Skip to main content
AI RegulationPolicy DecisionAug 26, 2026, 8:26 PM· 5 min read· in ai

EU AI Office Issues First Formal Orders to Major Labs on Model Security and Copyright Compliance

The European Commission has activated its enforcement powers under the AI Act, demanding detailed disclosures from over 30 AI developers regarding their cybersecurity protections and training data.

By Mateo Ramos

EU Regulators 40%Frontier AI Labs 30%Rightsholders & Creators 30%
EU Regulators
Argue that strict enforcement of transparency and security rules is necessary to protect European citizens and intellectual property.
Frontier AI Labs
Emphasize the need to balance transparency with the protection of trade secrets and proprietary model architectures.
Rightsholders & Creators
Demand full disclosure of training datasets to ensure they can exercise opt-out rights and receive compensation for their work.

Key points

  • The EU AI Office has issued its first formal orders to major AI developers, marking the start of active enforcement.
  • Over 30 companies were asked to detail their compliance with EU copyright rules and provide training data summaries.
  • Regulators are also demanding information on cybersecurity measures to prevent model theft and unauthorized access.
  • The AI Office can levy fines of up to 3% of global turnover for non-compliance with General-Purpose AI rules.
  • Enforcement currently focuses on foundational models, as the high-risk application tier was deferred to December 2027.
>30
AI companies targeted for copyright compliance
3%
Max global turnover fine for GPAI breaches
7%
Max global turnover fine for prohibited practices
Dec 2027
Deferred enforcement date for high-risk systems

The European Union has officially activated the enforcement machinery of the AI Act, issuing its first formal orders to major artificial intelligence laboratories. Tech Commissioner Henna Virkkunen confirmed this week that the European Commission has demanded detailed disclosures regarding cybersecurity, model safety, and copyright compliance from leading developers. This marks the transition of the EU AI Office from a purely advisory body into an active regulator capable of levying fines and forcing non-compliant models off the market. The orders represent the first concrete test of Europe's ambitious framework to govern foundational AI models, shifting the landscape from voluntary commitments to legally binding transparency.[1][3]

The legal mechanism driving these orders stems from the August 2, 2026, activation of the AI Office's inspection and enforcement powers over General-Purpose AI (GPAI) providers. While the underlying obligations for GPAI models took legal effect in August 2025, the Commission lacked the operational authority to investigate breaches until this month. Now, the AI Office can formally request documentation, conduct technical model evaluations, and mandate corrective measures. This structural shift empowers a dedicated team of regulators to look under the hood of the world's most advanced neural networks, ensuring they align with European safety and intellectual property standards before they are deployed at scale.[2][3]

A significant portion of the initial enforcement wave targets copyright transparency. The AI Office has sent formal requests to more than 30 AI companies demanding details on how they are complying with European copyright rules. Under the AI Act, developers must publish a standardized summary of the data used to train their models. The Commission specifically targeted companies that either failed to publish this training data form or ignored prior informal inquiries. By forcing labs to document their training inputs, regulators are attempting to create a verifiable paper trail that rightsholders can use to identify infringement and exercise their legal opt-out rights.[1][4]

Maximum fines under the EU AI Act for general-purpose AI providers.

Beyond copyright, the orders also probe the physical and digital security surrounding frontier models. Following a series of high-profile cybersecurity incidents at leading AI labs, the Commission is demanding proof that developers have implemented adequate infrastructure protections to prevent model theft by human actors or autonomous agents. Regulators are also scrutinizing how much access these labs provide to external safety evaluators and how they monitor model usage post-deployment. The focus on cybersecurity reflects growing concerns that the most powerful open-weight and proprietary models could be weaponized if their underlying weights or training environments are compromised by state-backed hackers.[1][6]

Beyond copyright, the orders also probe the physical and digital security surrounding frontier models.

The stakes for non-compliance are substantial, though tiered based on the severity of the violation. If a company fails to answer a formal request, the Commission can escalate the inquiry and eventually issue fines for obstruction. As a last resort, breaches of GPAI obligations can draw penalties of up to 15 million euros or 3 percent of a company's global annual turnover, whichever is higher. Prohibited AI practices carry an even steeper penalty cap of 35 million euros or 7 percent of global turnover. These financial threats are designed to ensure that even the most capitalized tech giants cannot simply absorb regulatory fines as a cost of doing business.[1][3]

What the data does not show, however, is a broad crackdown on all AI systems. The recent Digital Omnibus quietly deferred the enforcement of the AI Act's "high-risk" tier—which covers applications like employment screening, biometric categorization, and credit scoring—until December 2027. Consequently, day-one enforcement is narrower than many headlines suggest, focusing almost exclusively on the foundational models produced by frontier labs rather than the downstream applications built upon them. This phased approach allows the AI Office to concentrate its limited resources on the handful of companies building the most capable, and potentially disruptive, general-purpose engines.[2][5]

The phased enforcement timeline for the EU AI Act.

Significant uncertainties remain regarding how these orders will play out in practice. It is still unclear exactly which companies received the cybersecurity and safety orders, as Commissioner Virkkunen declined to name specific developers. Furthermore, the practical threshold for what constitutes a "sufficiently detailed summary" of training data has yet to be tested in court. While the AI Office has provided a standardized template, the tension between protecting trade secrets and satisfying transparency mandates will likely define the first major legal battles under the new regime. It is also unknown how aggressively US-based labs will push back against the jurisdiction of European regulators demanding access to their core intellectual property.[1][4]

For now, the issuance of formal orders signals that the grace period for GPAI providers has definitively ended. The European Union is demanding that the technical architecture of frontier models—and the massive data pipelines that feed them—be opened to regulatory scrutiny. How the major laboratories respond to these initial requests will set the precedent for artificial intelligence governance not just in Europe, but globally. If the AI Office successfully enforces these mandates, it will establish a blueprint for algorithmic accountability; if it falters, the AI Act risks becoming a paper tiger in the face of unprecedented technological acceleration.[1][2]

What we don’t know

  • Which specific frontier labs received the cybersecurity and safety orders, as the Commission has not named them.
  • How the AI Office will define a 'sufficiently detailed' training data summary in practice.
  • Whether US-based labs will fully comply with the data disclosures or challenge the AI Office's jurisdiction.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

EU Regulators 40%Frontier AI Labs 30%Rightsholders & Creators 30%
  1. [1]EuractivEU Regulators

    European Commission makes first use of new AI enforcement powers

    Read on Euractiv
  2. [2]Digital AppliedFrontier AI Labs

    EU AI Act enforcement formally began on August 2, 2026

    Read on Digital Applied
  3. [3]ServolaRightsholders & Creators

    EU Regulators Can Now Fine AI Firms 7% of Revenue

    Read on Servola
  4. [4]European CommissionEU Regulators

    Guidelines on obligations for General-Purpose AI providers

    Read on European Commission
  5. [5]EU AI Act ExplorerEU Regulators

    Introductory Remarks on Transition Periods

    Read on EU AI Act Explorer
  6. [6]The Future SocietyFrontier AI Labs

    Background on the Code of Practice for General-Purpose AI

    Read on The Future Society

Comments

Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.