Back to blog
October 2, 2026EU AI Act Weekly Radar

EU AI Act Weekly Radar: copyright scrutiny, governance transparency, and rising supervisory focus

This week’s EU AI Act radar tracks a new Commission consultation on AI and copyright, an Ombudsman inquiry into AI Act risk-information handling, and a supervisory signal from ESMA on AI oversight.

EU AI ActAI governanceGPAIcopyrightEuropean CommissionEuropean OmbudsmanESMAfinancial servicesAI complianceregulatory roundup

The EU AI Act story this week is less about headline legislative change and more about how implementation is being shaped around it. Three developments stand out: the European Commission has opened a targeted consultation on technology and copyright that expressly includes AI uses of protected content; the European Ombudsman has opened an inquiry concerning the Commission’s failure to reply to a request for information on management of risks under the AI Act; and, according to MLex, ESMA is placing AI among the initial priorities of a new supervisory initiative.

Taken together, these updates point to a familiar pattern in EU digital regulation: compliance is not only about reading the black-letter text of the AI Act. It is also about evidencing governance, responding to scrutiny, and preparing for sector-specific oversight that sits alongside the horizontal regime.

1. The Commission’s AI-and-copyright consultation raises the temperature for GPAI governance

The most directly operational development this week is the European Commission’s new targeted consultation on the effect of technology on copyright. The Commission says the consultation covers, among other issues, the use of copyright-protected content in AI and invites input from generative AI providers, rightsholders, intermediaries, researchers, national authorities, and consumer groups. Feedback is open until 3 November 2026, according to the Commission announcement titled *Commission seeks feedback on challenges and way forward in the area of effect of technology on copyright*.

For AI companies, this matters well beyond copyright policy in the abstract. In practice, the consultation is another sign that EU institutions continue to treat training-data governance, content-use traceability, and documentation around generative AI as live policy and compliance issues. Even where the AI Act’s implementation work is progressing on separate tracks, the surrounding copyright debate is likely to influence what regulators, rightsholders, and counterparties expect from providers’ internal controls.

For teams working on general-purpose AI, the immediate significance is governance readiness:

  • Documenting data sourcing choices will remain important where organizations may later need to explain how protected content was used, filtered, licensed, or excluded.
  • Retention of compliance evidence may become more valuable as policy discussions evolve and stakeholders test whether provider records are sufficiently complete.
  • Cross-functional coordination between legal, policy, engineering, procurement, and product teams is increasingly necessary; copyright risk cannot be isolated from broader AI governance.

This does not, by itself, change the AI Act’s legal text. But it does signal continued regulatory attention to one of the hardest operational questions in the market: what evidence organizations can produce about model-development inputs and downstream safeguards when challenged by regulators or rightsholders.

2. The Ombudsman inquiry is a governance signal, not just an administrative footnote

The second development is quieter but potentially important for anyone watching AI Act enforcement culture. The European Ombudsman has opened case 2098/2026/IJ concerning the European Commission’s failure to reply to a request for information about management of risks under the AI Act. The opening summary states that the inquiry was opened on 24 September 2026 and is ongoing.

On the face of it, this is a procedural transparency matter rather than an AI Act enforcement action against a provider or deployer. Still, it is notable for two reasons.

First, it highlights that AI governance scrutiny extends to institutional handling of risk information, not only to the conduct of market participants. In other words, questions about who knows what, who answers, and how risk-management information is handled are themselves becoming part of the accountability environment around the AI Act.

Second, it reinforces a broader implementation lesson for companies: responsiveness and explainability are governance functions. When regulators, supervisory bodies, customers, or affected stakeholders ask for information, the quality and timeliness of the response can become part of the compliance story. Organizations often focus on whether they have policies; they should also focus on whether those policies produce retrievable, reviewable, decision-grade records.

For compliance leaders, the practical takeaway is straightforward. If your organization may need to explain AI risk-management processes externally, governance should include:

  • clear ownership for regulatory and stakeholder requests;
  • recordkeeping that links risk assessments to decisions and approvals;
  • escalation paths where information requests raise legal or strategic issues; and
  • an operating model that can answer questions consistently across legal, product, risk, and public-policy teams.

That is useful whether the underlying issue concerns high-risk systems, transparency obligations, general-purpose AI, or procurement-driven due diligence.

3. ESMA’s reported focus on AI points to more sector-specific supervision

The third signal comes from financial-services supervision. MLex reported that ESMA said AI and tokenization will be the initial focus of a new Union Strategic Supervisory Priority designed to ensure supervisors have the expertise and capacity to oversee new technologies.

Because this item is reported by MLex rather than drawn here from a primary ESMA publication, it should be read carefully. Even so, the reported development fits a larger pattern that compliance teams should already expect: the AI Act is not the only oversight channel that matters. Sector regulators are building capability around AI, and that can translate into sharper supervisory expectations for firms in regulated markets.

For financial-services firms, that matters in at least three ways.

Supervisory attention may arrive through existing sector frameworks first

Even where an AI use case is being mapped against AI Act obligations, firms may be questioned under existing prudential, conduct, outsourcing, operational resilience, or governance expectations. The operational challenge is to avoid running AI Act compliance as a silo.

Control maturity will matter as much as legal classification

A firm may spend significant effort debating whether a particular use case falls within a high-risk category, but supervisors often start with basic control questions: who is accountable, what testing was done, how outputs are monitored, when humans intervene, and how incidents are escalated.

Evidence of board and senior-management engagement becomes more valuable

As supervisors build AI expertise, organizations should expect more attention on governance architecture, not just model performance claims. That includes risk appetite, documentation, challenge processes, and resource allocation.

For lextrace readers in banking, payments, insurance, capital markets, or fintech, the message is clear: horizontal AI Act implementation and vertical supervisory readiness should be planned together.

4. What this week says about the AI Act implementation phase

These three updates do not announce a dramatic rewrite of the AI Act. Instead, they show where implementation pressure is accumulating.

A. The compliance perimeter is wider than the statute alone

The Commission’s consultation shows that AI compliance cannot be reduced to the Act’s formal obligations. Copyright, data provenance, and stakeholder rights remain live adjacent issues that can shape enforcement priorities and market expectations.

B. Governance is becoming evidentiary

The Ombudsman inquiry underlines that the handling of risk information is itself a matter of scrutiny. In practical terms, organizations should assume that governance must be demonstrated, not merely described.

C. Sector supervisors are preparing to operationalize AI oversight

The ESMA signal, as reported by MLex, suggests that domain regulators are moving from general interest to supervisory preparedness. That increases the likelihood that AI questions will be asked in sector-specific examinations, reviews, or thematic workstreams.

5. Practical implications for providers, deployers, and SMEs

This week’s updates are especially relevant for organizations trying to prioritize limited compliance resources.

For providers of generative or general-purpose AI

The Commission consultation is a reminder to review how your organization documents training-data decisions, rightsholder-facing processes, and internal accountability for content-related issues. Even if legal positions differ across stakeholders, weak documentation is a recurring source of risk.

For deployers integrating AI into regulated services

The reported ESMA focus means deployers in financial services should not assume that responsibility sits only with the upstream vendor. Vendor diligence, use-case governance, monitoring, and escalation remain squarely relevant at deployment level.

For SMEs and startups

Smaller organizations often cannot build separate compliance tracks for AI Act, IP risk, and sector oversight. This week’s developments suggest the better approach is a compact but disciplined governance baseline: decision logs, clear ownership, proportionate recordkeeping, and contractual clarity with suppliers and customers.

6. What to watch next

Based on this week’s developments, the near-term watchlist is less about new grand announcements and more about whether institutions translate these signals into concrete implementation tools.

Key things to monitor include:

  • whether the Commission’s consultation generates more detailed expectations around AI use of copyright-protected content;
  • whether the Ombudsman inquiry produces broader discussion about transparency and handling of AI Act risk information within EU institutions; and
  • whether financial-sector supervisors issue more formal public material connecting AI oversight capability to supervisory practice.

Bottom line

This week’s radar suggests that the EU AI Act ecosystem is maturing through adjacent policy processes, transparency pressures, and sector-specific supervisory preparation. The main lesson for compliance teams is not that the legal text changed overnight. It is that implementation readiness now depends on something more demanding: the ability to show how AI decisions were made, how risks are documented, and how governance holds up when institutions start asking harder questions.

For lextrace readers, that makes this week less about doctrinal novelty and more about operational posture. The organizations best positioned for the next phase of the AI Act will be those treating copyright governance, information-handling discipline, and sector oversight readiness as part of one connected compliance system.