SPXNDXDJIBTCETHOILGLD10YGOOGAAPLNVDATSLAMSFTMETASOLXRPLINKLTCDOTBNBSPXNDXDJIBTCETHOILGLD10YGOOGAAPLNVDATSLAMSFTMETASOLXRPLINKLTCDOTBNB
Home AI

Brussels Wrote AI Rules a Year Ago and Only Just Got the Power to Enforce Them

For twelve months, the European Union had binding obligations on general-purpose AI models and no legal ability to make anyone follow them. That gap closed on…

EU flags with the circle of twelve gold stars fly outside the European Commission Berlaymont building in Brussels as pedestrians walk past

For twelve months, the European Union had binding obligations on general-purpose AI models and no legal ability to make anyone follow them. That gap closed on August 2, and the companies on the other side of it are Anthropic, OpenAI and Google.

The mechanics here are stranger than the headline. Substantive obligations for providers of general-purpose AI models placed on the EU market have applied since August 2, 2025. What did not exist until last week was an enforcement arm with teeth. As the European Commission confirmed when it began enforcing the AI Act’s rules and transparency requirements, the AI Office can now request technical documentation, run its own evaluations of a model, demand corrective measures, restrict or pull a model from the EU market, and fine.

A Year of Compliance Nobody Could Test

Think about what that year actually was. Model providers wrote documentation, published training-data summaries and signed codes of practice into a regulatory vacuum. Nobody could audit the paperwork. Nobody could compel a correction. Compliance was, functionally, self-graded.

That is now a legally testable position, retroactively. Every model shipped into Europe since August 2025 carries obligations that were live the whole time, and the regulator that can finally examine them just switched on. CNBC reported that the activation puts Anthropic and OpenAI among the firms facing new scrutiny, and the exposure is not prospective. It reaches back across a year of filings made when the filer knew no one would check.

Do the Arithmetic on 3%

The penalty ceiling under Article 99 is the greater of 15 million euros or 3% of total worldwide annual turnover. The word doing the work is “worldwide,” and the second word is “turnover.”

This is not 3% of European revenue, and it is not 3% of the revenue attributable to the offending model. It attaches to the whole company’s global top line. For a provider running $10 billion a year, one violation tops out near $300 million. For Alphabet, the same percentage is an entirely different order of magnitude, and Alphabet’s AI exposure to Europe is not a rounding error it can simply switch off.

The routes to a violation are also independent rather than cumulative. Ignoring a documentation request about a model that is itself non-compliant is two exposures, not one. That structure is deliberate, and it is what makes the ceiling meaningful rather than theoretical. Article 99’s penalty provisions put transparency breaches in the same top tier as the GPAI obligations themselves.

The Grandfather Clause Is the Real Negotiation

Here is the split almost nobody is pricing. Providers whose models went to market before August 2, 2025 generally have until August 2, 2027 to comply, while anything placed after that date has been on the hook since day one. Wilson Sonsini’s read of the enforcement phase sets out the two-tier timing clearly.

That creates a two-speed market inside the same jurisdiction. A legacy model can sit in Europe for another year under lighter obligations while its successor, shipped last autumn, is fully exposed today. The incentive that produces is not subtle: it rewards keeping older architectures in the European market and slowing the cadence of what you introduce there. Regulation that inadvertently penalizes shipping your newest model into a region is regulation with a product-strategy side effect, and the strategy teams have already noticed.

Separately, the Article 50 transparency duties took effect without delay. Chatbot disclosure, machine-readable marking of AI-generated content and deepfake labeling are obligations now, not roadmap items. Those are cheap to comply with and highly visible when you do not, which makes them the most likely source of the first enforcement action. Regulators building a track record start with the violations that are easy to prove.

Two Continents Moving in Opposite Directions

The transatlantic picture is what makes this a business story rather than a compliance memo. Europe just armed a regulator. The United States spent the first half of 2026 loosening merger review and pushing in the other direction entirely, including the federal effort to preempt state AI laws for frontier developers that we covered in June.

For a model provider, that divergence is an operating cost with a shape. You either build one product that satisfies the strictest regime and carry the European overhead everywhere, or you fork behavior by jurisdiction and absorb the engineering and legal complexity of running two products that share a name. The first is expensive. The second is expensive and creates a compliance surface every time the two versions drift.

Neither option shows up as a line item investors currently model. It shows up as gross-margin pressure and slower European launch cadence, eighteen months from now, attributed to something else.

What to Watch

The first formal information request from the AI Office is the event that matters, because it converts a legal capability into a precedent. Watch which provider gets it, whether it concerns a documentation gap or a transparency breach, and how fast the company complies. A cooperative first case sets a negotiated tone. A contested one tells every other provider that Brussels intends to litigate, and the compliance budgets across the industry get rewritten accordingly.