Questions about the European Commission’s oversight of general-purpose AI are putting compliance teams on alert. Major US labs, including OpenAI and Anthropic, may be among the companies assessing their exposure, although specific enforcement steps involving either provider have not been independently confirmed.
The practical issue is broader than any individual company. Providers offering general-purpose AI models in the European Union need a clear process for handling regulatory questions, evaluations and possible restrictions. The available details do not support treating every proposed power, deadline or penalty figure as settled, but they do identify several areas where providers can prepare.
Separate confirmed obligations from uncertain details
Descriptions of the enforcement framework have included information requests, model evaluations, potential restrictions on EU market access and financial penalties. A firm start date, the precise scope of any pre-release evaluation power and the stated maximum penalty of €15 million or 3% of annual turnover have not been independently confirmed.
Companies should therefore avoid building their compliance plans around a single date or penalty calculation. The safer approach is to map the obligations that may apply, document any uncertainty and have qualified European counsel verify the latest requirements before a product launch or regulatory response.
This matters because EU AI Act compliance is developing through multiple rules, implementation measures and codes rather than one isolated checkpoint.
Build a practical regulatory-readiness process
A provider does not need to wait for a formal request before deciding who will respond and how technical access will be handled. A useful preparation sequence is:
- Confirm whether the model is offered in the EU. Map which models, APIs and related services are available to European customers. Include services distributed through partners, because a provider’s location may not settle whether European requirements apply.
- Establish an EU point of contact. Elisabetta Righini, a partner at Sidley Austin, has said non-EU providers must appoint an EU-based authorised representative. Providers should verify that requirement for their circumstances and document who can communicate with regulators.
- Create an information-request workflow. Assign legal, policy and technical owners before an inquiry arrives. Responses should be reviewed for accuracy and completeness, since refusing a request, supplying misleading information or obstructing an evaluation may create exposure independently of a model’s underlying compliance.
- Plan for model evaluations. Decide how authorised reviewers could receive the access and technical information needed to examine a model. The process should define responsibilities, approval steps and safeguards for systems or data that fall outside the evaluation.
- Prepare for operational restrictions. Identify which products, customers and distribution channels would be affected if EU access were limited. A contingency plan can reduce rushed decisions while legal questions are resolved.
Why US headquarters may not limit exposure
The central jurisdictional point is straightforward: selling or providing a general-purpose AI model in Europe can matter more than the address on the provider’s headquarters. Righini has argued that a US address does not, by itself, place an AI laboratory beyond the European regulator’s reach.
That makes distribution strategy part of compliance planning. Teams should know where each model is offered, which entity provides it and who represents the provider in Europe. Product, legal and engineering leaders also need the same account of the model’s capabilities and controls so that a regulatory response does not contain conflicting answers.
What providers should do next
The immediate task is readiness, not speculation. Providers should inventory their EU-facing models, name response owners, verify representative requirements and rehearse how they would handle an evaluation or information request. Any assumptions about enforcement dates, inspection authority or maximum fines should be marked for legal confirmation.
OpenAI has said it has worked with the European Commission and the wider AI ecosystem on implementation of the legislation and its codes of practice. That kind of engagement may help providers understand expectations, but it does not replace a company-specific assessment. The most defensible plan is one that can adapt as uncertain details become clearer without leaving basic response procedures until the last minute.
