The AI Office Uses Its New Power for the First Time
The European Commission's AI Office sent formal requests for information to more than 30 general-purpose AI model providers on September 1, 2026, the first time it has used this specific power since it took effect. The requests were issued under Article 91 of the AI Act, which lets the AI Office demand detailed answers from any provider whose model is designated general-purpose.
This is not a routine compliance checklist. It is the Commission's first live test of an enforcement tool that had, until this request, existed only on paper.
Two Strands: Safety Claims and Copyright Transparency
The requests split into two separate strands. The first concerns safety and security, specifically how the most advanced models defend against attacks, whether independent experts have evaluated them, and how providers monitor systems once they are deployed. The second strand concerns copyright and transparency, asking providers to detail what their training data actually contains.
Splitting the request this way lets the AI Office pursue two different theories of risk at once: that a frontier model's safety claims might not survive scrutiny, and that a provider's transparency disclosures about training data might not match what it actually used.
What a Wrong Answer Costs
The stakes attached to these requests are real. Under Article 101 of the AI Act, a provider that submits an incomplete, incorrect, or misleading response faces a fine of up to EUR 15 million or 3% of its global annual turnover, whichever is higher. For a frontier lab with multi-billion-dollar revenue, the percentage-of-turnover option could dwarf the flat cap.
| Date | Milestone |
|---|---|
| August 2, 2026 | GPAI supervision and enforcement powers under the AI Act take effect |
| September 1, 2026 | AI Office sends first-ever Article 91 RFIs to 30+ GPAI providers |
| Any future date | Incomplete, incorrect or misleading answers risk a fine up to EUR 15 million or 3% of global turnover |
Less than a month passed between the power taking effect and its first use, a pace that suggests the AI Office intends to establish enforcement credibility early rather than waiting to build a longer supervisory record first.
Which Vendors Are Reportedly on the List
The Commission has not published an official roster of the more than 30 providers that received requests. Legal and trade press reporting names OpenAI, Anthropic, and Google among the recipients, consistent with the AI Office's focus on providers whose models carry systemic risk under the Act's classification.
The absence of an official public list is itself a detail worth noting for any business relying on a GPAI vendor: whether your own provider received a request, and what it disclosed in response, may not become public information even after the fact.
What This Means for a Company Built on Someone Else's Model
Until this request, a business embedding a general-purpose AI model into its own product could treat its vendor's AI Act compliance as a settled, background fact: the rules exist, presumably the vendor follows them. That assumption no longer holds. A vendor's compliance posture is now an active, ongoing investigation subject, not a box ticked once and forgotten.
The practical move for any EU or UK company with a GPAI dependency is to ask the vendor directly, now, whether it received an Article 91 request, and if so, what it disclosed about how it defends and monitors the very model the business depends on. A restriction or a public finding against that vendor later would not be a surprise a procurement team should have to absorb cold.
Read next: EU Regulators Can Now Fine AI Firms 7% of Revenue | Brussels Can Now Pull the Model You Build On



