blog
The EU's first AI Act enforcement RFIs are out. The open-source carve-out does not cover the training-data summary they ask for
Published . True as of that date; aging is not a defect.
Henna Virkkunen, the European Commission's executive vice-president, confirmed the first formal enforcement step under the AI Act on 29 August, in a post on LinkedIn: "As a first step in enforcing the AI Act, our AI Office has formally sent requests for information to a number of providers of general-purpose AI models based in different regions of the world."
The step lands 27 days after the GPAI enforcement powers became exercisable on 2 August 2026, and it is an information request, not a finding, a charge or a fine. No model has been restricted, no provider sanctioned. The requests open a supervisory file, and the file has teeth: the Commission's own enforcement-framework page sets the ceiling for breaches of the GPAI obligations at €15 million or 3% of worldwide annual turnover, whichever is higher, and states that a reply that is incorrect, incomplete or misleading, or no reply to a formal request at all, is sanctionable in its own right.
The recipients are not named
Virkkunen said only that the requests went to "a number of providers based in different regions of the world". Thomas Regnier, the Commission's digital spokesperson, put the count at more than 30 AI companies, "including most advanced AI model providers". Secondary accounts published on 31 August name OpenAI, Anthropic and Google among the recipients. The Commission has not named them, and the requests themselves have not been published.
Two sets of requests
Virkkunen described two sets. The first asks how providers secure their models against attack, whether independent external evaluations exist, and how models are monitored once they are available on the market. The second asks for the training-data summary that Article 53(1)(d) of the Act requires every GPAI provider to publish, and it went only to providers that have neither published one nor taken part in the AI Office's informal compliance dialogues. That is a compliance-gap query, not a sweep: the AI Office is asking the providers it thinks are least compliant, and Virkkunen said the publication requirement exists so copyright holders and other parties with legitimate interests can exercise their rights.
The carve-out covers documentation, not the summary
Article 53(2) of the Act exempts a model released under a free and open-source licence with its weights public from two of the four GPAI obligations: the technical documentation (Article 53(1)(a)) and the information sheet for downstream providers (Article 53(1)(b)). The exemption does not reach the copyright compliance policy, and it does not reach the training-data summary. The Commission's own GPAI guidance says so, and adds that the exemption never applies to a model designated as posing systemic risk.
The training-data summary is therefore one of the two obligations an open-weight release cannot shed (the copyright policy is the other), and it is exactly the subject of the second RFI set. Anyone who shipped an open-weight model into the EU on the strength of the carve-out should read the carve-out again: it covers the documentation, not the summary.
An RFI is a request, not a finding
The summary set maps to Article 53(1)(d). The security set has the shape of the Article 55 systemic-risk duties (evaluation, incident reporting, cybersecurity protection), as the Commission's Q&A describes them, but the Commission has not tied the requests to that article, and most of the more than 30 recipients will have no model designated as posing systemic risk. No model has been pulled, no market access restricted. The requests exist to check compliance, and the answers join a permanent supervisory record.
Virkkunen opened her announcement by writing that AI models "gave rise to a number of incidents during the summer". That line is suggestive, not causal: nothing in the announcement ties the requests to a specific incident.
If your company received one of these requests, the file is open and the reply is yours to make: an answer that is incorrect, incomplete or misleading is its own violation, and so is no answer at all. If you run a provider that has not published a training-data summary and has not been asked yet, you fit the description of the second set's recipients exactly, and Virkkunen said the Commission is "ready to take all necessary steps to ensure that companies comply with their obligations under the AI Act."
And if you released an open-weight model into the EU believing the open-source carve-out covered the obligations, the carve-out covers the documentation duties and the downstream information sheet. The training-data summary is not carved out. That is the line the requests are asking about.
Sources
All retrieved on 31 August 2026.
- Henna Virkkunen (European Commission), announcement on LinkedIn, posted 29 August 2026 — linkedin.com
- Thomas Regnier (European Commission digital spokesperson), announcement on LinkedIn, posted 31 August 2026 — linkedin.com
- European Commission, "The enforcement framework of the AI Act", page states last updated 24 August 2026 — digital-strategy.ec.europa.eu
- European Commission, "General-Purpose AI Models in the AI Act – Questions & Answers", page states last updated 9 September 2025 — digital-strategy.ec.europa.eu
- Tokenstead, "The EU has begun enforcing the AI Act: first RFIs to model providers", published 31 August 2026 — tokenstead.ai
- El Ecosistema Startup, "Bruselas pide datos a OpenAI, Anthropic y Google por AI Act", published 31 August 2026 — ecosistemastartup.com