Technology · Digital regulation
EU activates enforcement powers over general-purpose AI models with fines up to 3% of turnover
The European Commission can now demand pre-release model evaluations, restrict market access and impose penalties on providers including Anthropic, OpenAI and Google under the AI Act's new supervisory regime.
The European Union's new enforcement powers over general-purpose artificial intelligence models took effect on Sunday, giving the European Commission authority to inspect models before they reach the European market, restrict access for non-compliant providers and impose fines of up to 15 million euros or 3% of annual global turnover, whichever is higher. The move immediately raises the regulatory stakes for American AI laboratories including Anthropic, OpenAI and Google, which now face direct supervisory oversight from the EU AI Office regardless of where they are headquartered.
What the new powers cover
The supervisory and enforcement powers apply specifically to providers of general-purpose AI models, systems trained on broad data at scale that can perform a wide range of tasks. Under the regime, the Commission can demand to evaluate a model before its public release in the EU, request information and documentation, and conduct investigations. Crucially, the fine framework extends beyond substantive breaches of the AI Act's requirements. Refusing an information request, providing misleading answers or blocking a model evaluation are each fineable offences in their own right, a point that legal specialists say is widely underappreciated by the industry.
Henna Virkkunen, the Commission's executive vice-president for tech sovereignty, security and democracy, said in a statement: "Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale." The wording signals that the regulator intends to focus its earliest scrutiny on the most capable systems, where the potential for systemic risk is greatest.
Extraterritorial reach and the authorised representative requirement
The regulation's territorial scope is deliberate. Elisabetta Righini, a partner at the law firm Sidley Austin, told CNBC that "a U.S. address does not put a lab outside the EU regulator's reach." Any provider offering a general-purpose AI model in the EU must appoint an EU-based authorised representative who serves as the regulator's point of contact. That representative can be held liable for the provider's compliance failures, creating a direct legal hook for enforcement against non-European companies.
The requirement mirrors structures used in other EU digital regulations, including the Digital Services Act and the General Data Protection Regulation. For US labs without an existing EU corporate presence, it means establishing a legal entity or contracting a third-party representative before they can lawfully serve European users. The Commission has not published a definitive list of which models fall under the general-purpose definition, but the obligation applies to any model meeting the criteria that is placed on the EU market or put into service there.
Transatlantic friction over tech sovereignty
The activation of these powers arrives amid escalating tension between Brussels and Washington over technology regulation. In July, the Commission fined Google $1 billion for giving preferential treatment to its own services in search results, a decision that prompted US President Donald Trump to threaten "substantial" tariffs against the EU. The AI Act enforcement regime is likely to become a new flashpoint, particularly because it targets the very companies, Anthropic, OpenAI, Google, that dominate the frontier of generative AI development.
European officials frame the push as a matter of tech sovereignty. The bloc has been scrambling to reduce reliance on US systems as geopolitical tensions with the current US administration rise. Virkkunen's portfolio title, tech sovereignty, security and democracy, makes the political objective explicit. The AI Act is intended not only to mitigate risk but to shape the development of AI in a direction compatible with European values and regulatory standards, rather than accepting standards set elsewhere.
The Mythos model and cyber attack allegations
Relations between the EU AI Office and leading labs have already been tested. According to reporting by Reuters on Friday, the Commission sought access to Anthropic's Mythos model for months before the company agreed to share it. The same report stated that the EU is in talks with both OpenAI and Anthropic following recent cyber attacks attributed to their models. OpenAI confirmed it was in contact with the EU AI Office. The Commission and Anthropic have not commented publicly on the Reuters report.
If verified, the cyber attack allegations would represent the first known instance of frontier AI models being directly implicated in malicious cyber activity at a scale that triggers regulatory intervention. The AI Act includes specific provisions for models posing systemic risk, defined partly by the amount of compute used in training. Whether Mythos or OpenAI's models meet that threshold has not been disclosed, but the Commission's persistent demand for access suggests it considers them within scope.
Industry response: cooperation with conditions
OpenAI and Google both issued statements emphasising cooperation. Tom Duff Gordon, OpenAI's vice-president for EMEA policy, said the company has "collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age." A Google spokesperson said the company remains "dedicated to meeting all applicable rules as part of our primary mission: advancing European AI infrastructure and innovation."
Anthropic has not issued a public statement on the new enforcement powers. The company was approached for comment, as were the White House and the US Department of Commerce. The silence is notable given Anthropic's previous reluctance to grant the Commission access to Mythos. Industry observers expect the company to engage through its newly required EU authorised representative, though the identity of that representative has not been made public.
The staggered rollout and what remains uncertain
The enforcement powers activated on Sunday are one element of a phased implementation. The AI Act was adopted in 2024 after protracted negotiations between the Parliament, Council and Commission. Prohibitions on certain AI practices, such as social scoring and real-time biometric identification in public spaces, took effect in February 2025. Requirements for high-risk AI systems in sectors including healthcare, transport and law enforcement begin applying in August 2026. The general-purpose AI model provisions now in force sit alongside transparency obligations for AI-generated content, which apply from August 2026.
Several practical questions remain unresolved. The Commission has not yet published detailed guidance on how model evaluations will be conducted, what benchmarks will be used, or what timeline providers can expect. The Codes of Practice for general-purpose AI models, which are intended to provide a compliance safe harbour, are still being finalised through a multi-stakeholder process. Until they are adopted, providers face regulatory uncertainty about what constitutes sufficient compliance.
Sources
People mentioned
Elisabetta Righini
Organisations
European Commission · European AI Office · Anthropic · OpenAI · Google · Sidley Austin