EU prepares to regulate powerful AI models

The European Union is set to enforce sweeping new powers on Sunday to police large general purpose AI models, the versatile systems that power chatbots, image generators and enterprise tools. Starting August 2, the Commission can demand information from model providers, conduct safety evaluations, order corrective measures, pull models off the EU market and impose fines of up to 3% of annual total turnover.
Who is subject to the rules?
The rules target providers of the largest models rather than the businesses that deploy those models downstream. The threshold for models deemed to pose systemic risk is so high that only a handful of companies, such as the U.S.’s OpenAI, Anthropic, Meta, Alphabet, xAI and China’s Alibaba, ByteDance and Z.ai, are expected to fall within scope. France’s Mistral is the only European model provider that should fall under the law.
Because the enforcement authority will be concentrated in the hands of the AI Office, the practical application of these powers may hinge on political will. If the Commission hesitates, it reinforces criticism that the EU writes laws better than it makes powerful companies follow them. The AI Office must also manage the expectations of a market dominated by U.S. and Chinese giants, while trying to enforce standards that could conflict with those countries’ regulatory approaches.
Infrastructure for enforcement is already in place. The AI Office has published a Code of Practice, issued guidelines, established an advisory forum and partnered with independent evaluators like FAR.AI and Epoch AI. But a February report by Pour Demain estimated the unit supervising general purpose AI would need 160 staff by 2030, yet as of July it had only about 40. Without rapid recruitment and administrative flexibility, the office may struggle to keep pace with the rapid development of the technology it is meant to regulate.
Related Post: Europe’s utility spending spree reshapes credit risk
Obligations under the AI Act for the largest, most powerful models are governed by Article 55 of the AI Act, which requires companies to perform state-of-the-art model evaluations, assess and mitigate systemic risk, report serious security incidents, and ensure appropriate cybersecurity protection. The AI office has already built much of the infrastructure needed to enforce the rules, including publishing the Code of Practice, issuing guidelines for model providers, and establishing an AI Act Advisory Forum to assist with enforcement.
Enforcement and Challenges
The AI Office may face challenges in enforcing the law, particularly with regards to personnel. Pour Demain has argued that the AI Office needs more administrative flexibility, competitive salaries, and fast-tracked recruitment to attract more talent. The AI Office’s first enforcements are unlikely to involve blockbuster fines, but rather requests for information, structured dialogue with model providers, and independent evaluations.
Companies that refused to sign the Code of Practice may face closer scrutiny, including U.S.-based model providers such as Meta and xAI. The AI Office may also watch closely the companies with the “highest impact capabilities” that are “proving dangerous,” such as OpenAI and Anthropic, which have sparked concerns about emerging cyber capabilities and loss of human control.
The AI Office’s success will depend on avoiding politicization, prioritizing the largest safety risks, and being adaptable to rapid technological changes. With international support from countries such as the U.S. and China, which are also advancing their own AI rules, the EU is well-positioned to lead on global AI governance. As Risto Uuk noted, “Europe should not feel entirely alone in this,” and the geopolitical tide is turning towards greater regulation of these frontier models, with Chinese President Xi Jinping stating his desire for China to lead on global AI governance in July. The AI Office will begin its enforcement efforts on August 2, marking a significant milestone in the EU’s efforts to regulate general purpose AI models.