Why it matters
  • Lead. The European AI Office in Brussels, working with 24 national market surveillance authorities, has launched the first scheduled wave of AI Act compliance inspections in September 2026, targeting high-risk AI systems deployed in hiring, retail banking and private healthcare.
  • Fact. Inspectors are auditing three specific system types: automated resume screening tools, algorithmic credit assessment systems, and AI medical triaging tools — all classified as high-risk under the Act and required to have been in compliance since August 2, 2026.
  • Stake. Providers found non-compliant face fines of up to €35 million or 7% of global annual turnover, whichever is higher — making this the first moment the EU’s AI governance framework shifts from rulemaking to active enforcement with real financial consequences.

The European AI Act’s enforcement machinery moved from theory to practice in September 2026 as the European AI Office in Brussels, working alongside 24 national market surveillance authorities, began its first scheduled round of compliance inspections, detailed in a September 2026 regulatory update. The inspections focus on France, where CNIL is leading the effort, Germany (BfDI) and Spain (AESIA), concentrating on high-risk AI systems in three sectors that regulators have identified as presenting the most immediate risks to individual rights.

What Is Being Inspected

The three targeted system types represent the leading edge of AI deployment in employment and consumer-facing services. Automated resume screening tools — widely used to rank and filter job applicants — have drawn scrutiny for their potential to embed historical biases in hiring outcomes. Algorithmic credit assessment systems in retail banking are being audited for their transparency, the adequacy of human oversight, and whether they comply with Article 11’s technical documentation requirements. AI triaging tools in private healthcare clinics, which route patients to different levels of care, are being reviewed for risk management systems and cybersecurity benchmarks.

Inspectors are requesting what the Act calls Article 11 Technical Documentation dossiers: system architecture diagrams, training data governance logs, human oversight architecture, and risk management records. Providers are required to present these documents before placing systems on the market or deploying them operationally. Systems deployed after August 2, 2026 without complete documentation are the primary targets of this initial wave.

GPAI Model Deadline

Separately, September 15 marked a parallel enforcement deadline for providers of general-purpose AI foundation models that exceed 10²⁵ floating-point operations of compute during training. Those providers were required to submit formal systemic risk evaluations to the European AI Office, including red-teaming methodologies and copyright compliance documentation. The dual-track enforcement — one focused on deployed high-risk systems, the other on the most powerful frontier models — reflects the Act’s attempt to regulate both the point of deployment and the supply chain upstream of it.

The EU’s approach contrasts with the trajectory in the United States. California became the first US state to mandate third-party audits of AI systems, but there is no equivalent federal framework, and enforcement at the state level remains nascent. The EU inspections mark the first time a major jurisdiction has moved from legislating AI governance to actively auditing deployed systems, establishing a precedent that regulators in other markets are watching closely.