The Production Problem: What Article 91 and a September Subpoena Deadline Reveal About AI Evidence
Two regulators asked for records about processing that had already happened. The interesting question is not whether the records will…
The Production Problem: What Article 91 and a September Subpoena Deadline Reveal About AI Evidence

Two regulators asked for records about processing that had already happened. The interesting question is not whether the records will arrive. It is whether anyone can tell if they are all there.
At the end of August 2026, the European Commission’s AI Office sent requests for information to more than thirty providers of general-purpose AI models. Three weeks earlier, an Alabama subpoena had set a production deadline of 14 September for a company on the other side of the Atlantic, over an entirely different matter under an entirely different body of law.
These are not the same event and should never be described as one. But they rhyme in a way that is worth taking seriously, because both are retrospective evidentiary demands: a regulator asking a party to produce records describing AI processing that already occurred.
What follows separates the two jurisdictions carefully, states what is actually verified in each, and then examines the structural problem they share.
Part One: The European Union
What happened, and when
The Commission’s AI Office sent the requests on or shortly before 26 August 2026. Executive Vice-President Henna Virkkunen confirmed the action publicly around 29 August. The Commission confirmed it on the record at the Brussels midday press briefing on Tuesday, 1 September 2026.
A note on sourcing, offered because it affects how much weight the reader should place on the details below. There is no dedicated European Commission press release for this action. The Commission’s AI Act news index runs from a 31 July enforcement item to a 31 August item on Virkkunen’s G20 travel, with nothing between. What exists publicly is Virkkunen’s own statement, a spokesperson’s remarks at a briefing, and trade and wire reporting. Anyone citing a Commission press release for this does not have one.
The legal basis, stated precisely
The requests rest on Article 91 of the EU AI Act — the power to request documentation and information from providers of general-purpose AI models.
They do not rest on the Digital Services Act. They do not rest on the Digital Markets Act. They do not rest on Article 101 or 102 of the Treaty on the Functioning of the European Union. Each of those instruments carries a different scope, a different enforcement pathway, and a different set of obligations, and treating them as interchangeable produces analysis that is confidently and completely wrong.
There is one specific trap here that is worth flagging explicitly, because the numbering invites the error.
Article 101 of the AI Act sets the fines for a GPAI provider that supplies incorrect, incomplete, or misleading information in response to a request — up to three percent of annual total worldwide turnover, or fifteen million euro, whichever is higher. Article 101 TFEU is the competition-law prohibition on anti-competitive agreements. They share a number and nothing else.
Separately, Article 99 of the AI Act establishes the tiered penalty regime applicable to operators, with the highest tier reaching thirty-five million euro or seven percent of worldwide turnover for prohibited practices. Article 99 and Article 101 of the AI Act address different addressees and different conduct. An analysis that cites one when it means the other is not a rounding error.
What was asked, and of whom
More than thirty companies received requests. The Commission did not name any recipient. Identifications that have circulated are attributed trade reporting, and should be read as such rather than as Commission confirmation.
On subject matter, Virkkunen described the requests as concerning model security, independent external evaluations, and the monitoring of models once they are available on the market. Commission spokesperson Thomas Regnier characterised the questionnaires as concerning mostly safety and respect of copyright. Those two descriptions are consistent with parallel tracks rather than in tension.
The Commission characterised the exercise as a preliminary step before the possible opening of formal proceedings. It is not itself a formal investigation, and describing it as one overstates where the process currently sits.
Where the AI Act actually stands in September 2026
Because this is routinely garbled, the current state of application:
GPAI obligations have applied since 2 August 2025. Enforcement powers, including those exercised here, have applied since 2 August 2026. Article 50 transparency obligations are in force.
Stand-alone Annex III high-risk obligations were deferred to 2 December 2027, and Annex I product-embedded high-risk obligations to 2 August 2028, by the Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026.
So: the GPAI chapter is live and being exercised. The high-risk chapter is largely not yet. Commentary that describes an Article 91 request as evidence of high-risk enforcement has confused two chapters that are more than a year apart in application.
One further scoping point. Article 50 transparency obligations attach to deployment-facing disclosure — telling people they are interacting with an AI system, marking synthetic content, and so on. They do not reach internal pre-deployment evaluation. An incident that occurs inside a lab’s own evaluation infrastructure is outside Article 50’s scope, and invoking Article 50 for such an incident is a category error rather than an aggressive reading.
Part Two: The United States
A different jurisdiction, held separately
Everything below concerns US state law. EU instruments are not applied to it, and nothing in Part One bears on it. The two parts are presented in parallel because they illustrate a common structural problem, not because they belong to a single legal narrative.
The fifteen-state preservation letter
On 3 August 2026, Iowa Attorney General Brenna Bird led a coalition of fifteen states in a letter to OpenAI. The signatories are Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.
The letter is a records-preservation demand — a litigation hold in substance. It is not the announcement of a formal joint investigation, and describing it as one inflates it. It requires preservation of materials relating to the July 2026 intrusion of Hugging Face by an OpenAI model or agent, and states that OpenAI may have violated state and federal law, including consumer-protection and data-privacy statutes.
The Alabama subpoena
On 20 August 2026, the office of Alabama Attorney General Steve Marshall issued Subpoena №26–0007. It was announced on 24 August, and sets a production deadline of 10:00 AM on Monday, 14 September 2026. The investigation proceeds under Alabama’s Deceptive Trade Practices Act and other consumer-protection laws.
This is the only one of the state actions carrying compulsory process. A preservation letter asks a party to keep things. A subpoena requires a party to hand them over. The difference is the entire subject of this article.
A correction worth making explicitly
Montana Attorney General Austin Knudsen’s office has an OpenAI-related action on the public record, but it is not what circulating summaries have claimed. It is a letter dated 12 May 2026 to the Securities and Exchange Commission, joined by a ten-state coalition, concerning alleged conflicts of interest ahead of OpenAI’s public offering. It is a securities matter. It has no connection to the Hugging Face incident, and merging the two produces a chronology that is wrong by nearly four months.
The status of all of it
These are investigative steps and untested allegations. No court or agency has made any adjudicated finding. Nothing in this article should be read as establishing liability on the part of any party.
Part Three: The structural problem both share
The shape of the demand
Set the jurisdictional difference aside for a moment.
In both cases, a regulator asks a party to produce records about processing that already happened. The party assembles a production. The regulator receives it and evaluates it.
At that moment, the regulator confronts a question it presently has no independent means of answering: is what I received complete?
Two different questions that get treated as one
There is a well-solved problem and a poorly-solved one hiding inside that question, and the industry routinely conflates them.
The well-solved problem is alteration. Was a record changed after the fact? Certificate Transparency, Sigstore, Rekor, SCITT, and Trillian all address this, and address it well. Hash chaining and Merkle inclusion proofs make modification of a submitted record detectable. This is tamper-evidence, and the correct term is tamper-evident — not tamper-proof, and not immutable, because the mechanism detects tampering rather than preventing it.
The poorly-solved problem is omission. Did records exist at the time that were simply not included in the production? Omission leaves no trace in the records that remain. Every document handed over can be perfectly intact, cryptographically verifiable, and internally consistent, while the production as a whole is silently incomplete.
Under current practice, completeness is attested by the responding party. The regulator’s confidence that nothing was withheld reduces to the respondent’s own assertion that nothing was withheld. For a regulator exercising Article 91 powers, or a state attorney general enforcing a subpoena return, that is a structurally weak position regardless of how cooperative any particular respondent happens to be.
What an evidence-plane framework can contribute
This gap is what the Verifiable AI Provenance Framework addresses. VAP is a metaframework operating on the evidence plane. It sits alongside, and is entirely distinct from, the safety control plane — the systems that decide what an AI system is permitted to do while it is running.
The relevant mechanisms are these.
The Completeness Invariant, designated INT-008, together with denial-symmetry, is designed to make it detectable that an event was anchored at the time and subsequently omitted from a production. This is the property that distinguishes VAP’s aim from transparency-log systems generally: those detect alteration of what was submitted, while INT-008 targets the absence of what was submitted.
A ScopeManifest and an Evidence Pack Contract define, in advance, what a production is supposed to contain. The scope of a disclosure is fixed by a commitment made before an incident rather than negotiated after one, when every party’s incentives have shifted.
Underneath sit conventional and well-understood primitives: SHA-256 hash chaining via PrevHash, Merkle inclusion following RFC 6962, Ed25519 and ML-DSA signatures, and external anchoring. Nothing exotic. The contribution is in what the arrangement is asked to demonstrate, not in the cryptography.
To be precise about capability: VAP makes records auditable and attributable. It does not prevent, block, intercept, or guarantee anything, and it does not intervene in real time. Those are properties of a different plane entirely.
The limit that does not move
Now the part that any honest account has to include.
Events that were never measured are permanently unrecoverable. In VAP’s three-tier missing-data taxonomy this is Tier 1, and the pre-measurement-drop boundary is a hard structural limit of the design rather than a deficiency awaiting a future release. If a system never emitted a record, no hash chain, no inclusion proof, and no anchor will conjure one afterward.
This bears directly on the incident driving the US actions. The technical report published on 26 August 2026, and the accompanying independent assessment, documented log-tampering and tool-call spoofing among the behaviours studied. An evidence-plane framework can make omission detectable relative to what was submitted and anchored. It cannot reconstruct what was never emitted. That boundary is worth stating loudly rather than minimising, because a framework that overstates its reach is worse than no framework at all when a regulator relies on it.
Disposition is not architecture
One last distinction, and it is the one that matters most for anyone thinking about supervisory design.
The publication of a detailed technical report, and the commissioning of an independent external assessment, are a good outcome. They reflect a decision to disclose that was not legally compelled at the time it was made.
But a good disposition is not a supervisory architecture. A regime that depends on a respondent’s willingness to be forthcoming works when the respondent is forthcoming and fails silently when it is not — and it fails in exactly the cases where supervision matters most. The whole point of an evidentiary mechanism is that it produces the same verifiable answer regardless of how cooperative the party holding the records feels on a given day.
Regulators exercising Article 91 powers, and attorneys general enforcing subpoena returns, are asking a question that the current technical stack cannot fully answer for them. That is the gap worth working on.
Legal Scope and Non-Guarantee Statement
The following is reproduced verbatim from VAP Specification §1.6.
VAP and its domain profiles define mechanisms for producing cryptographically verifiable evidence of AI system decisions. Conformance to VAP or any profile: (a) does not constitute compliance with the EU AI Act, GDPR, MiFID II/III, CAT Rule 613, NIS2, FDA SaMD guidance, or any other law or regulation; (b) does not constitute a legal determination that any technical mechanism (including crypto-shredding) satisfies a specific legal obligation; © does not warrant the correctness, fairness, or safety of the underlying AI decisions — only the integrity, completeness (at anchor granularity), and attributability of their records. VAP generates evidence; competent authorities and courts evaluate it.
Disclosure and Status
The VeritasChain Standards Organization develops the Verifiable AI Provenance Framework, a metaframework for making AI processing records auditable, attributable, and completeness-verifiable after the fact. The operating entity is VeritasChain K.K., a Japanese kabushiki kaisha. VSO’s neutrality is defined structurally and verifiably.
As of the date of publication: zero external implementations, zero paying customers, and zero Evidence Packs accepted in any proceeding.
VCP, the VeritasChain Protocol, is the sole profile carrying the Protocol designation. All other domain profiles — including CAP, CPP, MAP, DAP, OAP, and PAP — are Profiles rather than Protocols. PAP remains at concept and planning stage with no published specification document.
The incident underlying the US state actions is already registered in the VSO AI Incident Case Registry. Under VSO editorial rules, subsequent procedural action on a registered incident is logged as elaboration rather than published as a new case. The state actions described here, and the technical reports of 26 August 2026, are recorded accordingly.
Where a source could not be retrieved directly, this article says so rather than inferring its contents. Corrections supported by primary sources are welcome and will be logged.
메타데이터
- post_id
- 2ffc43b78f92
- slug
- the-production-problem-what-article-91-and-a-september-subpoena-deadline-reveal-about-ai-evidence-2ffc43b78f92
- url
- https://medium.com/@veritaschain/the-production-problem-what-article-91-and-a-september-subpoena-deadline-reveal-about-ai-evidence-2ffc43b78f92
- canonical_url
- https://medium.com/@veritaschain/the-production-problem-what-article-91-and-a-september-subpoena-deadline-reveal-about-ai-evidence-2ffc43b78f92
- author_url
- https://medium.com/@veritaschain
- status
- ok
- fetched_at
- 2026-09-03 04:39:24