On 2 August, the European Union's AI Act stops being a calendar of deadlines and starts being a law with consequences. From that date the European Commission can supervise the companies building the most capable AI models, demand their documents, run evaluations with access to their source code, and, at the far end of the scale, order a model pulled from the market. Fines run to 3% of global annual turnover or 15 million euros, whichever is larger.
Joel Christoph, a Harvard Kennedy School fellow writing in Lawfare, calls the incoming powers "among the most far-reaching regulatory powers any government has claimed over frontier AI." He is probably right. The awkward part is that a government already claimed a bigger one, and used it, without any of this legal machinery.
In June, the Trump administration issued an export control order on national security grounds. Anthropic responded by disabling its most advanced models, Mythos 5 and Fable 5, for every user on earth. Not throttled, not geofenced: switched off. The controls have since largely been lifted after the company added safeguards, but Mythos remains available only to certain trusted US organisations. Joe Hancock, head of cyber risk at the London law firm Mishcon de Reya, put the lesson bluntly to The Independent: an advanced AI capability "sold commercially and relied upon operationally, can be withdrawn from every non-US user by unilateral government action at a few hours' notice, with no transition period."
The pattern is not isolated. OpenAI's GPT-5.6 launched last week only after a delay prompted by US government requests, with early access restricted to vetted partners whose details were shared with authorities. A presidential executive order now sets up a voluntary framework under which developers hand "covered frontier models" to the government for up to 30 days before wider release. In Beijing, officials are reportedly pressing domestic firms to restrict overseas access to their best models, having already blocked Meta's $2bn acquisition of the Chinese startup Manus. Last Tuesday, MPs on the UK's Science, Innovation and Technology Committee warned that Britain "may not be able to count on its allies" for access to critical AI and called for a sovereignty strategy. CIA director John Ratcliffe has taken to describing frontier models as "akin to digital nuclear weapons."
So the interesting question about 2 August is not whether states can control frontier models. That has been answered. It is whether a rules-based version of that control can keep pace with the improvised version.
Here Europe has a problem that no amount of legal text fixes. The heavy tier of the AI Act applies to models presumed to carry "systemic risk," a category defined by a training compute threshold of 10^25 floating-point operations. That is a blunt proxy for capability, and it captures perhaps a dozen models worldwide. Supervising them falls to the European AI Office, which employs somewhat over 125 staff across all its functions, only a fraction of whom work on general-purpose AI, against more than a hundred distinct duties under the Act. One recommendation cited by Christoph, from the think tank Pour Demain, is to get GPAI supervisory capacity to at least 160 people by 2030. Hiring has been slow: rigid EU pay scales make frontier-AI talent hard to attract. Risto Uuk of the Future of Life Institute called the delay "concerning." For comparison, the UK's AI Safety Institute, which pays above standard civil service rates, had roughly 250 staff by August 2025.
The transparency rules have a similar softness. Every model provider must publish a summary of its training data, and it must be "sufficiently detailed," a phrase nobody has pinned down. Lawyers at WilmerHale note the Commission's template does not say how scraped content should even be measured, whether by file size, word count, or something else. The Commission will not audit the data itself. It will act on complaints and on alerts from its scientific panel, which means a disclosure regime that depends on someone outside noticing the gap first.
None of this makes the AI Act toothless. It makes it slow, and slowness is the whole contrast. Washington needed no threshold, no template and no scientific panel to take two of the world's most capable models offline in an afternoon. Brussels has spent years building an apparatus that can do something similar, with due process attached, and arrives in August short of the people to run it. Christoph's summary is hard to improve on: "The tools are on the table. The question is whether anyone picks them up."