AI Policy

The GPAI Code of Practice Enforcement Window Opens: What August 2026 Actually Changes for Model Providers

The Digital Omnibus deferred the AI Act's high-risk deadlines. It did not touch GPAI enforcement, which became live on 2 August 2026.

By Institute for Joint Cognition & AI · 5 min · 22 September 2026

Modern European institutional building facade with glass and stone under daylight

Two AI Act deadlines sat on 2 August 2026. One moved. The other did not, and the difference is the most important fact for anyone providing a general-purpose AI model in the EU.

The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July — deferred high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. It arrived six days before the original high-risk deadline, making the deferral enacted law rather than a pending proposal.

The Commission’s supervision and enforcement powers over general-purpose AI providers were not deferred. They came into force on 2 August 2026 as scheduled.

What changed on 2 August, and what did not

GPAI provider obligations themselves have applied since 2 August 2025. What was missing for a year was the Commission’s ability to do anything about non-compliance. The 2026 date closes that gap: the obligations were already live, and now there is an enforcement apparatus behind them.

The powers sit with the Commission exclusively under Article 88, exercised through the AI Office, and fall into three supervisory instruments plus a fining power.

Article 91 — information. The Commission may require providers to hand over technical documentation and information.

Article 92 — evaluation. The Commission may conduct evaluations to assess compliance or investigate systemic risk, which includes compelling model access for the purpose.

Article 93 — measures. The Commission may require a provider to take appropriate measures to comply, request risk mitigation where serious concerns exist, and order restriction, withdrawal, or recall of a model from the EU market.

Article 101 — fines. Up to 3% of annual worldwide turnover or €15 million, whichever is higher.

The critical structural point is what the fine attaches to. Article 101 reaches not only substantive infringements but also non-compliance with a documentation request, failure to implement required measures, and denial of model access for evaluation. Procedural stonewalling is independently finable. A provider confident in its substantive compliance can still incur the maximum exposure by handling a request badly.

Substantive obligations versus procedural ones

The Chapter V obligations divide along a line worth internalising, because the two categories fail differently.

The substantive obligations under Articles 53 and 55 are documentary and policy artifacts: maintaining technical documentation, providing information to downstream providers, adopting a copyright compliance policy, and publishing a sufficiently detailed summary of training data content. These are built once and maintained. Their failure mode is that the artifact does not exist or is inadequate, which is discoverable only when someone asks.

The procedural obligations under Articles 51 to 54 are about responsiveness: cooperating with the Commission and national authorities, notifying the Commission of high-impact capabilities within two weeks, appointing an authorised representative for third-country providers, and providing model access on request. Their failure mode is a missed clock.

The two-week notification for models meeting the systemic-risk capability threshold is the tightest of these, and it is the one most likely to be missed by an organisation that has not assigned it to a named owner before the triggering evaluation happens.

The grace period does not cover what people think

Providers whose models were placed on the market before 2 August 2025 have until 2 August 2027 to reach full compliance. This is a genuine accommodation, and it is narrower than it sounds.

It applies to the model, not the provider. A provider with a pre-August-2025 model inside its grace window and a newer model released after that date is fully obligated on the newer one, with enforcement powers live now. Organisations running a mixed portfolio should be clear about which models sit in which regime rather than treating 2027 as an organisational deadline.

What signing the Code of Practice buys

The GPAI Code of Practice is voluntary, and the benefit it confers is regularly overstated.

Adherence to an adequate code lets a provider demonstrate compliance, and Commission guidance indicates that adhering providers receive increased trust, with the Commission focusing enforcement on monitoring adherence to the code rather than opening broader investigations. That is a meaningful reduction in investigative exposure.

It is not a presumption of conformity. The code is a demonstration mechanism, not immunity, and signing it does not convert a substantive failure into compliance. A provider that signs and then does not adhere has arguably worsened its position, having made a public commitment against which its conduct is now measured.

Enforcement will not only come from the Commission

The pathways into an investigation are broader than the AI Office’s own initiative.

National market surveillance authorities may request Commission intervention and process public complaints. Downstream providers can lodge complaints about suspected GPAI infringements — a route that matters commercially, because a provider’s own customers are the parties best positioned to know whether the Article 53 downstream information obligations are being met. The Scientific Panel can issue qualified alerts on systemic or identifiable risks, which trigger a rapid Commission review with a two-week decision requirement.

That last mechanism deserves attention from anyone modelling enforcement timing. A qualified alert compresses the Commission’s decision window to two weeks, which is not enough time to assemble documentation that does not already exist.

The practical read

The deferral of high-risk obligations to December 2027 happened because the surrounding ecosystem was not ready — harmonised CEN-CENELEC standards were behind, Commission guidelines were still in draft, and several Member States had not resolved their supervisory infrastructure. None of those constraints applied to GPAI enforcement, which is centralised in the Commission and does not depend on Member State designation or harmonised standards.

For a model provider, the operative questions are narrow. Does the Article 53 technical documentation exist now, in a form that could be produced on request? Is the training data content summary published? Is there a named owner for the two-week high-impact capability notification? For a third-country provider, is the authorised representative appointed? And if model access were demanded under Article 92 next month, is there a process for granting it — because refusing is itself the finable event.