On 2 August 2026 the EU AI Act stopped being a set of obligations and became a set of enforcement powers. The European Commission and its AI Office can now demand documentation from the companies that build the big AI models, run their own evaluations, order a model restricted or pulled from the market, and fine the provider up to 3% of global turnover. Your organisation in Auckland or Melbourne is not directly regulated. The catch is that the models you run on are.
What you need to know
- The obligations existed since August 2025. The teeth arrived in August 2026. The Commission now has the power to investigate general-purpose AI (GPAI) providers, require changes, and issue fines.
- A NZ or AU enterprise usually isn't in scope, but it feels this through two channels: the model vendors you depend on (OpenAI, Anthropic, Google, Meta and the rest), and any EU customers, staff or operations you have.
- The maximum GPAI fine is 3% of global annual turnover or 15 million euro, whichever is higher. That is a number large enough to change how your vendors behave, which is what should change how you buy.
- The practical move is procurement, not panic. Ask your AI vendor which models power your solution, whether those models are documented and compliant, and what your fallback is if one gets restricted.
- Models sold into the EU before August 2025 have until 2 August 2027 to comply. If your stack leans on an older model, there is a gap worth knowing about.
3%
of global annual turnover, or 15M euro, whichever is higher: the maximum GPAI fine now enforceable under Article 101
Source: EU AI Act, Article 101
2 Aug 2026
Commission and AI Office enforcement powers over GPAI model providers went live
Source: European Commission, AI Act enforcement
2 Aug 2027
deadline for GPAI models placed on the EU market before August 2025 to comply
Source: EU AI Act, Chapter V
What actually changed on 2 August 2026
The obligations did not change. The ability to enforce them did. GPAI providers have carried duties since 2 August 2025: publish technical documentation, summarise training data, respect copyright, and for the most capable models, assess and mitigate systemic risk. For a year those duties sat there with no enforcement behind them, a deliberate runway.
From 2 August 2026 that runway ended. The Commission's AI Office can now request documentation under Article 91, run its own model evaluations under Article 92, require a provider to take mitigation measures or restrict, withdraw or recall a model under Article 93, and fine under Article 101. Refusing to hand over documentation or blocking an evaluation is itself finable. This is enforcement machinery aimed at the model makers, not at the businesses that use their models.
You're not regulated. Your vendor is.
The AI Act applies to whoever places a GPAI model on the EU market. That is the model provider, not the New Zealand insurer or the Australian health provider running on top of one. So the direct legal exposure sits upstream of you.
You still inherit the consequences. If a model you depend on is found non-compliant and gets restricted under Article 93, the disruption lands in your workflow regardless of who paid the fine. If your vendor is a thin wrapper over a single model with no fallback, their supply risk is now your supply risk. And if you do have EU customers, EU staff or an EU entity, parts of the Act can reach you directly, so scope is worth confirming rather than assuming.
None of this is a reason to slow down your AI programme. It is a reason to ask sharper questions when you buy, because the enforcement pressure now flowing through your vendors is information you can use.
The dates that matter
| Date | What it means |
|---|---|
| 2 August 2025 | GPAI obligations began. A one-year period before enforcement. |
| 2 August 2026 | Commission and AI Office enforcement powers live: documentation requests, evaluations, mitigation orders, and fines. |
| 2 August 2027 | Models placed on the EU market before August 2025 must be brought into compliance. |
The procurement checklist
Run these questions past any AI vendor before you sign or renew. The point is not to become a compliance officer. It is to find out whether the people you are paying understand the ground they are standing on.
| Question to put to your AI vendor | Why it matters now | What a solid answer sounds like |
|---|---|---|
| Which specific models power our solution, and who is the provider of each? | You inherit their compliance posture, so you need to know whose it is. | Named models and named providers, not "we use the leading LLMs". |
| Are those models documented and compliant with their GPAI obligations? | A model that can't stay on the EU market is a model that can be pulled from under you. | A pointer to the provider's published documentation or training-data summary. |
| Does anything we rely on use a model placed on the market before August 2025? | Those have until August 2027, so there's a gap to plan around. | They know, and have a migration path if the answer is yes. |
| If a model is restricted or withdrawn, what is our fallback? | Enforcement can force a model off the market at short notice. | A named alternate model and a tested switch, not a shrug. |
| Where is our data processed and stored? | Sovereignty and EU footprint decide who is in scope. | NZ or AU hosting, or your own environment, documented. |
| Could our own EU customers or operations pull us into scope directly? | Some obligations reach users, not just providers. | Honest scoping, with the parts that apply to you named. |
The regulation is aimed at the model makers, not at you. But the pressure runs downhill through every vendor in your stack. The firms that treat that as a reason to get their documentation in order are the ones worth buying from.
Isaac RolfeManaging DirectorWhat to do this quarter
You don't need a working group or a policy binder. You need three things on a page.
First, a list of the models actually running in your production AI, with the provider named against each. Most organisations can't produce this today, and that is the real finding.
Second, a fallback for the one or two models you most depend on, so a restriction upstream is an inconvenience rather than an outage.
Third, an honest read on whether any part of your business, an EU customer, an EU office, staff in Europe, brings you into direct scope. If it does, that is a legal question, not a procurement one, and it goes to your counsel.
Governance that lives as a checklist stays a compliance cost. Governance built into how you buy and how you architect becomes an advantage, because it is the same discipline that keeps you from being locked into a single fragile vendor. That is the AI governance point, applied to a deadline that just passed.
- Does the EU AI Act apply to my New Zealand or Australian business?
- Usually not directly. The Act applies to whoever places an AI model or system on the EU market, which for general-purpose models is the provider, not the business using them. You can still be pulled into scope if you have EU customers, EU operations or staff in Europe, so confirm that rather than assume it. Even when you are out of scope, you inherit the effects through the model vendors you depend on.
- What can the EU actually do to a non-compliant AI provider now?
- From 2 August 2026 the Commission's AI Office can request technical documentation (Article 91), run its own evaluations of a model (Article 92), order a provider to take mitigation measures or restrict, withdraw or recall a model (Article 93), and fine up to 3% of global annual turnover or 15 million euro, whichever is higher (Article 101). Blocking a request or an evaluation is itself finable.
- Why did enforcement start a year after the obligations?
- The obligations on GPAI providers applied from 2 August 2025, but the Commission's power to enforce them was held back for a year to give providers a runway to comply. That runway closed on 2 August 2026. Models that were already on the EU market before August 2025 get longer, until 2 August 2027.
- What is the single most useful thing to do about this?
- Produce a list of the AI models running in your production systems with the provider named against each, then a fallback for the one or two you most depend on. Most organisations can't produce that list today, which is exactly why it is the place to start.