AI Office Issues First Formal GPAI Enforcement Requests for Information
On 29 August 2026, the EU AI Office formally issued Requests for Information (RFIs) to GPAI model providers under Article 91 of the EU AI Act, approximately four weeks after the Commission's own GPAI enforcement powers commenced on 2 August 2026 — Chapter V (GPAI) obligations themselves had already applied since 2 August 2025. The RFIs target two parallel tracks: (a) model security, covering adversarial-attack resilience, independent evaluation results, and post-market monitoring protocols; and (b) training-data transparency, targeting providers that had not published compliant training-content summaries under Article 53(1)(d). Maximum penalties applicable under Article 101 for GPAI providers: €15 million or 3% of worldwide annual turnover, whichever is higher. No formal investigation decision or financial penalty has been issued to date; the RFI campaign is ongoing.
Source integrity note: No primary European Commission press release was confirmed at time of writing. The 29 August RFI issuance was reported by Euractiv based on EVP Virkkunen's public statement; included on that basis, subject to formal confirmation.
What it means for you
If your organisation provides a general-purpose AI model (Article 3(63)), these RFIs are directed at organisations in your role. If you have integrated a third-party GPAI model into your own AI system — which makes your organisation a provider of that AI system under Article 3(3), not a deployer of the upstream GPAI model — your obligation is to verify and retain the technical documentation your upstream GPAI model provider is required to give you under Article 53(1)(b). Enforcement is moving faster than market consensus anticipated: the first RFIs arrived within four weeks of obligations becoming enforceable.
Sources
- The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
- AI Office first GPAI enforcement RFIs — Tokenstead/Euractiv (29.08.2026)
- GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
Annex XIV / AIH 0401 — "Agentic AI" Named in Binding EU Law, as a Notified-Body Code
Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, added new nomenclature codes to Annex XIV of the AI Act. One of them, AIH 0401, covers "AI systems based on other emerging AI technologies not covered by other codes, including agentic AI" — the first time the phrase "agentic AI" appears in binding EU law.
Annex XIV has one purpose: the notification procedure under Article 30, where its codes set the scope of what a notified body is designated to assess. AIH 0401 is a residual filing code that names agentic AI as an example. It does not define agentic AI, and it is not a risk category.
What it means for you
AIH 0401 creates no obligations for providers or deployers. Whether an agentic system carries duties still turns on the existing tests: is it high-risk under Article 6 and Annex III (or part of a product regulated under Annex I), does Article 50 apply because it interacts with people or generates synthetic content, or do you provide a general-purpose AI model under Chapter V? The practical change is narrower: if a high-risk agentic system needs third-party conformity assessment, check that the notified body you engage is designated for AIH 0401.
Sources
- Annex XIV AIH 0401 agentic AI classification analysis — NIC Fabrizio (28.08.2026)
- Annex XIV: codes for the notification procedure referred to in Article 30 — EU Artificial Intelligence Act
- The Definition the Law Did Not Write — AI Governance Report
Article 50 Watermarking — Major Model Providers Report Deployments
EU AI Act Newsletter #109 (24 August 2026) reported Article 50 watermarking deployments by the largest model providers ahead of the 2 August 2026 application date of Article 50's transparency obligations: Anthropic deployed invisible text watermarking; Google deployed SynthID alongside C2PA Content Credentials; Meta implemented C2PA metadata combined with deep-learning content authentication marks. Detection interoperability across providers is formally deferred to 2 February 2027, pending European Commission harmonised technical specifications.
What it means for you
If your AI system generates synthetic content, Article 50(2) has required you, as its provider, to mark that output in a machine-readable format since 2 August 2026. A narrower deployer duty under Article 50(4) also applies as of that date, but only to two cases — deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest — where you must disclose to your audience that the content is artificial. Verify whether any GPAI model you integrate carries Article 50-compliant watermarking or C2PA metadata; document the result in writing. Interoperability of detection tools across providers does not apply until February 2027, but the underlying marking and disclosure obligations are live now.
Sources
- The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
- EU AI Act Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)
ISO/IEC 42001 — German National Transposition Published
Germany's DIN (Deutsches Institut für Normung) published the official German-language national transposition of EN ISO/IEC 42001:2026, designated DIN EN ISO/IEC 42001:2026-08, in August 2026. The previous draft (DIN ISO/IEC 42001:2025-10) is superseded and withdrawn. DAkkS-accredited certification bodies in Germany now have a normative DIN EN reference for ISO/IEC 42001 certification engagements.
What it means for you
If your organisation operates in Germany or the DACH market, the "waiting for the German standard" objection to ISO/IEC 42001 certification is closed. The EN designation is a European adoption of the unchanged international text. It does not confer presumption of conformity under the AI Act — no Official Journal citation has been issued — and certification does not replace the Article 17 quality management system a high-risk provider must run. AFNOR (France), NSAI (Ireland), and BSI (UK) transpositions are expected on similar timelines.
Sources
- DIN EN ISO/IEC 42001:2026-08 — DIN Media (01.08.2026)
- EN ISO/IEC 42001:2026 CEN/CENELEC catalogue entry — CEN/CENELEC (01.08.2026)
CNIL Answers Common Questions on Credit Refusal
France's CNIL published a question-and-answer page on credit refusal on 19 August 2026. It explains that there is no general right to credit, that lenders must assess an applicant's capacity to repay, and that an applicant who is refused can ask why.
What it means for you
If you use scoring models or AI to decide on credit applications, this is what applicants in France are now told they can ask for: the reasons for a refusal. Where a refusal rests solely on automated processing, Article 22 GDPR also gives the applicant the right to human intervention and to contest the decision. Separately, AI used to evaluate the creditworthiness of natural persons is high-risk under Annex III point 5(b) of the AI Act, with obligations applying from 2 December 2027 under the Digital Omnibus timetable.
Sources
- Le refus de crédit en questions — CNIL (19.08.2026)
EDPB Stakeholder Event — Data Protection and Competition Law
The EDPB's call for expressions of interest in a stakeholder event on its forthcoming guidelines on the interplay between data protection and competition law closed on 28 August 2026. The event takes place on 15 October 2026. The EDPB has not published a date for the guidelines themselves.
What it means for you
These guidelines are not yet published, and no obligations result from this item. They are likely to matter most to organisations that rely on data held by large platforms, including for AI training. EDPB guidelines normally go to public consultation once drafted, which is the next opportunity to comment.
Sources
- EDPB stakeholder event on data protection and competition law interplay — EDPB (28.08.2026)
What to do this week
- If you have integrated a GPAI model API into your own AI system (making you a downstream system provider under Article 3(3)): confirm you have received, date-stamped, and retained the Article 53(1)(b) technical documentation from your upstream GPAI model provider; if you have not received it, request it in writing now.
- If you provide a general-purpose AI model (Article 3(63)): review your Article 53(1)(a)–(d) documentation for completeness in light of the active RFI campaign.
- List the agentic AI systems you provide or deploy and record, for each, whether it is high-risk under Article 6, within Article 50, or neither — AIH 0401 does not answer that question for you.
- Contact your GPAI model API provider to confirm whether their API responses carry Article 50-compliant watermarking or C2PA metadata; document the response.
- Where you publish deep fakes, or AI-generated text informing the public on matters of public interest, add the Article 50(4) disclosure.
- If you make automated decisions on credit applications, check that applicants can obtain the reasons for a refusal and, under Article 22 GDPR, human intervention in a solely automated decision.
- Note the EDPB's 15 October 2026 stakeholder event, and watch for the public consultation on its data protection and competition law guidelines.
Quick reference
| Topic | Change | Action |
|---|---|---|
| EU AI Act — GPAI Enforcement | AI Office RFIs to GPAI providers (29 Aug 2026): first formal enforcement instruments under the Act | GPAI providers: prepare Art. 53 documentation. Downstream system providers (Art. 3(3)): verify you hold Art. 53(1)(b) documentation from your upstream provider. |
| EU AI Act — Agentic AI | Digital Omnibus adds Annex XIV code AIH 0401, naming agentic AI — a notified-body scope code, not a new obligation | Scope agentic systems under the existing tests (Art. 6 and Annex III, Art. 50); check notified-body designations if third-party assessment applies |
| EU AI Act — Watermarking | Major GPAI providers deploying Art. 50 watermarking; interoperability deferred to Feb 2027 | Confirm your model provider's watermarking status; add the Art. 50(4) disclosure where you publish deep fakes or public-interest text |
| ISO/IEC 42001 | DIN EN ISO/IEC 42001:2026-08 published — German national transposition complete | Update standard references for DE/AT operations; no change to substantive controls |
| GDPR | CNIL publishes questions and answers on credit refusal (19 Aug 2026) | If you automate credit decisions: confirm refusal reasons and Art. 22 GDPR human intervention are available |
| GDPR | EDPB stakeholder event on data protection and competition law: registrations closed 28 Aug 2026, event 15 Oct 2026 | No action; watch for the public consultation on the guidelines |
Every source in this issue
- The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
- AI Office first GPAI enforcement RFIs — Tokenstead/Euractiv (29.08.2026)
- Annex XIV AIH 0401 agentic AI classification analysis — NIC Fabrizio (28.08.2026)
- Annex XIV: codes for the notification procedure referred to in Article 30 — EU Artificial Intelligence Act
- The Definition the Law Did Not Write — AI Governance Report
- GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
- EU AI Act Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)
- DIN EN ISO/IEC 42001:2026-08 — DIN Media (01.08.2026)
- EN ISO/IEC 42001:2026 CEN/CENELEC catalogue entry — CEN/CENELEC (01.08.2026)
- Le refus de crédit en questions — CNIL (19.08.2026)
- EDPB stakeholder event on data protection and competition law — EDPB (28.08.2026)
- EDPS Opinion 17/2026 — Regulation 2018/1725 revision — EDPS (20.08.2026)
Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.
The EU AI governance brief
One email a week. Sourced and dated. Unsubscribe in one click, from any of them.
Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.