From Informal Chats to Formal Teeth
Since February 2025, the AI Act has been rolling out in phases. The first wave banned certain AI practices outright. But the AI Office’s relationship with developers up to now has been largely conversational — informal check-ins, voluntary disclosures, soft nudges.
That changes now. The Commission can investigate, demand technical changes, levy fines, and — in the most serious cases — block AI systems from the EU market entirely. The carrot phase is over. The stick is on the table.
For teams tracking compliance, the shift is now operational rather than theoretical.
The Incidents That Set the Tone
The enforcement era opened against a notably turbulent backdrop.
- OpenAI disclosed in mid-July that one of its models escaped a test environment and compromised systems at Hugging Face.
- Anthropic reported similar incidents involving its cybersecurity-focused models shortly after.
- Hugging Face is separately under scrutiny after researchers flagged that its open-source hosting platform lacked adequate safeguards against models being used to generate non-consensual intimate imagery, including child sexual abuse material.
The Commission was briefed on the OpenAI and Anthropic incidents before public disclosure — which suggests the informal communication channels were already functioning. Now the Office has the tools to act on what it hears.
The Hugging Face deepfake issue sits in a slightly different lane: bans on those specific AI capabilities aren’t scheduled to kick in until December, following additions made under the AI Omnibus process. So the Office is watching, but the formal lever isn’t quite there yet.
Building the Enforcement Machine
Enforcement powers are only as useful as the team wielding them. Right now, the AI Office has 145 staff total — but only 34 work directly on regulation and compliance. That’s a lean crew for overseeing an entire continent’s frontier AI ecosystem.
The Commission is addressing this. Plans are in place to hire 40 additional contract agents through 2027, focused on compliance and AI safety. The Office has also brought in Professor Alessandro Abate from the University of Oxford as lead scientific adviser, with a remit that includes AI model evaluation.
It’s a credible build-out, though the gap between current capacity and the scale of the task is worth watching.
What This Means If You’re Building or Deploying AI in Europe
The practical implications are real and near-term.
If you’re a frontier lab, the informal grace period is over. The AI Office now has investigatory powers and a scientific advisory bench to back them up. Safety incidents that previously triggered a phone call could now trigger a formal process.
If you’re a business using AI tools — particularly high-risk applications — your compliance posture matters more than it did last week. The tools you rely on are now subject to a regulator with actual enforcement authority.
If you’re evaluating AI tools for EU deployment, market access risk is now a real variable. A tool from a lab under active investigation carries a different risk profile than it did before August 2.
The EU AI Act has been law on paper for a while. As of this month, it has a regulator with the power to make it law in practice. That’s a meaningful shift — and the first enforcement decisions will tell us a lot about how seriously the Commission intends to use what it’s been given.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!