← All articles

July 31, 2026

Enforcement Reaches the Provider

On August 2, 2026 the EU AI Act's supervision and enforcement powers over general-purpose AI providers become applicable. That power inspects the provider and fines after the fact. The enforcement that reaches a single agent action sits in the path the action has to take.

By Jonathan Luethke

This Sunday the EU AI Act's enforcement machinery switches on. From August 2, 2026, the Commission's supervision and enforcement powers over general-purpose AI model providers become applicable, and the penalty provisions attach. The power to request documentation, to conduct model evaluations, to demand mitigations, to order withdrawal from the market, and to impose fines.

That is real enforcement, and it has teeth. It also acts at one altitude. It reaches the provider and the model as a product, on inspection and after the fact. The enforcement that governs a single agent action is at a different altitude, and it sits in front of the action.

What switches on Sunday.

The provisions that become applicable on August 2 are not another disclosure duty. They are the enforcement apparatus itself. National market surveillance authorities have to be designated. The Commission gains the power to request documentation and information from a general-purpose model provider, to run evaluations of the model, to require compliance measures and risk mitigation, and to order market restriction, recall, or withdrawal.

The fines are set in statute. Article 101 reaches fifteen million euros or three percent of worldwide annual turnover for general-purpose model providers. Article 99 reaches thirty-five million euros or seven percent for the prohibited-practice and obligation breaches. These are the numbers that give the earlier deadlines their weight.

What this apparatus does well is hold a provider accountable for a model it placed on the market. It can compel the record. It can grade the system against its obligations. It can punish a provider that shipped a model it could not govern.

The altitude of that power.

The Commission's power operates on the provider, and it operates on the model as a product. It is retrospective. It reads what a system did, on inspection, on complaint, or on a scheduled evaluation, and it acts after the effect has already landed. It is periodic. An evaluation is a moment, a documentation request is a moment, and between two such moments the system runs.

An agent action is not a product placed on the market once. It is an event that happens thousands of times inside a single run, each one composing inputs the evaluation never saw and acting on tool results that did not exist when the model was assessed. The supervisory power cannot stand in front of each of those actions. It was not built to. It grades the provider, not the step.

So the power that arrives Sunday leaves a gap exactly where the action runs. It can find, after the fact, that a system exceeded its bound. It cannot be the thing that held the bound at the instant the action was taken.

Where a single action is governed.

An agent action becomes a durable effect at one moment. A payment leaves. A row is written. Before that moment the action can still be reduced or refused. After it there is only the account of what happened, and the fine that may follow.

A control that governs the action has to sit on the near side of that moment, in the path the action takes to the actuator, and set how much authority the action carries before it lands. That is a runtime governor. It reads how far realized behavior has diverged from the trajectory the system was assured to hold, and it sets the authority of the next step against a declared safety envelope. It can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the effect landed.

The supervisory power and the governor are not competing for the same job. One acts on the provider, after the fact, on inspection. The other acts on the action, before the effect, on every step. A fine reaches the provider after the effect. A bound reaches the action before it lands.

What a documentation request actually asks for.

Among the powers that become applicable Sunday is the power to request documentation and to conduct evaluations. A provider under that request has to show how its system behaved. A model card answers a narrower question. It describes a frozen model and the inputs it was tested against. It does not hold what one action, taken partway through a live run, was authorized to do.

The artifact that answers a documentation request about a specific run is the record the governor seals as it acts. Every action it governed, the authority it set, the envelope it measured against, and the divergence that moved the grant. That record is an output of the governor, produced at the moment of the decision, not a report assembled afterward from logs that were never designed to hold it.

A provider that runs a governor in the path can answer the August 2 power with evidence produced at runtime. A provider that governed with a rule in the prompt and a log beside it has a name and a timestamp, and reconstruction ahead of it.

Two altitudes, one obligation.

The obligation the Act now backs with fines is that a system stays inside its declared purpose and its risk controls. The supervisory power enforces that obligation on the provider, periodically, after the effect. It is the outer loop.

The same obligation is discharged, action by action, only by a control the action passes through, which sets the authority of each step before the step reaches the actuator and narrows the grant when behavior diverges. That is the inner loop, and it is the one that runs at the speed the agent runs. The outer loop can punish a provider for an action that already landed. The inner loop is what keeps the action inside the bound while there is still an action to govern.

The firms that will answer the August 2 power cleanly are the ones that put the bound where the action is, and let the supervisory power read the record the bound produced.

What we are building.

Velma is a runtime governor. It sits in the execution path, before the actuator, and sets how much authority each action carries against a declared safety envelope. It modulates that authority as the run proceeds, narrowing the grant when realized behavior diverges from the assured trajectory, and it enforces the grant in the path, so the system acts only inside what the governor allows and cannot reach the effect by another route. Every decision it governs is sealed to a tamper-evident record as it happens, which is the artifact a supervisory request is about to ask for. The governor is the product. The record is what it emits. Patents held in The Wayfinder Trust.

Next step

Thirty minutes. Architecture, not sales.

A conversation about where in your agent stack the governor has to sit so an action is bounded before it lands, and what the record it produces has to contain to answer a supervisory request without reconstruction.

JonathanLuethke@WayfinderSystemsGroup.com