AI Security

EU AI Act Enforcement Starts: 30+ AI Firms Now Face Formal RFIs

The European Union has moved from writing rules to enforcing them. On September 1, the European Commission confirmed it had sent formal information requests (RFIs) to more than 30 companies operating in the AI sector — the first concrete enforcement step taken under enforcement powers the Commission's AI Office gained on August 2, 2026. Commission spokesman Thomas Regnier told reporters the requests were "the first within the enforcement actions initiated by the Commission," and that they cover two main areas: safety and security, and respect for copyright, according to the AFP report carried by CGTN.

The Commission did not identify the recipients. Henna Virkkunen, the Commission's vice president for tech sovereignty and security, wrote on LinkedIn over the weekend that "our goal is to ensure that AI in Europe is developed, released and used safely and transparently — and we are ready to take all necessary steps to ensure that companies comply with their obligations under the AI Act." As of September 7, 2026, this is a preliminary mapping exercise, not a finding of wrongdoing, but it is the first time the AI Office has put its new tools to work against the industry at large since the August 2 transition.

Why this is a turning point, and why it is not a fine yet

There are two ways to misread this story, and both are dangerous for enterprise compliance teams. The first is to treat the RFIs as the beginning of mass penalties. They are not. An RFI is a data-gathering step that precedes a possible formal investigation. The Commission has said it has not identified the named companies and that the questionnaires concern mostly safety and respect of copyright. No fine has been issued, and none should be reported as having been. The second misreading is the reverse: to treat a preliminary RFI as a shrug. That is also wrong, because under the AI Act an incorrect, incomplete, or misleading reply to a request for information is itself an infraction. For general-purpose AI (GPAI) models, the AI Office can impose fines of up to €15 million or 3 percent of worldwide annual turnover, whichever is higher, for such breaches. A company that answered loosely because it assumed the request was informal would be opening a separate, own-goal enforcement file.

For downstream providers — companies that integrate a top-tier model into their own product but do not build the model — the concrete risk is different but real. The AI Act has an explicit channel for downstream providers to complain to the AI Office about their upstream GPAI supplier's compliance with Articles 53 to 55, covering transparency, copyright, and systemic-risk safety duties. If the Commission learns through its own RFIs, or through that channel, that an upstream model provider cannot document its safeguards, a downstream firm that relied on that provider could face concentrated scrutiny precisely because it is the party with direct EU market contact. The 30-plus RFIs are, in effect, the AI Office learning who stands behind which model at the moment downstream customers are being told to claim exemptions.

What is actually in force, and what is still years away

The single most common compliance error this autumn is treating the high-risk regime as if it were live. It is not. Under the AI Act's simplification package, obligations for standalone high-risk AI systems listed in Annex III apply from December 2, 2027, and obligations for high-risk systems embedded in regulated products apply from August 2, 2028 — both set out in the Commission's own enforcement timeline. Anyone writing that "the AI Act's high-risk rules are now binding" in the context of the current enforcement wave is wrong, and this site will not repeat that error.

What shifted on August 2, 2026, is narrower and specific. The AI Office and national authorities became responsible for supervising and enforcing the AI Act. The AI Office can now send RFIs, run model evaluations and require access to models, request corrective measures including restricting a model's public availability, and issue fines. The transparency duties of Article 50 — chatbots disclosing they are not human, machine-readable marks on synthetic content, deepfake labelling, and emotion-recognition disclosure to affected individuals — also became enforceable on that date. Enforcement of other provisions awaits their own start dates: prohibitions on generating non-consensual intimate imagery and CSAM material take effect on December 2, 2026, and the high-risk obligations roll in on the 2027 and 2028 dates above.

For a US or any non-EU company, the reach is broader than it sounds. The AI Act applies to providers and deployers whose systems are placed on the EU market or whose GPAI models are used within the EU, regardless of where the company is incorporated. A US foundation-model vendor that ships into Europe is in scope for the GPAI obligations, and a US enterprise that deploys that model in an EU-facing product is an in-scope deployer. The Commission confirmed the RFIs went to companies located across the world. There is no "we are not European, so this does not touch us" exemption that survives contact with an EU market footprint.

A transatlantic split arrives in the same week

The timing puts the American contrast into relief. The same cycle in which the EU launched its first formal enforcement action, US officials at the G20 meeting chaired by the United States argued against AI-specific regulation and promoted technology-neutral rules, per Al Jazeera's report on September 2. This is not a footnote; it is the operating assumption your compliance function has to design around. In the EU, the rulebook is old (enacted 2024), enforcement is finally switching on, and the enforcement posture — RFIs, transparency duties, a downstream complaint channel — is explicit and centralized in the AI Office. In the United States at the federal level, there is currently no equivalent federal statute, and the closest levers are procurement standards (the Stop Rogue AI Act proposed on September 3 would task NIST with agent-security standards) and state consumer-protection law. A multinational shipper faces two different regulatory logics running on two different clocks.

What to do now, before the questionnaires reach you

You do not need an RFI in your inbox to start preparing, because by the time one arrives the burden is on you to answer accurately and fast. Four moves are worth making now, all grounded in the Commission's own enforcement framework.

First, map your model supply chain. Document which GPAI models you integrate, from whom, whether that provider has been publicly identified in any RFI, and what supporting evidence you hold about its safeguard claims. If your contract relies on an upstream exemption, the burden of a downstream complaint channel means you want the paper trail ready. Second, re-read your transparency duties as if the August 2 date were yesterday. Chatbots must tell users they are not human; synthetic content you publish needs machine-readable marking; deepfakes need labelling. These are live obligations, not future ones, and they apply to systems deployed before the deadline too. Third, treat any information request your supplier receives as a signal to you. If an upstream provider is under an RFI on safety and copyright, verify independently that your own use carries its own compliance posture rather than inheriting the vendor's. Fourth, build governance that can flex, because the Commission itself has said early enforcement will define the edges of the high-risk definition more than the statutory text alone — one unnamed practitioner told IT Brief that the AI Office's early cases will shape real-world expectations more than the legislation. A compliance model bolted onto fixed deadlines will be obsolete by the time the boundaries are tested.

The arrival of formal RFIs does not mean the EU has started fining anyone. It means the EU has started asking, and an answer that is late or wrong is now its own independent violation with a €15 million / 3 percent ceiling attached to it for GPAI providers. For the enterprises that came closest to ignoring the Act this year, the distinction between "informational request" and "enforcement action" is no longer a semantic one. Every briefing cites its sources — and Brussels' first practical use of its August powers is now a documented fact, with the deadline cascade that follows it set out in the Commission's own timeline. The compliance teams that win this round are the ones that answered the questionnaire they never expected to receive before they received it.

Editorial sources

Every claim in this briefing traces back to the references below.

More from the brief

Browse all →
Guides

88 Hours, 130 Billion Tokens: Inside OpenAI's Navier-Stokes Proof

Guides

$900M ARR and a $48B Bet: What Cognition's Round Says About Agent Demand

Guides

Microsoft Puts Day-Long Agent Work Inside a Windows 365 Cloud PC