Skip to main content
EU Enforcement Powers for Frontier AI Are About to Get RealEU AI Act & GPAI
4 min readFor Legal & Compliance Officers

EU Enforcement Powers for Frontier AI Are About to Get Real

The European Commission is set to enforce the EU AI Act for General-Purpose AI Models with systemic risk starting August 2, 2026. If you're managing foundation models or deploying systems built on them, you have less than 18 months to prepare.

Here's what changed, what it means for your compliance roadmap, and where to focus your effort.

What Changed

The Commission is ready to use its enforcement powers under Articles 91, 92, 93, and 101 of the EU AI Act. These provisions enable the AI Office to request information, conduct evaluations, and impose corrective measures on providers of General-Purpose AI Models that pose systemic risks.

The Council has finalized the Omnibus VII simplification package, adjusting several AI Act timelines. Stand-alone high-risk AI systems now face compliance by December 2, 2027, and embedded high-risk systems have until August 2, 2028. The regulation also clarifies the AI Office's supervisory roles and specifies where national authorities retain responsibility.

A coalition of AI researchers and civil society organizations, including Yoshua Bengio and Stuart Russell, sent an open letter urging the Commission to fully enforce its authority. They highlight emerging systemic risks, such as cyber-offense capabilities and biological threats, noting that rapid model development makes enforcement more urgent than anticipated.

Key Findings

External assessments will be crucial. The open letter calls for empowering the AI Office's Network of Evaluators to conduct independent evaluations. If you're relying solely on internal testing for compliance, reconsider. External scrutiny is coming, and your documentation must withstand it.

Systemic risk thresholds are approaching fast. The letter points to cyber-offense capabilities and critical thresholds for biology and loss of control. Your risk assessment can't be a one-time exercise. Continuous monitoring is essential to flag when your model crosses into systemic risk territory.

The Scientific Panel has real authority. Established under Article 68 and operational as of June 1, 2026, the Scientific Panel consists of up to 60 independent experts who can request information and issue qualified alerts about Union-level systemic risks. This isn't just an advisory body; it's a mechanism for escalating technical findings directly to enforcement authorities.

Agentic AI systems complicate compliance. Analysis from Bristows highlights that the EU AI Act's functional definition in Article 3(1) often applies to agentic systems, complicating compliance. The Article 14 human oversight requirement conflicts with agents' reduced human involvement. Documentation and conformity assessments assume fixed functions, which agents don't have. Article 50 transparency obligations may not reach end users who never chose to interact with AI.

Timeline adjustments don't reduce your workload. The Omnibus VII package delays high-risk system compliance dates but tightens others. The transparency grace period for generative AI systems already on the market now ends December 2, 2026. If you've been treating existing deployments as grandfathered, you're mistaken.

What This Means for Your Team

You're not just preparing for a compliance deadline. You're preparing for ongoing regulatory scrutiny of a moving target.

If your model's capabilities change post-deployment (and they will, especially for agentic systems), you need to know when that constitutes a "substantial modification" under the Act. This isn't defined by code commits or version numbers but by functional changes that trigger re-assessment obligations.

Your Technical Documentation (Annex IV) needs to account for this. Document your model's adaptive mechanisms, the boundaries within which it can change, and your monitoring systems for detecting when it exceeds those boundaries. If you can't explain what your model is allowed to learn after deployment and how you'll know if it crosses a line, you don't have compliant documentation.

The Network of Evaluators will want evidence, not assertions. That means Validation Evidence showing what you tested, how you tested it, and what you found. It means Post-Market Monitoring data that tracks performance drift, emergent capabilities, and user complaints. It means Red Teaming reports that go beyond "we tried some jailbreaks and patched them."

Action Items by Priority

Immediate (Q2 2025): Map your models to systemic risk criteria. Review your General-Purpose AI Models against the systemic risk designation in Article 51. Don't wait for the Commission to tell you. If your model has capabilities in cyber-offense, biological design, or autonomous operation that could cause serious incidents at scale, assume you're in scope and start building your compliance case.

Q3 2025: Build continuous risk monitoring. Set up technical systems that flag capability changes, performance anomalies, and usage patterns that suggest systemic risk. This isn't about quarterly reviews. It's about instrumentation that tells you when your model's behavior changes in ways that matter for compliance.

Q4 2025: Prepare for external evaluation. Inventory your validation evidence. Can you produce testing protocols, datasets, results, and remediation records on demand? Can you demonstrate that your Red Teaming covered the threat scenarios relevant to your model's capabilities? If the Network of Evaluators requests information under Article 91, you won't have time to generate it from scratch.

Q1 2026: Document your agentic system boundaries. If you're deploying AI agents, document what they're authorized to do, what oversight mechanisms constrain them, and how you'll detect when they exceed their design parameters. The Article 14 human oversight requirement doesn't disappear just because your system operates autonomously. You need to show how oversight is maintained even when humans aren't in the loop for every decision.

Ongoing: Track Scientific Panel alerts. The Scientific Panel can issue qualified alerts about Union-level systemic risks. These alerts will shape how the AI Office interprets and enforces the rules. If your model operates in a domain flagged by the Panel, expect heightened scrutiny and adjust your risk controls accordingly.

EU AI Act official text

You Might Also Like