← All news
ComplianceEU AI ActRegulation

The EU AI Act's Enforcement Phase Has Begun — Here's What GPAI Providers and Enterprises Must Do Now

Obiguard Research Team·August 7, 2026·3 min read

August 2, 2026 was a quiet deadline that most enterprises spent the last year preparing for without much fanfare — and it just became a lot less quiet. As of that date, the European Commission's AI Office is formally empowered to investigate and enforce the EU AI Act's obligations on providers of general-purpose AI (GPAI) models, according to Help Net Security and legal analysis from Wilson Sonsini.

What actually changed

The substantive obligations weren't new — GPAI providers who placed models on the market on or after August 2, 2025 have technically been subject to the Act's requirements for a year already. What changed on August 2, 2026 is enforcement teeth: the AI Office can now request documentation, conduct evaluations, order risk-mitigation measures, force product recalls or market restrictions, and issue fines.

The core obligations being enforced center on Articles 53 and 55: maintaining up-to-date technical documentation, providing that documentation to downstream AI system providers, publishing a summary of training content, and adopting an EU-copyright-compliant policy. Providers whose models predate August 2025 have a longer runway — until August 2, 2027 — but the direction of travel is unambiguous.

Why this matters beyond the EU

Very few enterprises deploy AI in a way that's cleanly contained to one jurisdiction. If your organization uses a GPAI model in any EU-facing product, or your own AI system relies on a foundation model whose provider now owes the EU documentation it may not have previously prioritized, that documentation gap becomes your gap too. Downstream deployers under the AI Act are expected to be able to demonstrate the same kind of traceability the Act demands upstream — which model, which version, what it was trained on, what risk category it falls into, and what controls sit around it.

Enforcement also has a way of resetting internal priorities. Compliance requirements that engineering teams treated as "eventually" tend to become "now" the moment an eight-figure fine becomes a real possibility rather than a hypothetical one.

Where Obiguard fits

This is exactly the traceability problem Obiguard's Framework Mapping is built for — mapping the models, agents, and policies your organization actually runs against the compliance frameworks (EU AI Act included) that apply to them, so "can we prove this" has an answer that doesn't start with a scramble through Slack history. Paired with the audit ledger, every AI request your organization processes is timestamped, attributable, and exportable for exactly the kind of evaluation the AI Office can now request.

If EU AI Act enforcement just moved from "compliance roadmap item" to "active regulatory risk" on your desk, get in touch — mapping your current AI footprint against the Act's obligations is a good place to start.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →