The European Commission on Sept. 1, 2026, confirmed it had sent the first Artificial Intelligence Act requests for information to more than 30 AI companies, Commission spokesperson Thomas Regnier said at the Midday press briefing in Brussels. The confirmation matters because the AI Office's enforcement powers for general-purpose AI providers, including transparency, copyright, and systemic-risk safety for advanced models, became applicable on Aug. 2, so these RFIs are the first public sign that Brussels is using those tools in practice rather than only preparing the framework.
Unlike a fine, an infringement decision, or a model withdrawal, Regnier described the steps as simple RFIs and the first enforcement steps, with dialogue continuing. The Commission refused to name recipients. Separately, Regnier confirmed very recent exchanges with OpenAI and Anthropic that included cybersecurity risks, but he would not say whether either company received an RFI. Those cyber contacts are not confirmation that either firm is on the RFI list. High-risk Annex III obligations remain deferred until Dec. 2, 2027 under the Commission's enforcement timeline, so this is not the full AI Act going live at once.
Regnier said the RFIs fall in two main areas. The first covers safety and security, including general-purpose and the most advanced AI models. The second covers copyright and transparency and went to another set of AI companies. Agence Europe reported on Sept. 2 that the copyright and transparency strand, per Commission Vice-President Henna Virkkunen, targets companies that did not take part in informal AI Office compliance dialogues, and that the RFIs follow several summer AI-model incidents.
Under the Commission's published enforcement framework, the AI Office can send simple RFIs or RFIs by Commission decision to verify compliance. Incorrect or misleading replies to simple RFIs can trigger fines; decision-RFIs can also penalize failure to reply or incomplete replies. GPAI-related breaches may bring fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, with higher ceilings for prohibited practices. The AI Office can also evaluate models, issue requests for access, and ask providers to take measures that can include restricting public availability of a model. A July 31, 2026, Commission press release said enforcement of AI Act rules and new transparency requirements begins Aug. 2, alongside a first list of more than 180 organisations signing the Code of Practice on transparency of AI-generated content.
Independent EU wires corroborated the Midday confirmation without adding named recipients. Allegiance Law's Brussels counsel brief tied the RFIs to live supervisory demand for documentation, risk management, copyright compliance, and transparency under the Act's information powers. 2eu.brussels stressed that officials framed the requests as the beginning of scrutiny, not a finding of infringement, and that company identities remain confidential. Regnier also said ENISA's invitation to join advanced-model onboarding talks remains ongoing through bilateral discussions, not completed access.
What remains open is which companies received which strand of RFI, what follow-up evaluations or decision-RFIs the AI Office may issue, and whether summer-incident reporting becomes a formal compliance finding. The Commission has not published recipient names or an infringement decision; secondary outlets that speculate on named labs remain unconfirmed on that point, and the OpenAI and Anthropic cyber exchanges stay separate from the RFI cohort.