Most significantly, the Commission can now issue fines of up to 15 million euros or 3% of a company’s global annual revenue for failing to comply with the new standards.
These enforcement capabilities mark a significant escalation in Europe’s pursuit of tech sovereignty—the strategic effort to reduce dependence on foreign technology and establish independent safety standards.
The move arrives amid heightened trade tensions, highlighted by a $1 billion fine against Google in July and subsequent threats of substantial U.S.
tariffs from President Donald Trump.
European officials, including executive vice-president Henna Virkkunen, argue that such oversight is necessary because the scale of risk from modern, high-capacity AI models requires safeguards that prevent potential harms before they occur.
The regulation impacts any company offering general-purpose AI models within the EU, regardless of where the firm is headquartered.
To maintain operations, international providers must now appoint an official representative based in Europe to serve as a regulatory point of contact.
Legal experts from Sidley Austin note that companies face financial risks not just for model failures, but also for procedural violations such as providing misleading information or blocking model evaluations.
While OpenAI and Google have expressed commitment to the new standards, the EU AI Office is already in discussions with major labs following reports of model-linked cyber attacks.