rules require, who enforces them, what the fines are, and where the timetable stands as of 18 September 2026, from the legal texts themselves.
The rules arrived in two stages
The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and switches on in phases set by its Article 113. The general-purpose AI chapter took effect on 2 August 2025, with one deliberate carve-out: Article 101, the fines article, was held back a further year. The Act’s own words: “Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101.”
That design gave providers a year of binding obligations with no fining power behind them, and it ended on 2 August 2026. The Commission announced the start of enforcement on 31 July 2026, in press release IP/26/1714: “From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.”
What every model maker must do
Article 53 carries the baseline duties, and they bind every provider placing a general-purpose model on the EU market. Each provider has to:
| Duty | What it requires |
|---|---|
| Technical documentation | Draw up and keep current documentation of the model, for the AI Office and national authorities on request |
| Downstream information | Give the companies building on the model the documentation they need to comply themselves |
| Copyright policy | Put in place a policy to comply with EU copyright law, including reservations of rights |
| Training-data summary | Publish a “sufficiently detailed summary” of training content, on the AI Office’s template |
The first two duties are waived for free and open-source models that publish their weights, architecture and usage documentation. The waiver has a hard edge, in the Act’s own words: “This exception shall not apply to general-purpose AI models with systemic risks.”
The biggest models carry extra duties
Article 51 draws the line for the heavier tier. A model is presumed to have “high impact capabilities”, and so to carry systemic risk, “when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25”. The Commission can also designate a model by decision, on its own initiative or after a qualified alert from the Act’s scientific panel.
Providers of systemic-risk models take on Article 55 as well: model evaluation on standardised protocols including documented adversarial testing, assessment and mitigation of systemic risks at Union level, reporting of serious incidents to the AI Office without undue delay, and “an adequate level of cybersecurity protection” for both the model and its physical infrastructure. The Commission’s enforcement announcement names the risk categories it has in mind for this tier: chemical, biological, radiological and nuclear incidents, loss of control, cyber offence, harmful manipulation and threats to fundamental rights.
Fines reach 3% of worldwide turnover
Article 101 is what became applicable on 2 August 2026. Its operative sentence: “The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher.” The trigger is an intentional or negligent infringement of the obligations, failure to supply or correct requested information, failure to comply with a requested measure, or failure to give the AI Office access to the model for evaluation.
The GPAI tier sits in the middle of the Act’s three fine bands. Prohibited practices, banned outright since February 2025, reach €35m or 7% of worldwide turnover; supplying incorrect or incomplete information to authorities reaches €7.5m or 1%.
Who enforces what
Enforcement splits three ways, and the Commission’s announcement draws the lines. The AI Office enforces the general-purpose model rules across the board, and also polices AI systems “offered by the same provider as the underlying general-purpose AI model”, plus systems on very large online platforms already regulated under the Digital Services Act. National competent authorities in each member state enforce the rules for other AI systems. The European Data Protection Supervisor covers AI used by the EU’s own institutions.
The July 2026 Digital Omnibus widened the AI Office’s exclusive lane: it now also covers systems built on a general-purpose model where the system and model providers belong to the same corporate group.
Alongside the powers, the Commission launched machinery for hearing about breaches: a complaint tool, a whistleblower channel, and a dedicated route for downstream providers who build on general-purpose models. A 60-expert scientific panel advises the AI Office, with Professor Alessandro Abate of Oxford named as lead scientific adviser in the Commission’s announcement; the panel can trigger the systemic-risk designation of a model through a qualified alert.
Chatbots must say they are AI
The same 2 August 2026 date switched on the Act’s transparency rules, Article 50. In the Commission’s own summary: “chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human. Deepfakes… will have to be labelled. AI-generated or altered content will also have to carry machine-readable marks so it can be detected more easily.” Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty.
Two codes of practice, and who signed
Two separate codes sit under the Act, and they are often confused. The General-Purpose AI Code of Practice, published in July 2025, is the compliance vehicle for model providers: signing it and keeping to it is a recognised way to demonstrate compliance with Articles 53 and 55 until harmonised standards exist. Its signatories include Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed only its Safety and Security chapter, which the Commission notes means it “will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means”. Meta declined to sign, a refusal reported at the time by CNBC; the Commission’s signatory pages record the absence by listing the company nowhere.
The second code is the Code of Practice on Transparency of AI-generated Content, supporting Article 50. The Commission published its first signatory list on 31 July 2026 with more than 180 organisations on it, drawn from well beyond the model labs.
The Digital Omnibus moved the high-risk dates and left these alone
On 27 July 2026, days before enforcement began, the Digital Omnibus on AI entered into force as Regulation (EU) 2026/1744. Headlines called it a delay to the AI Act, and for high-risk systems it is: obligations for the Annex III high-risk categories moved from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products to 2 August 2028. It also added new prohibitions, applying from 2 December 2026, on AI systems that generate non-consensual sexually explicit content and child sexual abuse material.
The general-purpose track was untouched. The amending regulation rewrites Article 113’s points on prohibited practices and high-risk systems and leaves point (b), the clause carrying the GPAI dates, exactly as it was. The obligations have applied since August 2025, the fines since August 2026, and both survived the renegotiation.
The dates still to come
| Date | What applies |
|---|---|
| 2 December 2026 | New prohibitions on AI-generated non-consensual intimate imagery and CSAM; marking deadline for pre-existing systems |
| 2 August 2027 | Compliance deadline for models placed on the market before 2 August 2025 |
| 2 December 2027 | Annex III high-risk system obligations, as moved by the Omnibus |
| 2 August 2028 | High-risk AI embedded in regulated products |
The 2 August 2027 row is the one for the incumbent labs: Article 111(3) gives models already on the market before the obligations began a two-year runway, so the full weight of the documentation and copyright duties reaches the back catalogue next summer. As of 18 September 2026 the AI Office’s own news pages list no fine and no formal proceeding against a general-purpose model provider; the enforcement era is seven weeks old and the record so far is the machinery, the codes and the powers described above.
