> ## Content Index
> Fetch the complete content index at: https://bytevyte.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# EU AI Act Enforcement: 30+ AI Labs Face Brussels' First Information Requests [Update]
- URL: https://bytevyte.com/eu-ai-act-enforcement-30-ai-labs-face-brussels-first-information-requests-update/
- Published: 2026-09-01T14:38:59.000Z
- Updated: 2026-09-01T14:38:59.000Z
- Description: Brussels confirms EU AI Act enforcement RFIs reached 30+ AI labs, opening security and copyright practices of US frontier models to scrutiny.
- Author: Bytevyte Editorial
- Tags: ai-beats

Brussels' first **EU AI Act enforcement** action has reached more than 30 AI companies, Commission spokesperson Thomas Regnier confirmed at the daily press briefing on September 1, with requests spanning security and evaluation practices as well as copyright compliance. That is a wider net than the initial August 29 announcement by executive vice-president Henna Virkkunen suggested when the **AI Office**, as [we previously reported](https://bytevyte.com/eu-ai-act-enforcement-begins-security-rfis-land-on-30-model-providers/), sent its opening requests for information to general-purpose AI providers around the world. Recipient names will stay confidential for now, Regnier said, though he confirmed very recent cybersecurity exchanges with **OpenAI** and **Anthropic**. For now the move is procedural, but it turns the Act's paper obligations into a supervised process with fines attached.

The move activates enforcement powers that became usable on August 2, 2026, when the Commission's authority to issue information requests, demand model access and impose fines entered into application. Brussels waited four weeks before using them. The information demands split along two tracks. One set presses on the security and evaluation side: how the models withstand attacks, whether any outside evaluator had access, and how post-market monitoring operates once a model is live. The other presses on copyright and the practices behind training-data collection.

The practical effect is that the AI Office has opened a formal supervisory file on the labs behind the models most developers reach through an API, using an instrument that carries legal teeth. This is the **EU AI Act enforcement** regime shifting from rulebook to routine: replies that are incorrect, incomplete or misleading can draw fines of up to EUR 15 million or 3% of global annual turnover, whichever is higher.

## What the Requests Cover

On the security side, providers must explain how their models fend off attacks, whether any third-party testing has been performed, and what procedures track a model's behavior after release. The copyright track is anchored in Article 53(1)(c), which obliges general-purpose AI providers to maintain a policy for complying with Union copyright law, including identifying and respecting rights reserved by rightsholders. That obligation has applied since August 2, 2025; what changed a year later is that non-compliance can now be pursued with fines and corrective orders.

In practice the copyright track gives the Act's copyright chapter its first supervised teeth. The AI Office becomes the arbiter of whether a provider has done enough to identify and respect reserved rights, a judgment call with no checklist in the Act itself. Timing matters here too: the core duties in Articles 53 and 55 have applied since August 2025 regardless of whether a provider signs the voluntary GPAI Code of Practice, so the RFI round is not aimed at punishing non-signatories. What arrived on August 2, 2026 is the enforcement layer, and signatories that published contact details for the AI Office and downstream providers now sit under the same supervisory machinery as everyone else.

The two tracks also map onto the Act's division of labour. General-purpose AI models fall under the AI Office in Brussels, while other AI systems are supervised by national authorities in member states. For now, only the first pipeline has moved, which is why the targets are the labs rather than the thousands of deployers downstream.

## Why the First Targets Are US Labs

Press coverage of the August 29 announcement identified OpenAI, Anthropic and Google among the labs approached, and the security context explains the emphasis. The action follows a series of hacking incidents tied to Anthropic, OpenAI and Meta models in recent months, and Regnier confirmed that Brussels has held very recent exchanges with OpenAI and Anthropic specifically on those risks. He declined to say whether either company is among the formal RFI recipients, leaving the two most prominent US frontier labs in a state of confirmed contact but unconfirmed status.

That ambiguity is worth sitting with. The **EU AI Act enforcement** system applies to any provider selling into the European market regardless of headquarters, which is why US labs sit at the centre of a Brussels-led process. The AI Office is the body that frontier labs must satisfy if they want to keep selling into the EU. Any lab that wants to keep earning from EU customers has to reveal how it handles security, evaluation and copyright to a regulator outside its home market, and it must do so before Brussels has made any finding against it.

What Brussels has not done is equally instructive. There is no finding that any model is unsafe, no demand to pull a product, and no timetable for what happens after replies arrive. The Commission described the requests as procedural and stressed that dialogue with all companies continues. The RFI round is best read as the opening of a conversation with a deadline attached; it is not the first strike in a market ban.

Regnier's refusal to confirm whether OpenAI and Anthropic are inside the cohort leaves two readings open: either those exchanges are part of the ordinary supervisory dialogue, or the two labs are formal recipients and the Commission is holding back the list to avoid pre-judging the process. Both readings converge on the same point, that the security posture of the two largest US labs is now formally on record in Brussels.

## What EU AI Act Enforcement Means for Enterprises

The more immediate question is what this means for enterprises building on these models. The requests go to providers, not to their customers, but exposure does not stop at the API boundary. Every company whose product depends on a frontier model inherits the compliance risk: if a provider's replies are found incorrect, incomplete or misleading, the fine falls on the provider, yet the downstream customer carries the operational risk of a corrective order or a restricted model. In serious cases the Commission can require corrective measures or limit a model's public availability in the EU, and that is the scenario enterprise architects now have to plan around.

There is also a due-diligence gap. Brussels will not publish the recipient list or the substance of the exchanges, so a European enterprise cannot verify whether its model supplier has responded, what it disclosed, or whether a supervisory file is open against it. Procurement teams are left with two options: demand AI Act compliance evidence from vendors during evaluation, or carry an exposure they cannot see. For companies already subject to deployer obligations under the Act, that choice stops being theoretical.

The enforcement sequence itself is designed to escalate. Ignoring a request triggers follow-up demands and then penalties, and the fine ceiling of EUR 15 million or 3% of global annual turnover applies to incorrect replies as much as to silence. Because the turnover figure is computed worldwide, a fine would scale with a lab's global revenue rather than its EU sales alone, which is the detail that turns an information request into a board-level matter.

For independent software vendors, the exposure is indirect but concrete. A corrective order against a model they rely on would break their products, and Brussels has not specified how quickly such an order could take effect or what transition window would follow. The RFI round therefore changes the risk register of any company with a production dependency on a frontier API, touching procurement, product planning and legal review at once.

## The Verdict

The opening salvo is deliberately narrow. Nothing announced blocks any model from the European market, and the viral framing that models will soon be inaccessible in the EU is a prediction without a policy decision behind it. But the supervisory file is open, the instrument carries fines, and recipient identities will surface eventually through the dialogue itself. Whether Brussels moves from letters to corrective orders will depend on the quality of what the labs disclose, a judgment that remains untested. For enterprises, the practical consequence is that EU AI Act enforcement has moved from a 2027 planning item to a vendor-management question for today.

## Why this matters

The AI Office's first supervisory files are the test of how quickly Brussels moves from information requests to corrective measures, and of whether the EU's rules become the global standard for foundation-model oversight. The responses from OpenAI, Anthropic and the other recipients will set that precedent, and every enterprise building on their APIs inherits an exposure it cannot fully audit.

Photo by [Carl Gruner](https://unsplash.com/@squads%5Fcap?utm%5Fsource=bytevyte&utm%5Fmedium=referral) on [Unsplash](https://unsplash.com/?utm%5Fsource=bytevyte&utm%5Fmedium=referral)

## Related Articles

- [First EU AI Act enforcement action: Brussels puts frontier labs on notice over security and copyright \[Update\]](https://bytevyte.com/first-eu-ai-act-enforcement-action-brussels-puts-frontier-labs-on-notice-over-security-and-copyright-update/)
- [EU AI Act Enforcement Begins: Security RFIs Land on \~30 Model Providers](https://bytevyte.com/eu-ai-act-enforcement-begins-security-rfis-land-on-30-model-providers/)
- [EU AI Gigafactories Tender: A €30 Billion Compute Push Meets AI Act Enforcement](https://bytevyte.com/eu-ai-gigafactories-tender-a-eu30-billion-compute-push-meets-ai-act-enforcement/)

✔Human Verified

---

*Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.*