Morning Edition · №
Technology · AI Policy BRUSSELS

Brussels' AI Rulebook Gets Its Enforcement Teeth

Two weeks after the EU AI Office won the power to audit, fine and pull general-purpose AI models from the market, an uneven compliance record among top labs is already testing how hard the new regime will bite.

Brussels' AI Rulebook Gets Its Enforcement Teeth
The European Parliament in Brussels, where the EU's AI Office now has enforcement power over general-purpose AI models. — Photograph: paws_and_prints / Unsplash
SHARE X f in ⧉

The European Commission's AI Office switched on the enforcement machinery behind the EU's landmark AI law on August 2, gaining the power to audit general-purpose AI (GPAI) models, demand corrective fixes, restrict their availability across the bloc, and fine the companies that build them. Two weeks in, the gap between which labs are prepared and which are not is already visible.

The stakes are real money. Under Article 101 of the AI Act, GPAI providers now face fines of up to €15 million or 3 percent of global annual turnover, whichever is higher, across four distinct violation categories: breaching the substantive GPAI rules, ignoring a documentation request, refusing to grant model access for evaluation, or failing to carry out an ordered corrective measure.

A one-year head start with no teeth

The obligations themselves are not new. Providers of general-purpose models have been legally required since August 2025 to publish summaries of their training content, respect copyright law, document their systems and assess systemic risk. What changed this month is that, as one Euronews analysis put it, for twelve months regulators in Brussels could not compel any of it. The Commission can now request documentation, run technical evaluations, order risk-mitigation measures and, in the extreme, pull a model from the EU market.

Compliance so far is uneven. A comparison of the training-data summaries labs have filed under the mandatory disclosure rules found that Google, Meta and Microsoft filled out the Commission's standard template in full, while Anthropic, Mistral and xAI answered in looser prose that is harder to audit against. Separately, Meta declined to sign the voluntary GPAI Code of Practice that the Commission finalized last year — a choice that leaves it fully bound by the hard-law disclosure duties but forgoes the "good faith" treatment and softer fine calculations the Commission has promised signatories.

Signed up, but watching Washington

OpenAI, by contrast, signed the Code and has framed itself as a cooperative partner in its implementation, according to comments from the company reported by Euronews.

We've collaborated closely with the European Commission on implementing the AI Act, including its Codes of Practice.

Tom Duff Gordon, OpenAI VP of EMEA Policy

Not every European lawmaker is confident the regime will hold up to political pressure from Washington. Irish MEP Michael McNamara has cautioned that the U.S. administration could treat aggressive enforcement against American labs as a trade grievance rather than a technical compliance matter — a dynamic that could complicate how forcefully the AI Office is willing to use its new powers against the biggest U.S. players.

The AI Office itself is not fully staffed for the fight it just inherited. The Commission has acknowledged the unit is competing with private-sector salaries to hire the technical staff needed to actually evaluate frontier models, even as it is asked to keep pace with a technology that changes every few months.

What happens next

The current crackdown only applies to models placed on the market after August 2, 2025. Older systems — including some still widely used in production — have until August 2, 2027 before the same rules bite. In the meantime, European consumers and businesses may see marginally slower rollouts of new frontier models as providers front-load compliance paperwork before launch rather than after, according to compliance trackers monitoring the law.

Whatever happens with individual fines, the symbolic shift is significant: the EU is now the only major jurisdiction with a standing regulator empowered to audit and restrict frontier AI models on the market, at a moment when the U.S. Congress remains gridlocked on federal AI legislation and is instead relying on a patchwork of executive orders and state laws.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
C
Claire Fontaine

Reporting and analysis from the UBStandard newsroom — politics, business, technology and culture, published daily from New York.

Related coverage Front page →