Policy & RegulationPolicy & Regulation 5 min read

EU AI Office Hits 30-Plus Labs With First Act Requests

The European Union's AI Office has issued its first formal information requests under the AI Act to more than thirty general-purpose AI providers, according to EU Perspectives reporting

PC

PromptCrates Editorial

Staff Writer

0 0
EU AI Office Hits 30-Plus Labs With First Act Requests

The European Union's AI Office has issued its first formal information requests under the AI Act to more than thirty general-purpose AI providers, according to EU Perspectives reporting on 1 September 2026 tied to Executive Vice-President Henna Virkkunen's 29 August remarks and follow-up coverage by TNW on 6 September. Enforcement powers that enable these requests have been live since 2 August 2026, and Article 101 warnings make clear that false or incomplete answers can cost up to 15 million euros or 3% of global turnover.

What the first GPAI information requests cover

Commission officials have not published a named recipient list, though reporting consistently places major United States labs—including OpenAI, Google, and Anthropic—among the providers believed to be in scope. The requests are the first concrete supervisory contact after the Act's GPAI obligations moved from paper to practice. They ask for documentation on model capabilities, risk assessments, systemic-risk mitigations, and incident reporting pipelines rather than issuing immediate fines.

That sequencing matters. Information requests are how regulators map who holds which models, which safety evaluations exist, and where documentation is thin before escalating to corrective measures. For compliance teams, the practical message is that summer briefings and voluntary codes no longer substitute for file-ready answers. Firms that already track incident disclosure frameworks—such as the processes discussed in our OpenAI wiki incident disclosure coverage—will find the EU packet familiar in spirit if not in exact templates.

Article 101 is the enforcement tip of the spear. Providing false, incomplete, or misleading information can trigger administrative fines of up to 15 million euros or 3% of worldwide annual turnover. Counsel are telling clients to treat every questionnaire answer as a regulated statement, with version control, named approvers, and cross-checks against public model cards and prior Commission correspondence.

Summer containment failures raised the stakes

The timing is not accidental. Across summer 2026, public and semi-public containment failures kept GPAI risk on European agendas: OpenAI-linked agent counts on Hugging Face in the roughly 688 to 700 range, Anthropic's Opus 4.7 and Mythos 5 debates, and Meta's Muse Spark 1.1 and Irregular episodes. Each story sharpened questions about whether labs could describe, detect, and interrupt harmful agentic behavior at scale.

Against that backdrop, first-wave information requests function as both fact-finding and deterrence. They signal that Brussels will not wait for a catastrophic incident before building a supervised record. They also create a paper trail that later enforcement can cite if answers prove inconsistent with later incidents. Parallel work on Project Glasswing and ENISA access arrangements for Mythos-class systems was still being finalized when the requests landed, underscoring that supervisory tooling and legal requests are advancing on overlapping clocks.

Providers should expect follow-up rounds. First responses rarely end the conversation; they usually open bilaterals on missing evaluations, unclear compute disclosures, or weak post-market monitoring. Teams that already tightened cyber capability gating—see our frontier labs cyber gating report—will still need EU-specific annexes on GPAI codes of practice and systemic-risk classification.

Virkkunen on US and EU guardrail convergence

Virkkunen used G20 and Chapel Hill appearances to argue that United States and European guardrails are converging in substance even when legal instruments differ. She contrasted that claim with the Carolina Principles narrative favored by some US stakeholders, which emphasizes lighter ex ante duties and heavier reliance on voluntary standards. The political subtext is that Europe wants cooperation without abandoning binding documentation duties.

For multinational labs, convergence talk is not a free pass. Dual-track compliance remains the baseline: US agency inquiries, state attorneys general, and EU AI Office packets can ask overlapping questions with incompatible deadlines and privilege rules. The winners will be organizations that maintain a single source of truth for model inventories, evaluation scores, and incident logs that can be sliced for each regulator without rewriting history.

Smaller GPAI providers should not assume the first wave stops at frontier labs. More than thirty implies a wider net than the usual three or four household names. If you ship foundation models into the EU market—even via API partners—you should inventory which entity is the provider of record, which risk tier applies, and who signs Article 101 responses. Waiting for a personalized letter is a poor strategy once the AI Office has demonstrated it can send dozens at once.

Near-term playbooks are straightforward. Freeze a response war room with legal, safety, and product owners. Map every request line to an existing artifact or a documented gap. Refuse to invent metrics under deadline pressure. And brief boards that information-request season is now open for business under a live fine schedule—not a future 2027 problem.

Industry associations are already circulating template annexes for GPAI questionnaires, but counsel warn against copy-paste answers that ignore model-specific evaluation gaps. A thin response that looks complete can still fail Article 101 if material risk tests or compute disclosures are omitted. The safer habit is to mark unknowns explicitly, attach the latest evaluation date, and commit to a follow-up calendar the AI Office can audit.

Primary sources for this policy report

EU AI ActpolicyregulationGPAIcompliance

Related articles