A Commission implementing regulation sets out what access to a general-purpose AI model the Commission can require for an evaluation, naming source code, model weights and hosting infrastructure, and allowing it to require the provider to disable logging of that access

EU Can Demand Model Weights, and Your Logs Off. The Leveraged Years regulation briefing card.

The AI Act gave the Commission a power to evaluate general-purpose models. This is the instrument that says what evaluation means in practice, and it is considerably more intrusive than a document request.

The short version

Bottom line: A binding implementing regulation specifying the detailed arrangements for Commission proceedings under the AI Act. Its operative content on model evaluation defines the access a provider must give, sets a duty to provide it without undue delay, and prohibits constraints that would materially impede a proper evaluation.

Who this affects: Providers of general-purpose AI models within the Commission's supervision, their security and infrastructure teams, and counsel advising on what a regulator can compel. Also relevant to anyone modelling trade secret exposure in an EU evaluation.

Issue date: Adopted 20 July 2026, published in the Official Journal on 21 July 2026.

What changed: The AI Act already allowed the Commission to evaluate general-purpose models. What is new is the specification of what that entails: enumerated access types up to and including model weights, a defined time limit, and an express power over the provider's own logging.

Analysis: Two features distinguish this from an ordinary information-gathering power. The access list is defined by capability rather than by document, and expressly contemplates reaching the level of access the provider grants its own employees. And the logging provision runs in the opposite direction from most transparency rules: it lets the regulator require the regulated party to stop observing. Both are in the enacting articles, not the recitals.

Primary sources: Commission Implementing Regulation (EU) 2026/1755, Official Journal PDF · Same instrument on EUR-Lex

Instrument
Commission Implementing Regulation (EU) 2026/1755 on detailed arrangements for the conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689
Citation
Regulation (EU) 2026/1755; OJ L, 21 July 2026; CELEX 32026R1755
Authority
European Commission
Parent instrument
Regulation (EU) 2024/1689, the AI Act, in particular Article 92 on evaluations of general-purpose AI models
Jurisdiction
European Union
Status
Adopted 20 July 2026, published 21 July 2026.
Bindingness
A binding implementing regulation. The access duty falls on providers of general-purpose AI models that receive a Commission decision under Article 92(3) of the AI Act.
Editorial Note
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Primary source
https://eur-lex.europa.eu/eli/reg_impl/2026/1755/oj/eng/pdf

What access means

The regulation does not define access by reference to documents or answers. It defines it by reference to the model, and enumerates the forms it may take.

Access may include application programming interfaces, internal access, access to source code, access to model weights, access to the infrastructure used for hosting the general-purpose AI model, and access to inspect and modify the system state during interaction with the model.

It then indicates how far that can extend: such access may include but is not limited to all levels of access granted to employees of the provider. Read precisely, that is an illustration of what access may comprise, not an automatic entitlement to parity with every employee in every evaluation. What it establishes is that employee-level access is within the contemplated range rather than beyond it.

There is an anti-avoidance duty attached. Providers requested to provide access must ensure that the access provided is not subject to technical or other constraints that materially impede an appropriate evaluation. Granting nominal access through a channel that cannot support a real evaluation is therefore not compliance.

The logging provision

The provision most likely to surprise a compliance team concerns the provider's own telemetry.

The Commission may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process.

The direction of travel is worth pausing on. Nearly every obligation in this field requires the regulated party to record more and retain longer. This one permits a regulator to require it to record less, so that the subject of an evaluation cannot observe how the evaluation was conducted.

The rationale given is integrity and confidentiality of the evaluation, and the qualifier is doing real work: only to the extent necessary. But the practical consequence for a provider is that its standard security monitoring may have to be suspended over a defined window, which is a control it will need to have thought about in advance rather than during a decision.

Timing, and who carries out the evaluation

The duty is not open-ended in either direction. Providers requested to provide access under Article 92(3) of the AI Act must provide it without undue delay and within the time limit established in the Commission's decision, enabling access to all the elements of the model necessary to achieve the objectives in Article 92(1).

So the scope of access is tethered to the purpose of the evaluation rather than being at large, and the time limit is fixed by the decision rather than negotiated afterwards.

The regulation also addresses who may do the work. Where the Commission appoints an independent expert to carry out evaluations on its behalf under Article 92(2), it must assess that expert's independence from any provider of an AI system or general-purpose AI model, taking into account matters including shared ownership and governance.

That matters commercially. The people who are technically capable of evaluating a frontier model are concentrated in a small number of organisations, many of which have relationships with providers, and the regulation acknowledges the problem by requiring the entanglements to be assessed rather than assumed away.

What to do about it

For a provider in scope, the useful step is to work out in advance what each enumerated access type would actually mean in your environment. Access to model weights and to hosting infrastructure are not abstractions, and an organisation that has never considered how it would grant them under a deadline will be deciding under one.

The employee-level reference is the most practical planning tool in the instrument. It is illustrative rather than an entitlement, but if a category of access exists for staff it is within the range the regulation contemplates, so an internal map of what employees can reach is a reasonable proxy for the upper end of exposure.

The logging provision needs a named owner. Suspending monitoring is normally a security incident, and doing it lawfully on a regulator's requirement needs a pre-agreed process, an approval path and a record, none of which can sensibly be improvised.

One point of proportion to keep, stated in both directions. This is procedural machinery for evaluations under an existing power, not a new substantive obligation about how models are built, and it applies only where the Commission has taken a decision. Article 92 itself is bounded: it is engaged for assessing compliance where information obtained under Article 91 is insufficient, or for investigating systemic risk in a model with systemic risk. So it should not be reported as a general right of inspection over every AI system. Equally it should not be minimised, because the depth of access is now spelled out in binding enacting text rather than left to negotiation.

Key compliance takeaway

This is the instrument that converts the AI Act's evaluation power into something operational, and the detail sits in the enacting articles rather than the recitals. Article 2(2) says access may include APIs, internal access, source code, model weights, the infrastructure hosting the model, and the ability to inspect and modify the system state during interaction, and that it may include but is not limited to all levels of access granted to the provider's own employees. That is an illustration of reach, not an automatic entitlement to employee parity in every case. Access must not be constrained in ways that materially impede an appropriate evaluation, and is owed without undue delay within the time limit set in the decision. Article 2(3) lets the Commission require the provider to disable logging that would track or record the Commission's access, but only to the extent necessary for the integrity and confidentiality of the evaluation, which reverses the usual direction of a transparency obligation. The power is bounded by Article 92 of the AI Act, which is engaged where information already obtained is insufficient or where a systemic-risk model is under investigation. Two practical steps follow: map what your employees can reach, as a proxy for the upper end of exposure; and give any logging suspension a named owner and a pre-agreed process.

Source File

https://eur-lex.europa.eu/eli/reg_impl/2026/1755/oj/eng/pdf

Open the Official Journal PDF and confirm four things: the header showing Regulation (EU) 2026/1755 of 20 July 2026, published OJ L 21.7.2026, on detailed arrangements for the conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689; in Article 2, the enumeration of access including APIs, internal access, source code, model weights, hosting infrastructure and inspecting and modifying the system state, together with the statement that access may include all levels of access granted to employees of the provider; Article 2(3), permitting the Commission to require the provider to disable logging measures that could track or record the Commission's access; and Article 2(4), requiring access without undue delay within the time limit set in the decision.

The Commission may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process. Commission Implementing Regulation (EU) 2026/1755, Article 2(3), 20 July 2026

FAQ

What access can the Commission require?

Access that may include application programming interfaces, internal access, source code, model weights, the infrastructure used for hosting the model, and the ability to inspect and modify the system state during interaction with it. The regulation adds that such access may include, without limitation, all levels of access granted to the provider's own employees.

Can a provider give limited access instead?

Not if it impedes the evaluation. Providers must ensure the access provided is not subject to technical or other constraints that materially impede an appropriate evaluation.

Can the Commission really require logging to be turned off?

Yes, within a limit. It may require the provider to disable any logging measures that could track or record the Commission's access, to the extent necessary to ensure the integrity and confidentiality of the evaluation process.

How quickly must access be given?

Without undue delay and within the time limit established in the Commission's decision, covering all elements of the model necessary to achieve the objectives of Article 92(1) of the AI Act.

Who carries out the evaluation?

The Commission, or an independent expert it appoints under Article 92(2) of the AI Act. Where it appoints an expert, it must assess that expert's independence from any provider, taking into account matters including shared ownership and governance.

Is this a general power of inspection over AI systems?

No. It is procedural machinery for evaluations of general-purpose AI models under an existing AI Act power, and it operates where the Commission has taken a decision requiring access.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}