✓ Low compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
The AI Office’s information-gathering powers for GPAI oversight
Article 91 establishes the AI Office’s power to compel GPAI model providers to produce documentation, data and other information needed for enforcement and monitoring. It defines the scope of what can be requested, the timeframes for compliance, and the procedural safeguards that apply.
WHAT IT SAYS
Mandatory production of documentation, data, source code and model access
- The AI Office may, by simple request or by decision, require GPAI model providers to provide any information necessary for the performance of its tasks
- Information that may be requested includes: technical documentation, training data descriptions, model architecture, training methodology, evaluation results, incident reports, and the identity of any subcontractors
- Where necessary to assess systemic risks, the AI Office may request access to the model itself — including model weights and the ability to run evaluations
- Requests by decision are binding — failure to comply is itself a violation subject to penalties under Article 101
- Requests must specify: the legal basis, the purpose of the request, what is required, the deadline for compliance, and the penalties for non-compliance
- The AI Office must take into account the confidentiality obligations of Article 78 when handling information received
- Third parties — including downstream providers — may also be requested to provide information relevant to a GPAI investigation
WHO IS AFFECTED
GPAI model providers and downstream businesses involved in investigations
- GPAI model providers — primary recipients of documentation requests
- Downstream providers who may be asked to provide information about their use of GPAI models
- The AI Office which exercises the request power
- Subcontractors and third parties involved in GPAI model development
WHAT IT MEANS FOR SMES
Maintain your GPAI documentation — and know what your vendor must produce
- For SMEs using GPAI APIs: Article 91 information requests to your AI vendor may produce findings that affect how you can use their model — this is not directly your compliance risk but may have indirect implications
- For SMEs building AI products on GPAI models: you may be requested as a downstream provider to provide information about your use of a model under investigation — maintain records of how you use the GPAI model, what modifications you have made, and what your system does
- The binding decision power means non-compliance is penalised separately from any underlying violation — if you receive a request, respond within the deadline
- The scope of requests is broad — ‘any information necessary’ is deliberately wide; assume that detailed technical records of your AI development may be requested and maintain them accordingly
Related Articles
- Article 88 — GPAI enforcement (the investigation context in which information requests arise)
- Article 92 — Power to conduct evaluations (a more intensive investigative tool following information review)
- Article 78 — Confidentiality (protects the information provided)
- Article 101 — Fines for GPAI providers (non-compliance with requests is penalised here)
