AI Act: First Risk Evaluation Deadline Today

Models exceeding 10^25 FLOPs must submit reports by today; 24 national authorities are conducting technical audits.
The AI Office of the European Commission is receiving the first formal reports of systemic risk assessments from General-Purpose AI (GPAI) providers whose training exceeds the threshold of 10^25 FLOPs by this Monday, September 15. This marks the first real test of the compliance machinery set up by the Commission since the oversight phase went into effect on August 2.
The scope of the documents is technical and not often seen in public debate: red-teaming methodology, disclosures of energy consumption from training runs, and the Article 11 technical file, which is being audited in collaboration with 24 national market oversight authorities. Also included is the standardized summary regarding the use of copyrighted content in training, based on a template published by the AI Office in July.
Who Submits, Who Reviews
Anthropic, OpenAI, Google DeepMind, Meta, Mistral, xAI, and Alibaba's LLM team are among the providers required to submit documentation, as they operate models exceeding the FLOPs threshold. The review is conducted by the AI Office in Brussels, with support from national authorities and the Scientific Panel as stipulated in the regulation. Penalties for non-compliance can reach 3% of the global annual revenue of the infringing company or €15 million, whichever is higher. The regime, therefore, impacts American and Chinese vendors on a global revenue scale, not just within Europe.
What Changes for Enterprise Clients
For the CIO of a global bank using Anthropic or GPT in production, today’s submission quietly factors into future contracts. Article 25 of the AI Act imposes a reasonable due diligence obligation on the deployer, meaning the buyer must verify compliance of the supplier with the GPAI regime. In German and French banks and insurance companies, this oversight has already appeared as a mandatory clause in RFPs since the beginning of the year, but AI vendors had yet to present an official document from the Commission until now. The report submitted today serves precisely as that official document.
For the global consultant deploying Claude, Gemini, or GPT in solutions for clients in Asia and the Americas, the reading is twofold. Where the buyer's jurisdiction is European, they need to show a chain of responsibility that links back to compliance of the border supplier. Where the jurisdiction is Asian or American, the European regulation becomes a useful commercial argument benchmark, even without legal force. In Japan, the METI referenced the European FLOPs model in its own AI Business Guidelines published in May. In the United States, the NIST AI Risk Management Framework 2.0 interacts with the same vocabulary, albeit without the same type of sanctions.
In Brazil, Bill 2,338, which created the National System for AI Regulation and Governance currently under analysis by the Senate, adopts a structure similar to the European model but has yet to define the equivalent compute threshold. Consultancies operating multinational contracts are already using the European model as a de facto baseline in RFPs for local banks.
The Blind Spots of the Exercise
There are pertinent criticisms to be made. Sarah Chander from the European Center for Not-for-Profit Law stated at a Commission conference in July that the FLOPs threshold measures computational input, not real risk: a model trained on sensitive medical data below 10^25 FLOPs could pose more systemic risk than a generalist LLM trained on 10^26. The Commission responded that thresholds would be reviewed annually. On the other hand, Andrea Renda from the Centre for European Policy Studies defended the exercise as the only real border auditing mechanism that exists today in the West. Neither side expects perfection in the first round.
There is also a point of operational friction. Border suppliers complain that the standardized copyright template requires dataset-level detail that most models cannot reconstruct accurately retroactively. The AI Office accepted, in informal guidance from August, aggregated disclosures by category and scraping period for runs prior to August 2. For subsequent runs, the requirement is granular. This divides the industry between those who will invest in data provenance pipeline and those who will bet on retraining under an auditable budget.
Learning by Doing
What the AI Office aims to do is learn by doing. Marc Beaulieu, head of the Commission's GPAI unit, told Politico in August that the first wave of submissions will help calibrate the process itself: the clarification questions that arise may turn into formal guidance before the end of the year. Compliance begins today. The jurisprudence on what exactly it requires will be built over the next twelve months.
The Commission indicated a preference for starting with technical dialogue before enforcing sanctions. It is worth following two indicators in the upcoming quarters: the publication, or lack thereof, of submitted summaries and the volume of clarification questions redirected to more than one supplier. If the same clarification appears in five requests, it becomes a de facto norm.