← All news
Press · September 21, 2026 · 15 min read

An incorrect answer to a regulator is a separate infringement from the one it is asking about

An incorrect answer to a regulator is a separate infringement from the one it is asking about

Article 99(5) fines an incorrect reply: €7.5M or 1% of turnover. And that reply is assembled from documents that contradict each other.

On 1 September 2026, the European Commission confirmed that it had sent its first requests for information to more than thirty providers of AI models, covering model security, the use of external evaluations, and how model behaviour is monitored after release. The Commission’s page “The enforcement framework of the AI Act”, last updated on 24 August 2026, describes the instrument and its sanction: for a simple request, a fine can be imposed if the provider’s reply is incorrect or misleading. For a request issued by decision, fines also apply if the provider fails to reply or replies incompletely.

The consequence is easy to state: the quality of what you declare is sanctionable independently of the quality of what you do. An organisation that is compliant on the substance can be fined for describing its own compliance badly. And nobody writes that declaration from scratch: it is assembled from conflicting documents that AI compliance was never designed to arbitrate between. Once the answer has been sent, it is part of the file. Correcting it erases nothing; it adds a dated event, on a date when the calendar was no longer yours.

Who this is for, and who it is not for

Let us be exact about scope, because it is the first objection your legal department will raise. The enforcement powers of the European AI Office apply to providers of general-purpose AI models and to AI systems developed by that same provider or its group. That is not you if you buy an assistant off the shelf and deploy it. A large group that builds its own internal AI system, however, is a provider under the Regulation, and that is the exact perimeter of this article.

For everyone else, the relay is written into the same text, and it matters when it opens. AI systems outside the AI Office’s remit are supervised by national competent authorities, and Article 99(5) of the Regulation provides for fines of up to €7.5 million or 1% of total worldwide annual turnover, whichever is higher, for supplying incorrect, incomplete or misleading information to a notified body or a national competent authority in reply to a request. That is the only regulatory figure in this article, and it applies to the reply, not to the substance of the file.

Now the calendar, without which this text would be alarmist. If you deploy an assistant bought off the shelf, your AI Act deadline is 2 December 2027: the AI Digital Omnibus, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, deferred the obligations for Annex III high-risk AI systems to that date. Until then, that channel is closed for you. The one that is open today is not regulatory, and you already answer it several times a quarter: a large customer’s security questionnaire, an auditor preparing a certification, an insurer assessing cover, your sector regulator. The mechanism described here is identical in both cases. What changes is who is writing to you, and what it costs them not to believe you.

This text is not addressed first to your legal department, which knows these articles better than we do. It is addressed to the chief data officer and to the business owner of the documents, because the raw material of the answer sits with them. What is being transposed here is a method — how a statement destined for a third party is manufactured and verified — not the regulatory object itself: what interests us in the sanction is what it reveals about how a document estate behaves under constraint.

Two reflexes will come up, and both deserve better than a caricature. The first is the in-house process: an annual documentation review, a repository kept by a quality team, a validation procedure. The second is the tool already bought: an AI governance platform, a compliance registry, a GRC suite. Neither is useless. We will see where each one stops, and why the gap they leave is the one that decides your answer.

One gesture, half a day, no tooling. Take the last answer your organisation actually sent to a demanding third party: a large customer’s security questionnaire, an internal audit, an insurer’s request, a certification review. Reconstruct its assembly — which document each statement came from, in which version, and who decided when two sources diverged. What you write that day is the first page of the artefact described at the end of this article. Its failure mode deserves to be stated before you start: if the exercise succeeds, you will have learned only the size of the perimeter you did not test, at the cost of half a day from the one person who knew, the person whose availability you will not have under deadline.

What the instrument actually sanctions

The European AI Office can send requests for information in two forms, the simple request and the request issued by Commission decision, conduct interviews, and carry out inspections at a provider’s premises. The allocation of obligations matters as much as the instrument: design and logging obligations sit with the provider, log retention and human oversight with the deployer. When a vendor tells you it covers the AI Act, it is talking about its share. What stays with you is what you declare about your own use, drawn from your own documents.

Doing nothing is a real option, and an article that ignores it reads as an instruction with no cost of alternative. The status quo produces no sanction as long as nobody asks. It produces something quieter: it pushes the discovery of your documentary contradictions to the moment when the calendar is no longer yours. Its cost is that exchange — a topic you handle whenever you like becomes an incident you undergo when you are asked.

One methodological point. To date, no enforcement decision based on an incorrect reply to a request for information has been published, and the first wave of requests is three weeks old. What we write here about how an authority will read an answer is a reasoned reading of the text and the instrument, not a statement of established practice. Your legal department arbitrates that reading; our subject sits upstream, in the material it will receive.

The December 2027 deferral mentioned above will be used internally as an argument to wait, so it is worth saying immediately what it does not defer. Still applicable, unchanged: the prohibited practices, the obligations for providers of general-purpose AI models, the Article 50 transparency requirements, and the enforcement powers applicable since 2 August 2026. The instrument that sanctions an incorrect reply is live today, whatever date your high-risk systems have to comply.

The temporal reversal: you never find a conflict when you have time to settle it

An answer to a regulator is assembled from living documents: a security policy, an architecture note, a model qualification file, a human oversight procedure, a processing record. Each was approved through its own circuit, each has an owner, each is up to date from its own point of view.

When two of them contradict each other on the precise point at issue, the organisation sends whichever surfaces first, having never chosen between them. There are two reasons for that, and neither is a lack of rigour: nobody holds a written mandate to arbitrate between two documents approved through different circuits, and the response deadline leaves no time to create one.

That is the reversal. A conflict between two living documents is, in normal times, a background topic you handle whenever you like, if you like. Under a request for information it becomes an incident: you have to settle in a few days what nobody wanted to settle in three years, without a mandate, without a record of who decided, and under a rule that makes the error an autonomous infringement. The conflict has not changed its nature. The calendar has changed its own.

Whether an estate contains contradictions of this kind can be counted. On the documentation set behind the customer chatbot of TotalEnergies Retail Power & Gas — around 500 pages of official web documentation, mapped and audited without migration — K-AI identified 19% of pages requiring correction, and 53% of cases were resolved within three weeks by prioritising the most critical ones, with one to two people mobilised half a day to a day per week. Thomas Bensoussan, Head of Digital Products at TotalEnergies RPG, takes from the exercise that it surfaced conflicts that are hard to spot by eye and that it indicates which expert each case should be routed to. The scope of that figure is a 500-page documentation set during a first diagnostic: it establishes prevalence on that corpus, not a general law, and it says nothing about the volume of contradictions in yours.

That is the function of a Document Knowledge Platform (DKP): govern the document estate (ownership, authority, lifecycle), clean it by detecting anomalies, duplicates, obsolescence and contradictions, then activate it for AI systems only once those two steps hold — Govern, Clean, Activate. It runs upstream of an enterprise search engine, a knowledge layer or a vector store, on the estate those components consume, and that position does not depend on the analyst publication calendar. One point of placement, because the setting of this article could mislead: a DKP does not sell in the AI compliance category and has no business appearing in an AI governance RFP. The request for information is only the channel through which a documentary problem becomes visible and dated. On processing: document content only is ingested, within a contractually defined perimeter, with no telemetry or usage logs, and no reuse for model training.

Why an AI compliance registry does not hold this information

Take the serious alternative at its strongest, because it is good. An AI governance platform documents the system: its purpose, its provider, its training data, its evaluations, its logs, its owners, its risk level. It produces a maintainable inventory, carries the evaluation evidence and gives an auditor a point of entry.

Its boundary is precise. It describes the system and the documents that feed it. It does not store the authority relationship between two of those documents, because that relationship is an attribute of neither one: it belongs to neither, so neither carries it, so no registry built from them contains it. The same reasoning applies to the in-house repository: an annual review validates each document within its own circuit; it does not compare two documents from two different circuits.

This is precisely the moment the business owner of the documents walks on stage. The registry does not answer, so someone picks up the phone and calls him, because he is reputed to know. He was never given a mandate for this, he does not have both documents in front of him, and the person on the line has an answer to send before the end of the week.

We should be equally clear about our own boundary. K-AI answers for the counting of contradictions, the reproducibility of that count over time, and the routing of each case to the right expert. K-AI does not answer for the authority decision: which document prevails remains a business call, and it stays one. What the organisation is missing is a written attribution added to an existing role — process owner, domain lead, quality manager — stating who decides when two approved documents contradict each other. No post to create, no new committee.

The assembly record: what other functions already write

This requirement is not new, and that is the cheapest argument to accept. A financial close produces, beyond the figure, an audit trail linking each line to its supporting documents, with someone responsible for the package and a signature. A finance department treats that trail as the normal condition of a statement that has to stand up to a third party, never as extra governance. The document estate, meanwhile, produces statements addressed to third parties with no equivalent trail. What follows is catching up with a practice that is already normal elsewhere.

The corresponding artefact fits in a few columns. Call it the assembly record: for each statement sent to a third party, the source document and its version, its owner, the date, any contradiction found with another source, the decision taken and by whom. One line, written out in full, looks like this:

“Human oversight of model outputs” — source: Oversight Procedure, version in force, owner: operations quality manager. Contradiction found with the architecture note, which describes an automated control with no human review. Decision: the procedure prevails, the architecture note to be corrected within 30 days. Settled by the process owner, today.

One methodological point decides whether it is feasible: its first lines are written cold, retrospectively, on answers already sent. Filling it under deadline would ask the organisation for the very gesture the deadline forbids. It is the direct output of the half-day exercise proposed above; the following lines accrue as requests come in, on a base already started.

Its home matters as much as its columns, otherwise it dies as an email attachment. Its lines are written inside the response file that already exists — the one your compliance function assembles for every external request — and it is held by the person who signs the answer.

Writing and dating an arbitration creates a document that can be used against you, and that objection deserves a straight answer. If the authority decision turns out to be wrong, the record establishes that someone decided, when, and on what basis. Writing it remains preferable, because the real alternative is an answer sent with no identifiable arbitration, where the organisation can show neither who decided nor what was compared. This assessment is a reasoned reading with no published decision behind it; validate it with your legal department before any rollout.

That leaves budget, at the time of year when the question arises. This work attaches to the AI Act compliance programme already approved, or to the internal control plan, with no new line to open. The trade-off has to be stated straight away: that attachment creates a scheduling dependency, and the December 2027 deferral may push the host programme. So the work has to be cut into pieces that survive a postponement — counting contradictions on a narrow perimeter has value of its own, independent of the regulatory calendar.

Conclusion

The sequence is the one that applies to any estate you want to make defensible. Audit: count the contradictions across the documentation that would feed an answer, rather than assuming there are none. Clean: start with the ones bearing on statements you have already made to a third party. Monitor: governance is continuous, because living documents start diverging again the day after the clean-up.

Go back to the half-day exercise. The last answer your organisation sent to a demanding third party was already assembled by someone, from documents that exist. The business owner of those documents is the person who will be called on a Thursday afternoon to say which of the two versions prevails. The only variable is whether, on that day, he answers from memory or answers while reading.

Frequently Asked Questions

Does an AI Office request for information concern every company using AI?

No. The European AI Office’s powers apply to providers of general-purpose AI models and to AI systems developed by that same provider or its group. A large group building its own internal AI system is a provider under the Regulation. Other systems fall to national competent authorities, and Article 99(5) provides the same sanction for incorrect, incomplete or misleading information supplied to a notified body or a national competent authority.

We deploy an off-the-shelf assistant. Are we exposed in 2026?

Not through that channel. The obligations for Annex III high-risk AI systems were deferred to 2 December 2027 by the AI Digital Omnibus, Regulation (EU) 2026/1744. In 2026, the requests you already answer come from elsewhere: your large customers’ security questionnaires, certification auditors, insurers, sector regulators. The assembly mechanism and the risk of documentary contradiction are identical; only the sanction differs.

What is the difference between being non-compliant and answering incorrectly?

They are two distinct infringements. The first concerns what your system does, the second the accuracy of what you declare to an authority that is asking. An organisation compliant on the substance can be sanctioned on the second, and the reverse also holds.

Doesn’t our AI governance platform already cover this risk?

It covers the inventory of systems, their evaluations, their owners and their logs, and it does that well. It does not store the authority relationship between two documents that contradict each other, because that relationship is an attribute of neither document. That is the zone a Document Knowledge Platform addresses, upstream.

What exactly does K-AI see of our documents, and who approves the perimeter?

Document content only, within a contractually defined ingestion perimeter: no transcripts, no usage logs, no telemetry, and no reuse of content for model training. The perimeter is approved jointly by the business Document Owner and the CISO or DPO, never by IT alone.

Sources


Where to Go From Here

K-AI Corpus Diagnostic — 10 business days on your document estate, full report of the 20 most critical anomalies, money-back guarantee if no meaningful anomaly is found. A one-hour conversation is enough to tell whether the problem is on your side: we look at an answer you actually sent and where its lines would have come from, which is to say what your assembly record would contain today if you had to write it. Reach the K-AI team: contact@k-ai.ai. The scope of every diagnostic is validated jointly by the business Document Owner and the CISO/DPO, never by IT alone.

K-AI already works with CMA CGM, Veolia, PwC, BNP Paribas, TotalEnergies and CEVA Logistics. Partners: AWS, Snowflake, Microsoft, Wavestone, Devoteam.

And in your organization, what does your document estate look like?

30 minutes with a founder. We audit a sample of your documents for free and show you exactly what K-AI detects.

Book a demo → Read other articles