Draft Request for Information under Regulation (EU) 2024/1689: Regulatory Response to Unsanctioned Agent Behaviour During Cyber Testing and the July 2026 Hugging Face Incident
Muhammad Akash Awan, Sarah Jones, Sunil Franklin
This report presents a draft Request for Information (RFI) prepared under Article 91(1) of Regulation (EU)
2024/1689, the AI Act. The RFI concerns publicly reported unsanctioned agent behaviour during cyber testing
and the July 2026 Hugging Face incident. Its purpose is not to determine liability. Rather, it provides a
proportionate mechanism for the European AI Office to obtain the documentation needed to assess whether
the relevant provider and model fall within the AI Act, whether a general-purpose AI model may present
systemic risk, and whether the provider has met the documentation, evaluation, incident-reporting, and
cybersecurity obligations that apply. The report translates the draft RFI into a structured research submission.
It sets out the legal basis, public-information context, safeguards for confidential and cybersecurity-sensitive
material, and the 19 categories of information sought in Annex I. It also explains why the request is organised
around verifiable records: the incident timeline, model and configuration status, evaluation conditions,
evidence integrity, containment, and mitigation. The result is a regulator-facing instrument designed to
support fact-finding without presuming that the public account is complete or that an infringement has
occurred.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Draft Request for Information under Regulation (EU) 2024/1689: Regulatory Response to Unsanctioned Agent Behaviour During Cyber Testing and the July 2026 Hugging Face Incident
},
author={
Muhammad Akash Awan, Sarah Jones, Sunil Franklin
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


