On 2 August 2026, the European Commission’s AI Office gained binding enforcement powers under the EU AI Act.
For the first time, a jurisdiction can compel frontier labs to provide information, grant model access for independent evaluation, implement mitigations, restrict or withdraw models, and impose fines of up to €15 million or 3% of worldwide annual turnover.
This is a landmark moment. But it raises a single, urgent question: can the EU actually enforce against the world’s most capable AI labs, or is this a paper tiger?
Why enforcement matters now
The EU AI Act's obligations for general-purpose AI model providers have applied since August 2025. What changed this month is that the European Commission's enforcement powers, including the ability to impose fines and demand corrective actions, have now officially come into effect.
This matters because the industry’s voluntary safety practices are failing. The Future of Life Institute’s Summer 2026 AI Safety Index assessed leading frontier labs across 37 indicators. No major lab earned better than a C+ overall, with existential safety as the weakest domain. Four of nine developers documented no dangerous capability assessment at all. Frameworks rarely specify quantitative thresholds, independent audit, or who can halt a deployment. Several developers have made pause commitments entirely contingent on competitors’ behaviour.
Voluntary commitment is not working. Binding enforcement is the only alternative.
The case for enforcement is not hypothetical
The Act’s recitals name four categories of systemic risk justifying enforcement: chemical and biological uplift, loss of control, offensive cyber capability, and large scale manipulation.
Of these, cyber offence is where the evidence may now be strong enough to enforce. The harm is already concrete for finance, banking, and asset management. And loss of control is no longer hypothetical. Just days before enforcement powers took effect, OpenAI confirmed that two models, including flagship Sol, broke out of a secure test environment and compromised another company’s production infrastructure.
The evidence exists. The legal framework exists. The question is whether the EU will use it.
The enforcement challenge
But enforcement requires capacity. The AI Office’s enforcement unit has 36 people.
The labs they are meant to oversee have thousands of engineers, billions in capital, and models of rapidly growing capability. This creates a significant gap between legal authority and operational capacity. The question is how it will bridge this gap and whether it can do so effectively.
There are possible paths forward. The AI Office could develop deep technical partnerships with independent researchers and academic institutions. It could build specialised evaluation capacity over time. It could prioritise enforcement where the evidence is strongest and the risks are most concrete. And it could leverage the fact that providers operating in the EU market have strong incentives to engage constructively with the regulator.
The coming months will reveal whether the EU can translate its legal authority into genuine oversight. It is a question of strategy, resources, and institutional learning.
A test of seriousness
The EU is for now the only jurisdiction with binding powers to truly raise standards at the frontier. The United States relies on voluntary commitments. China has its own regulatory approach, but it is not structured around the same transparency and enforcement mechanisms.
Whether the EU uses its new powers and how it navigates the resource constraints and political pressures will define whether the AI Act is a genuine safeguard or a symbolic gesture. A 36 person enforcement unit facing the world’s most capable labs is a structural mismatch. But it is also a beginning.
The world is watching.
Join us for this conversation
Risto Uuk, Head of European Policy and Research at the Future of Life Institute, joins AI Safety Hong Kong to explain what the regime can actually deliver. Risto helped shape the general-purpose AI and systemic risk provisions of the EU AI Act and brings an insider’s perspective on both the law’s ambitions and its limits.
He will examine:
What the AI Office can now do
Where the strongest evidence for enforcement exists, particularly in cyber offence
How the Summer 2026 AI Safety Index reveals the gap between industry rhetoric and practice
Whether the EU can realistically enforce against the most powerful labs
This talk is essential for AI safety researchers, policy professionals, compliance officers, and anyone concerned with the future of AI governance. No technical background required.
About the Speaker:
Risto Uuk is the Head of European Policy and Research at the Future of Life Institute, where he contributed to shaping the general-purpose AI and systemic risk provisions of the EU AI Act. He is a PhD researcher and co-founder of the AI Safety Lab at KU Leuven, a member of Estonia’s government AI advisory board under the Prime Minister, and co-author of The AI Endgame (Wiley, forthcoming). He also runs one of the most widely read newsletters on the EU AI Act.
Event Details
📅 Date: 1 September, 2026
🔗 Register: https://luma.com/mxsd8eef
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.