Almost a month after the European Union Artificial Intelligence (EU AI) Act came into effect, the European Commission took the first step in its enforcement by asking global AI companies to submit information regarding AI models’ safeguards, independent evaluation and monitoring.
The European Commission’s AI office, sent a formal request to AI companies in the world, reacting to recent incidents of frontier AI models carrying autonomous operations to breach third-party organizations by exploiting their vulnerabilities. The case of OpenAI’s AI agents breaching Hugging Face platform has drawn considerable limelight drawing concerns over increasing capabilities of AI models sans human control.
In a post on LinkedIn, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said, “AI models are becoming increasingly capable and gave rise to a number of incidents during the summer. The AI Act gives us the power to require AI providers to strengthen their risk-mitigation measures and help ensure that the models and systems they place on the European market are safe.”
Key provisions of the AI Act covering general-purpose AI models, transparency requirements and related enforcement powers became applicable on August 2, 2026. The EU AI Act focuses on safety, privacy and transparency aspects of AI models and tools deployed in European markets by AI companies. The Act adopts a risk-based approach and is part of a broader package of policy measures that also includes the AI Continent Action Plan, the AI Innovation Package and AI Factories.
Virkkunen also informed that the AI Office has also sought information related to training of LLMs and a reminder to those “who have not participated in informal compliance dialogues with the AI Office. This publication requirement is intended to increase transparency and help copyright holders and other parties with legitimate interests exercise their rights.
Under the AI Act, providers must design AI systems to inform users when they are directly interacting with AI and add machine-readable marks to enable the detection of AI-generated or manipulated content. Deployers must inform users when they are exposed to deepfakes, AI-generated content on matters of public interest without human review or editorial control, and emotion recognition or biometric categorization systems.
The Commission is also introducing a range of tools to help organizations understand their AI Act obligations, including the Code of Practice on Transparency of AI-generated Content and the AI Act Service Desk.





