Omi Iyamu · Personal DossierVol. XVII · 2026 Edition
Omi Iyamu.
← All essays
2026 · 08 · 043 min read

Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers

# The month EU AI Act enforcement stopped being theoretical

The Commission's AI Office switched on its enforcement powers over general-purpose AI models on August 2. If you serve EU users, the calendar you were preparing against is now the calendar you are operating under.

The powers themselves are the ones that have been in the text for two years — request documentation, run technical evaluations of a model directly, demand risk-mitigation measures, restrict market access, fine providers up to fifteen million euros or three percent of global turnover, whichever is higher. What changed on August 2 is that the Office is now allowed to use them. Non-signatories to the Code of Practice, per the Commission's own language, should expect a larger number of requests for information.

The Commission also published the first list of Code signatories the same day. More than 180 organisations have signed the transparency Code, which is the flagship soft-law instrument that offers a presumption of conformity in exchange for meeting specific disclosure and marking obligations. The Section 1 list reads like the frontier map — Anthropic, OpenAI, Google, Meta, Mistral, Cohere, Aleph Alpha, Black Forest Labs, Synthesia. The Section 2 list is more interesting: Bulgari, Getty Images, Iberdrola, Lenovo, Lufthansa. Signatories are enterprise buyers, not just labs. That is a signal about procurement policy in Europe over the next year.

Three practical points if you are actually building here.

One: if you are a signatory, the Office will focus its early enforcement effort on monitoring adherence to the Code. That gives you a legible target — the Code itself is public — and it gives you a place to be measured that the whole ecosystem now recognises. If you are not a signatory, you are still obligated to demonstrate conformity by other adequate means, and the practical difference is that the Office will send you more requests for information. Both paths are valid. The signatory path is cheaper to operate as a program, and it is the one I have been advising clients into for the last two quarters.

Two: the machine-readable content marking obligations that arrived with Article 50 on August 2 are the part most teams have deferred. Chatbot disclosure is the easy half. The synthetic-content marking half — SynthID-style watermarks, C2PA credentials, provenance signals in a form other systems can verify — is not a policy problem. It is a production engineering problem, and most stacks I have looked at do not have it plumbed end-to-end. The deadline for machine-readable marking of existing content is December 2. That is four months, which is roughly one sprint less than most teams think.

Three: the transatlantic tension is real and worth pricing in. The enforcement start lands two weeks after the EU fined Google a billion dollars under the Digital Markets Act, and the White House has openly threatened tariff retaliation. If you are a US lab deciding how much documentation to ship into Europe over the next quarter, you are not making a technical call — you are making a political one. My read is that the Code-of-Practice signatories will do the minimum to hold their EU market access and will fight everything else through the Trade and Technology Council, which is exactly the venue the Commission built for it. That is fine. It is orderly. It is much better than the alternative, which was every fine being litigated separately.

What I am watching for in the next thirty days: the first Article 50 request-for-information sent to a non-signatory, the first formal enforcement action against a signatory for a Code violation (my guess is a watermark-provenance gap, not a documentation gap), and whether the UK's own AI Bill picks up any of the EU's marking specifications before its second reading in October. Any of those three will tell you a great deal about what the operating environment for AI companies in Europe will look like at Christmas.

I have been telling clients since spring that the right posture on August 2 was one you decided in June, not one you decided in August. That advice is now audited by the calendar. If your team has not written down your position on the Code, your marking plan, your incident-reporting path, and your named regulatory contact in the EU, that is this week's work.

Reply if you want the one-page compliance-posture template I have been sending. Not a compliance product, just a checklist, but it saves a meeting.

If this was useful, the weekly Brief covers shorter ideas like this every Wednesday.
Read the Briefs →
© Omi Iyamu · MMXXVIContact → · linkedin.com/in/omiiyamu