The Wire · GPAI Enforcement Powers Go Live · 2026-07-25
The Deep Read: the EU AI Act's GPAI enforcement regime under Article 101, exercisable from 2 August 2026.
Opening Wire
On 2 August 2026, the European Commission's enforcement powers over general-purpose AI providers become exercisable. GPAI model obligations have been binding law since 2 August 2025. Enforcement was not. From next week, the AI Office can request documentation, evaluate models, order corrective measures, restrict or withdraw models, and impose fines. Under Article 101, fines reach up to 3% of global annual turnover or EUR 15 million, whichever is higher.
Deadline Watch
GPAI enforcement powers become exercisable.
Regulation (EU) 2024/1689, Article 101 (artificialintelligenceact.eu; Latham & Watkins). Compliance date: 2 August 2026. From that date, GPAI providers are subject to Commission documentation requests, model evaluations, and fines up to 3% of global turnover or EUR 15M.
Article 50 transparency duties confirmed on schedule.
Regulation (EU) 2024/1689, Article 50, as amended by the Digital Omnibus (technology.org; CSA research note). Compliance date: 2 August 2026. Providers and deployers must disclose chatbot interactions, mark synthetic content, and label deepfakes. Penalties reach EUR 15M or 3% of turnover.
High-risk deadlines deferred to December 2027.
Digital Omnibus on AI, signed 8 July 2026 per curation (Council of the EU; Gibson Dunn). Standalone Annex III high-risk systems move to 2 December 2027; Annex I product-embedded AI moves to 2 August 2028. Until Official Journal publication, the original August 2026 baseline technically remains.
Illinois enacts frontier-model audit mandate.
SB 315, Artificial Intelligence Safety Measures Act, signed 6 July 2026 (Pritzker newsroom; Crowell). Effective 1 January 2027; audit obligation from 1 January 2028. Frontier developers with over $500M revenue training above 10^26 operations must obtain annual independent third-party compliance audits.
Colorado resets to a narrower ADMT statute.
SB 26-189, signed 14 May 2026 (leg.colorado.gov; Finnegan). Effective 1 January 2027. It repeals and replaces SB 24-205, which never took effect. Deployers making consequential decisions must give pre-use notice, explain adverse outcomes within 30 days, and offer human review.
The Deep Read
The instrument. Regulation (EU) 2024/1689 gains its enforcement teeth for general-purpose AI on 2 August 2026. The distinction matters. GPAI model obligations have been binding law since 2 August 2025. What was missing was the Commission's supervisory apparatus. Article 101 and Chapter V now activate it. The AI Office can request documentation, evaluate models directly, order corrective measures, restrict or withdraw models from the market, and levy fines. The GPAI Code of Practice, published in final form on 10 July 2025, covers transparency, copyright, and safety/security. Adherence is a mitigating factor. It does not exclude fines.
Who it binds. The obligated population is GPAI providers — those who develop and place general-purpose AI models on the EU market. This is a provider obligation, not a deployer one. Reach is extraterritorial: a model offered into the EU market triggers the regime regardless of where the provider sits.
One boundary remains unresolved. Whether modified GPAI models derived from pre-2 August 2025 base models fall under 2026 or 2027 enforcement is unclear. Providers of derivative or fine-tuned models sit in that gap until the AI Office clarifies.
What it requires. The underlying duties applied from 2 August 2025: technical documentation, copyright policy, training-content summaries, and — for systemic-risk models — model evaluation and incident reporting. From 2 August 2026, those duties become enforceable rather than merely owed. The Commission can compel their production. Providers subject to Article 101 must be able to furnish documentation on request from that date.
Two further obligations arrive later. The Article 50(2) machine-readable marking requirement for synthetic content applies from 2 December 2026, following the reduction of the format grace period from six to three months. The new Article 5 prohibitions on nudifier and CSAM-generating AI apply on the same date.
The exposure. Under Article 101, fines reach up to 3% of global annual turnover or EUR 15 million, whichever is higher (per Latham & Watkins; Jones Day). The enforcement posture is not theoretical. The AI Office holds direct evaluation authority — it can test models rather than rely solely on self-attestation. Code of Practice adherence mitigates but does not immunize. The first signal to watch is the Commission's initial GPAI compliance interactions and requests for information after 2 August 2026.
The operator's list.
- GPAI providers offering models into the EU must be positioned to furnish Article 53 technical documentation on AI Office request from 2 August 2026.
- Providers of models modified from pre-2 August 2025 base models fall in an unresolved 2026-vs-2027 enforcement window; the classification question warrants tracking pending AI Office guidance.
- Providers relying on Code of Practice signature should treat it as mitigation of fines, not exclusion — the underlying obligations still bind.
Compliance Tool Box
This week: model-documentation registries built for the EU AI Act's Article 53 GPAI documentation set. Tools in this category maintain a versioned inventory of model cards, training-data summaries, copyright policies, and evaluation records, mapping each artifact to the specific regulatory obligation it satisfies. The intended user is the provider-side compliance or ML-governance function that must produce documentation on AI Office request. The value is retrieval readiness: evidence organized by obligation rather than scattered across engineering repositories. Pricing is not publicly listed for tools in this category. One limitation: a registry organizes and surfaces evidence. It does not generate the underlying model evaluations or systemic-risk assessments that Article 55 requires.
Affiliate disclosure: links marked /go/ are affiliate links; AI Policy Wire may earn a commission at no cost to you. /go/gpai-doc-registry
The Clock Board
| Jurisdiction | Instrument | Compliance date | Status |
|---|---|---|---|
| EU | Reg (EU) 2024/1689, Art. 101 — GPAI enforcement | 2 August 2026 | Powers exercisable next week |
| EU | Reg (EU) 2024/1689, Art. 50 — transparency | 2 August 2026 | Confirmed on schedule |
| EU | Art. 50(2) synthetic-content marking; Art. 5 NCII/CSAM prohibitions | 2 December 2026 | Standing clock |
| EU | Digital Omnibus — Annex III high-risk systems | 2 December 2027 | Deferred (pending OJ publication) |
| EU | Digital Omnibus — Annex I product-embedded AI | 2 August 2028 | Deferred (pending OJ publication) |
| US — Colorado | SB 26-189 (ADMT); replaces SB 24-205 | 1 January 2027 | Repeal-and-replace enacted 14 May 2026 |
| US — Illinois | SB 315 (AI Safety Measures Act) | 1 January 2027 (audit 1 Jan 2028) | Signed 6 July 2026 |
| APAC — China | Implementation Opinions on AI Agents (CAC) | 15 July 2026 | Reported enforceable (tier-2; primary text pending) |
Watchpoints
EU. Watch for the first Commission GPAI request for information after 2 August 2026, which will set the enforcement posture. Also watch resolution of the modified-model 2026-vs-2027 enforcement question.
EU. Watch the Official Journal publication date of the Digital Omnibus; entry into force follows three days later, and until then the original August 2026 baseline technically holds.
US — states. Watch Colorado AG formal rulemaking after the 13 July 2026 comment deadline, with final ADMT and chatbot rules required before 1 January 2027.
US — states. Watch Illinois auditor-qualification and conflict-of-interest standards ahead of the 1 January 2028 audit obligation.
APAC. Watch for primary CAC text confirming the Implementation Opinions on AI Agents, currently single-sourced.
Independent regulatory intelligence — not legal advice. Matters with material exposure warrant counsel.