EU regulators gain power to scrutinize AI models, impose fines
The European Commission has activated new enforcement powers under the EU AI Act, allowing regulators to scrutinize general-purpose AI models from firms like Anthropic and OpenAI before deployment. Violators face fines up to $17 million or 3% of global revenue. The move intensifies U.S.-EU tech tensions, following a €1 billion penalty against Google, and mandates that non-EU providers appoint local representatives to ensure cooperation with regulators.

*this image is generated using AI for illustrative purposes only.
The European Commission has expanded its authority to oversee the world’s most advanced artificial intelligence systems, giving regulators new powers to scrutinize general-purpose AI models before they are released across the European Union. Under the latest enforcement phase of the EU AI Act, approved in 2024, regulators can demand model evaluations from leading developers and restrict systems deemed to pose significant risks. This expansion directly impacts major AI firms such as Anthropic and OpenAI, increasing compliance costs and operational scrutiny for companies deploying foundation models in Europe.
Companies that violate the new rules could face substantial financial penalties. Fines can reach up to $17 million (€15 million) or 3% of annual global revenue, whichever amount is higher. The oversight regime is part of a phased rollout designed to create stricter guardrails around high-impact AI technologies. Henna Virkkunen, the European Commission’s executive vice president for tech sovereignty, security and democracy, warned that risks from advanced AI models require heightened scrutiny.
"Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale," Virkkunen said.
The crackdown adds another point of tension between the U.S. and Europe over technology policy. Washington and Brussels have clashed over Europe’s efforts to reduce reliance on American technology companies and impose penalties on U.S.-based firms. In July, European regulators issued Google a €1 billion penalty under Digital Markets Act rules, prompting President Donald Trump to threaten the EU with a "substantial" tariff.
Regulatory exposure extends beyond where an AI company is headquartered. Elisabetta Righini, a partner at Sidley Austin, noted that U.S. companies cannot avoid EU oversight simply by operating outside the bloc. Non-European AI providers must appoint an EU-based authorized representative to communicate with regulators.
| Penalty Trigger | Consequence |
|---|---|
| Violation of AI rules | Fine of up to $17 million (€15 million) or 3% of annual global revenue |
| Refusing information request | Fineable offense |
| Giving misleading answers | Fineable offense |
| Blocking model evaluation | Fineable offense |
Righini added that companies could face penalties not only for model-related safety failures but also for failing to cooperate with regulators. "What’s rarely appreciated is that GPAI liability isn’t limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own," she said.
OpenAI said it has been working with European regulators as the new framework takes effect. Tom Gordon, OpenAI’s vice president for EMEA policy, stated that the company has "collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice." Google also said it expects to comply with the new requirements as the rules and related guidance are implemented.
How might the increased compliance costs and operational scrutiny under the EU AI Act impact the competitive landscape between European AI startups and major U.S. firms like OpenAI and Anthropic?
Could the threat of tariffs from the U.S. in response to EU tech regulations lead to a fragmented global AI market, forcing companies to develop region-specific models?
What specific technical safeguards or evaluation metrics are likely to be prioritized by regulators when scrutinizing general-purpose AI models for 'significant risks'?

































