Week 35 · 8 min read

EU AI Act Regulatory Brief — Week of 25–31 August 2026

The EU AI Office sent its first formal requests for information to general-purpose AI model providers. The Digital Omnibus put the words "agentic AI" into binding EU law, in a notified-body code rather than a new obligation. Germany published ISO/IEC 42001 under European numbering, and France's data regulator answered common questions on credit refusal.

Relay Labs Ltd ·

AI Office Issues First Formal GPAI Enforcement Requests for Information

On 29 August 2026, the EU AI Office formally issued Requests for Information (RFIs) to GPAI model providers under Article 91 of the EU AI Act, approximately four weeks after the Commission's own GPAI enforcement powers commenced on 2 August 2026 — Chapter V (GPAI) obligations themselves had already applied since 2 August 2025. The RFIs target two parallel tracks: (a) model security, covering adversarial-attack resilience, independent evaluation results, and post-market monitoring protocols; and (b) training-data transparency, targeting providers that had not published compliant training-content summaries under Article 53(1)(d). Maximum penalties applicable under Article 101 for GPAI providers: €15 million or 3% of worldwide annual turnover, whichever is higher. No formal investigation decision or financial penalty has been issued to date; the RFI campaign is ongoing.

Source integrity note: No primary European Commission press release was confirmed at time of writing. The 29 August RFI issuance was reported by Euractiv based on EVP Virkkunen's public statement; included on that basis, subject to formal confirmation.

What it means for you

If your organisation provides a general-purpose AI model (Article 3(63)), these RFIs are directed at organisations in your role. If you have integrated a third-party GPAI model into your own AI system — which makes your organisation a provider of that AI system under Article 3(3), not a deployer of the upstream GPAI model — your obligation is to verify and retain the technical documentation your upstream GPAI model provider is required to give you under Article 53(1)(b). Enforcement is moving faster than market consensus anticipated: the first RFIs arrived within four weeks of obligations becoming enforceable.

Sources

  1. The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
  2. AI Office first GPAI enforcement RFIs — Tokenstead/Euractiv (29.08.2026)
  3. GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)

Annex XIV / AIH 0401 — "Agentic AI" Named in Binding EU Law, as a Notified-Body Code

Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, added new nomenclature codes to Annex XIV of the AI Act. One of them, AIH 0401, covers "AI systems based on other emerging AI technologies not covered by other codes, including agentic AI" — the first time the phrase "agentic AI" appears in binding EU law.

Annex XIV has one purpose: the notification procedure under Article 30, where its codes set the scope of what a notified body is designated to assess. AIH 0401 is a residual filing code that names agentic AI as an example. It does not define agentic AI, and it is not a risk category.

What it means for you

AIH 0401 creates no obligations for providers or deployers. Whether an agentic system carries duties still turns on the existing tests: is it high-risk under Article 6 and Annex III (or part of a product regulated under Annex I), does Article 50 apply because it interacts with people or generates synthetic content, or do you provide a general-purpose AI model under Chapter V? The practical change is narrower: if a high-risk agentic system needs third-party conformity assessment, check that the notified body you engage is designated for AIH 0401.

Sources

  1. Annex XIV AIH 0401 agentic AI classification analysis — NIC Fabrizio (28.08.2026)
  2. Annex XIV: codes for the notification procedure referred to in Article 30 — EU Artificial Intelligence Act
  3. The Definition the Law Did Not Write — AI Governance Report

Article 50 Watermarking — Major Model Providers Report Deployments

EU AI Act Newsletter #109 (24 August 2026) reported Article 50 watermarking deployments by the largest model providers ahead of the 2 August 2026 application date of Article 50's transparency obligations: Anthropic deployed invisible text watermarking; Google deployed SynthID alongside C2PA Content Credentials; Meta implemented C2PA metadata combined with deep-learning content authentication marks. Detection interoperability across providers is formally deferred to 2 February 2027, pending European Commission harmonised technical specifications.

What it means for you

If your AI system generates synthetic content, Article 50(2) has required you, as its provider, to mark that output in a machine-readable format since 2 August 2026. A narrower deployer duty under Article 50(4) also applies as of that date, but only to two cases — deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest — where you must disclose to your audience that the content is artificial. Verify whether any GPAI model you integrate carries Article 50-compliant watermarking or C2PA metadata; document the result in writing. Interoperability of detection tools across providers does not apply until February 2027, but the underlying marking and disclosure obligations are live now.

Sources

  1. The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
  2. EU AI Act Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)

ISO/IEC 42001 — German National Transposition Published

Germany's DIN (Deutsches Institut für Normung) published the official German-language national transposition of EN ISO/IEC 42001:2026, designated DIN EN ISO/IEC 42001:2026-08, in August 2026. The previous draft (DIN ISO/IEC 42001:2025-10) is superseded and withdrawn. DAkkS-accredited certification bodies in Germany now have a normative DIN EN reference for ISO/IEC 42001 certification engagements.

What it means for you

If your organisation operates in Germany or the DACH market, the "waiting for the German standard" objection to ISO/IEC 42001 certification is closed. The EN designation is a European adoption of the unchanged international text. It does not confer presumption of conformity under the AI Act — no Official Journal citation has been issued — and certification does not replace the Article 17 quality management system a high-risk provider must run. AFNOR (France), NSAI (Ireland), and BSI (UK) transpositions are expected on similar timelines.

Sources

  1. DIN EN ISO/IEC 42001:2026-08 — DIN Media (01.08.2026)
  2. EN ISO/IEC 42001:2026 CEN/CENELEC catalogue entry — CEN/CENELEC (01.08.2026)

CNIL Answers Common Questions on Credit Refusal

France's CNIL published a question-and-answer page on credit refusal on 19 August 2026. It explains that there is no general right to credit, that lenders must assess an applicant's capacity to repay, and that an applicant who is refused can ask why.

What it means for you

If you use scoring models or AI to decide on credit applications, this is what applicants in France are now told they can ask for: the reasons for a refusal. Where a refusal rests solely on automated processing, Article 22 GDPR also gives the applicant the right to human intervention and to contest the decision. Separately, AI used to evaluate the creditworthiness of natural persons is high-risk under Annex III point 5(b) of the AI Act, with obligations applying from 2 December 2027 under the Digital Omnibus timetable.

Sources

  1. Le refus de crédit en questions — CNIL (19.08.2026)

EDPB Stakeholder Event — Data Protection and Competition Law

The EDPB's call for expressions of interest in a stakeholder event on its forthcoming guidelines on the interplay between data protection and competition law closed on 28 August 2026. The event takes place on 15 October 2026. The EDPB has not published a date for the guidelines themselves.

What it means for you

These guidelines are not yet published, and no obligations result from this item. They are likely to matter most to organisations that rely on data held by large platforms, including for AI training. EDPB guidelines normally go to public consultation once drafted, which is the next opportunity to comment.

Sources

  1. EDPB stakeholder event on data protection and competition law interplay — EDPB (28.08.2026)

What to do this week

  • If you have integrated a GPAI model API into your own AI system (making you a downstream system provider under Article 3(3)): confirm you have received, date-stamped, and retained the Article 53(1)(b) technical documentation from your upstream GPAI model provider; if you have not received it, request it in writing now.
  • If you provide a general-purpose AI model (Article 3(63)): review your Article 53(1)(a)–(d) documentation for completeness in light of the active RFI campaign.
  • List the agentic AI systems you provide or deploy and record, for each, whether it is high-risk under Article 6, within Article 50, or neither — AIH 0401 does not answer that question for you.
  • Contact your GPAI model API provider to confirm whether their API responses carry Article 50-compliant watermarking or C2PA metadata; document the response.
  • Where you publish deep fakes, or AI-generated text informing the public on matters of public interest, add the Article 50(4) disclosure.
  • If you make automated decisions on credit applications, check that applicants can obtain the reasons for a refusal and, under Article 22 GDPR, human intervention in a solely automated decision.
  • Note the EDPB's 15 October 2026 stakeholder event, and watch for the public consultation on its data protection and competition law guidelines.

Quick reference

TopicChangeAction
EU AI Act — GPAI EnforcementAI Office RFIs to GPAI providers (29 Aug 2026): first formal enforcement instruments under the ActGPAI providers: prepare Art. 53 documentation. Downstream system providers (Art. 3(3)): verify you hold Art. 53(1)(b) documentation from your upstream provider.
EU AI Act — Agentic AIDigital Omnibus adds Annex XIV code AIH 0401, naming agentic AI — a notified-body scope code, not a new obligationScope agentic systems under the existing tests (Art. 6 and Annex III, Art. 50); check notified-body designations if third-party assessment applies
EU AI Act — WatermarkingMajor GPAI providers deploying Art. 50 watermarking; interoperability deferred to Feb 2027Confirm your model provider's watermarking status; add the Art. 50(4) disclosure where you publish deep fakes or public-interest text
ISO/IEC 42001DIN EN ISO/IEC 42001:2026-08 published — German national transposition completeUpdate standard references for DE/AT operations; no change to substantive controls
GDPRCNIL publishes questions and answers on credit refusal (19 Aug 2026)If you automate credit decisions: confirm refusal reasons and Art. 22 GDPR human intervention are available
GDPREDPB stakeholder event on data protection and competition law: registrations closed 28 Aug 2026, event 15 Oct 2026No action; watch for the public consultation on the guidelines

Every source in this issue

  1. The EU AI Act Newsletter #109: The Watermarking Era — EU AI Act Newsletter (24.08.2026)
  2. AI Office first GPAI enforcement RFIs — Tokenstead/Euractiv (29.08.2026)
  3. Annex XIV AIH 0401 agentic AI classification analysis — NIC Fabrizio (28.08.2026)
  4. Annex XIV: codes for the notification procedure referred to in Article 30 — EU Artificial Intelligence Act
  5. The Definition the Law Did Not Write — AI Governance Report
  6. GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
  7. EU AI Act Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)
  8. DIN EN ISO/IEC 42001:2026-08 — DIN Media (01.08.2026)
  9. EN ISO/IEC 42001:2026 CEN/CENELEC catalogue entry — CEN/CENELEC (01.08.2026)
  10. Le refus de crédit en questions — CNIL (19.08.2026)
  11. EDPB stakeholder event on data protection and competition law — EDPB (28.08.2026)
  12. EDPS Opinion 17/2026 — Regulation 2018/1725 revision — EDPS (20.08.2026)

Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.

Subscribe

The EU AI governance brief

One email a week. Sourced and dated. Unsubscribe in one click, from any of them.

Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.

More issues
05.10.2026 · Week 41

EU AI Act Regulatory Brief — Week of 5 October 2026

The Dutch data protection authority's €825 million fine on Uber, now under appeal, shows what Article 22 GDPR demands when automated systems cut people off. A leaked Council text would add an AI legitimate-interest clause to the GDPR without four Commission safeguards; it is not law. The AI Board met on 17 September and set no new deadlines.

Read →
28.09.2026 · Week 40

EU AI Act Regulatory Brief — Week of 28 September 2026

EN 18286:2026, the first European standard written for the AI Act, is published but not yet cited in the Official Journal. The EDPB's draft fining guidelines decide who can be fined, not only how much. Council talks on the GDPR part of the Digital Omnibus continue, with an AI legitimate-interest clause back in the text. No ISO/IEC 42001 change.

Read →
21.09.2026 · Week 39

EU AI Act Regulatory Brief — Week of 21 September 2026

The EDPB adopted draft fining-methodology guidelines and finalised DSA-GDPR interplay guidance at its 21 September plenary. No new EU AI Act enforcement instruments or ISO 42001 revisions were confirmed during the 15-21 September window.

Read →