On August 2, 2026, the EU began enforcing its rules on general-purpose AI models. Most headlines called it European pre-market approval. The reality is more interesting — and more effective.
Software lived for years by one creed: ship first, apologize later. That creed just died, and not only in Brussels. Washington is reaching for the same lever from the other side, trying to assert pre-market control over frontier labs. That is the part many founders still do not want to say out loud. Two governments now get a say in the day your model is allowed to exist.
The law does not create a formal checkpoint before a lab trains or ships a general-purpose AI model. No one in Brussels stamps GPT-5 or Claude 4 before the servers turn on. What the EU built is different. Under Articles 91 and 92, the Commission can demand your documents, inspect how the model was built, and order changes after the fact.
If you ignore that demand, they can fine you up to three percent of global annual revenue. That is enough to make any serious lab pay attention. So no, Europe did not put a guard at the front door. It put a trapdoor in the room.

The same pressure — no formal gate, but heavy consequences — shows up in how the rules treat open-source models.
The conventional press narrative insists that open-weight models escape the reach of the AI Act. This comforting falsehood ignores the math embedded in the statute. The exemption vanishes the moment training compute crosses ten to the twenty-fifth power FLOPs. Meta training Llama models at scale or any independent lab pushing past the threshold finds themselves immediately inside the regulatory perimeter regardless of whether weights sit on GitHub or remain locked in a vault. The carve-out applies only to small research projects. It offers no shelter to the models shaping the commercial market.
But there is one place the EU backed down, and the reason is telling.
The early version said Europe could go after American labs for scraping data anywhere in the world. Then, on July 10, 2026, that language disappeared from the final rules. Brussels blinked under pressure from American tech lawyers. The result is simple: US labs can keep vacuuming up the web without facing that cross-border penalty from Europe. Where Europe had leverage, it pushed. Where it had none — data already scraped elsewhere — the threat vanished.
The EU also solved a practical problem with the same move: it does not have enough people to police this market.
So it outsourced the work. Competitors, angry startups, and whistleblowers can file official complaints. Brussels turned corporate rivalry into a policing force. A lab does not just answer to the Commission. It answers to anyone with a grievance and a filing channel.

The rules also treat different models differently — and the timing is not random.
Models placed on the market before August 2, 2025 get a grace period until August 2, 2027. Models released after that date face inspection now. GPT-4 and Claude 3 have room to adjust. Newer systems do not. The irony is hard to miss. Older, potentially less safe models get a two-year regulatory vacation, while bleeding-edge architectures face immediate inspection. Their business case may not even be proven yet. The newest, most powerful models carry the heaviest load on day one. The timeline literally inverts risk management.
That leads to the choice every major lab now faces.
Sign the General-Purpose AI Code of Practice, and the AI Office gives you a presumption of good faith during early enforcement. Refuse, and you carry the burden of proof yourself. Every request is sharper. Every investigation starts colder. Some labs will sign because the signal matters. Others will refuse on principle and dare regulators to prove their case.
That is where this lands. Brussels is pulling from one side. Washington is pulling from the other. The era of shipping free is over. The day your model is allowed to exist is no longer decided in a startup garage. It is negotiated in regulatory waiting rooms.

Frequently Asked Questions
What happens if an AI lab ignores an information request from the European Commission?
The Commission can demand documents and answers under Article 91. If a lab blows that off, the fine can reach three percent of global annual revenue. That penalty lands before any long argument about whether the model is safe or unsafe.
That is why labs do not treat these requests like routine paperwork. Europe does not need a formal approval line before launch if it can hit a company that hard the moment it refuses to cooperate.
Are open-source models completely exempt from the EU AI Act?
Open-source models enjoy exemptions only until their training compute crosses the statutory threshold of ten to the twenty-fifth power FLOPs. Once training compute surpasses that boundary, systemic risk provisions apply regardless of whether model weights remain public or proprietary. Small and medium developers retain freedom, but frontier open-weight creators face identical compliance burdens to closed-source commercial vendors.
How does crowd-enforcement work under the new enforcement regime?
The EU did not hire a small army of officials to watch every lab. It opened the complaint system instead. Competitors, downstream companies, and whistleblowers can file reports directly with the Commission when they think a lab broke the rules.
That changes the shape of enforcement. A rival does not need to beat you only in the market. It can drag you into a regulatory fight too. Every messy training record and every weak disclosure can become ammunition.
Why do older models have a longer grace period than newer releases?
The legislative text establishes August 2, 2025 as the dividing line for market entry. Models placed before that date retain a two-year compliance runway extending to August 2, 2027. Models appearing after that date face immediate enforcement. Policymakers attempted to shield existing enterprise deployments from sudden disruption while applying strict rules only to newly developed frontier systems.
Board & C-Suite AI Governance Briefings
Facing international AI compliance, risk exposure, and governance triggers across frontier models? Liat Ben-Zur provides strategic AI risk advisory and board briefings for enterprise leadership teams.
The Bias Advantage
The book behind these essays: how unconventional leaders gain power in an AI-driven world. Out now from Page Two.