“We Have an AI Policy” Is Not Enough for the Supervisor
By Jean-Hugues Migeon
On 29 August the EU AI Office sent its first formal requests for information to providers of general purpose AI models. Nobody was asked for their AI policy. Nobody was asked for a governance charter, a set of responsible AI principles, or the terms of reference of an ethics board.
What the AI Office asked for, confirmed by Executive Vice President Henna Virkkunen, was narrower and considerably harder: how the models are secured against attack, whether independent external evaluations have been carried out, how the models are monitored once they are on the market, and, from providers who have not published one, the summary of training content the Act requires. Four questions. Every one of them is answered with an artefact that carries a date, or it is not answered at all.
My read is that this is the most useful signal an AI governance team will get this year, and that it has very little to do with who happened to receive the letters.
The four questions all have the same shape
Look at what each one actually demands. Model security is a configuration state: which controls were in place, on which systems, on which date. External evaluation is a report by a named third party, with a scope, a methodology and a signature at the bottom. Post market monitoring is not a document at all. It is a stream, and the only way to demonstrate a stream is to produce a run of observations covering a period that has already elapsed. Even the training content summary, the most document-shaped of the four, is a disclosure whose accuracy can be tested against something else.
None of these can be produced by sitting down and writing them, which is the break with how compliance evidence has worked for most of the last decade. Under GDPR a policy, a record of processing activities and a completed impact assessment template carried a great deal of weight, because the underlying duty was largely to have considered something and to be able to show that the consideration happened. Documented consideration was the deliverable. Under the general purpose AI chapter of the AI Act, the deliverable is the state of a system and the record of what has been done to it since it shipped.
The stakes attached to that shift are not theoretical. A simple request from the AI Office can be escalated into a formal Commission decision, and failure to supply correct information carries penalties of up to 3 percent of global annual turnover or 15 million euros, whichever is higher. The Commission has also had the power since 2 August to run its own technical evaluations, demand mitigation measures, and restrict or withdraw a model from the EU market.
The objection is real, and it has a date on it
Anyone running an AI governance programme in Europe will have an answer ready: this is a model provider problem, and the rest of us were handed fifteen extra months. That deserves a straight response rather than a wave of the hand, because it is accurate. The Digital Omnibus moved the high risk obligations from 2 August 2026 to 2 December 2027. Parliament endorsed it on 16 June, the Council followed on 29 June, and it entered into force on 27 July. Watermarking of AI generated content slid to 2 December 2026. Registration duties and the AI literacy requirement were simplified, and small and mid cap companies picked up lighter obligations. That is genuine relief, not cosmetic redrafting.
It changes less than it appears to, for three reasons.
The first is that general purpose AI enforcement runs on a separate clock which started on 2 August 2026 and was not deferred at all. If your organisation deploys a frontier model, the provider you depend on is being supervised now, and the answers it gives about evaluation and monitoring describe a system you are accountable for at your own end.
The second is the one the deferral debate keeps stepping over. Evidence obligations are retrospective by construction. A monitoring record covering the twelve months before December 2027 has to have been accumulating throughout those twelve months. A drift analysis needs a baseline captured before the drift. An incident log is worthless if it starts on the day someone asks for it. December 2027 is not when the work begins, it is when the record gets read. Treating the deferral as fifteen months of slack only makes sense if the obligation were to hold a document, and the requests sent on 29 August are the clearest available statement that it is not.
The third is that regulators are no longer the only ones asking.
The questions travel downstream faster than the rules do
Supervisory expectations reach companies that no regulator has written to, through the contracts those companies have already signed. The Joint Committee of the European Supervisory Authorities demonstrated the mechanism in July when it set out what financial entities must show about frontier AI under DORA, imposing nothing directly on the suppliers of those models while guaranteeing that every one of them would be asked. The same movement happened in the United States without any regulator involved, when Fannie Mae reserved the right to demand a full AI inventory from servicers with no notice. And the Financial Stability Board has now told G20 finance ministers that frontier AI capability is the most immediate cyber risk facing the financial system, which is how a topic becomes a standing item in every supervisory dialogue in the sector.
Set that against what happened in the same week on the other side of the Atlantic. At the G20 Innovation Ministerial on 2 September the United States argued for lighter AI regulation and faster adoption, while the EU defended its legislative track. Read one way, that is the divergence everyone has been forecasting. Read against the enforcement actually underway, it matters less than it sounds, because a multistate attorney general subpoena into how a model was advertised, tested and monitored, a request for information from the AI Office, and an ICT risk diligence pack under DORA are all asking to see the same underlying material. The statutes are diverging. The evidence they run on is converging.
What has to exist before any of them asks
Strip the three regimes back and the same four artefacts sit underneath: which AI systems are actually in use, which obligations reach each of them, what was tested and on what date, and what has been observed since deployment. The useful question is not which regime you fall under. It is whether those four things exist as a maintained record or as a research project that gets commissioned each time someone asks.
That distinction is what Anove's insAIght platform is built to hold. Every system in the register carries the obligations that apply to it, the evaluations run against it and the dates those evaluations happened, so a question about a point in time is answered from a record of that point in time rather than reconstructed from memory and a shared drive. If you want a quick read on what your existing tools disclose about themselves before you start, ExplAIn is free and takes minutes.
The teams that will struggle are the ones with the best policies
There is an uncomfortable implication in all this. The organisations most exposed are not the ones that ignored AI governance. They are the ones that took it seriously in the form it was asked for until now: a board approved AI policy, a principles document, a risk taxonomy, a committee with minutes, an inventory refreshed for the annual report. All of it real work, all of it written, and almost none of it timestamped against a running system.
Being able to describe your governance and being able to prove it are different capabilities, and the years spent building the first do not build the second. What the AI Office sent on 29 August is a preview of a question that will reach the rest of the market through supervisors, customers and litigation over the next eighteen months. The organisations that answer it comfortably will not be the ones with the best written programme. They will be the ones that started keeping receipts early.
Learn more
- insAIght, Anove's AI governance and risk platform, for keeping the register, the mappings and the dated evidence current instead of assembling them on request.
- Brussels Did Not Write a Rule for AI Vendors. It Wrote Their Next Questionnaire., on how supervisory expectations reach suppliers through contracts.
- The FSB Just Told G20 Finance Ministers That AI Is Now Their Top Cyber Risk, on why frontier model capability is now a supervisory standing item.
- ExplAIn, our free tool for checking what an AI system actually discloses about itself.
If you would struggle to produce dated evidence for the AI systems already running in your business, book a demo and we will show you what the register looks like when it is maintained rather than rebuilt.