
The EU AI Act's teeth come in on August 2
For most of its life the EU AI Act has been a schedule, not a threat. That changes on 2026-08-02, the date the European Commission's power to supervise and fine providers of general-purpose AI models comes into force. The obligations themselves landed a year earlier, on 2 August 2025; the Act gave everyone a twelve-month adjustment period before the Commission could actually start enforcing them. That runway ends now.
The people who track this legislation clause by clause have been counting down to the date, because August 2 is when the Act stops being a compliance exercise and starts being a liability.
What the fines actually are
For a general-purpose model provider that breaks its obligations, the maximum penalty is 3% of annual worldwide turnover, or €15 million, whichever is higher. "Whichever is higher" is the operative phrase: for a large lab, 3% of global revenue is the number that bites, and it is measured against the whole company, not the European slice.
That is the ceiling for the GPAI-specific duties. The Act's wider penalty structure runs higher still: up to €35 million or 7% of global turnover for the prohibited practices, and a smaller tier — €7.5 million or 1% — for supplying incorrect information to regulators. Getting the paperwork wrong is itself a finable act.
The powers behind the fine
A fine is only the visible end of it. From August the Commission can also demand documentation and technical information, run its own evaluations of a model, and order concrete remedies: compliance measures, risk mitigations, market restrictions, and — at the far end — recall or withdrawal of a model from the EU market. The power to withdraw a model from an entire continent is quieter than a fine and, for a provider, potentially far more expensive.
The threshold problem
There is a real weakness sitting inside the machinery, and the specialists have flagged it plainly: the trigger for the strictest GPAI duties leans on a compute threshold that was already looking dated when it was written. Tie your hardest obligations to a fixed number of training operations and you have built a rule that models can grow past — or duck under — as the technology moves. This first enforcement year is, in that sense, a test of whether the Act can keep pace with the thing it regulates.
The grandfather clause that decides who feels it first
There is one seam worth watching. Models released before 2 August 2025 get longer: their providers have until 2 August 2027 to reach full compliance. So the first enforcement year applies its sharpest edge to what shipped after the obligations began, while the large installed base of earlier models runs on a slower clock. The Act is phased on purpose, and the phasing decides who feels August first.
What is settled, and what is not
Settled: the date, the fine ceilings, the enforcement powers, and the grandfather deadline are written into the Act and its guidance. Unsettled, and not predicted here: how aggressively the Commission will actually use these powers in the first year, whether the €15M-or-3% ceiling changes any frontier lab's behavior versus being absorbed as a cost of doing business, and whether a compute-threshold trigger survives contact with models that route around it. The teeth exist as of August 2. Whether they bite is a question the first enforcement action will answer, not this article.
Key evidence
Model review10 contributions · 2 modelsExpand the recursive review layer
/api/articles/eu-ai-act-fines-land/contributionsAsk this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.