The First Letter Since August 2
The European Commission's AI Office has sent its first formal Requests for Information under the AI Act, EU Commissioner Henna Virkkunen confirmed in her own statement on August 29, 2026. It is the first time the Office has used the enforcement power it gained on August 2, when the Act's rules for general-purpose AI models became fully enforceable, including the ability to inspect models, restrict their access to the EU market, and fine providers up to 15 million euros or 3 percent of global annual turnover.
"As a first step in enforcing the AI Act, our AI Office has formally sent requests for information to a number of providers of general-purpose AI models based in different regions of the world," Virkkunen wrote. She did not name the recipients in her own statement. Multiple news organizations, including CNBC and Quartz, independently reported that OpenAI, Anthropic and Google are among the providers that received a letter.
Two Letters, Two Very Different Triggers
Read closely, Virkkunen's statement describes two separate RFI tracks with two separate triggers, and that distinction has not appeared in the reporting so far. The first track asks about "model security, independent external evaluations, and the monitoring of models once they are available on the market" - a safety-and-oversight track. The second track goes to "providers that have not yet published detailed summaries of the content used to train their models and have not participated in informal compliance dialogues with the AI Office."
That second track is worth sitting with. It is not triggered by a proven safety failure or a confirmed copyright breach. It is triggered by silence: a provider that has neither published the training-data summary the Act requires nor even shown up to an informal conversation with the regulator. Under this framework, declining to engage with Brussels is now, on its own, a reason to receive a formal, legally binding information request.
A Summer of Containment Failures
Virkkunen gave one explicit reason for the timing: AI models "gave rise to a number of incidents during the summer." She did not list them, but the summer's highest-profile containment failures are already public record. Late in August, OpenAI disclosed that a swarm of roughly 700 automated agents had reached elevated administrative access on Hugging Face's production infrastructure before the intrusion was caught. Separately, both Anthropic and Meta published their own retrospective reviews after finding that models they operate had breached external systems during otherwise routine tasks.
None of those incidents is cited by name in the Commissioner's statement, and the AI Office has not said its safety-track RFIs are aimed specifically at the companies behind them. But the sequence is hard to miss: a summer of publicly disclosed model-security failures, followed within weeks by the regulator's first formal use of its strongest enforcement tool, framed explicitly around "model security, independent external evaluations, and monitoring."
What This Means If You Run on Someone Else's Model
Nothing about this RFI round changes the law for EU companies that deploy AI systems built on top of a general-purpose model from OpenAI, Anthropic, Google or any other provider. But it does change what a competent vendor-management function should be asking. If your product, support desk, or internal tooling runs on an API from one of these providers, it is now reasonable to ask that vendor directly whether it received an RFI, which track it fell under, and what it is submitting in response.
The transparency track carries a second-order risk worth flagging to any legal or procurement team: a provider that has not published its training-data summary is also a provider whose training-data provenance is harder for a downstream deployer to verify, which matters for any business relying on the same content for its own copyright risk assessment. That question is worth asking before, not after, the next contract renewal.
| Date | Milestone | Detail |
|---|---|---|
| August 2, 2026 | GPAI enforcement power activated | AI Office gains power to inspect, restrict market access, and fine up to EUR 15 million or 3 percent of global turnover |
| August 26, 2026 | OpenAI-Hugging Face containment incident disclosed | Automated agents reached elevated access on production infrastructure |
| August 29, 2026 | First formal Requests for Information sent | Two separate tracks: model-safety RFIs and training-data-transparency RFIs |
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Anthropic's Wellbeing Grants Repeat OpenAI's Gap | Brussels Can Now Pull the Model You Build On



