The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live | Simon Roses Femerling – Blog
Simon Roses Femerling – Blog
CyberSpace Insecurity 3.X
Skip to content
Home<br>About
Articles
Conferences
Disclaimer
interviews
Privacy Policy
System Crash Image Library
Services
Security Advisories
← The Future of Vibe Coding Security (Part 10)
The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live
Posted on August 8, 2026 by Simon Roses
Read Time: 13 minutes
TL;DR
On August 2, 2026 , the part of the EU AI Act everyone was quietly ignoring became enforceable: the AI Office can now fine providers of general-purpose AI models up to 3% of global annual turnover or €15 million, whichever is higher , and can demand your technical documentation, run its own evaluations of your model, order you to "take measures," and in the worst case make you restrict, withdraw, or recall the model from the EU market . The obligations themselves have technically existed since August 2, 2025 — technical documentation, downstream transparency, a copyright policy that honors robots.txt and opt-outs, a public summary of training data — but until now they were rules without a referee. That changed. Models judged to carry systemic risk (trained above 10^25 FLOP) carry heavier duties that read like a security checklist written by a regulator: model evaluations, adversarial testing / red-teaming , a safety-and-security framework, serious-incident reporting to the AI Office, and cybersecurity protection of the model weights themselves. The voluntary Code of Practice buys you a lighter touch, not immunity. Models already on the market before August 2, 2025 get until August 2, 2027 to fall in line. This is the regulatory half of a two-part story — the civil-liability half, the new Product Liability Directive, is the post I’m publishing right after this one. Read together, the EU has built a pincer: a regulator that fines you, and a courtroom that bills you. Here’s my security-practitioner read of the regulatory jaw.
The dates that matter:
Date<br>What happens
Aug 1, 2024<br>The AI Act enters into force
Aug 2, 2025<br>GPAI model obligations begin (for models placed on the market after this date)
Aug 2, 2026<br>Enforcement switches on — the AI Office / Commission can investigate, evaluate, order measures, and fine
Aug 2, 2027<br>Compliance deadline for GPAI models already on the market before Aug 2, 2025
The usual disclaimer, same as always: I am not a lawyer, and this is not legal advice — it’s a security practitioner reading a regulation the way I read an attack surface, looking for where the pressure actually lands and who ends up holding it. If you build or ship AI models into the EU, talk to actual counsel. What I can tell you is what this changes operationally for the people who build, secure, and deploy these models — because buried under the compliance language is a list of things I have been demanding on this blog for two years, now backed by a fine.
A note on framing before we start. This post is one of a pair. The EU is putting teeth behind AI on two different tracks at once , and they bite in different ways. This one — the AI Act’s rules for general-purpose AI — is regulatory: a public authority, the AI Office, with the power to investigate you and fine you. The companion piece, on the new Product Liability Directive , is civil: private plaintiffs and courts, strict liability, damages paid to the person your defective software harmed. I’m publishing them back to back on purpose, because if you only track one you’ll misjudge your exposure. A regulator fining you and a claimant suing you are two separate doors, and after this summer both are open.
I have been circling the regulatory door for a while — why "we use ChatGPT" isn’t an AI strategy, what happens when the model itself becomes the attacker, whether you can still tell an open-weight model from a frontier one. August 2 is the EU answering a slice of those questions with an enforcement budget attached.
What Actually Changed on August 2
Here’s the part that confuses people, so let me be precise: August 2, 2026 did not create new obligations. The substantive rules for general-purpose AI (GPAI) models kicked in a full year earlier, on August 2, 2025. What was missing until now was the enforcement machinery. For twelve months the AI Act’s GPAI chapter has been law you could technically break without anyone able to do much about it.
That grace period is over. As of August 2, 2026, the AI Office , the Commission’s dedicated AI enforcement body, has four concrete powers it did not have on August 1:
Demand your documentation. It can require a GPAI provider to hand over technical documentation and information about the model.
Evaluate your model. It can run its own assessments of your model to check compliance and investigate systemic risk — including requesting access.
Order compliance measures. It can require you to "take appropriate measures" to bring the model into...