The European Commission sent its first formal requests for information to more than 30 artificial intelligence providers in early September 2026, opening a new enforcement phase under the EU AI Act. The requests cover safety and security of advanced models as well as copyright and transparency obligations. For legal and compliance teams, an RFI is not a courtesy survey: Article 91 empowers the Commission to demand documentation drawn up under Articles 53 and 55, with penalties for incorrect, incomplete, or misleading responses.
This EU AI Act RFI checklist helps teams that received or expect a regulatory information request assemble the core document set, model and data lineage records, escalation paths, and timelines. Use it alongside your EU AI Act compliance program and vendor reviews for AI chatbot products built on frontier models.
Commission Vice-President Henna Virkkunen noted that some recipients had not participated in informal compliance dialogues, triggering a second copyright and transparency wave. Even providers who believe they are mid-dialogue should maintain a living evidence repository because RFIs can arrive without warning after high-profile incidents such as the July 2026 Hugging Face agent intrusion, which sharpened EU scrutiny of evaluation security and post-market monitoring.
RFI Trigger Scenarios and Who Receives Them
RFIs can follow informal compliance dialogues, summer 2026 security incidents, downstream complaints, or scientific panel requests under Article 68. The AI Office gained enforcement powers on 2 August 2026 for GPAI model rules, transparency duties, and certain prohibited practices. Providers who skipped voluntary dialogues reportedly featured in a second wave of copyright and transparency requests.
Article 91 allows the Commission to request documentation prepared under Articles 53 and 55 or any additional information necessary to assess compliance. The request must state the legal basis, purpose, required information, deadline, and applicable fines under Article 101. Providers, authorized representatives, or lawyers may supply answers, but the provider remains responsible for completeness and accuracy.
| Trigger | Typical RFI focus | Articles cited |
|---|---|---|
| Post-incident scrutiny | Agent security, eval infrastructure, incident reporting | Art. 55(1)(c), cybersecurity duties |
| Skipped compliance dialogue | Copyright policy, training-data summary, transparency | Art. 53(1)(c)-(d) |
| Downstream provider complaint | Annex XII downstream information, integration support | Art. 53(1)(b), Arts. 53-55 |
| Scientific panel request | Systemic risk evidence, evaluation protocols | Art. 91(3), Art. 68(2) |
Core Document Set for Article 91 Responses
Start with the documentation you already owe under Articles 53 and 55, then add evidence that proves current accuracy and operational reality. RFIs test whether paper compliance matches production behavior.
Baseline GPAI Provider Documents
- Annex XI technical documentation: training methodology, compute, architecture, capabilities, limitations
- Annex XII information for downstream AI system providers integrating the model
- Copyright compliance policy published and maintained under Article 53(1)(c)
- Public training-data summary under Article 53(1)(d)
- Authorized EU representative appointment if required under Article 54
- Code of practice adherence records or alternative compliance demonstration under Article 56
Systemic Risk Additions
Providers of GPAI models with systemic risk must also supply evaluation protocols, adversarial testing records, systemic risk mitigation measures, serious incident logs, and cybersecurity controls mapping to Article 55(1). If training compute exceeds 10^25 FLOPs or the AI Office designated the model, assume Article 55 applies unless you have a successful rebuttal on file.
| Document | Article reference | Owner function |
|---|---|---|
| Technical documentation pack | Art. 53(1)(a), Annex XI | Model / research engineering |
| Downstream integration guide | Art. 53(1)(b), Annex XII | Product / solutions |
| Copyright and data summary | Art. 53(1)(c)-(d) | Legal / policy |
| Adversarial eval reports | Art. 55(1)(a) | Safety / red team |
| Incident and mitigation log | Art. 55(1)(c) | Security / trust and safety |
Model and Data Lineage Records
Regulators increasingly ask for traceable lineage from base checkpoints through fine-tunes, distillation, and deployment configurations. A model card alone is rarely sufficient if weights, eval harnesses, or safety filters changed after the card was written.
- Versioned model identifiers with release dates and change logs
- Training and fine-tuning data sources with lawful basis summaries where applicable
- Compute records supporting systemic risk classification or rebuttal
- Safety filter, moderation, and tool-use policy versions tied to each API endpoint
- Third-party eval or audit reports with scope limitations clearly stated
- Post-market monitoring summaries and serious incident notifications sent to authorities
- Records of downstream integrations when complaints triggered the RFI
Store lineage in a single evidence repository with immutable timestamps. Legal teams should be able to prove which documentation version was accurate on the date the model was placed on the EU market.
Timeline, Escalation, and Penalty Exposure
Article 91 requests include a fixed response period; missing the deadline or submitting misleading material can trigger fines up to 3% of worldwide annual turnover or 15 million euros, whichever is higher. Simple RFIs and Commission decisions carry different procedural paths, but both penalize bad information.
- Day 0: Log receipt, identify legal basis, and preserve all internal communications about the requested model.
- Day 1-3: Convene a war room with legal, policy, security, and model owners. Map each request line to an evidence owner.
- Week 1: Gap analysis against Annex XI/XII and Article 55 packs. Flag stale model cards or missing incident logs.
- Mid-deadline: Executive review of draft answers. Never let marketing language override technical accuracy.
- Before submission: Consistency check across documents. Contradictions between eval reports and public summaries are a common failure mode.
- After submission: Monitor for follow-up questions, on-site inspections, or access requests for model evaluations under Commission powers.
Escalate immediately to external counsel if the RFI references incidents your security team has not fully documented, or if downstream complaints allege missing Annex XII information. Structured dialogue with the AI Office may continue, but RFIs signal formal scrutiny has begun.
Cross-Functional RACI for RFI War Rooms
Article 91 responses fail when legal owns the deadline but engineering owns none of the evidence. Assign a single response manager with authority to chase model owners, safety teams, and infrastructure leads. Typical RACI splits look like the table below.
| Workstream | Responsible | Accountable |
|---|---|---|
| Annex XI technical pack | Model engineering | Chief model officer or VP research |
| Copyright and training summary | Legal / policy | General counsel delegate |
| Adversarial eval evidence | Safety / red team | Head of trust and safety |
| Incident logs | Security operations | CISO |
| Final submission | Regulatory affairs | Authorized EU representative |
Common RFI Gaps That Trigger Follow-Up
September 2026 enforcement focused on safety and copyright strands. Providers who skipped informal dialogues received copyright-heavy requests. Teams most often stumble on stale training-data summaries, missing adversarial test documentation for systemic-risk models, incomplete Annex XII packets for integrators, and incident logs that describe customer tickets but not Article 55 serious incident criteria. Build a pre-RFI self-audit using the AI Act Service Desk Article 91 text as a line-by-line checklist.
Frequently Asked Questions
Who can receive an EU AI Act RFI?
Article 91 targets providers of general-purpose AI models. Downstream deployers of AI systems face separate complaint channels through national authorities. If you integrate a GPAI model into a product, your vendor may receive the RFI, but you should still verify Annex XII materials exist and match your deployment.
What is the difference between a simple RFI and a Commission decision?
The AI Office may issue simple requests or more formal requests by Commission decision. Both require accurate responses. Decision-based requests can add penalties for failure to reply as well as for misleading information. Treat every RFI as legally binding regardless of format.
Can we redact trade secrets?
Providers must supply requested information while protecting legitimate confidential business information under applicable EU procedures. Work with counsel on confidentiality claims early. Blanket refusals or obviously incomplete annexes increase enforcement risk.
Does open-source status change RFI scope?
Open-source GPAI models may be exempt from some Annex XI and XII duties under Article 53(2), but copyright policy and training-data summaries still apply. Systemic-risk models lose the open-source documentation exemption entirely. RFIs will test which tier your release occupies.
What if we never placed the model on the EU market?
Jurisdiction and provider status depend on placement, accessibility, and representative arrangements. Do not assume non-EU hosting avoids Article 91 without a formal legal analysis. Many frontier APIs are reachable from the Union regardless of corporate headquarters.
Should deployers prepare RFI packs?
Deployers of AI systems should maintain vendor diligence files with Annex XII receipts, model version pins, and incident notification clauses even if Article 91 is addressed to GPAI providers. Enterprise procurement teams increasingly require proof that upstream vendors can respond to Commission requests without breaking downstream service continuity.