Key Takeaways
What did the EU AI Office do? Starting in September 2026, the EU AI Office and national market surveillance authorities began their first wave of compliance inspections under the AI Act, confirming on September 10, 2026 that automated rΓ©sumΓ©-screening and HR decision-making tools are included.
Which regulators are involved? The European Commission’s AI Office is coordinating with national authorities including France’s CNIL, Germany’s BfDI, and Spain’s AESIA, which are focusing initial requests on hiring tools, credit-scoring systems, and healthcare triage AI.
Are major AI model providers also affected? Yes. On August 29, 2026, the EU AI Office sent its first formal requests for information to general-purpose AI model providers including OpenAI, Anthropic, and Google, and the European Commission has since sent RFIs to more than 30 AI providers overall.
What are the penalties for noncompliance? Article 50 transparency violations carry fines up to β¬15 million or 3% of global annual turnover, whichever is higher, while prohibited-practice violations under Article 5 can reach β¬35 million or 7% of turnover.
What triggered active EU AI Act enforcement in September 2026?
The European Commission’s AI Office gained formal investigative and enforcement authority over general-purpose AI model providers and the Act’s prohibited practices as of August 2, 2026, when Article 50 transparency obligations became enforceable, according to the European Commission’s own digital strategy announcements.
That authority moved from theoretical to active over the following weeks. On August 29, 2026, the AI Office issued its first requests for information to major foundation-model providers, including OpenAI, Anthropic, and Google, covering model safety, independent external evaluation, post-deployment monitoring, and training-data summary disclosure. The European Commission has since sent similar first-round information requests to more than 30 AI providers in total, according to Agence Europe’s reporting.
Why do hiring tools specifically matter in this enforcement wave?
On September 10, 2026, the European AI Office confirmed that automated rΓ©sumΓ©-screening and HR decision-making tools are included in the first wave of inspections, putting HR technology vendors and the employers who deploy them under direct regulatory scrutiny.
National market surveillance authorities are working alongside the AI Office on this wave. French regulator CNIL, German regulator BfDI, and Spanish regulator AESIA are focusing their initial requests on three regulated use cases: automated rΓ©sumΓ©-screening tools in human resources, algorithmic credit-assessment systems in retail banking, and AI triaging tools in private healthcare clinics, according to coverage tracking the rollout.
Does this mean hiring AI is already subject to full high-risk compliance?
No. The compliance deadline for the AI Act’s Annex III high-risk system requirements covering employment decisions was extended from August 2, 2026 to December 2, 2027, a 16-month delay β but that deferral applies to the full high-risk conformity regime, not to the transparency obligations being actively enforced now.
This distinction matters for legal teams: even though employers have until December 2027 before the complete high-risk AI system requirements (conformity assessments, human oversight documentation, and risk-management systems) apply to hiring tools, the Article 50 transparency obligations β disclosing when AI is used to interact with or make decisions about a person β became enforceable on August 2, 2026 and are the specific basis for the current inspection wave.
What are companies actually being asked to produce?
Regulators are using formal requests for information (RFIs), a legal mechanism that compels a company to produce documentation, disclosures, and technical information within a set deadline as the first step of a compliance inquiry, rather than issuing findings or fines at this stage.
For the general-purpose AI model providers contacted in August, the RFIs covered model safety practices, independent external evaluation results, post-deployment monitoring processes, and summaries of training data used, according to reporting on the RFIs sent to OpenAI, Anthropic, and Google. Separately, the eight foundation models that exceed the regulatory compute threshold of 10^25 FLOPs are already required to submit monthly systemic risk evaluations to regulators under the Act’s rules for the most powerful models.
What penalties can companies face?
The AI Act uses a tiered penalty structure, with Article 50 transparency violations carrying fines of up to β¬15 million or 3% of total worldwide annual turnover, whichever is higher, and prohibited-practice violations under Article 5 carrying fines of up to β¬35 million or 7% of turnover.
Supplying incorrect, incomplete, or misleading information to AI Act regulators β relevant to how companies respond to the current RFIs β carries its own penalty of up to β¬7.5 million or 1% of global annual turnover. For SMEs and startups, the lower of the two figures in each tier applies rather than the higher one.
Why is enforcement targeting three specific sectors together?
Regulators grouped automated hiring tools, algorithmic credit-scoring systems, and AI healthcare triaging tools into the same first inspection wave because each involves an AI system making or materially influencing a consequential decision about an individual β employment, credit access, or medical prioritization β which is exactly the category of use case the AI Act’s transparency and high-risk provisions were designed to address.
This grouping signals that regulators are working sector by sector through high-stakes, individual-facing AI use cases rather than attempting to inspect every AI deployment across the economy simultaneously. Legal teams at companies in adjacent sectors β insurance underwriting, tenant screening, or educational admissions, for example β should treat this as a signal that similar consequential-decision AI systems are likely candidates for a future inspection wave, even if their sector was not named in the September 2026 round.
How does this connect to the broader push for foundation model oversight?
Separately from the sector-specific hiring and credit-scoring inspections, the AI Act imposes ongoing obligations on the most powerful general-purpose AI models: the eight foundation models that exceed the regulatory compute threshold of 10^25 FLOPs are already required to submit monthly systemic risk evaluations to regulators.
For legal teams at companies that build hiring or HR products on top of third-party foundation models, this creates a two-layer compliance picture: the foundation model provider carries its own systemic-risk reporting obligations to the AI Office, while the company deploying that model inside an HR product carries separate transparency and, eventually, high-risk conformity obligations as the deployer. Contracts with model providers should clearly allocate responsibility for each layer.
What does an EU AI Office information request actually look like in practice?
An RFI is a formal, legally binding document that specifies the categories of information a regulator wants, a response deadline, and the legal basis for the request; it is not an accusation of wrongdoing, but failing to respond accurately and on time can itself trigger penalties under the Act’s separate provision covering misleading or incomplete information to authorities.
Because RFIs have gone out broadly β more than 30 AI providers in total, according to Agence Europe’s reporting, plus the sector-specific inspections targeting hiring, credit, and healthcare tools β legal and compliance teams should expect that receiving a request is now a routine part of operating an AI system in the EU market rather than a sign of being specifically targeted for enforcement action.
What Law Teams Must Do
- Inventory every AI system used in hiring or HR decisions now. If your organization or a vendor you use deploys automated rΓ©sumΓ© screening, candidate scoring, or AI-assisted interview evaluation in or affecting the EU, assume it falls within the current inspection wave’s scope.
- Confirm Article 50 transparency disclosures are live, not just planned. Because the transparency obligation has been enforceable since August 2, 2026 regardless of the deferred high-risk deadline, legal teams should verify that candidates and employees are actually being told when AI is involved in decisions about them β today, not by the 2027 deadline.
- Prepare an RFI response protocol before one arrives. Given that RFIs have already gone to over 30 AI providers and are being used at the national level by CNIL, BfDI, and AESIA, legal teams should pre-assign who compiles technical documentation, who reviews responses, and what the internal deadline is once a formal request lands.
- Audit third-party HR technology vendor contracts for compliance representations. If your HR or recruiting tools are licensed from outside vendors, confirm contractually who bears responsibility for AI Act compliance documentation if a regulator requests it from your company as the deployer.
- Distinguish transparency compliance from high-risk conformity in internal reporting. Do not let the December 2027 high-risk deadline create false comfort β brief leadership that the currently active enforcement targets transparency disclosures, not the full conformity regime, and that both matter on different timelines.
- Watch credit-scoring and healthcare triage AI compliance in parallel. Because regulators are running the hiring-tools, credit-scoring, and healthcare-triage inspections as one coordinated wave, legal teams at financial services or healthcare companies should assume similar scrutiny is coming even if HR is not their focus.
- Document good-faith cooperation with any RFI received. Because misleading or incomplete information to regulators carries its own separate penalty tier, legal teams should ensure RFI responses are accurate and complete even under time pressure, rather than rushed.
Frequently Asked Questions
When did EU AI Act enforcement become active?
Article 50 transparency obligations became enforceable on August 2, 2026, and the EU AI Office began sending formal requests for information to AI providers starting August 29, 2026.
Are hiring and rΓ©sumΓ©-screening tools being inspected under the AI Act?
Yes. The European AI Office confirmed on September 10, 2026 that automated rΓ©sumΓ©-screening and HR decision-making tools are included in the first wave of compliance inspections.
Which companies have received EU AI Act information requests?
The EU AI Office’s first RFIs, sent August 29, 2026, went to general-purpose AI model providers including OpenAI, Anthropic, and Google; the European Commission has since sent similar requests to more than 30 AI providers in total.
Has the deadline for AI hiring tool compliance been delayed?
The full high-risk conformity deadline for employment-related AI systems under Annex III was pushed from August 2, 2026 to December 2, 2027, but Article 50 transparency obligations remain enforceable now and are unaffected by that delay.
What is the maximum fine under the EU AI Act?
Violations of prohibited AI practices under Article 5 carry the highest fines, up to β¬35 million or 7% of a company’s total worldwide annual turnover, whichever amount is higher.
What happens if a company gives regulators incomplete information?
Supplying incorrect, incomplete, or misleading information to AI Act authorities carries a separate penalty of up to β¬7.5 million or 1% of global annual turnover, distinct from the underlying compliance violation being investigated.
Which national regulators are involved in the current inspection wave?
France’s CNIL, Germany’s BfDI, and Spain’s AESIA are among the national market surveillance authorities working with the EU AI Office, focusing initial requests on hiring tools, credit-scoring systems, and healthcare triage AI.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.