AI Office Gains Enforcement Powers and Places OpenAI, Anthropic, and Google Under the AI Act's Scrutiny

The European Commission can now inspect models, restrict the European market, and impose fines of up to 3% of global revenue. Meta remains outside the Code of Practice.
On August 2, the European Union activated the enforcement powers outlined in the AI Act for general-purpose models, ending the one-year grace period granted to big tech companies. From now on, the AI Office, a branch of the European Commission based in Brussels, can request technical documentation, conduct independent assessments on models, restrict or remove systems from the European market, and impose fines of up to €15 million or 3% of global annual revenue, whichever is greater.
The rule applies to any provider offering a general-purpose model in the EU, regardless of the company's headquarters. This includes OpenAI, Anthropic, Google, Mistral, xAI, and Meta, as well as European and Chinese suppliers. Providers of models deemed to be of "systemic risk" face additional obligations covering large-scale cyber threats and risks to fundamental rights.
The Code of Practice Becomes a Line of Demarcation
The Commission published the Code of Practice for GPT in July 2025, a voluntary but express pathway to comply with the AI Act. Google, Microsoft, OpenAI, Anthropic, and Mistral signed on. Meta refused, arguing that the text "goes beyond the AI Act," particularly regarding dataset documentation requirements and copyright filters. The decision places the company in a precarious position: without the procedural shortcut of the code, each obligation of the AI Act must be demonstrated independently, under the watch of a regulator that now has teeth.
The litmus test came before the effective date itself. OpenAI and Anthropic disclosed in the last two weeks that their models escaped from testing environments and accessed third-party production systems, including Hugging Face. According to Business Standard, the AI Office has already opened formal discussions with the two companies to understand what occurred. This is not an investigation under the new powers yet, but it illustrates how the standards will be applied: the Commission will demand detailed technical explanations when a model behaves unexpectedly in production.
Article 50 Reaches Those Building on APIs
The transparency obligations of Article 50 also come into effect, requiring AI systems to identify themselves as such when interacting with humans and that synthetic content be labeled in a machine-readable format. The rule has a direct impact on those building products on third-party APIs: the duty falls on the deployer, not the model provider. A bank using Claude or GPT-5 for a customer service chatbot must ensure labeling on its own and cannot delegate that responsibility to Anthropic or OpenAI.
For the CIOs of global banks and consultancies, the real cost of the AI Act will not be the 3% fine, but the operational compliance: inventory of AI systems in use, risk assessments per use case, contracts reviewed to pass on obligations to suppliers, and an audit trail that withstands inspection. The Big 4 have been selling the "AI Act readiness" package for months; now the demand transitions from an architectural project to the board agenda.
Market Readings
The fact that the largest providers are American transforms the AI Act into a line of commercial conflict. The White House has been publicly critical of European rules, viewing them as obstacles to American companies' competition. For OpenAI, Anthropic, and Google, withdrawing from the European market is off the table: all three have publicly described efforts to comply with the Code of Practice and the documentation required by the AI Office.
In Germany, the concern is different. SAP, Deutsche Telekom, and Siemens embed American models in products sold globally and now carry downstream compliance obligations for every use case deployed in the EU. The window of regulatory instability extends until August 2, 2027, when obligations for high-risk systems will also come under scrutiny. In Japan, MUFG and Mizuho accelerated partnerships with Anthropic and OpenAI for internal cases in the first half of the year, and now observe the European model as a reference for the local regulatory agenda that the FSA has been discussing since last year.
The European Commission knows that the first case will set the tone for enforcement. A symbolic fine on a smaller provider would signal accommodation; a heavy investigation against OpenAI or Google would show a willingness to engage. The timeline works in Brussels' favor: by August 2027, obligations for high-risk systems will also be under scrutiny, and the AI Office will have built sufficient jurisprudence to act at scale.