Image generated with Ai
On 2 August 2026, Belgium and 26 other EU member states entered the first major stage of the EU AI Regulation Act. This stage broadened the enforcement powers of both EU and national authorities on qualifying general-purpose AI model service providers. These providers must now comply with documentation, copyright, transparency, and safety obligations. Harmonized AI model requirements came into effect on 2 August 2025. However, the obligations fulfilled differ for different types of models, online services, deployers, and users. More safeguards are required for models that have been classified as systems of significant risk. In the new timetable, some of the more intrusive system requirements will not be enforced until December 2027, while for others, full enforcement will only happen in August 2028.
The EU AI Regulation Act entered into force on 1 August 2024 and follows a phased implementation schedule. Prohibited practices and AI Regulation duties began applying on 2 February 2025. Governance provisions and obligations for qualifying general-purpose AI models followed on 2 August 2025. Enforcement powers and Article 50 transparency requirements became applicable on 2 August 2026. Providers of general-purpose models already available before 2 August 2025 generally have until 2 August 2027 to meet the relevant model obligations.
Advertisement
The 2026 simplification amendments changed parts of the high-risk timetable. Rules for high-risk uses covering areas such as employment, education, migration, biometrics and access to essential services are now scheduled for 2 December 2027. High-risk systems embedded within regulated products have until 2 August 2028. The general-purpose AI Code of Practice remains voluntary, although providers can use it to demonstrate how they meet binding duties. No official EU finding reviewed for this article classifies every ChatGPT feature as high risk. The central question is how common rules will produce consistent supervision without creating 27 different legal standards.
| Regulatory element | Verified date | Who it affects | Current status |
|---|---|---|---|
| AI Act entered into force | 1 August 2024 | EU-wide framework | In force |
| Prohibited practices | 2 February 2025 | Providers and deployers | Applicable |
| AI-literacy duties | 2 February 2025 | Providers and deployers | Applicable |
| General-purpose model duties | 2 August 2025 | Qualifying model providers | Applicable to new models |
| National authority designation | 2 August 2025 | EU member states | National arrangements vary |
| Main enforcement powers | 2 August 2026 | EU and national authorities | Operational |
| Article 50 transparency duties | 2 August 2026 | Covered providers and deployers | Applicable |
| Existing general-purpose models | 2 August 2027 | Models placed on the market before 2 August 2025 | Transition continues |
| Annex III high-risk uses | 2 December 2027 | Covered providers and deployers | Future obligation |
| High-risk regulated products | 2 August 2028 | Covered product providers | Future obligation |
The AI Act creates one European market framework, while national authorities handle many complaints, investigations and enforcement decisions. Providers of general-purpose models may need technical documentation, information for downstream developers, copyright-compliance policies and public summaries of training content. Models presenting systemic risk face added evaluation, incident-reporting, cybersecurity and risk-mitigation duties. Public claims about safety should still be compared with the exact legal requirement and application date. Signing a code or publishing a policy may help demonstrate compliance, but neither action automatically proves that every binding obligation has been satisfied.
Advertisement
Advertisement
| Country | AI Regulation authority or structure | Verified national position | Main angle |
|---|---|---|---|
| Belgium | Competences distributed through federal and sector institutions; consolidated final structure requires confirmation | Official business guidance is available, but the reviewed federal material does not identify one universal regulator | National enforcement within the EU institutional centre |
| France | Data-protection, market-surveillance and sector bodies have relevant roles | Data-protection authority has a major AI role, but should not be treated as the only regulator without a final consolidated designation | Rights, privacy and market supervision |
| Germany | Federal Network Agency coordinates, supported by existing federal, state and sector authorities | National implementation law entered into force in July 2026 | Federal coordination and sector expertise |
| Italy | Digital administration and national cybersecurity agencies hold national AI responsibilities | National legislation and official planning establish a dual structure | Digital administration and cybersecurity |
| Spain | Spanish Agency for the Supervision of Artificial Intelligence, with other bodies for specified sectors | Dedicated supervisory structure and national implementation legislation are advancing | Specialist supervision and regulatory testing |
The AI Regulation Act is an EU regulation. It applies directly across all member states according to its phased dates. Belgium, France, Germany, Italy and Spain have not enacted five independent versions of the European framework. A provider entering several EU markets therefore faces the same central classifications and core obligations. National laws may establish procedures, authorities and penalties, but they cannot replace the common European requirements with conflicting national standards.
Member states must still arrange practical enforcement. They appoint notifying and market-surveillance authorities, establish complaint procedures and coordinate sector regulators. They must also provide regulatory sandboxes, which are controlled environments for testing innovative systems before wider deployment. National authorities may investigate local systems and users, while the European AI Office has central responsibility for general-purpose model supervision. Cross-border coordination takes place through the European AI Board.
Belgium holds a prominent institutional position because several central EU bodies operate in Brussels. However, this does not make Belgium the sole leader or controller of enforcement. European institutions based in Brussels perform EU-level functions, while Belgian authorities remain responsible for national implementation. Official federal guidance confirms that the law applies directly in Belgium and covers developers, deployers, importers, distributors and public bodies according to their roles.
Belgian businesses must first identify whether they provide a model, develop an AI system or simply deploy an external service. National AI Regulation may involve several competent bodies where existing authorities already supervise products, data, financial services or other regulated fields. Complaints may therefore move through different channels depending on the system and harm involved. The reviewed Belgian official material provides extensive compliance guidance but does not justify presenting one institution as the sole national AI Act regulator.
Advertisement
Advertisement
France’s data-protection authority has developed extensive guidance covering artificial intelligence, personal data and fundamental rights. Its official material explains that the AI Act and the General Data Protection Regulation operate together. The two laws are not identical. The GDPR applies when personal data is processed, while the AI Regulation Act governs systems and models according to their roles, risks and market use.
French implementation can involve data-protection, consumer, product-safety and sector regulators. A recruitment system processing personal information may fall under both laws, but each authority would act through its own legal powers. France’s data-protection authority has described itself as a major institution in responsible AI deployment. However, available official material does not support describing it as the country’s only market-surveillance authority for every AI system.
Germany adopted a national implementation structure centred on the Federal Network Agency. National legislation entered into force in July 2026. The agency acts as a central coordination point, develops AI expertise and supports cooperation among existing regulators. It also provides a service desk, a central complaint route and support for regulatory sandboxes. Germany deliberately retained sector experience instead of creating one authority to replace every existing regulator.
This structure means AI Regulation may involve different bodies across telecommunications, finance, health, transport and product safety. A regulated medical device containing artificial intelligence may remain within established product-supervision arrangements. A separate online tool could fall under another authority. The coordinating body should help businesses identify the correct regulator and encourage a consistent national approach without eliminating specialist responsibilities.
Italy’s national artificial intelligence legislation identifies the Agency for Digital Italy and the National Cybersecurity Agency as national AI authorities. Official planning material describes the digital agency as the national notifying authority. It supports innovation, national guidance and the responsible adoption of systems in public administration. The cybersecurity agency contributes technical, security and resilience expertise.
Italy has also conducted earlier official scrutiny of generative services under data-protection law. Those cases must not be described as AI Act enforcement. Data-protection investigations considered separate legal requirements involving personal information, transparency and lawful processing. The new European framework adds model and system duties, but it does not retrospectively convert an earlier privacy case into an AI Regulation Act penalty.
Spain created a specialist body for artificial intelligence supervision before many other member states established comparable structures. Official national material assigns that agency a general supervisory role while preserving responsibilities for other bodies in defined areas. These include biometric systems, border management, justice and democratic processes. This division reflects the AI Act’s reliance on existing sector expertise.
Spain has supported AI Regulation through a national testing environment and practical guidance. Its first regulatory sandbox helped participating organisations examine compliance requirements before the wider enforcement stage. The country has also published explanations of Article 50 transparency duties. The specialist agency is operating as a public institution, while national legislation continues to provide detailed enforcement procedures, powers and penalty arrangements.
The other member states follow the same European rules but use different administrative structures. Some have designated one central contact point supported by sector regulators. Others distribute responsibilities among product-safety, digital, data-protection, communications, financial and health authorities. A multi-authority structure is permitted when the country also provides a clear point of contact.
Authority designation alone does not prove that every complaint channel, investigation procedure or sandbox is fully operational. The European Commission has warned that failure to designate responsible authorities can lead to infringement proceedings. National arrangements should therefore be assessed through legislation, published mandates, accessible complaint systems and enforceable decisions rather than announcements alone.
ChatGPT is a service through which users access one or more underlying general-purpose models. The model provider carries duties relating to the model itself. These can include documentation, downstream information, copyright policies and training-content summaries. The service may also carry transparency duties, depending on its functions and outputs. An organisation integrating the model into another application could become an AI system provider.
A business using ChatGPT for internal drafting is usually a deployer rather than the model provider. It does not automatically inherit every provider obligation. However, its duties may increase if it substantially modifies the technology, sells a new application under its own name or uses the system within a regulated high-risk activity. End users generally do not carry provider duties merely because they enter prompts.
Providers of qualifying general-purpose models must maintain technical documentation. They must give relevant information to organisations building downstream systems. They must establish a policy for complying with EU copyright law and publish a sufficiently detailed summary of training content using the prescribed approach. The law does not require them to publish complete training datasets, proprietary model weights or source code.
Article 50 introduces separate transparency responsibilities for certain generated or manipulated content. AI Regulation requirements vary by model, system, output and risk category. Providers of relevant generative systems must support machine-readable marking where required. Deployers must label deepfakes and certain AI-generated text published to inform the public on matters of public interest, subject to the law’s exceptions. Content created before 2 August 2026 does not require retrospective labelling.
A general-purpose model is presumed to have systemic risk when its cumulative training computation exceeds floating-point operations. The European Commission may also designate another model when its capabilities or effects are equivalent. Relevant considerations can include model capabilities, user reach, scalability and access to tools. A provider may contest a classification through the legal process.
Providers of systemic-risk models face enhanced obligations. These include model evaluations, adversarial testing, systemic-risk assessment, mitigation, serious-incident reporting and cybersecurity protection. They must also report information concerning energy efficiency where legally required. No article should classify a particular ChatGPT model as systemic risk unless the provider or competent European authority has officially confirmed that status.
| Category | What it describes | Typical duties | Important distinction |
|---|---|---|---|
| General-purpose AI model | A broad model capable of performing many tasks | Documentation, downstream information, copyright policy and training summary | Not automatically a high-risk system |
| Systemic-risk general-purpose model | A model meeting the legal threshold or equivalent-impact test | Evaluations, risk controls, incident reporting and cybersecurity | Requires a threshold or formal designation |
| High-risk AI system | A system used in a legally specified sensitive context | Conformity assessment, risk management, records and human oversight | Classification depends on its intended use |
| Transparency-risk system | A system involving chatbots or generated content covered by Article 50 | Disclosure, marking or labelling | Usually carries fewer duties than a high-risk system |
| Prohibited practice | An unacceptable use identified by the Act | Banned | Different from a regulated lawful use |
ChatGPT should therefore not receive one blanket classification. A general conversational feature may fall within transparency rules. A separate deployment used to rank job applicants, determine access to education or support migration decisions could enter a high-risk category. The legal assessment depends on the exact function, intended purpose, organisation and context.
General-purpose model providers must maintain a policy for complying with EU copyright rules. That policy must address lawful text-and-data mining and rights holders’ reservations. Providers must also publish a sufficiently detailed summary describing content used for training. A standardised template supports consistent reporting across the market.
The summary requirement aims to improve transparency without forcing publication of entire datasets. It also does not resolve every copyright dispute. Existing copyright legislation continues to apply alongside the AI Regulation Act. Litigation, licensing debates and national copyright remedies remain legally separate from model-documentation requirements.
Users should receive clear information when they interact directly with certain artificial intelligence systems, unless the context already makes that interaction obvious. Covered generated and manipulated content may require detectable marking or visible labelling. People affected by high-risk systems can also benefit from documentation, human oversight and complaint procedures.
The AI Act does not replace data-protection, consumer-protection or equality laws. A person may still exercise GDPR rights when personal data is processed. Consumers may use national remedies when a service is misleading or unfair. Suspected AI Regulation Act violations can be reported to the relevant market-surveillance authority once the national complaint route is operational.
Organisations should identify whether they act as providers, deployers, importers or distributors. They must also assess the intended purpose and risk category of each system. A provider normally carries greater responsibilities than a business using a standard external tool. Organisations deploying covered systems must maintain appropriate AI literacy among staff.
Additional obligations can include human oversight, record-keeping, logging, data governance and impact assessments. Employers may face workplace information or consultation requirements. Organisations should obtain adequate documentation from vendors and establish incident-escalation procedures. Using ChatGPT does not automatically subject a business to every provision of the Act.
The AI Act and its applicable implementing measures create binding legal duties. European Commission guidelines explain how authorities interpret those duties but do not replace the legislation. Harmonised standards may help organisations demonstrate conformity. Their legal effect depends on formal recognition and the requirement involved.
Codes of practice remain voluntary compliance tools. The General-Purpose AI Code helps model providers demonstrate transparency, copyright, safety and security measures. The Article 50 code supports marking and labelling. Signing either code does not prove complete compliance. A provider choosing another method must demonstrate that its alternative measures satisfy the law.
Prohibited-practice violations can attract penalties of up to EUR 35 million or seven per cent of worldwide annual turnover, whichever calculation applies under the Act. Other breaches can reach EUR 15 million or three per cent. Supplying incorrect, incomplete or misleading information can lead to penalties of up to EUR 7.5 million or one per cent. Different calculations apply to smaller businesses.
For general-purpose model providers, the European Commission can impose fines of up to EUR 15 million or three per cent of worldwide annual turnover. Maximum penalties are not automatic. Authorities must consider the nature, gravity, duration and circumstances of a breach. Affected organisations retain procedural and appeal rights.
The AI Act can apply to providers established outside the European Union when they place models or systems on the EU market. It may also apply when outputs produced by their systems are used within the Union. The territorial test therefore depends on market access and European use rather than the provider’s headquarters alone.
International providers may adjust technical documentation, evaluations, product releases and customer contracts. Some may use European compliance measures more widely across their global operations. However, the AI Regulation Act does not automatically govern every system, user or activity worldwide.
The EU has one common regulation, not 27 separate artificial intelligence laws. National implementation statutes organise enforcement but do not replace the central framework. Authority designation does not prove active investigation. A corporate compliance statement is not a regulatory finding, while code membership does not establish complete compliance.
General-purpose models are not automatically high-risk systems. Earlier GDPR action is not AI Act enforcement. Future high-risk duties should not be described as active before their revised dates. Product changes may reflect several commercial, technical or legal factors. They should not be attributed to one requirement without official confirmation.
The AI Regulation Act states that it establishes “harmonised rules concerning the placing on the market, putting into service and use of artificial intelligence systems”.
That wording confirms the central structure of the framework. The rules are European and harmonised, while enforcement uses both European and national institutions. National governments can organise authorities and procedures, but the central classifications and obligations remain grounded in EU law.
The next major dates are 2 August 2027 for older general-purpose models, 2 December 2027 for specified high-risk uses and 2 August 2028 for AI embedded in regulated products. Authorities must continue developing complaint routes, regulatory sandboxes, technical expertise and cross-border cooperation. Providers must monitor new guidance, standards, templates and reporting procedures.
Effective AI Regulation will become visible through published documentation, functional complaint systems, transparent investigations and enforceable decisions. Voluntary announcements will provide supporting evidence but cannot replace regulatory findings. Users should watch for clearer content labels, accessible explanations and national contact points capable of receiving suspected violations.
The EU AI Act now operates through one common framework across Belgium and the other 26 member states. Belgium, France, Germany, Italy and Spain use different supervisory structures without creating separate European laws. General-purpose model providers may face documentation, copyright and training-summary duties, while systemic-risk models carry additional safeguards. Some requirements are already enforceable, but major high-risk provisions remain scheduled for 2027 and 2028. Successful AI Regulation will depend on coordinated authorities, practical complaint systems, published compliance evidence and proportionate enforcement rather than promises or voluntary code membership alone.
No. It is an EU regulation that applies directly across all 27 member states. National measures establish authorities, procedures and penalties.
Belgium uses federal and sector authorities according to their existing responsibilities. Available official guidance does not support identifying one body as the sole regulator for every system.
Relevant providers may need technical documentation, downstream information, copyright policies and public training-content summaries. Systemic-risk models face additional safety and security duties.
No blanket high-risk classification was identified. Classification depends on the underlying model, system, intended purpose and deployment context.
Older general-purpose models have a transition deadline of 2 August 2027. Specified high-risk use rules follow on 2 December 2027, while regulated-product requirements follow on 2 August 2028.
Users may receive transparency information and access national complaint routes. GDPR, consumer-protection, equality and other existing legal rights continue to apply.
Advertisement
Advertisement
Advertisement
Saturday, September 5, 2026
Friday, September 4, 2026
Saturday, September 5, 2026
Thursday, September 3, 2026
Wednesday, September 2, 2026
Saturday, September 5, 2026
Saturday, September 5, 2026