Brussels: The European Union’s flagship artificial intelligence law has spent the past year as a document more than a deterrent. That shifts on the second of August, when the Commission’s enforcement powers over the most capable general-purpose AI models fully activate and the period of polite encouragement gives way to the possibility of audits, demands for information, and financial penalties. The deadline turns an abstract rulebook into a live compliance problem for the handful of companies that build the foundation models the rest of the digital economy now leans on.
The instrument at the centre of this transition is the General-Purpose AI Code of Practice, and its design reveals how Brussels is trying to regulate a technology that moves faster than legislation can. Signing the code is technically voluntary. In practice it functions as a safe harbour, offering signatories a presumption of conformity with the law and assurance that the Commission will concentrate its scrutiny on adherence to the code rather than open-ended investigation. Refuse to sign, and a company invites the full, unpredictable weight of direct enforcement. It is a velvet glove with an iron incentive inside, and it has already pulled most major developers toward the table.
This is a shrewd regulatory bet. Rather than freezing detailed obligations into statute that would be obsolete within a product cycle, the EU has built a framework flexible enough to absorb new benchmarks, labelling standards, and transparency expectations as the technology evolves. A further strand of the code, due around the same window, tackles the marking and labelling of AI-generated content, giving providers a standardised way to meet the law’s transparency duties on synthetic media. The wager is that a living code can keep pace where black-letter rules would calcify.
The risk is the mirror image of the benefit. A voluntary code policed largely through self-reported conformity is only as strong as the Commission’s willingness and capacity to test it. The newly built AI Office must develop the technical expertise to scrutinise systems whose inner workings are guarded as trade secrets and understood in full by only a few thousand specialists worldwide, most of them employed by the very firms being regulated. If the office cannot credibly audit a frontier model, the presumption of conformity risks becoming a presumption of compliance that no one can verify, and the law’s teeth go blunt before they ever bite.
There is also the matter of who actually falls under the regime. The heaviest obligations attach to models judged to carry systemic risk, a category defined partly by the raw computing power used to train them. That threshold is a crude proxy. It captures today’s largest models cleanly enough, but it can be gamed by architectural choices and may miss smaller, specialised systems that prove dangerous in narrow domains. Anchoring regulation to a single technical metric invites a familiar dynamic in which the rule shapes engineering decisions as much as engineering shapes the rule.
For all these caveats, the August date matters because it sets a global reference point. The EU is once again trying to do for artificial intelligence what it did for data protection, exporting its standards through the sheer gravitational pull of access to its market. A company that builds one compliant model for Europe will find it cheaper to apply the same guardrails everywhere than to maintain two product lines. If that dynamic holds, the practical reach of the AI Act will extend far beyond the bloc’s borders, whatever happens in any single enforcement case.
The grace period that ends in August was meant to give developers time to align with the AI Office rather than to be ambushed by it, and the cooperative framing is genuine. But cooperation only works if the threat behind it is real. The coming months will reveal whether Brussels has built a regulator capable of holding the most powerful technology companies on earth to standards they helped write, or whether the AI Act becomes another well-intentioned European framework that commands respect on paper and struggles to compel it in practice. The answer will say as much about the EU’s enforcement muscle as about the law itself.




