As of this week, the European Union's landmark AI Act has entered a new phase: the rules governing general-purpose AI models—the technology behind chatbots like ChatGPT—are now enforceable. This cements the European Commission's role as the world's most assertive regulator of artificial intelligence, a position that will have repercussions far beyond the bloc's borders.
The AI Act, adopted in 2024, is the first comprehensive legal framework for AI anywhere. Its provisions on large language models and other foundation models were always seen as the most consequential, and they now apply across all 27 member states. The move comes as the EU also tightens transparency rules for deepfakes and chatbots, part of a broader push to make AI accountable.
What exactly is now regulated?
The AI Act originally targeted AI applications, but the explosive launch of ChatGPT in 2022 prompted EU policymakers to extend the scope to the underlying models. Any model that is general-purpose—meaning it can be adapted to many tasks—now falls under the rules. Developers must disclose how their models were built, including whether copyrighted material was used for training, and provide downstream users with enough detail to understand capabilities and limitations.
For the most powerful "frontier" models, which push the boundaries of what AI can do, additional obligations apply. Companies must identify and mitigate systemic risks, such as potential misuse in cyberattacks or the creation of biological weapons. The European Commission has endorsed a voluntary code of practice, drafted by experts including Yoshua Bengio, to guide compliance. Most leading Western AI labs have signed up, with the notable exception of Meta.
"We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," Tom Duff Gordon, OpenAI's Vice President and Head of EMEA Policy, told European Pulse.
Enforcement: a daunting task
The European AI Office, established within the Commission, is responsible for enforcement. The challenge is immense: regulating some of the most complex technologies ever created, and doing so against companies with vast resources. The EU's own capacity is limited, and AI talent is scarce, with public bodies competing against the private sector. To bridge the gap, the Commission is drawing on external expertise, including a panel of scientists and specialised AI safety firms.
But AI is a moving target. New generations of models emerge every few months, and officials have little prior experience or scientific consensus to guide them on preventing harm at scale. "The danger is that the current US administration treats this as an attack on US commercial interests, as it did when the Commission sought to implement its digital markets' rules in December 2025 and more recently this month when it sought to fine Google under the EU's Digital Markets Act," MEP Michael McNamara (Ireland/Renew) told European Pulse.
Washington's hostility is a real concern. The Trump administration has been quick to criticise EU digital rules that affect American tech giants, and the AI Act is likely to be a flashpoint. Brussels will need to navigate this carefully, balancing its regulatory ambitions with the risk of a transatlantic trade conflict.
What does this mean for Europeans?
The core purpose of the AI Act is to protect European citizens, ensuring that AI does not harm their safety or fundamental rights. The rules apply to any company, foreign or domestic, that commercialises AI in the EU. That means American firms like OpenAI, Google, and Anthropic must comply if they want to serve European users.
Industry critics argue the law will slow innovation, forcing companies to divert resources from engineering to legal compliance. In practice, Europeans may see some advanced AI models launch later in the EU than in other markets, as companies complete their compliance checks. But the trade-off, at least in theory, is that any AI model available in the EU is safe to use.
MEP Axel Voss (Germany/EPP) urged the Commission to enforce the AI Act in close alignment with other digital rules, since AI is increasingly embedded in connected products and online services. "Taking the AI Office's lack of capacities into account, I very much hope that they do not waste their energy on niche concerns but instead align strongly with the priorities of their platform regulation colleagues," Voss said.
Setting the global benchmark
As the world's most prominent AI regulator, the EU is inevitably setting the benchmark for how other jurisdictions approach the technology. The so-called "Brussels effect" means that global companies often adopt EU standards worldwide to avoid fragmentation. The enforcement priorities of the AI Office will therefore have an impact far beyond Europe.
Two philosophical approaches dominate the debate on AI risk. The AI ethics tradition focuses on fundamental rights violations, such as discrimination and privacy, and the need for human oversight. Effective altruism, by contrast, emphasises existential risks—the possibility that AI could cause catastrophic harm, whether through weapons development, massive cyberattacks, or loss of control. Recent episodes, such as Anthropic's model being pulled under US export controls over cybersecurity concerns, illustrate the stakes.
The EU's experience will be closely watched, not least by other regulators. But the bloc's capacity to enforce is under strain, as member states struggle to match Brussels in staffing and tech. The coming months will reveal whether the EU can turn its regulatory ambition into effective oversight—and whether the rest of the world follows its lead.


