All insights
Industry newsSep 02, 2026Source: European Commission

EU begins AI Act enforcement with requests to more than 30 companies

A European compliance team assembles AI system evidence for a regulatory information request

The European Commission confirmed on September 1, 2026 that it has sent requests for information to more than 30 AI companies. A Commission spokesperson described them as the first requests in enforcement action started by the Commission under the AI Act. The questions cover two broad areas: safety and security for advanced and general-purpose AI models, and copyright and transparency for another group of companies.

This is an early enforcement step, not a finding that any named company broke the law. The Commission has not identified the recipients, and it has not confirmed whether OpenAI or Anthropic received a formal request. It did confirm recent exchanges with both companies about cybersecurity risks.

What the Commission confirmed

The primary record is the transcript of the Commission's September 1 midday press briefing. Spokesperson Thomas Regnier said the requests went to more than 30 AI companies and called them the first requests where Commission enforcement action has started. He divided the questions into two groups:

The Commission declined to name recipients because the documents are requests for information and dialogue is continuing. Independent coverage from ANSA and The Star reported the same scope and stressed that an information request is preliminary. It can inform later supervision or investigation, but it is not itself a penalty, infringement decision, or proof of non-compliance.

That distinction matters. A company should not describe itself as under formal investigation solely because it receives questions, and observers should not infer that any company mentioned in the press briefing is a recipient.

Why information requests change compliance work

An information request turns an abstract duty into a concrete evidence exercise. A provider may need to explain how a model was classified, which risks were evaluated, what safeguards were tested, and how incidents or changes were handled. Copyright and transparency questions may require a different evidence set around policies, technical documentation, disclosures, and operational implementation.

Teams should prepare records that connect legal obligations to the system that actually operates:

Evidence questionUseful record
Which model or system is in scope?version, release state, owner, deployment regions, and connected services
Which risk was assessed?threat model, evaluation plan, test results, limitations, and residual risk decision
Which safeguard is active?configuration, policy version, monitoring rule, access control, and change history
What happened after an incident?timeline, affected systems, containment, notification decision, remediation, and verification
How is transparency delivered?user notice, technical documentation, model information, update history, and responsible owner
How is copyright policy implemented?written policy, data and process records, exceptions, review route, and evidence of operation

The exact documents required will depend on the request and the recipient's role under the AI Act. The Commission transcript does not publish a questionnaire, deadline, legal theory, or list of companies. Those details must not be invented.

Practical steps for AI providers and deployers

Organizations can improve readiness without assuming they are a recipient.

  1. Reconcile the AI inventory. Link each model, agent, product feature, tool, dataset, provider, and accountable owner. A product name alone is not enough when several model versions or services support it.
  2. Map obligations to evidence. Record the applicable role and requirement, the control intended to meet it, the evidence source, the owner, and the date the evidence was last checked.
  3. Preserve evaluation context. Keep the model version, tools, access, test environment, prompts, scoring method, failures, and reviewer decision. A benchmark result without its conditions is difficult to defend.
  4. Connect incidents to corrective action. Preserve what was observed, what was uncertain, which safeguard failed or was absent, what changed, and how the correction was independently verified.
  5. Separate policy from implementation. A written safety or copyright policy is only one artifact. Teams should also retain evidence that the policy was applied in development, release, monitoring, and change management.
  6. Control the response process. Assign legal, technical, security, and product owners, use one verified source of facts, document qualifications, and retain the exact response that was submitted.

Maetra's framework coverage helps teams connect requirements to controls and current evidence. The AI compliance evidence checklist offers a practical structure for owners, records, and freshness checks.

What remains unknown

The Commission has not named the more than 30 companies. It has not said which recipients fall into each topic, whether all questions rely on the same legal basis, or whether any response has been judged inadequate. The public record also does not establish that OpenAI or Anthropic received a formal request, even though the Commission confirmed recent contact with both about cybersecurity risks.

Later steps may produce additional facts, but a request for information should not be reported as a completed investigation or enforcement finding. Companies may also have different obligations depending on whether they are providers, downstream providers, deployers, importers, distributors, or another actor.

Maetra analysis

The main operational signal is that AI Act supervision is moving from published rules into evidence collection. The useful response is not a larger policy library. It is a current chain from system inventory to applicable requirement, implemented control, test result, incident record, owner, and verified change.

That chain should be reproducible. If a regulator asks why a safeguard was considered sufficient on a particular date, the organization needs the model version, test conditions, decision basis, and later changes. If the record must be reconstructed from separate tickets and slide decks, compliance evidence is already stale.

Sources

EU AI ActAI enforcementcompliance evidenceEuropean Commission
EU begins AI Act enforcement with requests to more than 30 companies | Maetra Insights