Eu Ai Act

EU AI Office opens first compliance checks

Brussels sent RFIs to 30+ model providers and began inspections under the AI Act

Brussels sent RFIs to 30+ model providers and began inspections under the AI Act

Brussels has moved from rule‑making to enforcement. On Sept. 1, 2026 the European Commission’s AI Office sent formal requests for information to more than 30 AI model providers — the first concrete use of the Act’s investigative powers.

The Commission told reporters the letters run on two tracks: one probes safety and cyber‑security for the most advanced models, the other targets copyright and transparency obligations for training data and outputs. Officials confirmed recent exchanges with major model developers while declining to name recipients.

The enforcement moment did not come out of the blue. Key parts of the AI Act became enforceable in stages, and the rules giving the AI Office authority over general‑purpose models are now active. That legal framework explicitly allows the Commission to request documents, conduct evaluations and, if needed, inspect systems on site.

Article 91 of the AI Act gives the Commission power to demand the technical documentation and any additional information necessary to assess compliance. If answers are insufficient, Article 92 lets the AI Office conduct deeper evaluations — including access to models via APIs or technical means. Those legal pathways are the basis for the current information requests.

Brussels is not working alone. The AI Office works alongside national market‑surveillance authorities, which will carry out many sector‑level checks and on‑the‑ground inspections in member states. The Commission’s web pages and guidance set out cooperation rules and single points of contact for cross‑border investigations.

Regulators say inspections already underway this month focus on high‑risk applications in HR, retail banking and healthcare — areas where automated decisions directly affect people’s jobs, credit and care. The initial wave will check for up‑to‑date technical documentation, bias testing, human oversight records and post‑market monitoring.

Model providers face specific deadlines and deliverables. Commission guidance and industry summaries highlight expectations such as red‑teaming reports, systemic‑risk evaluations for general‑purpose AI, and standardised summaries of training data and copyright policies. Those deliverables are explicitly tied to the AI Office’s request powers.

The legal bite is real. For breaches involving general‑purpose models the Commission can impose fines — Article 101 allows penalties up to €15 million or 3% of global annual turnover, whichever is higher. Supplying false or misleading information is also punishable under the Act.

Compliance is not only about model code. Inspections will review organisational processes: risk management systems, incident reporting, contractual flow‑downs to deployers and evidence that providers have implemented state‑of‑the‑art copyright measures and transparency summaries. The files regulators open will test both technical and governance claims.

The AI Office has signalled a willingness to use structured dialogue before escalation, but it can move to formal decisions and on‑site access if concerns persist. National market surveillance teams may carry out investigations on the AI Office’s behalf in their territories. That means vendors and deployers across Europe should expect coordinated requests.

For businesses the immediate consequence is a shortened runway for fixes. August’s entry into application turned obligations into testable requirements, and September’s inspections show regulators are sampling systems and documentation rather than waiting for large‑scale failures. Companies that delayed comprehensive technical dossiers, red‑teaming or copyright summaries now face deadlines and potential corrective orders.

The enforcement push also marks an institutional build‑out. The AI Office and national surveillance teams are staffing up, creating whistleblower channels and preparing templates for evaluations and post‑market monitoring. Observers say the shift from guidance to oversight will be uneven but inevitable — the Act now has teeth, and Brussels is using them selectively to set expectations.