The EU AI Office Can Now Enforce: What Its Powers Actually Are
The obligations on providers of general-purpose AI models under the EU AI Act have applied since August 2025. What was missing was the ability to do anything about a provider that ignored them.
That changed on 2 August 2026. From that date the European Commission, acting through the AI Office, can exercise investigation and enforcement powers over general-purpose AI providers, alongside the rules on prohibited practices. The Commission’s announcement of the enforcement start and its enforcement framework page are the primary sources.
Most coverage of this has been aimed at the model providers. It is more useful to read it from the buyer’s side, because the enforcement regime is what makes the paperwork you request from vendors actually obtainable.
The Powers, In Plain Terms
Four capabilities matter.
Request information and documentation. The AI Office can require a provider to produce technical documentation, training data summaries, and evidence of compliance.
Obtain access to a model for evaluation. This is the unusual one. A regulator can require access to the model itself for testing, not just paperwork about it.
Require corrective or risk-mitigation measures. Including, in principle, restricting or withdrawing a model from the EU market.
Fine. For general-purpose AI provider obligations, up to the higher of 15 million euros or 3 percent of worldwide annual turnover. Other parts of the Act carry higher ceilings for prohibited practices.
Note the shape: this is a regulator that can look inside the product, not only at the compliance file around it. That is a stronger instrument than most technology regulation.
Why This Helps You As A Buyer
If you have ever tried to get a straight answer out of an AI vendor about training data, retention, or subprocessors, you know the pattern. You ask a specific question and receive a paragraph about how seriously they take security.
Enforcement changes the incentive. A provider that must be able to produce documentation for a regulator has a much easier time producing a subset of it for a customer, because it already exists. Before enforcement powers existed, “we do not share that” was cost-free.
Practically, this means the questions in how to audit an AI vendor in 2026 are more likely to get answers now than they were a year ago. Ask for the documentation the provider maintains under its GPAI obligations rather than asking open questions, because a named artifact is harder to deflect than a general enquiry.
What It Does Not Mean For An Ordinary Business
Three clarifications, because the anxiety runs ahead of the text.
You are almost certainly not a GPAI provider. These obligations attach to the entities that develop and place general-purpose models on the market. Using an AI tool to write emails does not make you one, and neither does fine-tuning a small model for internal use in most configurations.
The high-risk obligations were deferred. The mid-2026 simplification package pushed the high-risk system duties out, while leaving the August 2026 date intact for transparency and enforcement. That produced widespread confusion about what actually applies now, which we untangled in what changes under the EU AI Act on 2 August 2026.
Article 50 transparency does apply to deployers in specific cases. Chatbots that interact with people, and synthetic content that needs machine-readable marking, are the main ones. Using AI to help write an email you then send yourself is not the target. The detail is in AI disclosure obligations in 2026.
The Work That Is Actually Worth Doing
Not a compliance program. An inventory and two documents.
An inventory. Which AI tools are in use, for what categories of text, and where each one processes data. Most organizations discover during this exercise that the list is longer than anyone believed, which is the shadow AI problem covered in how to run an AI tool audit for your team.
A one-page decision record. What you decided, why, on what date, and when you will review it. Regulators and clients both ask what you decided and when. An organization that can produce a dated record is in a completely different position from one reconstructing its reasoning afterwards. The format is in how to write a decision log entry.
A short answer for clients. Because they will ask, and the enforcement news gives them a reason to.
Before:
We take AI compliance very seriously and are fully compliant with all applicable regulations including the EU AI Act. Our vendors are all certified and we have robust processes in place.
After:
We use AI tools for drafting and editing internal and client correspondence. Confidential client text is processed by a model running locally on the author’s machine and is not transmitted.
For non-confidential drafting we use a hosted provider, listed in our subprocessor schedule.
A named person is accountable for these decisions and the position was last reviewed on 4 August 2026.
The second version is specific, checkable, and does not claim compliance with anything. “Fully compliant” is a claim a client’s counsel will test, and it is unnecessary: what they want is to know what you do.
A Wrivio Context for compliance answers could say:
Rewrite this as a precise, factual compliance answer for a client. Neutral register, complete sentences. Keep every regulation name, date, vendor name, and technical detail exactly as written. Do not add claims of certification or compliance, do not generalize a specific statement, and do not add reassurance that is not in the original.
Press Ctrl+Shift+Space, paste the draft, and check the diff. Watch specifically for the rewrite inserting “fully compliant” or “certified”, which models add because the register invites it and which create liability you did not intend.
The Honest Uncertainty
How aggressively these powers get used is not knowable in August 2026. Regulators with new instruments typically start with the largest providers and the clearest violations. Enforcement practice will take a year or more to become legible.
Date-stamp your position, review it, and do not buy a compliance product on the strength of a deadline that has already passed.
Common Questions
Does the AI Act apply to my company if I only use AI to write emails?
The general-purpose AI provider obligations do not. Some Article 50 transparency duties can apply to deployers in specific situations such as chatbots and synthetic media, but drafting assistance you review and send yourself is not the target.
What are the maximum fines?
For general-purpose AI provider obligations, the higher of 15 million euros or 3 percent of worldwide annual turnover. Prohibited practices carry a higher ceiling.
Do I need to be established in the EU for this to matter?
The Act reaches providers placing models on the EU market and, in some cases, use whose output is used in the EU. If you sell into the EU, it is worth a proper look rather than an assumption.
What single document should I produce this month?
A dated inventory of which AI tools process which categories of text and where. Everything else is easier once that exists.
Download Wrivio for Windows to keep client-confidential text on the author’s machine, which is the simplest answer to most of these questions.
Read Next
US State AI Rules Are Now the Harder Compliance Problem
Colorado delayed, California finalized, Illinois took effect. A patchwork of state AI employment rules is now the practical constraint for US employers.
What Changes Under the EU AI Act on 2 August 2026
Transparency obligations, general-purpose AI enforcement, and the full penalty regime take effect. High-risk duties were deferred. What applies to an ordinary business using AI writing tools.
The EU AI Act Digital Omnibus: What the Delay Actually Bought
High-risk obligations moved to December 2027 and August 2028. Why the deferral happened, what it changes, and why treating it as breathing room is the wrong reading.
Google's Cheap Gemini Tier Got Serious: What Flash Models Mean for Writing
Three new Gemini models shipped in July 2026, all in the cheap and fast tier, none a new Pro. Why the workhorse tier is where the useful work now happens.
This article is filed underPrivacy & Compliance, which has 53 articles.