Model Releases
Release notes just became compliance artifacts
With AI Act enforcement live, the AI Office can request technical documentation, evaluate models and require corrective measures. What a lab publishes at launch now has a regulatory reader.
The European Commission's AI Office began enforcing the AI Act on 2 August, with powers over general-purpose AI models that include requesting technical documentation, evaluating models directly and requiring corrective measures.
That changes the status of a model launch. The documentation accompanying a release is no longer purely developer communication — it is the first draft of what a regulator will read.
It shows in how releases are now written
The capability-threshold language appearing across recent launches is a good example. A vendor stating that a model meets a critical cybersecurity capability threshold is making a public, dated, specific claim about risk. A year ago that would have been a research disclosure. Now it is a statement with a regulatory audience and a discovery trail.
The same goes for published refusal rates, evaluation methodology and access-programme criteria. These read as marketing and function as evidence.
Everything a lab publishes about a model's limits is now a commitment somebody can hold them to.
What it means downstream
For deployers, vendor documentation has become more useful and more dangerous at once. More useful because it is more specific and more likely to be accurate, given the consequences of being wrong. More dangerous because relying on it does not transfer your obligation — you remain responsible for your deployment regardless of what the model card says.
The practical discipline is to archive the documentation as it stood when you made your decision. Vendor pages change silently. If you justified a deployment on a published evaluation, keep the version you relied on, dated, with the decision it supported. That record is what turns a vendor claim into part of your own case rather than a hyperlink that may not resolve the same way later.
The direction of travel
Expect launch documentation to keep getting more structured, more hedged and more legally reviewed. Some of that is genuine progress — the transparency is real and it is better than what preceded it.
But documentation written for a regulator is optimised for defensibility, not for helping you decide. The questions you actually need answered about your deployment will keep not being in it, because they were never the audience.
Sources
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs — The Hacker News
- EU Artificial Intelligence Act — developments and analyses — artificialintelligenceact.eu
Written by the Devence Lab research team.