From 2 August 2026 the European Commission's AI Office can fine providers of general-purpose AI models (GPAI) up to 3% of global annual turnover or 15 million euros, whichever is higher. This follows from Article 101 of Regulation (EU) 2024/1689, the EU AI Act. The fine applies to breaches of GPAI obligations, failure to provide requested documentation, failure to comply with imposed measures or refusing access for model evaluations.
Large language models behind systems such as ChatGPT, Claude and Gemini fall under the GPAI category. For organisations that rely on these models this means their AI supplier can become the subject of an investigation, orders or fines. That is a risk that carries through into their own continuity and accountability, even though the sanction lies with the provider.
What does Article 101 of the EU AI Act say exactly about GPAI fines?
According to the explanation of Article 101 on the European Commission's AI Act Service Desk, the Commission can impose a fine on providers of GPAI models of up to 3% of their global annual turnover or 15 million euros, whichever is higher. The sanction applies to intentional or negligent breaches.
The situations that can trigger a fine are described concretely:
- breach of the obligations that apply to GPAI models;
- failure to provide requested information and documentation;
- failure to comply with measures imposed by the Commission;
- failure to grant the Commission access for evaluating a model.
Article 101 does not stand alone. The full text of Regulation (EU) 2024/1689 in the Official Journal contains in Article 99 a layered fine structure for the broader system: the highest band for prohibited practices, a middle band of 15 million euros or 3% for other obligations, and a lower band for certain information obligations. Practical analysis from Regulation-AI.eu on Article 99 explains that this middle band applies broadly to non-prohibited breaches by providers, deployers, importers, distributors and notified bodies, including the transparency obligations under Article 50.
What powers does the AI Office gain from 2 August 2026?
The analysis from SERVOLA, published on 9 July 2026, places a concrete date on enforcement. According to that piece, the Commission's GPAI enforcement powers become applicable from 2 August 2026. From that moment the AI Office can request documentation, carry out model evaluations, impose measures for compliance and risk mitigation, and impose fines under Article 101.
That enforcement lies centrally with the Commission is also apparent from its own page on the European AI Office. There it states that GPAI models are monitored directly by the Commission and that non-compliance can lead to fines. In our assessment this is the core of the shift: enforcement for large general-purpose models does not lie solely with national supervisors, but with a central EU body with its own investigative and sanctioning powers. That is editorial interpretation; the source text only establishes that the AI Office fulfils this role.
Anyone wanting to place the broader timeline will find context in our discussion of the firm AI Act obligations from August 2026 after the Digital Omnibus.
What does GPAI enforcement mean for organisations using ChatGPT, Claude or Gemini?
The fines target the providers of the models, not directly the buyers. Yet there is a knock-on effect. If a core supplier comes under investigation, receives an order to adjust or withdraw a model, or is fined, this affects the continuity and accountability of the organisations that build on that model. In our assessment this is the practical point for teams working with confidential or regulated information: supplier risk becomes an explicit layer in their own risk picture.
That makes a number of preparatory steps relevant, as an editorial recommendation and not as a legal standard:
- map out which GPAI models are actually used in which workflows;
- record which AI Act obligations belong to those providers, such as documentation, risk mitigation and transparency;
- arrange audit rights and evidence obligations in AI contracts;
- prepare exit and fallback for AI services during disruption, so that disruption at one supplier does not immediately bring a process to a standstill.
More background on compliance obligations is available in our topic hub on the EU AI Act and compliance.
How do you record in your own workflows which GPAI models you use?
The answer begins with visibility: knowing which model performs which task and which data goes to the supplier in the process. Without that overview it is difficult to demonstrate how a provider's obligations carry through into your own logging, privacy and oversight policy.
On this point a verification layer can help concretely. IamVera.ai is not a chatbot and not its own language model, but a privacy-focused verification layer for professionals working with confidential information. Vera can route a task through selected independent AI models and expose verification steps, corrections, disagreements and sources for inspection. This supports control but does not remove the need to check for hallucinations; the professional final judgement remains with the user. More on how teams use disagreement between models as a signal is available in our explanation of multi-model verification and its limits.
For the data side the Semantic Privacy Shield is relevant. It can replace sensitive document values with synthetic, session-only equivalents on EU infrastructure before AI processing; the AI chain analyses the synthesised version and the original values can then be restored locally. The workflow is fail-closed: if the privacy check fails, the document is not sent onward. This is an architecture description and not a claim of full GDPR compliance. Anyone wanting to gather evidence about AI use per workflow will find the accompanying overview there.
The core remains: from August 2026 EU enforcement targets the GPAI layer directly. Organisations that rely on large models would be wise to translate those upstream obligations into their own visibility, accountability and verification.
Sources and references
Sources: The article relies on Article 101 and the text of Regulation (EU) 2024/1689 via the AI Act Service Desk and EUR-Lex, on the European Commission's page on the AI Office, and on practical analyses from Regulation-AI.eu and SERVOLA.