The European Commission has moved to enforce the EU AI Act for the first time: on August 29, 2026, the AI Office, led by European Commissioner Henna Virkkunen, sent information requests (RFIs) to general-purpose AI (GPAI) model providers — according to reports citing a Euractiv exclusive, these are OpenAI, Anthropic, and Google. The regulator is interested in model protection against attacks, the presence of independent external evaluation, and model monitoring after market release. Responses are mandatory: ignoring them or providing inaccurate data carries multi-million euro fines and the formation of a permanent supervisory file. Meanwhile, models continue to operate, and no bans or access restrictions have been announced — this is the start of formal supervision, not the shutdown of services.

image
image

What happened

On August 29, 2026, the European Commission's AI Office sent information requests (RFIs) to general-purpose model providers. According to reports citing a Euractiv exclusive, the first recipients were OpenAI, Anthropic, and Google. The requests cover three topics: model protection against attacks, the presence of independent external evaluation, and model monitoring after market release. Separate RFIs were sent to providers who have not published detailed summaries of training data content — this information is needed by rights holders to protect copyright. Refusing to respond, or providing an incomplete or misleading response, is itself punishable under Article 101 of the AI Act — up to €15 million or 3% of global annual turnover. All responses received become part of a permanent supervisory file, based on which the regulator can subsequently make demands or restrict a model's access to the EU market.

Context

The obligations of GPAI model providers became legally enforceable on August 2, 2026 — meaning Brussels applied the new powers approximately four weeks after they came into force. This contrasts with the US, where a similar model evaluation system remains unpublished and relies on voluntary cooperation from companies. Non-European providers, meanwhile, are required to have an official representative in the EU. The procedure itself shows that supervision is built primarily on documentation: the regulator collects written explanations rather than conducting its own technical tests of models. The file remains closed, so the public and research community may not see the content of the responses.

Why this matters for the industry

For the industry, RFIs are not a polite request but a legally binding tool: based on the file, the AI Office can later demand corrective measures up to restricting a model's access to the EU market. The topics of the requests effectively set the map of a provider's eval process maturity: resilience to attacks, independent external evaluation, and post-market monitoring are urgently rising in the priority list — according to reports, OpenAI, Anthropic, and Google teams are already gathering materials for responses. Meanwhile, external evaluation without a public methodology and protocol is poorly verifiable for reproducibility, so the formatting standard will likely be shaped by the tools market: evals, independent audits, data provenance, continuous monitoring. No immediate changes to APIs, limits, or new requirements for those embedding models in production have been announced, but the tone of European procurement will change: questions about model protection, independent evaluation, and monitoring will appear in RFPs, and a supplier without ready answers to them will lose to a competitor who has them.

Why this matters for users

Contrary to the viral thesis that "models will soon become unavailable in the EU," nothing of the sort has been announced — this is a forecast, not Commission policy. The requests are addressed to provider companies, not individuals: a model run locally on your own hardware remains outside the jurisdiction of the AI Act, although data provenance is already lost at the first fork of an open model. For developers embedding models in products, there are also no immediate changes: no API changes, limits, or new technical requirements have appeared. The actual change concerns the three largest providers, who are required to form responses for the regulator under threat of fine — users of these services continue to operate as before.

What is still unknown / limitations

Neither deadlines for responses, nor criteria by which the AI Office will assess their adequacy, nor a definition of acceptable independent external evaluation are available in accessible sources: RFIs request information, not present technical requirements, and neither methodology nor metrics have been published yet. The required level of detail for training data summaries is also unknown — a summary for rights holders is neither a dataset nor a datasheet. The list of companies is based on reports citing a Euractiv exclusive, not an official Commission list. Scenarios for the coming months and years — precedent responses, corrective requirements, industry evaluation templates — are interpretations, not announced plans. Finally, the file remains closed, so external observers may not learn what exactly companies answered the regulator.

Sources

Author

Look at AI, editorial team