EU AI Office Gains Powers Amid US AI Leverage
EU AI Office gets enforcement powers, but US leverage looms.
Model Diplomat11 min readEurope

Europe’s AI enforcers finally get teeth — and Washington just showed why Brussels might be afraid to bite
On August 2, 2026, the EU Commission gains powers to fine AI giants up to 3% of global turnover. But after the US cut off Europe's access to frontier AI overnight in June, the real question is whether Brussels dares use them.
On Wednesday, August 2, the European Commission’s AI Office gets teeth. After a two-year ramp-up, it can now demand internal documentation from the world’s most advanced AI developers, conduct its own model evaluations, mandate risk-mitigation measures, and levy fines of up to 3% of a company’s annual worldwide turnover under Article 101 of the AI Act.
The law is not the problem. The problem is the AI Office has 34 people working on regulation and compliance, according to a Commission document seen by Euractiv. Total headcount is 145. Fewer than a quarter are assigned to the enforcement mission that now formally begins.
And the problem beyond the problem is geopolitical. Washington spent June demonstrating that it can sever Europe’s access to frontier AI models with a single export-control directive. The Commission’s newly acquired formal powers land in the middle of a transatlantic standoff in which AI access has become a weapon. Brussels still does not have an answer to the question of what happens if it fines an American lab and Washington retaliates by pulling the plug again.
The first cases will set the precedent, and the pressure to go easy is already mounting.
The tools, on paper, are formidable
The AI Act’s enforcement architecture for general-purpose AI models is laid out in Section 5 of Chapter IX, spanning Articles 88 through 94. The Commission — acting through the AI Office — can request documentation and any additional information necessary to assess compliance (Article 91); conduct its own evaluations of a model, including by accessing the model itself (Article 92); and require providers to implement mitigation measures or restrict, withdraw, or recall a model from the EU market entirely (Article 93).
A structured dialogue between the AI Office and the provider must precede any formal request. But if that dialogue fails, the full suite of coercive tools activates. Under Article 93(3), the Commission can even make a provider’s voluntary commitments legally binding by decision, closing off further grounds for action. By implication, it sets a trap for any firm that offers commitments it cannot keep.
Since August 2, 2025, providers of the most advanced general-purpose AI models have been under a legal obligation to comply with the Act’s requirements. The one-year grace period was explicitly designed to let the AI Office conduct “technical compliance dialogues” before formal powers kicked in. According to the Commission’s own FAQ, it has been doing exactly that — engaging companies “to improve their practices to assess and mitigate systemic risks.” From Wednesday, the dialogues continue, but the velvet glove comes off.
The cyber model that changed the equation
The AI Act was drafted when “systemic risk” meant, in practice, hypothetical scenarios. That changed in April 2026, when Anthropic gave twelve US companies private access to Mythos Preview through an initiative called Project Glasswing — a model the company said could outperform humans at hacking and cybersecurity tasks.
Mythos did not stay theoretical for long. The UK’s AI Safety Institute found that the model could exploit system defences 73% of the time, a finding cited by BBC News. Bank of England governor Andrew Bailey told the BBC that regulators were “having to look very carefully now what this latest AI development could mean for the risk of cyber crime.” The IMF discussed Mythos extensively at its spring meetings in Washington.
Mythos also became the trigger for an unprecedented US intervention. On June 12, the Commerce Department issued an export-control directive barring all non-US nationals — including foreign employees at Anthropic itself — from accessing Mythos 5 and Claude Fable 5. Anthropic suspended both models globally the next day, as the BBC reported.
Thomas Regnier, European Commission spokesperson for tech sovereignty, called the development “another wake-up call for Europe” in an interview with Al Jazeera. The EU had only just secured access to Mythos after weeks of negotiations with Anthropic. It lost that access overnight.
The US partially reversed course by July 1. Fable 5 became publicly available globally, and the EU regained Mythos access. But the damage was done. As Chatham House noted, the EU “gained access to Mythos earlier in June after weeks of talks, only for the EU to lose it days later following the export control directive (and now, presumably, regain it).” The lesson was unambiguous: access to the frontier is a political decision made in Washington, and it can be revoked by a single directive.
The tariff shadow over enforcement
The AI Office’s new powers do not exist in a trade-policy vacuum. On June 27, President Donald Trump threatened a 100% tariff on any country that imposes a digital services tax on US technology companies, writing on Truth Social that such measures were “designed to harm, or discriminate against, American Technology,” as Al Jazeera reported.
This was not an isolated threat. The Trump administration has embedded anti-digital-regulation clauses into bilateral trade agreements with at least nine countries, from Malaysia to Guatemala, using tariff leverage to contain the spread of EU-style tech rules, according to CSIS analysis. In January 2026, the State Department imposed visa restrictions on five European officials involved in drafting the Digital Services Act and Digital Markets Act.
The White House has also granted itself a veto over who gets access to the most powerful US AI models. As Euractiv put it, the EU could end up “fining labs with one hand, while trying to secure AI access with the other.”
The trade architecture makes the Commission’s dilemma concrete. In August 2025, the EU and US signed a framework agreement capping most tariffs at 15%. That deal did not cover digital regulation. Trump has since threatened to supersede it with punitive tariffs on any country enacting digital taxes or regulations he deems discriminatory. A Commission decision to fine OpenAI or Anthropic under the AI Act could easily be cast by Washington as exactly the kind of “extortion” that justifies tariff retaliation.
The sovereignty argument — and its limits
The June cutoff has already reshaped the political debate inside Europe. Brando Benifei, the Italian Socialist MEP who co-authored the AI Act, told Euractiv that “Mythos showed that access to frontier models has become geopolitical leverage, but Europe’s sovereignty will be judged by whether it defends its own rulebook rather than trading away enforcement for access.”
Benifei’s framing — enforce first, negotiate access separately — is the maximalist position. It is not the Commission’s position. Nor is it clearly the position of Paris or Berlin, both of which have been deeply rattled by the realisation that the United States can unplug Europe from frontier AI at will. Bruno Retailleau, a leading candidate in France’s 2027 presidential election, called the Anthropic ban a “wake-up call” and said that “a nation that depends on others for its technology is a nation that can be unplugged overnight,” according to Al Jazeera.
The paradox is sharp. The AI Act was designed to project European regulatory power outward — to set a global standard. But enforcing it aggressively against US firms at a moment of maximum dependency on those same firms for frontier-model access risks producing the opposite result: a Europe that is legally sovereign but technologically dependent, with a rulebook it cannot afford to use.
This is not lost on Washington. Brookings captured the dynamic precisely: the Trump administration’s AI Action Plan aimed to “drive adoption of American AI systems, computing hardware, and standards throughout the world,” but by directing Anthropic to deny foreign nationals access to Mythos and Fable, it “set fire to its own strategy.” The collateral damage to EU enforcement credibility may be an unintended benefit for an administration that views EU digital regulation as a trade barrier to be dismantled.
The enforcement capacity gap
The politics matters, but so does the arithmetic. Thirty-four compliance staff at the AI Office will be responsible for monitoring and — in principle — enforcing obligations on companies whose individual legal and public-policy teams number in the hundreds.
The Commission’s FAQ notes that “the AI Office has also established the structures and competencies needed for using enforcement powers,” adding that formal powers will be used “in cases where technical compliance dialogues are not sufficient.” That language signals a preference for negotiated compliance, not adversarial enforcement. It also implicitly acknowledges that the AI Office cannot conduct evaluations of every model, track every incident, and pursue every infraction — it must triage.
Civil society groups have already sought to shape that triage. A letter sent to Commission President Ursula von der Leyen and tech commissioner Henna Virkkunen earlier this month, reported by Euractiv, urged the EU to apply its new AI tools “with confidence and resolve” and to focus initially on “big looming risks, like Mythos’ cyber-capabilities.”
The implication is clear: do not start with paperwork violations. Start with the model that can allegedly exploit 73% of tested defences and has already triggered crisis meetings at the IMF. That is the case that will define whether the AI Act is a serious enforcement regime or a paper tiger.
The counter-pressure is equally clear. The Commission has spent the last year building cooperative relationships with AI labs through compliance dialogues. Moving from dialogue to formal information requests — let alone fines or market-withdrawal orders — would mark a rupture in those relationships. In the current geopolitical climate, rupture carries costs that go well beyond any single company’s compliance budget.
What happens to the non-US frontier
One underappreciated dimension: the AI Act applies to all providers of general-purpose AI models placed on the EU market — not only American ones. The Commission’s enforcement powers extend to Chinese frontier models, should they seek EU market access.
But here, too, the geopolitical geometry complicates enforcement. The US has made clear it views Chinese AI as a strategic threat and has built an export-control architecture designed to deny Beijing access to advanced chips and, increasingly, to limit the spread of Chinese AI models globally. If the EU were to take enforcement action against a Chinese model under the AI Act, it would be doing so at a moment when Washington is actively pressuring allies to reduce their dependence on Chinese technology stacks.
Fortune reported that some 46 countries are now investing government funds in roughly 135 sovereign AI projects — a scramble accelerated by the Mythos cutoff. The EU’s own push for technological sovereignty, articulated by Commissioner Virkkunen, sits uneasily alongside an enforcement regime that, by design, is global in scope but depends on access to models built almost entirely outside Europe.
Paris-based Mistral remains, as one analyst told Al Jazeera, “the EU’s only major homegrown frontier-model competitor.” That is a thin reed on which to rest a sovereignty strategy.
The decision point
The AI Office will not have to decide everything on August 2. The formal powers enable action; they do not mandate it. The real question is what happens the first time the scientific panel — established under Article 90 to alert the Commission to systemic risks — flags a model for investigation. Or the first time a provider refuses a request for documentation under Article 91. Or the first time a structured dialogue under Article 93 fails to produce acceptable commitments.
At each of those inflection points, the Commission will have to weigh the enforcement imperative against the risk of triggering a transatlantic confrontation in which the EU holds a strong legal hand but a weak technological one.
CSIS assessed that while a trade war over tech regulation “would not be good for Europe, trade with the United States amounts to 20 percent of EU exports, roughly 3 percent of EU GDP. It would certainly be survivable.” The EU’s anti-coercion instrument also provides retaliatory options beyond tariffs, including measures against US service imports and intellectual property rights.
But survivability is not the same as leverage. The EU cannot build a frontier AI model on short notice to replace access it loses. That asymmetry will shape every enforcement decision the AI Office makes.
Diplomat View
The August 2 milestone is legally significant but strategically treacherous. The EU AI Office now possesses a suite of enforcement powers that are, on paper, among the most potent any regulator has ever held over the AI industry. The problem is that exercising those powers against American firms — the only firms building the models that most concern regulators — would occur at precisely the moment when Brussels has been reminded, in the bluntest possible terms, that Washington controls the supply of frontier AI.
The likely outcome is not a full retreat but a carefully calibrated opening. Expect the AI Office to launch its first formal investigation within three to six months, almost certainly targeting a cyber-capability risk of the kind Mythos represents — an area where the security argument for enforcement is hardest for Washington to dismiss as protectionism. Expect the first fine to be negotiated down in a structured dialogue, not imposed unilaterally. And expect Paris, which is more exposed to US pressure than Brussels alone, to push for parallel investment in sovereign AI capacity as the price of supporting aggressive enforcement.
The forecast changes if two things happen. First, if Washington imposes tariffs explicitly in retaliation for an AI Act enforcement action — that would test the EU’s anti-coercion instrument and could trigger a spiral that neither side has fully gamed out. Second, if a major cyber incident is credibly attributed to a frontier model’s capabilities — that would flip the political calculus, making non-enforcement politically costlier than enforcement. Watch both.
What to watch
- September–October 2026: First structured dialogue under Article 93 that fails to produce acceptable commitments — the trigger for formal enforcement.
- Q4 2026: US midterm elections, which could shift the domestic political calculus for Trump’s tariff-centric approach to tech regulation.
- Ongoing: G7 discussions on a “trusted partners” scheme for frontier AI access — the mechanism most likely to either defuse or inflame the US-EU AI access standoff.
The Bottom Line
The EU’s AI enforcers gain formal powers on August 2, but the capacity to use them — and the political courage to use them against American firms at a moment of maximum technological dependency — is what will determine whether the AI Act becomes a global standard or a shelf document. Washington has shown it can revoke frontier AI access with a single directive. Brussels must now decide whether defending its rulebook is worth risking that access again. The first case will answer the question.
Discover more

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

Economics
US Sanctions Iran's Nobitex Crypto Exchange
US Treasury sanctions Nobitex, Iran's largest crypto exchange, for processing billions in stablecoins for the central bank and IRGC, extending secondary sanctions risk to foreign platforms.