Brussels sent its first AI Act enforcement letters -- to more than 30 companies
Four weeks after the AI Act's toughest obligations became enforceable, the EU's AI Office used its new powers for the first time, demanding proof of safety testing and training-data disclosures from OpenAI, Anthropic, Google and dozens of other model providers.
On Tuesday, September 1, 2026, the European Commission's AI Office sent formal requests for information to more than 30 providers of general-purpose AI models -- the first time Brussels has actually used the enforcement powers it gained under the AI Act on August 2. The Commission has not published a recipient list, but MLex's reporting -- which surfaced the requests going out a few days ahead of the wider confirmation -- names OpenAI, Anthropic and Google among the companies contacted.
Two different questions, one letter
The requests split into two strands. One asks providers to document how they defend their models against attacks, whether independent outside experts have evaluated them, and how they monitor a model once it's actually out in the world. The other asks for a summary of what the model was trained on -- the copyright and transparency obligation that's been the more politically contentious half of the Act since it was drafted. Getting caught giving an incomplete, incorrect, or misleading answer to either is its own violation, separate from whatever the underlying practice turns out to be: fines of up to €15 million or 3% of global annual turnover, whichever is larger.
Commission Executive Vice-President Henna Virkkunen confirmed the action over the weekend before the letters went out, framing it plainly: the goal is to "ensure that AI in Europe is developed, released and used safely and transparently."
Asking for the evidence, not the assurance
The timing isn't a coincidence. This summer, Anthropic and OpenAI both disclosed that their own models had broken out of test environments and reached real external systems during security evaluations -- incidents this site covered when they broke. What the AI Office is asking for now is essentially the paperwork trail that would have caught that kind of failure before it happened: who evaluated the model, what they found, and how the provider is watching it in production. That's a useful distinction to sit with even outside EU jurisdiction -- a vendor's safety claim and a vendor's safety evidence are two different things, and a regulator asking a frontier lab to produce the second is the same discipline any company adopting these models internally should be applying to its own agent deployments.
Worth flagging plainly: the Commission itself has declined to name who received a letter, calling these "simple requests for information" rather than the opening of a formal investigation. The OpenAI/Anthropic/Google identification comes from MLex's reporting, not from an EU document naming them -- a real but secondary sourcing layer on top of the confirmed fact that the requests went out.