Lead Analysis
Regulation6 min

European AI Office Gains Power to Fine €15 Million and Begins Regulating GPAI Suppliers

Fachada do Berlaymont em Bruxelas ao entardecer com bandeiras da União Europeia e uma figura solitária atravessando a praça com documentos

Starting August 2, the European Commission can request technical documentation, assess models, and impose fines of up to 3% of global revenue on general-purpose AI suppliers that fail to comply with the AI Act.

The AI Office of the European Commission has, as of August 2, obtained formal authority to investigate and sanction suppliers of general-purpose AI (GPAI) models under the AI Act. This marks a regulatory turning point: while substantive obligations have been in effect since August 2025, the European executive did not previously have an enforcement tool to compel compliance.


The fine ceiling rises to €15 million or 3% of the group's global revenue, whichever is greater. The text outlines three scenarios that trigger penalties: non-compliance with GPAI obligations, provision of incorrect or misleading information to the regulator, and refusal to cooperate with requests or assessments from the AI Office.


"By starting the oversight, we take an important step towards an AI that people and businesses can understand and trust," stated Henna Virkkunen, Executive Vice President of the Commission for technological sovereignty, security, and democracy. This statement is official and signals the declared intention, but the practice in the first year is expected to differ: the AI Office has already indicated that the initial instrument will be "technical compliance dialogues," preliminary discussions with the supplier before any formal sanction procedure.


Who is Exposed


Models released to the market starting August 2, 2025, are already subject to the regime, which includes Gemini 3, Grok 5, Llama 5, GPT-6, and the latest generations of Claude and Mistral. Models released prior to this date have until August 2, 2027, to comply. For corporate buyers, the takeaway is that virtually every top-tier model in production today is subject to oversight from now on.


The most immediate new obligation is Article 50, which mandates transparency: chatbots must identify themselves as AI at the start of interactions, and content generated or manipulated by AI (including deepfakes) must carry a machine-readable label. This affects service, marketing, and automation flows that many companies operate without explicit signaling.


A Healthy Skepticism


Cornelia Kutterer, a lawyer and former Microsoft employee now researching AI governance at the Jacques Delors Institute, has argued that the AI Office is still under-resourced to effectively oversee the portfolio of models that has been handed to it. The European team has fewer than 100 dedicated professionals. On the other hand, industry associations like CCIA Europe have already requested an additional transition phase, arguing that the Code of Practice published in July 2025 left gray areas concerning copyright, systemic risk assessment, and training data transparency. Neither of these criticisms undermines the enforcement authority that the August 2 date has just unlocked.


What Changes for Those Operating in Europe


Those deploying GPAI models in products in the European Single Market must now have three documents on file, which the AI Office may request without prior notice: a summary of training data in the format of the Commission's template, technical documentation compatible with Annex XI of the AI Act, and an internal compliance policy with the Copyright Directive. A supplier that fails to present these documents will not receive an automatic fine but will enter the "technical dialogue" queue with the regulator. Recidivism or bad faith triggers the €15 million penalty.


Market-by-Market Analysis


For American hyperscalers, the impact is more operational than financial. OpenAI, Anthropic, and Google DeepMind have already been restructuring policy teams in Brussels throughout 2025, and the Code of Practice has been signed by nearly all major suppliers (Meta was the most notable exception). The real risk lies in a first exemplary fine that could set a precedent, likely in a case of training without the appropriate summary, rather than a broad wave of sanctions.


In Japan and the UK, both of which have lighter, principles-based regulatory approaches, the European standard has no direct effect but creates spillover pressure: a European multinational operating in Tokyo or London tends to extend the same internal controls to other markets for compliance standardization. This is the same effect that GDPR has created. In Brazil, the LGPD framework already covers part of the data concerns, but the Brazilian version of a general-purpose model oversight regime still depends on Bill PL 2338/2023, which has been in Congress since 2023 without a firm timeline. Meanwhile, the Brazilian company exporting services to Europe inherits Brussels' standards by contract, not by local law.

Lead Analysis