The Pulse
EU Begins AI Act Requests as Commission Keeps Targets Secret
The European Commission says it has begun using its enforcement powers under the EU AI Act, while officials have declined to identify the companies that received its first information requests.

AI.info Team ·
The European Commission says it has begun using its enforcement powers under the EU AI Act, while officials have declined to identify the companies that received its first information requests. The disclosure came as officials faced questions about Anthropic and other developers of advanced AI models.
“We have sent the first request for information,” Thomas Regnier, a European Commission spokesperson, said during the Commission’s midday press briefing in Brussels on September 14. The briefing did not identify the companies that received the requests or say whether Anthropic was among them.
The statement marks a shift from preparation to active supervision. The Commission has been applying the AI Act’s general-purpose AI obligations since August 2025, but its full enforcement powers for those providers began on August 2, 2026.
The Commission Will Not Name the Companies
Regnier said the European Union was already playing a leading role in setting safeguards for AI systems.
“We have the AI Act. It’s fully enforced. We are enforcing it.” — Thomas Regnier, European Commission spokesperson
The Commission provided more detail during a September 1 press briefing. Officials said the first requests covered more than 30 AI companies and two broad areas: safety and security for general-purpose and advanced AI models, and copyright and transparency issues. Regnier said the Commission would not name the companies because the requests were information-gathering measures rather than findings of wrongdoing.
That distinction matters under the law. Article 91 of the AI Act allows the Commission to request documentation or additional information from providers of general-purpose AI models when it needs to assess compliance. A request must state its legal basis and purpose, specify the information required and set a deadline for the response.
Anthropic and OpenAI Remain Outside the Public List
The September 14 briefing followed questions about Anthropic’s discussions with governments over the pace and safety of frontier AI development. Regnier said he was not aware of Anthropic engaging the Commission on that specific proposal and added that the Commission would not discuss bilateral contacts in public.
He confirmed that European cybersecurity officials have access to recent AI models for testing.
“I mean our cybersecurity agency, we’re testing them” — Thomas Regnier, European Commission spokesperson
The Commission did not say whether those technical exchanges were connected to the formal information requests.
Officials also avoided confirming whether Anthropic or OpenAI had received requests tied to cyber risks. At the September 1 briefing, Regnier said the Commission had held recent exchanges with both companies about those risks, while declining to identify them as recipients of formal requests.
Safety, Copyright and Transparency Form the First Test
The two-track approach gives the Commission a way to examine both model risks and the information companies provide about how their systems are developed and operated. The safety and security strand covers general-purpose AI and the most advanced models, according to the Commission’s September 1 briefing. The second strand concerns copyright and transparency.
The AI Act gives the Commission’s AI Office direct responsibility for supervising providers of general-purpose AI models. National market-surveillance authorities handle other parts of the law, including requirements for high-risk AI systems and prohibited uses. Those authorities can access documentation, datasets and source code, request corrective measures and impose penalties when the law allows it.
The Commission has also published guidance explaining that information requests can be followed by model evaluations, requests for mitigation measures and, in some cases, enforcement proceedings. Providers can face fines of up to €15 million or 3% of their total worldwide turnover for certain breaches involving general-purpose AI models.
Brussels Says Innovation Depends on Compliance
The Commission’s message is that stricter oversight does not amount to a campaign against advanced AI development.
“We are for innovation in Europe,” Regnier said. “We welcome AI services in Europe as long of course that this is done fully in line with the AI Act and the safeguards that we have put in place.”
He later described compliance as an obligation rather than a voluntary standard.
“We’re not compromising on our security standards,” he said, adding that companies must show their services are safe for people in the European Union.
The immediate question is not whether the Commission has begun acting. It has. The unresolved question is which providers received the requests, what information they must supply and whether the inquiries will lead to formal findings or corrective measures. For now, the Commission has disclosed only the scope of the first action: more than 30 companies, with safety, security, copyright and transparency at the centre.