
On September 17, the European AI Board held its ninth meeting under the Irish Council presidency. Read the agenda cold, and it doesn't sound like a policy workshop. It sounds like the operating plan of a regulator already running a caseload: enforcement priorities, recent AI incidents, market surveillance cooperation, pre-market conformity assessment, and the transparency duties that took effect on August 2.
That's the tell. Brussels has stopped arguing about what acceptable AI looks like in principle. It's now asking a narrower, harder question: which organizations can produce evidence of compliance on request, and which authority gets to act when they can't.
The transition is uneven, and this is the part I'd argue most boardroom briefings are getting wrong. Large chunks of the AI Act are already enforceable. The centerpiece — the high-risk system rules — has been pushed back more than a year. Several member states still haven't finished standing up their national regulators. What that leaves isn't a finished regime, and it isn't a grace period either. It's an enforcement system running on three separate clocks, and a company planning around a single "AI Act deadline" is planning around a deadline that doesn't exist.
That gap is where the real cost sits. The obligations that already bind you have to be separated from the ones still approaching — and the systems you'll need for the approaching ones can't be built the week before they land. Technical documentation, provenance controls, incident procedures, contractual rights: all of it gets decided during development and procurement, long before a deadline arrives. A date can move. The cost of having waited doesn't.
So the enforcement era, as it's shaping up, will be decided on evidence. Not intent. Not the strategy deck that says your company takes AI risk seriously. Can you show what your systems are, where they came from, how they're used, and who's accountable when something goes wrong.
The Act entered into force in August 2024, but it was always going to arrive in pieces. Prohibited practices and the first AI-literacy duties started applying in February 2025. Governance rules and obligations for general-purpose AI (GPAI) providers followed in August 2025.
August 2, 2026 was the next real threshold — not because new obligations appeared, but because enforcement did. The Commission and national authorities got the power to act on provisions already in force, and Article 50's transparency duties became applicable the same day. The GPAI rules providers have been preparing for since 2025 are now enforceable, fines included.
Here's the piece worth underlining for anyone running a GPAI model in Europe: providers must maintain technical documentation, give downstream system providers what they need to build responsibly, publish a copyright policy, and put out a sufficiently detailed summary of the training content. Non-EU providers generally need an authorized representative just to sell into the EU market.
Models with systemic risk carry more — evaluations, risk assessment and mitigation, documented adversarial testing, cybersecurity protections, and incident reporting without undue delay. And separately, any GPAI model placed on the market before August 2, 2025, systemic risk or not, gets until August 2, 2027 to come into line. Anything newer is already live.
Article 50 reaches somewhere different — not the model, the interaction. Systems built to talk to people directly have to make that obvious, unless it already is. Systems that generate content have to mark it so machines can detect it as synthetic. Deployers carry their own duties here, and they're public-facing in a way GPAI obligations aren't: use emotion recognition or biometric categorization on someone, tell them. Publish a deepfake, and it needs a disclosure a person can actually perceive, not metadata buried in a file. Publish AI-generated text on a matter of public interest, and it needs a label unless the piece went through review substantive enough to count.
The one soft edge here is narrower than it looks. Systems already on the market before August 2, 2026 get until December 2, 2026 — but only for the marking-and-detection piece of Article 50. Everything else in the article is live now. And the fines for getting it wrong aren't symbolic: up to €15 million or 3% of global annual turnover, straight from the Commission's own guidance.
High-risk sits on the longer clock, and this is the deadline most compliance decks are still built around. The 2026 AI Omnibus pushed the standalone high-risk rules in Annex III — recruitment, credit scoring, education, critical infrastructure, migration, law enforcement — from August 2026 to December 2, 2027. High-risk AI embedded in regulated products, machinery and toys among them, now lands on August 2, 2028.
Don't read that as a suspension. Prohibited practices, GPAI obligations, and the new transparency rules are all live. What moved is a large piece of the high-risk framework — its technical requirements and the conformity machinery behind them. That's a meaningful postponement. It is not the Act taking a year off.
The European AI Board coordinates all of this, but it isn't a single super-regulator sitting above national governments. Enforcement is split by actor, system, and context.
The Commission's AI Office owns general-purpose AI models. Since the Omnibus, its reach also covers AI systems built by the same provider — or the same corporate group — as the underlying GPAI model, plus any AI system that's part of a very large online platform or search engine designated under the Digital Services Act.
Everything else falls to national market surveillance authorities. They can investigate, monitor remotely, demand corrective action, and pull documentation, datasets, and, under the right conditions, source code. Anyone with grounds to believe the Act's been breached can file a complaint directly. The European Data Protection Supervisor plays the same role for AI used inside EU institutions themselves. National notifying authorities sit in a different lane: they designate and oversee the independent bodies that run third-party conformity checks.
Here's where I'd push back on the tidier version of this story. The Board coordinates; it doesn't command. And coordination is genuinely hard when enforcement capacity is this lopsided — the Commission's own published list of national contacts, last updated September 7, still shows several member states with no designated authority at all, and a longer list still pending final sign-off.
That's not a footnote. A single European law enforced through 27 national administrations with 27 different resource levels and sectoral habits is the actual mechanism here, and it's exactly as fragile as that sounds. A cross-border case can touch several authorities before anyone agrees on jurisdiction, let alone evidence.
So the Board's real authority won't come from a sanctioning power it doesn't have. It'll come from whether it can turn "we agreed on the legal text" into "we apply it the same way in Warsaw and in The Hague." That's the harder thing to build, and it's the thing worth watching.
The high-risk postponement exposed something the AI Act's design never quite solved: a law can require "adequate" risk management and "sufficient" accuracy and still leave open what those words mean for a specific system, in a specific conformity assessment, in front of a specific regulator.
Harmonized standards were supposed to answer that. The Commission tasked CEN and CENELEC's joint AI committee, JTC 21, with building ten of them — risk management, data governance, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment. Once the Commission signs off on one and its reference is published in the Official Journal, using it earns a presumption of conformity. That's a real legal effect attached to what's technically a voluntary standard.
The timeline slipped. The quality-management standard — the one built specifically for Article 17 compliance — didn't enter public inquiry until October 30, 2025, and the rest of the stack was still moving behind it. That left providers without the recognized technical playbook the high-risk regime assumed would exist by the time it took effect.
The Omnibus's postponement is the direct consequence of that gap, not a separate policy choice. Push the deadline out, and you avoid switching on an expensive compliance machine with no instruction manual. But it also makes the dependency plain: a technical committee is now setting the pace of a piece of EU law, not the legislature.
Worth sitting with, because it's not just an administrative delay. Standards decide which measurements count, what auditors expect to see, and how much room providers actually have. They can also quietly favor whoever can afford to run a complex assurance program — a smaller competitor without in-house expertise has to buy that credibility from outside.
The postponed deadlines buy Europe time to finish the machinery. They also buy companies a finite window to shape the standards while they're still drafts, and to line up assessment capacity before everyone else is competing for the same scarce auditors. Treat the delay as permission to wait, and the scarce resource by 2027 may not be legal advice. It may be the ability to reconstruct, credibly, how your system was actually built.
The Board's discussion of recent AI incidents points at where enforcement goes next, and it isn't more document review. Advanced models produce risks that only surface after deployment — new capabilities, unexpected interactions, misuse at scale. No amount of pre-market approval catches all of that.
For GPAI providers carrying systemic risk, the Act already requires an ongoing process: track serious incidents, document them, report them to the AI Office and, where relevant, national authorities. Record what was done about it. Keep the safeguards current.
What that builds is a feedback channel most companies haven't priced into their risk models. Providers hold the telemetry. Regulators hold the authority to compare cases across companies and act beyond any single one. Whether the channel actually works depends on how tightly incidents get defined, how fast they get reported, and whether regulators are willing to challenge a provider's own narrow read of what counts — and, less discussed, on whether authorities can independently evaluate model behavior at all, which takes specialized people, secure infrastructure, and access providers won't hand over willingly.
A regulator that gets a technically dense incident report and can't parse it has visibility without control. One that can parse it has leverage — corrective measures, market restrictions, updated expectations for everyone downstream. The ninth Board meeting is a signal that frontier-model oversight is drifting toward ordinary supervisory practice, where documentation can be demanded, and a weak answer has consequences. That used to be voluntary-commitment territory. It isn't anymore.
Article 50 reaches well past anyone who'd call themselves an AI company. A marketing agency, a publisher, a comms team, a brand — any of them can be a deployer the moment they put an AI system to professional use, and the legal entity stays the deployer even when contractors or freelancers are the ones operating it.
The provider/deployer line matters more than it looks like it should. An organization that just uses someone else's system sits in a different place than one that builds a system, has it built, or releases it under its own name. Rebrand something, modify it substantially, or repurpose it, and the obligations can shift onto you — especially once the high-risk rules are live.
For a marketing team, this isn't theoretical. A chatbot needs its disclosure from the first message, not buried in terms of service. A deepfake needs a label a person can actually see or hear — the machine-readable mark a provider embeds doesn't satisfy the deployer's own disclosure duty. AI-generated text on a matter of public interest needs a label, unless it went through review substantive enough to matter.
The Commission has been specific about what "substantive" means, and it rules out the shortcut most teams will reach for first: a human with real knowledge of the subject has to examine the substance, and the reviewer needs actual authority to change or reject it. A spell-check pass or a procedural sign-off doesn't count.
That has a direct evidentiary consequence. If you're relying on the human-review exception, you need to show who reviewed it, on what authority, and whether that review could actually have changed the outcome. "Approved" in a project-management tool is not that record. A documented editorial process tied to the specific piece is.
I'd expect this to reshape vendor selection faster than most legal teams are planning for. Buyers will start asking whether a tool's provenance marks survive editing and redistribution, and whether that information travels between systems at all. A vendor's transparency architecture is becoming a product feature. Missing provenance is becoming a procurement red flag.
Start with an inventory: every AI system, its provider, its model and version, its intended purpose, the countries where it's used, and whether you're the provider, deployer, importer, or distributor for it. That last classification isn't a one-time decision — fine-tuning, integration, rebranding, and purpose changes can all move you into a different role, so the file needs to preserve the underlying facts, not just a conclusion someone reached once.
Marketing and comms teams need a production record for anything AI-assisted that goes public: which system generated it, whether the output was synthetic or materially altered, which disclosure rule applied, proof of the actual label or mark. Where you're relying on human review, record who reviewed it, what they actually examined, and who signed off on publishing it.
GPAI providers carry a heavier file: architecture, development process, training and testing data, compute and energy figures, plus a separate technical package for downstream providers covering capabilities, limitations, and integration requirements. Keep the copyright policy and training-content summary aligned to the model version actually sold into Europe, not last year's version.
Providers of systemic-risk models need traceable evaluation results, adversarial-testing records, risk assessments, cybersecurity controls, and incident files that connect an identified risk to an actual decision made about it. A policy that names a process without showing it running is the first thing to fall apart under a documentation request.
Deployers should be recording the conditions of use, the instructions received from the provider, and their own internal controls — and contracts should guarantee access to documentation, notice of material changes, and support during a regulatory inquiry. A vendor's general assurance that "we're compliant" isn't evidence. It's a sentence.
None of this waits for the high-risk deadline. The postponed categories don't need these records yet, but the records themselves get produced during design and deployment, not reconstructed a year later — which is expensive when it's even possible. And a code of practice is a recognized route to compliance, not the only one; choosing to go another way just means you're the one explaining why your controls are equivalent.
It's easy to describe the AI Act as a list of obligations aimed at tech companies. The more accurate description is that it's building an assurance market around AI, with a specific division of labor: standards bodies translate law into technical spec, notified bodies check systems before they ship, surveillance authorities check them after, model providers feed information downstream, deployers generate the operational evidence, and regulators interpret incidents no single company can evaluate as a private failure.
That structure has competitive consequences. Large providers spread the cost of compliance across many customers. Smaller companies can actually win here if they build traceability in early — but they'll struggle if compliance ends up depending on scarce auditors, expensive evaluations, or information an upstream model provider controls.
I'd expect enterprise buyers to start weighting documentation quality and provenance support alongside raw model performance within the next procurement cycle, not the next five years. Compliance readiness isn't a cost center anymore. It's becoming a line in the pitch deck.
The most consequential shift, though, happens inside companies, not between them. Legal can't produce this evidence alone. Engineering owns model versions and logging. Procurement owns contractual access to vendors. Marketing owns public disclosure. Security owns incident response. Leadership decides what risk is acceptable. AI governance only works when those functions act as one system — and most organizations I talk to still have them acting as five.
Europe's enforcement era started before most of the Act's obligations are even active. The postponed high-risk rules don't undo that. They just make the underlying problem more visible: proving what your AI does was always the hard part, harder than reading the law. The rule-writing era rewarded reading the text carefully. This one rewards being able to produce the record. Those are not the same skill, and most companies have only built one of them.