When the European Union's AI Act entered into force in August 2024, it did so in stages, and the stage that matters most to the global AI industry arrived a year later: from August 2, 2025, the obligations for general-purpose AI models — the foundation models everything else is built on — became applicable. New models released since that date carry the duties immediately; models already on the market were given until August 2027 to comply.

The effect is visible not in courtrooms but in paperwork. Model providers now publish structured documentation, training-data summaries and evaluation results in forms that exist primarily because the Act requires them. Brussels, in other words, has become the world's de facto AI disclosure regulator.

Why it matters

The EU is following a playbook it has run before: regulate a market too large to abandon, and watch compliance become global because maintaining two product regimes costs more than adopting the stricter one. It happened with data protection after GDPR, and with phone chargers after the USB-C mandate. AI documentation is on the same trajectory — a model card written to satisfy the AI Act satisfies most other jurisdictions' emerging expectations at the same time.

For the industry, the sharp edge is the systemic-risk tier. Models trained above a compute threshold of 10^25 floating-point operations face additional duties: adversarial testing, systemic-risk assessment, incident reporting and cybersecurity protections. That threshold currently captures only the largest frontier models, which is precisely the intent — and precisely why frontier labs lobby over where it sits.

How it works

The Act's general-purpose obligations require providers to keep technical documentation for regulators and downstream developers, to honor EU copyright law including text-and-data-mining opt-outs, and to publish a sufficiently detailed summary of training content. Providers of open-weight models receive modified obligations — documentation and copyright duties apply, but some requirements are waived unless the model crosses the systemic-risk threshold.

Enforcement runs through the European AI Office, established within the Commission, which can request information, conduct evaluations and ultimately fine providers up to 3 percent of global turnover for violations of the general-purpose provisions. A code of practice, developed with industry through 2025, gives providers a recognized route to demonstrate compliance.

Evidence

The full text of Regulation (EU) 2024/1689 is published in the Official Journal, with Article 53 setting the general-purpose obligations and Article 55 the additional systemic-risk duties. The Commission's AI Office pages document the code of practice process and the phased application timeline, confirming the August 2, 2025 applicability date for general-purpose model obligations.

The competing read

Critics, including parts of the European tech industry itself, argue the Act front-loads compliance costs that large incumbents can absorb and startups cannot, and that regulating the model layer rather than specific uses risks freezing a moving target in legal text. Some member-state governments have pushed to slow or simplify implementation amid competitiveness worries. Supporters reply that the obligations are documentation duties, not approval gates, and that a predictable framework is itself a competitiveness asset.

What happens next

Two dates frame the next phase: August 2026, when most remaining provisions — including the high-risk system rules — apply, and August 2027, the compliance deadline for general-purpose models already on the market. In between, watch the first enforcement actions by the AI Office, the evolution of the compute threshold defining systemic risk, and whether the United States' state-by-state approach converges with or deliberately diverges from the European template.