Sophie Laurent, YuSMP Group
Sophie Laurent Legal & Compliance Lead, YuSMP Group · Tracking EU AI Act and GDPR obligations for US and EU software teams
Conceptual illustration of a glowing ring of European Union stars beside a scale of justice made of light, representing EU AI Act enforcement, on a deep navy background

The short answer

From 2 August 2026 the European Commission can enforce the EU AI Act's general-purpose AI (GPAI) rules and impose fines of up to €15 million or 3% of global annual turnover, whichever is higher. The obligations themselves have applied since 2 August 2025; what arrives now is the machinery to police them — documentation requests, model evaluations, corrective orders and penalties. The one-year grace period is over.

If your product is built on, hosts or fine-tunes a general-purpose model, this is a supply-chain question, not just a headline about model makers. The clean move is to treat your model vendor's AI Act readiness as due diligence you verify, not a box you assume is ticked.

What actually changes on 2 August

The GPAI rules are not new. They have applied to every general-purpose model placed on the EU market since 2 August 2025, covering technical documentation, a copyright policy, a public summary of training data, and additional safety and security duties for models judged to carry systemic risk. What was missing until now was enforcement: the Commission's supervision and penalty powers were deliberately held back for a year so providers and the newly built AI Office could operationalise the regime before anyone faced sanctions.

That grace period ends on 2 August 2026. From that day the Commission can do four concrete things. It can issue information requests and expect accurate, complete answers (Article 91). It can run evaluations of a model, including with independent experts, to check compliance or investigate systemic risk (Article 92). It can order corrective measures — up to restricting, withdrawing or recalling a model from the EU market (Article 93). And it can levy fines of up to 3% of global annual turnover or €15 million, whichever is higher (Article 101). Teams shipping GenAI features into the EU now sit downstream of a provider that can be told to change or pull a model.

Why the Omnibus did not move this date

There has been a lot of noise about the AI Act being softened, and some of it is real. The Digital Omnibus simplification package — endorsed by the European Parliament on 16 June 2026 and given its final green light by the Council on 29 June 2026 — postponed the high-risk obligations by roughly 12 to 16 months. Stand-alone high-risk systems under Annex III now apply from 2 December 2027, and high-risk AI embedded in regulated products under Annex I from 2 August 2028. If your compliance plan was pinned to the old high-risk dates, you have more runway than you did.

But the Omnibus was surgical about what it moved. It left the general-purpose AI enforcement powers and the Article 50 transparency duties exactly where they were: both still land on 2 August 2026. So the headline "the EU delayed the AI Act" is only half true. The high-risk timeline slipped; the GPAI and transparency timeline did not. For the many teams whose AI exposure runs through foundation models and user-facing AI features rather than formally high-risk systems, the binding date is the one that stayed put.

The part that catches buyers off guard

The fines are aimed at GPAI model providers, but the risk does not stop at their door. If you fine-tune, self-host or build products on top of a general-purpose model, that provider's documentation, copyright posture and compliance status become part of your own supply chain. A corrective order against an upstream model — a forced change, or a withdrawal from the EU market — is your outage, your re-architecture, your customer conversation. The practical response is to know exactly which models sit under your product and to keep your vendor's AI Act status under review rather than taking it on trust.

There is also a duty that lands directly on deployers, whatever model they use. Article 50 transparency, effective the same 2 August 2026, means telling people when they are interacting with an AI system and clearly labelling AI-generated or AI-manipulated content such as synthetic images, audio or video. That is not a model-maker problem you can outsource; it is a product decision in your own interface. If you run chatbots, generate media, or ship AI copilots into the EU, the disclosure and labelling work is yours to implement.

What it means for US & EU software teams

For US teams selling into Europe, the reframing is that the AI Act is now an enforced law with a supervisor that can request documents and issue penalties, not a future compliance project. Extraterritorial reach is the point: it applies where a model or AI system is placed on or used in the EU market, regardless of where the company sits. If European users touch your AI, the obligations follow the product across the Atlantic, and "we're a US company" is not a defence.

For EU teams and anyone in a regulated sector, the efficient move is to fold AI Act work into governance you already run rather than standing up a parallel programme. The documentation, data-provenance and access-logging habits that GDPR and data-protection compliance already demand map closely onto what an AI Act information request would ask for. In a FinTech handling payment data or a healthcare operator handling patient records, the auditability you built for existing rules is most of the work; the AI-specific additions are transparency disclosure, model inventory and vendor due diligence on top.

The trap on both sides is treating 2 August as a one-off deadline instead of the start of an enforced regime. Enforcement is a capability the Commission now has permanently, and the first information requests will show how aggressively it is used. Teams that come out ahead are the ones that can answer "which models do we rely on, what do they claim, and where do we disclose AI to users?" without a scramble — because that is precisely what a regulator, an enterprise customer, or a security review will ask.

What to do before the deadline

You do not need a legal department to make meaningful progress before 2 August. You need an inventory and a few decisions.

  1. Inventory your model dependencies. List every general-purpose model your products call, host or fine-tune, and note whether it is a hosted API or a model you run yourself.
  2. Check each provider's AI Act status. Confirm they publish technical documentation, a copyright policy and a training-data summary — and treat gaps as vendor risk, not a formality.
  3. Map your own Article 50 duties. Find every place users interact with AI or see AI-generated content, and implement clear disclosure and labelling in the interface.
  4. Keep records you could hand over. Maintain documentation of your data sources, model usage and decisions so you could answer an information request without reconstructing history.
  5. Reuse your GDPR foundation. Tie AI Act work to existing data-protection governance — data lineage, access control, logging — instead of building a separate track.
  6. Plan for an upstream change. Decide in advance what you would do if a model you depend on were altered or pulled from the EU market, and keep a fallback in mind.

None of this is legal advice, and the exact enforcement posture will only become clear once the Commission starts using its powers. But the direction is unambiguous: from 2 August 2026 the EU AI Act's GPAI rules are enforceable, backed by real fines, and the teams that mapped their exposure early will meet that with an answer rather than a scramble.

Frequently asked questions

What changes for AI providers on 2 August 2026?

The European Commission's enforcement powers over general-purpose AI (GPAI) model providers become applicable. The GPAI obligations have been in force since 2 August 2025, but the supervision and penalty machinery was held back for a year to let providers and the AI Office prepare. That grace period ends on 2 August 2026, when the powers gain teeth: information requests, model evaluations, corrective measures and fines.

How large are the EU AI Act fines for GPAI providers?

Under Article 101, the Commission can fine a GPAI model provider up to 3% of total worldwide annual turnover or €15 million, whichever is higher. Fines can apply for infringing the GPAI obligations, for supplying incorrect, incomplete or misleading information to a documentation request, for refusing corrective measures, or for denying access to a model for evaluation.

Did the Digital Omnibus delay the 2 August 2026 date?

No. The Digital Omnibus, which the Council gave its final green light on 29 June 2026 after the Parliament's 16 June 2026 endorsement, postponed the high-risk obligations by 12 to 16 months: stand-alone Annex III systems from 2 December 2027 and AI embedded in regulated products from 2 August 2028. The GPAI enforcement powers and the Article 50 transparency duties were left untouched and both still land on 2 August 2026.

Does this affect companies that only use AI, not build models?

The fines target GPAI model providers, but the effects reach downstream. If you fine-tune, host or ship products on top of a general-purpose model, your provider's compliance status, documentation and copyright posture become your supply-chain risk. Deployers also carry their own Article 50 transparency duties from the same day — disclosing AI interaction and labelling AI-generated content — so treat vendor readiness as due diligence, not an assumption.

What should US and EU teams do before the deadline?

Map which general-purpose models your products depend on and confirm each provider's AI Act status, including technical documentation and copyright policy. Inventory where you have Article 50 transparency obligations and implement AI-interaction disclosure and content labelling. Keep records of data sources and model usage so you can answer a documentation request. For regulated sectors, fold this into existing GDPR and sector governance rather than running a separate project.

Sources

Council of the EU — Artificial Intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026 (primary source)
European Commission — AI Act, regulatory framework and application timeline (primary source)
EU Artificial Intelligence Act — Enforcement of Chapter V (GPAI): powers under Articles 91–93 and 101