Skip to content
news11 min read

The EU Can Now Fine GPT, Claude and Gemini's Makers: What Actually Applies on August 2, 2026

On August 2, 2026, the EU AI Act's Article 101 lets the European Commission fine general-purpose AI providers up to EUR 15 million or 3 percent of global turnover. Here is what actually applies, who is on the hook, and what slipped to 2027.

Author
Anthony M.
11 min readVerified July 21, 2026Tested hands-on
EU AI Act GPAI enforcement begins August 2, 2026 — editorial illustration of a glass calendar marked AUG 2 2026, orange scales of justice and an AI model document, with a penalty badge reading EUR 15M / 3%, orange and violet glow on a white background
From August 2, 2026, the European Commission can fine the makers of general-purpose AI models up to EUR 15 million or 3 percent of global annual turnover.

On August 2, 2026, the European Union gains the power to fine the companies behind general-purpose AI models — the makers of GPT, Claude, Gemini, Llama and Mistral. The AI Act's obligations for these models have technically been in force since August 2, 2025, but the European Commission could not impose penalties until now. Under Article 101, fines can reach EUR 15 million or 3 percent of a provider's total worldwide annual turnover, whichever is higher. This is not the entire AI Act switching on: the headline high-risk regime has slipped to December 2027.

Key takeaways

  • August 2, 2026 is the general application date of the EU AI Act and the day Article 101 — the Commission's power to fine general-purpose AI (GPAI) providers — becomes enforceable.
  • GPAI fines can reach EUR 15 million or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher.
  • The obligations themselves — technical documentation, an EU copyright policy, a public training-data summary and downstream documentation — have applied since August 2, 2025. Only the enforcement teeth are new.
  • Unlike most of the Act, GPAI rules are enforced centrally by the European Commission through its AI Office, not by 27 separate national regulators.
  • This is not the AI Act going live in full: the high-risk regime was pushed to December 2, 2027 for standalone systems and August 2, 2028 for embedded ones, while Article 50 transparency duties still apply from August 2, 2026.

What actually changes on August 2, 2026

What changes on August 2, 2026 is enforcement, not the rulebook. The rules for general-purpose AI models have existed since August 2, 2025. What was missing was the Commission's ability to punish non-compliance. Article 101 — deliberately carved out of the 2025 start date — switches on now.

Article 113 of the AI Act sets the regulation's general application date as August 2, 2026 and lists the exceptions to it. Chapter V, which contains the general-purpose AI obligations, applied a year earlier, from August 2, 2025 — but the text says it applied "with the exception of Article 101." That single clause is the whole story. Providers were legally bound by the GPAI rules for a full year, yet the mechanism to fine them for breaking those rules was held back, giving both the industry and the newly created European AI Office time to stand up. That grace period ends now.

From August 2, 2026, the AI Office can escalate along a defined ladder: request documentation and information under Article 91, run technical evaluations of a model under Article 92, order specific measures under Article 93, and — if a provider does not cooperate or does not comply — impose fines under Article 101. In the most serious cases it can restrict or force a model off the EU market entirely, as the AI Office's own guidance on enforcement of Chapter V sets out.

Who counts as a GPAI provider — and who is on the hook

A general-purpose AI model is one trained on broad data at scale that can perform a wide range of distinct tasks and be plugged into many downstream systems — in plain terms, the foundation models that sit behind chatbots and coding copilots. The "providers" on the hook are the companies that develop these models and place them on the EU market: OpenAI (GPT), Anthropic (Claude), Google DeepMind (Gemini), Meta (Llama), Mistral AI, and xAI (Grok), among others.

The reach is deliberately extraterritorial. The Act applies to any provider that places a general-purpose model on the EU market, regardless of where the company is legally established. A model trained in San Francisco or Hangzhou and offered to European users falls squarely in scope. There is no way to serve the EU market and opt out of Chapter V.

A sub-category carries heavier duties. Under Article 51, a model trained using more than 10^25 floating-point operations (FLOP) of compute is presumed to carry "systemic risk" and picks up extra obligations. Most current frontier models sit above that threshold. One important nuance softens the immediate impact: models that were already placed on the market before August 2, 2025 have until August 2, 2027 to reach full compliance, under Article 111(3). The enforcement that begins in 2026 bites hardest on newer models and on ongoing duties like answering the AI Office's requests.

The four core obligations for general-purpose AI providers under Article 53 of the EU AI Act — technical documentation, downstream documentation, an EU copyright policy and a public training-data summary — shown as four glass cards labeled TECH DOCS, DOWNSTREAM INFO, COPYRIGHT POLICY and TRAINING DATA SUMMARY, orange and violet glow on a white background
Article 53 sets four baseline duties for every GPAI provider; systemic-risk models face extra testing and reporting under Article 55.

The four obligations every GPAI provider must meet

Article 53 sets four baseline obligations for providers of general-purpose AI models:

  • Technical documentation. Draw up and keep up-to-date the technical documentation of the model, including its training and testing process, and make it available to the AI Office on request.
  • Downstream documentation. Prepare and maintain information and documentation for the providers who integrate the model into their own AI systems, so those downstream builders can meet their own obligations.
  • Copyright policy. Put in place a policy to comply with Union law on copyright and related rights, including honoring machine-readable rights reservations such as text-and-data-mining opt-outs.
  • Training-data summary. Draw up and make publicly available a "sufficiently detailed summary" of the content used to train the model, following the template published by the AI Office.

Models with systemic risk carry more. Under Article 55, their providers must run model evaluations and adversarial testing (red-teaming), assess and mitigate systemic risks, track and report serious incidents, and ensure an adequate level of cybersecurity. The main practical route to demonstrate compliance is the GPAI Code of Practice, finalized in 2025 as a voluntary instrument; signing it gives providers a presumption of conformity with their obligations. Most major labs signed on, though adherence is voluntary and some declined, as law firm Latham & Watkins documented when the code was published.

How big the fines are — and why the GPAI tier is its own thing

For GPAI providers, the maximum fine is EUR 15 million or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. For a company the size of Google or Microsoft, the percentage is the one that bites — 3 percent of global turnover runs into the billions.

It helps to keep the AI Act's penalty tiers separate, because it is easy to quote the wrong one. The general penalty scheme in Article 99 has three levels: up to EUR 35 million or 7 percent of worldwide annual turnover for using a banned, "prohibited" AI practice; up to EUR 15 million or 3 percent for most other breaches, including high-risk duties; and up to EUR 7.5 million or 1 percent for supplying incorrect, incomplete or misleading information to authorities or notified bodies. For SMEs and start-ups, the lower of the fixed amount and the percentage applies.

GPAI providers, however, sit under their own provision. Article 101 is enforced directly by the Commission rather than by national market-surveillance authorities, and it caps fines at the same EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. The Commission can impose them when it finds a provider intentionally or negligently infringed the regulation, failed to comply with an Article 91 information request or supplied misleading information, ignored a measure requested under Article 93, or refused to give access for an evaluation under Article 92. In setting the amount, it must weigh the nature, gravity and duration of the infringement, and the principles of proportionality and appropriateness.

EU AI Act enforcement timeline — GPAI obligations from August 2, 2025, Commission fines for GPAI providers from August 2, 2026, and high-risk rules from December 2, 2027 — alongside the three penalty tiers EUR 35M / 7 percent, EUR 15M / 3 percent and EUR 7.5M / 1 percent — orange and violet glassmorphism on a white background
The staggered calendar: GPAI obligations in 2025, GPAI fines in 2026, and the high-risk regime in 2027 and 2028.

Why August 2, 2026 is not "the AI Act going live"

The general application date is August 2, 2026, which once meant the marquee high-risk regime would bite the same day. That is no longer true, and the gap matters. The Digital Omnibus — approved by the European Parliament on June 16, 2026 by 423 votes to 57 with 174 abstentions, and formally adopted by the Council of the EU on June 29, 2026 — pushed the high-risk obligations back. Standalone high-risk systems under Annex III, covering areas such as credit scoring, hiring, biometric identification, critical infrastructure and education, now apply from December 2, 2027. High-risk AI embedded in regulated products such as lifts and toys applies from August 2, 2028. We broke down that retreat in our analysis of the 16-month high-risk delay.

So on August 2, 2026, two things actually take effect. The first is GPAI enforcement under Article 101, as described above. The second is the Article 50 transparency regime: providers and deployers must mark AI-generated content and deepfakes, and disclose to users when they are interacting with an AI system rather than a human. Those transparency duties were not delayed by the Omnibus, and the European Commission's own regulatory framework timeline keeps the general date intact for them. Reporting on the Omnibus, including from White & Case, indicates a grace period for machine-readable watermarking of AI content running into December 2026, so the marking rules phase in rather than snap on overnight.

What it means for companies building on these models

If you build products on top of GPT, Claude or Gemini, you are usually a deployer, not the GPAI provider — but the provider's duties reach you through the documentation they must hand over. The practical checklist before August 2, 2026 is short and concrete. Confirm your model vendor has signed the Code of Practice or otherwise complies. Obtain and keep the technical and downstream documentation they are required to provide. Check the public training-data summary and the vendor's copyright posture if you have any intellectual-property exposure. And if your product is user-facing, implement Article 50 transparency now: label AI-generated media and disclose the presence of a chatbot.

There is one trap worth flagging. If you fine-tune or substantially modify a general-purpose model, you can become a provider yourself for the modified model, inheriting the Article 53 obligations for the change you made. The line between deployer and provider is drawn by what you do to the model, not by your size, and the AI Act's staggered implementation timeline gives no exemption for that.

The bigger picture: enforcement in a fragmenting world

The paradox of 2026 is that Brussels switched on binding, centrally enforced obligations for foundation-model makers in the same season it softened its own high-risk regime under industrial and US pressure. The EU is now the first jurisdiction where a missing training-data summary or an ignored documentation request can escalate into a nine- or ten-figure fine — even as it hands the more contentious high-risk rules an extra 16 months.

Elsewhere, the direction of travel is the opposite. In the United States, lawmakers have been pushing to override the patchwork of state AI laws with a single federal standard, as we covered in the Great American AI Act. Internationally, coordination remains thin: the first attempt at a shared forum, which we reported on in the UN's first global AI governance dialogue, can convene but cannot compel. Against that backdrop, the EU's Article 101 is the rare instrument with real teeth. Whether the Commission wields it aggressively in year one or holds fire while the ecosystem adjusts is the open question that August 2, 2026 leaves on the table.

Frequently asked questions

What changes under the EU AI Act on August 2, 2026?

Enforcement, not the rules themselves. The general-purpose AI (GPAI) obligations have applied since August 2, 2025, but the European Commission could not fine providers for breaking them. From August 2, 2026, Article 101 becomes applicable, giving the Commission the power to open proceedings and impose fines on GPAI providers of up to EUR 15 million or 3 percent of worldwide annual turnover.

How much can the EU fine a general-purpose AI provider?

Under Article 101, up to EUR 15 million or 3 percent of the provider's total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, the lower of the two figures applies. The amount is set by weighing the nature, gravity and duration of the infringement, alongside proportionality.

Is August 2, 2026 the day the entire EU AI Act takes effect?

No. It is the Act's general application date, but the headline high-risk regime was pushed back by the Digital Omnibus. Standalone high-risk systems now apply from December 2, 2027 and embedded ones from August 2, 2028. What actually takes effect on August 2, 2026 is GPAI enforcement under Article 101 and the Article 50 transparency duties.

Which companies count as general-purpose AI providers?

The developers that place foundation models on the EU market: OpenAI (GPT), Anthropic (Claude), Google DeepMind (Gemini), Meta (Llama), Mistral AI and xAI (Grok), among others. The obligations attach to whoever provides the model, and they apply regardless of where the company is established, so US and Chinese labs serving European users are in scope.

What are the four obligations for GPAI providers under Article 53?

Keep up-to-date technical documentation of the model, including its training and testing; provide documentation to downstream providers who integrate the model; put in place a policy to comply with EU copyright law; and publish a sufficiently detailed summary of the content used for training. Models with systemic risk add testing, risk mitigation, incident reporting and cybersecurity duties under Article 55.

Weren't GPAI providers already subject to these rules before August 2026?

Yes. Chapter V of the AI Act, which contains the GPAI obligations, applied from August 2, 2025 — but Article 113 explicitly excluded Article 101 from that date. So the duties were binding for a year while the fining mechanism was held back. Models placed on the market before August 2, 2025 also have until August 2, 2027 to reach full compliance.

Who enforces the fines against GPAI providers?

The European Commission, through its AI Office, enforces the GPAI rules centrally under Article 101 — not the 27 national market-surveillance authorities that handle most of the Act. The AI Office can request information (Article 91), evaluate a model (Article 92), order measures (Article 93), impose fines (Article 101), and in serious cases restrict or withdraw the model from the EU market.

What is a GPAI model "with systemic risk"?

Under Article 51, a general-purpose model is presumed to carry systemic risk when the cumulative compute used to train it exceeds 10^25 floating-point operations (FLOP). Most current frontier models exceed that threshold. Such models face additional obligations under Article 55, including adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity.

Does the AI Act apply to US-based providers like OpenAI, Google and Anthropic?

Yes. The Act's reach is extraterritorial: it applies to any provider that places a general-purpose AI model on the EU market, regardless of where the company is legally established. A US or Chinese lab offering its model to European users must meet the Article 53 obligations and is exposed to Article 101 fines from August 2, 2026.

What happened to the high-risk AI rules that were due in August 2026?

They were delayed. The Digital Omnibus, approved by the European Parliament on June 16, 2026 and adopted by the Council on June 29, 2026, moved standalone high-risk obligations to December 2, 2027 and high-risk AI embedded in regulated products to August 2, 2028. The change simplifies and defers the high-risk regime without repealing it.

Do the transparency rules for deepfakes and chatbots apply on August 2, 2026?

Yes. The Article 50 transparency duties — marking AI-generated content and deepfakes, and disclosing to users when they are interacting with an AI system — apply from August 2, 2026 and were not delayed by the Omnibus. Reporting indicates a grace period for machine-readable watermarking of AI content runs into December 2026, so the marking rules phase in.

What should companies using GPT, Claude or Gemini do before August 2, 2026?

Confirm your model vendor complies with the Code of Practice, collect the technical and downstream documentation they must provide, review the training-data summary and copyright posture if you have IP exposure, and implement Article 50 transparency in any user-facing product. If you fine-tune or substantially modify a model, be aware you may inherit provider obligations for the modified version.

Sources

Related Articles

Was this review helpful?
Anthony M. — Founder & Lead Reviewer
Anthony M.Verified Builder

We're developers and SaaS builders who use these tools daily in production. Every review comes from hands-on experience building real products — DealPropFirm, ThePlanetIndicator, PropFirmsCodes, and many more. We don't just review tools — we build and ship with them every day.

Written and tested by developers who build with these tools daily.