← Insights / Compliance

EU AI Act enforcement begins: France, Germany, Spain request technical files from high-risk systems (September 2026)

For months, businesses have been watching the EU AI Act move from legislation to lived reality. In September 2026, that shift became impossible to ignore. Regulators in France, Germany, and Spain began requesting technical files from operators of high-risk AI systems. The European Commission declare

Compliance 16 September 2026 6 min read

EU AI Act Enforcement Is Here: What the September 2026 Crackdown Means for Your Business

For months, businesses have been watching the EU AI Act move from legislation to lived reality. In September 2026, that shift became impossible to ignore. Regulators in France, Germany, and Spain began requesting technical files from operators of high-risk AI systems. The European Commission declared the AI Act "fully enforced". And a series of enforcement actions, triggered in part by autonomous AI agents being exploited in cyberattacks, signalled that the era of grace-period compliance is over.

If your business uses, develops, or deploys AI systems — and your clients or operations touch the EU market — this is the moment to take stock.

What Happened in September 2026

On 11 September 2026, several things converged. The EU warned technology firms to exercise tighter control over their AI models following a wave of hacks involving autonomous AI agents. An EU spokesman confirmed the AI Act was "fully enforced", removing any ambiguity about where regulators stood. The European Commission also formally requested information from a number of companies, a clear signal that enforcement is not passive.

On the same day, national regulators in France, Germany, and Spain began actively requesting technical files from operators of high-risk AI systems. This is significant. Technical file requests are not advisory conversations — they are the regulatory mechanism by which authorities verify that a high-risk AI system has been properly assessed, documented, and governed before deployment. If your documentation is incomplete, out of date, or simply nonexistent, that becomes apparent immediately.

Also on 11 September, new obligations under the EU's Cyber Resilience Act came into force, requiring all software providers to report actively exploited vulnerabilities and other security incidents to a designated governmental authority and to users. For businesses whose AI tools sit inside software products or SaaS platforms, this adds a parallel compliance layer that cannot be treated as a separate conversation.

Three days later, on 14 September, Reuters reported that the European Commission is preparing an "EU Kids Act" that would ban under-15s from accessing social media platforms, video-sharing services, and AI chatbots. While this proposal is not yet in force, it signals where regulatory intent is heading, particularly for businesses whose AI tools could be accessed by minors.

Who Is Affected — and Where

The EU AI Act applies extraterritorially. If your AI system is used by people in the EU, or if the outputs of your AI system affect people in the EU, the Act applies to you regardless of where your business is headquartered. That means firms in the UK, US, Canada, the Middle East, and Asia-Pacific are not bystanders to these developments.

For professional services firms specifically, the exposure is more direct than many assume. Consider the following:

Accountancy and financial services firms using AI for credit risk assessment, client due diligence, or automated financial advice may be operating systems that fall into the high-risk category under Annex III of the AI Act. If so, they are required to maintain technical documentation, implement risk management systems, and ensure human oversight.

Law firms and legal technology providers using AI to assist with case assessment, document review, or legal research need to assess whether those tools qualify as high-risk or, at minimum, ensure that any AI-generated content is properly disclosed under the Act's transparency requirements.

HR consultancies and recruitment platforms should already be on high alert. AI systems used in employment decisions — including CV screening, candidate ranking, or performance assessment — are explicitly listed as high-risk under the Act. The technical file requests now being issued in France, Germany, and Spain will almost certainly include this category.

Marketing agencies using AI for profiling, targeting, or content generation need to consider both the AI Act and, where children are involved, the trajectory of the proposed EU Kids Act. The latter is not yet law, but building compliance posture now is considerably less costly than retrofitting later.

What Technical Files Actually Require

The national regulatory requests for technical files are not a formality. Under the AI Act, providers of high-risk AI systems are required to produce documentation that covers the system's general description, the design specifications and development process, the training data used, the risk management system, the accuracy and robustness testing conducted, and the cybersecurity measures in place.

For many businesses, particularly those that have adopted third-party AI tools without conducting their own due diligence, assembling this documentation retrospectively is a significant undertaking. The September 2026 enforcement activity makes clear that "we're using an off-the-shelf tool" is not a sufficient answer. Deployers of high-risk AI systems carry compliance obligations of their own, distinct from those of the original developer.

The Cyber Resilience Act Adds a Second Front

The new Cyber Resilience Act obligations that came into force on 11 September 2026 deserve attention in their own right. Software providers — including those offering AI-powered platforms — must now report actively exploited vulnerabilities to a designated authority and notify users. This is not a future obligation with a transition period. It is live.

For professional services firms that rely on AI software vendors, this creates a due diligence question: are your suppliers compliant? If a vulnerability in a tool you use is actively exploited and your vendor fails to notify you, you need to understand what your own obligations are and whether your contracts provide adequate protection. The intersection of AI governance and cybersecurity compliance is no longer theoretical.

What Businesses Should Do Now

The September 2026 developments are a clear marker. Regulators are not waiting. Here is what firms operating in or serving the EU market should prioritise:

Conduct an AI inventory. Map every AI system your business uses, deploys, or provides. Identify which fall into the high-risk categories under the AI Act. This is the foundation of everything else.

Audit your technical documentation. If you are a provider or deployer of high-risk AI, your documentation must be complete and current. A technical file is not a one-time exercise — it must reflect the system as it is actually operating.

Review vendor contracts. Understand which of your AI suppliers are subject to the Cyber Resilience Act and what their obligations are to notify you in the event of a security incident. Ensure your contracts reflect this.

Monitor the EU Kids Act proposal. If your services could be accessed by under-15s, begin scoping what compliance would require now, before the proposal becomes law.

Do not assume geography provides cover. Regulators are enforcing extraterritorially, and the pace of enforcement is accelerating.

How Ops Intel Can Help

Ops Intel works with professional services firms globally to build clear, practical AI compliance frameworks — from initial AI inventories and risk classification to technical documentation, vendor due diligence, and ongoing monitoring. We cut through complexity and give you a compliance posture you can defend.

If September 2026 has raised questions your business cannot currently answer, now is the time to act. Visit Ops Intel to find out how we can help you meet your obligations under the EU AI Act and beyond.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

What to do about it

The news is what changed. A framework is what you do about it.

Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Before you spend anything, read a real one — the whole pack, produced by the same system that will write yours.

Call Now Claim Your Free Audit