Artificially Confident

Artificially Confident

Practical AI, properly examined

European Commission Sends Its First AI Act Enforcement Requests to More Than 30 Companies

Written by

in

Abstract network of AI systems connected to layered evidence files passing through a transparent regulatory review panel.

Evidence note. Last checked 2 September 2026 at 01:22 BST. The immediate effect may be limited because these are information-gathering requests, not findings that any company has breached the law. The operational lesson is material: AI Act enforcement has moved from published obligations to evidence production across safety, security, copyright and transparency.

The European Commission has sent requests for information to more than 30 artificial-intelligence companies in what it described on 1 September as its first enforcement actions under the EU AI Act.

At the Commission’s daily press briefing, spokesperson Thomas Regnier said the requests cover two broad areas. One concerns safety and security, including general-purpose and the most advanced AI models. The other concerns copyright and transparency. The Commission is not naming the recipients at this stage because the inquiries are simple requests for information and its dialogue with companies continues.

ANSA independently reported the number, the two enforcement tracks and the Commission’s refusal to identify recipients. The briefing also confirmed recent exchanges with OpenAI and Anthropic about cybersecurity risks, but it did not establish that either company received one of these information requests. That distinction matters: contact with a regulator is not evidence of a violation, and an inquiry is not a penalty decision.

The first enforcement step is an evidence request

The Commission announced in July that its AI Office and national authorities would begin enforcing relevant AI Act rules from 2 August 2026. The new requests show what that transition looks like in practice. Enforcement begins with questions: what a provider built, how it assessed risk, which controls it operates and what evidence supports its claims.

The Commission’s AI Act enforcement framework distinguishes simple information requests from requests issued through a formal Commission decision. A simple request can still carry consequences if a response is incorrect or misleading. A request made by decision can also attract penalties if a provider fails to reply or supplies an incomplete answer.

That does not mean every recipient is suspected of serious misconduct. A regulator may use information requests to understand a market, verify compliance, compare provider practices or decide whether further investigation is justified. The important change is that public commitments and internal policies must now survive an external request for records.

Safety and copyright require different evidence

The two inquiry tracks are related but operationally distinct. For safety and security, a provider may need to explain capability evaluations, systemic-risk assessments, adversarial testing, cybersecurity controls, incident handling and decisions about release or restricted access. For the most capable general-purpose models, the evidence should connect identified risks to specific mitigations and show how those controls are monitored after deployment.

Copyright and transparency raise a different set of questions. A provider may need to show how it prepared the required training-content summary, how it implements its copyright policy, what information it gives downstream organisations and how generated or manipulated content is marked or disclosed where the law requires it.

A single “AI compliance” document will struggle to answer both tracks. Evidence has to follow the actual obligation, system and decision. Artificially Confident’s earlier analysis argued that the AI Act is becoming an operational-readiness test. These inquiries sharpen that point: readiness now includes the ability to assemble an accurate, scoped and internally consistent response under regulatory scrutiny.

The operational and governance consequence

Providers should treat a regulatory information request as a governed production process, not an improvised legal exercise. The response needs an accountable owner, a preserved copy of the request, a clear interpretation of scope and a record of which source supports every material statement.

A defensible response pack should normally connect five layers of evidence:

  • System identity: the model, version, service, deployment state, intended purpose and legal role of the organisation.
  • Risk evidence: evaluations, red-team results, known limitations, systemic-risk analysis and the assumptions under which testing was performed.
  • Operating controls: access restrictions, monitoring, incident response, security architecture, content transparency and copyright procedures.
  • Decision history: who approved release, which evidence they reviewed, what remained uncertain and which events would trigger a pause or reassessment.
  • Current verification: evidence that the documented controls still operate for the version and service being examined.

The last layer is easy to overlook. A policy approved months ago does not establish that a current classifier, watermark, access gate or incident route works today. Compliance evidence has to be versioned, tested and connected to the live operating state.

Downstream organisations are not the direct focus of the Commission’s statement, but they should expect the evidence demand to travel through the supply chain. A model provider responding to questions may ask customers or integration partners for deployment context, incident records or information about how disclosures and restrictions are implemented. Buyers therefore need their own system inventories, supplier records and change histories.

Accuracy matters more than speed

A rushed response can create a second problem. Marketing language, technical documentation, legal analysis and operational records may describe the same system differently. Before submitting anything, the response team should reconcile those accounts and label what is established, what is an inference and what remains unknown.

This is also why AI transparency must be an operating workflow. A public disclosure is only one output. The underlying process must preserve provenance, assign responsibility and make changes visible. The same discipline that supports users and auditors also makes a regulatory response more reliable.

What to watch and do next

The Commission has not disclosed the recipients, the exact questions, response deadlines or whether any inquiry will progress to a formal investigation. Those are unresolved facts, not blanks to fill with speculation. The next useful evidence will be any detailed Commission notice, company disclosure or subsequent request for model access, corrective measures or enforcement decision.

AI providers should meanwhile test whether they can answer a regulator’s questions without reconstructing the system from scattered documents and inboxes. Assign a response owner, map each obligation to current evidence, preserve the decision trail and rehearse how legal, product, security and compliance teams would resolve conflicting records.

The first AI Act information requests do not prove widespread non-compliance. They do establish a new operating reality. For companies in scope, responsible AI is no longer only a set of promises made before enforcement. It is a body of evidence that must be accurate, current and ready to withstand questions.

How we work: articles are source-led, AI-assisted and editorially reviewed. Read our editorial method.

Reader response

Questions, corrections or a story lead?

Send us a message with enough context to make it useful. Your note will reach the Artificially Confident editorial inbox.