Strasbourg: For almost a year the most powerful artificial-intelligence companies operating in Europe have lived in a curious legal half-light. The obligations governing general-purpose AI models technically entered into application in August 2025, but the machinery to enforce them was held back. That grace period ends on 2 August 2026, and its expiry will reveal whether the European Union’s flagship technology law has real bite or merely impressive paperwork.
The instrument at the centre of this transition is the General-Purpose AI Code of Practice, published by the Commission in July 2025. It is a voluntary scheme designed to help developers of large foundation models demonstrate compliance with Articles 53 and 55 of the AI Act, organised around three chapters covering transparency, copyright and safety. Signing the code does not exempt a company from the law, but it offers a presumption of conformity and a degree of legal predictability that most major providers have judged worth having.
The significance of the August deadline is procedural but far from trivial. From that date the Commission’s AI Office may begin issuing formal requests for information, demanding access to models, and ultimately imposing fines for non-compliance. Until now the office has functioned largely as a convener and standard-setter. It is about to become a regulator with the power to compel, and the difference between those two roles will shape how seriously the global industry treats Brussels.
Three tensions will define the months ahead. The first is the copyright chapter, the most contested element of the code. It asks signatories to respect rights reservations and to document the data used to train their models, a demand that collides with an industry culture of opacity about training corpora. Publishers and authors across Europe argue the provisions remain too weak to be meaningful, while developers warn that aggressive disclosure could expose trade secrets. Neither side is satisfied, which may indicate a workable compromise or merely a fight deferred.
The second tension concerns capacity. Policing the most sophisticated AI systems on earth requires technical expertise that public administrations have historically struggled to recruit and retain. The AI Office has expanded, but the asymmetry between regulator and regulated is stark. Enforcement that depends on companies disclosing their own risks invites the familiar problem of self-assessment, and the credibility of the entire regime will rest on whether the office can independently verify what it is told.
The third tension is geopolitical. The AI Act was conceived when Europe still hoped to set the global template for trustworthy technology, much as its data-protection rules once did. That ambition now meets a harder environment, in which the United States favours lighter-touch oversight and warns against rules it sees as protectionist, while several European governments fret openly that regulation is throttling the continent’s own nascent model developers. The Commission has insisted enforcement will be proportionate, language that signals flexibility but also exposes it to accusations of blinking first.
What makes the August threshold genuinely consequential is that it converts principle into precedent. A law that is never enforced reshapes behaviour only at the margins; the first formal information request, the first finding of non-compliance, the first negotiated remedy will tell developers everywhere how much latitude they actually have. The Commission will be acutely aware that overreach could chase investment abroad while timidity would hollow out the credibility it spent years building.
The likeliest outcome is neither dramatic confrontation nor quiet capitulation but a slow calibration, in which the AI Office tests its powers cautiously and companies probe the limits of compliance. Europe has written the rules. From August it must prove it can apply them, and that proof will matter far beyond its borders.




