TTW
TTW

Belgium and 26 Other EU Nations Are Now Tightening the AI Regulation as ChatGPT Moves to Meet New Safety Duties

Belgium and 26 other eu nations are now tightening the ai regulation as chatgpt moves to meet new safety duties

Image generated with Ai

Europe’s new oversight of ChatGPT targets digital risks but leaves visa, passport and border rules unchanged.

On 2 August 2026, Belgium and 26 other EU member states entered the first major stage of the EU AI Regulation Act. This stage broadened the enforcement powers of both EU and national authorities on qualifying general-purpose AI model service providers. These providers must now comply with documentation, copyright, transparency, and safety obligations. Harmonized AI model requirements came into effect on 2 August 2025. However, the obligations fulfilled differ for different types of models, online services, deployers, and users. More safeguards are required for models that have been classified as systems of significant risk. In the new timetable, some of the more intrusive system requirements will not be enforced until December 2027, while for others, full enforcement will only happen in August 2028.

Current Legal Position Across the European Union

The EU AI Regulation Act entered into force on 1 August 2024 and follows a phased implementation schedule. Prohibited practices and AI Regulation duties began applying on 2 February 2025. Governance provisions and obligations for qualifying general-purpose AI models followed on 2 August 2025. Enforcement powers and Article 50 transparency requirements became applicable on 2 August 2026. Providers of general-purpose models already available before 2 August 2025 generally have until 2 August 2027 to meet the relevant model obligations.

Advertisement

The 2026 simplification amendments changed parts of the high-risk timetable. Rules for high-risk uses covering areas such as employment, education, migration, biometrics and access to essential services are now scheduled for 2 December 2027. High-risk systems embedded within regulated products have until 2 August 2028. The general-purpose AI Code of Practice remains voluntary, although providers can use it to demonstrate how they meet binding duties. No official EU finding reviewed for this article classifies every ChatGPT feature as high risk. The central question is how common rules will produce consistent supervision without creating 27 different legal standards.

Key AI Act Dates and Responsibilities

Regulatory elementVerified dateWho it affectsCurrent status
AI Act entered into force1 August 2024EU-wide frameworkIn force
Prohibited practices2 February 2025Providers and deployersApplicable
AI-literacy duties2 February 2025Providers and deployersApplicable
General-purpose model duties2 August 2025Qualifying model providersApplicable to new models
National authority designation2 August 2025EU member statesNational arrangements vary
Main enforcement powers2 August 2026EU and national authoritiesOperational
Article 50 transparency duties2 August 2026Covered providers and deployersApplicable
Existing general-purpose models2 August 2027Models placed on the market before 2 August 2025Transition continues
Annex III high-risk uses2 December 2027Covered providers and deployersFuture obligation
High-risk regulated products2 August 2028Covered product providersFuture obligation

Why the New Stage of AI Regulation Matters

The AI Act creates one European market framework, while national authorities handle many complaints, investigations and enforcement decisions. Providers of general-purpose models may need technical documentation, information for downstream developers, copyright-compliance policies and public summaries of training content. Models presenting systemic risk face added evaluation, incident-reporting, cybersecurity and risk-mitigation duties. Public claims about safety should still be compared with the exact legal requirement and application date. Signing a code or publishing a policy may help demonstrate compliance, but neither action automatically proves that every binding obligation has been satisfied.

Advertisement

Advertisement

Five-Country Enforcement Comparison

CountryAI Regulation authority or structureVerified national positionMain angle
BelgiumCompetences distributed through federal and sector institutions; consolidated final structure requires confirmationOfficial business guidance is available, but the reviewed federal material does not identify one universal regulatorNational enforcement within the EU institutional centre
FranceData-protection, market-surveillance and sector bodies have relevant rolesData-protection authority has a major AI role, but should not be treated as the only regulator without a final consolidated designationRights, privacy and market supervision
GermanyFederal Network Agency coordinates, supported by existing federal, state and sector authoritiesNational implementation law entered into force in July 2026Federal coordination and sector expertise
ItalyDigital administration and national cybersecurity agencies hold national AI responsibilitiesNational legislation and official planning establish a dual structureDigital administration and cybersecurity
SpainSpanish Agency for the Supervision of Artificial Intelligence, with other bodies for specified sectorsDedicated supervisory structure and national implementation legislation are advancingSpecialist supervision and regulatory testing

How the EU AI Act Applies Across 27 Nations

The AI Regulation Act is an EU regulation. It applies directly across all member states according to its phased dates. Belgium, France, Germany, Italy and Spain have not enacted five independent versions of the European framework. A provider entering several EU markets therefore faces the same central classifications and core obligations. National laws may establish procedures, authorities and penalties, but they cannot replace the common European requirements with conflicting national standards.

Member states must still arrange practical enforcement. They appoint notifying and market-surveillance authorities, establish complaint procedures and coordinate sector regulators. They must also provide regulatory sandboxes, which are controlled environments for testing innovative systems before wider deployment. National authorities may investigate local systems and users, while the European AI Office has central responsibility for general-purpose model supervision. Cross-border coordination takes place through the European AI Board.

Belgium’s National Role

Belgium holds a prominent institutional position because several central EU bodies operate in Brussels. However, this does not make Belgium the sole leader or controller of enforcement. European institutions based in Brussels perform EU-level functions, while Belgian authorities remain responsible for national implementation. Official federal guidance confirms that the law applies directly in Belgium and covers developers, deployers, importers, distributors and public bodies according to their roles.

Belgian businesses must first identify whether they provide a model, develop an AI system or simply deploy an external service. National AI Regulation may involve several competent bodies where existing authorities already supervise products, data, financial services or other regulated fields. Complaints may therefore move through different channels depending on the system and harm involved. The reviewed Belgian official material provides extensive compliance guidance but does not justify presenting one institution as the sole national AI Act regulator.

Advertisement

Advertisement

France’s Data and Market-Supervision Structure

France’s data-protection authority has developed extensive guidance covering artificial intelligence, personal data and fundamental rights. Its official material explains that the AI Act and the General Data Protection Regulation operate together. The two laws are not identical. The GDPR applies when personal data is processed, while the AI Regulation Act governs systems and models according to their roles, risks and market use.

French implementation can involve data-protection, consumer, product-safety and sector regulators. A recruitment system processing personal information may fall under both laws, but each authority would act through its own legal powers. France’s data-protection authority has described itself as a major institution in responsible AI deployment. However, available official material does not support describing it as the country’s only market-surveillance authority for every AI system.

Germany’s Coordinated Federal Approach

Germany adopted a national implementation structure centred on the Federal Network Agency. National legislation entered into force in July 2026. The agency acts as a central coordination point, develops AI expertise and supports cooperation among existing regulators. It also provides a service desk, a central complaint route and support for regulatory sandboxes. Germany deliberately retained sector experience instead of creating one authority to replace every existing regulator.

This structure means AI Regulation may involve different bodies across telecommunications, finance, health, transport and product safety. A regulated medical device containing artificial intelligence may remain within established product-supervision arrangements. A separate online tool could fall under another authority. The coordinating body should help businesses identify the correct regulator and encourage a consistent national approach without eliminating specialist responsibilities.

Italy’s Dual National Structure

Italy’s national artificial intelligence legislation identifies the Agency for Digital Italy and the National Cybersecurity Agency as national AI authorities. Official planning material describes the digital agency as the national notifying authority. It supports innovation, national guidance and the responsible adoption of systems in public administration. The cybersecurity agency contributes technical, security and resilience expertise.

Italy has also conducted earlier official scrutiny of generative services under data-protection law. Those cases must not be described as AI Act enforcement. Data-protection investigations considered separate legal requirements involving personal information, transparency and lawful processing. The new European framework adds model and system duties, but it does not retrospectively convert an earlier privacy case into an AI Regulation Act penalty.

Spain’s Dedicated Supervisory Development

Spain created a specialist body for artificial intelligence supervision before many other member states established comparable structures. Official national material assigns that agency a general supervisory role while preserving responsibilities for other bodies in defined areas. These include biometric systems, border management, justice and democratic processes. This division reflects the AI Act’s reliance on existing sector expertise.

Spain has supported AI Regulation through a national testing environment and practical guidance. Its first regulatory sandbox helped participating organisations examine compliance requirements before the wider enforcement stage. The country has also published explanations of Article 50 transparency duties. The specialist agency is operating as a public institution, while national legislation continues to provide detailed enforcement procedures, powers and penalty arrangements.

How the Remaining 22 Member States Fit In

The other member states follow the same European rules but use different administrative structures. Some have designated one central contact point supported by sector regulators. Others distribute responsibilities among product-safety, digital, data-protection, communications, financial and health authorities. A multi-authority structure is permitted when the country also provides a clear point of contact.

Authority designation alone does not prove that every complaint channel, investigation procedure or sandbox is fully operational. The European Commission has warned that failure to designate responsible authorities can lead to infringement proceedings. National arrangements should therefore be assessed through legislation, published mandates, accessible complaint systems and enforceable decisions rather than announcements alone.

Which Duties Could Apply to ChatGPT?

ChatGPT is a service through which users access one or more underlying general-purpose models. The model provider carries duties relating to the model itself. These can include documentation, downstream information, copyright policies and training-content summaries. The service may also carry transparency duties, depending on its functions and outputs. An organisation integrating the model into another application could become an AI system provider.

A business using ChatGPT for internal drafting is usually a deployer rather than the model provider. It does not automatically inherit every provider obligation. However, its duties may increase if it substantially modifies the technology, sells a new application under its own name or uses the system within a regulated high-risk activity. End users generally do not carry provider duties merely because they enter prompts.

What Providers May Need to Disclose

Providers of qualifying general-purpose models must maintain technical documentation. They must give relevant information to organisations building downstream systems. They must establish a policy for complying with EU copyright law and publish a sufficiently detailed summary of training content using the prescribed approach. The law does not require them to publish complete training datasets, proprietary model weights or source code.

Article 50 introduces separate transparency responsibilities for certain generated or manipulated content. AI Regulation requirements vary by model, system, output and risk category. Providers of relevant generative systems must support machine-readable marking where required. Deployers must label deepfakes and certain AI-generated text published to inform the public on matters of public interest, subject to the law’s exceptions. Content created before 2 August 2026 does not require retrospective labelling.

When Additional Systemic-Risk Duties Apply

A general-purpose model is presumed to have systemic risk when its cumulative training computation exceeds 102510^{25} floating-point operations. The European Commission may also designate another model when its capabilities or effects are equivalent. Relevant considerations can include model capabilities, user reach, scalability and access to tools. A provider may contest a classification through the legal process.

Providers of systemic-risk models face enhanced obligations. These include model evaluations, adversarial testing, systemic-risk assessment, mitigation, serious-incident reporting and cybersecurity protection. They must also report information concerning energy efficiency where legally required. No article should classify a particular ChatGPT model as systemic risk unless the provider or competent European authority has officially confirmed that status.

General-Purpose Models and High-Risk Systems Are Different

CategoryWhat it describesTypical dutiesImportant distinction
General-purpose AI modelA broad model capable of performing many tasksDocumentation, downstream information, copyright policy and training summaryNot automatically a high-risk system
Systemic-risk general-purpose modelA model meeting the legal threshold or equivalent-impact testEvaluations, risk controls, incident reporting and cybersecurityRequires a threshold or formal designation
High-risk AI systemA system used in a legally specified sensitive contextConformity assessment, risk management, records and human oversightClassification depends on its intended use
Transparency-risk systemA system involving chatbots or generated content covered by Article 50Disclosure, marking or labellingUsually carries fewer duties than a high-risk system
Prohibited practiceAn unacceptable use identified by the ActBannedDifferent from a regulated lawful use

ChatGPT should therefore not receive one blanket classification. A general conversational feature may fall within transparency rules. A separate deployment used to rank job applicants, determine access to education or support migration decisions could enter a high-risk category. The legal assessment depends on the exact function, intended purpose, organisation and context.

Copyright and Training-Content Requirements

General-purpose model providers must maintain a policy for complying with EU copyright rules. That policy must address lawful text-and-data mining and rights holders’ reservations. Providers must also publish a sufficiently detailed summary describing content used for training. A standardised template supports consistent reporting across the market.

The summary requirement aims to improve transparency without forcing publication of entire datasets. It also does not resolve every copyright dispute. Existing copyright legislation continues to apply alongside the AI Regulation Act. Litigation, licensing debates and national copyright remedies remain legally separate from model-documentation requirements.

What Changes for People Using AI Services?

Users should receive clear information when they interact directly with certain artificial intelligence systems, unless the context already makes that interaction obvious. Covered generated and manipulated content may require detectable marking or visible labelling. People affected by high-risk systems can also benefit from documentation, human oversight and complaint procedures.

The AI Act does not replace data-protection, consumer-protection or equality laws. A person may still exercise GDPR rights when personal data is processed. Consumers may use national remedies when a service is misleading or unfair. Suspected AI Regulation Act violations can be reported to the relevant market-surveillance authority once the national complaint route is operational.

What European Organisations Must Check

Organisations should identify whether they act as providers, deployers, importers or distributors. They must also assess the intended purpose and risk category of each system. A provider normally carries greater responsibilities than a business using a standard external tool. Organisations deploying covered systems must maintain appropriate AI literacy among staff.

Additional obligations can include human oversight, record-keeping, logging, data governance and impact assessments. Employers may face workplace information or consultation requirements. Organisations should obtain adequate documentation from vendors and establish incident-escalation procedures. Using ChatGPT does not automatically subject a business to every provision of the Act.

Which Measures Are Binding and Which Are Guidance?

The AI Act and its applicable implementing measures create binding legal duties. European Commission guidelines explain how authorities interpret those duties but do not replace the legislation. Harmonised standards may help organisations demonstrate conformity. Their legal effect depends on formal recognition and the requirement involved.

Codes of practice remain voluntary compliance tools. The General-Purpose AI Code helps model providers demonstrate transparency, copyright, safety and security measures. The Article 50 code supports marking and labelling. Signing either code does not prove complete compliance. A provider choosing another method must demonstrate that its alternative measures satisfy the law.

Penalties and Enforcement

Prohibited-practice violations can attract penalties of up to EUR 35 million or seven per cent of worldwide annual turnover, whichever calculation applies under the Act. Other breaches can reach EUR 15 million or three per cent. Supplying incorrect, incomplete or misleading information can lead to penalties of up to EUR 7.5 million or one per cent. Different calculations apply to smaller businesses.

For general-purpose model providers, the European Commission can impose fines of up to EUR 15 million or three per cent of worldwide annual turnover. Maximum penalties are not automatic. Authorities must consider the nature, gravity, duration and circumstances of a breach. Affected organisations retain procedural and appeal rights.

Why Providers Outside Europe Must Pay Attention

The AI Act can apply to providers established outside the European Union when they place models or systems on the EU market. It may also apply when outputs produced by their systems are used within the Union. The territorial test therefore depends on market access and European use rather than the provider’s headquarters alone.

International providers may adjust technical documentation, evaluations, product releases and customer contracts. Some may use European compliance measures more widely across their global operations. However, the AI Regulation Act does not automatically govern every system, user or activity worldwide.

What Current Evidence Can and Cannot Prove

The EU has one common regulation, not 27 separate artificial intelligence laws. National implementation statutes organise enforcement but do not replace the central framework. Authority designation does not prove active investigation. A corporate compliance statement is not a regulatory finding, while code membership does not establish complete compliance.

General-purpose models are not automatically high-risk systems. Earlier GDPR action is not AI Act enforcement. Future high-risk duties should not be described as active before their revised dates. Product changes may reflect several commercial, technical or legal factors. They should not be attributed to one requirement without official confirmation.

Official Legal Position

The AI Regulation Act states that it establishes “harmonised rules concerning the placing on the market, putting into service and use of artificial intelligence systems”.

That wording confirms the central structure of the framework. The rules are European and harmonised, while enforcement uses both European and national institutions. National governments can organise authorities and procedures, but the central classifications and obligations remain grounded in EU law.

What Regulators, Providers and Users Should Watch Next

The next major dates are 2 August 2027 for older general-purpose models, 2 December 2027 for specified high-risk uses and 2 August 2028 for AI embedded in regulated products. Authorities must continue developing complaint routes, regulatory sandboxes, technical expertise and cross-border cooperation. Providers must monitor new guidance, standards, templates and reporting procedures.

Effective AI Regulation will become visible through published documentation, functional complaint systems, transparent investigations and enforceable decisions. Voluntary announcements will provide supporting evidence but cannot replace regulatory findings. Users should watch for clearer content labels, accessible explanations and national contact points capable of receiving suspected violations.

Conclusion

The EU AI Act now operates through one common framework across Belgium and the other 26 member states. Belgium, France, Germany, Italy and Spain use different supervisory structures without creating separate European laws. General-purpose model providers may face documentation, copyright and training-summary duties, while systemic-risk models carry additional safeguards. Some requirements are already enforceable, but major high-risk provisions remain scheduled for 2027 and 2028. Successful AI Regulation will depend on coordinated authorities, practical complaint systems, published compliance evidence and proportionate enforcement rather than promises or voluntary code membership alone.

Frequently Asked Questions

Is the EU AI Act a separate law in every member state?

No. It is an EU regulation that applies directly across all 27 member states. National measures establish authorities, procedures and penalties.

Which authorities enforce it in Belgium?

Belgium uses federal and sector authorities according to their existing responsibilities. Available official guidance does not support identifying one body as the sole regulator for every system.

Which duties apply to general-purpose AI models?

Relevant providers may need technical documentation, downstream information, copyright policies and public training-content summaries. Systemic-risk models face additional safety and security duties.

Has ChatGPT been formally classified as high risk?

No blanket high-risk classification was identified. Classification depends on the underlying model, system, intended purpose and deployment context.

When do the remaining obligations take effect?

Older general-purpose models have a transition deadline of 2 August 2027. Specified high-risk use rules follow on 2 December 2027, while regulated-product requirements follow on 2 August 2028.

What rights do EU users have?

Users may receive transparency information and access national complaint routes. GDPR, consumer-protection, equality and other existing legal rights continue to apply.

Advertisement

Share On:

Advertisement

Advertisement

Gtranslate

PARTNERS

@

Subscribe to our Newsletters

I want to receive travel news and trade event updates from Travel And Tour World. I have read Travel And Tour World's Privacy Notice .