On August 3, the European Union’s AI law crossed from rulebook to enforcement. Regulators for the first time hold the power to fine or restrict general-purpose AI models, and OpenAI, Anthropic and Google are first in line for review, according to CNBC, which cited people familiar with the matter. The activation follows a day after the requirement that chatbots disclose they are AI. Europe has moved from writing rules to using them.
The law, Regulation (EU) 2024/1689, has been building toward this date since it took effect. Duties for general-purpose AI models applied from August 2, 2025, but the enforcement machinery was switched on only now. The Commission announced in late July that its AI Office would begin enforcing from this month, and the August 3 activation makes the powers real.
The penalties give the law its weight. For breaches of the general-purpose model rules, fines can reach 3% of a company’s worldwide annual turnover or 15 million euros, whichever is higher. For the most serious violations, involving prohibited practices, the ceiling rises to 7% of global turnover or 35 million euros. For companies the size of the three named, those are real numbers.
The AI Office is the enforcer. It can request information, evaluate models, demand corrective measures and, in the extreme, order a model restricted or withdrawn from the market. The Commission holds exclusive authority over general-purpose models, which means enforcement will be uniform across the bloc rather than fragmented by member state.
The identity disclosure requirement that took effect August 2 is the softer half of the package. Chatbots must now tell users they are interacting with AI. The enforcement powers activated a day later are the harder half. Together they mark the transition the industry has watched for two years.
OpenAI, Anthropic and Google being named first is not a coincidence. Their models are the most widely deployed general-purpose systems in Europe, which makes them the natural first targets for review. It also makes them the test case for how the rules will be applied in practice.
The companies have had a year of lead time. Duties under the law began applying in August 2025, and the providers used that period to build documentation, publish training-data summaries and appoint representatives in the EU. Whether that preparation is judged sufficient is now a question for the AI Office.
Compliance has already become a line item. European lawyers who advise US AI companies said the cost of documentation, legal review and ongoing monitoring has moved from optional to structural, part of the pricing of any model sold in the bloc. The fines, in that sense, are the least expensive part of the regime.
In practice, being under review means paperwork and questions before any fine. The AI Office can send requests for information, demand technical documentation and evaluate models directly, and the first reviews are likely to move through those stages before any penalty is considered. Companies that respond poorly to the early stages face fines on their own, even without a finding against the model itself.
The largest systems sit in a separate category under the law, reserved for general-purpose models judged to carry systemic risk. Those models face extra obligations, including evaluations and serious-incident reporting, and the category is where the biggest names are expected to land. The distinction will shape how the first reviews unfold.
The providers have also leaned on the Code of Practice the Commission adopted to help companies show compliance, and adherence to it can count as a mitigating factor if fines are fixed. The arrangement gives the companies a road map, but it does not guarantee the outcome. The review will test whether following the code is enough.
The activation lands at a delicate moment for the three companies. OpenAI is managing an expanding agent investigation and questions about its IPO timing. Google is defending its position in AI search and cloud. Anthropic is preparing a fall listing. A regulatory review in Europe is the last thing any of them wanted on the calendar.
The EU’s approach differs from the patchwork of US state rules and the light-touch federal posture. Europe has chosen a single regime with real teeth, and the AI Office’s powers over general-purpose models are the clearest expression of that choice. The three American labs are now the ones carrying the test.
Member states have not fully stood aside. Germany’s data protection authorities, for example, have pressed their own line on consumer devices, and the tension between Brussels and national regulators is a theme of the enforcement era. The AI Office’s exclusive powers over models simplify one layer while leaving others open.
For the rest of the industry, the message is procedural: the grace period is over. Any company placing a general-purpose model on the European market now faces a regulator that can fine, restrict and, in theory, withdraw. The compliance question has become a pricing question, and the pricing question is now on the balance sheet.
The first reviews will take months, and the first fines could take longer. But the direction is fixed. Europe has the tools, the targets and the calendar. The era of voluntary alignment has ended, and the era of enforced compliance has begun.


