Barcelona: For a year the European Union’s rules on the most powerful artificial intelligence systems have carried an unusual quality: they applied, but nobody could be punished for ignoring them. That grace period is about to close. From the second of August the bloc’s AI Office gains the teeth its founding law always promised, with the power to demand information, compel access to models and, in the last resort, order a system pulled from the market.
The obligations themselves are not new. Rules governing general-purpose AI, the sprawling foundation models that sit beneath chatbots and image generators, took effect in August of last year, requiring their makers to document how the systems were built, respect copyright in their training data and, for the most capable models, assess and mitigate systemic risks. What was missing until now was consequence. The law deliberately staggered enforcement by twelve months, giving both companies and regulators time to build the practices and expertise that meaningful oversight requires.
The stakes attached to that switch are considerable. The AI Office can levy fines reaching three percent of a company’s global annual turnover, or fifteen million euros, whichever bites harder, a scale calibrated to register even on the balance sheets of the American giants that dominate the field. For firms whose revenues run into the tens of billions, three percent is not a rounding error but a genuine deterrent, and the mere prospect of a formal information request now concentrates minds that a voluntary regime never quite could.
Much of the compliance architecture rests on a code of practice finalised last summer, a voluntary rulebook drawn up with outside experts and organised around transparency, copyright and safety. Signing it is not mandatory, but doing so offers companies a presumption of good behaviour and a clearer path through the law’s requirements, while holding out is likely to invite closer scrutiny. The arrangement is a familiar European bargain, trading regulatory forbearance for demonstrable cooperation, and most major developers have judged the shelter worth the commitment.
The timing is not uniform for everyone. Models placed on the market before last August enjoy a longer runway, with a compliance deadline stretching into 2027, an acknowledgement that retrofitting safeguards onto systems already in wide use is harder than building them in from the start. Newer models enjoy no such latitude. What happens next will define whether the union’s gamble pays off. Writing rules for a technology that evolves monthly is one thing; enforcing them against companies with armies of lawyers and headquarters on another continent is another entirely. The office is still hiring and its methods largely untested, and its first moves will be read as a signal of how aggressive Europe intends to be. From August, that bet stops being theoretical and starts being enforced.




