Politics & Policy 28 Sep 2026 16 min read 10 sources

The Enforcement Test: How the EU AI Act's First Compliance Deadlines for General-Purpose AI Will Reshape Global Model Governance

The EU AI Act's obligations for general-purpose AI models have moved from legislative text to binding law, backed by fines reaching up to 7% of global turnover and a fully operational enforcement regime. This article examines what the GPAI deadlines demand of model providers, how the penalty architecture and supply-chain liability reshape compliance practice, and why the collision between EU enforcement and American deregulation will determine who writes the rules for global AI governance.

The Enforcement Test: How the EU AI Act's First Compliance Deadlines for General-Purpose AI Will Reshape Global Model Governance

Introduction

On 2 August 2025, the world's most ambitious attempt to regulate artificial intelligence crossed a decisive threshold. The EU AI Act -- the first comprehensive legal framework for AI systems anywhere in the world [1][2] -- formally extended its reach to the general-purpose AI (GPAI) models that power the modern AI economy: large language models, multimodal systems, and the foundation models whose outputs flow into countless downstream applications [3][4]. After entering into force on 1 August 2024 following its publication in the Official Journal of the European Union on 12 July 2024, the Act has been unfolding on a deliberately phased timetable designed to give regulators and industry time to build the machinery of compliance [1][4].

That machinery is now running. The transparency obligations that took effect in August 2025 were followed, on 2 August 2026, by the Act's general applicability and the activation of its full enforcement framework -- including penalty provisions specifically calibrated for GPAI providers [5][4]. What was previously a compliance runway has become an enforcement test: the first genuine trial of whether a risk-based regulatory architecture can govern technologies as complex, fast-moving, and globally distributed as foundation models [6].

The stakes extend far beyond Brussels. The Act applies extraterritorially to any provider whose systems or outputs reach European users [7][8], and its phased rollout is widely expected to trigger a "Brussels Effect" in which EU standards become a de facto global benchmark [1]. Yet the enforcement moment has arrived just as the regulatory tide is turning elsewhere -- with Washington pushing federal preemption and state-level rollbacks even as the EU itself debates delay through its Digital Omnibus package [7]. The result is a global contest over who writes the rules for artificial intelligence, and the first GPAI compliance deadlines are its opening round.

A Regulatory Clock Built for Transformation

The EU AI Act's drafters chose gradualism by design. The Act entered into force on 1 August 2024, but its obligations activate on a rolling schedule calibrated to risk and to the time organizations need to adapt [2][4]. The first milestone arrived on 2 February 2025, when Article 5's prohibited practices became unlawful: social scoring, exploitative or manipulative AI tools that alter human behaviour, facial recognition databases built through untargeted scraping of images or CCTV footage, emotion recognition tools, and biometric identification systems based on highly sensitive characteristics [2][4]. The same date introduced an AI literacy obligation requiring providers and deployers to ensure the people who build and use AI systems possess the skills to make informed decisions about them [8].

Then came the milestone at the heart of this article. On 2 August 2025, Chapter V of the Act -- the provisions governing general-purpose AI models -- began to apply, along with the Act's governance structures and its sanctions regime [3][4]. From that date, any company developing or providing a GPAI model for the EU market became subject to binding obligations around classification, documentation, and, for the most capable models, systemic-risk management [3][4].

The clock keeps ticking. Most of the Act's general provisions apply from 2 August 2026, when the transition shifted from legislative framework to operational enforcement regime -- the moment European and national authorities began actively monitoring compliance [6][4]. Businesses with existing high-risk AI systems in production have until August 2027 to bring them into full conformity, which means auditing every component, retraining models on approved data where necessary, updating user-facing documentation, and in many cases rebuilding parts of their risk management infrastructure [9][4]. From 2028 onward, the first wave of regulator audits and investigations begins, with penalties fully enforceable [9].

Infographic timeline of the EU AI Act rollout from August 2024 through 2028, highlighting the five key milestones: entry into force, prohibited practices, GPAI obligations, general applicability and enforcement, and full high-risk compliance The Brussels Effect: What US Enterprises Need to Know About the EU AI Act.

Inside the GPAI Rulebook: What the Deadlines Actually Demand

The obligations facing GPAI providers are not aspirational principles; they are enforceable legal requirements. Providers of general-purpose models must now maintain technical documentation, publish transparency reporting, and conduct systemic risk assessments where applicable [3]. Critically, providers must also implement a copyright policy and produce a sufficiently detailed summary of the content used to train their models -- a transparency obligation that is legally binding, not optional [5].

This transparency mandate cuts across several contested legal domains simultaneously. It speaks to intellectual property by addressing whether protected content was used lawfully in training; to data protection by requiring demonstrable GDPR compliance where personal data was included; and to trade secrets, where the law explicitly requires balancing disclosure against the protection of sensitive commercial information [5]. For an industry whose foundation models were trained on vast, opaque datasets, this is arguably the most consequential shift: the era of unaccountable training data is legally over in Europe.

The Systemic-Risk Tier

For the most powerful models -- those designated as carrying systemic risk -- additional obligations apply under Article 55 of the Act [3][5]. These requirements target state-of-the-art practices for identifying, mitigating, and monitoring high-impact risks associated with advanced models, including model evaluations and risk-mitigation measures [3][5]. The two-tier structure reflects a deliberate regulatory judgment: general obligations for everyone, enhanced scrutiny for models whose capabilities could produce harms at civilizational scale.

The GPAI Code of Practice

Regulators have provided a compliance pathway alongside the legal mandates. On 10 July 2025, the first General-Purpose AI Code of Practice was published, establishing a regulatory framework organized into three chapters, each aligned with specific legal obligations under the Act [5]. The Transparency and Copyright chapters apply to all GPAI model providers and support compliance with Article 53, while the Safety and Security chapter is relevant only to providers of systemic-risk models and supports compliance with Article 55 [5]. For companies willing to engage, the Code transforms abstract statutory duties into concrete operational practices.

Diagram showing the three chapters of the GPAI Code of Practice -- Transparency, Copyright, and Safety & Security -- with arrows mapping each chapter to its corresponding AI Act article (Articles 53 and 55) and indicating which provider categories each applies to EU AI Act Enforcement Goes Live: The Agentic AI Architect's Compliance Playbook (2026) - RPABOTS.WORLD

The Enforcement Architecture: Penalties With Teeth

What separates this framework from earlier waves of AI ethics guidelines is the penalty architecture waiting behind it. The Act's headline sanctions under Article 99 reach up to €35 million or 7% of global turnover for the most serious breaches -- a ceiling deliberately calibrated to exceed the fines that reshaped corporate behaviour under GDPR [9][2][5]. The August 2025 milestone brought these maximum penalties into play for prohibited practices, and they are now enforceable [9][3].

For GPAI providers specifically, a dedicated enforcement provision came into effect on 2 August 2026: Article 101 enables fines of up to €15 million or 3% of global turnover for violations of the model-specific obligations [5]. Enforcement targets include non-compliance with transparency requirements, refusal to provide regulators with model access, and deployment of GPAI models in prohibited AI practices [5]. The Commission has defined a three-stage enforcement calendar that legal teams must now incorporate into compliance timelines [5].

The liability model is equally significant because it distributes responsibility across the entire AI supply chain. The Act places obligations on both the provider -- who builds or trains the model -- and the deployer -- who uses it in a real business process. A software vendor selling an AI hiring tool into the EU is liable for the tool's compliance; the human resources department buying that tool is liable for how it is used [6]. Finger-pointing between vendor and customer no longer suffices, and enforcement can reach providers, deployers, importers, distributors, and other participants across an AI supply chain [6][8]. The market consequences are already visible: analysis of early compliance scenarios suggests companies that aligned their general-purpose models with the Act's governance requirements have avoided fines estimated in the tens of millions of euros while reinforcing consumer trust [10].

Chart comparing the EU AI Act's penalty tiers -- prohibited-practice violations, GPAI breaches, and other infringements -- showing maximum fines in euros alongside the percentage-of-global-turnover ceilings EU AI Act Compliance: What Companies Need to Know About Penalties

Compliance as an Operational Test, Not a Paper Exercise

Perhaps the most important lesson of the first enforcement phase is that documentation policies do not constitute compliance. The AI Act now governs real deployment decisions rather than hypothetical future products, and regulators expect operational evidence: records showing how systems were classified, what safeguards were documented, how users were informed, and what evidence trails exist for regulators [8].

This operational standard is complicated by the Act's architecture. Risk classification determines which obligations apply, and classification follows a system's intended purpose and actual use -- not the identity of the model vendor [8]. A single foundation model can simultaneously support an ordinary writing assistant, a recruitment screener, and a medical product; the same model can thus underpin both low-risk and high-risk deployments with entirely different obligation profiles [8]. Organizations must decompose a broad legal framework into hundreds of smaller decisions about systems, people, data, and controls, then connect legal analysis to product design, data governance, security, procurement, and post-market monitoring [8].

For enterprises, the practical playbook is becoming clear. Mid-term priorities include registering all high-risk systems in the EU database before the August 2027 deadline, completing fundamental rights impact assessments, ensuring GPAI compliance where the organization provides or modifies general-purpose models, and conducting internal audits to verify documentation is complete and accurate [9]. Ongoing imperatives include monitoring guidance from national regulators and the European AI Board, tracking legislative amendments through the Act's review clauses, and -- most durably -- building compliance into product development lifecycles so that future AI systems are compliant by design rather than retrofitted under deadline pressure [9]. Enterprise AI leaders describe the current window as critical: early compliance investment reduces regulatory risk, improves AI governance maturity, and positions organizations as trustworthy partners in an increasingly scrutinized sector [6].

The Global Stakes: Brussels Effect Meets Deregulatory Counterpressure

The enforcement test is unfolding against a paradoxical global backdrop. In 2026, the EU AI Act's most consequential milestones arrived just as both Washington and -- unexpectedly -- Brussels itself pumped the brakes [7]. In the United States, a federal preemption push and state-level rollbacks signal an innovation-first posture with no comprehensive federal framework. In Europe, the Digital Omnibus package has introduced debate over delays even as enforcement capacity steadily builds around the Act's early provisions [7].

This collision of trajectories frames a battle over norm-setting with profound implications for multinational organizations. For the EU, the risk is that enforcement delays erode momentum toward its vision of human-centric, trustworthy AI [7][1]. For the United States, the mirror-image risk is ceding the norm-setting battlefield by default -- while American companies remain exposed to EU rules that still apply extraterritorially to anyone serving European users [7]. The practical reality for global business is unchanged by American deregulation: overseas providers fall within the AI Act's scope whenever their systems or outputs enter the European Union [7][8].

The economic logic of compliance is equally clear-eyed. Companies operating in or selling to the European market must assess their AI systems for conformity, absorbing substantial costs in risk management frameworks, documentation, and specialized counsel [1]. But the Act also redistributes competitive advantage. Organizations that invested early in ethical AI foundations, robust data governance, and transparent practices are adapting more easily and may convert compliance into a market differentiator built on demonstrable trustworthiness [1]. European AI companies accustomed to regulatory discipline may gain an edge serving the EU market with compliant solutions, while non-EU companies unwilling or unable to adapt risk exclusion from one of the world's largest economic blocs -- and companies with opaque models and poor data governance will struggle to meet transparency and accountability requirements at all [1].

World map illustrating divergent AI governance approaches -- the EU's enforcement regime, America's deregulatory turn, and other jurisdictions -- with arrows showing the extraterritorial reach of EU rules toward companies serving European users EU AI Act Regulation Explained: Risk Categories, Penalties

Conclusion

The EU AI Act's first compliance deadlines for general-purpose AI have converted the world's most watched AI governance experiment from theory into practice. The transparency, copyright, and systemic-risk obligations that took effect in August 2025, the enforcement regime and penalty powers activated in August 2026, and the high-risk conformity deadline looming in August 2027 together form a sequence that will define what credible model governance looks like for the rest of the decade [9][3][5][4].

The emerging picture is one of compliance as an operational discipline: providers and deployers alike must produce evidence, not statements; document risk decisions across a supply chain where liability can no longer be outsourced; and embed governance into product lifecycles rather than bolting it on at launch [9][6][8]. Companies that treat the Act as a design constraint rather than a legal obstacle are already positioned to compete on trust in European markets and beyond [1].

Whether the EU's model ultimately sets the global standard remains contested. The collision between European enforcement and American deregulation means the next several years will determine whether foundation-model governance converges on Brussels's risk-based architecture, fragments along geopolitical lines, or evolves into something hybrid [7]. What is no longer in doubt is that the enforcement test has begun -- and every organization that builds, deploys, or sells AI models with any connection to European users is now taking it, whether prepared or not.

References

  1. 1.
    The EU AI Act's Phased Rollout: A New Era for Global AI Governance Retrieved September 29, 2026, from https://markets.financialcontent.com/wral/article/marketminute-2025-9-23-the-eu-ai-acts-phased-rollout-a-new-era-for-global-ai-governance.
  2. 2.
    EU AI Act Timeline: Key Dates For Compliance Retrieved September 29, 2026, from https://www.goodwinlaw.com/en/insights/publications/2024/10/insights-technology-aiml-eu-ai-act-implementation-timeline.
  3. 3.
    Navigating the EU AI Act August 2025 Deadline: GPAI Compliance, Penalties, and Enforcement – Cranium Retrieved September 29, 2026, from https://cranium.ai/navigating-the-eu-ai-act-august-2025-deadline-gpai-compliance-penalties-and-enforcement.
  4. 4.
    EU AI Act Enters into Force: Key Compliance Dates for... Retrieved September 29, 2026, from https://www.mccannfitzgerald.com/knowledge/data-privacy-and-cyber-risk/eu-ai-act-enters-into-force-key-compliance-dates-for-stakeholders.
  5. 5.
    EU AI Obligations for GPAI Providers: Compliance, Enforcement & Deadlines (2025–2027) - MediaLaws Retrieved September 29, 2026, from https://www.medialaws.eu/eu-ai-obligations-for-gpai-providers-compliance-enforcement-deadlines-2025-2027.
  6. 6.
    EU AI Act Enforcement: First Compliance Deadlines Hit Enterprises | CAIO Weekly Retrieved September 29, 2026, from https://caioweekly.co.uk/eu-ai-act-enforcement-compliance-deadlines-2026.
  7. 7.
    Enforcement Meets Deregulation: The EU AI Act's First Deadlines Collide with America's Reversal—and the Fight to Set Global AI Rules | Reducates Retrieved September 29, 2026, from https://reducates.com/ai-digests/enforcement-meets-deregulation-how-the-eu-ai-acts-first-compliance-deadlines-collide-with-americas-policy-reversal-and-the-battle-to-set-global-ai-governance-standards.
  8. 8.
    EU AI Act Rules Turn Compliance Deadlines Into an Operational Test Retrieved September 29, 2026, from https://www.remio.ai/post/eu-ai-act-rules-turn-compliance-deadlines-into-an-operational-test.
  9. 9.
    EU AI Act Enforcement: First Penalties and Compliance Deadlines Retrieved September 29, 2026, from https://www.unboxfuture.com/2026/09/eu-ai-act-enforcement-first-penalties.html.
  10. 10.
    The EU AI Act: Your Compliance Roadmap for 2025 Prt. 1 Retrieved September 29, 2026, from https://www.linkedin.com/pulse/eu-ai-act-your-compliance-roadmap-2025-prt-1-yosef-nesirat-huo4e.

Notification

We do not offer direct memberships yet. You can explore our available content through our Archives and AI Digests.