AI Governance

The AI Act stopped being theoretical: first inspections begin

Published
Read time3 min read
AI Governance

Enforcement of the EU AI Act has moved from timetable to practice. On 1 September 2026 the European Commission sent its first requests for information to more than 30 AI providers, and the European AI Office, working with 24 national market surveillance authorities, has opened its first scheduled wave of compliance inspections. The three system types in scope should give a lot of organisations pause, because two of them are not AI products at all — they are ordinary business processes that happen to have AI inside them.

What has actually happened

The Commission's enforcement powers over general-purpose AI model providers became applicable on 2 August 2026. Less than a month later it used its investigatory powers for the first time. According to Agence Europe and analysis by Matheson, the requests went to more than 30 AI providers on 1 September and covered two strands: the safety and security of the most advanced models, and copyright and transparency.

Alongside that, the European AI Office and 24 national market surveillance authorities opened a first wave of compliance inspections targeting three high-risk system types:

  • Automated CV and resume screening
  • Algorithmic credit assessment
  • AI-assisted medical triage

The EU AI Board met on 17 September 2026 to coordinate enforcement; it did not set any new obligation or deadline.

Key points
Who is being asked
Model providers, via information requests, and deployers of specific high-risk systems, via inspections.
Why it matters to non-AI companies
Two of the three inspection categories are HR and lending functions, not AI products.
Next date on the calendar
Prohibited-practice provisions land on 2 December 2026.

The uncomfortable part: you may be a deployer already

Most organisations following the AI Act have been asking whether they build AI. That is the wrong first question. The obligations that bite soonest attach to deploying a high-risk system, and the inspection categories make the point neatly.

If your recruitment team uses an applicant tracking system that ranks or filters candidates, you are plausibly deploying automated resume screening. If your lending or insurance function uses a scoring model — including one embedded in a platform you bought — that is algorithmic credit assessment. Neither of those procurement decisions was necessarily made by a technology team, and neither is likely to be recorded anywhere that a compliance function would find it.

What an inspection will expect you to produce

The detail varies by system and authority, but the shape of it is predictable, because it is the shape of every other regulated assurance regime:

  • An inventory. Which AI systems are in use, what they do, who supplied them, who owns them internally and which risk classification applies.
  • Documentation from the provider. What the system was trained on, what it was tested for, its known limitations and its intended purpose — and evidence you are using it within that purpose.
  • Human oversight that is real. Not a policy saying a human reviews decisions, but evidence of who reviews what, with what authority to overturn, and how often they do.
  • Transparency to affected people. Article 50 duties have applied since 2 August 2026. Candidates and customers subject to these systems have information rights.
  • Monitoring after deployment. Performance and bias do not stay where they were at procurement.

Where to start if you have not

Begin with procurement and HR records rather than with the IT estate. Ask which tools in use make or materially influence decisions about people — hiring, credit, pricing, eligibility, triage. That list is almost always longer than the technology function expects and shorter than the worst case, and producing it is the single most useful week of work available on this topic.

The organisations that will handle an inspection calmly are not the ones with perfect AI governance. They are the ones that can answer "which systems, doing what, overseen by whom?" without starting a discovery exercise.

Build an AI registry and oversight model that would survive an inspection.

Talk about AI governance

Common questions

Very likely, yes. Deployers of high-risk systems carry obligations in their own right, including human oversight, transparency to affected people and use within the provider's intended purpose. The first inspection wave covers resume screening and credit assessment, which most organisations buy rather than build.

Automated resume screening, algorithmic credit assessment and AI-assisted medical triage. The European AI Office opened the wave with 24 national market surveillance authorities.

Article 50 transparency duties have applied since 2 August 2026, and the prohibited-practice provisions land on 2 December 2026. Timelines for some high-risk categories are subject to change under the Commission's proposed Digital Omnibus, so check the current position before planning against a specific date.

Sources

  1. European Commission sends first requests for information to more than 30 AI providers — Agence Europe, 2 September 2026
  2. The European Commission's first use of EU AI Act investigatory powers — Matheson, 10 September 2026
  3. The enforcement framework of the AI Act — European Commission, 1 September 2026