Reglog

← Guides & analysis

What happens when the Commission investigates your AI model — the new procedural rules, in force since 10 August 2026

· 10 min read

On 10 August 2026, a piece of the EU AI Act's enforcement machinery quietly took effect. Commission Implementing Regulation (EU) 2026/1755 sets out how the Commission actually conducts an investigation into a general-purpose AI model — what it can demand to see, who does the testing, how long you get to respond, and how long the Commission has to act.

It was adopted on 20 July 2026 and published in the Official Journal on 21 July. Article 15 brings it into force "on the twentieth day following that of its publication", which is 10 August 2026. It arrived without the announcement that accompanied the August enforcement milestones — no press release, and a commencement date that falls in the middle of the institutional summer. It is nonetheless in force.

This is an information service to help you plan, not legal advice. For the obligations tied to your own AI use, see which apply to your company.

What it covers — and what it does not

Precision matters here, because the AI Act now has two separate enforcement tracks and they are easy to confuse.

Article 1 of the Implementing Regulation limits it to two things:

  • detailed arrangements and conditions for evaluations of general-purpose AI models under Article 92 of the AI Act, including how independent experts are involved and selected; and
  • detailed arrangements and procedural safeguards for proceedings that may end in a decision under Article 101(1) — the provision that lets the Commission fine a general-purpose AI model provider.

So this instrument is about general-purpose AI models. It is not the procedure for the AI Office's newer supervisory powers over AI systems, which the Digital Omnibus created as Articles 75a–75d of the AI Act. Those are a different track with a different legal basis. If you deploy an AI system rather than provide a model, this regulation is not the one that governs your file.

Worth noting: Articles 91, 92 and 101 of the AI Act were not amended by the Digital Omnibus. This procedure sits on top of provisions that are unchanged since 2024.

Who this actually binds

Providers of general-purpose AI models — and that is a narrower group than "companies using AI".

If you build on someone else's model, the question is whether your modification makes you a provider in your own right. The Commission's guidelines on general-purpose AI obligations say that actors modifying or fine-tuning a model "are not automatically subject to all the obligations for providers of general-purpose AI models", and become providers "only in exceptional circumstances" — with the indicative criterion being that the modification used more than one third of the original model's training compute.

For nearly all ordinary fine-tuning, adaptation and prompt-engineering work, that threshold is nowhere close to being met. Note also that those guidelines are not legally binding: as the Commission itself states, "an authoritative interpretation of the AI Act may only be given by the Court of Justice of the European Union."

Not sure which side of the provider line you sit on? Answer three questions about your AI use and we will show you the obligations that actually attach to your role.

What triggers an evaluation in the first place

Under Article 92 of the AI Act, the AI Office may evaluate a general-purpose AI model in order to:

  • assess compliance where the information gathered through an Article 91 information request "is insufficient"; or
  • investigate systemic risks, in particular following a qualified alert from the scientific panel.

In other words, an evaluation is normally the second step. The first is a documentation request. The Implementing Regulation governs what happens once the Commission decides that documentation was not enough.

The access the Commission can demand

This is the part of the instrument with the sharpest teeth. Article 2(2) lists what access to a model may include:

"access through application programming interfaces ('APIs'), internal access, access to source code, access to model weights, access to the infrastructure used for hosting the general-purpose AI model, access to inspect and modify the system state during interaction with the model."

And it adds that such access "may include but is not limited to all levels of access granted to employees of the provider". Providers must ensure the access given "is not subject to technical or other constraints that materially impede an appropriate evaluation."

Article 2(3) goes further still. The Commission "may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process."

Read that twice if you provide a model: the regulator may require that it be able to probe your model without you being able to observe what it probed.

The consequence of refusing is not abstract. Under Article 101(1) of the AI Act, failing "to make available to the Commission access to the general-purpose AI model ... with a view to conducting an evaluation pursuant to Article 92" is one of the listed grounds for a fine of up to 3% of total worldwide annual turnover or €15 million, whichever is higher. For how that compares with the rest of the Act's penalty structure, see EU AI Act penalties: how much are the fines?

Who does the testing, and how you can object

The Commission can appoint independent experts to evaluate on its behalf. Article 3 sets out how their independence is assessed: shared ownership, governance, management, personnel or resources; prior appointments; and "the existence of contractual relationships between the expert and the provider concerned or any other provider over at least the 12 months prior" to the evaluation. Each expert files a declaration of interest and must maintain information-security protocols throughout.

Providers are not powerless here. Under Article 3(5) a provider "may submit reasoned observations regarding the independent experts appointed to conduct the evaluation of their model". The Commission may terminate an appointment where a material change casts "serious doubt" on independence, where the expert fails on confidentiality, or where a provider's observations "manifestly and unequivocally prove" the independence criteria are absent — a deliberately high bar.

Experts may come from a standing list built through a call for expression of interest, directly from the Article 68 scientific panel, or through EU procurement rules.

Interim measures can land before proceedings even open

Article 5(3) is the provision most likely to surprise people. Before opening proceedings, the Commission may by decision order interim measures

"on grounds of urgency due to a risk of serious damage to health, safety requirements, or other grounds relating to the public interest covered by Regulation (EU) 2024/1689, including preventing a general-purpose AI model from being made available on the market, based on a prima facie finding of an infringement."

A prima facie finding — not a proven one — can support taking a model off the EU market on an interim basis. Separately, Article 5(2) confirms the Commission may use its investigative powers before formally opening proceedings at all.

If proceedings are opened and then closed for lack of grounds, Article 6(2) lets the Commission reopen them — including where its earlier decision rested on "incomplete, incorrect, or misleading information", or where there is "a significant change to the systemic risks posed by the general-purpose AI model concerned at Union level."

Your right to be heard has a format, a page limit and a clock

Before fining you, the Commission must communicate preliminary findings and hear you. The Implementing Regulation makes that concrete:

Requirement Rule Source
Time to respond Set by the Commission, but no less than 21 days Art. 7(2)
Late submissions Commission "shall not be obliged to take account of" them Art. 7(2)
Length Maximum 50 pages; evidential annexes excluded Annex
Format A4, ≥12pt body text, single spacing, ≥2.5cm margins, max 4 700 characters per page Annex
Language Any official EU language Art. 7(4)
Filing method Digital, signed with a Qualified Electronic Signature under Regulation (EU) 910/2014 Art. 14(1)–(2)
Extensions Possible on a reasoned request made before the deadline expires Art. 13(2)

Two practical traps sit in that table. The first is the 21-day floor combined with the Commission's freedom to disregard late material — for a technically complex model evaluation, three weeks is not long, and the extension must be requested before expiry. The second is the Qualified Electronic Signature requirement: a provider without eIDAS-qualified signing already in place cannot validly file at all. That is an administrative problem to solve before you need it, not during.

Access to the Commission's file follows an antitrust-style confidentiality ring (Articles 8–9): disclosure to named external counsel and technical experts under terms of disclosure, who must not be your employees, who carry a notification duty for three years after the investigation ends, and who may use the documents only for those proceedings.

The five-year clock, and what restarts it

Article 10 introduces a limitation period the AI Act itself did not spell out:

"The Commission may adopt a decision fining a specific provider of general-purpose AI model for conduct listed in Article 101(1) of Regulation (EU) 2024/1689 within five years from the day on which that conduct was carried out by that provider."

For continuing or repeated conduct, the five years run from the day the conduct ceases. The period is interrupted — and starts running afresh — by any investigative action, which Article 10(3) lists as:

  • requests for documentation or other information;
  • requests for access to conduct model evaluations;
  • invitations to a structured dialogue;
  • the opening of a proceeding.

There is a long-stop: the period expires at the latest once "a period equal to twice the limitation period has elapsed" without a fine, extended by any suspension while the matter is before the Court of Justice. A separate five-year period governs enforcement of a fine already imposed (Article 11).

The item worth internalising is the third bullet. An invitation to a structured dialogue sounds like the cooperative, pre-enforcement conversation — and it is. It also legally resets a five-year clock. Cooperative contact from the AI Office is not the same thing as the matter going away.

What to do if you provide a general-purpose AI model

  1. Confirm whether you are actually a provider. For most companies building on third-party models the answer is no, and none of this applies. The one-third-of-training-compute criterion is the place to start.
  2. Work out today how you would grant Article 2 access. Weights, source code, hosting infrastructure and state inspection are not things most organisations can expose to an outside party on a deadline without preparation — or without a plan for how to do it securely.
  3. Get eIDAS-qualified signing in place. It is a prerequisite for filing anything, and it is a procurement task, not a legal one.
  4. Treat any AI Office contact as clock-relevant. An information request or an invitation to a structured dialogue restarts the five-year period. Log the date.
  5. Set your record-retention horizon against five years, not the fiscal year. With interruptions and the long-stop, exposure can run substantially longer than the headline period.

For the wider phased calendar this sits inside, see the EU AI Act timeline. Because procedural instruments like this one arrive without announcements, join the waitlist and we will tell you when something that affects your obligations changes.

The official texts are Regulation (EU) 2024/1689 (the AI Act) and Commission Implementing Regulation (EU) 2026/1755 (OJ L, 2026/1755, 21.7.2026). This article is an information service to help you orient — it is not legal advice, and you should confirm the position against the official sources before acting.

Frequently asked questions

What is Implementing Regulation (EU) 2026/1755?

It is a Commission implementing regulation, adopted on 20 July 2026 and published in the Official Journal on 21 July 2026, that lays down the detailed procedure for two things under the EU AI Act: evaluations of general-purpose AI models under Article 92, and proceedings that may lead to a fine on a general-purpose AI model provider under Article 101(1). It entered into force on the twentieth day following publication, which is 10 August 2026.

Can the European Commission demand access to AI model weights?

Yes, where it has decided to evaluate a general-purpose AI model under Article 92 of the AI Act. Article 2(2) of Implementing Regulation (EU) 2026/1755 states that access may include APIs, internal access, source code, model weights, the hosting infrastructure, and the ability to inspect and modify the system state during interaction with the model, and that it may include all levels of access granted to the provider's own employees. Refusing that access is itself grounds for a fine under Article 101(1) of the AI Act.

How long does the Commission have to fine a general-purpose AI model provider?

Five years from the day the conduct was carried out, under Article 10 of Implementing Regulation (EU) 2026/1755, or from the day the conduct ceased if it was continuing or repeated. The period is interrupted — and starts running afresh — by any investigative step, including a request for information, a request for access to conduct a model evaluation, an invitation to a structured dialogue, or the opening of proceedings. It cannot run beyond twice the limitation period, and it is suspended while the matter is before the Court of Justice.

Does this apply to companies that fine-tune an existing AI model?

Usually not. These rules bind providers of general-purpose AI models. Under the Commission's guidelines on general-purpose AI obligations, a downstream actor who modifies or fine-tunes someone else's model becomes a provider only in exceptional circumstances — the indicative criterion is that the modification used more than one third of the original model's training compute. Those guidelines are not legally binding; only the Court of Justice can authoritatively interpret the AI Act.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.