Opinion · 4 min read

The Tools Are on the Table: Joel Christoph on What August 2 Actually Changes

Drawing on Joel Christoph's Lawfare analysis, this opinion argues August 2 grants the EU AI Office compulsion powers over frontier models — but credibility depends on whether regulators use them.

By Classy AI News · August 2, 2026

The Tools Are on the Table: Joel Christoph on What August 2 Actually Changes

This opinion draws on Joel Christoph's published analysis in Lawfare. Classy AI News did not interview Christoph; views below are reconstructed from his May 2026 essay with factual claims sourced independently.

On August 2, 2026, the European Commission's AI Office gains something most regulators only promise: the power to compel. Documentation requests. Independent evaluations with source-code access. Fines up to 3% of global annual turnover. Christoph writes that these are "among the most far-reaching regulatory powers any government has claimed over frontier AI."

The question is not whether the tools exist. It is whether anyone picks them up.

Government building columns representing regulatory authority

Three powers, one escalation ladder

Christoph's Lawfare analysis maps Article 91 through 93 as a deliberate sequence:

Article 91 — information requests. The AI Office can demand technical documentation, training summaries, and compliance materials. Incomplete responses trigger Article 101 fines.

Article 92 — independent evaluations. When documentation is insufficient, the office can appoint Scientific Panel experts and request API or source-code access. Providers must comply or face penalties.

Article 93 — corrective measures. Noncompliance or systemic risk can trigger restrictions, withdrawal, or recall — preceded by structured dialogue where binding commitments may resolve investigations without formal findings.

Underpinning all three: Article 101 fines reaching 3% of worldwide turnover or €15 million, imposed centrally by the Commission rather than fragmented across 27 national authorities — a structural difference from GDPR enforcement.

The DSA precedent — and its limits

Christoph points to early Digital Services Act proceedings against major platforms as the closest template. Formal investigations began within months of applicability; fines were slower, but the signal arrived quickly.

GPAI providers, he argues, will calibrate compliance investments based on whether Article 91 requests become routine supervision or reserved weapons.

The resourcing gap is real. The AI Office employs more than 125 staff across all functions; a Pour Demain recommendation cited in Lawfare urges scaling GPAI supervisory capacity to at least 160 by 2030. Rules without investigators strain credibility — a tension Christoph states plainly without predicting the outcome.

What August 2 changes psychologically

Until today, the GPAI Code of Practice — signed by Amazon, Anthropic, Google, Mistral, OpenAI, and others — guided voluntary compliance. Meta remains a prominent non-signatory; X signed only the safety chapter.

Commission guidelines state signatories receive increased trust while non-signatories should expect heavier information requests. If the office enforces that asymmetry visibly, the Code becomes a rational choice rather than a courtesy.

July's agent cybersecurity incidents give regulators a factual hook without waiting for a consumer harm headline. Commission officials told Reuters on July 31 that OpenAI and Anthropic briefed them bilaterally before public disclosure — contact continues, formal follow-up not ruled out.

Christoph does not claim those incidents violate specific articles. He doesn't need to. August 2 changes the default posture from engagement to enforcement authority.

The credibility window

Christoph closes with a sentence worth taking seriously: "The tools are on the table. The question is whether anyone picks them up."

Three early choices will define the next year:

  1. Routine Article 91 requests to Code signatories establishing a supervisory baseline — or reactive waiting until scandal forces action
  2. Visible asymmetry between signatories and holdouts like Meta — or uniform light-touch treatment that erodes sign-up incentives
  3. Early structured dialogues producing binding commitments under Article 93(3) — or vague assurances that teach providers the office won't escalate

International audiences matter too. The International Network for Advanced AI Measurement, Evaluation and Science includes the EU, U.S., U.K., Japan, and South Korea. Portable compliance information from credible EU enforcement helps global coordination; paperwork theater helps no one.

Urban street at night representing the moment enforcement begins

A personal read

I do not know whether the AI Office will move with DSA urgency or GDPR patience. Christoph doesn't either — he maps the powers and the staffing math, then stops.

But August 2 is not another guideline publication date. It is the day informal engagement could become compelled disclosure — the day a Commissioner asking nicely becomes a Commissioner asking under penalty.

Frontier labs spent July disclosing evaluation breaches to Brussels before journalists got the story. That courtesy has a shelf life. The enforcement calendar does not.

The tools are on the table. Today's date is the test of whether Europe meant what it wrote.

Sources

Newsletter

Get the dispatch

One field. One email when we publish. Privacy.