Brussels: On 2 August 2026 a grace period ends and Europe’s most ambitious technology law grows teeth. From that date the European Commission may, for the first time, take enforcement action against the makers of general-purpose artificial intelligence models, issuing requests for information, demanding access to systems, and ultimately imposing fines of up to 15 million euros or 3 percent of global annual turnover. The obligations themselves have technically applied since August 2025, but the year of forbearance that followed was the point: it gave regulators and companies alike time to work out what compliance actually means. That runway is now almost gone.
The centrepiece of the regime is the General-Purpose AI Code of Practice, published in mid-2025 and drawn up by the Commission’s AI Office with hundreds of stakeholders. It is voluntary, but the incentive to sign is deliberately lopsided. Signatories, a list of twenty-six that includes OpenAI, Google, Microsoft, Anthropic, IBM, Mistral and Amazon, get a lighter-touch relationship in which the Commission concentrates on monitoring adherence and treats good-faith commitments as mitigating factors when calculating penalties. Non-signatories must prove compliance by other means, which in practice means more paperwork, more scrutiny and less benefit of the doubt. The most telling refusal is Meta, which publicly declined to sign, while xAI endorsed only the safety and security chapters.
That split matters because it exposes the strategy behind the law. The Code divides obligations into three parts. Transparency and copyright compliance apply to every provider of a general-purpose model; the heavier safety-and-security chapter binds only the largest systems, those trained above a threshold of ten to the twenty-fifth floating-point operations deemed capable of posing systemic risk. By making the toughest rules apply to a handful of frontier developers while asking baseline documentation of everyone, Brussels is trying to regulate the few without smothering the many. Whether that compute threshold is a sensible proxy for danger, or an arbitrary line that will age badly as models grow more efficient, is one of the law’s genuine uncertainties.
The harder question is enforcement capacity. Passing rules is one thing; policing the world’s most sophisticated software companies is another. Academics and civil-society groups have warned that the AI Office is badly under-resourced for the task, with some estimates calling for a near-tripling of staff in its compliance and safety units. A regulator that cannot credibly audit a frontier model cannot credibly threaten it, and the 15 million euro headline fine is trivial against the revenues of the firms most likely to matter. The risk is a familiar European one: a law that is world-leading on paper and hesitant in practice.
Supporters counter that the framework’s real power is not the fine but the standard-setting. As with data protection, the EU is betting that global companies will build to the strictest market rather than maintain two versions of their systems, exporting European norms on transparency and copyright far beyond the single market. Detractors reply that AI moves faster than any regulator, that heavy documentation burdens entrench incumbents who can afford compliance departments, and that Europe risks regulating an industry it has largely failed to build. Both readings contain truth, and 2 August will not settle them.
What the deadline does is convert principle into consequence. For a decade European digital regulation has been long on ambition and short on visible teeth. The AI Act now forces a test of whether Brussels can hold frontier developers to account in real time, or whether it has once again written rules that outrun its capacity to enforce them. The answer will shape not only Europe’s AI market but the credibility of the regulatory model it hopes the rest of the world will copy.




