Articles

The EU AI Act's GPAI Rules Get Teeth in August

On August 2, 2026, the EU gains real enforcement power over general-purpose AI models — fines, mandated mitigations, even recalls. What providers need to know.

The Lycoris Team The Lycoris Team · · 2 min read
A digital security shield with circuit traces

The EU AI Act has been law for a while, but a key deadline is about to change how it feels in practice. On August 2, 2026, the European Commission’s supervision and enforcement powers over general-purpose AI (GPAI) model providers come into force — turning a year of paper obligations into rules with consequences.

What changes

Obligations for GPAI providers — the companies behind general-purpose large language models — technically applied from August 2, 2025. But providers were given a one-year adjustment period before regulators could actually act. That grace period ends in August 2026.

From that date, the EU’s AI Office gains real teeth. It can:

  • request detailed information from model providers,
  • demand access to models for evaluation,
  • order mitigations when it identifies risks, and
  • ultimately require that a model be withdrawn or recalled from the EU market.

Providers of the most capable models — those deemed to carry systemic risk — face heightened duties, including a legal obligation to notify the AI Office.

Why it matters beyond Europe

Like the GDPR before it, the AI Act’s reach extends past the EU’s borders. Any company that wants to offer a general-purpose model in the European market has to comply, which in practice means global providers building EU requirements into their core processes rather than maintaining a separate “EU mode.” Documentation, evaluations, and risk assessments become table stakes.

This lands at a moment when models are proliferating fast — from frontier systems like Gemini 3 to the growing field of open-weight competitors — and when AI agents are being wired into real systems. Regulators are explicitly trying to get ahead of the capability curve.

The open questions

Plenty remains unsettled: how aggressively the AI Office will use its new powers, how “systemic risk” gets measured in practice, and how the rules apply to open-weight models whose creators can’t control downstream use. There’s also a one-step-removed deadline — models released before August 2025 have until August 2, 2027 to come into compliance.

The takeaway

August 2026 marks the point where the EU AI Act shifts from obligations on paper to enforcement in practice. For anyone shipping a general-purpose model into Europe, compliance work that could be deferred now has a hard deadline and real penalties behind it. The bigger picture is that AI governance is maturing from principles into the kind of audited, documented process the rest of software supply-chain security already knows well.

Chisato Chisato · · 4 min read

What Is AI Red Teaming?

AI red teaming is the practice of deliberately attacking a model or AI system to find failures before real adversaries do. Here's how it works.

#AI #Security #LLMs