techpolicy.press web signal

AI Act Adapted to ChatGPT Rather Than Breaking, Uuk Argues

TL;DR

  • European Commission's supervision and enforcement powers over general-purpose AI providers under the AI Act come into force on August 2, 2026.
  • Anthropic, Google, Microsoft, OpenAI and more than twenty others signed the July 10, 2025 Code of Practice; Meta declined and xAI signed only the safety chapter.
  • The AI Office employs more than 125 people and draws on a Scientific Panel of 60 independent experts to inform GPAI oversight.

A tidy narrative has hardened around the EU's AI Act, that ChatGPT's late-2022 arrival caught Brussels flat-footed and exposed a broken law. Risto Uuk, head of European policy and research at the Future of Life Institute, pushes back on that reading in a Tech Policy Press essay, arguing the legislative record shows something closer to the opposite: the framework bent, and kept moving.

Uuk's timeline is the interesting part. The Commission's April 2021 proposal regulated AI according to the risks of its use rather than the technology itself, and, as Uuk and other stakeholders warned in the August 2021 public consultation, it had "no answer to general-purpose AI." The Slovenian Council presidency floated separate treatment for GPAI in November 2021, member states agreed to specific obligations in the Council's late-2022 general approach, Parliament introduced a tiered regime for foundation models in June 2023, and the December 2023 trilogue produced the layered GPAI architecture that made it into the final Act. ChatGPT, in Uuk's phrasing, "did not reveal this problem for the first time. It made it politically impossible to ignore."

The near-term inflection point for anyone shipping foundation models into the EU is a calendar one. GPAI obligations have applied since August 2, 2025, but for a year they sat "without teeth." On August 2, 2026, the Commission's supervision and enforcement powers come into force, and models already on the market before August 2025 have until August 2, 2027 to comply. The Commission's Code of Practice, published July 10, 2025, has been signed by Anthropic, Google, Microsoft, OpenAI and more than twenty others; Meta declined, and xAI signed only the Safety and Security chapter.

The honest caveat is that Uuk is writing from inside the pro-regulation camp, and his own piece concedes the framework's effectiveness "will ultimately depend on implementation, institutional capacity, and political willingness." The AI Office now employs more than 125 people and leans on a Scientific Panel of 60 independent AI experts, but whether that is enough weight to hold a Meta or an xAI to the standard is the question the next twelve months will answer. What the reporting does not spell out is how the Commission plans to handle non-signatories, or how systemic-risk thresholds get drawn in practice. The move worth watching is whether other jurisdictions borrow the tiered GPAI architecture the EU landed on, now that there is a working template.