The European Union has taken its first concrete enforcement step under the AI Act, sending formal requests for information to several of the companies behind the world's most capable AI systems. Henna Virkkunen, the Commission's executive vice-president for technology sovereignty, confirmed on 29 August that the requests had gone out to a number of providers of general-purpose AI models, with recipients understood to include OpenAI, Anthropic and Google.
The requests are not fines or charges. They are the regulatory equivalent of a knock on the door: the AI Office, the Commission body that now polices the most powerful models, asking each company to show its work. According to the Commission, the questions cover how the firms secure their models, whether they commission independent external evaluations, and how they monitor a model's behaviour once it is out in the world and being used at scale.
What changed on 2 August
The enforcement powers behind these letters became active on 2 August, a year after the AI Act's rules for general-purpose models first entered the statute book. As CNBC reported, the powers apply to any company making a general-purpose model available inside the EU, regardless of where the company is based. That is what pulls American firms squarely into scope.
The teeth are real. The Commission can now demand to evaluate a model before it is released in the region, restrict or suspend its access to the EU market, and levy fines of up to 15 million euros or 3 percent of a provider's worldwide annual turnover, whichever is larger. For a company the size of Google, the percentage figure is the one that matters.
The risks Brussels wants covered
Providers of the most advanced models, the ones the Act designates as carrying systemic risk, face a heavier set of obligations. The Commission has said these firms must show they are managing the possibility of large-scale harm, a list that in the regulation's own language runs from chemical, biological and nuclear incidents to loss of control over the system, cyber misuse, manipulation of users, and threats to fundamental rights. The information requests are how the AI Office starts checking that those obligations are more than paperwork.
None of the named companies has treated the moment as a surprise. OpenAI has spent recent months arguing publicly for clearer safety rules, even urging California to strengthen a state law it had earlier opposed, and Anthropic has been fighting its own regulatory battles, including a court fight with the Pentagon over procurement. The EU letters add a second front, one where the questions come with statutory deadlines and financial consequences.
What comes next depends on the answers. If the Commission judges a response thin or a practice deficient, it can escalate. For now the significance is simpler. After years of drafting and lobbying, the AI Act has stopped being a document and started being a regulator that writes to you. The same pattern is playing out at the state level in the United States, where individual legislatures are writing their own chatbot rules, and the model makers now answer to both.
Sources
- i. www.cnbc.com
- ii. qz.com
- iii. www.helpnetsecurity.com
- iv. www.euronews.com
Commentarii · 0