# EU AI Act enforcement of general-purpose AI model rules began on 2 August 2026, and deployers keep their own share of responsibility > The Commission can now enforce the AI Act against general-purpose AI model providers. What remains with organisations deploying LLMs, and how vendors split it. FireAI Security & Research Team (HisnLabs) · Published 2026-09-30 Canonical: https://hisnlabs.com/en/news/eu-ai-act-gpai-enforcement-llm-shared-responsibility From 2 August 2026 the European Commission can enforce the EU AI Act against providers of general-purpose AI models, and fines become possible, according to the Commission’s guidance and its implementation timeline [[1]](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers) [[5]](https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act). Days earlier the Digital Omnibus on AI, an amending regulation, had entered into force on 27 July and moved the high-risk deadlines to December 2027 and August 2028 [[3]](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo). For an organisation that deploys a large language model (LLM) from a vendor, the model provider’s duties and the deployer’s own duties are different things. ## Background The AI Act’s rules for general-purpose AI models began to apply on 2 August 2025. The Commission’s guidelines list the duties of a model provider: technical documentation for authorities and the AI Office, information for downstream developers about the model’s capabilities and limitations, a copyright policy, a public summary of training content, and an EU representative for providers established outside the Union [[1]](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers). The guidelines treat a model as general-purpose when it is trained with more than 10^23 floating-point operations and can generate language, text-to-image or text-to-video output, and describe this as an indicative threshold. Models trained with more than 10^25 operations are presumed to carry systemic risk [[1]](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers). ## What the sources describe The Commission’s FAQ gives three dates: 2 August 2025, when obligations begin with an initial compliance period for adherents of the Code of Practice; 2 August 2026, when full enforcement with potential fines commences; and 2 August 2027, when models already on the market before the rules applied must comply [[1]](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers). The Commission’s AI Act Service Desk timeline states that enforcement for general-purpose AI models and for transparency obligations begins on 2 August 2026 [[5]](https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act). A law-firm analysis published on 24 July 2026 describes the earlier arrangement as a year’s grace period for signatories of the General-Purpose AI Code of Practice, ending on 2 August 2026 [[2]](https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/). On the Digital Omnibus, the status is adoption, not proposal. A law-firm analysis and a Cloud Security Alliance research note report that Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 [[3]](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo) [[4]](https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/). It moves the application date for stand-alone high-risk systems in Annex III from 2 August 2026 to 2 December 2027, and for AI embedded in products covered by sectoral safety law (Annex I) to 2 August 2028 [[2]](https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/) [[3]](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo). The Commission’s timeline page shows the same dates [[5]](https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act). Other obligations stay on their original schedule, including the general-purpose AI provider duties, the prohibited practices in force since 2 February 2025, and the Article 50 transparency duties. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty for synthetic media [[3]](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo) [[4]](https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/). For deployers, the sources point to duties that sit outside the model provider’s documentation. Providers must disclose that a person is interacting with an AI system and mark AI-generated content; deployers must disclose deepfakes, emotion recognition and biometric categorisation, and the duties reach organisations that run branded chatbots and generative AI tools [[2]](https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/). The Omnibus softened the general AI literacy duty to a requirement of measures rather than a specific competence outcome, while deployers of high-risk systems keep the competence requirement in Article 26(2) [[3]](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo). Vendor security documentation divides the work in a similar way. Microsoft’s model for generative AI describes three layers: the AI platform, the AI application and AI usage. It states that responsibility generally sits with the party that performs the task, and that the split changes between software-as-a-service, platform-as-a-service and infrastructure-as-a-service deployments [[6]](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai). Its separate model for autonomous agents adds orchestration, tools and actions, and memory. In it the customer keeps responsibility for data, identities, human approval of high-impact actions and acceptable-use accountability in every deployment type, and, for an agent built on a managed platform, for its instructions, tool selection and per-tool permissions [[7]](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai-agent). Microsoft calls its guidance illustrative and not a legal conclusion [[6]](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai). A Cloud Security Alliance blog post from 2023 had proposed the same shape for generative AI, with an AI service provider and an AI service user, where the user keeps data lineage, application security and prompt controls [[8]](https://cloudsecurityalliance.org/blog/2023/07/28/generative-ai-proposed-shared-responsibility-model). > FireAI, the on-device firewall for macOS developed by HisnLabs, records which apps, including AI apps, connect to which destinations on a Mac. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for organisations Enforcement against model providers does not transfer the deploying organisation’s obligations to the vendor. The provider’s documentation and downstream-developer information are inputs to the deployer’s own assessment of its prompts, data, tool permissions and output handling. The sources reviewed do not settle when a deployer that fine-tunes or substantially modifies a model becomes a provider itself; the Commission’s guidelines are the place to check that question for a given case. ## Recommendations 1. List each LLM and agent in use, the vendor, and the deployment type (software, platform or self-hosted), since the split of duties depends on it. 2. Record which duties the vendor’s documentation assigns to the customer, and treat vendor documents as guidance, not as a contract or legal advice. 3. Check whether the Article 50 transparency duties apply to chatbots or generated content the organisation publishes. 4. For agents, review tool permissions, human approval steps and logging, which the Microsoft model leaves with the customer. 5. Read the [FireAI University course on AI security frameworks and red teaming](https://hisnlabs.com/en/university/ai-security-frameworks-and-red-teaming) and the [blog post on shared responsibility for LLMs](https://hisnlabs.com/en/blog/shared-responsibility-for-llms). ## Relevance to FireAI FireAI is a network firewall for a single Mac, not a compliance product. It does not assess AI Act obligations, does not classify AI systems and does not certify anything. What it can show is the network side of an LLM tool on a Mac. [Per-app rules](https://hisnlabs.com/en/docs/per-app-rules) let an AI app or coding assistant be limited to the destinations it needs, the [first-connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt) asks before a new app reaches an unfamiliar destination, the [world map](https://hisnlabs.com/en/docs/world-map) shows where an app’s traffic goes, and the [upload alerts](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes) flag a sudden large upload to one country. The [kill switch](https://hisnlabs.com/en/docs/kill-switch) stops new connections. FireAI does not read prompts or model output and does not see what an agent does inside an application. > FireAI’s per-app rules and connection prompts give a Mac user a record and a veto over where an AI tool connects. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The Commission’s FAQ and timeline pages were read without a visible publication date, and the Commission page does not state fine amounts. The law-firm and research-note summaries agree on the Omnibus dates, but the Official Journal text itself was not opened for this item. Microsoft’s pages are vendor guidance for its own services and the Cloud Security Alliance post is a 2023 proposal, so neither has legal force. No source read here says how national authorities or the AI Office will use their powers in practice. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [European Commission, Digital Strategy: Guidelines on the obligations of providers of general-purpose AI models (FAQ)](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers) - [Data Protection Report (Rosie Nance and Marcus Evans), 24 July 2026: The EU AI Act: when does it become enforceable now?](https://www.dataprotectionreport.com/2026/07/the-eu-ai-act-when-does-it-become-enforceable-now/) - [Lewis Silkin, 27 July 2026: The Digital Omnibus on AI enters into force today](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo) - [Cloud Security Alliance Labs, 1 August 2026: EU AI Act high-risk deadline, deferred, not cancelled (research note)](https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/) - [European Commission, AI Act Service Desk: Timeline for the implementation of the EU AI Act](https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act) - [Microsoft Learn (page dated 24 August 2026): Artificial intelligence shared responsibility model](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai) - [Microsoft Learn (page dated 26 August 2026): AI agent shared responsibility model](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai-agent) - [Cloud Security Alliance (Vishwas Manral), 28 July 2023: Generative AI, a proposed shared responsibility model](https://cloudsecurityalliance.org/blog/2023/07/28/generative-ai-proposed-shared-responsibility-model)