Skip to content

The European Commission’s first use of EU AI Act investigatory powers

Under the phased implementation of the EU AI Act (“the AI Act”), the enforcement powers of the European Commission’s AI Office became applicable in respect of general-purpose AI (“GPAI”) model providers on 2 August 2026.  Less than a month later, it exercised its investigatory powers for the first time, marking the beginning of active regulatory oversight of the AI Act.

On 29 August 2026, the AI Office issued its first formal Requests for Information (“RFIs”) to providers of GPAI models under the AI Act.  These RFIs fell into two broad categories.

  • Safety and Security: The first set concerned GPAI model safety, security, independent external model evaluations, and the monitoring of GPAI models once they are available on the market. The focus is on safeguarding GPAI models against physical, human and AI-related risks as well as ensuring model usage is monitored once the AI is publicly available.  While the European Commission has not publicly identified the recipients of these RFIs, Henna Virkkunen, Executive Vice-President of the European Commission for Technological Sovereignty, Security and Democracy has reportedly confirmed that developers of some of the world’s most advanced GPAI models were among those contacted.
  • Transparency and Copyright: The second set of RFIs were issued to more than 30 AI companies that have not yet published detailed summaries of the content used to train their GPAI models and have not participated in informal compliance dialogues with the AI Office. The RFIs require those providers to detail how they are complying with EU copyright rules, and to provide detailed summaries of the training data used for developing their GPAI models,.  Through these RFIs, the European Commission aims to ensure compliance with the AI Act, enhance transparency, and enable copyright holders and other parties with legitimate interests to understand whether their content may have been used in training, and where appropriate to exercise their rights.

What is the AI Office’s enforcement role under the AI Act?

The AI Office and national competent authorities work together to enforce the AI Act.  The AI Office oversees compliance by providers of GPAI models.  It also oversees AI systems built by the same provider (or a group company) as the underlying GPAI model, and AI systems built into very large online platforms (VLOPS) or very large online search engines (VLOSES) designated under the Digital Services Act.  The national competent authorities enforce the rules for other AI systems.

What is an RFI?

In the context of both GPAI models and AI systems, the AI Office can send RFIs to verify providers’ compliance with the AI Act.  RFIs are formal, legally binding requests asking operators to detail their practices, system operations and compliance documentation.  They are a preliminary investigative tool used before formal compliance proceedings.

In respect of AI systems within the AI Office’s exclusive competence under Article 75(1) of the AI Act, RFIs can be issued as simple RFIs by the AI Office or, more formally, by decision.  For simple RFIs, there is no obligation to respond, but in the case of a voluntary reply, fines can be imposed if the provider’s reply is incorrect or misleading.  For RFIs issued by decision, fines can also be imposed if the provider supplies incorrect, incomplete or misleading information.

In regard to GPAI models, Article 91 of the AI Act grants the European Commission with power to issue RFIs to providers of GPAI models requiring them to produce documentation and any additional information necessary to demonstrate compliance with Articles 53 and 55 of the AI Act.  Each RFI must specify its legal basis and purpose, identify the information required, set a response deadline, and warn of potential fines for incorrect, incomplete or misleading information.  Where information gathered and reported is insufficient, the AI Office may escalate its activity by conducting its own GPAI model evaluation under Article 92 of the AI Act, requiring corrective measures and in serious cases, restricting a GPAI model’s availability in the EU.

In regard to AI systems within its exclusive competence under Article 75(1) of the AI Act, the AI office can, during an inspection under Article 75a, conduct interviews of any person subject to the investigation for information relating to its subject matter, as well as conduct inspections of providers’ premises.

What are the sanctions for non-compliance with RFIs?

Organisations should not delay preparations for regulatory engagement.  Existing  procedures, such as those developed for data protection inspections, can provide a useful starting point, although they will require tailoring to the AI Act’s specific requirements.

Organisations must establish clear AI governance structures with defined responsibilities and escalation procedures (discussed previously here).  Moreover, AI systems in use should be mapped, including those embedded in third party software and staff likely to be involved in responding to information requests or evaluations should be trained accordingly.

If the AI Office establishes an intentional or negligent breach of the AI Act, the European Commission may adopt a decision imposing penalties on the provider of the relevant GPAI model or AI system.  Failure to respond to RFIs carries significant risk.  The amount of the penalty will be determined by the nature, gravity, and duration of the infringement.  Under Article 101 of the AI Act, providers of GPAI models face significant administrative fines of up to €15 million or 3% of global annual turnover for ignoring an RFI issued, or providing inaccurate, incomplete or misleading responses, or otherwise obstructing an AI Office evaluation of the GPAI model concerned.  Providers of AI systems may also face administrative fines of up to €7.5 million or 1% of their global turnover, under Article 99(5) of the AI Act, for providing incorrect, incomplete or misleading information to a notified body or national competent authority.

While the AI Office’s initial enforcement activity has, to date, focused on GPAI model providers, scrutiny will likely extend in the future to organisations developing AI systems in their operations.  Any organisation that develops AI systems should therefore assess its compliance obligations and readiness for regulatory engagement.

Complaints channel for downstream providers

Enforcement is not solely driven by the AI Office.  Under Article 89(2) of the AI Act, downstream providers (businesses that integrate a GPAI model into their own systems) have a statutory right to lodge complaints to the AI Office alleging that a provider of a GPAI model has infringed the AI Act (for example, in relation to technical documentation, information-sharing requirements, copyright policies, or systemic risk mitigation obligations under Chapter V of the AI Act).  While such a complaint lodged does not itself determine liability or impose sanctions, a well-supported complaint can serve as the factual basis for the AI Office to open an inquiry and exercise its enforcement powers, including issuing RFIs under Article 91 of the AI Act.  Therefore, this complaints’ channel may become an increasingly important element of the broader enforcement ecosystem.

Key takeaways

The AI Office’s first use of its formal enforcement powers is a significant milestone.  The exercise of its binding information-gathering powers at this early stage of the AI Act’s application demonstrates a willingness to scrutinise providers’ compliance in practice.  Organisations that develop GPAI models and AI systems should expect robust and meaningful oversight and enforcement of the AI Act.

GPAI providers should treat compliance documentation as a live, ongoing concern.  Technical documentation, copyright policies, training data summaries and, for models with systemic risk, incident records, risk assessments and cybersecurity documentation should all be maintained to withstand regulatory scrutiny.  RFI responses should undergo thorough internal review and verification before submission, given the obligation to respond completely and accurately, and potential sanctions for failing to do so.

Further RFIs, GPAI model evaluations and supervisory activity are to be expected, and the AI Office or the applicable market surveillance authority may in some cases publicise enforcement and corrective measures against specific providers.  We shall continue to monitor developments on the enforcement of the AI Act.

Contact us

If you have any questions on the AI Act or anything contained in this article, please feel free to reach out to a member of the Technology and Innovation Group or your usual Matheson contact.

© 2026 Matheson LLP | All Rights Reserved