EU AI Act GPAI Obligations Take Full Effect; ECB Orders 110 Banks to Address AI Cyber Risk
Summary
Updated Aug 13 — EU AI Office began active Article 50 enforcement on 13 August; Meta is the most notable non-signatory of the Code of Practice.
- • EU AI Act GPAI model obligations and Article 50 transparency rules are fully in force from 2 August 2026
- • EU AI Office began actively enforcing Article 50 chatbot disclosure requirements on August 12–13, 2026
- • Over 180 companies signed the EU Code of Practice — including Anthropic, OpenAI, Google, Microsoft, and Amazon — but Meta declined
- • European Systemic Risk Board elevated systemic cyber risk to 'severe'; ECB required all 110 European banks to submit AI cybersecurity action plans by 31 October 2026
Updates
Active enforcement launched Aug 12–13
The EU AI Office, working alongside national regulators, began actively policing Article 50 compliance on August 12–13, 2026 — the first wave of live enforcement since the rule took effect August 2.
180+ companies signed Code of Practice
Anthropic, OpenAI, Google, Microsoft, Amazon, IBM, Mistral AI, and Cohere are among over 180 signatories; the signature earns regulatory deference — enforcers treat signatories as acting in good faith.
Meta declined to sign
Meta cited legal uncertainty over the code's terms and did not sign the Code of Practice, meaning it must prove compliance without the goodwill that signature provides to a 38-person enforcement team.
38-person Brussels enforcement team
The AI Office assembled a 38-person enforcement team with powers to interview company staff, demand model documentation, and in the most serious cases pull a product's access to the EU market entirely.
Grace period for machine-readable labels
Tools already on the EU market before August 2 have until December 2026 to implement machine-readable AI-content labels; all plain-language disclosure requirements apply immediately.
Disclosure cannot be buried in T&Cs
The AI Office has clarified that burying AI disclosure in terms and conditions or watermarks alone does not constitute compliance; the disclosure must be clear and at the point of interaction.
Details
GPAI obligations live from 2 August 2026
EU AI Act General Purpose AI model requirements and Article 50 transparency rules are now fully enforceable — a major compliance milestone for AI developers and deployers in the EU
Standards deadline extended to December 2027
The Omnibus package extended the harmonised standards deadline, but standards could arrive 6–12 months early — making rolling preparation essential rather than waiting for the deadline
Workplace AI bans already in force since Feb 2025
Prohibitions on emotion recognition in workplaces, social scoring, and biometric mass surveillance have been in effect since 2 February 2025 and remain unchanged
Fines up to €15M or 3% of global turnover
Non-compliance with the EU AI Act now carries penalties of up to €15 million or 3% of worldwide annual turnover, whichever is higher
ESRB rates AI cyber risk as 'severe'
The European Systemic Risk Board escalated its systemic cyber risk assessment to 'severe,' noting frontier AI models now compress exploit development timelines from weeks to minutes
ECB mandates action plans from 110 banks
ECB letter requires all 110 European banks to submit comprehensive AI cybersecurity action plans by 31 October 2026, covering vulnerability management, monitoring, third-party risk, and board governance
96% of EU banks breached via third parties
96% of European banks have already experienced security breaches through third-party suppliers — a key vulnerability area the ECB action plans must address
Source: Mercer / EU AI Act official text / ECB (August 2026).
What This Means
The EU AI Act has moved from a compliance planning exercise to live regulatory enforcement. With GPAI obligations now active and the ESRB raising its cyber risk rating to its highest tier, European organizations — especially in financial services — face dual pressure: comply with AI governance requirements while simultaneously fortifying defenses against AI-enabled cyberattacks. The ECB's direct letter to 110 banks is a landmark supervisory moment, explicitly connecting frontier AI capabilities to systemic financial risk and demanding concrete institutional responses on a hard deadline. Meta's refusal to sign the Code of Practice puts it in a more adversarial position with the newly active 38-person enforcement team, while over 180 competitors gain regulatory goodwill. Organizations outside financial services should treat this as a preview of the compliance intensity coming their way.
Sentiment
Serious focus on compliance deadlines and dual regulatory pressure, with some seeing audit/opportunity upside
“The EU AI Act enters its heaviest phase on 2 August 2026. Banks face dual-stack regulation alongside DORA/CRR/PSD2; retraining third-party models can trigger provider obligations; penalties up to 7% global turnover. Yet EU bank AI adoption remains high — compliance posture now a trust differentiator.”
“The EU AI Act just grew teeth. As of Aug 2, GPAI enforcement is live: fines up to 3% of global turnover or €15M, plus mandatory model evals, red-teaming, weight security and incident reporting for systemic-risk models.”
“ESRB issued formal warning: frontier AI models can discover vulnerabilities, generate exploits and accelerate attacks against EU financial infrastructure. Banks must submit AI risk action plans to Joint Supervisory Teams by October 31, 2026 — 108 days away.”
“The ECB is convening banks to address cybersecurity vulnerabilities exposed by AI models including Claude Mythos, warning that threats need to be dealt with faster.”
“On August 2 the EU's AI Act may begin enforcing transparency rules... The reflexive reaction could be that AI may be too risky for regulated industries. But that would be backwards. The opportunity now is to use AI to rebuild old, dysfunctional software into systems that are cheaper, simpler and that you can actually audit.”
Notably frames enforcement as catalyst for rebuilding legacy systems rather than barrier.
Split
~60/40 compliance-burden focus vs opportunity/audit upside (practitioners vs founders).
