Week 38 · 6 min read

EU AI Act Regulatory Brief — Week of 14 September 2026

No new EU AI Act guidance or GDPR enforcement decisions were published this week. The material story is the AI Office's ongoing formal information request campaign against 30-plus GPAI model providers — the Act's first enforcement instruments. Germany and Austria completed ISO 42001 national transpositions in August; the underlying standard is unchanged.

Relay Labs Ltd ·

AI Office — Formal Requests for Information to 30+ GPAI Model Providers: First Enforcement Instruments Under the AI Act

Following the 2 August 2025 application date for Chapter V (GPAI) obligations — with the Commission's enforcement powers commencing 2 August 2026 — the EU AI Office dispatched Requests for Information (RFIs) under Article 91 to more than 30 GPAI model providers. These are the first formal enforcement instruments reported under the AI Act. The RFIs require providers to demonstrate compliance with:

  • Technical documentation obligations (Article 53(1)(a))
  • Downstream system-provider disclosure requirements (Article 53(1)(b))
  • Copyright compliance policy (Article 53(1)(c))
  • For frontier-tier models flagged as posing systemic risk: adversarial testing and incident reporting obligations (Article 55)

The AI Office has not publicly named the 30+ recipients. No investigation decision or financial penalty has been issued to date; the campaign is ongoing.

Role note: Article 53(1)(b) governs what a GPAI model provider must disclose to organisations that integrate the GPAI model into their own AI systems. An organisation that integrates a third-party GPAI model API into its own AI system is a downstream provider of that system under Article 3(3) — not a deployer of the upstream GPAI model — and is the recipient of Article 53(1)(b) documentation, not the source of it.

What it means for you

If you provide a general-purpose AI model (Article 3(63)), these RFIs are directed at organisations in your role. If you have built an AI system by integrating a third-party GPAI model — making you a downstream system provider under Article 3(3) — your obligation is to verify that you have received, retained, and date-stamped the Article 53(1)(b) technical documentation packet from your upstream GPAI model provider. If that documentation was not proactively provided, request it now in writing. Absence of this documentation is a recordable compliance gap. The Article 101 fine ceiling for general-purpose AI model providers — €15 million or 3% of worldwide annual turnover, whichever is higher — is now enforceable.

Sources

  1. Commission starts enforcing AI Act rules and new transparency requirements — 2 August 2026 — European Commission (02.08.2026)
  2. AI Act Enforcement Framework — AI Office — European Commission (02.08.2026)
  3. GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
  4. European Commission receives final version of General-Purpose AI Code of Practice — IAPP (10.07.2025)

No New Harmonised Standards, Delegated Acts, or National Authority Decisions — Week of 8–14 September 2026

No additional harmonised standards beyond EN 18286:2026 (published 31 July 2026; first reported in the week of 7 September 2026 brief) were confirmed published or cited in the EU Official Journal during the 8–14 September monitoring window. No new Commission delegated or implementing acts under the AI Act were confirmed. Many Member States have still not confirmed their national competent authority (NCA) designations.

What it means for you

Nothing to act on this week regarding harmonised standards, delegated acts, or NCA designations. The only AI Act-specific harmonised standard remains EN 18286:2026, which is not yet cited in the Official Journal and therefore does not confer presumption of conformity. If your organisation operates in a Member State without a confirmed NCA, you have no national authority to engage with yet — monitor the Official Journal and national announcements for designations.

Sources

  1. CEN-CENELEC EN 18286 — AI Quality Management — CEN/CENELEC (31.07.2026)
  2. Bundesnetzagentur takes on key role in AI Act implementation — Bundesnetzagentur (29.07.2026)

ISO/IEC 42001 — DIN and OEVE Publish National Adoptions of EN ISO/IEC 42001:2026

DIN (Germany) and OEVE (Austria) published their national adoptions of EN ISO/IEC 42001:2026 in August 2026. These are transpositions of the existing ISO/IEC 42001:2023 base document under the European EN prefix — not a revision of the underlying standard. ISO/IEC 42001:2023 remains the current base document; the underlying controls are identical to the 2023 edition.

What it means for you

For organisations operating in Germany or Austria, the normative reference for ISO/IEC 42001 certification engagements is now DIN EN ISO/IEC 42001:2026-08 / ÖNORM EN ISO/IEC 42001:2026-08. No change to substantive obligations or controls. The standard does not confer AI Act presumption of conformity — no Official Journal citation has been issued. NSAI (Ireland), AFNOR (France), and BSI (UK) transpositions are expected on similar timelines.

Sources

  1. DIN EN ISO/IEC 42001 — 2026-08 — DIN Media (01.08.2026)
  2. OEVE/OENORM EN ISO/IEC 42001:2026-08-01 — DIN/OEVE (01.08.2026)

GDPR — EDPB Guidelines 03/2026 on Web Scraping: Consultation Open Until 30 October

No new EDPB opinions, enforcement decisions, or proposed GDPR revisions were confirmed for the week of 14 September 2026. The live item in this domain remains EDPB Guidelines 03/2026 on web scraping in the context of generative AI (adopted 7 July 2026). The public consultation is open until 30 October 2026. The guidelines confirm that "legitimate interests" under Article 6(1)(f) is not straightforwardly available as the lawful basis for scraping publicly available personal data for AI training, and that data subjects' rights — including the right to object — apply to scraped personal data used in training sets.

What it means for you

If your organisation uses AI models trained on scraped data — or you are a downstream system provider (Article 3(3)) building on such a model — the EDPB 03/2026 guidelines are the governing framework for your training-data lineage documentation. "Legitimate interests" under Article 6(1)(f) is not straightforwardly available as the lawful basis for scraping publicly available personal data for AI training. Review your training-data provenance records: timestamping and source recording are required for training datasets involving EU personal data.

Sources

  1. Guidelines 03/2026 on Web Scraping in the Context of Generative AI — public consultation — EDPB (08.07.2026)
  2. EDPB sheds light on anonymisation and web scraping for generative AI — EDPB (08.07.2026)
  3. What Do the EDPB's Web Scraping Guidelines Mean for AI Training Datasets? — Sidley (23.07.2026)
  4. Anonymous or not? EDPB's new draft guidelines on anonymisation — Freshfields (08.07.2026)

What to do this week

  • If your organisation has built an AI system integrating a third-party GPAI model API (making you a downstream system provider under Article 3(3)): verify you have received, date-stamped, and retained the Article 53(1)(b) technical documentation from your upstream GPAI model provider; if not, request it in writing now.
  • If you provide a general-purpose AI model (Article 3(63)): review Article 53(1)(a)–(d) documentation completeness in light of the active RFI campaign.
  • Update standard references for German-market or Austrian-market operations from DIN ISO/IEC 42001:2025-10 to DIN EN ISO/IEC 42001:2026-08 / ÖNORM EN ISO/IEC 42001:2026-08 as applicable; no substantive changes to controls.
  • If you have operational experience of training on scraped data, consider responding to the EDPB consultation on Guidelines 03/2026 before 30 October 2026.
  • Review and document your training-data provenance records against EDPB 03/2026 criteria: timestamping and source recording are required for training datasets involving EU personal data.

Quick reference

TopicChangeAction
EU AI Act — EnforcementAI Office RFIs to 30+ GPAI providers; first enforcement instruments under the Act; no decisions or fines yetGPAI providers: prepare Art. 53 documentation. Downstream system providers (Art. 3(3)): verify and retain Art. 53(1)(b) documentation from your GPAI model provider.
EU AI Act — Standards/ActsNo new harmonised standards, delegated acts, or NCA decisions this weekMonitor OJ for EN 18286:2026 citation (presumption of conformity trigger)
ISO/IEC 42001DIN (Germany) + OEVE (Austria) national EN ISO/IEC 42001:2026 adoptions published August 2026; no change to underlying standardUpdate standard references for DE/AT operations if applicable
GDPRNo new developments; EDPB 03/2026 web scraping consultation open until 30 Oct 2026Maintain training-data provenance documentation; consider responding by 30 Oct

Every source in this issue

  1. Commission starts enforcing AI Act rules — 2 August 2026 — European Commission (02.08.2026)
  2. AI Act Enforcement Framework — AI Office — European Commission (02.08.2026)
  3. GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
  4. European Commission receives final version of General-Purpose AI Code of Practice — IAPP (10.07.2025)
  5. EU AI Omnibus Enters Into Force: Amending the AI Act — White & Case (15.07.2026)
  6. EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes — Orrick (15.07.2026)
  7. EU AI Act Unpacked #34: The Final Digital Omnibus on AI — Freshfields (15.07.2026)
  8. CEN-CENELEC EN 18286 — AI Quality Management — CEN/CENELEC (31.07.2026)
  9. First European standard supporting the AI Act — ANEC (31.07.2026)
  10. Bundesnetzagentur — AI Act implementation role — Bundesnetzagentur (29.07.2026)
  11. Germany's AI Implementation Act (KI-MIG) — activeMind.legal (01.07.2026)
  12. DIN EN ISO/IEC 42001 — 2026-08 — DIN Media (01.08.2026)
  13. OEVE/OENORM EN ISO/IEC 42001:2026-08-01 — DIN/OEVE (01.08.2026)
  14. Guidelines 03/2026 on Web Scraping in the Context of Generative AI — EDPB (08.07.2026)
  15. EDPB sheds light on anonymisation and web scraping for generative AI — EDPB (08.07.2026)
  16. What Do the EDPB's Web Scraping Guidelines Mean for AI Training Datasets? — Sidley (23.07.2026)
  17. EDPB adopts guidelines on anonymous data, web scraping, and blockchain — Hunton Andrews Kurth (08.07.2026)
  18. Anonymous or not? EDPB's new draft guidelines on anonymisation — Freshfields (08.07.2026)

Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.

Subscribe

The EU AI governance brief

One email a week. Sourced and dated. Unsubscribe in one click, from any of them.

Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.

More issues
05.10.2026 · Week 41

EU AI Act Regulatory Brief — Week of 5 October 2026

The Dutch data protection authority's €825 million fine on Uber, now under appeal, shows what Article 22 GDPR demands when automated systems cut people off. A leaked Council text would add an AI legitimate-interest clause to the GDPR without four Commission safeguards; it is not law. The AI Board met on 17 September and set no new deadlines.

Read →
28.09.2026 · Week 40

EU AI Act Regulatory Brief — Week of 28 September 2026

EN 18286:2026, the first European standard written for the AI Act, is published but not yet cited in the Official Journal. The EDPB's draft fining guidelines decide who can be fined, not only how much. Council talks on the GDPR part of the Digital Omnibus continue, with an AI legitimate-interest clause back in the text. No ISO/IEC 42001 change.

Read →
21.09.2026 · Week 39

EU AI Act Regulatory Brief — Week of 21 September 2026

The EDPB adopted draft fining-methodology guidelines and finalised DSA-GDPR interplay guidance at its 21 September plenary. No new EU AI Act enforcement instruments or ISO 42001 revisions were confirmed during the 15-21 September window.

Read →