The European Commission has made its first reported use of new EU AI Act enforcement powers, seeking information from selected developers of the most advanced artificial intelligence models on cybersecurity, safety and copyright compliance. European Commission Executive Vice-President for Tech Sovereignty, Security and Democracy Henna Virkkunen confirmed the requests in an interview.
The Commission did not identify the recipients. Virkkunen said the requests did not cover every provider because the Commission had already held close dialogue with some developers in recent months. Euractiv approached Anthropic, OpenAI, Google, Meta and Mistral for confirmation; the publication reported that none had responded at the time of publication.
EU AI Act enforcement focuses on model and infrastructure security

According to the report, the information requests examine whether the laboratories have appropriate cybersecurity protections and physical-infrastructure safeguards for their models. The Commission is seeking evidence about measures intended to prevent a model from being stolen by either people or other AI systems. It is also looking at the access offered to external model evaluators, the follow-up given to their safety recommendations, and monitoring of model use after public release.
The requests put the operational side of model security under closer regulatory attention. For background on the technical and organizational risks at issue, readers can review Nemko Digital’s overview of the cybersecurity landscape in the field of AI, including risks such as data poisoning, model theft and unauthorized access.
The AI Act’s rules for providers of general-purpose AI models have applied since 2 August 2025. Providers must maintain technical documentation, establish a copyright policy and publish a sufficiently detailed public summary of the training content used for their models. Providers of models with systemic risk have further obligations to assess and mitigate systemic risks, conduct model evaluations, report serious incidents, and ensure adequate cybersecurity for the model and its physical infrastructure.
What the requests mean for AI providers and downstream organizations
For providers, the immediate development is a request for information, not a public disclosure of enforcement findings. However, it signals that the Commission is moving from guidance and dialogue into the use of its formal supervisory powers and broader enforcement framework. The European AI Office, or AI Office, which enforces the GPAI rules, can request information and technical documentation, carry out model evaluations, request corrective measures, restrict model availability and apply sanctions in cases of infringement.
Organizations that build products or services on top of third-party models should also monitor the outcome. The Commission says GPAI technical documentation is intended both for the AI Office and national authorities on request and for downstream providers that must meet their own relevant AI Act obligations. In practice, product, procurement and governance teams may need to confirm what model-level documentation, security information and risk-management evidence they receive from suppliers. This access can be an essential pillar of a broader governance architecture for the digital future.
The report also described a separate set of copyright-related information requests to more than 30 AI companies. These concern compliance with European copyright rules, including the training-content summary required under the Act. The distinction matters: the Commission’s current activity spans both safeguards around advanced models and transparency about the content used to develop them.
For context on voluntary implementation measures, Nemko Digital’s coverage of the EU GPAI Code of Practice explains how the code addresses transparency, copyright and systemic-risk management. Its discussions of AI security auditing and enterprise AI governance frameworks provide further background on the control areas now receiving regulatory scrutiny, including high-risk AI systems and general-purpose AI models.
The next indicators of EU AI Act enforcement will be whether the Commission discloses further details on the requests, identifies affected providers or proceeds to evaluations or other measures. Organizations developing or relying on advanced models should follow those announcements closely, particularly where models are placed on the EU market or integrated into regulated AI systems. The emerging enforcement timeline may also clarify how the AI Office works with national authorities and other market surveillance authorities in each member state.

