official regulation / European Commission AI Office

Europe’s AI Office can now fine and force-test the biggest general-purpose models

Origin Lane: aiEuropean Union · AI Office (Brussels) · GPAI providers worldwide placing models on EU market

Since August 2, 2026, the European Commission’s AI Office holds live investigative and fining powers over general-purpose AI models — including orders to evaluate models, demand risk mitigation, and punish breaches with fines up to 3% of global turnover or €15 million — under rules that explicitly name systemic risks such as loss of control, CBRN harm, and cyber offense.

European Commission AI Office (Brussels) — GPAI enforcement locus, not a model-lab pin. Source map

Key facts

Switch-on
Enforcement powers of the AI Office and Member State authorities apply from 2 August 2026
AI Office scope
GPAI model providers (incl. most advanced / systemic-risk models); certain AI systems from same provider/group; AI systems inside designated VLOPs/VLOSEs under DSA
Investigative tools
Requests for information; for GPAI — model evaluations and access requests; power to require measures including restricting public availability; for AI systems — interviews/inspections
Sanctions (GPAI)
Fines up to €15 million or 3% of total worldwide annual turnover (whichever higher); prohibited-practice ceiling separately up to €35 million or 7%
Systemic-risk language
Security/safety rules for most advanced models protecting against large-scale harm incl. CBRN incidents, loss of control, cyber offense, harmful manipulation, fundamental rights; GPAI Code of Practice operationalises obligations
Timeline context
GPAI obligations from 2 Aug 2025; enforcement machinery from 2 Aug 2026; high-risk Annex III deferred to 2 Dec 2027; embedded Annex I product rules to 2 Aug 2028
Channels
AI Act complaint tool, whistleblower tool, downstream-provider complaint channel

August 2 turned the GPAI chapter into a live supervisory risk for frontier providers — document demands, forced evaluations, withdrawal threats, and percentage-of-turnover fines — while the Commission’s own explainer still lists loss of control and CBRN among the systemic harms the regime is meant to police.

Desk reading of European Commission AI Act enforcement framework

Note

Europe’s grace period on general-purpose AI enforcement ended on August 2, 2026. The Commission’s AI Office can now demand technical files, run its own model evaluations, order corrective measures, restrict or pull a model, and fine providers up to 3% of worldwide turnover or €15 million. The same official pages say the hardest GPAI duties exist to blunt large-scale harms — including loss of control, CBRN pathways, and cyber offense. That is not a culture essay about a startup. It is the EU writing catastrophic-risk categories into an enforceable market rule and switching the penalty machine on.

Attribution: European Commission — “The enforcement framework of the AI Act” (digital-strategy.ec.europa.eu). Companion: Commission AI Act regulatory-framework page confirming AI Office GPAI enforcement from 2 August 2026.

Why it matters

Paper rules without a whip are theater. Pair with AISI’s measured capability climb: one note is the ruler, this note is the legal fence going live.

Sources

Official data. Live values go to the HUD / source product.

Daily board