The quiet phase of the AI Act is over. On Monday the Commission's AI Office confirmed it has sent formal compliance notices to four providers of general-purpose AI models, asking each to substantiate, within eight weeks, how their training-data summaries, copyright policies and serious-incident procedures satisfy the obligations that became enforceable this month.
The notices are not fines and the AI Office was careful to say so. But they are the first use of the information powers that unlocked in August, and they change the temperature of the conversation. Until now, GPAI compliance rested on the voluntary code of practice signed last year; a notice converts those commitments into questions with deadlines attached.
Officials would not name the four recipients. Two are widely reported to be US frontier labs, one a European champion and one an open-weight provider whose downstream fine-tunes have repeatedly surfaced in consumer apps without the required transparency notices.
What the letters actually ask
People who have seen the template describe three blocks of questions. The first asks providers to reconcile their public training-data summaries with the more detailed documentation held internally. The second probes incident handling: who decides that a capability failure is serious, on what evidence, and how fast it reaches the AI Office. The third asks for the provider's own systemic-risk assessment, including red-team results, in unredacted form.
“The notices are deliberately boring. That is the point: compliance in this regime looks like paperwork, not press releases.”
Benedikt Sorensen, senior fellow, Centre for Digital Governance, Copenhagen
The procedural stakes are real. Failure to answer, or answering with material gaps, lets the Commission impose periodic penalty payments and, in the endgame, fines of up to three percent of global turnover. No one in Brussels expects that this year. Everyone expects the answers to shape the first enforcement decisions of 2027.
Member-state authorities, meanwhile, are watching the division of labour. National market-surveillance bodies own high-risk systems; the AI Office owns the models underneath them. The notices are the first test of whether that seam holds when a single incident implicates both layers.
The providers have until early October to respond. The AI Office says it will publish an anonymised summary of the exercise before the end of the year, a small transparency gesture that policy veterans read as pressure on the slowest of the four.