Brussels Can Now Fine a Frontier Lab. Nobody Changed a Model.
The EU AI Act's enforcement powers over general-purpose models went live on August 2 — a year after the obligations did — and the interesting part is what the Commission can now demand rather than what it can charge.

On August 2, the European Commission acquired the power to investigate, evaluate, and fine the companies that build general-purpose AI models. Not the power to write rules for them — that happened a year earlier. The power to act on the rules it already wrote.
That gap is the whole story. The obligations on GPAI providers came into force on 2 August 2025. Providers then got a twelve-month adjustment period in which the rules were real and the consequences were not. As of last Sunday, the European AI Office can request documentation, run its own evaluations of a model, order risk mitigations or a market withdrawal, and levy fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
No lab shipped a different model on August 3. That is precisely what makes this worth reading carefully: the enforcement phase does not change what models do. It changes what labs must be able to prove about them, and to whom, on demand.
What actually switched on
Four categories of Commission power came alive at once, and they escalate in a deliberate order.
Information requests. The Commission can compel a provider to hand over technical documentation about a model — architecture, training process, evaluation results, the internal record of what was tested and what was found. This is the workhorse. Most enforcement in most regulatory regimes never gets past this stage, because most of the leverage is here.
Evaluations. The AI Office can conduct its own assessment of a GPAI model, including to investigate systemic risk. This is the provision that matters most and is discussed least. A regulator that must accept the provider's own benchmark results is negotiating. A regulator that can demand access and run its own evaluation is auditing.
Measures. Compliance orders, risk-mitigation requirements, market restrictions, recall, withdrawal. The nuclear options, and correspondingly unlikely to be used early.
Fines. Four distinct grounds, and the framing is instructive: a provider can be fined for infringing the Act, but also for failing to supply requested documentation, failing to implement requested measures, or withholding model access for evaluation. Three of the four are procedural. The Commission built explicit penalties for stonewalling the audit, separate from the penalty for failing it.
The obligations being enforced are documentary
Read the substantive GPAI duties and the shape of the regime becomes clear. Providers must maintain technical documentation. Provide information to downstream providers who build on their models. Adopt a copyright compliance policy. Publish a sufficiently detailed summary of training data content.
None of these constrain capability. All of them constrain opacity.
The training-data summary is the one with teeth nobody has fully tested. A frontier lab publishing a meaningful account of what its model was trained on is publishing a document that plaintiffs' lawyers, rights-holders, and competitors will read with extraordinary care. The obligation has existed since August 2025. The ability to fine a provider for an inadequate one arrived last week. Those are very different pressures, and the second one has no track record yet.
Alongside them sit the procedural duties: cooperate with the Commission and national authorities, answer information requests inside the specified windows, provide model access for evaluation, and — for providers based outside the EU — appoint an authorized representative in the Union. That last item quietly resolves the jurisdictional question American labs might otherwise have litigated for years. If you place a general-purpose model on the EU market, you name someone in Europe who answers for it.
There is also a two-week notification duty: a provider must tell the Commission within two weeks of the point at which its model meets the high-impact capability threshold. That threshold is presumed at cumulative training compute above 10^25 FLOP — a line that every frontier training run now clears without effort, and which functions less as a filter than as a registration trigger.
The 3% number is the least interesting number
Coverage of August 2 fixated on the fine cap. It shouldn't. Three percent of worldwide turnover is a serious figure for a company with turnover; for a lab whose revenue is a fraction of its valuation and whose compute bill exceeds both, it is not obviously the binding constraint.
The binding constraint is the evaluation power combined with the penalty for withholding access. A lab facing a Commission evaluation has to decide what it hands over, and every answer creates a record. That record is discoverable, comparable across labs, and — critically — comparable against the lab's own public claims. The compliance risk is not really the fine. It is the accumulation of a documentary trail in a regulator's hands, produced under legal compulsion, at a moment when the same companies are making expansive safety claims in every other forum.
Article 50's transparency obligations landed in the same window: systems that interact with people must disclose that they are AI, and generated or altered content must carry provenance signals. That one touches deployers as much as model providers, and it is the piece consumers will actually encounter.
What to watch
One date remains on the calendar and it is the important one: 2 August 2027, the deadline for GPAI models placed on the market before August 2025 to reach compliance. Everything built in the pre-Act era gets two years of grace. That cohort includes model families still in production service.
The near-term tell is simpler. Watch for the first Article 91 information request to become public — either because the Commission announces it or because a provider discloses it. Enforcement regimes reveal their actual temperature in the first case, not the statute. A regime that opens with a documentation request to a mid-sized European provider is a different regime from one that opens by asking an American frontier lab for training-data records.
Until then, the honest summary is narrow and worth stating plainly: Europe spent a year with rules it could not enforce, and now it can. Whether it will is a separate question, and August 2 answered none of it.
