EU AI Act enforcement begins 20 September 2026: what the first compliance deadline means for UK firms using AI systems
The EU AI Act moved from paper obligation to live enforcement on 20 September 2026. For professional services firms — accountants, solicitors, HR consultancies, marketing agencies — that moment marks a significant shift in how AI use must be governed, documented, and justified. If your business oper
The EU AI Act moved from paper obligation to live enforcement on 20 September 2026. For professional services firms — accountants, solicitors, HR consultancies, marketing agencies — that moment marks a significant shift in how AI use must be governed, documented, and justified. If your business operates in, sells into, or processes data belonging to EU residents, this deadline applies to you, regardless of where your company is headquartered.
This briefing sets out what happened in the week of 20 September 2026, what it means in practice, and what you should be doing now.
What Came Into Force on 20 September 2026
The EU AI Act's enforcement framework became active on 20 September 2026, requiring businesses that develop, deploy, or use AI systems within the EU — or whose AI systems affect EU markets — to comply with its risk-based regulatory structure.
The Act categorises AI systems by risk level. Prohibited systems, those deemed an unacceptable risk, have been banned since earlier in the implementation timeline. But the broader compliance obligations — covering high-risk systems, transparency requirements, and accountability mechanisms — are now fully enforceable. Regulators have the authority to investigate, fine, and require remediation.
For professional services firms, the practical question is straightforward: which AI systems are you currently using, and have you assessed where they sit within the Act's risk categories? Tools used in HR decision-making, legal research, financial analysis, client-facing chatbots, and automated document review all warrant scrutiny. The Act does not exempt businesses simply because they are using third-party AI products rather than building their own.
The EDPB's New Fining Guidelines Land at the Same Moment
The timing of what followed was notable. On 21 September 2026 — the day after AI Act enforcement began — the European Data Protection Board adopted updated guidelines on the application of administrative fines under the GDPR, and finalised guidelines on the interplay between the Digital Services Act and the GDPR.
This is not coincidental. Regulators are signalling that data protection obligations and AI compliance obligations are converging, not running in parallel. If your AI system processes personal data — and most do — you are now operating at the intersection of at least two major regulatory frameworks simultaneously.
For UK firms, this has particular weight. Post-Brexit, the UK GDPR remains closely aligned with EU GDPR in many respects, and UK businesses with EU customers, clients, or data flows remain subject to EU rules in those contexts. The EDPB's refreshed fining methodology will shape how seriously regulators pursue violations — and the direction of travel is towards more rigorous enforcement, not less.
The Leaked Irish Presidency Document: A Warning, Not a Green Light
On the same day, the privacy rights organisation NOYB reported on a leaked document originating from the Irish Presidency of the EU Council. According to that report, the document proposed to member states that the commercial interests of AI companies should take precedence over individuals' fundamental right to data protection, and that personal data used "in the context of AI" should be treated as automatically lawful.
This proposal has not been adopted. It is not law. But its existence matters for two reasons.
First, it illustrates that there are active lobbying efforts to weaken the data protection floor that governs AI use. Businesses should not mistake this political manoeuvring for permission to lower their own compliance standards. The GDPR's requirements for lawful basis, data minimisation, and transparency remain in force.
Second, the fact that this document leaked and was reported publicly is itself a governance signal. Regulatory and political scrutiny of how AI companies handle personal data is intensifying, not receding. Any business that assumes the compliance environment will soften in the near term is making a risky bet.
Children, Manipulation, and the Prohibitions Already in Force
On 23 September 2026, EU Executive Vice-President Henna Virkkunen, speaking in the context of the EU KIDS Act, reiterated that the AI Act's prohibitions on systems that manipulate people or exploit the vulnerabilities of children are fully operative and will be strongly enforced.
This is a reminder that the Act's prohibition tier is not theoretical. AI systems that use subliminal techniques, exploit psychological weaknesses, or target minors in ways that circumvent their judgement are banned outright. Marketing agencies running personalised campaigns, HR platforms targeting job seekers, and client engagement tools that adapt messaging based on behavioural profiling all need to be assessed against these prohibitions.
The reminder from a senior EU official that enforcement will be robust is not a formality. It is a signal to compliance teams and legal counsel that they should treat these provisions as live obligations, not future considerations.
What This Means for Businesses Operating Internationally
The EU AI Act has extraterritorial reach. A firm based in London, Toronto, Dubai, or Singapore that provides services to EU clients, or whose AI systems produce outputs affecting EU residents, falls within scope. The same logic that extended GDPR compliance obligations globally now applies to AI governance.
For businesses across the UK, North America, the Middle East, and Asia-Pacific, this means:
Audit your AI inventory. Know which systems you use, what decisions they inform or automate, and what data they process. This is the foundational step. Without it, no other compliance action is reliable.
Establish risk classification. Map each system against the Act's risk tiers. High-risk systems require conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU database. Limited-risk systems require transparency measures. This is not optional groundwork — it is the basis on which regulators will assess your compliance.
Review your lawful basis for AI-related data processing. The EDPB's updated fining guidelines make clear that GDPR obligations run alongside AI Act obligations. If you cannot demonstrate a lawful basis for the personal data your AI systems process, you are exposed on two fronts simultaneously.
Do not rely on supplier assurances alone. If you deploy a third-party AI tool, the compliance obligation does not transfer to the vendor. You remain responsible for ensuring that the system, as you use it, meets the Act's requirements. Contractual protections are necessary but not sufficient.
Document everything. Regulators investigating AI Act compliance will expect to see policies, risk assessments, human oversight protocols, and records of how systems were evaluated. If you cannot produce this documentation, you cannot demonstrate compliance.
The Compliance Window Is Narrow
The week of 20 September 2026 made one thing clear: AI governance is no longer a forward-looking project. It is a present-tense obligation, and the regulatory architecture supporting enforcement is now active and aligned across multiple instruments.
Professional services firms that have not yet structured their AI compliance programmes are not behind schedule — they are operating in breach. The frameworks are in force. The regulators have their mandates. The fining guidelines are updated.
If your business uses AI systems and you are not certain of your compliance position under the EU AI Act, that uncertainty is itself a risk that needs to be managed.
Ops Intel works with professional services businesses globally to build structured, proportionate AI compliance programmes. From initial AI system audits and risk classification through to policy development and ongoing regulatory monitoring, our work is practical, jurisdiction-aware, and built for firms that need to operate confidently across multiple markets.
To understand your current exposure and what steps to take next, visit www.opsintel.io.
Follow us in Google
See Ops Intel first when AI rules change
One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.
What to do about it
The news is what changed. A framework is what you do about it.
Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Before you spend anything, read a real one — the whole pack, produced by the same system that will write yours.