On August 2, 2026, the European Commission's enforcement powers over general-purpose AI model obligations entered into application, including fines. The law changed today. Whether it becomes a documentation regime, a safety regime, or a market-access regime depends on the first cases the Commission chooses to bring.

The European Commission's AI Office now holds a power it did not have yesterday: the authority to impose fines on providers of general-purpose AI (GPAI) models. From August 2, 2026, the enforcement powers of the European Union (EU) Artificial Intelligence Act entered into application, one year after the underlying GPAI obligations became binding. The official with the real choice is the AI Office's enforcement leadership, and the choice is which first actions to bring. That decision will define whether the AI Act is a paperwork regime, a genuine safety gate, or a market-access lever, and it will set the precedent for a decade of enforcement. The stakes are concrete: for the largest providers, the difference between a documentation regime and a market-access regime is the difference between a compliance cost and a structural constraint on market access.
What changed
On August 2, 2025, obligations on GPAI providers entered into application: documentation, copyright policy, training-data summaries for general-purpose models, and the additional safety and transparency duties for models presenting systemic risk. On August 2, 2026, the Commission's enforcement powers entered into application, including the power to impose fines, per the Commission's own guidance for GPAI providers, last updated April 28, 2026. Under Article 101 the ceiling is 3 percent of total worldwide annual turnover or EUR 15 million, whichever is higher, and it applies not only to substantive breach but to failure to supply requested information, non-compliance with a requested measure, and denial of access for a model evaluation. Article 50 transparency obligations also entered into application today: disclosure when a user is interacting with an AI system, and marking of AI-generated content in a machine-readable form, with a grace period to December 2, 2026 for watermarking systems already on the market. The same regulation's other August 2, 2026 obligations did not survive intact. Under the AI digital omnibus, agreed in May 2026 and approved by the European Parliament on June 16, 2026, and finalised but awaiting Official Journal publication at the cutoff, stand-alone high-risk obligations under Annex III move to December 2, 2027, product-embedded high-risk obligations under Annex I move to August 2, 2028, and regulatory sandboxes move to August 2, 2027. GPAI obligations and the Commission's enforcement powers were not deferred. The Union delayed most of today and kept this part of it. Providers that placed GPAI models on the market before August 2, 2025 have until August 2, 2027 to bring those models into compliance. The legal machinery already exists. The institutional machinery is thinner than the powers it now carries. Systemic-risk model providers must notify the AI Office. Document submission runs through the EU SEND platform. The voluntary Code of Practice is a compliance pathway that the Commission treats as a route to compliance, not as immunity. What does not yet exist is any enforcement action, formal request, or provider dispute. The regime has gained the power to compel. It has not yet used it.
The lazy consensus is that the AI Act is now enforceable, so compliance is either settled for code signatories or reduced to a paperwork exercise. The correction: enforcement powers are in force, but the enforcement posture is untested, and the posture is what determines the regime. The Commission can bring a documentation-first case, a systemic-risk safety case, or a market-access case, and those three choices send entirely different signals to providers, investors, and third-country model developers. Before today the regime could only ask for compliance. After today it can compel it. Nobody has seen the first ask, so nobody knows what kind of regime this is. That uncertainty is the analytical fact that matters, and it is obscured by coverage that treats the legal entry into force as if it had already resolved the compliance question.
Why this matters now
The decision window is the next 90 days, and it is open because the first enforcement decision has not been made. The AI Office is working through systemic-risk notifications that predate today, and how it sequences its first visible actions will be read by every provider as a signal of intent. Code of Practice signatories are watching whether the code earns a compliance presumption or a case-by-case review, which tells the open-weight community and third-country providers whether the regime is cooperative or adversarial. The window closes once the first case or formal request locks in the posture, because regulatory credibility, once defined, is very hard to redefine. The moment that matters is not August 2, 2026. It is the moment the AI Office issues its first visible decision, and that moment has not arrived.
The institutional constraint
The AI Office cannot define the regime alone. Credible enforcement rests on three capabilities, and each is untested on day one. First, a functioning case intake through the AI Office and the EU SEND platform, with visible early activity, under the Article 91 information-request power. Second, the technical capacity to evaluate systemic-risk claims, under the Article 92 evaluation power, which means the AI Office can assess model evaluations rather than only collect documents. Third, predictable sanctioning, meaning the first fines are proportionate, published, and consistent with the Act's escalation ladder, under the Article 93 measures power, which includes market restriction and withdrawal. The office also depends on member-state market surveillance authorities to cooperate on enforcement work, and on the Commission as a whole to fund and defend contested actions in court, because a market-access posture will be challenged by third-country providers whose models circulate globally. The AI Office runs on roughly 145 staff across six teams, of whom about 34 sit in regulation and compliance and 38 in AI safety. The Commission has requested 38 additional posts for the new enforcement tasks, pending the 2027 budget procedure. An independent assessment by Pour Demain judged the office significantly under-resourced against its mandate and recommended at least 160 staff by 2030. The gap between the announced power and the executed power is, in the first instance, a headcount. Each of these is a constraint that separates the announced power from the executed power. Until the first enforcement action or formal request lands, every claim about how the regime will behave is a hypothesis, not a fact.
What the consensus misses
The consensus frames the AI Act's credibility as a matter of legal design. It is a matter of enforcement practice, and specifically of which of three postures the Commission adopts in practice. A documentation regime keeps administrative friction low and deterrent effect low, and it risks becoming a paperwork exercise that changes neither safety nor behavior. A safety regime concentrates on systemic-risk evaluation, incident reporting, and evidence that mitigations are effective, with higher technical complexity for the AI Office and higher deterrent value. A market-access regime conditions access to the EU market through fines, corrective orders, or withdrawal of access, which is the highest leverage and the posture most likely to be contested. The plausible outcome is a mix, but the mix determines the signal. The consensus also over-reads the Code of Practice: it is a compliance pathway, not immunity, and the treatment of signatories in the first enforcement cycle is the clearest early test of whether the regime is cooperative or adversarial. Amazon, Anthropic, Google, Microsoft, Mistral AI and OpenAI signed the Code of Practice. X signed only the safety chapter. Meta did not sign. The Commission's guidance promises signatories increased trust and lighter monitoring, which means the treatment of the largest non-signatory is not a hypothetical first case. It is the obvious one. What the consensus misses is that the law's credibility is now a set of first cases waiting to happen, not a settled architecture.
Resolvable outcomes
These are Juncture's assessment of the enforcement posture, not a fact about any pending case. The three outcomes below are mutually exclusive and jointly exhaustive: exactly one will be true on the resolution date of October 31, 2026, which is 90 days after the entry into application and matches the brief's stated decision window. Probabilities sum to 100 percent. Each outcome is resolved by an observable first-case signal on the public record, and the observation rule is stated for each.
| Outcome by 2026-10-31 | Definition | How observed | Probability |
|---|---|---|---|
| Paperwork Primacy | The first published enforcement action or formal request from the Commission concerns documentation obligations – training-data summaries, copyright policies, technical filings – under the Article 91 information-request power, and no Article 92 evaluation or Article 93 measure is opened in the same period. | A published Article 91 information request, a Commission announcement on documentation submissions through the EU SEND platform, or a statement treating signatories as presumptively compliant, with no systemic-risk evaluation and no fine announced. | 40% |
| Safety Gate | The first published enforcement action or formal request centers on systemic-risk models – an Article 92 evaluation, incident reporting, or evidence that risk mitigations are effective – rather than on documentation or on sanctioning. | A published Article 92 evaluation decision, an AI Office announcement of an evaluation or incident-report follow-up on a systemic-risk model, or published mitigation-effectiveness findings, before any Article 93 measure. | 35% |
| Market-Access Lever | The first published enforcement action is an Article 93 measure – a fine, a corrective order, or a market-access restriction or withdrawal – against a named provider, inviting a legal contest. | A published Article 93 decision naming a provider, a Commission announcement of a sanctioning procedure, or a publicly reported challenge by the affected provider in EU courts. | 25% |
Paperwork Primacy, 40 percent. The omnibus that deferred most of the other day-one obligations reveals an enforcement-averse Commission under competitiveness pressure, and the AI Office's least risky first move is an information request against the least controversial obligation.
Safety Gate, 35 percent. The AI Office's systemic-risk notifications predate day one and its Article 92 evaluation capacity is the capability it most needs to prove, which makes an evaluation-led first action a plausible way to demonstrate intent.
Market-Access Lever, 25 percent. The largest non-signatory of the Code of Practice is a sitting first case, but an Article 93 contest is the most expensive posture for an office that is under-resourced, which is why it is the least probable of the three.
Resolution rule for ambiguity. Where the first published action combines elements, the outcome resolves to the strictest element present: any Article 93 measure resolves to Market-Access Lever; an Article 92 evaluation without an Article 93 measure resolves to Safety Gate; documentation-only activity resolves to Paperwork Primacy. If no enforcement action or formal request is published by October 31, 2026, the forecast resolves to Paperwork Primacy, because inaction is itself the documentation-regime signal and no case exists at cutoff.
Forecast record
| Field | Entry |
|---|---|
| Forecast timestamp | 2026-08-02 |
| Forecast horizon | 2026-10-31 |
| Resolution date | 2026-10-31, assessed within five working days of that date |
| Resolution authority | Juncture Policy editorial desk, on the public record only: European Commission press releases and the AI Office's published decisions, formal requests, and evaluations on the Commission's digital-strategy pages and the EU SEND platform, and reports in the trade press. |
| Outcome definitions | Paperwork Primacy: first published action is documentation-only under Article 91. Safety Gate: first published action is a systemic-risk evaluation or incident follow-up under Article 92. Market-Access Lever: first published action is a fine, corrective order, or market restriction under Article 93 against a named provider. |
| Probability revision conditions | See the list below. |
| Update history | v1 2026-08-02, initial forecast. |
Probability revision conditions.
- A published Article 91 information request on documentation, with no evaluation or fine in the same announcement, revises toward Paperwork Primacy.
- Publication of an Article 92 evaluation, an incident-report finding, or a mitigation-effectiveness decision revises toward Safety Gate.
- Publication of an Article 93 measure against a named provider, or a sanctioning announcement, revises toward Market-Access Lever.
- Treatment of Code of Practice signatories in the first cycle: a compliance presumption revises toward Paperwork Primacy; case-by-case review revises toward Safety Gate; an action against the largest non-signatory revises toward Market-Access Lever.
- The 2027 budget procedure: funding the 38 requested posts strengthens evaluation capacity and revises toward Safety Gate; refusal revises toward Paperwork Primacy.
- A member-state market surveillance authority referral to the Commission, or a high-profile incident involving a systemic-risk model, revises toward Safety Gate or Market-Access Lever.
What to watch
- The first enforcement action or formal request from the Commission, the single most important evidence item. Trigger: no published case exists as of August 2, 2026; any announcement in the next 90 days.
- How the AI Office handles existing systemic-risk notifications, visible through any published decisions or evaluations.
- Whether Code of Practice signatories receive a compliance presumption or a case-by-case review in the first enforcement cycle.
- Whether early activity clusters on documentation, on systemic-risk evaluation, or on market access, which tells providers which regime is forming.
Bottom line
For the AI Office official deciding the first actions, the point is that the regime's meaning is now in their hands and nobody else's. The AI Act's enforcement powers are real as of today, but the law does not decide what kind of regulator the Commission becomes. The first case does. Run the first actions to demonstrate the capability the office claims to have, publish the reasoning, and let the signal be the message. A documentation-first regime is a choice, not an accident, and it should be chosen knowingly, because the AI Act's credibility for the next decade is being set in the next 90 days.
Evidence and sources
Primary and institutional sources
- European Commission, Guidelines for providers of general-purpose AI models, last updated April 28, 2026: digital-strategy.ec.europa.eu. Source for: GPAI obligations entering into application August 2, 2025; enforcement powers including fines entering into application August 2, 2026; compliance deadline of August 2, 2027 for pre-August 2, 2025 models; systemic-risk notification; the EU SEND platform; the Code of Practice as a voluntary compliance pathway. Verified near-verbatim against the primary text this run.
- Regulation (EU) 2024/1689, the Artificial Intelligence Act, Official Journal of the European Union. [No article-level Official Journal URL in the ledger and none verified this run; Article 50, 91, 92, 93 and 101 content verified via artificialintelligenceact.eu and Lawfare, listed below]
- European Commission, opinion on the assessment of the Code of Practice on transparency of AI-generated content: digital-strategy.ec.europa.eu. [UNVERIFIED this run: not opened; retry before publish. Not load-bearing in this brief.]
Secondary sources
- Secondary: TechPolicy.Press, "Brussels Gains New AI Act Enforcement Powers as Autonomous AI Tests Regulators": techpolicy.press. Source for: no enforcement action or formal request as of cutoff, the AI Office's approximately 145 staff across six teams, the Code of Practice signatory list, and the Article 50 same-day transparency obligations.
- Secondary: Lawfare, "How Much Power Does the EU AI Office Actually Have?", May 18, 2026: lawfaremedia.org. Source for: the Article 101 fine ceiling, the Article 91/92/93 powers, the Code of Practice signatory list, and the Pour Demain resourcing assessment (roughly 145 staff, 38 posts requested, at least 160 staff recommended by 2030).
- Secondary: artificialintelligenceact.eu, "Enforcement of Chapter V under the EU AI Act": artificialintelligenceact.eu. Source for: Article 101 ceiling of 3 percent or EUR 15 million, whichever higher, and its application to substantive breach, information failures, non-compliance with measures, and denial of evaluation access; Article 91/92/93 powers.
- Secondary: Gibson Dunn, "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes": gibsondunn.com. Source for: the AI digital omnibus deferrals (Annex III to December 2, 2027; Annex I to August 2, 2028; sandboxes to August 2, 2027) and that GPAI obligations and enforcement powers were not deferred.
- Secondary: Pinsent Masons, "Law delaying EU high-risk AI rules finalised": pinsentmasons.com. Source for: the omnibus text finalised but awaiting Official Journal publication at cutoff.
- Secondary, consulted via search-result summaries only, not fetched in full: Morgan Lewis, "EU Approves Delays and Other Amendments to Certain EU AI Act Obligations" and Ogletree, "EU AI Act Amended: Parliament Votes to Delay Key Deadlines", both corroborating the omnibus deferrals. URLs: morganlewis.com, ogletree.com
Load-bearing claim map
| Claim in this brief | Source |
|---|---|
| GPAI obligations entered into application August 2, 2025 | Commission GPAI provider guidelines |
| Enforcement powers including fines entered into application August 2, 2026 | Commission GPAI provider guidelines |
| Guidance last updated April 28, 2026 | Commission GPAI provider guidelines (page footer) |
| Article 101 ceiling: 3 percent or EUR 15 million, whichever higher; applies to breach, information failures, non-compliance with measures, evaluation-access denial | artificialintelligenceact.eu; Lawfare |
| Article 50 transparency obligations and the December 2, 2026 watermarking grace period | Commission GPAI provider guidelines; TechPolicy.Press; Gibson Dunn; Pinsent Masons |
| AI digital omnibus: Annex III to December 2, 2027; Annex I to August 2, 2028; sandboxes to August 2, 2027; GPAI and enforcement not deferred; awaiting Official Journal publication | Gibson Dunn; Pinsent Masons; Morgan Lewis; Ogletree |
| Pre-August 2, 2025 models must comply by August 2, 2027 | Commission GPAI provider guidelines |
| Systemic-risk models must notify the AI Office; EU SEND platform for submissions | Commission GPAI provider guidelines |
| Code of Practice is a compliance pathway, not immunity | Commission GPAI provider guidelines; artificialintelligenceact.eu; Lawfare |
| Signatories: Amazon, Anthropic, Google, Microsoft, Mistral AI, OpenAI; X safety chapter only; Meta not signed | TechPolicy.Press; Lawfare |
| AI Office roughly 145 staff; about 34 in regulation and compliance, 38 in AI safety; 38 posts requested; Pour Demain recommends at least 160 by 2030 | TechPolicy.Press; Lawfare |
| No published enforcement action or formal request as of August 2, 2026 | TechPolicy.Press (negative claim, bounded) |
| Which of the three postures the Commission adopts | Juncture assessment, labeled hypothesis; probabilities are analytical judgment |
Publication cutoff: 2026-08-02. All sources last accessed 2026-08-02.