The Commission's enforcement powers over general-purpose AI models are now live
Providers have had obligations since August 2025, but the AI Office could not enforce them until 2 August this year. The compliance industry that formed in the gap is about to find out how much of it was necessary.
The European Commission's supervision and enforcement powers over providers of general-purpose AI models came into force on 2 August. Providers have carried obligations under the AI Act since August 2025; for the intervening year, no one could act on them.
That gap is now closed, and the AI Office is monitoring compliance — including, for providers that have signed up to an approved code of practice, monitoring adherence to that code rather than auditing the underlying obligations directly.
New transparency rules took effect the same day, requiring certain AI systems to tell users they are interacting with AI and to disclose when content has been generated or altered by it.
The code of practice is the actual regime
The most consequential design decision in the AI Act's GPAI chapter is the one that gets least attention. For providers who adhere to a code of practice the Commission assesses as adequate, enforcement focuses on adherence to that code.
In practice this makes the code, not the regulation, the operative rulebook — and the code was negotiated with the companies it binds. That is standard European practice and it has a real advantage: it produces obligations that are technically coherent, because the people who understand the systems helped draft them. It also produces the familiar hazard, which is that the compliance bar ends up close to what the largest providers were already doing.
The firms best placed under this structure are those whose safety documentation practice already exceeds the code. Anthropic publishes system cards and alignment research and has built customer-controlled monitoring into its enterprise product. OpenAI publishes a Preparedness Framework and rates its own models against it. Both are, in effect, pre-compliant.
Where the friction will actually be
The firms with a problem are smaller European providers and open-weight publishers, for whom documentation, copyright policy and systemic-risk evaluation are fixed costs against much smaller revenue.
Mistral, which raised €3 billion this month at a valuation above €21 billion, can absorb them. A research group publishing open weights on Hugging Face cannot, and the question of what obligations attach to a free open-weight release has been the least settled part of the regime throughout.
That question just acquired a new owner. Nvidia has agreed to buy Hugging Face for $12.9 billion, which makes the largest distributor of open-weight models in Europe a subsidiary of a US chipmaker with the resources to litigate its interpretation of the AI Act — and a commercial interest in open weights remaining cheap to publish.
The transparency rule nobody has solved
The requirement to disclose AI-generated or altered content is the provision most likely to produce visible non-compliance, because the technical means of satisfying it do not reliably exist.
Content credentials are the leading approach — Anthropic released a free browser-based tool on 2 September for verifying C2PA credentials, processing files locally. But credentials survive only as long as nothing strips them, and ordinary operations strip them constantly: screenshots, re-encoding, most social platform upload pipelines.
A provider can attach a credential at generation. It cannot ensure the credential is present when a European sees the content, and the obligation is written in terms of informing the user.
The Commission has not published enforcement priorities, and no action against a GPAI provider has yet been announced.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters