EU AI Act Enforcement Begins with RFIs to AI Firms
The EU has issued its first AI Act RFIs to model providers including OpenAI and Anthropic. Here is what the enforcement powers actually mean and why it matters.
Written by AI. Tomas Reyes-Kim

The grace period is over. That is the framing The Next Web used, and it is pretty hard to argue with it. After years of drafting, debating, and phased rollouts, the European Union has moved from policy document to enforcement action, issuing its first Requests for Information (RFIs) to AI model providers under the EU AI Act. Companies including Anthropic and OpenAI are now facing formal regulatory scrutiny, according to CNBC, in what marks the first real test of whether Brussels can actually police the frontier AI industry.
So what does this actually mean in practice? And how worried should anyone be?
What an RFI Actually Is (and Isn't)
First, some grounding. A Request for Information is not a fine, not a ban, and not a finding of wrongdoing. It is, functionally, a formal "explain yourself" letter. Regulators use them to gather data before deciding whether deeper investigation is warranted. In the EU context, they are a relatively low-drama opening move.
But calling them low-drama undersells the shift they represent. The Parliament Magazine notes that Europe is now actively preparing to police frontier AI, and these RFIs are the opening salvo of that posture. The EU is not asking companies to self-certify anymore. It is asking them to open the hood.
The tools behind those requests are significant. According to The Next Web, the EU now has the authority to inspect AI models directly, block market access for non-compliant systems, and levy fines of up to 3% of global annual turnover. For a company the size of OpenAI or Anthropic, 3% of global turnover is not a rounding error. It is a real number.
The Architecture of the AI Act (Briefly, Because It Matters)
The AI Act sorts AI systems into risk tiers. General-purpose AI models, the kind that OpenAI, Anthropic, and their competitors build, occupy a specific category with its own set of obligations around transparency, security, and capability disclosures. The RFIs being issued now appear to target this tier directly, as tokenstead.ai outlines, focusing on model providers and the accountability frameworks around their systems.
The risk-tiered architecture is worth sitting with for a second, because it explains why the law lands so differently on different actors. A niche AI tool for scheduling meetings faces almost no friction under the Act. A general-purpose model capable of generating code, drafting legal documents, synthesizing scientific literature, and potentially doing things its developers did not fully anticipate? That is a different story entirely. The regulation is explicitly designed to concentrate scrutiny where capability is highest, which is exactly where the most commercially valuable products sit.
That design choice is either very smart or very clunky depending on your priors, and the RFIs will start to reveal which.
Why These Companies Specifically
CNBC's reporting names Anthropic and OpenAI among the firms facing new scrutiny, which tracks: both operate frontier general-purpose models with hundreds of millions of users, including substantial European user bases. They are not being singled out for alleged wrongdoing. They are being singled out for being the most prominent players in the category the Act is designed to regulate.
The question of what regulators are actually asking for is, frustratingly, not fully answered in the public record yet. RFIs in regulatory processes are often confidential in their specifics, so the detailed questionnaires may not surface publicly until enforcement actions (if any) proceed. What we can infer from the Act's framework is that questions around systemic risk assessment, security testing, and transparency obligations are likely front and center.
Simon Willison has been doing some of the more technically grounded public writing on how these models actually function, at simonwillison.net, and one useful frame from that work is that explaining how a large language model behaves is genuinely hard, even for the people who built it. Regulators asking for clear accountability documentation are going to bump up against a real epistemic problem: some of what they want to know, nobody fully knows yet.
That is not an excuse. It is a complication. And it is one the enforcement process will have to grapple with.
The "Brussels Effect" Question
Here is where things get interesting from a global perspective. When the EU moves on tech regulation with teeth, the rest of the world pays attention. The GDPR did not just reshape European data practices; it rewrote privacy policies globally because companies found it easier to implement one standard than to maintain separate systems by jurisdiction. The question hanging over the AI Act is whether it produces a similar gravitational pull.
The argument for yes: the EU is a massive market, enforcement is now credibly real, and the compliance infrastructure companies build for Europe does not disappear when they cross a border. Global model providers will likely build to the highest regulatory standard, just as they did with GDPR.
The argument for not-necessarily: AI models are not websites. They are not simple data processing pipelines where you can add a cookie banner and call it a day. Adjusting model behavior for regulatory compliance is more technically complex, and the Act's requirements are still being interpreted in real time. Early enforcement may produce as much legal ambiguity as clarity.
It is also worth acknowledging that the companies being regulated here are primarily American, and Washington has taken a markedly different posture on AI governance. The EU is not operating in a vacuum; it is operating in a geopolitical environment where AI capability is tied up with national competitiveness in ways that make pure regulatory harmonization unlikely in the near term.
What the Industry Is Watching For
The short-term signal everyone is waiting for is how companies respond to the RFIs. Cooperation signals one thing; pushback, delays, or legal challenges signal another. If OpenAI or Anthropic contest the scope of an information request in court, that fight would be enormously clarifying about where the Act's authority actually begins and ends.
The medium-term signal is what the EU does with the information it collects. RFIs lead somewhere. They either result in a clean bill of health, the opening of a formal investigation, or some negotiated compliance commitment. How that plays out in the first few cases will set the tone for every model provider operating in Europe.
And the background signal, running underneath all of this, is the pace of model development relative to the pace of regulatory response. The AI landscape at the moment the Act was drafted looks quite different from the one being regulated today. New model generations are arriving faster than regulatory frameworks can be updated. That gap does not invalidate the EU's effort, but it does mean enforcers are, to some degree, always catching up.
The grace period being over is a meaningful milestone. Whether what follows is rigorous oversight, regulatory theater, or something messier and more interesting is the story that the RFIs have just begun to tell.
By Tomas Reyes-Kim, Budget Travel and Digital Nomad Correspondent, BuzzRAG
More Like This
Dual Internet Connections Are Still Needlessly Hard to Set Up
IPv6 multihoming could let you plug two ISPs into one network and get automatic failover. Here's how close we actually are—and what's still broken.
California Exempts Linux from Age Verification Law
California's AB-1856 unanimously exempts Linux and open-source software from age verification. Here's what changed, what didn't, and why it matters beyond California.
UN AI Summit: Big Room, Bigger Questions on Governance
193 countries met in Geneva to tackle AI governance. The warnings were credible. The robots were cool. The binding rules? Still not there.
Hacking a Ball Bearing for Precision on a Budget
A father-son engineering duo modified a standard ball bearing with a grinder to achieve wobble-free precision — no expensive parts required.
Dario Amodei Says AI Backlash Is a Crisis of Trust
Anthropic CEO Dario Amodei says AI's public backlash is a decades-long trust crisis—not a messaging problem. Here's what that diagnosis gets right, and what it sidesteps.
Pentagon's Anthropic Blacklist Ruled Unconstitutional
A federal judge has ruled the Pentagon's blacklisting of Anthropic as a supply chain risk was illegal retaliation. Here's what the ruling means for AI firms.
LeCun's JEPA Roadmap Has a Regulatory Gap
Yann LeCun's JEPA world models could reshape industrial AI—but his deployment roadmap runs straight into regulatory frameworks nobody has updated yet.
Brad Carson: AI Surveillance Dossiers Are Already Legal
Former Congressman Brad Carson argues AI isn't unstoppable — and warns that using AI to compile surveillance dossiers on Americans is currently lawful.
RAG·vector embedding
2026-08-31This article is indexed as a 1536-dimensional vector for semantic retrieval. Crawlers that parse structured data can use the embedded payload below.