News Weekly
LV 10 XP
0% read
S34governance
#34 Issue #1Confirmed

EU AI Act: first systemic-risk GPAI evaluations due September 15

The week of September 10–17, 2026 sits inside the first real enforcement cycle of the EU AI Act's GPAI regime. Sequence of events (FACT unless labelled): 31 July 2026 (announcement, pre-window context): Commission press release "Commission starts enforcing AI Act rules and new transparency requirements" — as of 2 August 2026 the Commission (via the AI Office) can exercise its GPAI enforcement powers: request information and documentation (Article 91), conduct evaluations of GPAI models (Article 92), request measures including risk-mitigation and market-recall steps (Article 93), and impose fines of up to 3% of global annual turnover or €15 million, whichever is higher (Article 101). Algorithmic-transparency rules (Article 50: chatbots, deepfakes) became enforceable on the same date. 1 September 2026: the Commission sent its first information requests to 30+ AI companies, in two streams: (1) safety- and security-related requests under Article 91 (systemic-risk models: evaluations, risk mitigation, incident reporting, cybersecurity) and (2) copyright/transparency requests under Article 53 (training-content summaries, copyright compliance policy). (COMMISSION ACTION per law-firm and policy-blog reporting — Allegiance Law, Magica, EU Perspectives; the requests themselves were announced by the Commission, i.e., a company/institutional claim, echoed by secondary sources.) 8 September 2026: TechTimes reports OpenAI filed the first serious-incident report under Article 55(1)(c) with the AI Office, with OpenAI's chief scientist reportedly admitting a monitoring gap in incident detection. (SECONDARY REPORTING per TechTimes; not independently confirmed with the AI Office. INTERPRETATION: the first public exercise of the GPAI serious-incident-reporting pipeline.) 10 September 2026: POLITICO Europe covers the EU's response to frontier-AI "extinction warnings", including the AI Office's contracting of evaluation capacity with METR (Model Evaluation and Threat Research) — the office is building the technical muscle to use its new Article 92 evaluation power credibly. 15 September 2026 (the in-window event): per Enterprise DNA (8 Sep 2026) and the September press wave, providers of systemic-risk GPAI models (presumed over the ~10^25 FLOP training-compute threshold) were due to submit their first-round systemic-risk model evaluations to the AI Office — red-teaming/adversarial-testing methodology and results (Art 55(1)(a)), systemic-risk assessments (Art 55(1)(b)), plus the related transparency package: energy-consumption disclosures and copyright training-summary template compliance (Art 53). On the same date the first compliance inspection wave of high-risk AI systems began across the Union — targeting HR/resume screening, retail banking/credit scoring, and healthcare/AI triage — co-led by the French CNIL, German BfDI and Spanish AESIA together with the AI Office, spanning the 24 Member State market surveillance authorities (MSAs). 16 September 2026: Lawfare (Eliška Andrš) publishes "You Don't Have to Sell It to Be Bound by It — GPAI and the EU AI Act", a governance analysis arguing Chapter V binds providers of systemic-risk GPAI models even where the model is deployed internally rather than "placed on the market" — significant because GPAI obligations are typically framed around market placement, yet Articles 51/55 attach systemic-risk duties to the model's high-impact capabilities regardless of how it is made available.

A compliance calendar wall with one aperture opening accepts ordered dossiers while mobile lens units inspect a grid of identical system cabinets.
How do you want to read this?

Tailored emphasis while keeping the full article available.

Best for you · Decision maker

▥ Enterprise and strategic impact, risks, and the actions to take.

At a glance

The essential information in 30 seconds

What happened

The week of September 10–17, 2026 sits inside the first real enforcement cycle of the EU AI Act's GPAI regime. Sequence of events (FACT unless labelled):

  • 31 July 2026 (announcement, pre-window context): Commission press release "Commission starts enforcing AI Act rules and new transparency requirements" — as of 2 August 2026 the Commission (via the AI Office) can exercise its GPAI enforcement powers: request information and documentation (Article 91), conduct evaluations of GPAI models (Article 92), request measures including risk-mitigation and market-recall steps (Article 93), and impose fines of up to 3% of global annual turnover or €15 million, whichever is higher (Article 101). Algorithmic-transparency rules (Article 50: chatbots, deepfakes) became enforceable on the same date.
  • 1 September 2026: the Commission sent its first information requests to 30+ AI companies, in two streams: (1) safety- and security-related requests under Article 91 (systemic-risk models: evaluations, risk mitigation, incident reporting, cybersecurity) and (2) copyright/transparency requests under Article 53 (training-content summaries, copyright compliance policy). (COMMISSION ACTION per law-firm and policy-blog reporting — Allegiance Law, Magica, EU Perspectives; the requests themselves were announced by the Commission, i.e., a company/institutional claim, echoed by secondary sources.)
  • 8 September 2026: TechTimes reports OpenAI filed the first serious-incident report under Article 55(1)(c) with the AI Office, with OpenAI's chief scientist reportedly admitting a monitoring gap in incident detection. (SECONDARY REPORTING per TechTimes; not independently confirmed with the AI Office. INTERPRETATION: the first public exercise of the GPAI serious-incident-reporting pipeline.)
  • 10 September 2026: POLITICO Europe covers the EU's response to frontier-AI "extinction warnings", including the AI Office's contracting of evaluation capacity with METR (Model Evaluation and Threat Research) — the office is building the technical muscle to use its new Article 92 evaluation power credibly.
  • 15 September 2026 (the in-window event): per Enterprise DNA (8 Sep 2026) and the September press wave, providers of systemic-risk GPAI models (presumed over the ~10^25 FLOP training-compute threshold) were due to submit their first-round systemic-risk model evaluations to the AI Office — red-teaming/adversarial-testing methodology and results (Art 55(1)(a)), systemic-risk assessments (Art 55(1)(b)), plus the related transparency package: energy-consumption disclosures and copyright training-summary template compliance (Art 53). On the same date the first compliance inspection wave of high-risk AI systems began across the Union — targeting HR/resume screening, retail banking/credit scoring, and healthcare/AI triage — co-led by the French CNIL, German BfDI and Spanish AESIA together with the AI Office, spanning the 24 Member State market surveillance authorities (MSAs).
  • 16 September 2026: Lawfare (Eliška Andrš) publishes "You Don't Have to Sell It to Be Bound by It — GPAI and the EU AI Act", a governance analysis arguing Chapter V binds providers of systemic-risk GPAI models even where the model is deployed internally rather than "placed on the market" — significant because GPAI obligations are typically framed around market placement, yet Articles 51/55 attach systemic-risk duties to the model's high-impact capabilities regardless of how it is made available.

The Act-vs-implemented deadline distinction (FACT + INTERPRETATION): Article 113(b) made Chapter V (Articles 51–56) applicable from 2 August 2025 — so model evaluations, adversarial testing, serious-incident reporting and cybersecurity were already legal obligations before September 2026. What changed in the current window is that the enforcement machinery became operative (2 August 2026 powers), the Commission began issuing Article 91 requests (1 September 2026), and the 15 September milestone is the first concrete administrative submission date for evaluation documentation inside that machinery. No calendar date for evaluation submissions appears in the Act itself; "September 15" is the AI Office's implemented first-milestone date as reported by the press. Any statement that "the AI Act requires evaluations by September 15" as a statutory deadline is therefore an oversimplification of a real operational deadline.


Why it matters
  • The first enforceable frontier-model compliance deadline in the world (discovery's why_it_matters): California's SB 53/AB 54-style laws and voluntary commitments set precedents, but no other jurisdiction had, by Sep 2026, combined a hard model-evaluation obligation with information powers, an inspection apparatus and a turnover-linked fine. The EU is defining what "regulated frontier AI" means operationally.
  • Evaluation evidence is now a regulated asset: adversarial-testing outputs move from safety-team internal documents into regulator-submitted records with legal consequences — reshaping how labs resource red-teaming.
  • A working model for supervision: the AI Office–METR contract (POLITICO Europe) shows the EU buying third-party evaluation capacity, effectively outsourcing the "ARIA-style" technical scrutiny the Act's authors knew the office could not build in-house — a model other regulators will copy.
  • Copyright enforcement enters the frontier: Article 53 training-content-summary requests put EU copyright law into the frontier-training pipeline — the second front of this enforcement cycle alongside safety.
  • Signal to enterprises and deployers: inspection wave = deployer-side diligence becomes enforceable now, in the highest-visibility sectors (HR, banking, healthcare) — not in 2028.

Evidence

CONFIRMED

27 sources · 78 min read
Story identity
  • Story ID: S34
  • Title: EU AI Act: first systemic-risk GPAI evaluations due September 15
  • Organization: European Commission (AI Office / Directorate-General for Communications Networks, Content and Technology, digital-strategy)
  • Category: governance
  • Event date: 2026-09-15 — CONFIRMED in-window (2026-09-15 ∈ [2026-09-10, 2026-09-17])
  • Evidence status: CONFIRMED (event and legal framework corroborated by official Commission pages and press releases, the primary Regulation (EU) 2024/1689 text via EUR-Lex and the AI Act Explorer, plus multiple independent outlets — Lawfare, POLITICO Europe, Enterprise DNA, Slaughter and May, CSA)
  • Confidence: High
  • What it is: The first operational milestone of the EU AI Act's enforcement of obligations on general-purpose AI (GPAI) models with systemic risk. Providers whose models are presumed to present systemic risk (training compute above the ~10^25 FLOP threshold, Article 52) were due by September 15, 2026 to have their first-round systemic-risk model evaluations — including adversarial testing documentation under Article 55(1)(a) — in the AI Office's hands, as part of the first enforcement wave that became legally operative on 2 August 2026, running in parallel with the first coordinated compliance inspections of high-risk AI systems in HR, retail banking and healthcare across 24 Member States. Critical nuance (FACT vs INTERPRETATION): the Act itself contains no calendar date for evaluations — Article 55 obligations have applied since 2 August 2025 (Article 113(b)); September 15, 2026 is the implemented/operational first submission milestone inside the AI Office's supervision agenda, as reported by Enterprise DNA and mirrored across the September press (adversarial-testing/red-teaming methodology reports, energy-consumption disclosures, copyright training-summary template compliance).

✓

What happened?

The week of September 10–17, 2026 sits inside the first real enforcement cycle of the EU AI Act's GPAI regime. Sequence of events (FACT unless labelled):

  • 31 July 2026 (announcement, pre-window context): Commission press release "Commission starts enforcing AI Act rules and new transparency requirements" — as of 2 August 2026 the Commission (via the AI Office) can exercise its GPAI enforcement powers: request information and documentation (Article 91), conduct evaluations of GPAI models (Article 92), request measures including risk-mitigation and market-recall steps (Article 93), and impose fines of up to 3% of global annual turnover or €15 million, whichever is higher (Article 101). Algorithmic-transparency rules (Article 50: chatbots, deepfakes) became enforceable on the same date.
  • 1 September 2026: the Commission sent its first information requests to 30+ AI companies, in two streams: (1) safety- and security-related requests under Article 91 (systemic-risk models: evaluations, risk mitigation, incident reporting, cybersecurity) and (2) copyright/transparency requests under Article 53 (training-content summaries, copyright compliance policy). (COMMISSION ACTION per law-firm and policy-blog reporting — Allegiance Law, Magica, EU Perspectives; the requests themselves were announced by the Commission, i.e., a company/institutional claim, echoed by secondary sources.)
  • 8 September 2026: TechTimes reports OpenAI filed the first serious-incident report under Article 55(1)(c) with the AI Office, with OpenAI's chief scientist reportedly admitting a monitoring gap in incident detection. (SECONDARY REPORTING per TechTimes; not independently confirmed with the AI Office. INTERPRETATION: the first public exercise of the GPAI serious-incident-reporting pipeline.)
  • 10 September 2026: POLITICO Europe covers the EU's response to frontier-AI "extinction warnings", including the AI Office's contracting of evaluation capacity with METR (Model Evaluation and Threat Research) — the office is building the technical muscle to use its new Article 92 evaluation power credibly.
  • 15 September 2026 (the in-window event): per Enterprise DNA (8 Sep 2026) and the September press wave, providers of systemic-risk GPAI models (presumed over the ~10^25 FLOP training-compute threshold) were due to submit their first-round systemic-risk model evaluations to the AI Office — red-teaming/adversarial-testing methodology and results (Art 55(1)(a)), systemic-risk assessments (Art 55(1)(b)), plus the related transparency package: energy-consumption disclosures and copyright training-summary template compliance (Art 53). On the same date the first compliance inspection wave of high-risk AI systems began across the Union — targeting HR/resume screening, retail banking/credit scoring, and healthcare/AI triage — co-led by the French CNIL, German BfDI and Spanish AESIA together with the AI Office, spanning the 24 Member State market surveillance authorities (MSAs).
  • 16 September 2026: Lawfare (Eliška Andrš) publishes "You Don't Have to Sell It to Be Bound by It — GPAI and the EU AI Act", a governance analysis arguing Chapter V binds providers of systemic-risk GPAI models even where the model is deployed internally rather than "placed on the market" — significant because GPAI obligations are typically framed around market placement, yet Articles 51/55 attach systemic-risk duties to the model's high-impact capabilities regardless of how it is made available.

The Act-vs-implemented deadline distinction (FACT + INTERPRETATION): Article 113(b) made Chapter V (Articles 51–56) applicable from 2 August 2025 — so model evaluations, adversarial testing, serious-incident reporting and cybersecurity were already legal obligations before September 2026. What changed in the current window is that the enforcement machinery became operative (2 August 2026 powers), the Commission began issuing Article 91 requests (1 September 2026), and the 15 September milestone is the first concrete administrative submission date for evaluation documentation inside that machinery. No calendar date for evaluation submissions appears in the Act itself; "September 15" is the AI Office's implemented first-milestone date as reported by the press. Any statement that "the AI Act requires evaluations by September 15" as a statutory deadline is therefore an oversimplification of a real operational deadline.


Δ

What changed?

  • First enforceable frontier-model compliance milestone in the world (discovery's core claim): earlier deadlines (prohibitions Feb 2025; GPAI obligations Aug 2025) had no operational supervision behind them; September 2026 is the first time frontier labs face a concrete, inspector-backed submission date for evaluation evidence, backed by a functional fining power (Art 101).
  • Hands-on supervision of frontier labs became real: the AI Office now runs an actual enforcement cycle — information requests (Art 91), evaluations (Art 92), requested measures (Art 93) — against the operators of the most capable models, with METR-style evaluation capacity contracted in (POLITICO Europe).
  • Adversarial testing moved from research practice to regulated deliverable: red-teaming results are now documentation a lab must produce on a schedule, to a standard the regulator can interrogate — not just a safety-benchmark scorecard.
  • Inspection wave for high-risk AI systems began in parallel: HR, retail banking and healthcare deployers (not just model providers) now face MSA inspections requiring evidence of AI Act compliance documentation — the first sectoral enforcement of the deployer-side regime (postponed Annex III obligations to 2 Dec 2027 do not stop inspections of systems whose obligations applied from Aug 2025/2026).
  • Copyright/transparency enforcement started: first Article 53 information requests (training-content summaries, copyright policy) pulled frontier providers into the copyright pipeline the Act created — a separate fight from safety evaluation.

↔

Before → Change → After

  • Before: Chapter V rights and duties existed on paper since 2 Aug 2025; the GPAI Code of Practice (assessed adequate; signatories incl. OpenAI, Anthropic, Google, Meta, Microsoft) was the voluntary vehicle; the AI Office could recommend but not compel; no information requests, no inspections, no fines for GPAI providers (Art 101 excluded from the 2 Aug 2025 penalties date and became operable with the general application from 2 Aug 2026); serious-incident reports were a contractual, not enforceable, expectation.
  • Change (2 Aug–15 Sep 2026): enforcement powers live (2 Aug); first Article 91 information requests to 30+ companies (1 Sep); first Article 55(1)(c) serious-incident report filed (8 Sep); systemic-risk evaluation submissions due (15 Sep); first MSA inspection wave in HR/banking/healthcare begins (15 Sep); evaluation capacity being contracted (METR).
  • After: frontier labs operate under a standing EU supervision cycle — submissions, evaluations, follow-up requests, and the credible prospect of Article 101 fines (€15M/3% worldwide turnover) for intentional/negligent failure; evaluation evidence becomes a regulated input into both EU enforcement and the labs' own public safety narratives; deployments of high-risk AI in EU HR, banking and healthcare face inspector scrutiny; the precedent exists for the rest of the world's regulators (US, UK, Canada, Japan) to benchmark against.

⚙

How it works

Legal mechanics (FACT, per Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744):

  1. Classification (Arts 51–52): a GPAI model is classified as presenting systemic risk either by Commission decision or — presumptively — where cumulative training compute exceeds 10^25 FLOP (Art 52; criteria in Annex XIII; Scientific Panel can alert the Commission under Art 90). Designation is by implementing act; providers may rebut with documented justifications (Art 51(2)).
  2. Obligations (Art 55(1)(a)–(d)): providers of systemic-risk GPAI models must, in addition to Arts 53–54: (a) perform model evaluation in accordance with state-of-the-art standardised protocols and tools, including conducting and documenting adversarial testing, to identify and mitigate systemic risks; (b) assess and mitigate possible systemic risks at Union level, including their sources, from development, placing on the market, or use; (c) track, document and report serious incidents and corrective measures without undue delay to the AI Office (and national authorities as appropriate); (d) ensure adequate cybersecurity for the model and its physical infrastructure.
  3. Enforcement powers (Arts 88–94): the AI Office supervises GPAI providers (Art 88); monitoring actions (Art 89); power to request documentation and information (Art 91); power to conduct evaluations of the model, including with independent experts / third-party evaluation support such as METR (Art 92); power to request measures, including risk mitigation and market recall (Art 93); procedural rights of providers (Art 94).
  4. Fines (Art 101): up to €15 million or 3% of total worldwide annual turnover, whichever is higher, when the Commission finds intentional or negligent infringement of GPAI provisions, failure to comply with Art 91 requests or supply of incorrect/incomplete/misleading information, failure to comply with Art 93 measures, or failure to make the model available for an Art 92 evaluation. Court of Justice retains unlimited jurisdiction (Art 101(5)). Per the Commission's own framing and Praxikon's reading, Article 101 became operable on 2 August 2026 (excluded from the earlier Chapter XII application date).
  5. Compliance routes (Arts 55(2), 56): adherence to the GPAI Code of Practice assessed as adequate demonstrates compliance (not a full presumption of conformity) until harmonised standards are published; non-signatories must show alternative adequate means (e.g., a gap analysis vs the Code).
  6. Timing (Art 113; Omnibus amendments): in force 1 Aug 2024; prohibitions from 2 Feb 2025; Chapter V GPAI from 2 Aug 2025; most remaining provisions (incl. GPAI enforcement powers) from 2 Aug 2026; new Omnibus-added Article 5 prohibitions (sexual imagery/CSAM-related) from 2 Dec 2026; Annex III high-risk obligations deferred to 2 Dec 2027 and Annex I to 2 Aug 2028 by the Omnibus — Chapter V GPAI untouched by the deferral; models on the market before 2 Aug 2025 must fully comply with Chapter V by 2 August 2027 (Art 111(3)).
  7. The Sep 15 milestone: reported by Enterprise DNA (8 Sep 2026) and the September press wave as the first submission deadline for systemic-risk evaluation documentation (adversarial-testing methodology + results under Art 55(1)(a), systemic-risk assessment under 55(1)(b), plus energy-consumption and copyright training-summary transparency under Art 53) — an implementation date set inside the AI Office's supervision agenda rather than a date found in the Regulation (INTERPRETATION; the source basis is press reporting, not a directly verified AI Office notice).

!

Why it matters

▥ For Decision maker
  • The first enforceable frontier-model compliance deadline in the world (discovery's why_it_matters): California's SB 53/AB 54-style laws and voluntary commitments set precedents, but no other jurisdiction had, by Sep 2026, combined a hard model-evaluation obligation with information powers, an inspection apparatus and a turnover-linked fine. The EU is defining what "regulated frontier AI" means operationally.
  • Evaluation evidence is now a regulated asset: adversarial-testing outputs move from safety-team internal documents into regulator-submitted records with legal consequences — reshaping how labs resource red-teaming.
  • A working model for supervision: the AI Office–METR contract (POLITICO Europe) shows the EU buying third-party evaluation capacity, effectively outsourcing the "ARIA-style" technical scrutiny the Act's authors knew the office could not build in-house — a model other regulators will copy.
  • Copyright enforcement enters the frontier: Article 53 training-content-summary requests put EU copyright law into the frontier-training pipeline — the second front of this enforcement cycle alongside safety.
  • Signal to enterprises and deployers: inspection wave = deployer-side diligence becomes enforceable now, in the highest-visibility sectors (HR, banking, healthcare) — not in 2028.

✦

What became possible?

  • The AI Office can compel evaluation documentation, run its own model evaluations (Art 92) with third-party support (METR), and order risk-mitigation measures (Art 93) — a full supervisory loop over the most capable models.
  • Serious-incident transparency: Article 55(1)(c) reports create a regulator-facing record of frontier-model incidents (first exercised by OpenAI on 8 Sep 2026 per TechTimes).
  • Turnover-proportional fines make compliance economically non-optional for the largest labs.
  • Downstream deployers get an authoritative compliance signal to anchor procurement and risk due diligence (who has submitted, what gaps the AI Office flags).
  • Non-EU regulators gain a live experiment on which to calibrate their own regimes (US federal preemption fights, UK's pro-innovation posture, Japan's soft-law approach).

◎

Implications

▥ For Decision maker

Technical

  • Evaluation methodology is now a legal artifact: "standardised protocols and tools reflecting the state of the art" (Art 55(1)(a)) — the reference point is the Code of Practice's safety-and-security chapter; expect harmonised standards (EU) to crystallise shortly, and expect the AI Office to push for shared evaluation protocols (METR-style) across labs for comparability.
  • Red-teaming capacity gap exposed: OpenAI's own reported monitoring gap (TechTimes, 8 Sep) underscores that even top labs lack systematic incident detection — the gap the AI Office's Art 89 monitoring and Art 92 evaluations are designed to probe.
  • Energy disclosure becomes compliance data: energy-consumption reporting (Art 53-related transparency) is now a supporting compliance deliverable — environmental claims and compute-scale claims will be cross-checked against FLOP designations.
  • FLOP-threshold disputes will surface: as enforcement bites, labs will litigate the 10^25 FLOP presumption and the definition of training compute boundaries (what counts, clustering of models, hybrid/agent training runs) — technical interpretation becomes legal argument (cf. Cambridge Commentary's Article 51 paper).
  • Internal-deployment scope question (Lawfare, 16 Sep): whether "placing on the market" is required at all for systemic-risk duties is contested; if the Lawfare reading prevails, internally-deployed frontier models face the same obligations — widening the technical surface under enforcement.

Developer

  • Frontier-lab engineering teams must now operate evaluation pipelines as auditable, dated, versioned deliverables, with reproducible adversarial-testing documentation (protocol, scope, results, mitigations) ready for Art 91 requests — treat the Code of Practice safety chapter as the de-facto spec until harmonised standards land.
  • Incident-reporting hooks required: Art 55(1)(c) demands "track, document and report… without undue delay" — labs need automated serious-incident detection/reporting pipelines with AI Office contact paths; OpenAI's 8 Sep filing is the template others will be measured against.
  • Open-source nuance: free/open-source GPAI models are exempt from most Chapter V obligations unless they present systemic risk (Art 53/54 recitals) — open-weight systemic models (e.g., a future open-weights >10^25 FLOP release) carry the full obligation set, which will shape open-model release decisions.
  • Non-signatories face a documentation gap: providers who did not sign the Code must justify alternative means of compliance (e.g., CoP gap analysis) — the AI Office can and likely will use Art 91 to test those justifications.
  • Authorised representatives (Art 54): third-country providers need a mandated EU representative able to produce Annex XI technical documentation on request for 10 years — a live procurement item for non-EU labs.

Enterprise

  • Procurement diligence is now anchored in enforcement data: enterprises adopting GPAI-based tools can (and should) verify provider evaluation submissions, incident reports and AI Office measures; that information becomes the due-diligence baseline, replacing vendor self-certification.
  • HR, banking and healthcare deployers are in the first inspection wave: EU deployers of AI for resume screening, credit scoring and clinical triage must evidence risk-management, data governance, human-oversight and logging documentation (Arts 8–15) under MSA inspection — the enforcement wave is deployer-facing, not just model-facing; the Omnibus postponement of Annex III obligations to Dec 2027 does not suspend MSAs' powers to inspect systems whose duties already apply.
  • Cross-border operations: US and Asian enterprises with EU subsidiaries face dual supervision (AI Office at model layer + national MSAs at deployer layer); central compliance teams need a single evidence repository feeding both.
  • Legal-risk budgeting: Art 101 fines (€15M/3% turnover) sit above GDPR-level exposure for the largest labs; enterprises should treat GPAI non-compliance of material vendors as a concentration risk in vendor risk registers.

Strategic

  • The EU is now the world's frontier-AI regulator by default: with the US Congress stalled (per the broader week's reporting) and the UK/Japan non-intervening, Brussels is the only jurisdiction actively supervising frontier models in 2026 — the "Brussels effect" applied to AI capability governance.
  • Regulatory capture and credibility: the AI Office's dependence on contracted evaluators (METR) and on labs' own red-teaming begs the question of independence; how the office handles its first Art 92 evaluations will set or damage its credibility.
  • Divergence risk with the US: the enforcement wave sharpens EU–US divergence (EU: binding evaluations + fines; US: voluntary commitments, state-law patchwork), creating compliance arbitrage questions for global labs and possibly friction in transatlantic AI cooperation.
  • The extinction-risk politics arrived inside the machinery (POLITICO Europe): "extinction warnings" are no longer just a public debate — they are the justification for the enforcement architecture and for METR-type capacity, tying existential-risk discourse to concrete regulatory spending and powers.
  • Precedent-setting cascades: other regulators (Canada's AIDA, Japan, UK, Korea) will copy or contest the EU's evaluation-first enforcement; the Sep 15 milestone is the reference event they will measure themselves against.

⚠

Risks & limitations

▥ For Decision maker
Risks
  • Deadline confusion / legal certainty (INTERPRETATION): press increasingly reports "September 15" as if it were a statutory date; the Act has no such date, and the AI Office has not (as of this research) published an individually-verifiable notice for the milestone. Providers and advisors may over- or under-prepare depending on which reading they follow; a legally challenged first enforcement action on a non-statutory deadline would be an own goal.
  • Enforcement without public evidence: no public register yet confirms which providers submitted by Sep 15 or what the AI Office received; reporting (Enterprise DNA, TechTimes, Winzheng) is the only window into compliance status — a transparency gap the office must close to sustain credibility.
  • Inspection-wave friction: 24 MSAs with heterogeneous capacity and inclinations (CNIL/BfDI/AESIA lead) create enforcement-arbitrage and inconsistency risk; the Art 81/83 safeguard procedures may be tested early.
  • Industry pushback / legal challenge: expect appeals over Art 52 FLOP presumptions, Art 55(1)(a) "state of the art" methodology, and the internal-deployment scope question (Lawfare's analysis flags precisely this battleground).
  • Trade-secret vs transparency tension: Art 55 documentation is confidential (Art 78), but the Act's credibility depends on visible enforcement; over-secrecy will look like capture, under-secrecy will trigger litigation.
  • Evaluation-capacity dependency (POLITICO Europe): outsourcing core evaluations to METR-type contractors introduces its own risks — contractor availability, methodology disputes, neutrality perceptions — especially at the "extinction-level" stakes the office itself advertises.
  • Over-reach/under-reach balance: if the first wave produces no visible consequences, the threats (Art 101 fines) ring hollow; if it escalates to a headline fine quickly, expect accusations of politicised enforcement — the office's first Art 101 decision will be closely judged.

Limitations
  • No directly verified AI Office notice for "September 15": the milestone date is established via press reporting (Enterprise DNA 8 Sep 2026 as the primary written statement, echoed by Winzheng and others); the AI Office's own published calendar was not located during research.
  • Incident-report fact rests on one secondary outlet: the OpenAI Article 55(1)(c) filing (TechTimes, 8 Sep) is single-source; the AI Office has not confirmed receipt, and the "chief scientist admits monitoring gap" quote is a secondary paraphrase of a company figure (label: COMPANY CLAIM, reported).
  • Compliance status of individual labs unknown: no verified list of which providers were designated/presumed systemic-risk or which submitted by Sep 15; the "30+ companies" receiving RFIs is the Commission's own figure through law-firm summaries.
  • Effect of the Digital Omnibus on the wave is partially interpretive: the deferral of Annex III obligations (to 2 Dec 2027) and Annex I (to 2 Aug 2028) is confirmed (Regulation (EU) 2026/1744; Praxikon), but how MSAs sequence inspections of not-yet-fully-applicable Annex III systems is a legal reading, not a settled practice.
  • The discovery-named Engineering & Technology (8 Sep) article could not be located/verified and was therefore not used; no URL for it is listed in the sources artifact to avoid fabricating a citation.
  • Art 101 applicability date (2 Aug 2026) follows the Commission's framing and Praxikon; one secondary source (RegulatoryAI) gives a different (implausible) date (2 Dec 2027) — the Commission-aligned reading is used and the discrepancy is noted here.

?

Open questions

▥ For Decision maker
  1. Which providers were (a) presumed systemic-risk by the 10^25 FLOP threshold and (b) formally designated by implementing act — and which actually submitted evaluation documentation by Sep 15, 2026?
  2. What exactly did the Sep 15 submission package require, and is that requirement documented in an AI Office notice, a Code of Practice annex, or only in press reporting?
  3. Will the AI Office publish evaluation outcomes or a compliance register, or stay behind Article 78 confidentiality?
  4. When will the first Article 92 evaluation run, with which external evaluator (METR or another), and on which model?
  5. Will the first Article 101 fine land in 2026–27, and on which ground (infringement, info-request failure, requested-measure failure, or denial of Art 92 access)?
  6. Does the internal-deployment reading (Lawfare) survive judicial contact — i.e., are internally-deployed systemic models bound by Chapter V?
  7. How will FLOP-threshold disputes be adjudicated (training-compute definitions, model clustering, rebuttal evidence)?
  8. Which sectors get inspected second (after HR/banking/healthcare), and what enforcement findings will the 24 MSAs actually surface?
  9. How will the Code of Practice be updated (Art 56(8)) now that enforcement is live, and will harmonised standards for GPAI evaluation emerge before the next milestone?
  10. What will the pre-2-Aug-2025 grandfathered models (full Chapter V compliance due 2 Aug 2027) do differently versus new releases?

↗

What happens next?

  • Late Sep–Oct 2026 (near-term, FACT-adjacent/prediction): AI Office review of Sep 15 submissions; first documented Art 92 evaluations likely in Q4 2026 (with METR or similar); follow-up Article 93 requests where evaluations find unmitigated systemic risks; MSA inspection feedback in HR/banking/healthcare flowing to the Board and Safeguard procedures as needed.
  • 2 Dec 2026: new Article 5 prohibited practices (sexual-imagery/CSAM-related, added by the Omnibus) become applicable — the next hard date after the Sep milestone.
  • 2026–27 enforcement escalations (PREDICTION): first Article 101 fines before end-2027 (likely on Art 91 request failures or Art 92 access denials first, since those are easiest to prove); one or more legal challenges to FLOP presumptions at the General Court; a visible AI Office clash with a non-signatory provider over "alternative adequate means".
  • 2 Aug 2027: full Chapter V compliance for models placed on the market before 2 Aug 2025 (Art 111(3)) — a second, broader compliance cliff hitting older flagship models.
  • 2 Dec 2027 / 2 Aug 2028: Annex III and Annex I high-risk obligations apply (post-Omnibus dates); deployer-side enforcement in full swing; harmonised standards for GPAI evaluation likely consolidated by then.
  • 2027+ (PREDICTION): Code of Practice updated (Art 56(8)) with enforcement-learned refinements; other jurisdictions mirror or differentiate from the EU's evaluation-first model; the Sep-2026 wave is retrospectively seen as the moment EU frontier-AI enforcement became operational rather than symbolic.

★

Editorial takeaway

▥ For Decision maker

September 15, 2026 is the day the EU AI Act stopped being a compliance exercise and became an enforcement cycle. The headline — "first systemic-risk GPAI evaluations due" — is directionally true and globally significant, but the honest version contains two corrections the reporting mostly elides: the Act itself never sets a September 15 calendar date (the obligations have bound providers since August 2025; the deadline is the AI Office's implemented first-milestone inside a machinery that only became operational on 2 August 2026), and the actual enforcement teeth — information powers, regulator-run evaluations, requested measures, and €15M/3%-of-turnover fines — are all from Article 101-inflected Articles 88–94 that are being exercised for the very first time. Watch three things: whether the AI Office converts its milestone into published, verifiable facts (it has not yet); whether the first Article 92 evaluation and the first Article 101 fine are credible enough to matter; and whether the scope fight — does "placing on the market" even matter for systemic-risk duties, per Lawfare's analysis — lands in Luxembourg. In one sentence: the world's first enforceable frontier-model compliance deadline is real, it is operational, and the next twelve months will decide whether it becomes the global template or a cautionary tale in transatlantic divergence.


Evidence discipline summary: FACT (statutory provisions and dates as enacted — Art 51/52/53/54/55/56, 88–94, 101, 113 of Regulation (EU) 2024/1689; 2 Aug 2025 / 2 Aug 2026 / 2 Aug 2027 / 2 Dec 2026 / 2 Dec 2027 / 2 Aug 2028 dates; Digital Omnibus Regulation (EU) 2026/1744 deferrals; Art 101 fines 3%/€15M; Commission enforcement powers from 2 Aug 2026 per official press release); COMPANY CLAIM (Commission announcement of info requests to 30+ companies, echoed by law-firm summaries; OpenAI chief-scientist monitoring admission as reported by TechTimes); INDEPENDENT EVIDENCE (Lawfare scope analysis; POLITICO Europe on AI Office–METR; Enterprise DNA on the Sep 15 milestone and inspection wave; Slaughter and May and CSA enforcement-readiness briefings; Praxikon penalty-structure analysis); INTERPRETATION (Sep 15 as implemented/operational milestone vs statutory date; internal-deployment scope; Annex III inspection sequencing); PREDICTION (first Art 101 fines, FLOP-threshold litigation, CoP update, transatlantic divergence). The discovery-named E&T article could not be verified and was excluded. No rumours used.

One wide request channel forks into two streams: a braced safety rail ending at a heavy inspection gate, and a flexible sheets rail ending at an open logging desk.
⌘

Lab: NO-LAB

≡

Research sources

Primary Sources (6)
Primary
European Commission — AI Act Service Desk, "Article 101: Fines for providers of general-purpose AI models"Official summary of Art 101: fines up to 3% of global annual turnover or €15M (whichever higher) for intentional/negligent infringement, failure to comply with Art 91 requests or incorrect/misleading info, failure to comply with Art 93 measures, failure to make model available for Art 92 evaluations; CJEU unlimited jurisdiction. — Primary official corroboration of the fining mechanism. ---Date: live 2026 (accessed 2026-09)
Visit source ↗
Primary
EUR-Lex — Regulation (EU) 2024/1689 (the AI Act), consolidated textAuthoritative text of Articles 51/52/53/54/55/56 (Chapter V), 88–94 (AI Office powers), 99–101 (penalties incl. Art 101 fines €15M/3% for GPAI providers), 111 (transitional provisions), 113 (entry into force and application dates). — Primary legal text; statutory anchors for the analysis.Date: OJ L, 2024-07-12 (in force 2024-08-01)
Visit source ↗
Primary
European Commission — GPAI Q&A (printable PDF rendering of the above)Same content as #3, fetched as the printable PDF; confirms AI Office enforcement powers wording and Code of Practice adequacy/compliance mechanics. — Primary official text (alternate rendering).Date: PDF generated 13/09/2026
Visit source ↗
Primary
European Commission — "General-purpose AI models in the AI Act — Questions & Answers" (FAQs page)GPAI obligations applicable since 2 Aug 2025 (Art 113(b)); systemic-risk obligations incl. model evaluations, serious-incident reporting, cybersecurity (Art 55); AI Office powers (Arts 88–94: request information Art 91, evaluations Art 92, measures incl. market recall Art 93, fines Art 101); Code of Practice as compliance route (Arts 55(2)/56); special rules for models placed on the market before 2 Aug 2025 (Art 111). — Primary official Q&A; basis for the legal-mechanics section.Date: 2026 (PDF generated 2026-09-13 per the printable version)
Visit source ↗
Primary
European Commission — press release "Commission starts enforcing AI Act rules and new transparency requirements"From 2 August 2026 the Commission can exercise GPAI enforcement powers (request information under Art 91, conduct evaluations under Art 92, request measures/risk mitigations under Art 93, impose fines up to 3% of global turnover or €15M under Art 101); simultaneous enforcement of Article 50 transparency rules (chatbots, deepfakes). — Primary official announcement of the enforcement-wave start; anchors the 2 Aug 2026 date.Date: 2026-07-31
Visit source ↗
Primary
European Commission — "Enforcement of the AI Act" (policy hub)Enforcement framework and timeline; systemic-risk GPAI obligations (Article 55); AI Office powers (information requests, evaluations, measures, fines); Digital Omnibus deferrals (Annex III → 2 Dec 2027, Annex I → 2 Aug 2028) leaving GPAI/Chapter V untouched. — Primary official source for the enforcement architecture and dates.Date: page live 2026 (updated 2026-08-24 per page metadata)
Visit source ↗
Independent Sources (8)
Independent
AI Act Explorer (Future of Life Institute) — "Article 54: Authorised Representatives of Providers of General-Purpose AI Models"Verified full text of Art 54 (authorised representatives for third-country providers; Annex XI documentation retention, 10 years); confirms Art 54 is NOT the systemic-risk article (Article 55 is), correcting potential mislabeling. — Independent publisher of primary text; structural verification. ---Date: live 2026 (accessed 2026-09)
Visit source ↗
Independent
AI Act Explorer (Future of Life Institute) — "Article 55: Obligations of Providers of General-Purpose AI Models with Systemic Risk"Verified full text of Art 55(1)(a)–(d): model evaluation incl. adversarial testing; systemic-risk assessment/mitigation; serious-incident tracking/reporting to the AI Office; cybersecurity; applies from 2 Aug 2025 (Art 113(b)); Code of Practice compliance route (Art 55(2)); confidentiality (Art 78). — Independent publisher of primary text; statutory verification during this research.Date: live 2026 (accessed 2026-09)
Visit source ↗
Independent
AI Policy Bulletin — "Is the EU AI Act equipped for a crisis?"Analysis of the Act's crisis-handling capacity as enforcement begins; governance-gap perspective informing Risks and strategic sections. — Independent policy analysis (perspective).Date: 2026-09-07
Visit source ↗
Independent
Slaughter and May — "The EU AI Act: challenges and questions for AI providers as the Act starts to bite"Interpretation challenges for providers under the 2 Aug 2026 enforcement start; information-request practice; open questions on scope and GPAI obligations. — Independent top-tier law-firm brief; corroborates enforcement-start reading.Date: 2026-09-07
Visit source ↗
Independent
Cloud Security Alliance (CSA) — research note "EU AI Act GPAI enforcement" (PDF)Post-2-Aug-2026 enforcement readiness overview: GPAI obligations, systemic-risk duties (Art 55), AI Office powers, cybersecurity angle (Art 55(1)(d)). — Independent technical/industry analysis of the enforcement regime.Date: 2026-08-03
Visit source ↗
Independent
POLITICO Europe — "EU response to AI extinction warnings"The AI Office's evaluation-capacity build-out, incl. the contract with METR (Model Evaluation and Threat Research); the extinction-risk politics behind the enforcement architecture; named independent source in the discovery record. — Independent political/technical reporting; basis for evaluation-capacity and strategic sections.Date: 2026-09-10
Visit source ↗
Independent
Lawfare — "How Much Power Does the EU AI Office Actually Have"Pre-window analysis of AI Office powers and constraints — context for whether the enforcement wave will be credible. — Independent background on AI Office capability (context only).Date: 2026-05-18
Visit source ↗
Independent
Lawfare (Eliška Andrš) — "You Don't Have to Sell It to Be Bound by It: GPAI and the EU AI Act"The in-window independent analysis arguing systemic-risk GPAI obligations bind providers even for internal deployment (no "placing on the market" required); scope fight over Chapter V; named independent source in the discovery record. — Independent governance analysis; basis for the scope/open-question sections.Date: 2026-09-16
Visit source ↗
Secondary Sources (13)
Secondary
Regulation AI — "Article 101 — Penalties applicable to providers"Confirms Art 101 grounds and figures (€15M/3%); confirms Digital Omnibus = Regulation (EU) 2026/1744 which did not amend Art 101; **note: gives a divergent Art 101 applicability date (2 Dec 2027) that is inconsistent with the Commission's own framing and Praxikon (2 Aug 2026) — the Commission-aligned date is used and the discrepancy is flagged in research/S34.md §13.** — Secondary reference; flagged discrepancy, used with caution. ---Date: 2026-06-21
Visit source ↗
Secondary
Praxikon — "Article 99, 100 and 101: the penalty structure per obligation"Precise penalty-structure analysis: Art 101 applied since 2 Aug 2026 (excluded from the earlier Chapter XII application); Art 101 grounds (Art 91 info failures, Art 93 measures, Art 92 access); Art 75c AI Office fine regime; Digital Omnibus (Regulation (EU) 2026/1744) did not amend Arts 100–101; new Art 5 sexual-imagery prohibitions from 2 Dec 2026. — Secondary legal analysis resolving the Art 101 applicability date and Omnibus scope.Date: 2026 (live; accessed 2026-09)
Visit source ↗
Secondary
Magica — "EU AI Act information requests to AI labs"Corroboration of the Commission's first information-request wave to AI labs in Aug–Sep 2026. — Secondary corroboration of the RFI wave.Date: 2026-08-26
Visit source ↗
Secondary
Winzheng — "EU AI Act enforcement September 2026: high-risk audit"Corroboration of the September 2026 enforcement wave and high-risk audit focus (Sept 15 evaluations; HR/banking/healthcare inspections). — Secondary corroboration of the milestone and inspection wave.Date: 2026-09-12
Visit source ↗
Secondary
Cambridge Commentary on the AI Act — "Article 51: Classification of general-purpose AI models as general-purpose AI models with systemic risk" (PDF)Academic analysis of the Art 51 classification regime and the 10^25 FLOP presumption (Art 52), informing the Technical-implications and Risks sections (FLOP-threshold disputes). — Secondary academic source on classification mechanics.Date: 2026-03
Visit source ↗
Secondary
AI Safety Hong Kong — "Enforcement begins: the EU AI Act" (substack)Independent commentary on the first formal enforcement (FFE) wave beginning Aug–Sep 2026; systemic-risk evaluations context. — Secondary independent commentary corroborating the enforcement-wave narrative.Date: 2026-09-08
Visit source ↗
Secondary
AI in Europe — "Act Tracker 2026-08-03"Timeline tracking of AI Act application dates after 2 Aug 2026 (GPAI enforcement powers live; subsequent dates 2 Dec 2026, 2 Aug 2027, 2 Dec 2027, 2 Aug 2028). — Secondary compliance-tracker corroboration of milestone dates.Date: 2026-08-03
Visit source ↗
Secondary
2EU Brussels — "AI Office can request information, evaluate models and require risk mitigation measures from GPAI providers"Overview of AI Office powers (Arts 91–93) as enforcement went live in Aug 2026. — Secondary EU-affairs analysis of AI Office powers.Date: 2026-08-11
Visit source ↗
Secondary
EU Perspectives — "The AI Act gives Brussels new powers: frontier labs are first in line"1 Sep 2026 information requests to 30+ AI companies; framing of frontier labs as first enforcement targets. — Secondary policy-blog corroboration of the RFI wave.Date: 2026-09-01
Visit source ↗
Secondary
Grant Thornton UK — "The EU AI Act: what UK and cross-border general counsel need to know now the high-risk deadline has moved"Digital Omnibus deferral of Annex III high-risk obligations (2 Dec 2027) and Annex I (2 Aug 2028); the GPAI/enforcement wave (2 Aug 2026) unaffected; UK cross-border GC implications. — Secondary advisory source confirming deferral dates and enforcement start.Date: 2026-09-14
Visit source ↗
Secondary
TechTimes — "OpenAI Files First EU AI Act Incident Report, Chief Scientist Admits Monitoring Gap"Report that OpenAI filed the first serious-incident report under Art 55(1)(c) with the AI Office (8 Sep 2026) and that OpenAI's chief scientist admitted a monitoring gap (COMPANY CLAIM via secondary reporting; not independently confirmed with the AI Office). — Secondary single-source reporting of the first incident-report exercise; treated with caution.Date: 2026-09-08
Visit source ↗
Secondary
Allegiance Law — "EU AI Act enforcement has started: Commission sends first information requests to AI companies"1 Sep 2026 Commission information requests to 30+ companies in two streams (safety/security under Art 91; copyright/transparency under Art 53); legal framing of the enforcement wave. — Secondary law-firm reporting of the Commission's RFI announcement.Date: 2026-09-13
Visit source ↗
Secondary
Enterprise DNA — "EU AI Act: First Compliance Inspections to Begin September 2026"The September 15, 2026 deadline for systemic-risk GPAI (>10^25 FLOP) evaluation submissions; first inspection wave scope (HR resume screening, retail banking credit scoring, healthcare AI triage) co-led by CNIL (FR), BfDI (DE), AESIA (ES) with 24 national market surveillance authorities; Sept 15 package incl. red-teaming methodology, energy-usage disclosures, copyright training-summary compliance. — Key secondary source establishing the in-window event date and milestone details; the sole written source for the "Sep 15" operational deadline specifics.Date: 2026-09-08
Visit source ↗