August 2, 2026: the date the EU AI Act stopped being a warning
2026·09·27 · 3 min read

Foto: Christian Lue · Unsplash
Esta entrada todavía no está traducida a este idioma — se muestra la versión original.
The obligations for general-purpose AI models took effect in 2025, but the Commission could not enforce them until a year later. That grace period ended on August 2, 2026. Here is what is actually binding, and what is still only recommended practice.
Two dates, and only one of them mattered
The AI Act's rules for general-purpose AI models — GPAI, in the Act's language — took effect on August 2, 2025: every model placed on the EU market from that date has to comply. But the Commission's enforcement powers, the ones with teeth, were held back for a year. Requests for information, access to models and model recalls only became available on August 2, 2026. The gap was a deliberate grace period to let providers work with the AI Office. (artificialintelligenceact.eu)
That is the whole story of the date: nothing new became illegal in August 2026. What changed is that the regulator can now act on what was already required.
The Code of Practice is not the law
This is the distinction that gets flattened in most coverage. The GPAI Code of Practice is voluntary. It offers a framework for demonstrating compliance, and providers remain free to demonstrate it by other appropriate means. Signing it is the path of least resistance, not the obligation. (European Commission)
So when a lab announces it has signed the Code, it has chosen a compliance route. When a lab announces it has not, that is not automatically non-compliance — it means the burden of showing an equivalent route is on them.
What signing actually puts you on the hook for
Reading the Code chapter by chapter, three things stand out for anyone who builds rather than lobbies:
Documentation. Up-to-date documentation for every GPAI model distributed in the EU, following a standardized Model Documentation Form — licensing, technical specs, intended uses, datasets, compute and energy usage. Kept for at least ten years and handed over to the AI Office and to downstream users on request. Public release is encouraged, not required.
Copyright. A copyright policy applying to every GPAI model distributed in the EU, aligned with the Code's standards.
Safety and security, but only for systemic risk. The heavy chapter — pre-market assessment, ongoing monitoring, incident reporting — applies to models classified as posing systemic risk. It comes with real deadlines: signatories must confirm their Safety and Security Framework within four weeks of notifying the Commission that a model crosses the systemic-risk threshold, and at least two weeks before launch.
The open-source carve-out is narrower than people think
Free and open-source models are exempt from the documentation and safety commitments — unless they are classified as GPAI models with systemic risk. Release the weights of something small and the exemption applies. Release the weights of something at the frontier and it does not. Given how much open-weight capability shipped this year, that conditional is going to get tested.
What to take from it
If you deploy someone else's model, the practical consequence is that you can now ask for documentation and expect it to exist, because the provider has to supply it to downstream users on request. That is a lever that did not practically exist before August, and it costs an email.