In Six Days, Europe’s AI Law Gets Teeth. The Question Is Whether Europe Dares to Bite.

Jul 27, 2026 | europe & ai

In a nutshell

Four weeks ago, gafam.ai counted down to August 2 and explained what the EU AI Act would switch on and what Brussels had quietly deferred. That preview is now imminent reality: in six days the most consequential date in European AI regulation arrives. But the question worth asking on the eve of enforcement is no longer what the law says. It is whether Europe will actually use it — against companies that have started refusing to comply, and that a foreign government now shields as strategic assets. This is the moment European regulatory sovereignty is tested rather than asserted.

What Actually Switches On in Six Days

First, an update to the caveat we flagged on July 1. At that point the Digital Omnibus — which softened the Act's timeline — was still a provisional agreement. It is now settled: the European Parliament granted final approval on June 16, 2026 by a vote of 423 to 57 with 174 abstentions, pushing the most demanding high-risk obligations out to December 2027 and August 2028. The uncertainty is resolved. What remains for August 2 is fixed law.

And August 2 remains formidable. Three mechanisms activate together. The European Commission gains its active enforcement toolkit over general-purpose AI providers — the power to issue information requests, demand model access, order recalls, and levy fines. The Article 50 transparency obligations take effect: chatbots must disclose they are AI, AI-generated content must be marked in machine-readable form, and deepfakes must be labelled. And national market-surveillance authorities gain full power to investigate and sanction.

The penalties are real. Violations of the GPAI and Article 50 transparency obligations carry fines of up to €15 million or 3% of total worldwide annual turnover, whichever is greater. And there is a sharp detail: because the underlying GPAI obligations have been legally in force since August 2025, the Commission's new power to fine can reach back — violations dating to August 2025 become sanctionable from August 2, 2026.

The Compliance Split — Who Signed, Who Refused

Here is the fresh and revealing dimension, the one that turns an abstract deadline into a live confrontation. The Commission built a voluntary GPAI Code of Practice as the recommended path to demonstrating compliance — signing it creates a presumption of conformity, a safe harbour. And the industry has split over whether to sign.

As of June 2026, roughly 24 organisations had signed, including Amazon, Anthropic, Google, IBM, Microsoft — and, notably, the European players Mistral AI and Aleph Alpha. But Meta declined to sign the Code outright. And xAI signed only the Safety and Security chapter, leaving its compliance with the transparency and copyright chapters to be demonstrated, or not, by other means.

That split matters enormously as enforcement begins. Meta, which is not a signatory, has no safe harbour — and Meta is precisely the company whose Muse Image tool, which we covered on July 11, generates AI images of people from their public photos and sits squarely in the path of Article 50's deepfake and AI-content labelling rules. A non-signatory operating exactly the kind of synthetic-media product Article 50 targets is the most obvious early test case the enforcement toolkit could face. Whether Brussels takes it up is the question.

The Collision Nobody Legislated For

The EU AI Act was designed as a product-safety and fundamental-rights regime — a technical framework for governing how AI behaves in Europe. It was not designed for the geopolitical environment it is now entering, and that mismatch is the story.

Over the past month, gafam.ai has documented that environment accumulating. The US administration was offered a 5% equity stake in OpenAI, formalising the treatment of frontier labs as national strategic assets. Brussels fined Google €890 million under the Digital Markets Act just last week, on top of the €4.125 billion Android judgment made final on July 2. Previous EU penalties against American technology companies have drawn direct objection from Washington. Enforcing the AI Act against GPT, Claude, Gemini or Llama from August 2 is therefore not a routine regulatory act. It is a decision to sanction companies that an allied government increasingly regards as instruments of its own economic and security strategy.

That is the vice European regulators are now in. The Act gives them the power to fine. The geopolitics raise the cost of using it. And the credibility of the entire European regulatory project — the one lever gafam.ai has consistently identified as Europe's genuine strength — depends on whether the power, once acquired, is exercised or left on the shelf.

The Case for Restraint, and the Case Against

There is a serious argument for a cautious start, and it deserves stating fairly. The Commission has signalled throughout that it prefers behavioural compliance to punishment; the modest scale of the Google DMA fine last week showed that instinct in action. A measured first year — information requests and negotiated compliance rather than immediate maximum fines — would mirror how GDPR enforcement ramped up, and would avoid handing Washington a grievance at a delicate moment. Prudent sequencing is not weakness.

But there is an equally serious argument that restraint, if it becomes permanent, is indistinguishable from impotence. A law that can fine but never does is a law that gatekeepers learn to ignore. Meta's decision not to sign the Code is, in part, a bet — a bet that non-compliance carries less cost than compliance, and that Brussels will hesitate to make an example of it. If that bet pays off, every other lab learns the lesson. The deterrent value of the August 2 powers exists only for as long as their use remains credible. The first enforcement decisions, or the conspicuous absence of them, will tell the market which world it is operating in.

The European Perspective

The arrival of the AI Act's enforcement powers is the moment Europe's entire AI strategy is put to the test, because enforcement is where regulatory sovereignty is either proven real or exposed as rhetorical. For a year, the Act has been a framework of obligations the Commission could not punish; in six days that changes, and Europe acquires, for the first time, direct legal power over the American companies that build the models Europe depends on.

gafam.ai has argued all summer that regulation is Europe's one genuine lever in an AI economy where it lacks the models, the chips, the platforms and the capital to compete directly. August 2 is when that lever is connected to an engine. But a lever is only worth what its operator is willing to pull, and Europe now faces the hardest version of that choice: the companies it can finally sanction are the same ones a powerful ally treats as strategic assets, and the act of enforcement has become an act of geopolitics.

The honest reading is that Europe's regulatory power is simultaneously more real and more constrained than it was a week ago — real because the legal authority is now live and retroactive, constrained because every use of it carries a transatlantic cost that did not exist when the Act was drafted. What Europe does with the first genuinely hard case — a non-signatory like Meta operating a product squarely in Article 50's crosshairs, or a systemic-risk model that has quietly ignored its documentation duties — will define whether the AI Act becomes the global regulatory benchmark its architects intended or a monument to European ambition that gatekeepers learned to wait out. The rules were the easy part; Europe wrote them years ago and the world took notice.

Enforcement against the powerful, at geopolitical cost, is the hard part, and it begins in six days. Europe is about to discover what its own sovereignty is worth when exercising it is no longer free. gafam.ai will be watching.

We are not first. We are right.

🔒 This analysis is for GAFAM Intelligence members only.

→ Become a Member

Already a member? Log in here