The EU AI Office's Enforcement Powers Expand Today — Fines Up to €15M or 3% of Revenue
Starting today, August 2, 2026, the European AI Office gains expanded powers to request information, access models, and impose fines of up to 15 million euros or 3% of global revenue for noncompliance under the EU AI Act. OpenAI timed a statement to the deadline, detailing the governance infrastructure it says supports compliance: a Preparedness Framework, in place since 2023 and updated in 2025, that sets out how it identifies and manages serious risks from advanced models, and a newer Frontier Governance Framework aligning its safety and security practices with the Act’s General-Purpose AI Code of Practice — plus watermarking AI-generated audio to meet the EU’s transparency requirements.
The specifics matter more than the gesture. A vendor publishing a named framework, tied to a named legal instrument, with a named enforcement date, is a different posture than a general “we take safety seriously” statement — and it’s the kind of documentation enterprise buyers in regulated markets are about to start asking for as standard due diligence.
That expectation lines up with what BCG has been telling regulated-industry clients directly: retrofitting governance after agentic AI has already spread across business units is the wrong sequence. BCG’s recommended architecture — semantic intelligence, data abstraction, and governance/operations as integrated layers, decided before scaling — cites measured results from that approach: a 25% productivity gain across the software development life cycle and a 20-30% improvement in software quality at organizations that built governance in from the start.
For consulting engagements advising EU-facing enterprise clients, the vendor’s documented governance framework is moving from a compliance footnote to a procurement question — and “when was this last updated” is now a fair thing to ask.