The European Commission’s A.I. Office took possession of its investigative and penalty powers over general-purpose model providers on Aug. 2, exposing OpenAI, Anthropic, Google and every foreign lab serving the bloc to fines of up to €15 million or 3 percent of worldwide annual turnover, whichever is higher. It’s the most consequential enforcement moment for the A.I. Act since the regulation was adopted two years ago, and it closes a gap that the industry had quietly been living inside.

That gap is worth naming. Wilson Sonsini, in a client advisory this week, noted that substantive obligations on GPAI providers have technically applied since Aug. 2, 2025, but the A.I. Office had no authority to enforce them until this week. Rules without a regulator produce compliance theater. Rules with a regulator produce law firms.

The reach is extraterritorial by design. “A U.S. address does not put a lab outside the EU regulator’s reach. Non-EU providers must also appoint an EU-based authorised representative as the regulator’s point of contact,” said Elisabetta Righini, a partner at Sidley Austin, who told CNBC the powers “could be used on any company offering a general purpose AI model in the EU, regardless of where they were based.”

Righini also flagged a subtler dimension. “GPAI liability isn’t limited to substantive breaches,” she said. “Refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own.” The procedural surface area, in other words, is now as large as the substantive one. How labs behave inside a supervisory conversation is itself regulated.

Brussels is signaling restraint on the front end. A Commission FAQ published alongside the enforcement kickoff describes “technical compliance dialogues” as the preferred first tool, with national competent authorities across member states assuming parallel supervisory roles. That’s the TARP-era playbook: activate the instrument, but keep the first move collaborative.

Two other clocks are ticking. Article 50 transparency rules, covering chatbot disclosure and deepfake provenance marks, also took effect Aug. 2, with a transitional period until Dec. 2, 2026 for generative systems already on the market. And models placed before Aug. 2, 2025 have until Aug. 2, 2027 to reach compliance.

The dialogues have started. Reuters reported Friday that the E.U. is already in discussions with OpenAI and Anthropic following recent cyber incidents involving their models. OpenAI confirmed it’s in contact with the A.I. Office. Anthropic didn’t immediately respond. The regulator has arrived, and it’s already asking questions.

Sources