Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Breaking Regulation

EU AI Act: First Compliance Inspections Are Now Underway

EU AI Office launches first inspection wave targeting HR, banking, and healthcare AI. September 15 deadline looms for major model providers.

Enterprise DNA | | via European Commission AI Office
EU AI Act: First Compliance Inspections Are Now Underway

Six weeks after the EU AI Act’s enforcement machinery switched on, European regulators have moved from issuing warnings to opening files. Throughout September 2026, the European AI Office — working alongside 24 national market surveillance authorities — is conducting its first scheduled wave of compliance inspections, targeting businesses deploying high-risk AI in three sectors: human resources, retail banking, and healthcare.

The moment that many businesses hoped was still abstract just became operational.

Who’s Getting Inspected First

The initial inspection requests are being led by three national regulators: France’s CNIL, Germany’s BfDI, and Spain’s AESIA. The sectors weren’t chosen randomly — they represent the highest concentration of automated decision-making that directly affects people’s lives.

Human resources: The focus is automated resume screening tools. If your business uses AI to filter, rank, or reject job applicants — whether built in-house or through a vendor — you are in scope. Regulators will be looking for Technical Documentation dossiers, bias testing records, and evidence of human oversight in the decision chain.

Retail banking: Algorithmic credit assessment systems are under the microscope. This covers any AI-driven credit scoring, loan approval, or risk profiling tools used with retail customers. Providers and deployers both face scrutiny.

Private healthcare: AI triaging tools — systems that prioritise patient care, flag urgent cases, or recommend diagnostic pathways — are being reviewed for safety validation, data quality records, and post-market monitoring evidence.

The EU AI Act requires providers of high-risk systems to have an up-to-date Technical Documentation dossier on hand before deploying. Inspectors will audit specific technical assets: system architecture diagrams with hardware and software topology, data pre-processing scripts, and model weight versioning records. This is not a questionnaire. Inspectors can request direct access to documentation and, in some circumstances, the systems themselves.

The September 15 Deadline for Model Providers

For the companies building the foundation models that power these applications, there is a parallel and pressing deadline: September 15, 2026.

By that date, providers of general-purpose AI (GPAI) foundation models that exceed the 10^25 FLOPs training threshold — which captures virtually every major frontier model in commercial use — must submit their first formal systemic risk evaluations to the European AI Office.

The evaluation package must include:

  • Red-teaming methodology reports (showing adversarial testing was conducted)
  • Energy consumption disclosures across training and inference
  • Compliance with the standardised copyright training data summary template published in July 2026

The AI Office will review these evaluations and has the authority to request corrective actions, public disclosures, or escalate cases to member state authorities if submissions are incomplete or indicate non-compliance.

This matters for any business that relies on a major third-party AI model. The regulatory scrutiny does not stop with the model provider — it flows downstream through commercial agreements, usage policies, and ultimately to the business deploying the model.

The Enforcement Apparatus Is Real

The EU AI Office now has 38 dedicated enforcement staff. That is not a large number relative to the volume of AI systems in the European market, but it is sufficient to conduct targeted, sector-specific investigations — which is exactly what September’s inspection wave represents.

The whistleblower mechanism adds a dimension that many businesses haven’t factored in: employees, contractors, and third-party partners can report suspected violations of watermarking, documentation, or systemic-risk obligations directly to EU regulators. Internal governance gaps that would otherwise stay internal are now an external risk.

Penalty exposure is real. Non-compliance with high-risk AI obligations can trigger fines of up to €15 million or 3% of total global annual turnover, whichever is higher. For systemic-risk GPAI model violations, the upper bound is 3% of global annual turnover.

What This Means for Businesses Operating in Europe

The transition from guidance to enforcement is complete. The question for any business deploying AI that touches EU users is not whether to comply, but whether compliance documentation is in the shape regulators expect.

Three immediate priorities:

1. Audit your AI inventory for high-risk classification. If you are running automated decision systems in hiring, lending, insurance, or medical triage — or if you are building tools for those sectors — those systems are likely high-risk under the EU AI Act. The classification is based on what the system does, not how sophisticated it is.

2. Get Technical Documentation to the standard regulators expect. This isn’t a summary document. It’s a structured technical record covering data governance, model architecture, testing methodology, and post-deployment monitoring. If your vendor built the system, you need their documentation and evidence of your own oversight processes.

3. Pressure-test your third-party agreements. If your AI capabilities come from a GPAI provider, their September 15 submission may create obligations that flow to you through contract terms. Review what your agreements require you to do when a model is subject to a regulatory action.

The Bigger Picture

The EU is not operating in isolation. As Brussels conducts its first inspections, Washington is actively pushing a lighter-touch approach at G20 level. The divergence matters for global businesses: a system designed for a US market may need significant adaptation — in documentation, human oversight requirements, and audit trails — before it can legally operate in Europe.

Businesses that treated August 2 as the start of a long compliance runway may find September’s inspections a sharp correction to that timeline.


Enterprise DNA helps organisations build the data and AI capability they need to navigate this shift — from understanding what compliance actually requires to deploying AI systems that perform and hold up to scrutiny. If you’re mapping your AI inventory and don’t know where to start, talk to the team.