EU AI Act Enforcement Moves to Dockets: Hiring, Credit and Student Tools First [Update]
The first formal dockets in EU AI Act enforcement are open, and they read like a list Brussels drafted years ago: automated hiring tools, credit-scoring algorithms, student monitoring and healthcare triage. The European AI Office has held investigative authority since 2 August 2026, and through September it has worked with 24 national market surveillance authorities on the first coordinated wave of compliance checks. As we reported on 17 September, the opening inspections centred on recruitment software and a procurement test. The docket has since widened to scoring and education systems.
The sequencing tells you more than the target list does. Brussels is enforcing in the order it always said it would: prohibitions that have applied since February 2025, then the transparency and copyright duties binding general-purpose model providers since August 2025, and only after those the conformity track that Regulation (EU) 2026/1744 deferred. For a US vendor with a European pipeline, the near-term exposure is document access and market-restriction powers, not a CE-marking bill that falls due in 2027. What stands out to me is how little of that exposure fits neatly into a compliance calendar.
What the AI Office Can Do Today
No substantive rule was added on 2 August 2026. The change is that the Office stopped being a correspondent and became an investigator. Before that date, EU regulators could collaborate with AI companies only informally, and nothing in the framework produced a punishment for non-compliance. Four powers now matter operationally:
- Demanding technical documentation and training-data summaries from providers.
- Running the Office's own evaluations of a model instead of accepting vendor self-assessment.
- Ordering risk-mitigation measures with a deadline attached.
- Issuing fines, which reach 35 million euros or 7% of global annual turnover for prohibited practices and 15 million euros or 3% for general-purpose AI breaches.
The evidence a deployer is expected to hold is the same set the Office can compel. A duty register of roughly 20 deployer obligations includes the EU database registration entry, the vendor's instructions and documentation, the human-oversight arrangement, the notices shown to affected people, system logs and any impact assessment the instrument requires. Teams that filed those artefacts under future compliance work now have to produce them on request, in a form an investigator can follow.
The split of duties between provider and deployer is where most organisations misread their own exposure. Model providers owe the upstream package: transparency documentation, training-data summaries and enough technical detail for downstream developers to integrate a model responsibly. Deployers owe the downstream package: registration, oversight design, notices to the people affected, incident reporting and, for credit scoring and public-service use, an impact assessment. A bank running a third-party scoring engine cannot hand that second list back to its supplier.
Transparency duties cut across all of it. Providers must tell EU users when they are dealing with an AI system, wherever the company is headquartered, and general-purpose model providers owe a structured public summary of the data categories used in training: public datasets, licensed material, scraped content, user data and synthetic data. Deployers carry quieter obligations too, including reporting serious incidents to market surveillance authorities and labelling deepfakes and AI-generated text under Article 50(4).
Why EU AI Act Enforcement Started Here
The initial targets are Annex III categories, which makes the selection deliberate rather than arbitrary. Hiring tools, credit scoring and education AI sit inside that annex; a product recommendation engine or a support chatbot does not. Advanced general-purpose models above the 10^25 FLOPs compute threshold face monthly risk evaluations, so the largest model providers already run on a recurring reporting cycle rather than an annual filing. With 24 national authorities checking in parallel, one product can face questions from more than one regulator at once.
National regulators are moving on a parallel track with older instruments. Spain's data protection authority issued a preemptive warning over a company's plan to screen, score and prioritise job candidates, even though the system had not gone live. The conditions attached were data-protection safeguards, a documented risk assessment and meaningful human oversight. That route does not wait for the Annex III conformity regime, and it does not need the AI Office to open a docket.
The two tracks do not resolve each other. A clean AI Act file will not close a data-protection question about candidate scoring, and a GDPR-compliant hiring process will not satisfy an Annex III conformity check. Vendors that map the requirements of only one regulator stay exposed to the other.
The 2027 Deferral Is Narrower Than It Sounds
The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed standalone Annex III compliance from 2 August 2026 to 2 December 2027. AI embedded in regulated products follows on 2 August 2028. The Council agreed the amendment on 29 June 2026, so these dates are settled law. What was deferred is the conformity-assessment track; the prohibitions, the general-purpose AI duties and the investigative powers were untouched.
Article 27 shows how uneven the obligations are underneath. A fundamental rights impact assessment is required of three groups: public bodies, private firms that deliver public services, and any organisation that deploys AI to score credit or to set life and health insurance risk. Its effective date moved with the Omnibus, and Article 99 attaches no dedicated fine tier to it. A deployer rationing compliance budget should note that asymmetry: a weak FRIA can surface through other provisions, but it will not generate the headline penalty that a prohibited-practice finding does.
| Obligation | Status | Exposure |
|---|---|---|
| Prohibited practices (social scoring, predictive policing) | In force since February 2025 | Up to 35 million euros or 7% of global turnover |
| GPAI transparency and copyright duties | In force since August 2025 | Up to 15 million euros or 3% of global turnover |
| AI Office investigative powers | Active since 2 August 2026 | Document compulsion, model evaluation, mitigation orders |
| Annex III high-risk conformity | Deferred to 2 December 2027 | CE marking, EU database registration, Article 27 FRIA |
| Annex I embedded high-risk | Deferred to 2 August 2028 | Conformity for AI inside regulated products |
Where the Near-Term Risk Sits for US Vendors
ITIF's analysis of the Act's cost to American innovation frames the exposure through procurement. US firms are the leading suppliers of both models and systems into the EU, and their European pipeline leans on public-sector and regulated-industry buyers who will now request evidence before contracting. Scope is extraterritorial in the GDPR sense: the Act binds any provider or deployer placing a system on the EU market or putting one into service there, whatever the company's place of incorporation. A Delaware vendor selling candidate-screening software to a German manufacturer is inside it.
Market restriction is the sharpest instrument in the set, and it is the one procurement teams grasp immediately. The Office can order a system withdrawn or made unavailable while a question is unresolved, which turns a documentation gap into a revenue event rather than a filing fee. Public-sector and regulated-industry buyers in the EU have started writing evidence requirements into tenders, so the same paperwork serves two audiences: the investigator and the customer. If I were briefing a sales lead this week, that single overlap would be the slide I would put in front of them.
The practical verdict is that 2027 is the wrong planning horizon for anyone whose AI touches hiring, credit, education or insurance pricing in Europe. The deadline that binds is the next document request, and the useful preparations are unglamorous: keep the evidence pack current, be able to name the person accountable for human oversight, and know which of your systems are genuinely Annex III rather than assuming a chatbot exemption covers a scoring tool.
Why this matters
Enforcement arriving in this order means the first companies to feel it are those with the most visible, already-regulated use cases. The 2027 deferral bought time for conformity paperwork while supervision continued, and the September wave showed that national data-protection authorities will act on hiring AI through their own powers while Brussels works the dockets. For vendors selling into EU public sector and regulated industries, document readiness is now a sales qualification.
See our earlier coverage: EU AI Act Enforcement Opens With Hiring Tools and a Procurement Test
Photo by Carl Gruner on Unsplash
Related Articles
- EU AI Act Deadlines Shifted for High-Risk Systems and New Prohibitions
- EU AI Act Enforcement Opens With Hiring Tools and a Procurement Test
- EU AI Act Simplification: Deadlines Extended to 2027-2028
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.