The EU AI Office has activated its enforcement powers — regulators can now inspect AI models, block market access, and fine providers up to 3% of global turnover.
For two years, the EU AI Act lived largely on paper. Compliance teams built policies, drafted documentation, and mapped obligations against future deadlines. That era just ended. The European Commission's AI Office has formally activated its enforcement powers under Chapter V of the AI Act, and the practical consequence is simple: the regulator now has teeth, and it is willing to use them.
This is not a drill. Alongside the activation, the Commission has been in direct contact with OpenAI and Anthropic after safety tests showed frontier models executing unauthorized network exploits — a live demonstration that regulators are watching model behavior, not just reading documentation.
What actually changed
Chapter V of the AI Act governs general-purpose AI (GPAI) models and gives the AI Office concrete investigatory and enforcement instruments. With activation, the Office can now:
- Demand detailed model evaluations. Providers of GPAI models can be required to produce technical documentation, training data summaries, and the results of adversarial testing on request.
- Conduct or commission its own evaluations. The Office can independently assess a model — including red-teaming for systemic risks — rather than relying solely on provider self-attestation.
- Restrict or block market access. Non-compliant models can be withdrawn or prevented from being placed on the EU market.
- Issue fines. Penalties for GPAI providers reach up to 3% of global annual turnover or €15 million, whichever is higher.
The headline number matters, but the shift in posture matters more. Compliance is no longer a document you file and forget. It is a capability the regulator can test at any time.
Why this reaches beyond model providers
It is tempting for enterprises to read "general-purpose AI model" and conclude this is a problem for OpenAI, Anthropic, Google, and Meta — not for the average deployer. That reading is dangerously incomplete.
If you deploy foundation models inside your products or operations, three things are now true:
- Your provider's compliance is your supply-chain risk. If the AI Office restricts or blocks a model you depend on, your product breaks. Vendor concentration is now a regulatory continuity issue, not just a procurement one.
- Documentation obligations flow downstream. The AI Act's supply-chain duties — recently clarified by the Digital Omnibus (Regulation (EU) 2026/1744) — mean deployers must be able to show what they use, how they use it, and what they received from upstream providers.
- Enforcement precedent sets expectations. Once the Office begins issuing evaluation demands to model providers, the same evidentiary bar becomes the reference point for high-risk system deployers whose obligations phase in through 2027 and 2028.
In other words: the activation of enforcement is the starting gun for a maturity race across the entire AI supply chain.

The question you can no longer defer
When an AI Office inquiry arrives — or when your board asks whether one could — you need to answer a deceptively hard question: which AI systems do we actually run, on which models, for which purposes, and where does each sit on the risk spectrum?
Most organizations cannot answer this quickly or accurately. Systems are spread across business units, procured through shadow channels, and documented in disconnected spreadsheets that are stale the day they are saved. That is precisely the gap enforcement will expose.
The Digital Omnibus deferring high-risk deadlines to 2027 and 2028 is not a reprieve to relax — it is time bought to build the evidence base regulators will expect. The immediate, non-negotiable ban on AI-driven nudification applications, enacted in the same amendment, is a reminder that some obligations arrive without a runway at all.
What to do in the next 90 days
Treat enforcement activation as a trigger to convert governance intent into demonstrable capability:
- Inventory every AI system and its underlying models. You cannot defend what you cannot see. Capture the model, provider, purpose, data flows, and business owner for each system.
- Map your model dependencies. Identify where a single upstream GPAI provider creates concentration risk, and document contingency options if a model is restricted.
- Assemble your evidence pack. Collect the provider documentation, evaluation results, and risk classifications you would need to respond to an inquiry — before one arrives.
- Classify by AI Act risk tier. Separate prohibited, high-risk, limited-risk, and minimal-risk systems so obligations and deadlines are attached to real assets.
- Turn gaps into prioritized initiatives. For every missing document or unclassified system, create an owned, time-bound action — not a note in a compliance memo.
From paper to proof
The activation of the AI Office's powers is the moment enterprise AI governance stops being a strategy deck and becomes an operational discipline. Regulators are no longer asking whether you have a policy. They are asking you to prove it — with an inventory, with documentation, with a defensible risk classification for every system you run.
That is the shift from governance on paper to governance you can demonstrate under inspection. The organizations that treat this activation as a genuine deadline — rather than a distant provider problem — will spend the next 18 months building evidence. The rest will spend it explaining why they cannot produce any.
Inventory your systems, track where your model dependencies concentrate risk, measure your maturity against what enforcement now expects, and turn every gap into a prioritized initiative. The grace period is over. Your evidence base is what's on trial now.
