Until this month, EU AI Act enforcement was mostly theoretical: a framework of penalties and authorities that existed on paper but had not yet acted. That changed in the first two weeks of September 2026. The European Commission's AI Office sent its first formal requests for information to more than 30 AI companies, and national market surveillance authorities opened the first coordinated wave of compliance inspections. Here is exactly what happened and who it affects first.
What the Commission actually did
On 1 September 2026, the European Commission confirmed it had sent requests for information under its AI Act enforcement powers to over 30 AI companies. The requests cover three areas: safety and security of general-purpose and frontier models, copyright compliance, and transparency obligations. This is the Commission exercising the direct enforcement authority it has held over general-purpose AI (GPAI) model providers and the Act's prohibited practices since 2 August 2026.
A request for information is not a fine and not an accusation. It is the standard first step of a regulatory investigation: the Commission asking a company to document and justify its compliance before deciding whether further action is warranted. But it is a clear signal that the AI Office intends to use the powers it has, not let them sit unused.
National authorities opened inspections on three specific system types
Separately, the AI Office is coordinating with 24 national market surveillance authorities, led by France's CNIL, Germany's BfDI and Spain's AESIA, on the first scheduled wave of compliance inspections. Unlike the Commission's GPAI-focused information requests, these inspections target specific high-risk system types already in deployment:
- Automated CV and resume screening — AI that ranks, filters or shortlists job candidates.
- Algorithmic credit assessment — AI used to score creditworthiness or approve lending decisions.
- AI medical triage — AI that prioritises or directs patients in clinical settings.
These three categories were not chosen at random. They sit squarely in Annex III of the EU AI Act, employment (point 4), creditworthiness (point 5(b)), and healthcare, and they are exactly the kind of consumer-facing, high-stakes automated decision-making the regulation was written to catch first. If you operate a recruitment platform, a lending or BNPL product, or clinical decision-support software with EU users, your system type is one national authorities are actively looking at right now.
But the Annex III deadline is still December 2027, so why does this matter today?
This is the detail worth sitting with. The Digital Omnibus postponed the full Annex III conformity regime, technical documentation, EU database registration, conformity assessment, to 2 December 2027 (see our breakdown of what the Digital Omnibus changed). That has not moved. What has already started is:
- Market surveillance authorities identifying and cataloguing high-risk deployments ahead of the 2027 deadline, so they know who to check first once conformity becomes mandatory.
- Article 50 transparency obligations, which are unaffected by the Annex III delay and have applied since 2 August 2026.
- The Commission's GPAI and prohibited-practice enforcement powers, live since August 2026, independent of the Annex III timeline entirely.
In other words: an inspection today is not (yet) about your Annex III conformity file, because that file is not due yet. It is authorities building the case list, checking Article 50 disclosures, and getting eyes on the exact system types Annex III already names. Being on that list in September 2026, with nothing to show, is a worse position than being on it in December 2027 having already classified your system and started documentation.
What to do if you run one of these three system types
- Confirm your risk classification in writing. If you already know you are high-risk under Annex III, you should be able to say why, and cite the specific point (4, 5(b), or the healthcare provisions) that applies.
- Check your Article 50 disclosure is live and correct. This is the one obligation an inspector can act on today, not in 2027.
- Start technical documentation now, while the system's design decisions and training data provenance are still fresh, rather than reconstructing them under time pressure once the 2027 deadline is closer and inspection volume is higher.
Read our dedicated guides for the three system types under inspection: recruitment and CV screening, credit scoring and lending, and medical diagnosis and clinical decision support. Each lays out the exact Annex III basis, the obligations, and the current deadline.
EuroComply's free EU AI Act assessment classifies your system's risk tier in about 3 minutes and returns the documents your tier requires, with the legal article and deadline for each, so you know exactly where you stand before an information request lands in your inbox.