The EU AI Act Just Grew Teeth: What Actually Changed on 2 August — and Why US Labs Are Watching
For two years the EU AI Act was rules without enforcement. As of 2 August 2026 the Commission's AI Office can inspect frontier models, demand their training-data summaries, fine providers a slice of global revenue, and pull a model from a market of 450 million people. Here's what that means in plain terms.

The European Union's AI Act has existed on paper since 2024. For most of that time it was a set of rules with no teeth — obligations written down, deadlines set, but no one actually knocking on doors. That changed on 2 August 2026. The Act entered its enforcement era, and the difference between "on the books" and "enforceable" is the whole story.
Here is what actually shifted, in plain terms.
Who can now do what
The enforcer is the European Commission's AI Office, working alongside national market-surveillance authorities in each member state. As of 2 August, it can act on the rules for general-purpose AI (GPAI) models — the large foundation models made by OpenAI, Anthropic, Google, Meta, Mistral and the rest.
One clarification, because it is easy to get wrong: the obligations on these models have been on the books since August 2025. What switched on this month is the machinery to enforce them — the power to investigate, to fine, and to pull a model. The rules did not appear on 2 August 2026; the teeth did.
Concretely, the AI Office can now:
- Demand documentation about how a model was built and tested.
- Run its own technical evaluations of a model, rather than taking the provider's word.
- Require providers to publish a summary of their training data — on an official template — a long-standing sore point for labs that would rather not say what went into the model.
- Assess systemic risk for the most powerful models — those trained above roughly 10²⁵ floating-point operations, the current regulatory line for "frontier."
- Restrict or withdraw a model from the EU market.
That last power is the one that matters. For the first time, a regulator can look inside a frontier model, decide it does not meet the bar, and pull it from a market of about 450 million people. No US framework gives any agency that lever.
What it costs to get it wrong
The penalties are tiered, and they are large enough to notice:
- Up to €35 million or 7% of global annual turnover — whichever is higher — for the banned "prohibited practices" (things like social scoring or certain biometric surveillance).
- Up to €15 million or 3% of global turnover for GPAI-obligation violations.
For a company the size of a frontier lab, "3% of global turnover" is not a rounding error. It is a number that shows up in a board meeting.
The transparency rules you will actually see
Some of the newly enforceable rules are aimed squarely at ordinary users:
- Chatbots and voice agents must tell you they are AI at the start of an interaction — no more pretending to be a human agent.
- Deepfakes — AI-generated or edited images, video and audio — must be labelled.
- AI-generated content more broadly must carry machine-readable marks so platforms and tools can detect it automatically.
This is the part most likely to ripple outward. A company that has to build AI-disclosure and content-labelling for the EU rarely bothers to build a separate, unlabelled version for everyone else. The cheapest path is to apply the EU standard globally — the "Brussels effect" that turned EU cookie banners and privacy prompts into a worldwide default.
The catch that softens the blow
Enforcement does not hit every model at once. Models first released before 2 August 2025 get a compliance runway until 2 August 2027 — a managed two-year grace period. So the sharpest edge of enforcement lands on new models, the ones being released right now. A lab shipping a frontier model this month is operating fully inside the new regime; a lab maintaining a 2024 model has breathing room.
Why US labs are watching
The AI Act does something no American rulebook currently does: it pairs inspection power with a market it can close. A US lab can largely decide for itself how much to disclose about a model at home. In the EU, it now has to satisfy a regulator that can demand the documentation, run its own tests, and revoke access if the answers fall short — and can fine it a slice of global revenue for non-compliance.
For the labs, that reframes the EU from a market you sell into as a market you have to be cleared into. Whether that pushes them toward more openness or toward quietly geofencing their newest models out of Europe is the question the next year will answer. Either way, "the rules have no teeth" is no longer true.
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission
- The enforcement framework of the AI Act — European Commission
- EU begins enforcing AI Act, putting AI models under the microscope — Help Net Security
- AI Act Article 99 — Penalties (€35M/7% and €15M/3% tiers)
- AI Act Article 101 — Fines for providers of general-purpose AI models
- AI Act Article 111 — Pre-2 Aug 2025 models: compliance by 2 Aug 2027
Ask Relay — he reads every question himself and replies personally by email.
