OLKERIAI News
← All AI news
OLKERI · AI NEWS
Policy & RegulationEurope2 September 20262 min read

By Olkeri.space

EU AI Office sends first information requests to model providers

Regulators asked general-purpose model providers to document security, external evaluations and post-market monitoring — the first concrete test of whether the AI Act's obligations can actually be audited.

Read this story in: Français · Deutsch · Español

The EU AI Office sent formal requests for information to a number of general-purpose AI model providers on 29 August, covering model security, independent external evaluations and the monitoring of models once they are on the market. Recipients are reported to include OpenAI, Anthropic and Google. The requests come four weeks after the AI Act's obligations for general-purpose models became enforceable on 2 August, with penalties of up to 3% of global turnover.

Requests for information are unglamorous and easy to underrate. They are also the point at which a regulation stops being a text and becomes a practice, because they force the first answer to the question that matters: can these obligations be checked at all?

The three subjects chosen are pointed. Model security, external evaluation and post-market monitoring are precisely the areas where providers make public claims that no outside party can currently verify. A lab can state that it ran adversarial testing, that independent evaluators had meaningful access, and that it watches for harms after release. Until a regulator asks for the underlying evidence, each of those is a description of intent.

The harder problem sits on the regulator's side. Judging whether an evaluation was genuinely independent, or whether a monitoring programme amounts to more than a support inbox, requires technical judgment that supervisory bodies have historically had to build slowly and expensively. A request for information is only as good as the capacity to read the answer sceptically.

Context matters for reading the pace, too. The conformity assessment deadline for high-risk systems — employment, credit, law enforcement, healthcare — was pushed to December 2027 under the Digital Omnibus, so the enforcement now beginning covers the model layer rather than the applications where concrete harm mostly occurs.

What to watch is whether anything follows these letters. Published findings, or a first penalty, would establish that the obligations bind. Prolonged silence would establish something as well.