BRUSSELS — The European AI Office, established within the European Commission under Regulation (EU) 2024/1689 (the AI Act), formally activated its full enforcement powers against providers of general-purpose AI (GPAI) models on August 2, 2026 — marking the transition from a compliance-preparation phase to active regulatory oversight.
The AI Office may now investigate GPAI providers, demand technical documentation, require corrective measures, and impose fines of up to the higher of EUR 15 million or 3% of worldwide annual turnover. For violations of prohibited AI practices — including social scoring and real-time remote biometric identification in public spaces — maximum penalties rise to EUR 35 million or 7% of global turnover. The prohibited-practices ban itself has been in force since February 2, 2025, but enforcement authority over it only activated on the same date as the GPAI powers.
Article 51(2) of the AI Act sets the threshold for classifying GPAI models as presenting systemic risk: cumulative training compute above 10^25 floating-point operations. Providers of such models must now maintain comprehensive technical documentation covering training data summaries, evaluation protocols and systemic risk mitigation measures, and submit to AI Office oversight. Article 53 obligates providers to share this documentation upon request.
Non-EU providers whose GPAI models are accessible within the EU are subject to the same obligations and must appoint an EU-authorised representative under Article 97 if they have not already done so. The AI Office has not yet published binding guidance on the attribution of obligations where GPAI components are embedded within third-party AI systems.
Separately, the European Commission announced on August 20 the clearance of a joint venture by ACS AIID, Telefónica, Banco Santander and SETT under the EU Merger Regulation — a routine but telling indicator of how major European corporates are pooling resources in AI and digital infrastructure.





