ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
EU AI Act Enforcement Enters Its Operational Phase: Hiring and Credit-Scoring AI First in Line for Checks

EU AI Act Enforcement Enters Its Operational Phase: Hiring and Credit-Scoring AI First in Line for Checks

AI compliance • Admin • • 3 views

The EU AI Act is moving from paper rules to operational enforcement: on 17 September, the EU AI Board held its ninth meeting with the Commission's enforcement activities and priorities at the top of the agenda; in early September the European Commission sent formal requests for information to more than 30 AI providers; and according to media reporting on 24 September, the EU AI Office is carrying out a first coordinated wave of compliance checks with 24 national market surveillance authorities, with hiring, credit-scoring, student-monitoring and healthcare-triage AI systems first in the spotlight.

What happened: three September developments put enforcement on the table

The first was the ninth Board meeting on 17 September, chaired by Ireland in its role holding the Presidency of the Council of the EU, with Moldova attending as an observer for the first time. According to the meeting summary published on the Commission's website on 18 September, discussion focused on the Commission's enforcement activities and priorities, progress on implementing the transparency rules applicable since 2 August (including the Code of Practice and accompanying guidelines), market-surveillance cooperation among Member States, and the Action Plan on Cybersecurity and AI.

The second was the formal information requests of 1 September. At that day's daily press briefing, a Commission spokesperson confirmed that formal requests for information had been sent to more than 30 AI providers, covering model security and evaluation practices, post-market monitoring arrangements, and copyright compliance of training data. It was the first time the Commission used this finable investigative instrument since its enforcement powers took effect on 2 August.

The third was September's first coordinated inspection wave. According to industry reporting on 24 September, the EU AI Office has teamed up with 24 national market surveillance authorities for a first wave of compliance checks on Annex III (high-risk) systems such as recruitment software, with the scope since widened to credit scoring, education and healthcare-triage systems. One caveat: the "first formal dockets" framing comes from media reporting; the Commission's own summary speaks of "enforcement activities and priorities."

Who is affected: model vendors and deployers of hiring and credit AI are first in line

Three groups are in scope, and the trigger is "placing on the EU market or putting into service" — regardless of where the company is incorporated:

  • General-purpose AI model providers: any model served in the EU must have technical documentation and a training-data summary ready, and submit to the AI Office's own evaluations; models with systemic risk must report serious incidents "without undue delay." Replies to information requests that are incorrect, incomplete or misleading can themselves draw fines.
  • Deployers of high-risk AI: users of Annex III systems for hiring screening, credit scoring, student monitoring and healthcare triage. The checklist includes registration in the EU database, human-oversight arrangements, notices to affected people, system logs, and fundamental-rights impact assessments for credit scoring and public-service use.
  • Buyers: public-sector and regulated-industry procurers in the EU have started writing compliance-evidence requirements into tenders — document readiness is becoming a sales qualification.

Copyright deserves its own mention: general-purpose model providers must publish a "sufficiently detailed" training-data summary, which may in turn become a lead for creators asserting their rights. A recent US Ninth Circuit ruling on AI-generated code and copyright management information shows how differently the two sides of the Atlantic are approaching training-data questions.

What to do: get these three evidence packs ready

  1. The provider evidence pack: technical documentation, training-data summaries, third-party evaluation records, post-market monitoring processes. The Commission can now compel these materials — and run its own evaluations instead of accepting vendor self-assessments.
  1. The deployer responsibility list: first confirm whether your system genuinely falls under Annex III — support chatbots and product recommenders do not; name the person accountable for human oversight; prepare the notices and logs for candidates, borrowers and other affected people.
  1. Watch the 2 December deadline: systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty; new prohibitions, including on AI-generated non-consensual intimate imagery, also apply from that date.

Worth noting alongside: the EU's recently adopted KIDS Act proposal brings minor protection into the AI compliance picture too, so products aimed at young users need a parallel assessment.

Where the risks are: the two easiest misreadings

First, "high-risk compliance deferred to 2027" does not mean enforcement is paused. The Digital Omnibus (Regulation (EU) 2026/1744), in force since 27 July, did push Annex III conformity assessment to 2 December 2027 — and AI embedded in regulated products to 2 August 2028 — but only that one track was deferred. Prohibitions (applicable since February 2025), general-purpose AI duties (since August 2025) and the investigative powers are untouched.

Second, the fines and withdrawal powers are real. Prohibited practices can draw up to €35 million or 7% of global annual turnover; general-purpose AI breaches up to €15 million or 3%, whichever is higher. More immediate is the market-restriction power: the AI Office can order a system withdrawn or disabled while a question is unresolved — a documentation gap can turn directly into a revenue event.

There is also a parallel track: data-protection authorities will not wait for the AI Act timetable. Spain's data protection authority has reportedly issued a preemptive warning over a company's hiring-AI plans, demanding data-protection safeguards, a risk assessment and meaningful human oversight. GDPR compliance and AI Act compliance must each be satisfied on their own terms — clearing one does not clear the other.

The EU AI Act's enforcement sequence was written into the law from the start: prohibitions first, then the transparency and copyright duties for general-purpose models, and only then high-risk conformity assessment. September's moves show that sequence is being followed to the letter — for vendors selling hiring, credit, education or healthcare AI in Europe, the deliverable is no longer a 2027 plan, but the next document request.

Recommended Tools

More