EU AI Act: First Enforcement Letters Hit Frontier Labs
The Short Answer
What: The EU AI Office issued its first formal AI Act requests for information (RFIs) to frontier general-purpose AI model providers.
When: Confirmed publicly in late August 2026 — roughly four weeks after GPAI obligations became enforceable on August 2, 2026.
Two tracks: (1) security, evaluation and monitoring practices; (2) training-content summary compliance.
Exposure: up to €15 million or 3% of global turnover for GPAI provider breaches, including misleading responses.
Not an investigation. Virkkunen confirmed only that some providers of “the most advanced” models received requests.
Last verified: August 31, 2026.
What an RFI Actually Is
Under the AI Act’s enforcement framework, the AI Office — sitting inside the European Commission’s DG CNECT — holds exclusive supervisory power over general-purpose AI models. Its first-line tool is the request for information: a formal written demand that a provider document how it meets a specific obligation.
RFIs sit below formal proceedings. Nobody has been charged. But under the DSA and DMA, which use the same procedural architecture, RFIs are the near-universal opening move before formal proceedings. Treating one as routine correspondence is the mistake.
The trap is Article 101’s information-integrity provision. Supplying incorrect, incomplete or misleading information in response to a request is independently finable at the same 3%-of-turnover ceiling as a substantive breach. A lab that answers sloppily can be penalised even if its underlying practices were compliant.
The Two Tracks, Decoded
Track 1 — Security, evaluation and monitoring
This maps to the systemic-risk obligations that attach to models above the compute threshold. Providers must perform model evaluation including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and maintain adequate cybersecurity protection for the model and its physical infrastructure.
The likely target of questioning is the gap between published safety frameworks and operational evidence. Every major lab has a public frontier-safety policy. Far fewer can produce dated, auditable records showing the policy was executed for a specific model release.
Track 2 — Training-content summaries
Every GPAI provider placing a model on the EU market must publish a “sufficiently detailed summary” of the content used for training, using the AI Office’s template. This is the obligation with the widest observed compliance variance.
OpenAI has published training-data summaries and describes a provenance stack including Content Credentials, C2PA metadata and SynthID watermarking. Anthropic committed to watermarking text, saying it will apply globally at launch because it lacks a durable way to geofence the feature, with a watermark-detection API promised. Meta signed the EU Code of Practice on Transparency of AI-Generated Content. Google and Meta both stated in July 2026 that they would adopt transparency and watermarking tooling.
Publishing a summary is the easy half. Defending its sufficiency against a regulator with subpoena-adjacent powers is the hard half — particularly for models trained on licensed corpora the provider cannot describe without breaching the licence.
Who Is Actually Exposed
The counter-intuitive read: the frontier labs are the least endangered parties here.
OpenAI, Anthropic, Google and Meta all run EU policy teams and can absorb documentation, copyright-policy and training-summary obligations as a line item. A €15M ceiling is a rounding error against Anthropic’s reported ~$965B valuation.
The genuinely exposed cohort is the middle tier: Series A and B companies that fine-tune or distribute models into the EU, have GPAI-provider obligations they may not know they’ve triggered, and have no compliance function. They will not receive an RFI in this wave. They will receive one after a competitor or NGO complains.
What Builders Should Do This Quarter
- Determine whether you are a “provider.” Fine-tuning a model and placing it on the EU market under your own name can make you a GPAI provider with your own obligations, not merely a deployer.
- Write the training-content summary now, using the AI Office template, even if you believe you’re out of scope. It is the cheapest artefact to produce and the most conspicuous to lack.
- Make your safety evaluations dated and auditable. “We test for jailbreaks” is not evidence. A signed evaluation report per model version is.
- Assign an RFI owner. The information-integrity fine punishes disorganised answers, and standard response windows are measured in weeks.
Our Aug 2 deadline compliance guide covers the underlying obligation set, and the watermarking requirement is treated separately.