EU AI Act's First RFIs Issued: What Compliance Challenges Do Model Providers Face?

EU regulators issue first RFIs under the AI Act, pushing model providers into real compliance action.
The EU AI Act has entered its enforcement phase with the issuance of the first Requests for Information (RFIs) to general-purpose AI model providers. These RFIs compel providers to disclose training data, risk assessments, and technical details. The article examines the triple pressure of transparency, risk evaluation, and tight deadlines, the asymmetric impact on large vs. small companies, and how the Act's extraterritorial reach could establish a de facto global AI regulatory standard.
EU AI Regulation Enters the Operational Phase
After years of legislative deliberation and heated debate, the EU AI Act has finally moved from paper to practice. Recently, EU regulators issued the first batch of Requests for Information (RFIs) to several general-purpose AI model providers, marking the formal transition of the world's first comprehensive AI regulatory framework into substantive enforcement.
The symbolic significance of this move cannot be overstated. Previously, industry discussions around the AI Act largely revolved around compliance preparation. The issuance of RFIs signals that regulators have begun actively exercising their investigative powers, demanding that leading model providers furnish detailed accounts of their models' training processes, technical capabilities, risk management practices, and other critical aspects. For the entire AI industry, the message is unmistakable: regulation is no longer a distant threat — it is a present-day reality that demands immediate attention.

What Are RFIs, and Why Start with Model Providers?
The Nature and Purpose of RFIs
An RFI is an information-gathering tool used by regulators before launching a formal investigation or imposing penalties. While an RFI does not constitute a penalty in itself, companies typically have a legal obligation to respond truthfully and completely within a specified deadline. Through RFIs, regulators can gain a thorough understanding of a model's technical details, assess whether it complies with the Act's requirements, and build an evidence base for potential future enforcement actions.
As an administrative investigation tool, the RFI has a well-established history within the EU regulatory system. In EU competition law, the European Commission has long used similar mechanisms for preliminary investigations into companies suspected of monopolistic or anti-competitive behavior. The legal force of an RFI falls somewhere between an informal inquiry and a formal investigation — companies that refuse to respond or provide false information may face fines or other legal consequences. Under the AI Act framework, the legal basis for RFIs stems from the information-gathering powers granted to the EU AI Office, which was officially established in 2024 as the core enforcement body responsible for regulating general-purpose AI models.
For the model providers singled out, responding to an RFI means disclosing information that may have previously been treated as trade secrets — such as training data sources, parameter scales, evaluation results, and systemic risk mitigation measures. This poses a significant challenge for vendors whose core competitive moat is built on closed-source models.
Focusing on General-Purpose AI Models
The EU's decision to target General-Purpose AI (GPAI) model providers follows a clear logic. GPAIs are foundation models pre-trained on massive datasets and capable of performing a wide range of tasks — the GPT series, Claude, Gemini, Llama, and others all fall into this category. Unlike specialized AI systems (such as models used solely for medical imaging diagnosis), GPAI's generality means that developers cannot fully anticipate during training which downstream scenarios a model will be used in. This inherent uncertainty itself constitutes a unique governance challenge.
The AI Act adopts a risk-based tiered regulatory approach, classifying AI systems into four risk categories: unacceptable risk (e.g., social credit scoring systems, which are outright banned), high risk (e.g., AI used for recruitment screening or credit assessment, subject to strict compliance requirements), limited risk (e.g., chatbots, which must fulfill transparency obligations), and minimal risk (e.g., spam filters, with essentially no additional requirements). This tiered approach draws on the EU's mature experience in areas such as product safety and chemical management (e.g., the REACH regulation), with the core logic of concentrating regulatory resources on areas of greatest potential harm while avoiding unnecessary burdens on low-risk applications.
Within this framework, large foundation models with broad capabilities and the potential to pose "systemic risk" are squarely in the regulatory crosshairs. The EU AI Act further divides GPAI into two tiers: general GPAI must meet basic transparency obligations, while GPAI deemed to carry "systemic risk" (one criterion being training compute exceeding 10²⁵ FLOPs) must shoulder stricter obligations, including conducting model evaluations, performing adversarial testing (red-teaming), and reporting serious safety incidents to regulators. When problems arise with such models, their impact is amplified through countless downstream applications. Regulators' choice to intervene at the source is therefore a natural consequence of their risk governance logic.
What This Means for AI Vendors
From a compliance perspective, companies that receive an RFI face a triple squeeze:
- Transparency pressure: The Act requires model providers to publish technical documentation and training data summaries, and to comply with EU copyright rules.
- Risk assessment pressure: Models with systemic risk must undergo adversarial testing, report serious incidents, and ensure cybersecurity.
- Time pressure: RFIs typically come with strict response deadlines, requiring companies to rapidly mobilize cross-functional teams spanning legal, engineering, and compliance.
In Hacker News discussions, many practitioners have pointed out that this type of regulation affects large vendors and startups asymmetrically. Major companies have dedicated legal and compliance teams that can handle RFIs with relative ease, while resource-constrained smaller teams may be forced to scale back European operations — or even choose not to serve the EU market at all — due to prohibitive compliance costs.
This "Compliance Gap" is a classic topic in regulatory economics. During the early days of GDPR implementation, extensive research showed that compliance costs disproportionately impact companies of different sizes: large tech companies spent less than 1% of revenue on GDPR compliance on average, while small and medium enterprises could see compliance expenditures reach 3%-5% of revenue or more. In the context of the AI Act, this problem may be even more pronounced, because AI compliance involves not just legal paperwork but also technical tasks such as model evaluation, adversarial testing, and continuous monitoring — all of which require specialized talent and compute resources. The EU has attempted to mitigate this through the establishment of "Regulatory Sandboxes," where SMEs and startups can test innovative products under regulatory guidance, reducing the cost of compliance trial and error. Nevertheless, whether the compliance gap will undermine the competitive vitality of Europe's AI ecosystem has become one of the key points of contention.
The Eternal Tension Between Innovation and Regulation
Two camps have consistently emerged in debates surrounding enforcement of the EU AI Act.
Supporters argue that a clear regulatory framework actually provides the industry with certainty. When companies understand where the "red lines" are, they can allocate compliance resources more strategically. Moreover, regulation helps build public trust in AI technology — and that trust is essential for the technology's long-term adoption.
Critics worry that over-regulation will stifle innovation. They point out that the EU already fell behind the US and China in previous technology waves — mobile internet, cloud computing — and that imposing heavy compliance burdens on AI could widen the gap further. Some commentators even fear that stringent rules will accelerate the concentration of AI innovation hubs in regions with more lenient regulatory environments.
This tension is not unique to the EU; it is a shared dilemma in global AI governance. The EU's "legislate first, enforce strictly" approach stands in sharp contrast to the US model, which is relatively decentralized and relies heavily on industry self-regulation. The US has long favored "light-touch regulation," preferring to address AI risks through executive orders (such as the Biden administration's 2023 AI Executive Order), voluntary industry commitments, and existing legal frameworks (such as the Federal Trade Commission's anti-fraud authority), rather than enacting dedicated comprehensive AI legislation. This model's advantage lies in its flexibility and minimal suppression of innovation, but critics argue it lacks enforceability and systemic coherence. China has taken a third path, issuing specialized regulations for specific AI application scenarios (such as deep synthesis, generative AI, and algorithmic recommendations), forming a "case-by-case" regulatory model. Each of the three approaches has its pros and cons, and their long-term effectiveness remains to be seen — only time will tell which path — or paths — prove most effective.
A Global Regulatory Bellwether
A key feature of the EU AI Act is its extraterritorial reach — as long as a model serves users in the EU market, the provider must comply with the relevant rules regardless of where it is registered. This design directly inherits the extraterritorial jurisdiction model of the GDPR. Columbia Law School professor Anu Bradford has termed this phenomenon the "Brussels Effect": given the enormous size of the EU single market (approximately 450 million consumers), companies often find it more cost-effective to adopt EU standards as the unified global standard for their products rather than maintaining multiple versions for different markets.
This means the impact of this round of RFIs extends far beyond European companies — all major global AI vendors must integrate EU compliance into the core of their product and operational strategies. Just as the General Data Protection Regulation (GDPR) reshaped global data privacy practices — the GDPR profoundly influenced global privacy protection through the Brussels Effect, with many non-EU countries (such as Brazil's LGPD and Japan's amended APPI) clearly drawing on the GDPR framework in their own legislation — the EU AI Act is likely to become the de facto global standard for AI regulation. Other countries and regions will most likely reference the EU's tiered approach and enforcement experience when crafting their own AI policies. The issuance of this first batch of RFIs marks a critical starting point in this global process.
Conclusion
The issuance of the first RFIs marks the official transition of AI regulation from the "legislative era" to the "enforcement era." For AI vendors, compliance is no longer something that can be postponed — it is work that must begin immediately. For the industry as a whole, how to maintain innovative vitality while playing by the rules will be the central question of an ongoing tug-of-war for years to come.
Regardless of how this step by the EU is ultimately judged, it is destined to leave a lasting mark on the history of global AI governance.
Related articles

iPhone Duo: Apple's Foldable Phone Development in Full Swing
Apple launches iPhone Duo foldable phone developer preview with tech videos, Group Labs, and forums. Learn about its dual-screen design and dev preparation.

CUDA Toolkit 13.4 Released: Windows on Arm Support and Fine-Grained GPU Resource Control
NVIDIA CUDA Toolkit 13.4 adds native Windows on Arm support and fine-grained shared GPU management. A deep dive into cross-platform development and multi-tenant resource optimization.

EPD Disaggregation: A Deep Dive into Inference Acceleration for Multimodal Models
Learn how EPD disaggregation accelerates multimodal model inference by decoupling vision encoding, prefill, and decode stages for independent optimization and scaling.