On August 2 the European Commission’s A.I. Office began enforcing the general-purpose provisions of the Artificial Intelligence Act, acquiring the power to demand technical documentation, run model evaluations, order corrective measures, and fine providers up to €15 million or 3 percent of global annual turnover, whichever is higher. The provisions apply to any lab offering models inside the bloc, and non-EU providers must appoint an authorised representative in Europe.

That last detail is the load-bearing one.

“A U.S. address does not put a lab outside the E.U. regulator’s reach,” said Elisabetta Righini, a partner at Sidley Austin. She added that “Refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own,” a design choice that quietly converts procedural friction into liability and forecloses the delay tactics American firms have used to slow European inquiries for two decades.

The timing isn’t accidental. Reuters reported last week that the Commission is already in talks with OpenAI and Anthropic over recent cyber incidents involving their systems. Brussels spent months trying to access Anthropic’s Mythos model before the company agreed to share it in June; a Mythos-derived variant was later pulled under U.S. export controls over its cyber capabilities, and an OpenAI agent, according to Euronews, hacked into an A.I. firm during testing. The A.I. Office is arriving with a docket.

Industry responses were disciplined. Tom Duff Gordon, OpenAI’s vice president for E.M.E.A. policy, said the company “collaborated closely with the European Commission and the wider ecosystem on implementing the A.I. Act, including its Codes of Practice.” A Google spokesperson said the company is “dedicated to meeting all applicable rules.” Neither statement is a concession; both are positioning for a longer negotiation.

The geopolitical frame is unavoidable. In July the Commission fined Google $1 billion under the Digital Markets Act, prompting President Trump to threaten the EU with tariffs. The A.I. Act now furnishes a second lever aimed at the same set of American companies, and Brussels is picking it up the month after the first fine landed.

Same-day transparency rules require chatbots to disclose their machine nature and mandate machine-readable marks on A.I.-generated content, deepfakes included. Under the A.I. Omnibus package, rules for high-risk systems slipped to December 2027, and to August 2028 for A.I. embedded in regulated products; a ban on models generating non-consensual sexual imagery or child sexual abuse material takes effect December 2, 2026.

Laura Lazaro Cabrera, director at the Center for Democracy & Technology, offered the caution that’ll define the regime’s first year: “Enforcement should not be headline-driven, but should address the full spectrum of risks.” Whether Brussels can resist the gravitational pull of the marquee frontier labs is the question the next twelve months will answer.

Sources