Operational notes Regulation

From 10 August the European Commission has its AI-model procedure: who sees your file

7 min read

Row of red ring binders side by side on an office shelf, black and white photograph
Each binder has a label and a barcode: the procedure decides who gets to open it, not you.

On Monday 10 August, Commission Implementing Regulation (EU) 2026/1755 enters into force, “on detailed arrangements for the conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689” — the AI Act. Three days ago we covered what the Commission can demand from an AI supplier: weights, infrastructure, internal access. Today the question changes: not what the Commission can demand, but how the proceeding runs — who sees which documents, on what deadlines, and what a company needs ready.

There is an asymmetry worth noting: it is what makes the topic timely today. Article 15 sets entry into force on “the twentieth day following that of its publication in the Official Journal of the European Union”, published on 21 July: come Monday, the European procedure will exist. The two Italian legislative decrees transposing the AI Act, approved in final reading by the Council of Ministers on 4 August — we wrote about that here — do not yet appear in the Official Gazette (check, with date and time, further down). While Brussels’ procedure becomes operational on schedule, Italy’s supervisory powers and national penalty regime remain, for now, on paper.

A trade secret is not invoked: it is prepared

Article 9 covers the most common case: a company — as a supplier or as a third party that provided information — ends up inside a Commission file containing data it considers a business secret. Paragraph 3 says the Commission “may require natural or legal persons who are the originators of documents in its file to identify the documents, statements, or parts thereof which they consider to contain business secrets or other confidential information”. Saying so is not enough: paragraph 4 lets the Commission set a deadline by which, “for each individual document or part thereof”, claims must be substantiated, a “non-confidential version of the documents in which the business secrets and other confidential information are redacted in a clear and intelligible manner” must be provided, and “a concise, non-confidential description of each piece of redacted information” attached.

Three tasks, all before anyone looks at the document. Paragraph 5 leaves no room for interpretation: “If a natural or legal person fails to comply with paragraphs 3 and 4, the Commission may consider that the information concerned does not contain business secrets or other confidential information.” That is worse than a fine: it strips away the very protection sought. And when the Commission decides a piece of information may be disclosed, it informs the person concerned “that it intends to disclose such information unless it receives objections within one week”.

It is the same mechanism we wrote about two days ago on the Data Act: Article 4 of Regulation (EU) 2023/2854 asks you to identify, agree and justify before a user’s request arrives; Article 9 asks the same before a Commission file arrives. Same architecture, two regulations: a trade secret is not a property of the data but the outcome of work done in advance — and whoever has not done it finds out too late.

You do not choose who sees your file

Article 8 governs file access for the addressee of preliminary findings — a supplier under formal investigation. Paragraph 1 is unambiguous: “Access to file shall not be granted before the notification of the preliminary findings.”

For unredacted documents, paragraph 3 opens a “terms of disclosure” procedure tighter than it first appears. Access “shall only be granted to a limited number of specified external legal and economic counsel and external technical experts engaged by the addressee and whose names shall be communicated to the Commission in advance”. The company under investigation does not choose alone: it proposes, but the Commission knows their identity beforehand, and those individuals become the only eyes allowed on certain documents — not the board, not in-house counsel.

Point (c) of paragraph 3 deserves a precise reading: those counsel and experts may not, “at the date of the Commission decision setting out the terms of disclosure”, already be in an employment relationship with the addressee — not an outright ban on future hiring: if such a relationship arises “during the investigation or during the three years following the end of the Commission’s investigation”, the rule requires them to “promptly inform the Commission about the terms of such relationship” and confirm that access to documents not shared with the addressee has been closed off — a transparency duty, not a blanket bar. Paragraph 10 closes the loop: documents obtained “shall only be used for the purposes of the relevant proceedings within which access to those documents was given”.

The limitation clock resets easily

Article 10 sets the deadline beyond which the Commission can no longer fine a provider: five years “from the day on which that conduct was carried out by that provider”; for continuing or repeated conduct, it instead begins “on the day on which the conduct ceases”. It does not run undisturbed: “any action taken by the Commission for the purpose of its investigation or proceedings” interrupts it — little is required: “requests for documentation or other information”, “requests for access to conduct model evaluations”, “invitations to a structured dialogue”, or “the opening of a proceeding”. A letter requesting documents resets the clock like a formal proceeding.

“Each interruption … shall start time running afresh.” The ceiling is wide: the limitation period “shall expire at the latest on the day on which a period equal to twice the limitation period has elapsed” without a fine imposed — ten years, in effect, if interruptions keep coming. It stretches further still: the period “shall be suspended for as long as the decision of the Commission is the subject of proceedings pending before the Court of Justice of the European Union”. A file opened today can legitimately stay open for years: every request keeps it alive.

Why it matters even if you only buy the models

The regulation does not apply to anyone using artificial intelligence: it governs proceedings against providers of general-purpose AI models. If your company runs a third party’s proprietary model — not your own, with weights you hold — the procedure formally targets the supplier, not you. But it reaches you two ways: the supplier must hand the Commission technical documentation that can contain information about you, and the fate of your production model depends on how the supplier handles the proceeding — whether it has already mapped its own secrets or discovers them once a request lands.

The Italian text, not yet in the Gazette: checked this morning

At 7:00 this morning, 7 August, we checked the Official Gazette’s website. The latest fully published General Series is no. 181 of 6 August; it does not contain the two decrees, nor did no. 179 of 4 August or no. 180 of 5 August. No. 182 of 7 August, at the time of checking, was still shown as loading. That means the operating powers and national penalty regime the two decrees set out are not yet in force: oversight of anyone supplying or integrating AI systems in Italy still runs through existing channels — the European AI Act, the GDPR, sector codes — not the framework announced on 4 August.

How we put this into practice

The mapping Article 9 requires — knowing, document by document, what counts as a business secret, with justification already written and the non-confidential version already prepared — is not work to improvise in a week: it is a control we build to run over the client’s documents and systems, with a register of what is classified confidential, by whom, on what grounds and since when. The same system ties together the organisation’s scattered data — plant, archives, business systems, sensors, documents — into a single operating model on which AI agents execute decisions with a human operator in command: for large enterprises, defence, the public sector and healthcare.

One point is worth stating without overstating it: if your production model is your own, with weights you hold, a proceeding against a third-party supplier does not touch you the same way — not immunity, one fewer dependency. Always in both modes together: on-premises, on self-contained machines needing no deep integration into the client’s network, or dedicated cloud, with a data centre in Italy — always with shared management: whoever lacks in-house AI administration does not need to hire one.

Could you say today, document by document, what in your AI supply file is a business secret — and on what grounds? Half an hour with one of our experts, at no cost, for the first map.

Sources