Analysis
The European Commission's AI Office gained real fining power over frontier AI companies on August 2, 2026, as the AI Act's one-year grace period expired and enforcement formally began. For the first time, a major regulator can levy fines specifically tied to how a company trained its models and what those systems do once deployed -- not just voluntary disclosure or a negotiated framework, but statutory penalties with real teeth.
How the Penalties Stack
The fine structure is tiered by severity: prohibited practices carry penalties up to €35 million or 7% of global annual turnover, a ceiling 75% higher than GDPR's top tier of €20 million or 4%. General-purpose AI providers -- the category that captures foundation-model makers like OpenAI, Anthropic and Google directly -- face fines up to €15 million or 3% of turnover for falling short of transparency and safety obligations. Providing incorrect or misleading information to regulators carries penalties up to €7.5 million or 1%. New transparency rules activate the same day, requiring certain AI systems to tell users plainly when they're interacting with AI and when content in front of them has been generated or altered by it.
“Providing incorrect or misleading information to regulators carries penalties up to €7.5 million or 1%.”
A Different Posture Than Washington
The AI Office's enforcement toolkit is substantial: it can request technical documentation directly from labs, evaluate models itself, require corrective measures, and issue fines without waiting for a lengthy investigation to conclude. That's a materially different regulatory posture than the one playing out in Washington, where the White House convened AI companies this same week specifically because its own executive-order oversight framework missed its 60-day deadline with none of its three required deliverables made public. Brussels moved from grace period to active enforcement on schedule; the US administration's voluntary framework is still being negotiated well past its own deadline.
What It Means for US Labs
For US labs with meaningful European revenue or EU-based users, this is no longer a compliance timeline to plan around -- it's live legal exposure today. Every general-purpose AI provider operating in the EU now has a genuine, quantifiable regulatory cost tied directly to training and deployment practices, which changes the calculus on model documentation, red-teaming rigor, and disclosure practices in a way voluntary US frameworks have not yet forced.
What to Watch
What to watch: which company, if any, becomes the AI Office's first enforcement target, whether US labs adjust EU-specific model documentation practices in response, and whether the contrast between EU enforcement and the US's still-stalled voluntary framework becomes a bigger factor in where labs choose to prioritize compliance investment.