Operational notes Observatory

Regulation (EU) 2026/1755: what the Commission can demand from your AI model provider

7 min read

Two surveillance cameras fixed to a grey corrugated metal wall, in black and white
Two vantage points on the same wall: what matters is not how many, but who can order them switched off.

On 20 July 2026 the European Commission adopts Commission Implementing Regulation (EU) 2026/1755, published in the Official Journal of the European Union, L series, on 21 July (CELEX 32026R1755). Article 15 sets entry into force on the twentieth day after publication: 10 August 2026, six days from now. The text creates no new powers: it implements the ones the AI Act — Regulation (EU) 2024/1689 — already gives the Commission to evaluate general-purpose AI models (Article 92) and fine their providers (Article 101). What changes is the precision, and that matters most to whoever has bought or integrated a third party’s model.

The facts, in order

  • 20 July 2026 — the Commission adopts Implementing Regulation (EU) 2026/1755, “on detailed arrangements for the conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689”.
  • 21 July 2026 — published in OJ L 2026/1755.
  • 10 August 2026 — entry into force (Article 15): “This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.”
  • Recital (1): Article 92(3) of the AI Act already let the Commission request access to a model “through application programming interfaces (‘APIs’) or further appropriate technical means and tools, including source code”; the regulation exists “to increase legal certainty and ensure proportionality”.

From an open-ended formula to a named list

An open-ended formula gets negotiated: “further appropriate technical means and tools” is a perimeter a provider can argue over case by case. Regulation 2026/1755 closes it. Article 2(2) lists what that access “may include”:

“The access requested shall be appropriate to the objectives of the evaluation. Such access may include access through application programming interfaces (‘APIs’), internal access, access to source code, access to model weights, access to the infrastructure used for hosting the general-purpose AI model, access to inspect and modify the system state during interaction with the model. Such access may include but is not limited to all levels of access granted to employees of the provider. Providers of general-purpose AI models requested to provide access shall ensure that the access provided is not subject to technical or other constraints that materially impede an appropriate evaluation.”

Six items, not one. Weights, not just source code. Hosting infrastructure, not just the public endpoint. And the last sentence pushes the perimeter further out: all levels of access granted to employees of the provider — if an in-house engineer can see something, the Commission can ask to see it too. The decision, says paragraph 1, “shall specify the technical means, tools, components, and conditions, including the time limit”; the provider must give access, adds paragraph 4, “without undue delay and within the time limit established in the decision”. There is no table to negotiate at: there is a deadline, and the Commission sets it.

The consequence for anyone who buys or integrates a third party’s model is direct: your supplier does not own what it promised you. Whatever confidentiality or exclusivity clause sits in your supply contract, the supplier can be compelled to open the model — weights included — to a Commission decision. Clauses in an AI supply contract read like clauses in an open-weight licence: what matters is what happens when someone tests them — here, a regulation does.

The paragraph nobody will read

There is a third paragraph, shorter than the other two, that is worth reading line by line:

“The Commission may require the provider to disable any logging measures that could track or record the Commission’s access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process.”

The stated logic is legitimate: if a provider knows exactly when and how the Commission is inspecting its model, it can alter the system’s behaviour for the occasion — the same reason a tax audit is not announced in advance. But the operational consequence for whoever simply bought or integrated that model is stark: by law, there is a category of access to your supplier on which the supplier itself may not hold — not through negligence, through obligation — a log to show you. We have already written about the gap between what a supplier states and what it leaves unsaid: there the silence sat inside a technical report; here it sits in the access log, and the law authorises it. If your compliance rests on the audit trail your supplier hands you, that trail has, by design, a zone it does not cover. This is not a conspiracy: it is a design choice with a cost, and the cost falls on whoever delegated to a third party the only traceability it had.

The other side, and why it exists

Stopping here would be dishonest. A regulator that has to assess a frontier model without being able to see its weights is not assessing anything: until now the asymmetry ran entirely in favour of whoever builds the model. Regulation 2026/1755 corrects it, and that is the reason it exists — recital (1) says so, “to increase legal certainty and ensure proportionality”, not to single out any one supplier.

Nor does it leave trade secrets unprotected. Article 3 builds a serious perimeter around the independent experts the Commission may appoint in its place: independence is assessed partly on “contractual relationships between the expert and the provider concerned or any other provider over at least the 12 months prior” to the evaluation, and experts “shall commit to maintaining the confidentiality, integrity and availability to the Commission of sensitive information” they access, bound also by the secrecy obligation of Article 339 of the Treaty on the Functioning of the European Union. The point here is not that the system is wrong: it moves the boundary of who sees what, and anyone who has built compliance on a third-party supplier’s model needs to know that before 10 August, not after.

The regulation applies to providers of general-purpose AI models within the meaning of the AI Act — the category that includes, by size, the large labs this column follows, from OpenAI to Anthropic, from Google to Meta, to those publishing open weights such as Alibaba or DeepSeek. We name them only to place them in the category, not to attribute positions they have not taken publicly.

What to do, in practice

  • Do not base your compliance traceability solely on your supplier’s access log: you now know, from a regulation and not a hypothesis, that it can have an uncovered zone.
  • Reread the confidentiality and exclusivity clauses in your AI supply contracts: none of them override a Commission decision requesting access under Article 92 of the AI Act.
  • Keep your own traceability of every material interaction with a third party’s model regardless: whether or not the Commission ever intervenes, it is the one trail you fully control.

How we solve this

The traceability you need for an inspection cannot rest solely on the logs of a supplier that a Commission decision can order switched off. A control that runs on your own systems and your own documents produces a trail that is yours — who asked what, which model answered, on what data — and it stays yours whatever happens upstream, including the few lines of Article 2(3).

The same system holds together the organisation’s scattered data — archives, business systems, documents, sensors, plant — in a single operating model on which AI agents execute decisions with an operator in command: for large enterprises, defence, government and healthcare. Compliance with this regulation is the way in; the decision-making system running on top of it is what we sell. The argument for open weights on premises we guard is specific here, and it should be made without triumphalism: a model running inside your own perimeter, with weights you hold, has no supplier that can be compelled to open it or switch off its logs, because that role is yours. The same principle holds when the rules on open weights change from outside: whoever holds the copy in-house does not depend on a decision made elsewhere. We do this both ways — on premises, on self-contained machines that need no deep integration into your network, or on a dedicated cloud with a dedicated VPN and a data centre in Italy, in premises we guard directly — always with shared management: you do not need to already have someone in-house who administers AI models.

Do you buy or integrate a third party’s model in a process that will one day have to withstand an inspection? Thirty minutes with one of our experts: we will map out where your traceability sits today, and what happens if your supplier’s trail goes dark.

Sources