← Insights / Compliance

EU AI Office begins automated hiring tool inspections: first enforcement wave under Article 50 starts September 2026

The first week of September 2026 marked a clear shift in the regulatory landscape for artificial intelligence. Across the EU, the US, and California, new rules moved from preparation into active enforcement — and the consequences for professional services firms that have been slow to act are now imm

Compliance 13 September 2026 6 min read

EU AI Office Begins Automated Hiring Tool Inspections: What the September 2026 Enforcement Wave Means for Your Business

The first week of September 2026 marked a clear shift in the regulatory landscape for artificial intelligence. Across the EU, the US, and California, new rules moved from preparation into active enforcement — and the consequences for professional services firms that have been slow to act are now immediate. This briefing sets out what happened, what it means, and where your compliance obligations now sit.

EU AI Office Confirms HR Tools Are Under Active Scrutiny

On 10 September 2026, the European AI Office confirmed that automated résumé screening and HR decision-making tools are included in the first wave of inspections under the EU AI Act. This is a significant moment. It signals that enforcement has moved beyond guidance documents and compliance checklists into direct regulatory scrutiny of specific systems in use within organisations.

For professional services businesses — law firms, accountancy practices, HR consultancies, and marketing agencies — this matters immediately. Many of these firms use AI-assisted recruitment tools, either built in-house or procured through third-party HR platforms. If those tools fall within the EU AI Act's high-risk classification for employment-related AI systems, they are subject to obligations around transparency, human oversight, documentation, and conformity assessment.

The relevant obligations sit under Article 50 of the EU AI Act and the broader high-risk AI framework. Firms operating within the EU, or offering services to EU-based clients, need to understand whether their recruitment tools are in scope — and if they are, whether those tools meet the requirements. The fact that inspections are already under way is not a warning of what is coming. It is confirmation that scrutiny is here.

EU Cyber Resilience Act: Vulnerability Reporting Is Now Mandatory

On 11 September 2026, Article 14 of the EU Cyber Resilience Act (CRA) became applicable. This article mandates that manufacturers and developers of products with digital elements must report actively exploited vulnerabilities and incidents to the relevant national authority — and in some cases to ENISA, the EU Agency for Cybersecurity — within defined timeframes.

For professional services firms that develop or significantly customise software tools, this is a direct compliance obligation. For firms that use off-the-shelf AI products and platforms, the obligation falls primarily on the vendor — but firms should be verifying that their suppliers are compliant. A vendor who cannot demonstrate CRA compliance presents a due diligence risk to your business, particularly if your clients are in regulated sectors.

The CRA applies to products placed on the EU market. For firms based in the UK, US, Canada, or the Asia-Pacific region that supply digital products or services into the EU, the territorial reach of this legislation is relevant to you regardless of where your organisation is headquartered.

EU Data Act: Access-by-Design Obligations Now Apply to New Products

From 12 September 2026, Article 3(1) of the EU Data Act became applicable to connected products and related services introduced to the market from that date. This provision requires that connected products are designed so that data generated by their use is, by default, accessible to the user — not locked within the manufacturer's ecosystem.

This is not abstract. For firms that incorporate connected devices, AI-powered tools, or integrated software platforms into their client delivery, the products they now procure must meet these design obligations. When evaluating new technology vendors, access-by-design compliance should be part of your procurement checklist.

NIST Publishes Draft AI Cybersecurity Guidance for Consultation

On 10 September 2026, the US National Institute of Standards and Technology (NIST) released draft guidance on the integration of AI into cybersecurity frameworks, opening it for public consultation. While NIST guidance does not carry the force of law in the same way that EU regulations do, it has significant practical influence. US federal agencies frequently reference NIST frameworks, and many global organisations use them as a baseline for internal governance.

For firms operating in the US or with US clients, this draft is worth engaging with now rather than waiting for finalisation. Participation in public consultations is also an opportunity to shape guidance that will affect your sector. Professional services firms with AI governance programmes should review the draft and assess whether their current approach to AI security aligns with the emerging framework.

California Strengthens Child Safety Obligations for AI and Online Services

On 11 September 2026, California Governor Newsom signed a package of child safety legislation covering AI, social media, online safety, and mental health. Whilst this may appear peripheral to professional services firms, it is not entirely so.

Marketing agencies that operate consumer-facing platforms, manage social media for clients, or deploy AI in content personalisation need to understand whether any aspect of their operations reaches minors. Similarly, HR technology providers and platforms used in educational or youth-facing contexts may find themselves in scope. California's regulatory reach has a history of influencing broader US and global policy, and firms should treat this legislation as an early indicator of the direction of travel.

The Pattern Across These Developments

These developments are not coincidental. They represent a coordinated acceleration of AI and technology regulation across multiple jurisdictions. The EU is moving from rule-making into enforcement. The US is formalising AI governance expectations at both federal and state level. The common thread is accountability: regulators expect organisations to know what AI systems they are using, understand how those systems make decisions, and be able to demonstrate appropriate oversight and controls.

For professional services businesses, the risk is not only regulatory. It is reputational. Clients in regulated sectors — financial services, healthcare, legal — are increasingly asking their advisers and agencies to demonstrate their own AI governance credentials. Your compliance posture is becoming a commercial consideration, not just a legal one.

The international dimension is also critical. A UK accountancy firm using an EU-based HR platform, a Canadian law firm with EU clients, a Singapore-headquartered agency supplying into the EU market — all of these businesses have exposure to these obligations even if they are not incorporated in the EU. Territorial scope clauses in modern technology regulation are deliberately broad.

What You Should Be Doing Now

If you have not already mapped the AI tools in use across your organisation, that process needs to start immediately. You need to know what is being used, by whom, for what purpose, and whether those tools meet the compliance requirements applicable to your jurisdiction and your clients' jurisdictions.

If you are using AI in recruitment or HR decision-making, the EU AI Office's inspection programme is reason enough to prioritise a gap assessment. If you are procuring connected products or third-party AI platforms, your vendor due diligence process needs to incorporate CRA and Data Act compliance requirements.


Ops Intel helps professional services businesses understand and meet their AI compliance obligations — from scoping and gap assessment to documentation, vendor review, and ongoing monitoring. If the developments set out in this briefing have raised questions about your organisation's position, we can help you answer them. Visit https://www.opsintel.io to find out how we work with accountancy firms, law firms, HR consultancies, and marketing agencies across the UK, EU, US, and beyond.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit