preloader

· · digital-privacy eu ai-act compliance regulation ai-security europe

The EU AI Act Has Moved Into Enforcement Mode With More Than 30 Information Requests, and Regulators Are Testing Their Nerve

Source: Agence France-Presse

The EU AI Act is no longer a future obligation. Enforcement has been possible since August 2026, and the European Commission has already sent more than 30 requests for information to companies, covering issues from copyright to cybersecurity and safety. Those requests are the preliminary step that can open formal investigations, and they signal that Brussels has moved from writing the rulebook to using it.

What the Commission is claiming

EU spokesman Thomas Regnier says the rules are fully fit for purpose and that Europeans can feel safe precisely because the safeguards exist. The Commission points to the fact that AI providers have already been forced to hand over information to regulators as evidence the framework works. Ursula von der Leyen has separately proposed talks with the main frontier labs to pace the technology’s growth, arguing the AI Act puts Europe in a position to shape global regulatory efforts, even as US opposition to AI regulation complicates that ambition.

Where the gaps are, according to lawmakers

Not everyone in Brussels is convinced. Four EU lawmakers, including lead AI Act negotiator Brando Benifei, warn of legislative gaps after the EU shelved planned AI liability rules that would have made it easier to hold providers accountable for harm. They argue the current rules do not apply to the research, testing and development phase, leaving Europeans unprotected while models are trained and evaluated. The Commission rejects that reading, saying the law can be enforced from the testing phase onward if a provider loses control in a way that affects the internal market, for example through cyberattacks. Researchers add a further concern: if a deployed AI agent hacks a website, accountability for the resulting damage is not clearly assigned in EU law today.

Why European companies should care now

For any European business building with or deploying AI systems, this is the moment to get ahead of the process. Information requests tend to arrive before investigations, and organizations that can document their model evaluations, risk assessments, cybersecurity posture and data protection alignment will move through scrutiny far faster than those improvising answers under deadline pressure. The enforcement era rewards companies with an AI governance story that is written down, not improvised.

If you want a clear-eyed assessment of how the AI Act’s enforcement phase applies to your systems, contact Excello Digital at https://excello.digital/contact/. We help European businesses translate AI regulation into practical governance, security review, and documentation before regulators ask the first question.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!