Since 2 August 2026, the European Commission's EU AI Office can investigate providers of general-purpose AI models, demand access to models for evaluation, and fine up to the higher of EUR 15 million or 3% of worldwide turnover. For builders serving EU users, the practical half matters more: transparency and marking duties are live now.
Key facts
- Since 2 August 2026, the EU AI Office holds formal investigative and enforcement powers over GPAI-model duties and prohibited practices.
- Breaches can draw fines up to the higher of EUR 15 million or 3% of global turnover, plus corrective or risk-mitigation orders.
- Article 50 transparency duties — AI-interaction disclosure, machine-readable marking of synthetic output, biometric notices, deepfake disclosure — apply from the same date.
- Generative systems already on the market get until 2 December 2026 to add marking and detection; pre-August-2025 GPAI models generally have until 2 August 2027.
- The Commission adopted transparency guidelines on 20 July 2026, and the AI Office published a voluntary Code of Practice on transparency.
What happened
Two law-firm alerts published 3 August 2026 describe the same milestone from complementary angles. Wilson Sonsini's account centers on the EU AI Office: GPAI-model duties had applied since 2 August 2025 but sat unenforced for a year while the Office ran implementation support and collected provider information. Since 2 August 2026, those duties are backed by powers to request documentation, obtain model access for evaluation, require corrective measures, and fine. Cooley's alert centers on Article 50, which splits duties between providers (disclose AI interaction; embed machine-readable markings in synthetic audio, image, video, or text with a detection mechanism) and deployers (inform people subject to emotion-recognition or biometric categorization; disclose AI-generated deepfakes and public-interest AI text absent substantive human editorial review).
Three details matter for implementation planning. First, the duties apply immediately to all in-scope systems regardless of placement date; only the marking-and-detection duty for already-marketed generative systems gets the 2 December 2026 transition, and content published before 2 August needs no retroactive labeling. Second, the AI Office describes "technical compliance dialogues" as its preferred first tool, per its published FAQ — dialogue first, fines later. Third, the AI Omnibus postponed high-risk-system duties but did not move these August 2026 milestones.
Why it matters
For builders deciding where to run models for EU users, compliance is now a hosting criterion alongside price and latency. A provider that cannot tell you how synthetic output is marked, or a GPAI supplier with no documentation posture for a compliance dialogue, is a regulatory risk you inherit. This is the same trust-stack logic behind the week's enterprise moves: Anthropic's zero-retention path and the sovereign-AI builds that keep data inside jurisdiction are what Article 50 and GPAI duties look like from the buyer's side — documented, attestable, localizable.
The marking duty also collides with an open research question: watermarking techniques can shift model refusal behavior, so the mechanism you choose for compliance has safety implications to test, not just a checkbox to tick.
Background
The Act's extraterritorial reach is the part US and Asian providers keep underestimating: it covers anyone placing AI on the EU market or whose AI outputs are used inside the EU, across providers, deployers, importers, and distributors. GPAI providers that placed models after 2 August 2025 have been living under the substantive duties for over a year; the new element is enforcement, advocated forcefully by bodies including the European Data Protection Board and the EU Agency for Fundamental Rights. The voluntary Code of Practice on Transparency offers a recognized compliance path — voluntary in name, persuasive in practice once dialogues begin.
DeAI's standing advice applies: provider claims about compliance are claims. Our tracker work shows zero verified claims across 17 decentralized-inference providers — and "we comply with the AI Act" belongs in the same verify-it-yourself bucket until documentation, markings, and attestations are public. Start from what private inference actually guarantees before signing a vendor's compliance slide.
What's next
Watch three dates: 2 December 2026 (marking compliance for existing generative systems), 2 August 2027 (pre-existing GPAI models come under full duties), and the first public outputs of the AI Office's technical compliance dialogues — the first dialogue summaries will set the de facto documentation standard faster than any guidance document. Firms that published the August alerts will track enforcement actions; we will update this page's lineage as cases land.
Questions
- What EU AI Act duties are enforceable right now?
- Since 2 August 2026: GPAI-model duties and banned practices (backed by EU AI Office investigative powers), plus Article 50 transparency duties — disclosing AI interaction and marking synthetic output — for providers and deployers serving EU users.
- What fines can the EU AI Office impose?
- Up to the higher of EUR 15 million or 3% of the provider's worldwide annual turnover for GPAI and transparency breaches, alongside orders for corrective or risk-mitigation measures.
- What is the December 2026 deadline for AI marking?
- Providers of generative AI systems already on the market get until 2 December 2026 to add machine-readable markings and detection mechanisms; all other Article 50 duties applied immediately from 2 August 2026.
- I run inference for EU users — what should I do first?
- Disclose AI interaction where it isn't obvious, add machine-readable provenance marking to synthetic output, and document your GPAI-model supply chain — then diary the 2 December marking deadline and watch the AI Office's technical compliance dialogues.
Sources
- EU AI Act Enforcement Phase Begins — Wilson Sonsini
- EU AI Act: Transparency Obligations Take Effect 2 August 2026 — Cooley
- Implementation Timeline — EU Artificial Intelligence Act portal
About DeAI
DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.
Powered by Morpheus and StrandCMS
Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.
