EU AI Act GPAI Enforcement: What It Requires and What It Costs
A source-cited briefing for CAIOs, CIOs, and CFOs on the general-purpose AI provisions: what is actually in force as of August 2026, what lands on deployers versus model providers, the extraterritorial reach for US enterprises, and the real penalty exposure.
Satori Canton · August 17, 2026 · 13 pages · v1.0
The general-purpose AI (GPAI) provisions of the EU AI Act have been binding on model providers since August 2, 2025. On August 2, 2026, two weeks before this report's date, the European Commission gained the power to fine GPAI providers up to 3 percent of global turnover or EUR 15 million, whichever is higher, and the Act's transparency rules for AI-generated content took effect. No fines have been issued and no formal AI Act proceedings against any GPAI provider have been announced as of this writing. The AI Office has signaled it will open with compliance dialogues, not penalties. Even so, the period in which enforcement was theoretical has ended.
The practical bottom line for a large enterprise is narrower than most coverage suggests. If you use AI models rather than build them, nearly all GPAI obligations sit on your model provider, not on you. Your direct exposure concentrates in three places: transparency duties when you deploy chatbots or publish AI-generated content, the compliance quality of the vendors you depend on, and the risk of accidentally becoming a provider by rebranding or heavily modifying a model. For US-based enterprises, the Act reaches you if your provider places a model on the EU market, if you have EU establishments deploying AI, or if your AI system's output is used in the EU. That last hook is the broadest and least settled.
Every major US model provider except Meta has signed the GPAI Code of Practice, and even Meta signed the separate transparency code in July 2026. Vendor documentation now exists that did not exist a year ago. Your procurement and governance processes should be consuming it. This report states what the regulation requires, what guidance recommends, and what is our own analysis, and labels each.
What the GPAI provisions actually say
The GPAI regime is Chapter V of Regulation (EU) 2024/1689, Articles 51 to 56, plus the fine power in Article 101 and the transparency rules in Article 50. It is a two-tier structure: baseline duties for every GPAI provider, and a heavier tier for models designated as posing systemic risk.
The Act defines a GPAI model as one that "displays significant generality and is capable of competently performing a wide range of distinct tasks," typically trained with large-scale self-supervision, and integrable into many downstream systems (Article 3(63)).12 Commission guidelines from July 2025 add an indicative technical criterion: a model is presumed in scope when its training compute exceeds 1023 FLOPs and it can generate text, audio, images, or video.1321 That is guidance, not binding text, but it is the test the AI Office says it will apply.
Tier one: every GPAI provider
Article 53 imposes four baseline duties on anyone placing a GPAI model on the EU market. The provider must maintain technical documentation for the AI Office and national authorities, with minimum contents set in Annex XI. It must give downstream AI system builders enough documentation to understand the model's capabilities and limits, per Annex XII. It must put in place a policy to comply with EU copyright law, including honoring text-and-data-mining opt-outs under the 2019 Copyright Directive. And it must publish a "sufficiently detailed summary" of training content, using a template the AI Office published in July 2025.114 Providers of free and open-source models with public weights and architecture are exempt from the two documentation duties, but never from the copyright policy or the training-content summary, and the exemption disappears entirely for systemic-risk models (Article 53(2)).2 Third-country providers must appoint an EU authorised representative before placing a model on the market, who must hold the technical documentation at the AI Office's disposal for ten years (Article 54).2
Tier two: systemic risk
Article 51 classifies a GPAI model as posing systemic risk if it has "high-impact capabilities." A model is presumed to have them when cumulative training compute exceeds 1025 FLOPs; the Commission can also designate a model directly using the criteria in Annex XIII.1 A provider whose model meets the threshold must notify the Commission within two weeks, and may argue the model nonetheless does not present systemic risks (Article 52).2 Designated providers carry four additional Article 55 duties: model evaluation using standardized protocols including documented adversarial testing, assessment and mitigation of systemic risks at Union level, tracking and reporting of serious incidents to the AI Office without undue delay, and adequate cybersecurity protection for the model and its infrastructure.1 The Commission is required by Article 52(6) to publish a list of systemic-risk models. We could not locate a published list as of this report's date, and the Commission's own Q&A says only that such models are "developed by a handful of companies." Treat the roster of designated models as not public.15
The timeline as it actually stands
Dates matter here because a widely reported amendment changed some of them but not the GPAI ones. The "Digital Omnibus on AI," Regulation (EU) 2026/1744, was adopted July 8, 2026 and entered into force July 27, 2026.3 It postponed the high-risk system obligations (Annex III systems to December 2, 2027; AI embedded in regulated products to August 2, 2028) and softened the AI literacy duty, but it did not touch Chapter V. GPAI obligations, the Commission's fine power, and the Article 50 transparency date all stand.456 The one GPAI-adjacent relief: systems already on the market before August 2, 2026 have until December 2, 2026 to implement machine-readable marking of synthetic content; new systems must comply immediately.5
| Date | What applies | Status |
|---|---|---|
| Aug 1, 2024 | AI Act enters into force | Done |
| Feb 2, 2025 | Prohibited practices; AI literacy (softened by the 2026 Omnibus) | In force |
| Aug 2, 2025 | GPAI obligations (Arts. 51 to 56), governance chapter, penalties framework except Art. 101 | In force |
| Aug 2, 2026 | General application; Art. 50 transparency; Commission fine power over GPAI providers (Art. 101); national enforcement of operator duties | In force as of two weeks ago |
| Dec 2, 2026 | End of marking grace period for systems on the market before Aug 2, 2026 (Omnibus) | Pending |
| Aug 2, 2027 | Compliance deadline for GPAI models placed on the market before Aug 2, 2025 | Pending |
| Dec 2, 2027 / Aug 2, 2028 | Postponed high-risk system obligations (Annex III / Annex I), per the Omnibus | Pending |
Table 1. GPAI-relevant dates, verified as of August 17, 2026.
The Code of Practice and the guidance stack
The GPAI Code of Practice, published July 10, 2025, is the Commission-endorsed voluntary route to demonstrating compliance. It has three chapters: Transparency (including a Model Documentation Form covering Article 53), Copyright, and Safety and Security, the last applying only to systemic-risk providers.8 Twenty-one companies have signed in full, including OpenAI, Anthropic, Google, Microsoft, Amazon, IBM, and Mistral. xAI signed only the Safety and Security chapter; the Commission notes it must demonstrate transparency and copyright compliance "via alternative adequate means." Meta declined to sign.910 Signing is not compliance and refusing is not violation; the Code's practical value is a lighter evidentiary burden and, for non-signatories, the prospect of more information requests.22
Around the Code sits a guidance stack an enterprise team should know exists: the July 2025 guidelines on the scope of GPAI obligations,12 the July 2025 training-content summary template,14 a serious-incident reporting template for systemic-risk providers published November 4, 2025,16 and, for Article 50, both Commission guidelines and a separate Code of Practice on Transparency of AI-Generated Content finalized in mid-2026, which had roughly 190 signatory organisations by end of July 2026.454647
As of August 17, 2026: no fines, no publicly announced formal AI Act proceedings against any GPAI provider. The Commission's enforcement powers activated August 2, 2026, and law firm and trade press reporting in the first weeks confirms the AI Office is opening with "technical compliance dialogues."1718 The most visible EU action against an AI model, the January 2026 formal proceedings over Grok's conduct on X, runs under the Digital Services Act, not the AI Act.4950 Our view: absence of early fines is expected, not evidence of a paper tiger. The DSA fine record shows the Commission will use new powers once precedent and staffing mature.
Impact on EU-based companies
The single most consequential fact in this report: the GPAI obligations in Articles 53 to 55 bind providers of models, not companies that use them. Most enterprise readers are deployers. Be precise about which duties are actually yours.
The Act's definitions do the sorting. A provider develops an AI system or GPAI model, or has one developed, and places it on the market under its own name or trademark (Article 3(3)). A deployer uses an AI system under its authority in a professional context (Article 3(4)).2 An enterprise running Copilot, ChatGPT Enterprise, Claude, or Gemini through vendor contracts is a deployer. Law firm analysis is consistent on this: buying and even configuring a third-party tool, including adding company data through retrieval or fine-tuning within normal bounds, "likely maintains deployer status."2324
What deployers actually owe
For ordinary, non-high-risk GPAI-based tools, the deployer obligation set is short. The regulation requires three things. First, transparency under Article 50: deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons (Article 50(3)); deployers must disclose deepfakes, and must disclose AI-generated or manipulated text when it is published to inform the public on matters of public interest, unless the content has undergone human review with editorial responsibility (Article 50(4)).2 Note the allocation: the duty to make a chatbot identify itself as AI sits with the provider under Article 50(1), not the deployer. Second, AI literacy: Article 4 originally required providers and deployers to ensure adequate AI literacy in staff; the 2026 Omnibus softened this toward Commission and member-state support and facilitation, reducing the direct enterprise obligation.5 Third, the extensive deployer duty list in Article 26 (human oversight, input-data controls, log retention, monitoring) applies only to high-risk systems, and the Omnibus deferred the Annex III high-risk regime to December 2027.25 Our view: the common enterprise instinct to treat every AI Act duty as its own is the main source of overscoped, overpriced compliance programs. Scope first, then spend.
The trap: becoming a provider by accident
Deployer status is not permanent. Under Article 25, a company that puts its own name or trademark on an AI system, substantially modifies one, or repurposes a general-purpose system into high-risk use inherits provider obligations.224 For GPAI models specifically, the July 2025 Commission guidelines set an indicative threshold: a downstream modifier becomes the provider of a modified GPAI model when the modification uses more than one third of the original model's training compute, with the practical fallback comparator of one third of 1023 FLOPs where the original compute is unknown.1321 Skadden's reading, which matches ours: ordinary enterprise fine-tuning "will rarely meet this threshold."22 The realistic trap is branding, not compute. A white-labeled customer-facing assistant marketed under your name is the fact pattern that converts a deployer into a provider.
GDPR does not move over
The AI Act layers on top of GDPR; it does not replace it. Two interactions matter for deployers. The EDPB's Opinion 28/2024 (December 2024) holds that AI models trained on personal data are not automatically anonymous, that legitimate interest can be a lawful basis for AI development and deployment under the standard three-step test, and that companies deploying a model trained on unlawfully processed data should conduct due diligence on the model's provenance.25 That last point quietly adds a GDPR reason to demand training-data documentation from vendors, on top of the AI Act reason. Second, the AI Act expressly links the two regimes: providers' transparency information feeds deployers' GDPR data-protection impact assessments (Article 26(9)), and an EDPB expert report from April 2025 provides a working risk framework for LLM deployments.226 A GPAI compliance review that ignores the GDPR file will double-spend; the vendor evidence overlaps heavily.
Sector overlays
Financial services firms should assume supervisors will examine AI through existing prudential and conduct law first. The EBA's November 2025 fact sheet mapped the AI Act against EU banking and payments legislation and found "no significant contradictions," describing the frameworks as complementary, with common supervisory approaches planned for 2026 and 2027.27 EIOPA's August 2025 opinion on AI governance deliberately covers AI systems that are not high-risk under the Act, which means insurers face supervisory expectations on data governance, explainability, and oversight even where the AI Act itself asks little.28 ESMA said as early as 2024 that firms using AI in investment services must meet MiFID II duties regardless of the AI Act.29 In healthcare, MDCG 2025-6 addresses the interplay between the medical device regulations and the AI Act; AI-based medical devices follow the embedded high-risk route, now deferred to August 2028 by the Omnibus.305 Our view: in regulated sectors, the binding constraint through 2027 is the sector supervisor, not the AI Office.
Impact on US-based companies
The Act does not stop at EU borders. Article 2(1) reaches US providers that place models on the EU market, EU establishments of US groups, and, most broadly, any provider or deployer anywhere "where the output produced by the AI system is used in the Union."
Article 2(1) sets three hooks. Point (a): providers placing AI systems or GPAI models on the market in the Union, "irrespective of whether those providers are established or located within the Union or in a third country." Point (b): deployers with their place of establishment or location in the Union. Point (c): providers and deployers located in a third country "where the output produced by the AI system is used in the Union."2 The first two are conventional market-regulation territoriality. The third is not, and it is the one US general counsels underweight.
How broad is the output hook? This is unsettled, and we will not pretend otherwise. Recital 22 frames the provision around output "intended to be used" in the Union, an anti-circumvention rationale. The operative article contains no intent element. White & Case flags exactly this discrepancy and concludes the scope is "at best uncertain, and at worst aggressively expansive": on a literal reading, a non-EU company can be in scope when its AI output ends up used in the EU without its knowledge.31 William Fry reads it as output-based jurisdiction turning on the fact of use.32 Ogletree Deakins, writing for US employers, adopts the narrower intent-qualified reading.33 We found no Commission guidance resolving the question as of this report's date. Our planning advice: assume the fact-of-use reading for anything customer-facing, and reserve the intent argument as a defense, not a scoping principle.
Three concrete US scenarios
Scenario one: a US enterprise calls a US model provider's API from US offices and serves EU customers. The GPAI model obligations are the provider's problem, and the provider is in scope under point (a) if the model is on the EU market. The enterprise's own exposure runs through point (c): if system output is used in the Union, deployer-facing duties such as Article 50(4) disclosure attach, and if the AI feeds decisions about EU persons (screening EU job applicants, scoring EU customers), the analysis extends to whether the use case is high-risk once the deferred regime lands in December 2027. Employment-law analysis already treats US-based hiring tools used for EU candidates as in scope.33
Scenario two: a US group with EU subsidiaries whose employees use AI tools procured in the US. The subsidiary is a deployer under point (b), full stop; its place of establishment settles the question and no output analysis is needed.2 Procurement location is irrelevant. The practical consequence is that a central US procurement function is making EU regulatory commitments it may never have reviewed, which is a governance gap, not a legal ambiguity.
Scenario three: the US enterprise is itself a model provider whose model is available to EU users. Point (a) applies regardless of headquarters. Article 54 then requires appointing an EU authorised representative before placing the model on the market, holding Annex XI documentation for ten years.2 The Commission's scope guidelines add a subtle extension: a model released outside the EU and later incorporated into a system marketed in the EU can trigger the obligations.1221 If your model is open-weights, the Article 53(2) exemption relieves the two documentation duties but not the copyright policy or training-content summary, and none of it if the model crosses the systemic-risk line.
How US model providers have responded
Table 2 summarizes the public record. The pattern worth noting: signature behavior split in 2025, then converged in 2026. Meta refused the GPAI Code with Joel Kaplan's statement that "Europe is heading down the wrong path on AI,"10 yet signed the separate transparency code in July 2026.40 Google signed the GPAI Code while publicly stating concerns about copyright departures and trade-secret exposure.11 Every named provider has now made EU-specific compliance commitments of some form.
| Provider | GPAI Code of Practice (Jul 2025) | Transparency code, Art. 50 (2026) | Training-content summary (Art. 53(1)(d)) | Notable for procurement |
|---|---|---|---|---|
| OpenAI | Signed, full349 | Endorsed / signatory36 | Published for current models on its EU AI Act customer-guidance page35 | Dedicated EU AI Act resource page; C2PA plus watermarking on image output3536 |
| Anthropic | Signed, full379 | Signatory46 | No Commission-template summary confirmed; secondary reports conflict44 | Shipped global text watermarking (SynthID-Text) plus C2PA on images, August 202638 |
| Signed, with publicly stated concerns11 | Signatory39 | Reported filed for Gemini on the Commission template; we could not locate a Google-hosted copy44 | SynthID deployed across modalities; licensed to others3938 | |
| Meta | Refused10 | Signed, Section 140 | Reported filed for its current flagship; we could not locate a Meta-hosted copy44 | Llama 4 multimodal license excludes EU-based users; must show GPAI compliance via "alternative adequate means"41429 |
| Microsoft | Signed, full9 | Signatory46 | Published for Phi-4; graded poorly in an academic quality review44 | Trust Center hosts a dedicated EU AI Act compliance section43 |
| xAI | Safety and Security chapter only9 | Not confirmed | None found44 | Subject of formal EU proceedings over Grok under the DSA, not the AI Act4950 |
Table 2. US provider posture toward GPAI obligations, public record as of August 17, 2026.
What this means for a procurement or legal team reviewing a vendor contract: the compliance artifacts you should ask for now exist, unevenly. From full signatories, request the Model Documentation Form or equivalent Annex XII downstream documentation, the published training-content summary, the copyright policy, and the provider's Article 50 marking approach. From Meta, xAI, or any non-signatory, the same substance is still legally owed under the Act itself; the Code is voluntary but Articles 53 and 55 are not.822 Expect to rely more on contractual representations and less on standardized artifacts, and price that diligence burden into vendor selection. Our view: signature status is a weak proxy for model quality but a useful proxy for how much compliance evidence a vendor will hand you without a fight.
What is changing about the models themselves
GPAI obligations are starting to show up in the products: published training-content summaries, copyright policies, watermarked output, and, in a few cases, models withheld from the EU market.
Training-data disclosure has begun, unevenly
The Article 53(1)(d) training-content summary is the first mechanism forcing frontier labs to say publicly, in a standard format, what they trained on: data sources by category, use of scraped web data, use of user data, and measures for opt-out compliance.14 Implementation quality varies widely. An academic review presented at FAccT 2026 assessed early template filings and graded some poorly on transparency and usefulness, Microsoft's Phi-4 summary worst among those evaluated.44 OpenAI now hosts summaries for its current model line on a dedicated EU page.35 There is no central Commission registry of filed summaries; each provider publishes on its own site, which means your vendor-diligence process has to go find them.14 Copyright policies follow a similar pattern: required of all providers, shaped in practice by the Code's Copyright chapter, and a live source of friction, since Google's stated concerns when signing centered on exactly this chapter.11
Synthetic-content marking is now a shipped feature
Article 50(2) requires providers of generative systems to mark output "in a machine-readable format and detectable as artificially generated," effective August 2, 2026, with the Omnibus grace period to December 2, 2026 for systems already on the market.25 The supporting Code of Practice on Transparency of AI-Generated Content, finalized in mid-2026, recommends at least two machine-readable techniques, such as signed metadata plus an imperceptible watermark, with a free public detection mechanism and an interoperability deadline of February 2027; it drew roughly 190 signatories by end of July 2026.454648 What has actually shipped: Google's SynthID across image, video, and text; C2PA Content Credentials in OpenAI image output with expansion planned toward audio and text; Meta's "AI info" labeling continuing from its 2024 rollout; and, most notably, Anthropic applying SynthID-based text watermarking to Claude output globally as of August 2026, licensed from Google DeepMind, with C2PA on images.36383940 Anthropic's own caveat is worth repeating to your teams: the mark indicates content may have been processed by the model; absence of a mark proves nothing.38
Availability: a real but narrow effect
Attribute model-availability decisions carefully, because several famous EU delays were driven by GDPR or the DMA, not the AI Act. The clearest AI-Act-adjacent case is Meta: it announced in July 2024 it would withhold future multimodal models from the EU, and the Llama 4 license excludes EU-based users from the multimodal models.4142 Reports in July 2026 that xAI geoblocked its newest Grok release in the EU cite the Act's systemic-risk obligations, but the sourcing is weak and we treat that attribution as unconfirmed.54 Meta AI's delayed, initially text-only European launch was a GDPR story.10 Our view: for enterprise procurement the material risk is not mass EU withdrawal, which has not happened, but license-level carve-outs of the Llama 4 type that quietly remove specific capabilities from your EU entities while the vendor relationship continues.
Systemic risk and release strategy
The 1025 FLOPs presumption sits at roughly the training scale of current frontier models, and the Commission notes a training run at that scale currently costs tens of millions of euros.15 The observable effects on release strategy so far are procedural rather than dramatic: frontier providers signed the Safety and Security chapter and now maintain EU-facing safety frameworks, adversarial-testing documentation, and incident-reporting readiness against the November 2025 template.916 Because the Article 52(6) list of designated models is not public, statements about which specific models are formally in the systemic-risk tier are inference, not record, and we flag them as such.15 The two-week notification duty means classification now runs ahead of launch: a provider crossing the compute threshold engages the AI Office before the product ships, which pulls EU regulatory review into frontier release timelines even without any public designation.
Compliance cost and governance, by who owns it
Split the work three ways. The CFO owns exposure and budget. The CAIO owns model risk and vendor assessment. The CIO owns the operational machinery that keeps compliance current instead of a one-time file.
For the CFO: exposure and cost
Get the penalty numbers right, because the wrong ones circulate constantly. The figure that applies to GPAI providers is Article 101: Commission-imposed fines up to 3 percent of total worldwide annual turnover or EUR 15 million, whichever is higher, for infringing the GPAI provisions, ignoring information requests, or refusing model access for evaluation. That power activated August 2, 2026, and only the Commission wields it; deployers are not exposed under Article 101 at all.220 Deployer exposure runs through Article 99 and national authorities: up to EUR 35 million or 7 percent for prohibited practices, up to EUR 15 million or 3 percent for the listed operator violations including the Article 50 transparency duties, and up to EUR 7.5 million or 1 percent for supplying false information.2 The 35 million and 7 percent figure quoted in most board decks is the prohibited-practices cap. It is not the GPAI number, and citing it as such overstates a deployer's realistic exposure by more than double. One tempering fact: national enforcement launches into a patchwork, with trackers showing only around nine member states having fully designated their authorities by mid-2026.537
On cost, published data is thin and honesty requires saying so. The Commission's impact-assessment support study estimated compliance at roughly EUR 29,277 per year per high-risk AI product including overheads, and EUR 193,000 to 330,000 upfront plus about EUR 71,400 a year for a new quality-management system; CEPS later showed the widely quoted EUR 400,000-per-system figure was a misreading of these numbers.5152 Those are provider-side, high-risk-system estimates from 2021. We found no credible published figures for what GPAI-era compliance costs an enterprise deployer, and we will not invent them. What we can offer, clearly labeled as ROAI planning estimates rather than benchmarks: for a 1,000-plus employee deployer, the cost concentrates in vendor contract review and re-papering (typically a few days of counsel time per material AI vendor), building and maintaining the AI inventory and governance artifacts described below (a part-time role, not a department, in year one), and implementing Article 50 disclosure in customer-facing products (an engineering task whose size depends entirely on how many products generate content). An EU authorised representative and the heavy Article 55 machinery are provider costs; if a budget request includes them and you do not ship models, ask why.
For the CAIO: vendor assessment and governance artifacts
The GPAI regime gives a model risk function new, concrete questions with checkable answers. Add these to the vendor and model assessment: whether the provider signed the GPAI Code of Practice, and which chapters; whether a training-content summary on the Commission template is published, and its quality; whether a copyright policy is published and what it says about TDM opt-outs; what Annex XII downstream documentation the vendor supplies under NDA; how output is marked under Article 50(2) and whether a detection mechanism is available; whether the model sits in the systemic-risk tier by the provider's own account, and what evaluation and incident-reporting commitments follow; whether an EU authorised representative is appointed, for non-EU providers; and what contractual notice you get on model deprecations, migrations, and license changes affecting EU entities.8914 These questions are cheap to ask and expensive for a noncompliant vendor to dodge, which is the point.
Model-selection criteria should change in one specific way: documentation availability is now a scored criterion, not a tiebreaker. A model whose provider publishes template-conformant summaries, downstream documentation, and marking specifications is auditable; an otherwise equivalent model without them transfers diligence cost and regulatory ambiguity to you. On governance artifacts, the regulation itself mandates little for deployers of non-high-risk tools, so what follows is our recommendation shaped by what supervisors and auditors ask for in practice: a maintained AI system inventory with each system's role classification (deployer versus provider, high-risk versus not, EU exposure versus not); a model risk register recording each model's provider, version, GPAI documentation received, and marking status; documented human-oversight arrangements for consequential uses; and a disclosure register showing where Article 50 duties arise in your products and how they are met. GDPR accountability files and EDPB expectations already point the same direction, so build one evidence base, not two.2526
For the CIO: the operational machinery
The recurring work is verification and change management, not paperwork. Demand from each AI vendor, and file centrally: the training-content summary, the downstream documentation pack, the copyright policy, the Article 50 marking specification, and the vendor's EU AI Act compliance page or attestation. Then verify rather than file-and-forget: test that marking is actually present in output your systems emit (providers are shipping detection portals and APIs for this),3638 confirm chatbot self-identification renders in your deployed configuration, and check that license terms still cover your EU entities after each model upgrade, since capability carve-outs arrive silently through license changes.42 Build three ongoing processes. First, a vendor-documentation refresh on a fixed cycle, because model versions turn over faster than annual reviews. Second, a model-change gate: any provider migration, deprecation, or new model adoption passes through a check of GPAI documentation and marking status before production. Third, an incident path that connects your internal AI incident handling to each provider's reporting commitments, so a serious incident involving a systemic-risk model reaches the provider who carries the Article 55 reporting duty.16 None of this requires new platforms to start; it requires ownership, a repository, and a calendar. The Commission's enforcement posture of dialogue-first will not last forever, and the enterprises that can produce their file on request will not be the test cases.1719
One-page action summary before your next board or vendor review
Scope, this week
- Confirm your role per AI use case: deployer or provider. Flag anything white-labeled under your brand or fine-tuned at unusual scale for legal review of Article 25 and the one-third-compute rule.
- Map EU exposure three ways: EU establishments deploying AI, EU customers receiving AI output, and any model you place on the EU market yourself.
- Correct the penalty figures in any internal deck: GPAI providers face 3 percent or EUR 15 million (Article 101, Commission-enforced); deployer transparency violations face up to 3 percent or EUR 15 million under Article 99 via national authorities; 7 percent or EUR 35 million is the prohibited-practices cap, not the GPAI number.
Vendor file, this month
- Collect per material AI vendor: Code of Practice signature status, training-content summary, copyright policy, Annex XII downstream documentation, Article 50 marking specification, EU authorised representative details where applicable.
- Where artifacts are missing, especially from non-signatories, obtain contractual representations covering the same substance, and record the gap in the model risk register.
- Check current license terms for EU carve-outs, and re-check at every model upgrade.
Product and process, this quarter
- Inventory where Article 50 duties arise in your products: chatbots, generated media, published AI-generated text on matters of public interest. Verify disclosure and marking render in production. Systems on the market before August 2, 2026 have until December 2, 2026 for machine-readable marking.
- Stand up the four governance artifacts: AI system inventory, model risk register, documented human oversight for consequential uses, disclosure register.
- Set the recurring machinery: vendor-documentation refresh cycle, model-change gate, incident path to provider reporting duties.
- Note the deferred but real deadline: high-risk obligations under Annex III arrive December 2, 2027. Anything in hiring, credit, or essential services should be classified now, not then.
References
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- AI Act Explorer, article-level text reproduction of Regulation (EU) 2024/1689, Future of Life Institute. Cited for Articles 2, 3, 25, 26, 50 to 56, 99, 101, 111, 113. https://artificialintelligenceact.eu/the-act/
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex. https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- White & Case, "EU AI Omnibus enters force, amending the AI Act," July 2026. https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act
- Cooley, "Digital AI Omnibus delays key deadlines, introduces new rules," 2026. https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
- Gibson Dunn, "EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes," May 27, 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- Future of Privacy Forum, "The AI Act implementation timeline: what changes under the AI Omnibus," July 28, 2026. https://fpf.org/blog/the-ai-act-implementation-timeline-what-changes-under-the-ai-omnibus/
- European Commission, "The General-Purpose AI Code of Practice." https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
- European Commission, GPAI Code of Practice signatories page. https://digital-strategy.ec.europa.eu/en/policies/gpai-code-practice
- TechCrunch, "Meta refuses to sign EU's AI Code of Practice," July 18, 2025. https://techcrunch.com/2025/07/18/meta-refuses-to-sign-eus-ai-code-of-practice
- Google (Kent Walker), "We will sign the EU AI Code of Practice," July 30, 2025. https://blog.google/around-the-globe/google-europe/eu-ai-code-practice/
- European Commission, "Guidelines on the scope of obligations for providers of general-purpose AI models," July 18, 2025. https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act
- European Commission, FAQ on the guidelines for GPAI providers. https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers
- European Commission, "Explanatory notice and template: public summary of training content for general-purpose AI models," July 24, 2025. https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
- European Commission, "General-purpose AI models in the AI Act: questions and answers." https://digital-strategy.ec.europa.eu/en/faqs/general-purpose-ai-models-ai-act-questions-answers
- European Commission, reporting template for serious incidents involving general-purpose AI, November 4, 2025. https://digital-strategy.ec.europa.eu/en/library/ai-act-commission-publishes-reporting-template-serious-incidents-involving-general-purpose-ai
- Wilson Sonsini, "EU AI Act enforcement phase begins," August 3, 2026. https://www.wsgr.com/en/insights/eu-ai-act-enforcement-phase-begins.html
- Help Net Security, "EU AI Act enforcement: AI models," August 4, 2026. https://www.helpnetsecurity.com/2026/08/04/eu-ai-act-enforcement-ai-models/
- European Commission, "Enforcement of the AI Act." https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
- AI Act Explorer analysis, "Enforcement of Chapter V under the EU AI Act." https://artificialintelligenceact.eu/enforcement-of-chapter-v-under-the-eu-ai-act/
- WilmerHale, "European Commission issues guidelines for providers of general-purpose AI models," July 24, 2025. https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20250724-european-commission-issues-guidelines-for-providers-of-general-purpose-ai-models
- Skadden, "The EU's general-purpose AI obligations," August 2025. https://www.skadden.com/insights/publications/2025/08/eus-general-purpose-ai-obligations
- Freshfields, "EU AI Act unpacked #22: key considerations for employers, deployers vs providers," February 26, 2025. https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-22-key-considerations-for-employers-as-deployers-vs-provide-102k1kz
- A&O Shearman, "Zooming in on AI #4: interplay between deployers and providers in the EU AI Act." https://www.aoshearman.com/en/insights/ao-shearman-on-tech/zooming-in-on-ai-4-what-is-the-interplay-between-deployers-and-providers-in-the-eu-ai-act
- EDPB, Opinion 28/2024 on certain data protection aspects of AI models, December 17, 2024. https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf
- EDPB Support Pool of Experts, "AI privacy risks and mitigations: large language models," April 2025. https://www.edpb.europa.eu/system/files/2025-04/ai-privacy-risks-and-mitigations-in-llms.pdf
- EBA, "AI Act: implications for the EU banking and payments sector," November 21, 2025. https://www.eba.europa.eu/sites/default/files/2025-11/d8b999ce-a1d9-4964-9606-971bbc2aaf89/AI Act implications for the EU banking sector.pdf
- EIOPA, "Opinion on artificial intelligence governance and risk management," August 6, 2025. https://www.eiopa.europa.eu/publications/opinion-artificial-intelligence-governance-and-risk-management_en
- ESMA, guidance on firms using AI in investment services, May 30, 2024. https://www.esma.europa.eu/press-news/esma-news/esma-provides-guidance-firms-using-artificial-intelligence-investment-services
- MDCG 2025-6, FAQ on the interplay between the MDR/IVDR and the AI Act, June 19, 2025. https://health.ec.europa.eu/latest-updates/mdcg-2025-6-faq-interplay-between-medical-devices-regulation-vitro-diagnostic-medical-devices-2025-06-19_en
- White & Case, "The EU AI Act's extraterritorial scope, Part 2," May 2024. https://www.whitecase.com/insight-our-thinking/eu-ai-acts-extraterritorial-scope-part-2
- William Fry, "A practical guide to the extraterritorial reach of the AI Act," July 2024. https://www.williamfry.com/knowledge/a-practical-guide-to-the-extraterritorial-reach-of-the-ai-act/
- Ogletree Deakins, "The EU AI Act is here: what it means for U.S. employers," October 31, 2025. https://ogletree.com/insights-resources/blog-posts/cybersecurity-awareness-month-in-focus-part-iii-the-eu-ai-act-is-here-what-it-means-for-u-s-employers/
- OpenAI, "The EU Code of Practice and the future of AI in Europe," July 11, 2025. https://openai.com/global-affairs/eu-code-of-practice/
- OpenAI Help Center, "EU AI Act: OpenAI resources and customer guidance." https://help.openai.com/en/articles/12141645-eu-ai-act-openai-resources-and-customer-guidance
- OpenAI, "Advancing responsible AI across Europe," July 31, 2026. https://openai.com/index/advancing-responsible-ai-across-europe/
- Anthropic, "Anthropic to sign the EU Code of Practice," July 21, 2025. https://www.anthropic.com/news/eu-code-practice
- Anthropic, "How Claude's text watermarking works," August 2026. https://www.anthropic.com/news/claude-text-watermark
- Google (Karen Massin), on signing the EU transparency code of practice, July 24, 2026. https://blog.google/company-news/outreach-and-initiatives/public-policy/eu-ai-act-transparency-code-of-practice/
- Meta Newsroom, "Meta is signing the EU AI Act Code of Practice on Transparency of AI-Generated Content," July 28, 2026. https://about.fb.com/news/2026/07/meta-is-signing-the-eu-ai-act-code-of-practice-on-transparency-of-ai-generated-content/
- Axios, "Meta won't offer future multimodal AI models in EU," July 17, 2024. https://www.axios.com/2024/07/17/meta-future-multimodal-ai-models-eu
- The Decoder, "Meta releases first multimodal Llama 4 models, leaves EU out in the cold," April 2025. https://the-decoder.com/meta-releases-first-multimodal-llama-4-models-leaves-eu-out-in-the-cold/
- Microsoft Trust Center, "EU AI Act compliance." https://www.microsoft.com/en-us/trust-center/compliance/eu-ai-act
- Blankvoort, Pandit, Gahntz et al., "GPAI training transparency" (FAccT 2026 research), AI Accountability Lab. https://aial.ie/research/gpai-training-transparency/
- European Commission, "Code of Practice on Transparency of AI-Generated Content." https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- European Commission, "Strong backing for the Code of Practice on Transparency of AI-Generated Content," July 31, 2026. https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content
- European Commission, "Guidelines on transparency obligations for providers and deployers of AI systems," 2026. https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
- Paul, Weiss, "EU finalises transparency rules for AI-generated content," August 4, 2026. https://www.paulweiss.com/insights/client-memos/eu-finalises-transparency-rules-for-ai-generated-content
- European Commission press release IP/26/203, formal DSA proceedings concerning X and Grok, January 2026. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_203
- TechPolicy.Press, "Regulators are going after Grok and X, just not together," January 26, 2026. https://www.techpolicy.press/regulators-are-going-after-grok-and-x-just-not-together/
- Study to support an impact assessment of the AI Act (European Commission, 2021), cost annexes. https://artificialintelligenceact.eu/wp-content/uploads/2022/06/AIA-COM-Impact-Assessment-3-21-April.pdf
- CEPS, "Clarifying the costs for the EU's AI Act," September 24, 2021. https://www.ceps.eu/clarifying-the-costs-for-the-eus-ai-act/
- AI Act Explorer, national implementation plans tracker, updated June 17, 2026. https://artificialintelligenceact.eu/national-implementation-plans/
- Cybernews, "How to access Grok 4.5 in the EU," July 2026. Cited with reservation; weak sourcing on the geoblock attribution. https://cybernews.com/geo-restrictions/how-to-access-grok-4-5-in-the-eu/
Method note. Statements of what the regulation requires cite the legal text. Statements of what guidance recommends cite the issuing body. Passages marked "our view" or "our recommendation" are ROAI analysis. Facts were verified against the sources listed above on August 17, 2026; enforcement practice is new and will change. This report is research, not legal advice.
What’s inside
- What the GPAI provisions actually say
- Impact on EU-based companies
- Impact on US-based companies
- What is changing about the models themselves
- Compliance cost and governance, by who owns it
- One-page action summary before your next board or vendor review
Who this is for
Get the full paper
Free: sign in to download.
Sign inAuthor
Satori Canton
Founder & Principal
Satori Canton is the founder and principal of ROAI, an advisory practice focused on measuring and improving the return on enterprise AI investment.
Want the numbers behind your own AI investment?
Book a focused session to see where AI creates real economic value in your organization.