On 2 August 2026, the European AI Office, established within the European Commission under Article 3(1)(b) of Regulation (EU) 2024/1689, became formally entitled to exercise its full enforcement powers against providers of general-purpose AI (GPAI) models marketed or deployed in the EU. The date simultaneously activated maximum penalty authority over prohibited AI practices, which have been banned since 2 February 2025 under Article 5 of the AI Act but for which enforcement remained in a preparatory phase. The shift marks the transition from compliance preparation to active regulatory oversight by the AI Office.
The operative legal text is Regulation (EU) 2024/1689, the AI Act. Chapter V (Articles 51 to 56) sets out obligations on GPAI model providers, including classification of models presenting systemic risk at cumulative training compute above 10^25 floating-point operations under Article 51(2). Article 88 confers on the AI Office jurisdiction to monitor, investigate, and enforce those obligations. Article 101 sets maximum fines for GPAI providers at the higher of EUR 15 million or 3 per cent of worldwide annual turnover; for violations of prohibited practices under Article 5, the ceiling rises to EUR 35 million or 7 per cent of turnover. Prohibited practices include real-time remote biometric identification in publicly accessible spaces under Article 5(1)(h), social scoring by public or private entities under Article 5(1)(c), and untargeted scraping of facial images from online sources under Article 5(1)(e).
GPAI model providers, including foundation model developers and operators of large language model APIs available in the EU, must now treat the AI Office as an active enforcement counterpart. The Office may demand technical documentation under Article 53, covering training data summaries, evaluation protocols, and mitigation measures for identified systemic risks. Deployers of GPAI models within high-risk AI system categories listed in Annex III face overlapping obligations monitored by national market surveillance authorities, creating the potential for coordinated multi-authority investigations. Non-EU providers whose models are accessible within the EU are subject to the same obligations under Article 2(1)(c) and must appoint an EU-authorised representative under Article 97 if they have not done so.
The AI Act provides transitional relief for GPAI models placed on the market before 2 August 2025, which benefit from a one-year grace period under Article 111(3) to bring technical documentation and testing protocols into compliance. Models below the 10^25 floating-point operations compute threshold are not currently classified as presenting systemic risk, though the Commission may revise that threshold by delegated act. Open questions remain about the attribution of obligations where GPAI components are embedded within third-party AI systems; the AI Office has not yet published binding guidance on that allocation.
Licentium advises technology developers, AI system operators, and deployers on EU AI Act compliance obligations, including GPAI documentation requirements and prohibited practice assessments, drawing on a partner network of EU regulatory counsel for market surveillance matters. Contact us to discuss your position under the AI Act. Work we undertake includes AI Act compliance mapping, prohibited practice audits, GPAI model risk assessments, and EU authorised representative mandates.
Source: European Commission Digital Strategy, The enforcement framework of the AI Act, 2 August 2026