The EU Can Now Inspect AI Models, Restrict Access, and Fine Providers 3% of Turnover
The European Union entered a new enforcement phase on August 2, 2026, giving regulators direct authority over general-purpose AI providers. The headline circulating through Google News is blunt but broadly accurate. The European Commission can request information, evaluate models, order corrective measures, and impose substantial fines.
For general-purpose AI providers, the first year of supervised implementation has ended. Obligations already applied to newly released models from August 2, 2025. However, the AI Office initially emphasized collaboration, especially for companies following the voluntary General-Purpose AI Code of Practice.
That posture has now changed. The Commission says it will enforce full compliance, including through financial penalties. Major providers such as Google, OpenAI, Microsoft, Anthropic, Amazon, Mistral AI, and Cohere have signed the code. Providers outside that framework must demonstrate compliance through other adequate measures.
The central conflict is no longer regulation versus innovation. It is voluntary cooperation versus compulsory proof. Companies can still choose their compliance route, but regulators can now test whether that route meets the law.
What Exactly Changed on August 2
The EU has moved from helping general-purpose AI providers prepare to checking whether they actually comply.
The AI Act entered into force on August 1, 2024. Its provisions were scheduled to apply in stages, rather than arriving as one regulatory package.
Rules covering prohibited AI practices and AI literacy began applying in February 2025. Obligations for general-purpose AI models followed on August 2, 2025. The Commission’s enforcement powers for those model obligations became operational one year later.
That date matters because general-purpose AI models sit beneath many consumer and enterprise products. The category includes models capable of performing a broad range of tasks and integrating into numerous downstream systems.
The Commission’s current guidance uses a technical threshold to help identify these models. It generally treats models trained with more than 10^23 floating-point operations as general-purpose models when they can generate language.
The exact legal analysis involves more than computing volume. Regulators also examine a model’s capabilities, market placement, distribution terms, and possible modifications by downstream companies.
All covered providers must prepare technical documentation for authorities and share information with downstream system developers. They must also establish a policy for complying with European copyright law.
Providers must publish a sufficiently detailed summary describing the content used to train each covered model. The Commission has issued a mandatory template for these public summaries.
The rules become stricter for general-purpose models classified as presenting systemic risk. These providers must evaluate and mitigate systemic risks, report serious incidents, and maintain suitable cybersecurity protections.
A model is presumed to present systemic risk when its training consumed more than 10^25 floating-point operations. The Commission can also designate other models after considering their capabilities, users, scalability, and access to external tools.
The enforcement shift means the AI Office no longer needs to rely on a provider’s assurances. Under the GPAI enforcement rules, it can request information, evaluate models, demand mitigations, and require a model’s withdrawal from the European market.
Withdrawal is the most consequential option. A provider that cannot satisfy the Commission may lose access to one of the world’s largest technology markets.
The law also gives regulators intermediate tools. They can request documents, investigate suspected infringements, require corrective measures, or demand changes to risk controls before pursuing withdrawal.
That escalation structure is important. It does not mean every documentation error immediately causes a model ban. It means providers can no longer assume that incomplete documentation will remain a private compliance problem.
Another deadline remains in place. Models already placed on the EU market before August 2, 2025, generally have until August 2, 2027, to satisfy the relevant general-purpose model obligations.
That transition prevents the new enforcement phase from applying identically to every existing model. Newer releases face immediate scrutiny, while qualifying older models retain a limited compliance runway.
The Google News headline therefore compresses several distinct legal powers into one sentence. The Commission can inspect and evaluate covered models, but enforcement should follow the procedures and proportionality requirements established by the regulation.
Google News Captures the Fine but Not the Full Exposure
The 3% figure is real, but the financial penalty is only one part of the provider’s risk.
The Commission can fine a general-purpose AI provider up to €15 million or 3% of its total worldwide annual turnover. For companies other than qualifying smaller businesses, the higher amount can apply.
That calculation uses global turnover from the preceding financial year. It does not use only European revenue or income generated by the affected model.
For the largest technology companies, 3% of worldwide turnover can exceed the fixed amount by a wide margin. The percentage makes noncompliance material even when AI represents only one division within a broader business.
The penalty applies when a provider intentionally or negligently violates relevant AI Act obligations. It can also apply when a provider fails to follow a Commission measure or withholds requested documents and information.
The law requires officials to consider the nature, gravity, and duration of an infringement. They must also account for proportionality and the provider’s circumstances.
Small and medium-sized enterprises receive different treatment. For each category of infringement, the lower applicable ceiling is generally used for qualifying smaller companies.
The headline figure should not be confused with the AI Act’s maximum penalty for every possible violation. Certain prohibited practices elsewhere in the regulation can attract higher penalties.
For general-purpose model providers, the immediate issue is Article 101. The Commission’s AI Act guidance describes a ceiling of €15 million or 3% of worldwide annual turnover for violations involving these obligations or requested measures.
Yet a fine may not be the most damaging consequence. An order restricting or recalling a model can interrupt API services, enterprise deployments, and downstream products.
Consider a provider serving European software developers through an application programming interface. Restricting that underlying model would affect every connected product, even if the downstream companies committed no violation.
The same problem applies to cloud marketplaces. A model may reach European customers through several hosting providers, regional deployments, and integrated software services.
Compliance failures can therefore spread through an entire distribution chain. Enterprise buyers may demand stronger contractual assurances, audit rights, incident notifications, and exit plans before adopting a model.
Providers also face disclosure pressure. Technical documentation must give authorities enough information to understand the model’s capabilities, limitations, training process, and integration requirements.
Public training-content summaries create a different tension. Rightsholders want meaningful information about training sources, while providers want to protect trade secrets and security-sensitive details.
The Commission’s template attempts to establish a common disclosure format. It does not require providers to publish every training item or expose confidential model weights.
Still, the summary must be sufficiently detailed. A vague statement that a model used public internet data is unlikely to resolve questions about source categories, major datasets, and protected material.
The Commission states that failing to publish the required summary can trigger enforcement from August 2, 2026. Its training-content guidance applies the same €15 million or 3% ceiling.
This is where the enforcement phase becomes operational rather than symbolic. Regulators now have standardized documents they can request and compare across providers.
A company that submits detailed records creates an auditable trail. A company that submits thin documentation also creates a trail, but one that may expose gaps during an evaluation.
Google News readers may focus on the size of the fine. Providers will focus equally on documentation requests, testing access, corrective deadlines, and the possibility of market restrictions.
Cooperation and Compulsory Proof Are Now in Direct Conflict
Providers can choose how to comply, but they cannot choose whether regulators evaluate the result.
The EU’s General-Purpose AI Code of Practice remains voluntary. Signing it offers a recognized path for demonstrating compliance with several model obligations.
The code has three chapters. Transparency and copyright apply broadly to general-purpose AI providers. Safety and security apply to providers responsible for models with systemic risk.
The transparency chapter includes a standardized model documentation form. The copyright chapter covers policies for respecting rights reservations and managing lawful access to protected content.
The safety and security chapter addresses risk identification, model evaluations, serious incident reporting, cybersecurity, and post-deployment monitoring. It targets the relatively small group developing the most capable models.
Google, OpenAI, Microsoft, Anthropic, Amazon, IBM, Mistral AI, Cohere, and several other providers appear on the Commission’s published signatory list. The full GPAI code has been recognized as an adequate voluntary compliance tool.
Signing does not grant immunity. It gives the Commission a structured set of commitments against which it can monitor the provider.
A signatory that follows the code gains a clearer evidentiary route. Its forms, risk frameworks, and reporting procedures align with practices already reviewed by the Commission and the AI Board.
A non-signatory can still comply with the law. However, it must show that its alternative controls adequately satisfy the underlying obligations.
That distinction creates the article’s central tradeoff. The code reduces uncertainty but also commits providers to detailed practices that may exceed their preferred disclosure or governance approach.
Providers outside the code preserve more flexibility. They also accept the risk that the AI Office will assess their compliance methods without the same presumption of structure.
The Commission’s first-year approach gave cooperative providers room to complete implementation. Officials said they would work closely with code participants acting in good faith.
From August 2, 2026, that informal runway is over. The Commission now says it will enforce full compliance, including with fines.
This does not turn the code itself into binding legislation. Enforcement still concerns obligations established by the AI Act, not every voluntary practice in isolation.
The difference matters during a dispute. Regulators must connect any penalty or corrective order to the applicable legal requirement and follow procedural protections.
The code nevertheless shapes expectations. It tells authorities what mature documentation, copyright controls, and systemic-risk management can look like.
It also gives enterprise customers a common reference point. Procurement teams can ask whether a provider signed the code and how it implements the relevant chapters.
A signature alone should not decide a purchasing decision. Customers need evidence covering the particular model, version, hosting arrangement, and intended use.
Developers should also distinguish model obligations from system obligations. A foundation-model provider and the company building an employment tool on top of it can face different requirements.
The model provider must supply downstream information needed for compliance. The system provider remains responsible for obligations associated with its own product and use case.
That division becomes difficult when one company controls both layers. Recent EU changes expanded centralized oversight for certain systems built on general-purpose models, especially when the same company supplies both.
The Commission also has a role when such systems are integrated into very large online platforms or search engines. National market-surveillance authorities handle many other AI-system obligations.
This mixed enforcement structure creates room for coordination problems. Providers may deal with the AI Office, national authorities, data-protection regulators, and sector-specific supervisors.
The law attempts to divide responsibilities, but the practical boundaries will develop through investigations and enforcement decisions. Those early cases will matter more than broad promises about regulatory consistency.
Model Inspections Will Test the Limits of Regulatory Access
The Commission has meaningful evaluation powers, but using them effectively requires technical expertise, secure access, and defensible procedures.
The AI Office can conduct evaluations to assess whether a general-purpose model complies with the AI Act. It can investigate systemic risks and examine whether providers have implemented required safeguards.
An evaluation may involve reviewing internal documentation, risk assessments, testing methods, incident records, and other technical evidence. The Commission can also appoint independent experts to support its work.
The word “inspect” can create an exaggerated image of officials seizing a model’s source code. The regulation establishes formal powers, but their use depends on the facts and procedural steps of each case.
Model weights, training records, evaluation datasets, and security controls can contain valuable trade secrets. They may also reveal vulnerabilities that should not become public.
The Commission must therefore balance investigative access with confidentiality and security. Mishandling sensitive information would weaken provider cooperation and create new cyber risks.
Testing advanced models also presents a measurement problem. A model may perform differently across prompts, languages, system configurations, tool permissions, and safety layers.
One evaluation cannot describe every deployment. Regulators will need repeatable methods that connect measured behavior to a specific legal concern.
Systemic-risk investigations are especially demanding. The AI Act covers possible harms involving cybersecurity, manipulation, discrimination, public health, democratic processes, and other large-scale effects.
Some risks appear only after deployment. Others depend on how downstream developers combine a model with search, code execution, private data, or autonomous tools.
Providers may challenge an evaluation’s design, model version, statistical basis, or relevance. The Commission will need a strong record when an order could restrict European market access.
This is the main skeptical angle. Legal authority does not automatically create technical capacity.
The AI Office must recruit specialists, protect confidential materials, coordinate with national authorities, and apply standards consistently across model architectures.
The EU has created an expert pool to advise the AI Office. It has also issued guidelines, templates, and codes intended to make provider evidence more comparable.
Those tools reduce ambiguity, but they cannot eliminate judgment. Terms such as “systemic risk,” “adequate mitigation,” and “sufficiently detailed” still require case-specific interpretation.
Open-source models create another boundary. Some models released under genuinely free and open licenses can receive exemptions from selected documentation obligations.
Those exemptions have conditions. They do not cover every model marketed as open source, and they do not remove added obligations for models presenting systemic risk.
A company that modifies an existing model can also become a provider when the modification is substantial. Minor changes generally do not transfer the full provider role.
This creates a practical question for fine-tuners. They must determine whether their compute, technical changes, branding, and market activity amount to placing a modified model on the EU market.
The Commission’s provider guidelines explain its interpretation, but they are not themselves binding legislation. Courts retain the final authority over contested readings of EU law.
The first enforcement actions will reveal how aggressively the Commission interprets these boundaries. They will also show whether providers resolve disputes cooperatively or challenge orders.
Regulators have incentives to begin with clear documentation failures. Such cases are easier to prove than broad claims about a model’s contribution to societal harm.
A missing training summary, ignored information request, or unreported serious incident creates a defined compliance question. A disputed systemic-risk theory requires more technical and causal analysis.
That suggests enforcement may initially look administrative. The consequences can still become substantial when a provider ignores requests or repeatedly fails to correct identified gaps.
Readers arriving through Google News should therefore resist two extremes. The EU has not gained unlimited access to every AI system, but its powers are no longer merely advisory.
Three Signals Will Show Whether Enforcement Has Teeth
The next phase will be defined by actual information requests, model evaluations, and corrective orders, not another round of policy announcements.
The first signal is whether the AI Office opens a visible investigation into a general-purpose model released after August 2, 2025.
A formal information request would show which evidence regulators consider essential. It could clarify expectations for technical documentation, copyright policies, training summaries, and systemic-risk assessments.
If providers respond without litigation, the cooperative framework will look stronger. A legal challenge would expose unresolved questions about scope, confidentiality, and proportionality.
Either outcome would add more useful guidance than general compliance statements. Companies need to know what regulators request, how much time they allow, and how they assess incomplete records.
The second signal is whether the Commission orders a concrete mitigation or market correction. A corrective measure sits between informal engagement and a fine.
The order might require better documentation, new risk controls, revised downstream information, additional evaluations, or limits on a specific distribution arrangement.
A carefully scoped order would support the EU’s claim that it can regulate model risks without blocking useful services. A broad or technically unclear order would strengthen concerns about regulatory uncertainty.
Market withdrawal remains the strongest intervention. Its credibility depends partly on whether the Commission can design proportionate steps before reaching that point.
The third signal is how providers handle the August 2, 2027 deadline for older models. That date will bring previously marketed general-purpose models into the compliance framework.
Older models can present harder documentation problems. Records may be incomplete, training pipelines may have changed, and relevant employees may have moved to other projects.
The Commission’s training-summary guidance allows providers to explain gaps caused by unavailable information or disproportionate retrieval burdens. It does not create a general exemption from the obligation.
Providers must identify those gaps and justify them. Regulators will decide whether the explanation reflects genuine limitations or inadequate recordkeeping.
If major providers publish consistent summaries and documentation for older models, the transition will strengthen the EU’s framework. Widespread exceptions would weaken comparability across generations.
These signals also matter beyond Europe. Model developers prefer common internal processes, rather than maintaining completely different safety and documentation programs for every jurisdiction.
An EU requirement can therefore affect global development practices even when its direct legal reach stops at the European market. Providers may standardize documentation, incident reporting, and risk evaluations across regions.
That wider effect is not guaranteed. Companies can create EU-specific controls, delay European releases, or withhold certain models when compliance costs appear too high.
The market-access power makes that choice explicit. A provider must either meet the European conditions, contest them, or decline to offer the covered model within the Union.
Enterprise buyers should respond now by mapping their dependencies. They need to know which models support critical workflows and whether an enforced restriction would interrupt those services.
Contracts should identify model versions, hosting regions, notification duties, data-retention terms, and migration options. Buyers should also ask how providers handle regulatory investigations.
Developers need an inventory of downstream integrations. Replacing a model is rarely as simple as changing an API endpoint because prompts, evaluations, safety controls, and output behavior differ.
Knowledge workers face a less direct risk. Their immediate concern is whether tools remain available and whether AI-generated content carries the required disclosures.
Article 50 transparency obligations began applying on August 2, 2026. They cover machine-readable marking for certain synthetic content and disclosure duties involving deepfakes and selected public-interest text.
A limited transition extends some marking requirements until December 2, 2026, for systems placed on the market before the main deadline. It does not postpone the entire AI Act.
The distinction has been blurred in some Google News coverage. General-purpose model enforcement, content-transparency rules, and high-risk system requirements follow related but different schedules.
Several high-risk system deadlines were extended through the AI Omnibus. Rules for specified sensitive uses now apply later than the general August 2026 date.
That postponement does not reverse the Commission’s authority over general-purpose models. It narrows which requirements are currently enforceable across other parts of the AI market.
The practical question is no longer whether the EU has enforcement tools. It is whether officials will use them consistently, proportionately, and with enough technical precision to survive scrutiny.
Watch the first formal model investigation. Then examine the first corrective order and the treatment of older models approaching August 2027.
Those events will show whether the EU’s framework becomes a working supervisory system or remains mostly a documentation regime. Providers, customers, and developers should prepare for either outcome now.



