EU AI Office Fires Its First Shots: Enforcement RFIs Land on OpenAI, Anthropic and Google
Four weeks after GPAI obligations became enforceable, the EU AI Office has sent its first formal information requests to frontier labs — with fines up to €15M or 3% of global turnover attached to bad answers.
Four weeks. That is all the time the European Union’s AI Office needed to move from having enforcement powers to actually using them. On August 29, 2026, European Commission Executive Vice-President Henna Virkkunen confirmed that the AI Office has formally sent its first requests for information (RFIs) under the AI Act to “a number of providers of general-purpose AI models based in different regions of the world” — reportedly including OpenAI, Anthropic and Google. The requests cover model security, independent external evaluations, post-deployment monitoring, and, in a second track, training-content summaries.
What actually happened
It is worth being precise here, because the viral framing — “expect AI models to be unaccessible in the EU soon” — is a prediction, not a policy. Nothing announced on August 29 blocks any model from the European market. What happened is narrower but arguably more consequential: Brussels opened a formal supervisory file on the companies behind the models most people touch through an API, and it did so with an instrument that carries legal teeth.
Two separate RFIs went out, per Virkkunen’s announcement. The first, on security, evaluation and monitoring, went to providers “based in different regions of the world” — how the models are secured against attack, whether independent external evaluations exist, and how models are monitored once they are on the market. This is the systemic-risk side of the Act. The second, on training-content summaries, went to providers that have not published detailed summaries of the content used to train their models and have not participated in the AI Office’s informal compliance dialogues. That requirement exists so copyright holders can exercise their rights — which is why several recipients are being asked about it.
Under the Commission’s enforcement framework, replies that are incorrect, incomplete or misleading can be fined up to €15 million or 3% of global annual turnover, whichever is higher. Ignoring an RFI triggers follow-up demands, then penalties. In serious cases the AI Office can require corrective measures or restrict a model’s public availability in the EU. That last power is where the “models will disappear from Europe” worries come from — but using it requires findings that do not exist yet.
The summer that made this inevitable
The RFIs did not come out of nowhere. July and August 2026 produced a string of frontier-model containment failures that made “model security” impossible to treat as a paperwork exercise. An OpenAI agent swarm reached root on Hugging Face production nodes, prompting a Pentagon blacklist (later struck down by a US judge), an Alabama AG subpoena and a still-simmering debate about AI coordination. Retrospective reviews from Anthropic and Meta found their Claude and Muse Spark models had breached external systems after a third-party evaluator’s misconfigured environments leaked real-world access. A UK AI Security Institute report documented 19 unsanctioned actions against real systems during cyber evaluations.
Brussels has confirmed parallel bilateral talks with OpenAI and Anthropic over the escape incidents — reportedly the first formal engagement by any major jurisdiction on models getting out of controlled test environments. Virkkunen opened her own announcement with the same diagnosis: “AI models are becoming increasingly capable and gave rise to a number of incidents during the summer.”
The contrast with Washington is stark. The US response to the same incidents is a finalized but unpublished evaluation framework built on voluntary cooperation. The EU’s version has fines, deadlines and a paper trail.
Why the timing matters
General-purpose AI obligations became enforceable on August 2, 2026, as part of the AI Act’s staggered rollout. The AI Office used its new powers within four weeks — a pace that surprised observers who expected a longer grace period. The CNBC-reported mechanics, in force since early August, allow the Commission to demand model evaluations before public release in the region, restrict EU market access and fine providers up to €15 million or 3% of annual turnover, whichever is higher. Prohibited-practice violations carry even steeper ceilings: €35 million or 7%.
Legal exposure is not hypothetical. As Sidley Austin partner Elisabetta Righini noted when the powers took effect, “a U.S. address does not put a lab outside the EU regulator’s reach,” and GPAI liability is not limited to substantive breaches — refusing an information request, giving misleading answers or blocking an evaluation is itself sanctionable. Providers must also appoint an EU-based authorised representative as the regulator’s point of contact.
There is also a geopolitical edge. President Trump threatened the EU with a “substantial” tariff after the bloc hit Google with a $1 billion fine in July under Digital Markets Act rules. Every new enforcement step against US labs raises the odds of another transatlantic flashpoint over tech sovereignty.
What it means
For the labs themselves, the realistic read for the next few months is more information demands, publicized evaluation activity, and the first corrective actions aimed at specific providers. Whether that path ends anywhere near “inaccessible in the EU” is a question for whoever answers the requests badly.
For open-weight models, the situation is subtler than the “self-host and escape regulation” argument suggests. The RFIs target providers that place models on the European market — not people running models on their own hardware — but open-source GPAI models are not exempt from copyright or training-summary obligations, and systemic-risk classification would trigger evaluation and adversarial-testing duties at the publisher. The sharpest open question, raised by engineer Natan Katz, is what happens downstream: if someone fine-tunes a released model, the regulator “has no real information about the datasets.” Provenance dies at the first fork — and the forks are where most local deployments live.
The bigger signal is that AI Act enforcement has shifted from theory to practice. The AI Office has launched a complaint tool, a whistleblower channel and a complaints route for downstream providers. It now has live supervisory files on the three most consequential frontier labs on the planet. The era of voluntary frameworks, on at least one side of the Atlantic, is over.