official regulation / European Commission AI Office
Europe’s AI Office can now fine and force-test the biggest general-purpose models
Since August 2, 2026, the European Commission’s AI Office holds live investigative and fining powers over general-purpose AI models — including orders to evaluate models, demand risk mitigation, and punish breaches with fines up to 3% of global turnover or €15 million — under rules that explicitly name systemic risks such as loss of control, CBRN harm, and cyber offense.
Key facts
- Switch-on
- Enforcement powers of the AI Office and Member State authorities apply from 2 August 2026
- AI Office scope
- GPAI model providers (incl. most advanced / systemic-risk models); certain AI systems from same provider/group; AI systems inside designated VLOPs/VLOSEs under DSA
- Investigative tools
- Requests for information; for GPAI — model evaluations and access requests; power to require measures including restricting public availability; for AI systems — interviews/inspections
- Sanctions (GPAI)
- Fines up to €15 million or 3% of total worldwide annual turnover (whichever higher); prohibited-practice ceiling separately up to €35 million or 7%
- Systemic-risk language
- Security/safety rules for most advanced models protecting against large-scale harm incl. CBRN incidents, loss of control, cyber offense, harmful manipulation, fundamental rights; GPAI Code of Practice operationalises obligations
- Timeline context
- GPAI obligations from 2 Aug 2025; enforcement machinery from 2 Aug 2026; high-risk Annex III deferred to 2 Dec 2027; embedded Annex I product rules to 2 Aug 2028
- Channels
- AI Act complaint tool, whistleblower tool, downstream-provider complaint channel
August 2 turned the GPAI chapter into a live supervisory risk for frontier providers — document demands, forced evaluations, withdrawal threats, and percentage-of-turnover fines — while the Commission’s own explainer still lists loss of control and CBRN among the systemic harms the regime is meant to police.
Desk reading of European Commission AI Act enforcement framework
Note
Europe’s grace period on general-purpose AI enforcement ended on August 2, 2026. The Commission’s AI Office can now demand technical files, run its own model evaluations, order corrective measures, restrict or pull a model, and fine providers up to 3% of worldwide turnover or €15 million. The same official pages say the hardest GPAI duties exist to blunt large-scale harms — including loss of control, CBRN pathways, and cyber offense. That is not a culture essay about a startup. It is the EU writing catastrophic-risk categories into an enforceable market rule and switching the penalty machine on.
Attribution: European Commission — “The enforcement framework of the AI Act” (digital-strategy.ec.europa.eu). Companion: Commission AI Act regulatory-framework page confirming AI Office GPAI enforcement from 2 August 2026.
Why it matters
Paper rules without a whip are theater. Pair with AISI’s measured capability climb: one note is the ruler, this note is the legal fence going live.
Sources
Official data. Live values go to the HUD / source product.