What changed on August 2
The European Commission's AI Office and national market surveillance authorities gained real enforcement power over general-purpose AI (GPAI) models on August 2, 2026. This is a different rule from the chatbot-disclosure and deepfake-labeling requirements that took effect the same day. Those are [Article 50's transparency rules](https://questloops.com/blog/the-eu-ai-act-s-transparency-rules-just-went-live-what-article-50-actually-requires), aimed at anyone deploying an AI system. Article 53 is aimed one level up the stack, at the companies that build the underlying models: OpenAI, Anthropic, Google, Mistral, and the rest.
The obligations themselves weren't new. Providers of GPAI models have had to comply with Article 53 since August 2, 2025, a full year earlier. What's new is that the Commission can now actually investigate and act on it.
What Article 53 actually requires
Providers of general-purpose AI models have to:
- Maintain technical documentation covering the model's capabilities and limitations
- Make that documentation available to downstream providers who build AI systems on top of the model
- Put in place a policy for complying with EU copyright law
- Publish a public summary of the data used to train the model
Open-source GPAI models get a partial exemption from the documentation rules, unless they're classified as a "systemic risk" model, meaning they cross a compute threshold the Act treats as high-stakes regardless of licensing.
The enforcement powers that just switched on
Before August 2, 2026, the AI Office could ask questions. Now it can act on the answers. The Commission's enforcement toolkit includes:
| Power | What it means |
|---|---|
| Request documentation and information | Can formally demand a provider's technical files and training data summary |
| Conduct evaluations | Can run its own technical assessment of a model, not just review paperwork |
| Request compliance measures | Can order risk mitigation, market restriction, or product recall |
| Impose fines | Can fine a provider directly for non-compliance |
That last power is the one that gives the other three teeth. A documentation request with no penalty behind it is a suggestion; one backed by a fine is not.
Who's actually covered, and who's opted out
The Commission runs a voluntary GPAI Code of Practice that functions as the easy way to prove compliance: sign it, and the Commission treats you as having adequately met Articles 53 and 55. As of the current signatory list, Amazon, Anthropic, Google, Mistral AI, and OpenAI have signed. Meta has publicly refused, saying in mid-2025 that the Code goes beyond what the AI Act itself requires.
Refusing to sign doesn't exempt a company from Article 53, it just means proving compliance the harder way, directly to regulators, without the Code's pre-approved template. For a company the size of Meta, that's a deliberate bet that its own documentation practices will hold up to direct scrutiny rather than a rejection of transparency obligations outright.
Why this matters if you're not a frontier lab
If you're a developer building on top of GPT-5.6, Claude, Gemini, or another GPAI model, Article 53 is the reason you can now request technical documentation from the provider and expect an actual answer, not a shrug. If you're choosing between models for a product you're shipping into the EU, whether your chosen model's provider signed the Code of Practice is now a real due-diligence question, not a nice-to-have.
The honest caveat: enforcement powers switching on doesn't mean fines start landing this week. The AI Office still has to build its investigation and evaluation capacity, and the first real test of how seriously this gets enforced will show up in actions taken over the coming months, not in the first 24 hours.


