Week 40 · 6 min read

EU AI Act Regulatory Brief — Week of 28 September 2026

EN 18286:2026, the first European standard written for the AI Act, is published but not yet cited in the Official Journal. The EDPB's draft fining guidelines decide who can be fined, not only how much. Council talks on the GDPR part of the Digital Omnibus continue, with an AI legitimate-interest clause back in the text. No ISO/IEC 42001 change.

Relay Labs Ltd ·

EN 18286:2026 — The First European Standard for the AI Act, Not Yet Harmonised

CEN-CENELEC published EN 18286:2026 (Artificial intelligence — Quality management system for EU AI Act regulatory purposes) in July 2026. It is the first European standard developed under the Commission's AI Act standardisation request to be published, and it specifies the quality management system (QMS) that Article 17 requires of providers of high-risk AI systems. Its requirements map to the elements of Article 17(1)(a)–(m).

Status: EN 18286 has not been cited in the Official Journal of the EU. Until it is, it is not a harmonised standard in the legal sense and gives no presumption of conformity under Article 40. Certification against it is voluntary. Certification bodies already offer training and gap assessments against it.

Following the Digital Omnibus on AI, Article 17 applies to providers of stand-alone Annex III high-risk systems from 2 December 2027, and to high-risk AI in products covered by Annex I from 2 August 2028.

What it means for you

If you provide an AI system in an Annex III area — employment, creditworthiness, emergency patient triage, biometrics, critical infrastructure and the others listed — EN 18286 is the most detailed published reference for the QMS you must have in place by 2 December 2027. A gap assessment this autumn leaves about fourteen months for remediation.

Most Annex III systems are assessed by the provider itself under the internal-control procedure (Annex VI). A notified body is mainly relevant to biometric systems under Annex III point 1 (Article 43(1)). Plan your timeline on that basis.

In our assessment, EN 18286 is a likely early candidate for citation in the Official Journal. No citation date has been announced.

Sources

  1. EN 18286 — a New European Standard for AI Quality Management and EU AI Act Readiness — Has Been Published — SGS (21.07.2026)
  2. EN 18286 in the Spotlight: Supporting Compliance with the AI Act — CEN-CENELEC (30.07.2026)
  3. Artificial Intelligence: Council gives final green light to simplify and streamline rules — Council of the EU (29.06.2026)

EDPB Fining Guidelines — Who Can Be Fined, and When a Reprimand Is Enough

Last week's issue reported that the EDPB adopted draft Guidelines 04/2026 on administrative fines at its 21 September plenary. Two points in the five-step methodology matter most in practice.

Who can be fined (step 2). Liability depends on who is bound by the provision that was breached. Controllers answer for processing carried out on their behalf. Processors can be fined for breaching their own obligations — for example under Articles 28, 29, 30(2), 32 and 33(2) GDPR — and a processor that goes beyond the controller's instructions is treated as a controller for that processing (Article 28(10)).

Fine or no fine (steps 3 and 4). A fine requires the infringement to be intentional or negligent. That has been the law since the CJEU's Deutsche Wohnen judgment (C-807/21, December 2023); the methodology writes it into the process. A minor infringement generally leads to no fine, and a reprimand may be issued instead. A non-minor infringement carries a strong presumption of a fine.

The guidelines are a consultation draft. They are not binding, and supervisory authorities are expected to apply them once finalised. The consultation closes on 13 November 2026. The EDPB's final guidelines on the interplay between the Digital Services Act and the GDPR, adopted at the same plenary, will be published on the EDPB website after linguistic review.

What it means for you

Paperwork is not a defence in itself. The negligence test asks whether you could have been aware that the conduct infringed the GDPR; the draft says documented legal advice does not necessarily exculpate, and good faith avoids negligence only for a rare, unavoidable error. What a record does show is that you identified an obligation and acted on it — a data protection impact assessment where Article 35 requires one, safeguards actually implemented, your data protection officer consulted. Treat those records as evidence of how you handled the obligation, not as a shield.

If you are a processor — for example, a provider of an AI service that processes its customers' data — the controller's liability does not shield you. Your own duties on security, records of processing and breach notification carry their own fine exposure.

Sources

  1. EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines — EDPB (21.09.2026)
  2. Guidelines 04/2026 on the application of the power to impose administrative fines — EDPB (21.09.2026)
  3. European Data Protection Board consults on new GDPR fining framework — Pinsent Masons Out-Law

Digital Omnibus (GDPR) — Council Text Restores an AI Legitimate-Interest Clause; No Agreement

Council negotiations on the GDPR amendments in the Digital Omnibus resumed in September under the Irish Presidency. This is a separate track from the Digital Omnibus on AI, which is already law. A Presidency compromise text dated 3 September 2026 (Council document 12535/26) was prepared for the Antici Group meeting of 11 September.

Two provisions remain contested:

  • Pseudonymisation. The 3 September text moves the pseudonymisation provision into a new Article 25a, under which pseudonymised data would not be personal data for a party that cannot identify the person concerned. Critics argue this narrows the definition of personal data.
  • Legitimate interest for AI. A June compromise had reduced the AI legitimate-interest provision to a recital. The 3 September text restores an operative clause, Article 88bis, without the unconditional right to object that the Commission had proposed.

Member States have not agreed a position. Nothing has been adopted.

What it means for you

No operative AI legitimate-interest provision exists in the GDPR today. Legitimate interest under the existing Article 6(1)(f) can already be used for AI development case by case, subject to the three-step test the EDPB set out in Opinion 28/2024. There is no statutory presumption in its favour.

If you use pseudonymised datasets for model development — common in healthcare and financial services — do not assume the data falls outside the GDPR until a final text is adopted and in force.

Sources

  1. noyb: leaked EU draft makes AI data use lawful by default — ResultSense (21.09.2026)
  2. Digital Omnibus: What the Leaked Council Documents Say About AI and Personal Data — GDPR Local
  3. EDPB Opinion 28/2024: key takeaways on processing personal data in the context of AI models — CMS
  4. CDT Europe's AI Bulletin: September 2026 — Center for Democracy and Technology

What to do this week

  • If you provide an Annex III system, map your quality-management documentation against the elements of Article 17(1)(a)–(m). EN 18286:2026, sold by national standards bodies, details each of them.
  • Check whether each Annex III system uses internal control (Annex VI) or needs a notified body (Annex III point 1, Article 43(1)), and set your timeline accordingly.
  • For each AI system that processes personal data, check whether Article 35 requires a data protection impact assessment (processing likely to result in a high risk, including the types on your supervisory authority's list), and that one is on file where it does.
  • If you act as a processor, review your own GDPR duties — security (Article 32), records (Article 30(2)) and breach notification to the controller (Article 33(2)) — not only your contract terms.
  • If the fining methodology affects you, respond to the EDPB consultation on Guidelines 04/2026 by 13 November 2026.
  • Do not rely on a future AI legitimate-interest clause. Document a full Article 6(1)(f) assessment for any AI processing of personal data now.

Quick reference

TopicChangeAction
EN 18286:2026 (Art. 17 QMS)Published July 2026; first European standard for the AI Act; not cited in the OJ, so no presumption of conformityMap your QMS against Art. 17(1)(a)–(m)
AI Act high-risk datesAnnex III stand-alone systems: 2 Dec 2027; Annex I products: 2 Aug 2028Plan readiness to these dates
EDPB fining guidelines (04/2026)Draft; liability follows who is bound by the breached provision; records are not a negligence defence; consultation until 13 Nov 2026Check Art. 35 DPIAs and processor duties; respond by 13 Nov
GDPR legitimate interest for AICouncil text 12535/26 restores Art. 88bis; no agreement, not lawRely only on existing Art. 6(1)(f) assessments
ISO/IEC 42001No change this weekNone

Every source in this issue

  1. EN 18286 — a New European Standard for AI Quality Management and EU AI Act Readiness — Has Been Published — SGS (21.07.2026)
  2. EN 18286 in the Spotlight: Supporting Compliance with the AI Act — CEN-CENELEC (30.07.2026)
  3. Artificial Intelligence: Council gives final green light to simplify and streamline rules — Council of the EU (29.06.2026)
  4. EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines — EDPB (21.09.2026)
  5. Guidelines 04/2026 on the application of the power to impose administrative fines — EDPB (21.09.2026)
  6. European Data Protection Board consults on new GDPR fining framework — Pinsent Masons Out-Law
  7. noyb: leaked EU draft makes AI data use lawful by default — ResultSense (21.09.2026)
  8. Digital Omnibus: What the Leaked Council Documents Say About AI and Personal Data — GDPR Local
  9. EDPB Opinion 28/2024: key takeaways on processing personal data in the context of AI models — CMS
  10. CDT Europe's AI Bulletin: September 2026 — Center for Democracy and Technology

Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.

Subscribe

The EU AI governance brief

One email a week. Sourced and dated. Unsubscribe in one click, from any of them.

Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.

More issues
05.10.2026 · Week 41

EU AI Act Regulatory Brief — Week of 5 October 2026

The Dutch data protection authority's €825 million fine on Uber, now under appeal, shows what Article 22 GDPR demands when automated systems cut people off. A leaked Council text would add an AI legitimate-interest clause to the GDPR without four Commission safeguards; it is not law. The AI Board met on 17 September and set no new deadlines.

Read →
21.09.2026 · Week 39

EU AI Act Regulatory Brief — Week of 21 September 2026

The EDPB adopted draft fining-methodology guidelines and finalised DSA-GDPR interplay guidance at its 21 September plenary. No new EU AI Act enforcement instruments or ISO 42001 revisions were confirmed during the 15-21 September window.

Read →
14.09.2026 · Week 38

EU AI Act Regulatory Brief — Week of 14 September 2026

No new EU AI Act guidance or GDPR enforcement decisions were published this week. The material story is the AI Office's ongoing formal information request campaign against 30-plus GPAI model providers — the Act's first enforcement instruments. Germany and Austria completed ISO 42001 national transpositions in August; the underlying standard is unchanged.

Read →