The EU AI Act Rolls Out in Phases: From Entry into Force to GPAI Obligations
The EU AI Act entered into force on August 1, 2024; prohibitions applied from February 2025 and GPAI obligations from August 2025.
The world's first comprehensive AI regulation — the EU AI Act — entered into force on August 1, 2024 and is rolling out in phases: prohibitions and AI-literacy requirements applied from February 2, 2025, and obligations for general-purpose AI (GPAI) model providers took effect on August 2, 2025.
The act classifies AI applications by risk level, imposing transparency, data-governance and human-oversight obligations on high-risk uses like biometrics and critical infrastructure, with fines of up to 7% of global revenue. For large-model providers like OpenAI and Google, the GPAI obligations make training-data transparency and systemic-risk assessment hard requirements.
Full obligations for high-risk systems phase in through 2026-2027. Analysts note the EU's legislation has become the key reference template for AI regulatory frameworks worldwide.
Where the Phased Rollout Actually Bites
For vendors, the real watershed in the timeline is August 2025's GPAI obligations: mandatory public summaries of training data, copyright-compliance policies, and extra assessments plus incident reporting for models deemed to carry 'systemic risk' — requirements that touch model makers' most sensitive trade secret: where the data comes from. The companion GPAI Code of Practice is voluntary; OpenAI, Google and Anthropic signed, while Meta publicly refused — signing or not became a statement of regulatory posture in itself.
The fine structure rewards close reading too: violations of the prohibitions carry penalties of up to 7% of global revenue, above GDPR's 4% — the EU rates AI violations as more serious than privacy ones.
Can the Brussels Effect Repeat
GDPR leveraged market access to make EU rules a de facto global standard, but whether the AI Act can replicate that 'Brussels effect' is doubtful: the US has pivoted decisively to innovation-first (see our US AI Action Plan coverage), China runs its own labeling-and-filing regime (see our China content-labeling coverage), and the three jurisdictions are hardening into separate blocs. Inside Europe, industry worry that compliance costs handicap homegrown players like Mistral keeps fermenting, and lobbying for simplification never stopped — by the Paris AI Action Summit the EU had audibly softened its tone (see our summit coverage).
Our Take
The AI Act's value lies less in its clauses than in making 'risk tiers + phased effect' the shared vocabulary of global regulation; its risk is equally clear — if only giants can afford compliance, the law entrenches incumbent advantage. The practical takeaway for anyone shipping into the EU: get training-data inventories and risk-assessment processes on the books before the 2026-2027 high-risk obligations land, rather than cramming after the first enforcement case — the GDPR-era habit of taking rules seriously only after the first mega-fine is far too expensive under a 7% ceiling.
This article aggregates official announcements and public reporting; original sources are linked below.
Source:欧盟委员会 AI Act 服务台