Almost every account of the European Commission's new authority over foundation models leads with the same number. From 2 August 2026, providers of general-purpose AI models that breach the AI Act face fines of up to the higher of €15 million or 3% of worldwide annual turnover. For prohibited practices the ceiling is €35 million or 7% of global turnover. A percentage of revenue is a legible, quotable threat, and it has become the frame through which the enforcement phase is being read.
It is the wrong frame. The fine is the least consequential power the Commission acquired that day. Read the same enforcement clause a few lines further and you find the remedies that will actually move behaviour inside a frontier lab: the Commission, acting through the AI Office, can request documentation, conduct its own technical evaluations of a model, require compliance and risk-mitigation measures, and restrict, recall or withdraw a model from the Union market entirely.
A fine is a cost. Market access is not.
What actually became enforceable on 2 August
The sequencing matters, because a lot of coverage has compressed it. The AI Act entered into application on 2 August 2024 with staged phase-ins. Prohibited practices and AI-literacy duties applied from February 2025. Obligations on providers of general-purpose AI models — documentation, copyright policy, training-data summaries, and for models with systemic risk, adversarial testing and incident reporting — have been binding since 2 August 2025.
What changed this month is not the obligations. It is that the Commission became formally entitled to supervise and enforce them. For a full year, GPAI providers were subject to rules that no European authority had the standing to act on. That gap has now closed.
The Commission's toolkit from 2 August 2026: request information and documentation; conduct evaluations of a model; require compliance measures, risk-mitigation measures, market restriction, recall or withdrawal; and impose fines.
A capped penalty and an uncapped remedy produce different behaviour
Consider how each remedy is processed inside a company that has any competent finance function. Three percent of worldwide turnover is a large number in absolute terms and a bounded one in structural terms. It is knowable in advance, provisionable, insurable in parts, and — crucially — it can be weighed against the commercial value of the conduct that triggered it. That is what a cap does: it converts a legal risk into a line item. Firms in every regulated industry have made exactly this calculation for decades, and sometimes the answer is to pay.
Withdrawal from the EU market is not a line item, because it is not a cost at all. It is a discontinuity. A model pulled from the Union loses its enterprise contracts, its API customers, its distribution partners and its position in a market of roughly 450 million people, and it loses them at once rather than at a rate. There is no provision you can take against it and no insurer who will write it. More importantly, it is uncapped: the harm scales with how much of your business depends on Europe, which for several providers is a great deal.
The practical consequence is that the two remedies are managed by different parts of a company. A fine schedule is a legal and finance problem. A market-restriction power is a product and engineering problem, because the only way to manage it is to change what you ship. That is the shift the enforcement phase actually represents, and it is invisible if you only read the penalty tiers.
The regulator got its own benchmark
The second change has had almost no coverage and may outlast the first. Until now, systemic-risk assessment under the AI Act has been substantially self-reported. A provider evaluates its own model, documents its own adversarial testing, and submits its own conclusions. The Commission reviewed the paperwork. From 2 August it can run the evaluation itself.
This is a structural change to what a benchmark is for. A vendor-published evaluation is a marketing artefact with a technical body — it is produced by the party with the strongest interest in the result, on a harness that party designed, at a checkpoint that party selected. That is not an accusation of bad faith; it is a description of the incentive. Every lab in the industry publishes this way, and readers have learned to discount accordingly.
A regulator with an independent evaluation capability changes the equilibrium in a specific way: the provider's own numbers become checkable. Not necessarily checked, and not necessarily checked well — but checkable, which is enough to change what a lab is willing to claim. The long-tail effect of the enforcement phase is likely to be quieter and more conservative systemic-risk documentation, not a headline penalty.
Where the systemic-risk designation comes from
The heavier obligations attach to models designated as carrying systemic risk. Article 51 sets a training-compute threshold of 10^25 floating-point operations, measured across the full training run rather than at inference, above which a model is presumed to carry systemic risk.
That presumption is rebuttable, which is doing more work than it appears. A provider can argue that its model does not in fact present systemic risk despite crossing the threshold. The Commission can also designate a model below the threshold, on the advice of the Scientific Panel. So the number is an entry point to an argument, not a switch. Anyone reading 10^25 as a bright line has misread it in both directions.
The case that none of this bites
The counter-argument is serious and deserves to be argued rather than gestured at.
Start with capacity. The AI Office is small relative to the organisations it supervises. Running credible independent evaluations of frontier models requires compute, evaluation engineering talent and secure model access — three things the labs have in far greater quantity than any European regulator, and two of which they are competing for globally. A power to evaluate that is exercised rarely, slowly, or on a weaker harness than the provider's own is a power in name.
Then the severity problem. Market withdrawal is so drastic that it may be self-deterring for the regulator rather than the regulated. Removing a widely-deployed model from the EU would disrupt European businesses that built on it, and the political cost of that disruption lands on the Commission, not on the provider. A remedy that nobody is willing to use is not a remedy — it is a bargaining position, and the labs will price it as one. The honest answer is that we do not yet know which it is, because it has never been used.
And there is the incidence argument, which the European industry has made loudly and which is not obviously wrong. Compliance overhead is close to a fixed cost. A firm with a large legal and policy function absorbs it as a rounding error; a European startup training at the margins of the threshold absorbs it as a meaningful share of headcount. If that is right, a regime designed with large non-EU labs in mind lands hardest on the smaller European providers it was meant to leave room for. Supporters respond that the GPAI obligations scale with capability and that the Code of Practice exists precisely to lower the compliance cost of demonstrating conformity. Both positions are held in good faith and the evidence to settle them does not exist yet.
What to watch
The signal will not be a fine. Fines are the visible end of an enforcement process and they arrive late. The earlier and more informative signals are these: whether the AI Office issues formal information requests and to whom; whether it publishes or references an evaluation it conducted itself rather than one submitted to it; whether any provider's systemic-risk documentation becomes noticeably more hedged in the next filing cycle; and whether the Commission designates a model below the 10^25 threshold, which would be the clearest statement that the number is not the boundary.
“A capped fine is something a company plans around. An uncapped structural remedy is something it builds around. Only one of those changes the product.”
The enforcement window opened three weeks ago and no action has been taken under it. That is not evidence that the powers are hollow, nor evidence that they are potent. It is simply early. But the frame through which the next twelve months get reported is being set now, and if it stays anchored to the fine schedule, the reporting will consistently miss the lever that is actually moving.