EU AI Act Enforcement Begins: Security RFIs Land on ~30 Model Providers
The European Commission has formally opened EU AI Act enforcement, with its AI Office dispatching requests for information to a number of general-purpose AI model providers in the United States, Europe, and Asia. Executive Vice-President Henna Virkkunen confirmed the step on August 29, calling the requests the opening move in applying the bloc's flagship AI regulation and saying they cover model security, independent external evaluations, and monitoring of models after deployment.
The first batch reaches roughly 30 AI companies, which face a legal duty to respond whether or not they are headquartered in the EU, as long as their models are made available on the EU market. Virkkunen has not disclosed the recipient list, and the Commission has not explained how it selected the targets.
The enforcement wave that produced these requests went live on August 2, when the AI Office and national market surveillance authorities across all 27 member states began applying the Act's rules for general-purpose AI (GPAI) models. The same date activated Article 50 transparency duties: chatbots must disclose that users are talking to an AI, and synthetic or altered content, including deepfakes, must be labelled across the EU's single market of roughly 450 million people.
From August 2, the AI Office holds a full investigative toolkit over GPAI providers:
- Request technical documentation and information under Article 91
- Commission independent model evaluations under Article 92
- Order corrective or risk-mitigation measures
- Restrict, withdraw, or recall a model from the EU market
- Fine up to €15 million or 3% of worldwide annual turnover, whichever is higher
The requests went out weeks after those powers took effect, and they land in a strained security climate: the Commission's move follows a run of high-profile cybersecurity incidents at leading AI labs. The multi-region spread is deliberate, since the rules cover every company that makes a GPAI model available in the EU no matter where it is based. The GPAI Code of Practice was finalised in July 2025, more than a year before the first requests went out, so the substantive expectations were known well in advance.
EU AI Act Enforcement: What the First RFIs Signal
The substance of the questions matters as much as the timing. The RFIs ask what measures providers have taken on safety, security, and model training, and they extend into independent external evaluations and post-deployment monitoring. That framing reaches past a documentation check and into how models are built, tested, and watched in production.
The requests build on the GPAI Code of Practice, which was finalised in July 2025 after a drafting process that drew nearly 1,000 participants and covers transparency, copyright compliance, and safety. Providers whose models exceed 10^23 floating-point operations in training compute and are offered in the EU carry additional systemic-risk obligations on top of those baseline duties.
Until this month, the AI Office had announced no formal enforcement action, so this batch is the first visible exercise of its powers. The legal posture for providers changed on August 2: GPAI suppliers have carried compliance duties since August 2025, but the office can now compel information and evaluations directly, without first seeking a court order. Ignoring a request exposes a company to the full fine scale.
The Trade-Off: Compliance Becomes an Engineering Cost
The strategic question is whether these requests harden into a de facto certification gate for frontier models. If the AI Office routinely requires independent external evaluations and demonstrated post-deployment monitoring before models can be placed or kept on the EU market, compliance stops being a documentation exercise and becomes a budget line. Labs would fund third-party evaluation runs, security audits, and monitoring infrastructure the way they fund training compute. That shift would move compliance spending from legal teams to security and evaluation teams, with the RFI process as the mechanism that verifies it.
The cost lands unevenly. Large labs can absorb an evaluation and monitoring regime; smaller GPAI providers face a higher fixed cost of selling into the EU, which favours the players that can carry it. Enterprise buyers get the same signal from the demand side: models offered in Europe will increasingly ship with evidence of external scrutiny, giving procurement teams a regulator-backed benchmark for comparing suppliers.
For companies that deploy GPAI models in the EU, the operational consequence is immediate: compliance files must be current. The first RFI round signals that the office will test security practice and evaluation evidence on a live timeline, and answers to future requests will have to come from engineering records rather than a compliance binder. Internal AI governance teams should map which of their products depend on which GPAI models and confirm each provider's status under the Act before the next request round.
The affected providers now need the material the office can demand at short notice: technical documentation, copyright policy, and training-data summaries, with a heavier documentation load for models posing systemic risk.
Enforcement pressure can also arrive from a second level: the AI Office leads on GPAI models at EU level, while national market surveillance authorities act on other parts of the Act in member states, so providers answer to two layers of supervision.
The Open Questions
Two unknowns determine how far enforcement goes. First, the recipient list: whether the office started with the largest frontier labs or a broader cross-section of the roughly 30 companies reveals its sequencing strategy. Second, the standard of proof: how independent evaluations are commissioned, by whom, and what the office does with the results. If poor evaluation outcomes translate into corrective orders, recalls, or market restrictions, the security RFI becomes the template for a pre-market review regime no GPAI provider has faced.
Developers building on GPAI APIs inherit a related risk. Their upstream model choices now carry a regulatory record, and a model that fails an EU evaluation could be restricted or withdrawn mid-deployment, which is a supply-chain factor to price into vendor selection. Procurement teams should ask vendors how their models fare under EU evaluation requirements and what monitoring evidence they can supply.
A boundary is already drawn. The enforcement wave now running covers GPAI models and prohibited practices, while the AI Omnibus postponed the rules for high-risk AI systems to December 2, 2027. That leaves the GPAI track as the place where EU AI Act enforcement establishes its credibility in year one.
| Milestone | Date | Effect |
|---|---|---|
| GPAI obligations apply | August 2025 | Compliance duties for GPAI providers begin |
| Enforcement powers live | August 2, 2026 | AI Office can demand information, evaluate, and fine |
| First RFIs sent | Late August 2026 | ~30 providers asked about security and training |
| High-risk AI rules apply | December 2, 2027 | Postponed by the AI Omnibus |
Why this matters
The RFI batch converts the EU AI Act from a planning exercise into an active regulatory relationship between the AI Office and the world's leading model labs, and the count of formal enforcement actions moves from zero to one. For CTOs and founders, the consequence is concrete: security, evaluation, and monitoring evidence now carry market-access weight in the EU, and engineering budgets, not legal paperwork, will decide how smoothly the first enforcement round runs. The next visible milestone is the office's reading of the responses it receives and any follow-up evaluations it orders on that basis.
Sources
Commission starts enforcing AI Act rules and new transparency ...
Photo by Ayush Design on Unsplash
Related Articles
- European Commission Appoints 60-Expert Scientific Panel for EU AI Act Enforcement
- EU AI Act Enforcement Is Underway: What Enterprises Face From August 2 [Update]
- First EU AI Act enforcement action: Brussels puts frontier labs on notice over security and copyright [Update]
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.