GPAI enforcement: a year of duties, and now the power to fine

GPAI enforcement: EU AI Act Article 101 fining powers begin 2 August 2026

In short: GPAI enforcement begins on 2 August 2026, when the European Commission gains power under Article 101 of the EU AI Act to fine providers of general-purpose AI models up to 3% of worldwide annual turnover or 15 million euros, whichever is higher. The duties in Articles 53 to 55 have applied since 2 August 2025.

By Rob Bratby, Managing Partner, Bratby Law. Lexology Global Elite Thought Leader for Data Protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A UK company that puts a general-purpose AI model on the EU market has spent a year subject to duties that carried no penalty. GPAI enforcement starts on 2 August 2026. The European Commission announced on 31 July 2026 that its AI Office would begin enforcing the EU AI Act, Regulation (EU) 2024/1689, from that date, using powers in Chapter IX that did not exist for the first year of those duties.

The obligations that have applied since August 2025

Providers of general-purpose AI models have been subject to the documentation, transparency and copyright duties in Articles 53 to 55, set out in Chapter V of the EU AI Act, since 2 August 2025 under Article 113. Under Article 53(1) every provider must keep technical documentation, give downstream providers the information set out in Annex XII, operate a copyright policy that identifies and complies with rights reservations expressed under Article 4(3) of the Copyright in the Digital Single Market Directive, and publish a sufficiently detailed summary of the content used to train the model, following a template the AI Office provides.

A provider established outside the EU must also appoint an authorised representative in the Union by written mandate under Article 54, before it places the model on the market. Providers of models with systemic risk must in addition evaluate the model, mitigate systemic risk, report serious incidents and protect the model’s cybersecurity, under Article 55. A model whose cumulative training compute exceeds 1025 floating point operations is presumed under Article 51(2) to have high impact capabilities. Until a harmonised standard is published, providers may rely on the General-Purpose AI Code of Practice to demonstrate compliance.

What GPAI enforcement means from 2 August 2026

The European Commission enforces the Articles 53 to 55 duties. Under Article 88(1) it holds exclusive supervisory and enforcement powers over general-purpose AI models and must entrust those tasks to the AI Office, so no national market surveillance authority takes the lead. The AI Office may require documentation and information under Article 91, and may evaluate a model under Article 92, including through access by application programming interface or to source code. Under Article 93 it may require compliance measures, risk mitigation, or restriction, withdrawal or recall. Under Article 101 the Commission may fine a provider up to 3% of worldwide annual turnover or 15 million euros, whichever is higher, where it finds the provider acted intentionally or negligently.

The co-legislators applied the Articles 53 to 55 duties from 2 August 2025 under Article 113 but expressly excepted Article 101, and never brought Chapter IX, which contains Articles 88 to 94, forward at all, so none of those powers existed before 2 August 2026. The Commission stated the position in its guidelines for providers of general-purpose AI models of 19 November 2025: “In the first year from 2 August 2025 onwards, the Commission cannot take any enforcement actions because its enforcement powers only enter into application on 2 August 2026.” In the same paragraph it states that from 2 August 2026 it will fine providers who are not fully compliant on that date. A provider that has not complied since August 2025 must therefore be compliant on 2 August 2026, the day GPAI enforcement starts.

The scientific panel of independent experts under Article 68, which the Commission constituted at 60 members by Commission Implementing Regulation (EU) 2025/454, may issue a qualified alert under Article 90 where a model poses a systemic risk at Union level. A downstream provider may lodge a reasoned complaint under Article 89(2), and the Commission announced a complaint tool, a whistleblower channel and a downstream-provider route on 31 July 2026.

Which UK businesses are within scope of GPAI enforcement

Under Article 2(1)(a) the EU AI Act applies to providers placing general-purpose AI models on the Union market, irrespective of whether they are established in the Union or in a third country. Under Article 2(1)(c) the Regulation applies to third-country entities whose output is used in the Union, but only in respect of AI systems, not models. A UK model provider is therefore within scope of GPAI enforcement only if it places the model on the Union market. A business told that EU-consumed output alone brings its model within the Articles 53 to 55 duties has been given the AI system test, not the model test.

Under the Commission’s guidelines a provider places a model on the Union market where it supplies the model through an application programming interface, a software library, a public model hub, a cloud service or an app store. On that reading a UK provider that ships no weights and serves inference from London to callers in Dublin has placed the model on the Union market, and needed an authorised representative before it did so.

A company that calls a third party’s model through an API and builds a product on it is a downstream provider under Article 3(68), and is therefore the provider of an AI system rather than of a model, so the Articles 53 to 55 duties do not apply to it. Ordinary fine-tuning does not change that. A modifier becomes the provider of the modified model, and then only in relation to the modification, where the training compute used for the modification exceeds a third of the original model’s training compute. That threshold appears nowhere in the Regulation itself.

A provider whose model was already on the Union market before 2 August 2025 has until 2 August 2027 to comply, under Article 111(3). A provider releasing a model under a free and open-source licence, with publicly available weights, architecture and usage information, is exempt under Article 53(2) from the technical documentation and downstream information duties, and under Article 54(6) from appointing an authorised representative, in each case unless the model presents systemic risks. The copyright policy and training-content summary in Article 53(1)(c) and (d) apply either way, and the Commission reads the licence condition strictly where a provider monetises access.

EU AI Act provisionWhat it requiresApplied fromEnforceable from
Article 5 (prohibited practices)Ban on manipulation, exploitation of vulnerabilities, social scoring and five further practices2 February 20252 August 2026
Articles 53 and 55 (all GPAI model providers, and systemic-risk providers)Technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk duties2 August 20252 August 2026
Article 54 (third-country GPAI model providers only)Appointment of an EU authorised representative before market placement2 August 20252 August 2026
Article 50(1), (3), (4) and (5) (transparency, other than marking)Chatbot disclosure, emotion-recognition notice, deepfake and public-interest text labelling2 August 20262 August 2026
Article 50(2) (machine-readable marking of synthetic content)Marking of synthetic audio, image, video and text as artificially generated or manipulated2 August 2026, or 2 December 2026 for systems placed on the market before 2 August 2026 (Article 111(4), inserted by the Digital Omnibus)On application
Chapter III (high-risk, Annex III systems)Risk management, data governance, human oversight, conformity assessment2 December 20272 December 2027
Chapter III (high-risk, Annex I regulated products)The same requirements, for AI in products already covered by EU harmonisation legislation2 August 20282 August 2028

What the Digital Omnibus on AI did not change

The co-legislators signed the Digital Omnibus on AI, Regulation (EU) 2026/1744, on 8 July 2026, and it entered into force on 27 July following publication in the Official Journal on 24 July. They deferred the high-risk requirements in Chapter III to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems.

The co-legislators did not amend the general-purpose AI model duties: Articles 51 to 55, Articles 88 to 94 and Article 101 all stand as enacted, and the 2 August 2025 date in Article 113 did not move. The deferral applies only to the Chapter III high-risk requirements. A model provider that also deploys a chatbot or generates synthetic content has Article 50 transparency duties from 2 August 2026 alongside its Articles 53 to 55 obligations, and may use the code of practice to demonstrate compliance.

In the same instrument the co-legislators enlarged the AI Office’s remit over AI systems. Under a replaced Article 75(1) the AI Office holds exclusive competence over AI systems built on a general-purpose AI model by the same provider or by a provider forming part of the same undertaking, and over AI systems that constitute or are integrated into a very large online platform or very large online search engine designated under the Digital Services Act, a competence created for the first time in the Omnibus.

Viewpoint

The twelve months between duty and enforceability is the part I would look at first. A provider serving an EU-accessible API since late 2025 has by now accumulated a year of documentation, copyright-policy and training-summary obligations, and the guidelines explaining what those obligations mean have been public since November 2025. Under Article 101 the Commission must find intention or negligence before it fines.

In our experience advising on market entry into regulated sectors, the authorised representative is the appointment providers leave latest. Under Article 54(5) the representative must terminate the mandate and tell the AI Office its reasons where it has reason to consider the provider is acting contrary to the Regulation, so the representative is under a duty to report the provider to the regulator. That is an unusual thing to find inside an administrative appointment.

In its announcement of 31 July 2026 the Commission describes the AI Office as covering AI systems offered by the same provider as the underlying model. The enacted text covers a provider forming part of the same undertaking, which is a group-level test and materially wider. A corporate group holding its model in one entity and its customer-facing systems in another falls within the AI Office’s exclusive competence on the enacted wording and outside it on the announcement, and the Commission marks that page as published for information only.

The Commission’s own guidelines leave open what counts as a sufficiently detailed training-content summary. Will the first Article 91 information request settle that, or will the AI Office wait for a harmonised standard?

Frequently asked questions

What changed on 2 August 2026 for GPAI model providers?

Articles 53 to 55 of the EU AI Act have applied since 2 August 2025 and are unchanged. Article 101 and Chapter IX became applicable on 2 August 2026. GPAI enforcement is for the European Commission alone, acting through the AI Office, which may now request information, evaluate models, require measures and impose fines of up to 3% of worldwide annual turnover or 15 million euros.

Is a provider that has not complied since August 2025 exposed on 2 August 2026?

The duties applied from 2 August 2025, and the Commission’s guidelines state that from 2 August 2026 it will fine providers who are not fully compliant on that date. Under Article 101 it must find intention or negligence. Whether it can also penalise the year in which the duties applied but Article 101 did not is not addressed in the guidelines, and commentary asserting that fines reach back to August 2025 goes further than the published material supports. Providers of models placed on the Union market before 2 August 2025 have until 2 August 2027 under Article 111(3).

Does a UK company using a third party’s model API need an authorised representative?

No. A company that integrates a third party’s model is a downstream provider under Article 3(68), and is therefore the provider of an AI system rather than of a general-purpose AI model. Article 54 applies to model providers. Ordinary fine-tuning does not convert a downstream provider into a model provider on the Commission’s compute-based criterion.

Who enforces the EU AI Act against AI systems rather than models?

Under the replaced Article 75(1) the AI Office holds exclusive competence over systems built on a general-purpose AI model by the same undertaking and over systems in platforms designated under the Digital Services Act. National competent authorities enforce against other AI systems, and the European Data Protection Supervisor enforces against EU institutions.

For advice on whether a model or an AI-enabled product falls within the EU AI Act, on the authorised representative requirement, or on the interaction between the Act and UK data protection duties, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts