EU AI Act's High-Risk Rules Activate Amid US
EU AI Act's high-risk rules activate amid US leverage and enforcement gaps
Model Diplomat9 min readEurope

Europe's AI Enforcers Get Their Teeth on August 2 — Six Weeks After Washington Showed Them Who Really Holds the Leash
On August 2, 2026, the EU activates the most consequential provisions of its AI Act — high-risk system rules. But the real story is that the enforcement machinery being switched on is outgunned roughly 10,000-to-1 by the industry it regulates, and the United States just spent June demonstrating it can unplug Europe from frontier AI on a Friday afternoon.
The European Union flips the switch on the most punishing part of its AI Act on August 2, 2026: the rules for high-risk systems. After two years of phased implementation — prohibited practices banned in February 2025, general-purpose AI model obligations kicking in last August — the law's most demanding provisions finally take effect, covering everything from hiring algorithms and credit-scoring systems to critical infrastructure and law enforcement applications. The EU AI Office, the bloc's dedicated enforcement body, will formally hold the tools legislators designed for it. The question Euractiv's Eliza Gkritsi posed this week—"whether or not the bloc will dare to use them"—is the right one, but for darker reasons than her piece could fully explore. Euractiv
The backdrop has shifted decisively since the AI Act was signed in June 2024. The United States has demonstrated — in real time, on live infrastructure — that frontier AI access is now an instrument of geopolitical coercion, and that Europe is on the receiving end.
On June 12, 2026, the US Department of Commerce imposed export controls on Anthropic's two newest models, Mythos 5 and Fable 5, via a letter to the company. The order required that all foreign nationals — inside the United States or out, including Anthropic's own foreign employees — be denied access. Anthropic, unable to comply selectively, disabled both models for everyone. BBC The European Union, which had negotiated access to Mythos only weeks earlier after protracted talks with Anthropic, lost it in an afternoon. Thomas Regnier, European Commission spokesman for tech sovereignty, told reporters the ban was "discriminatory against partners" and underlined "Europe's need for technological sovereignty."
Al Jazeera
Commerce Secretary Howard Lutnick lifted the Anthropic embargo on July 1, 19 days after it was imposed. The strategic damage was done. Chatham House French President Emmanuel Macron called the episode "strictly nationalist." Former French minister and 2027 presidential candidate Bruno Retailleau crystallized the European mood: "A nation that depends on others for its technology is a nation that can be unplugged overnight."
Al Jazeera
This is the strategic environment into which the EU's AI enforcement apparatus now steps. It is not the one legislators imagined when they drafted the Act.
The enforcement asymmetry in one number
The EU AI Office was allocated a starting budget of €46.5 million. The Economist Global hyperscaler capital expenditure — the money spent by the companies whose models the office is supposed to police — is projected at $527 billion in 2026.
Chatham House Anthropic's private valuation, meanwhile, is approaching $1 trillion ahead of an expected public listing.
BBC
The arithmetic is not complicated. Even with the AI Office's "capable researchers" — a description economists and think-tank analysts have granted it — the institution is being asked to enforce a product-safety regime against firms whose individual training runs may soon cost more than its annual budget. OpenAI's CEO projected in 2025 that future frontier models could require $100 billion in capital per training run. Chatham House
The capacity gap is not just financial. Europe's operational AI compute stands at roughly 123,000 H100-equivalent chips, against approximately 1.4 million in the United States. RAND Even including all confirmed and likely planned capacity through 2030, Europe reaches an estimated 3.2 million H100-equivalents — while the United States is projected to hit at least 19.4 million.
Enforcement here is not a legal exercise. It is a test of whether a mid-sized agency can impose costs on firms that dwarf the entire European AI ecosystem.
What actually activates on August 2
To understand the stakes, it helps to be precise about what the August 2 deadline triggers. Under the AI Act's phased structure, the rules on general-purpose AI models — the obligations covering companies like OpenAI, Anthropic, and Google — entered application on August 2, 2025, supported by a voluntary Code of Practice finalized in July 2025. More than 25 companies signed that code, though Meta publicly refused. CSIS
What activates this year is broader. The high-risk rules cover AI embedded in hiring, education, financial services, critical infrastructure, law enforcement, border control, and judicial processes. Any provider placing such a system on the EU market must comply with requirements on data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and non-discrimination. Fines reach 6% of global annual turnover. EUR-Lex
The legal architecture delegates enforcement to member states, each of which must designate at least one market surveillance authority. These national bodies form the European AI Board, coordinated by the AI Office. General-purpose AI models with systemic risk fall under the AI Office's exclusive central oversight. RAND The system is deliberately decentralized — but it creates an enforcement landscape that analysts have warned will be fragmented, with member states varying sharply in capacity and political willingness to act.
Brookings
Crucially, the harmonized standards that would give companies a presumption of conformity — the technical specifications developed by European standardization bodies CEN and CENELEC — were supposed to be ready by April 2025. Their status as the August 2026 deadline arrives remains uncertain. Without them, companies face legal ambiguity about what, precisely, compliance requires.
The Anthropic shock and the sovereignty scramble
The events of June 2026 did more than disrupt access to two AI models. They validated, with the force of a live demonstration, the most pessimistic European assumptions about technological dependency.
Anthropic's Mythos is not an ordinary model. It independently developed offensive cyber capabilities that can identify zero-day vulnerabilities in software infrastructure — including flaws in operating systems considered secure for 27 years. The model found thousands of zero-days in testing; 99 percent remained undefended at the time of Anthropic's April disclosure. Council on Foreign Relations The UK's AI Security Institute found it could exploit system defenses 73 percent of the time — "a step change in capability in cyber security," according to Professor Gina Neff of Queen Mary University London.
BBC
When Washington cut off access, it was not blocking a chatbot. It was demonstrating that the most strategically significant AI capability in existence would be available to allies on American terms — or not at all.
The response has been a surge of investment and deal-making aimed at building European alternatives. On July 21 — one day before this Euractiv piece published — Microsoft and Paris-based Mistral announced a significant expansion of their partnership, bringing Mistral's frontier models into Microsoft's sovereign cloud portfolio for deployment in public cloud, cloud-connected, and fully disconnected environments. Brad Smith, Microsoft's vice chair and president, framed the deal explicitly in sovereignty terms: "Europe should have access to the world's most capable AI without compromising control over their data, operations or digital future." Microsoft/Mistral
Mistral, described by analysts as the "EU's only major homegrown frontier-model competitor," is now the obvious beneficiary of the post-Anthropic scramble. Al Jazeera Germany and France's domestic spy agencies have already pivoted toward European technology providers to reduce dependence on US firms like Palantir. EU Executive Vice President Henna Virkkunen, responsible for tech sovereignty, called the Anthropic cutoff "another wake-up call" for Europe.
Brookings
The enforcement dilemma Brussels cannot avoid
Here is the tension that will define the next 12 months.
The AI Act's enforcement credibility depends on Brussels demonstrating it will impose its rules on the largest model providers — overwhelmingly American companies — exactly as written. The fines are substantial (6% of global revenue), the documentation requirements are onerous, and the systemic-risk provisions for frontier models give the AI Office genuine investigative authority.
But the sovereignty imperative pushes in the opposite direction. Europe needs US models. It needs Anthropic's continued participation in the Code of Practice. It needs OpenAI, Google, and Meta to keep offering services in the European market while European alternatives mature. Every enforcement action against an American firm is also a provocation at a moment when the US has shown it considers AI access a lever of state power.
The Trump administration has already made clear it views EU digital regulation as "extortion" against US companies, increasingly folded into the broader negotiation over tariffs and trade. CSIS The EU's own AI Continent Action Plan — which promised to "turbocharge AI" in Europe — toned down language on regulatory simplification in its final version, with analysts interpreting the shift as Brussels keeping cards in hand for transatlantic negotiations.
CSIS
The result: a regulatory apparatus that must project strength from a weakened geopolitical position. The AI Office will be expected to evaluate systemic-risk models, demand documentation, and potentially sanction non-compliance — all while European governments are simultaneously negotiating with the same companies for continued access to frontier capabilities they cannot yet build themselves.
What to watch
Three concrete catalysts will reveal the enforcement trajectory before year-end:
-
The Commission's first formal adequacy assessment of the Code of Practice. Under Article 56(6) of the AI Act, the AI Office and the AI Board must regularly evaluate whether the code adequately covers the obligations in Articles 53 and 55. A finding of inadequacy would trigger the Commission's power to impose common rules by implementing act — a nuclear option that would strip providers of the voluntary compliance pathway.
EU AI Act Service Desk
-
The first national enforcement actions under the high-risk system rules. Which member state moves first, against which system, and at what scale, will signal whether the decentralized enforcement model produces genuine accountability or regulatory arbitrage. Germany, France, and the Netherlands have the deepest technical capacity among national authorities and are the most likely first movers.
-
Anthropic's integration into the EU compliance framework, now that Mythos access has been restored. The company's participation in the Code of Practice and its willingness to submit to AI Office evaluations will test whether the sovereignty crisis of June 2026 has tilted the balance toward accommodation or assertion on both sides.
Diplomat View
The August 2 activation was supposed to be the moment Europe claimed the regulatory high ground — the world's first comprehensive AI law, fully armed, policing the technology's most consequential applications. Instead, it arrives as a stress test of whether legal authority means anything when the underlying power relationship runs decisively the other way.
The EU has written a law that assumes a functioning transatlantic partnership. The partnership has been demonstrated, in operational terms, to be conditional. Washington can and will cut off access to strategically vital AI capabilities on national-security grounds, without meaningful consultation, applying the same legal instrument — export controls — to allies that it uses against adversaries. Brussels has no reciprocal capability. There is no European model that Washington needs.
The forecast: Enforcement in the first 12 months will be calibrated for minimum transatlantic friction. The AI Office will prioritize process over penalty, documentation over prohibition, and will avoid direct confrontations with major US providers. The Code of Practice — voluntary, co-regulatory, and already weakened by Meta's refusal — will serve as the primary compliance vehicle rather than the backstop it was designed to be. The high-risk system rules will be enforced most actively against European deployers — hospitals, banks, recruitment firms — rather than American model providers.
This forecast changes if: (1) Another US access restriction triggers a second sovereignty crisis, hardening European political will for assertive enforcement; (2) Mistral or another European frontier-model developer achieves capability parity with US labs in a specific domain, reducing the deterrence effect of threatened withdrawal; or (3) A major AI-related harm — a cyberattack traced to an unregulated model, a discriminatory hiring system with mass impact — creates political demand for visible enforcement that overrides diplomatic caution.
The Bottom Line
The EU AI Act's high-risk provisions activate on August 2 into a strategic environment its authors did not anticipate: the US has weaponized AI access against allies, Europe's enforcement budget is outmatched roughly 10,000-to-1 by the industry it polices, and Brussels now needs the very American firms it is supposed to regulate for the technological sovereignty it is trying to build. The law's first year will be a study in calibrated under-enforcement — unless Washington forces Europe's hand again.
Discover more

India
Delhi CM Rekha Gupta Blasts Opposition's Delm
Delhi CM Rekha Gupta's remarks on women's quota defeat reveal BJP's strategy for the 2029 Lok Sabha elections, focusing on delimitation.

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

Economics
US Sanctions Iran's Nobitex Crypto Exchange
US Treasury sanctions Nobitex, Iran's largest crypto exchange, for processing billions in stablecoins for the central bank and IRGC, extending secondary sanctions risk to foreign platforms.