← Back to articles
European AI Act: What Really Changes from August 2, 2026

European AI Act: What Really Changes from August 2, 2026

Retroactive fines, technical inspections, transparency obligations for chatbots: the new enforcement regime of the European AI regulation is now active. What this means for OpenAI, Anthropic, Google, Mistral, and all models sold in Europe.

By Brice Matter··3 min read

August 2, 2026 marks the true shift in the European Artificial Intelligence Regulation. On paper, obligations for general-purpose AI models (GPAI) and Article 50 on transparency have been in effect for a year. In practice, the European Commission did not have the power to impose fines during this first year. This transitional period is over. From now on, the regulator has teeth.

What the Commission Can Now Do

The AI Office, supported by the national market surveillance authorities of each Member State, has had a full arsenal since August 2:

  • Demand the complete technical documentation of a model
  • Conduct internal technical assessments (audits, security tests, red-teaming)
  • Impose mitigation and compliance measures
  • Restrict or remove a model from the European market
  • Impose retroactive fines, applicable to violations observed since August 2025

The Sanctions Scale

Two caps coexist, depending on the nature of the violation:

  • Violation of GPAI obligations: up to 15 million euros or 3% of the annual global turnover, whichever is higher.
  • Prohibited AI practices (e.g., social scoring, subliminal manipulation, biometric categorization for policing purposes without exemption): up to 35 million euros or 7% of the annual global turnover.

For a giant like OpenAI (estimated revenue of $20 billion in 2026), the upper range potentially represents more than 1.4 billion euros. For Anthropic, whose Q2 2026 exceeds $10 billion, the same 3% weighs heavily.

The Transparency Obligation (Article 50) Becomes Enforceable

Any interactive AI system—chatbot, voice agent, customer assistant—deployed in the Union must now clearly declare to the user that it is not human, from the start of the interaction. The same goes for AI-generated or modified content: it must be marked as such (watermarking, explicit mention, or metadata).

Concretely: French sites using support chatbots (ChatGPT-based, Anthropic, Mistral, specialized providers) must have updated their interface before August 2. Editorial teams publishing AI content without declaring it face sanctions.

The Timeline to Remember

August 2, 2025: GPAI obligations + Article 50 come into force, without sanction power.
August 2, 2026: The Commission can sanction, including retroactively for violations since 2025.
August 2, 2027: Final deadline for models published before August 2025 (“legacy”).

Frontier models like GPT-5.6, Claude Fable 5, Gemini 3.7, Llama 5 are therefore fully in the crosshairs.

The French Position: Mistral Takes the Lead

Mistral AI emerges as the only frontier player with a structurally compliant response: headquarters in the European Union, inference capacity hosted in the EU, downloadable weights for sovereign hosting. The company is among the ~24 signatories of the General-Purpose AI Code of Practice published by the AI Office.

For IT departments of French mid-sized companies subject to sectoral obligations (banks, health, public sector), Mistral becomes a rational rather than ideological choice: no AI Act to negotiate with a Californian provider, no risk of cross-sanction, personal data that does not leave the territory.

What Changes in the Short Term

  1. American providers will document like never before. The legal teams of OpenAI, Anthropic, Google, Meta are producing system cards, model cards, and risk assessments to avoid official requests from the AI Office.
  2. A phase of mutual learning. The first cases from the Commission will serve as jurisprudence. The first major public sanction is expected within 6-12 months.
  3. European buyers integrate compliance into their RFPs. “Model compliant with the AI Act” becomes a checkbox, just like GDPR.
  4. The debate on European restraint is reignited. Some actors (Big Tech, chambers of commerce) are advocating for a pause or a relaxation—the Commission is holding firm for now.

What to Do If You Are Concerned

For a French company deploying a GPAI model (SaaS or integrated):

  • Map out the AI systems in production and their AI Act classification (prohibited / high risk / limited / minimal)
  • Ensure that chatbots and voice agents declare their AI nature
  • Mark generated content (visible watermark, tag, mention)
  • Obtain system cards from providers
  • Document personal data processing by models (cross-reference with GDPR)

The timeline is short, the fines are real, and for the first time since GDPR, Europe has a real digital policing power. It remains to be seen with what intensity the Commission intends to exercise it.