The European Commission has refreshed its AI Act, enforcement, and General-Purpose AI Code of Practice pages as the law’s August 2026 obligations move from preparation into operational compliance.
The Commission’s AI Act page was updated July 31, 2026. Its enforcement page says enforcement is shared among the European Commission’s AI Office, the European Data Protection Supervisor, and national competent authorities designated by member states.
The Commission’s General-Purpose AI Code of Practice page says the code is meant to help providers comply with AI Act legal obligations on safety, transparency, and copyright for general-purpose AI models.
This is a different policy lane from the earlier Article 50 content-transparency story. In June, The AI Feed covered OpenAI’s support for the EU code for AI-generated content transparency, where the key date was August 2, 2026 for transparency obligations around AI-generated content. The general-purpose model obligations create another compliance surface for model providers.
The enforcement map now matters
The AI Act is broad, and broad laws can look abstract until the enforcement machinery is visible. The Commission’s enforcement page makes the split of responsibilities concrete. The AI Office has a central role for general-purpose AI, the EDPS has public-sector data-protection responsibilities, and national authorities handle many member-state enforcement duties.
For model providers, that means compliance is not one document. It is a package: technical documentation, copyright policy, transparency commitments, risk management, incident handling, and the ability to answer regulator questions.
The Code of Practice is important because it gives providers a practical route for showing compliance with the GPAI parts of the law. The code does not make every uncertainty disappear. It does give the market a shared checklist before formal enforcement practice matures.
Buyers should ask for artifacts, not slogans
Enterprise buyers do not need to become AI Act lawyers to make better procurement decisions. They do need to ask whether a model provider can produce the documents and processes the regulation now makes more important.
The most useful near-term questions are concrete. Does the provider have model documentation? Does it describe training-data and copyright practices? Does it have a safety and security process for high-impact models? Does it explain how deployers should label or disclose AI-generated outputs where required?





