Binding law · GPAI enforcement
Regulation (EU) 2026/1755 turns GPAI supervision into a concrete procedural framework.
The Commission now has detailed rules for evaluating general-purpose AI models and for proceedings that can lead to fines under Article 101 of the EU AI Act.
Entered into force: 10 August 2026 · Legally reviewed: 26 September 2026.
What changed
The AI Act already gave the Commission GPAI enforcement powers. Regulation 2026/1755 specifies how they can be used.
Commission Implementing Regulation (EU) 2026/1755 was adopted on 20 July 2026, published on 21 July and entered into force on 10 August 2026. It implements Articles 92(6) and 101(6) of the AI Act.
Model access can be deep
For a Commission evaluation under Article 92, requested access can include APIs, internal access, source code, model weights, hosting infrastructure and access to inspect or modify system state where appropriate to the evaluation objective.
Evaluation conditions are specified
A Commission decision requesting access must set the technical means, tools, components, conditions and deadline. Minimum technical requirements can include performance, latency and throughput.
Logging may need to be disabled
Where necessary to protect integrity and confidentiality of an evaluation, the Commission may require a provider to disable logging that could track or record the Commission's access.
Independent experts can be appointed
The Regulation sets independence criteria and procedures for experts appointed to conduct model evaluations on the Commission's behalf.
Article 101 proceedings
The Regulation also adds procedural safeguards around GPAI fines.
It governs the opening of proceedings, preliminary findings, the provider's right to be heard, access to the file, confidentiality and business-secret handling, and limitation periods. The Commission can also use investigative powers before formal proceedings and may order interim measures in urgent cases where serious damage or public-interest risks are involved.
Operational implication
GPAI governance should assume that technical evidence may need to withstand direct regulator scrutiny.
- Maintain current technical documentation and model-version records.
- Know where evaluation access would be technically provided and who owns that process.
- Preserve evidence around systemic-risk evaluation, testing, incident management and cybersecurity where applicable.
- Define escalation procedures for Commission requests, preliminary findings and confidentiality claims.
- Do not treat the GPAI Code of Practice as a substitute for the binding Regulation or the AI Act.