Back to blog
September 17, 2026EU AI Act Weekly Radar

EU AI Act Weekly Radar: enforcement is live even as key high-risk deadlines move

This week’s signal from the EU AI Act is clear: some deadlines have moved, but enforcement, transparency duties, and regulator scrutiny are already here for providers and deployers.

EU AI ActAI Act enforcementArticle 50 transparencyhigh-risk AI systemsAI governanceprovider and deployer obligationsSME complianceGPAI governance

The clearest message from this week’s EU AI Act developments is that delay does not mean dormancy. Even with reported movement around parts of the high-risk regime, multiple sources point in the same direction: enforcement activity is beginning, transparency duties are already live, and both providers and deployers should expect regulators to look closely at documentation, controls, and internal accountability now.

For lextrace readers, that matters because the current compliance question is no longer just *when do the biggest obligations apply?* It is also *which obligations are already enforceable, what evidence do regulators expect, and how should teams organize for a staggered implementation timeline?*

The main theme: implementation is staggered, but supervision is not paused

Several of this week’s updates reinforce a distinction that organizations need to keep straight.

As reported by Baker Botts, Article 50 transparency obligations are already enforceable, even though the so-called Digital Omnibus delay affects the timing of some high-risk rules. In parallel, EL PAÍS reports that postponement of high-risk obligations does not give companies a free pass to ignore the AI Act now, especially where already-applicable provisions can still trigger sanctions. DLA Piper adds a further practical warning: regulators have reportedly already started investigations and information requests, including questions directed at leading AI developers about cybersecurity, safety, and copyright practices.

Taken together, those updates suggest a regulatory environment where the formal timeline may be phased, but supervisory expectations are arriving earlier through transparency enforcement, information gathering, and role-based obligations that continue to apply.

Article 50 is the immediate pressure point for many AI products

The most concrete near-term compliance development this week comes from Baker Botts’ review of Article 50. Its key point is straightforward: transparency duties have gone live and are not waiting for the rest of the high-risk framework.

That matters especially for teams shipping chatbots, synthetic media tools, generative interfaces, or other systems whose outputs may trigger user-facing transparency requirements. Baker Botts also highlights a 2 December 2026 transition for generative systems placed on the market before 2 August 2026 to implement machine-readable marking. Just as importantly, the publication notes that non-EU providers may still fall within scope when outputs are used in the EU.

For companies that had treated the AI Act primarily as a future high-risk classification exercise under Article 6 and Annex III, this is a significant reframing. The immediate work is not limited to product classification. It can include:

  • determining whether any current product experience triggers transparency duties;
  • mapping where synthetic or AI-generated outputs are shown to end users;
  • assessing whether machine-readable marking capabilities are needed within the transition window; and
  • confirming whether territorial reach captures non-EU entities serving EU-facing use cases.

In practical governance terms, Article 50 looks less like a distant legal issue and more like a live product, labeling, and engineering implementation task.

High-risk delay does not remove current exposure

EL PAÍS adds an important counterweight to any market narrative that a delay to high-risk obligations means companies can safely stand down. Its reporting says the postponement does not mean businesses can ignore the AI Act, because sanction risk remains under provisions that are already in force.

That framing is useful for boards and executive teams. Too many compliance programs still treat the AI Act as a single future deadline. The better interpretation of this week’s reporting is that the Act now has multiple operative layers:

  1. obligations already in effect, such as transparency-related requirements highlighted by Baker Botts;
  2. active supervisory attention, as reflected in the DLA Piper report on information requests and investigations; and
  3. deferred but still material high-risk obligations, which continue to require preparation because the eventual regime will still demand governance evidence, technical controls, and role clarity.

EL PAÍS also notes that guidance and training are available through the AI Act Service Desk and that compliance work is becoming increasingly cross-functional across legal, engineering, cybersecurity, and audit. That is a notable operational signal. It suggests the market is moving away from narrow legal-readiness exercises and toward integrated assurance models.

Enforcement signals are getting more concrete

Among this week’s updates, the most direct enforcement signal comes from DLA Piper. Its 11 September briefing says AI Act investigations have started and that information requests have asked leading AI developers for details on cybersecurity, safety, and copyright practices. The same piece warns deployers not to assume they can wait, emphasizing that obligations for users of AI systems continue to apply and that responses to regulator letters may later serve as evidence in enforcement.

That should reshape how organizations think about AI Act readiness.

An information request is not only a legal event. It is also a stress test of whether a company can explain, consistently and quickly:

  • what role it plays for each system, such as provider or deployer;
  • what systems are in scope;
  • what controls exist for safety, security, and oversight;
  • how copyright-related practices are governed where relevant; and
  • who owns the evidence needed to support those statements.

The DLA Piper report is especially important because it shifts the conversation from abstract compliance architecture to regulator-facing proof. If responses to supervisory inquiries can become enforcement evidence, then draft documents, internal role confusion, and incomplete control descriptions all carry higher risk.

Provider and deployer obligations remain a live dividing line

A recurring implication across the Baker Botts, EL PAÍS, and DLA Piper items is that role allocation remains central. The market often defaults to asking whether a system is high-risk, but the more immediate governance question may be whether the organization is acting as a provider, deployer, or both across different products and workflows.

DLA Piper’s warning to deployers is particularly useful here. Even if organizations were expecting more time on certain high-risk obligations, that does not erase current duties attached to use, implementation, or response to supervisory outreach. Meanwhile, Baker Botts’ note on non-EU providers underscores that scope questions are not confined to EU-incorporated entities.

For multinational groups and platform businesses, this means AI governance cannot sit only at the product-manufacturer layer. It also has to reach customer deployments, internal use cases, output design, and contract structures that define who is doing what in practice.

The policy direction still points toward stronger incident and systemic-risk governance

This week also included two broader policy signals that matter for implementation strategy.

POLITICO Europe reports that member-state officials are set to discuss global AI rules, recent AI incidents, and updates on EU and international AI policy at an AI Board gathering. Based on that agenda, the continuing focus appears to include incident response and systemic-risk governance alongside AI Act implementation.

Separately, Euronews reported comments from MEP Brando Benifei that the EU has both the legal and technical capacity to lead on a global treaty on AI, but requires the political will to do so. While not an implementation document, the interview reinforces the idea that the EU sees the AI Act as a baseline for wider international guardrails, particularly around advanced-model risk.

These two items matter because they suggest the current implementation debate is not trending toward deregulatory retreat. Even where timelines for specific obligations are adjusted, the broader direction still points toward more coordinated oversight, more attention to incidents, and a stronger expectation that advanced AI governance will be evidenced in operational terms.

What this week means for Article 6 and Annex III planning

Although this week’s sources do not provide a detailed new interpretation of Article 6 or Annex III, they do make one strategic point clearer: organizations should avoid pausing high-risk analysis simply because some obligations have reportedly moved.

The reason is practical. Classification work under Article 6 and Annex III is not valuable only for meeting the final compliance date. It is also foundational for:

  • deciding whether a product roadmap is likely to enter the high-risk perimeter;
  • identifying which teams need to own future technical and governance controls;
  • separating systems with immediate transparency exposure from systems with later high-risk exposure; and
  • preparing a coherent regulator-facing explanation of why a system is or is not considered high-risk.

In other words, high-risk mapping remains part of present-tense governance, even if some parts of the mandatory regime land later than originally expected.

A practical operating model for SMEs and startups

Smaller organizations may be tempted to interpret this week’s news as a reason to wait for clearer guidance. That would be understandable, but the source set suggests a more selective approach.

EL PAÍS emphasizes the value of guidance and training through the AI Act Service Desk. DLA Piper’s enforcement-focused update suggests that even smaller deployers should be able to answer basic role, system, and control questions if approached by a regulator. Baker Botts shows that some obligations are product-specific and already active, especially for transparency.

For SMEs and startups, the most proportionate response is likely not a full enterprise compliance buildout overnight. It is a targeted readiness baseline:

  • maintain a current inventory of AI features and systems;
  • identify which offerings produce synthetic or generative outputs that may trigger transparency duties;
  • record whether the business is acting as provider, deployer, or both for each relevant use case;
  • assign responsibility across legal, engineering, security, and product; and
  • create a regulator-response file containing the core documents the company would rely on if asked about safety, cybersecurity, or governance.

That kind of lightweight structure is consistent with the cross-functional compliance trend described by EL PAÍS and the evidentiary concerns raised by DLA Piper.

The lextrace take

This week’s roundup does not show an AI Act that is slowing down in any simple sense. It shows an AI Act entering a more operational phase.

The reported delay around parts of the high-risk framework may change sequencing, budgets, and implementation calendars. But the same week’s reporting also shows:

  • live transparency enforcement, according to Baker Botts;
  • ongoing sanction risk under already-applicable rules, according to EL PAÍS;
  • active investigations and information requests, according to DLA Piper; and
  • continued policy focus on incidents, systemic risk, and international coordination, according to POLITICO Europe and Euronews.

For legal, product, and governance teams, the result is a more nuanced implementation reality. The right question is no longer whether the AI Act is here. It is which parts are here now, which parts are coming later, and whether the organization can prove it understands the difference.

That is where the next phase of AI governance work is likely to be won or lost: not in broad statements of intent, but in role clarity, product mapping, documentation quality, and the ability to respond credibly when regulators ask questions.