A compliance calendar is usually where ambitious product roadmaps go to nap. August 2 is less sleepy. According to The Parliament, the European Commission will be able to demand information from large general purpose AI model providers, conduct safety evaluations, order corrective measures, pull models off the EU market and impose fines of up to 3% of annual total turnover. That makes AI Act compliance less like a memo in a legal drive and more like an operations drill with named owners, retrievable evidence and escalation paths. The important shift is not that every chatbot in Europe suddenly needs a permission slip from Brussels. The Parliament describes the affected systems as large general purpose AI models, the behind the scenes systems powering chatbots, image generators and enterprise tools. The practical question is narrower and more uncomfortable: if the Commission asks for model information or safety evaluation material, can the provider answer without staging a corporate archaeology dig? ## What changes on August 2 The Parliament reports that from August 2 the Commission can demand information, conduct safety evaluations, order corrective measures, remove models from the EU market and issue fines up to 3% of annual total turnover. TechPolicy Press separately reports that Brussels gains enforcement powers on Aug. 2, when the Commission can begin fully enforcing rules for providers of general purpose AI models, although those obligations started applying last year. That distinction matters. A rule without an investigative lever is a compliance memo; a rule with information demands and fines is a queue in someone’s ticketing system. The European Commission’s own AI Act page frames the law as the EU regulatory framework for AI, but the sharper operational detail comes from the enforcement reports. The Commission is not just receiving filings. It can test, ask, require fixes and exclude models from the EU market. For frontier model teams, the calendar now reads: obligations existed, enforcement capacity arrives, evidence needs to be producible. ## Who has the first homework Bird and Bird’s guide to the European Union Artificial Intelligence Act separates obligations for providers of general purpose AI models from obligations for general purpose AI models with systemic risk, and also treats enforcement, governance and penalties as distinct subjects. That is a useful map for builders because the heaviest first burden falls on model providers, not every company that embeds an AI feature in a workflow. Still, downstream companies are not merely spectators. If your product relies on a covered model, vendor diligence now needs to ask what the provider can supply if the Commission asks. The July 9 open letter published by SaferAI focuses on general purpose AI models with systemic risk and urges the Commission to use its powers as August 2 2026 approaches. The letter also says the Code of Practice had been finalized one year earlier and had been signed by all GPAI providers advancing the frontier, describing it as a de facto industry standard. Translation for procurement: do not accept a vendor’s we welcome oversight paragraph as evidence. Ask where the documentation lives, what evaluations were run and who can authorize a regulator facing response. ## What readiness looks like in practice The Parliament’s list of powers gives builders the checklist hiding inside the statute. Information demands mean a provider needs current model documentation, not a slide deck whose owner left six months ago. Safety evaluations mean test design, results, assumptions and limitations should be preserved in a form an outside examiner can understand. Corrective measures mean someone has to know how a fix is approved, shipped and evidenced. TechPolicy Press reports that the enforcement powers arrive alongside new transparency rules intended to help people recognize when they are interacting with an AI system or seeing synthetic content. That is a separate compliance lane, but the operational lesson is similar. Legal obligations become expensive when teams cannot connect policy text to product surfaces, model behavior, release gates and user disclosures. The dreary work is the useful work: ownership, logs, versioning, evaluation records and incident escalation. ## Where builders get stuck between regimes Brookings describes general purpose AI regulation as an area of convergence and divergence across the EU and the US. That is polite policy language for builders having to support more than one compliance theory at once. The EU approach now includes a central Commission role for GPAI model enforcement. Other jurisdictions may align in some places and differ in others, which means global AI teams should avoid hard coding Europe specific compliance into a spreadsheet owned by one lawyer. The better response is to treat August 2 as an operational readiness date, not a ceremonial legal milestone. Model providers should prepare evidence packs for information requests, preserve safety evaluation materials and define who responds when corrective measures are ordered. Downstream builders should update vendor contracts and diligence questions so they know whether their suppliers can answer Brussels before the panic email arrives. Watch the first Commission requests closely; the first fine will matter, but the first detailed information demand may teach builders more. ## Sources - Europe gets ready to police frontier AI

Sources