TL;DR: The EU AI Office can now fine GPAI model providers up to 3% of global turnover. More than 180 companies signed the Code of Practice to earn presumptive compliance. Meta refused. xAI signed only partially. If your products run Llama or Grok in EU markets, your vendor's compliance posture is now your problem.
What happened on August 2, 2026
The EU AI Act's enforcement machinery went live. As of that date, the European Commission's AI Office can formally request documentation from general-purpose AI model providers, run technical evaluations, demand corrective measures, restrict market access, and issue fines. The ceiling: 15 million euros or 3% of worldwide annual turnover, whichever is higher. For prohibited practices the ceiling rises to 35 million euros or 7%.
Alongside enforcement powers, Article 50 transparency obligations kicked in: chatbots must identify themselves as AI at the start of interactions, and AI-generated or manipulated content must carry machine-readable provenance marks.
Both sets of rules apply to providers globally -- not just EU-based companies. OpenAI, Anthropic, Google, Meta, and xAI are all within scope.
The Code of Practice and what it does
The GPAI Code of Practice is a voluntary framework finalized by the EU AI Office in July 2025. It covers three areas: transparency (training data summaries, model cards, incident reporting), copyright (documentation of text-and-data mining compliance, opt-out signal handling), and safety/security (catastrophic risk thresholds, cybersecurity measures).
Signing creates a legal shortcut. Under the AI Act, a provider that follows an approved Code of Practice gets a "presumption of conformity" with the matching obligations. Regulators treat you as compliant by default. You don't have to affirmatively prove it on every AI Office inquiry.
Not signing removes that shortcut. You must "demonstrate compliance by other adequate means." In practice that means more documentation, more scrutiny, and no safe harbor if the AI Office decides to investigate.
More than 180 organizations signed before enforcement started. The list includes all the names you'd expect: Anthropic, Google, Microsoft, OpenAI, Amazon, IBM, Mistral AI, and Cohere. One notable name is absent.
Meta is the only tier-1 holdout
Meta declined to sign the Code entirely. Their stated reason: "legal uncertainty" about the code's scope and measures that "go far beyond the scope of the AI Act."
Whatever the legal merits of that argument, the practical consequence is clear. Meta's Llama model family -- the most widely deployed open-weight model in the world -- operates outside the Code's conformity shield. The AI Office can investigate Meta, demand documentation, and impose fines, and Meta has no presumption working in its favor.
Meta has already shown what its regulatory posture toward the EU looks like in practice. The Llama 4 Community License Agreement explicitly excludes "any person or entity resident in the European Union, or whose headquarters is located in the European Union." Llama 4 is not available in the EU. Llama 3.x weights are still accessible, but the trajectory is restriction.
xAI's partial signature creates a different gap
xAI's situation is more nuanced. The company signed the Safety and Security chapter of the Code but declined to sign the Transparency and Copyright chapters. That means Grok has a conformity presumption for safety risk disclosures -- but not for training data transparency or copyright compliance.
For enterprises, this matters if you're using Grok or any xAI-powered product in EU workflows and you've been relying on the Code presumption to cover your copyright documentation requirements. It doesn't. You need to verify how xAI satisfies those obligations separately.
What this means if your stack runs Llama
Many companies don't think of themselves as "using Llama." They use a product -- a chatbot builder, an agent framework, an LLM-as-a-service API -- that runs Llama underneath. If that product is EU-facing and the underlying provider is Meta, you've inherited the compliance gap.
The AI Office's enforcement authority runs against the model provider directly, not the deployer. But if the provider faces a market-access restriction or withdrawal order, your application loses its infrastructure. That's pure vendor risk -- the same category as a cloud provider going down, but with regulatory escalation attached.
The risk is not hypothetical. The AI Office has investigative tools and no backlog yet. The first enforcement cycle is live.
The checklist for teams using non-Code providers
1. Map your AI vendor stack by provider and model. List every AI tool your team uses. Note the underlying model or provider for each. Flag any that run Llama or xAI products in EU-facing workflows.
2. Distinguish EU-facing from non-EU-facing deployments. If your Llama-based tool serves only US users and stores no EU data, the EU AI Act's direct jurisdiction is limited. If you have EU customers, EU employees, or EU data subjects in scope, the Act applies.
3. Ask your vendor how they document GPAI compliance without the Code. The answer should reference specific technical documentation: training data summaries, copyright compliance methodology, incident reporting protocols. Vague answers ("we comply with all applicable laws") are not sufficient and don't protect you in a downstream audit.
4. Add contract language covering model withdrawal. Your vendor agreement should require 30-day notice if: (a) the underlying model is withdrawn from EU markets, (b) the provider faces an AI Office enforcement action, or (c) the model's compliance posture materially changes. Standard SaaS contracts don't include this. Negotiate it now.
5. Identify a fallback model. If you're on Llama for price or performance reasons, know which Code-signed alternative (Mistral, Anthropic Claude, Google Gemini) you could switch to within 30 days. Doing this exercise now is far cheaper than doing it under enforcement pressure.
6. Document your compliance rationale. If the AI Office asks how your Llama-based deployment satisfies GPAI obligations, you need a written answer. This document -- describing your technical measures, transparency practices, and why you assessed the model as compliant -- becomes your "adequate means" showing. Start it now, not when the inquiry arrives.
Why the Code matters more than it looks
The presumption of conformity is easy to dismiss as regulatory paperwork. It isn't. In any investigation, the difference between "we signed the Code and followed it" and "we believe we comply and here's why" is the difference between a presumed-clean audit and a live evidentiary burden.
For enterprises, the Code's value isn't just what it gives the vendor -- it's what it gives you. When your vendor has signed the Code, you can point to that as a due-diligence check when regulators ask how you vetted your AI supply chain. When your vendor has not signed, that check doesn't exist. You have to do more work to fill the gap.
That work is real. It takes time. And it costs more than updating a vendor contract before anyone asks.
What to watch for next
The AI Office has not yet announced formal investigations against Meta or any Llama-based provider. The enforcement regime is days old. But the first inquiries will almost certainly go to the largest, highest-profile non-signatories -- and Meta's public refusal to engage with the Code makes it the clearest target.
For teams that use Llama, the immediate risk is not a fine against you. The risk is operational: a compliance action against Meta that triggers EU market restrictions on Llama would remove your foundation model without warning. The time to build your fallback plan and document your rationale is now, before the AI Office's first investigation closes and sets a precedent on what "adequate other means" actually requires.
