The EU has fired its first enforcement shots at AI model providers. The era of 'we'll deal with it later' is officially over.
elcome to issue eighteen. This week the EU stopped warming up and started swinging, sending its first formal requests for information to AI model providers under the AI Act. That is not a drill, and it is not a consultation: it is enforcement. We also dig into a French court ruling that knocked down a youth social media ban, which has quiet but real implications for how EU member states try to layer extra restrictions on top of the Act's framework.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We have added an enforcement tracker to the Flux compliance dashboard so you can follow which model provider categories are receiving RFIs as the AI Office's first wave of enforcement unfolds.
- Updated Our general-purpose AI model checklist has been updated to reflect the security and capability disclosure focus signalled by the EU AI Office's first requests for information.
- ICYMI Issue seventeen's deep-dive on the Dutch predictive policing shutdown is worth revisiting alongside this week's enforcement news as a case study in what happens when AI governance is treated as optional.
The EU Has Sent Its First AI Act Enforcement Requests to Model Providers, and the Grace Period Is Over

No more dress rehearsal. The EU has begun sending formal requests for information, known as RFIs, to AI model providers as the opening move in its AI Act enforcement programme. An RFI is not a chat over coffee. It is a legally significant instrument that requires recipients to hand over documentation about their systems, safety testing, and risk controls. Getting one means regulators have you in their sights.
What the RFIs are actually asking about. According to the Tokenstead guide tracking the enforcement activity, the early RFIs are focused on security and model capability disclosures. That signals the AI Office is starting where the risk is highest: large general-purpose AI models that could affect critical systems. Providers who assumed the Act was still a future problem are now discovering it is a present one.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓EU AI Office issued its first formal requests for information to general-purpose AI model providers under the AI Act enforcement programme.
- ✓France's Constitutional Council struck down a national law that would have banned under-15s from social media, limiting member states' ability to add sweeping age-based platform restrictions on top of EU-level rules.
- ✓The Meta settlement in the US prompted renewed EU commentary on age assurance mandates, with critics warning that embedding age verification into every product creates its own surveillance infrastructure.
- ~US Immigration and Customs Enforcement issued a wave of administrative subpoenas to tech companies seeking subscriber data on individuals who documented ICE activities or attended protests, raising serious speech-chilling concerns.


- 1Tokenstead EU AI Act Enforcement Guideenforcement
A regularly updated guide tracking the AI Office's first enforcement actions, including the security-focused RFIs sent to model providers this week.
Why we like it. It is the closest thing to a live scoreboard for who is being asked what, written in plain language rather than regulatory jargon.
- 2EU AI Office official portalofficial
The central hub for all official AI Act guidance, including the GPAI Code of Practice, model registration requirements, and published enforcement notices.
Why we like it. If an RFI arrives, this is where the framework you will be judged against lives. Bookmark it before you need it urgently.
- 3Zizka AI Act Roadmap for CIOs and CTOs

The first RFI changes everything, even if it was not sent to you
By John Ferguson
I have been waiting for this week for about two years. Not because I wanted anyone to get in trouble, but because the AI Act only becomes real when enforcement becomes real. A regulation without a first move is just a very long PDF.
What strikes me about the EU AI Office's decision to start with security-focused RFIs is how deliberate it is. They are not going after the easy targets. They are going after the foundational layer: the large model providers whose systems everything else is built on. That is a smart place to apply pressure.
For anyone building on top of a general-purpose AI model, whether you are a solo developer or an enterprise team, this week is a prompt to ask a question you may have been avoiding: does my vendor actually know what the AI Act requires of them? Not in theory. In practice. With documentation ready to send.
The grace period was a gift. Most people treated it as a reason to wait. The RFIs are the universe's way of saying the waiting is done.
John Ferguson · Founder, Agentic Fluxus

Short answer.Potentially yes. If the provider's response reveals non-compliance with GPAI obligations, any deployer relying on that model inherits reputational and contractual risk. More practically, a provider under regulatory pressure may change model behaviour, restrict outputs, or update terms of service on short notice. Review your vendor agreement now for change-notification clauses and have a contingency model in mind.
Your main AI model provider just received an EU AI Office RFI. What is your first move?

The EU AI Office has issued its first requests for information to AI model providers, focused on security documentation and capability disclosures. This is the official end of the 'it is still theoretical' era for AI Act compliance.
France passed a law banning under-15s from social media platforms, scheduled to take effect in January 2027. Its own Constitutional Council struck it down before it ever went live, ruling it incompatible with fundamental rights.

