From Statute to Subpoena
For two years, the EU AI Act existed mostly as a compliance exercise: codes of practice, guidance documents, and a slow rollout of obligations. That changed on September 1, 2026, when the European Commission's AI Office sent its first formal requests for information (RFIs) to more than 30 AI providers — the Act's investigative machinery being used for the first time since general-purpose AI (GPAI) obligations became enforceable on August 2, 2026 (Commission enforcement notice).
The RFIs split into two strands. One targets frontier-model safety and security — providers must detail how their most advanced models are evaluated for misuse and monitored once deployed. The other targets copyright and transparency, and reportedly went specifically to providers that had not engaged in the AI Office's informal "structured dialogue" process before formal requests went out (enforcement framework; Allegiance Law analysis). Reported recipients include major frontier labs, though the Commission has not published a full list (tokenstead.ai).
The Legal Trigger
The timing is not coincidental. Article 91 of the AI Act gives the Commission power to request GPAI providers' compliance documentation or "any additional information necessary" to assess compliance, and the AI Office can move straight to a formal RFI once informal dialogue stalls. Non-compliance — failing to reply, replying incompletely, or supplying misleading information — carries fines of up to €15 million or 3% of global annual turnover, whichever is higher (enforcement framework). That the Commission moved within four weeks of GPAI enforceability taking effect suggests this was queued, not improvised.
Steelmanning the Regulator
The case for acting now is real. The Commission's own framing points to a run of incidents over the summer of 2026 involving advanced models behaving unexpectedly during security evaluations and agentic deployments — the kind of containment failures that safety researchers have warned about for years. If frontier models are approaching capability levels where a single unmonitored failure can compromise external systems, a regulator that waits for a catastrophic incident before asking basic questions about evaluation and monitoring practices has arguably already failed at its job. Likewise, the copyright strand isn't arbitrary: Article 53 of the AI Act already requires GPAI providers to publish a summary of training content and maintain a copyright compliance policy, and targeting only the providers who skipped the voluntary compliance dialogue is a reasonably proportionate way to allocate scarce enforcement attention — it rewards good-faith engagement rather than punishing everyone equally.
More than 180 organizations have already signed the Commission's Code of Practice on transparency of AI-generated content (Commission enforcement notice), and the GPAI Code of Practice's three chapters — transparency, copyright, safety and security — were built precisely to give providers a documented, negotiated path to compliance rather than open-ended discretionary enforcement (Code of Practice). Providers who signed up have a paper trail; providers who didn't are, by construction, the ones now getting RFIs.
Where the Proportionality Argument Breaks Down
Still, the structure of this rollout should worry anyone who wants the AI Act to work rather than just look tough. An RFI is not a finding of wrongdoing, but the Commission's decision not to identify targets or publish the substance of the requests creates exactly the kind of opacity that undermines the Act's own transparency rationale — providers face real fine exposure while the public, and competing firms, get none of the specificity needed to judge whether enforcement is even-handed. That asymmetry is compounded by the fact that GPAI obligations only became enforceable a month earlier; providers had a narrow compliance runway before facing formal information demands with €15 million fine exposure attached to the accuracy of their paperwork, not to any demonstrated harm.
There's also a sequencing problem. The safety-and-security strand is reactive to specific incidents, which is defensible. The copyright strand, by contrast, appears to penalize non-participation in a voluntary process — effectively converting the Code of Practice from optional guidance into a de facto mandatory filter, where opting out becomes evidence of suspicion. That inverts the Code's original design as a safe harbor, and it sets a precedent EU regulators should be careful about: voluntary frameworks that quietly become prerequisites for avoiding investigation stop being voluntary.
The Global Contrast
The EU's posture — formal information demands with statutory fine backstops, four weeks into enforceability — is notably more assertive than the largely voluntary, disclosure-based approach favored in the United States. That divergence will shape where frontier labs choose to headquarter safety-testing infrastructure and how much they front-load EU-specific compliance work versus treating Brussels as a jurisdiction to manage reactively. Proportionate regulation should track demonstrated risk, not compliance-process optics — and the Commission's own transparency about why a given provider was targeted, not just that 30-plus were, will determine whether this looks like accountability or like enforcement theater.