EU Begins Enforcing AI Act, Expanding Oversight of OpenAI, Anthropic and Google The European Union has begun enforcing the AI Act, granting the European Commission's AI Office authority to investigate providers of general-purpose AI models, require technical evaluations, restrict market access, and impose fines of up to €15 million or 3% of annual global revenue for violations, affecting companies including OpenAI, Anthropic, and Google. Non-EU providers must appoint an authorized representative in the EU, and transparency rules now require chatbots to disclose AI identity and AI-generated content to carry machine-readable identifiers. The Commission has also established a 60-expert scientific advisory panel led by Alessandro Abate of the University of Oxford. The European Union has entered a new phase of AI regulation, granting the European Commission expanded authority to oversee the world’s largest AI model developers under the AI Act. The Commission’s AI Office can now investigate providers of general-purpose AI GPAI models, require technical evaluations, restrict market access within the EU and impose fines for violations, increasing regulatory pressure on companies including OpenAI, Anthropic and Google. The latest measures are another milestone in the implementation of the AI Act, the comprehensive legislation adopted in 2024 to establish a common regulatory framework for AI across the EU. The new enforcement authority extends beyond European companies, applying to any provider that makes a general-purpose AI model available within the EU regardless of where the company is headquartered. Non-EU providers must also appoint an authorized representative based in the EU to serve as the regulator’s point of contact. Significant Penalties Under the new rules, regulators may request access to AI models for evaluation before deployment, require providers to supply technical documentation and training data summaries, verify copyright compliance policies and assess whether advanced models present systemic risks. Companies that fail to comply may face penalties of up to €15 million or 3% of annual global revenue, whichever is greater. Legal experts also note that companies can incur penalties simply by refusing information requests, providing misleading responses or obstructing model evaluations, even without violating substantive AI requirements. The regulations introduce still more obligations for the leading AI models whose capabilities could create broader societal risks. These providers must demonstrate measures to mitigate threats including chemical, biological, radiological, nuclear, and cybersecurity risks, and scenarios involving loss of human control and threats to fundamental rights. Transparency requirements also became effective. Chatbots and other interactive AI systems must clearly inform users that they are communicating with AI rather than a human. AI-generated or AI-altered content, including deepfakes, must carry machine-readable identifiers that allow the material to be detected programmatically. To support enforcement, the Commission has established a scientific advisory panel comprising 60 independent AI experts. The Commission has appointed University of Oxford computer scientist Alessandro Abate as Lead Scientific Adviser. The AI Office has also introduced complaint, whistleblower and downstream-provider reporting tools that allow businesses and individuals to report suspected violations confidentially. European officials have been seeking greater access to frontier AI systems as model capabilities have advanced rapidly. OpenAI has acknowledged ongoing engagement with the Commission regarding the AI Act, while Anthropic has previously agreed to provide model access following discussions with European authorities. Google said it remains committed to complying with the new regulatory framework while continuing to invest in AI infrastructure across Europe. For US enterprise tech leaders, the significance may extend beyond Europe. The EU AI Act establishes the world’s first comprehensive governance frameworks for foundation models, and these requirements are likely to influence product development and compliance strategies in locations across the globe.