EU AI Act: Rules on AI Models Now Enforceable
08 Aug 2026
The European Union's AI Act has crossed a major threshold: its provisions regulating large language models are now enforceable, making it the first comprehensive law governing artificial intelligence to take effect. For founders building or deploying AI models—especially those with EU customers or ambitions—this shift changes the compliance calculus overnight.
What's happening
The AI Act was passed in 2024, and significant provisions targeting large language models became applicable in August. The rules apply broadly to "all models that lack a specific purpose but can be adapted to a variety of use cases"—a definition that captures most general-purpose foundation models, not just consumer-facing chatbots.
To drive enforcement, the European Commission has established the European AI Office. The Commission has also endorsed a voluntary code of practice drafted by leading experts, including Yoshua Bengio. Notably, most major Western AI labs have signed on—but Meta has not, signaling that industry compliance remains uneven even as the law takes effect.
OpenAI, for its part, says it has worked closely with regulators. Tom Duff Gordon, OpenAI's VP and Head of EMEA Policy, stated the company has collaborated with the European Commission on implementing the AI Act, including its Codes of Practice.
Timeline
- 2022: ChatGPT's public launch kicks off the current wave of generative AI adoption.
- 2024: The EU AI Act passes into law.
- December 2025: The Commission separately pushes to implement its digital markets' rules.
- August (2026, per the event date): AI Act provisions on large language models become applicable and enforceable.
The friction points
The report flags several tensions that could shape how enforcement unfolds:
- Pace vs. expertise. Officials will need to keep up with fast-moving AI technology, but there's no established scientific consensus on how to prevent harm at scale—raising questions about how consistently rules will be applied.
- US-EU trade friction. The Trump administration has been particularly assertive in pushing back against EU digital rules when they affect American companies, a dynamic that could spill over into how the AI Act is enforced against US-based labs.
- Fragmented compliance. Meta's decision not to sign the voluntary code, while most peers did, suggests the industry isn't moving in lockstep—something regulators and competitors alike will be watching.
- Resource allocation. Laura Lazaro Cabrera, a director at the Center for Democracy & Technology, has urged the Commission not to funnel enforcement resources solely toward cyber-offence and loss-of-control systemic risks, implying other risk categories could be under-resourced if the Commission isn't deliberate.
Sources do not disagree on these points; the report presents them as open questions rather than conflicting claims.
Why founders should care
For early-stage founders building general-purpose AI models, this is likely to matter in a few concrete ways:
- If your model lacks a narrow, fixed purpose and can be adapted across use cases, it's likely to fall within the AI Act's scope—worth an early legal review rather than waiting for enforcement actions to clarify boundaries.
- Aligning with the voluntary code of practice may plausibly serve as a trust signal to regulators and EU users, potentially easing friction as enforcement ramps up—though it's not a guarantee against future obligations.
- Meta's choice not to sign suggests there's some flexibility in how companies engage with the voluntary framework today, but this could carry more risk down the line if the Commission tightens expectations or Meta faces consequences.
- Founders operating across both the US and EU markets should watch the geopolitical layer: friction between the Trump administration and EU digital regulators could introduce volatility that's hard to predict from the startup side.
- Because the European AI Office is newly stood up, enforcement guidance is likely to evolve rather than remain static—founders should plan for ongoing monitoring rather than a one-time compliance check.
What's still unclear
Several important details remain undefined in the current reporting, including the specific penalties for non-compliant models, the precise scope of what counts as a "general purpose" model, how the European AI Office will coordinate enforcement across member states, and what—if any—consequences Meta will face for not signing the code. How the Commission will balance resources across different risk categories, and what specific actions the Trump administration has taken or threatened regarding these rules, also remain open questions.
Bottom line
The AI Act's enforcement window is now open, and the framework's ambition—being the first comprehensive AI law—means there's no direct precedent for how strictly or unevenly it will be applied. Founders building general-purpose models should treat this as a live, evolving regulatory environment rather than a fixed rulebook, and stay close to guidance from the European AI Office as it takes shape.