Since 2 August 2026, the European Commission's AI Office is no longer a standards-writing body watching a calendar — it is a regulator with the power to investigate and fine. That date did not add a new obligation to the EU AI Act; it activated the enforcement machinery behind obligations that, for general-purpose AI (GPAI) providers, have already applied for a year.

This post is about what changed in the AI Office's authority, not about deadlines. For the full Annex III / Annex I compliance-deadline picture — what moved and what didn't in the Digital Omnibus — see our omnibus explainer; the deadline table lives there, not here.

What actually changed on 2 August 2026

2 August 2026 is when the Commission and AI Office gained the legal authority to enforce GPAI and prohibited-practice obligations with real consequences, not when any new duty came into force. Until that date, GPAI providers had substantive obligations to meet but the Commission lacked the fining power to act on non-compliance; from that date, it has it.

This is a mechanics change, not a scope change. The obligations a GPAI provider must meet did not change on 2 August 2026 — the full engineering-oriented obligation set is covered in the EU AI Act explained for engineering teams. What changed is that the Commission can now investigate whether a provider is meeting them, and act if it is not.

The five things the Commission/AI Office can now do

Per the enforcement provisions taking effect 2 August 2026, the AI Office can: request documentation from a GPAI provider; run its own technical evaluations of a model; demand risk-mitigation measures where it finds a gap; restrict or withdraw a model from the EU market; and issue fines. Four of those five are investigative or corrective — only the fifth is punitive, and it's the one most compliance teams fixate on.

Power What it does
Request documentation Compels a GPAI provider to produce technical documentation supporting its compliance position
Run technical evaluations Lets the AI Office independently assess a model rather than rely solely on provider self-reporting
Demand risk-mitigation measures Requires specific corrective action where the AI Office finds a gap
Restrict or withdraw a model Can limit or remove a model's availability in the EU market
Issue fines Financial penalty, up to the ceilings below, for established violations

That ordering matters operationally. A provider under scrutiny is more likely to first receive a documentation request or face a Commission-run technical evaluation than an immediate fine notice — the design leans toward investigate-then-escalate rather than fine-on-first-contact. Treat a documentation request as the live signal to respond to; it is the step that actually starts an enforcement cycle under this regime, well before a fine becomes a live possibility.

The fine ceilings: up to €15M or 3% for GPAI, up to €35M or 7% for prohibited practices

GPAI provider violations are fineable up to the higher of €15 million or 3% of worldwide annual turnover; prohibited-practice violations — the unacceptable-risk category the Act has banned outright since February 2025 — are fineable up to the higher of €35 million or 7% of worldwide annual turnover. Both figures use "the higher of," which is the detail most summaries drop: for a large GPAI provider, 3% of global turnover is very likely to exceed €15 million, so the real ceiling scales with company size rather than capping out at the flat euro figure.

The gap between the two ceilings — 3% vs. 7% — reflects the Act's risk-tier structure: prohibited practices sit above GPAI obligations in severity, and the fine ceiling is roughly double.

Violation category Fine ceiling
GPAI provider obligations Higher of €15 million or 3% of worldwide annual turnover
Prohibited practices (unacceptable-risk uses) Higher of €35 million or 7% of worldwide annual turnover

Neither figure is a routine expectation; both are the maximum the Commission can impose after establishing a violation, not a default penalty applied automatically. For most organizations, the more useful planning exercise is not estimating what a fine could theoretically reach, but confirming which category — GPAI provider or deployer of a system that could implicate prohibited-practice rules — actually applies to what you've built, since the two ceilings and the obligations behind them are not interchangeable.

Retroactivity: obligations that have applied since August 2025

GPAI providers' substantive obligations have applied since August 2025 — a full year before the Commission could fine anyone for failing to meet them. That gap between "the rule applies" and "the rule is enforceable by fine" closed on 2 August 2026, and it closed retroactively: the enforcement power that activated on that date reaches conduct governed by obligations already in force during that prior year, not only conduct going forward from 2 August 2026.

Practically, a GPAI provider that treated August 2025-to-August 2026 as a compliance grace period was correct that fines weren't possible yet, but wrong if it read that as meaning the obligations themselves were optional. Documentation and evaluation gaps that opened during that first year are now within scope for an AI Office inquiry.

What this means for agent deployers who are not GPAI providers

If you deploy agents built on top of GPAI models rather than provide a GPAI model yourself, the enforcement mechanics above aren't aimed at you directly — but they aren't irrelevant either. First, an AI Office restriction or withdrawal action against an underlying model is a supply-chain risk for anything you've built on it: a governance program that can show why a specific model was selected, and can substitute or roll back quickly, is now hedging against a live regulatory tool rather than a hypothetical one, not a purely theoretical scenario. Second, deployer-side obligations — transparency, registration, and on a later timeline, high-risk conformity duties — run on separate provisions from the GPAI enforcement powers described here; a compliance checklist that tracks your own obligations by article, rather than by GPAI-specific headlines, keeps the two straight.

Third, and easy to overlook: a documentation request or technical evaluation aimed at a model provider can pull deployer-side evidence into scope indirectly, if the AI Office's inquiry touches how the model is actually being used in production. A deployer that already has clean records of what agent, what model version, and what configuration was live at a given time isn't just meeting its own transparency duties — it's also the party best positioned to answer quickly if a question arrives secondhand, through the provider, rather than directly.

What the Digital Omnibus did and did not move

The Digital Omnibus — Regulation 2026/1744, in force since 27 July 2026 — deferred the Annex III standalone high-risk conformity obligations and the Annex I obligations for AI embedded in regulated products; it did not touch the GPAI enforcement date or the fine ceilings described above. GPAI enforcement and high-risk conformity deadlines are separate tracks in the Act, and the Omnibus moved only the second one. As of August 2026, the regulation's implementing and delegated acts are still pending, so treat the mechanics in this post as the current legal position, not a fully settled one.

What to do with this now

No confirmed fine or enforcement action under these powers has been reported as of August 2026 — the AI Office gained a capability, not a track record. That's a reason to prepare, not to relax: a regulator's earliest actions after enforcement powers activate tend to set the pattern for what it actually prioritizes, and a provider that comes under review will have had months of warning that the powers existed. If you provide a GPAI model, your documentation and evaluation posture should already assume an AI Office request could arrive. If you deploy on top of one, your governance program should track which upstream models you depend on and how quickly you could respond to a supply-side disruption.

Common questions

Has the EU AI Office issued any fines yet? Not that has been publicly confirmed as of August 2026. The Commission and AI Office gained the legal power to fine GPAI and prohibited-practice violations on 2 August 2026; no confirmed fine or enforcement action under that power had been reported as of this writing.

Does the 2 August 2026 enforcement date apply to high-risk systems under Annex III? No — that's a separate track. Annex III high-risk conformity obligations were deferred to 2 December 2027 by the Digital Omnibus. The enforcement powers described here apply to GPAI provider obligations and prohibited-practice violations, both already in force before 2 August 2026 and made fineable on that date.

What is the fine for a GPAI provider that violates its obligations? Up to the higher of €15 million or 3% of worldwide annual turnover. Prohibited-practice violations carry a higher ceiling: up to the higher of €35 million or 7% of worldwide annual turnover.

If GPAI obligations applied since August 2025, why weren't providers fined during that first year? Because the obligations being in force and the Commission having fining power are two different things. The substantive GPAI obligations applied from August 2025, but the AI Office's authority to fine violations of them only activated on 2 August 2026 — retroactively covering conduct from that entire prior period, not just conduct going forward.

Is my organization a GPAI provider, or a deployer? That distinction determines which obligations and which enforcement track apply to you, and it's worth confirming explicitly rather than assuming. If you build and release a general-purpose AI model, GPAI provider obligations and the enforcement powers in this post apply to you directly. If you build agents or applications on top of a model someone else provides, you're a deployer — subject to a different, and in some respects later, set of obligations under the Act, covered in the EU AI Act explained for engineering teams.