Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature AI Risk

The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.

The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.

By Rebecca Leung · September 5, 2026 ·
Table of Contents

TL;DR

  • On August 30, 2026, the European AI Office began its first wave of on-site inspections under the EU AI Act, working with 24 national market surveillance authorities across member states.
  • The initial targets are algorithmic credit-assessment systems, automated resume-screening tools, and AI-powered healthcare triage — all classified as high-risk under Annex III.
  • Inspectors are requesting Article 11 technical documentation: architecture diagrams, data governance logs, human oversight records, and risk management artifacts — and they want evidence the documents match production systems, not just policy statements.
  • Penalties reach €15 million or 3% of global annual turnover for high-risk system violations. The compliance runway closed August 2.

The August 2 compliance deadline passed five weeks ago. For most fintech and financial services AI teams, that deadline came and went with a lot of internal activity — updated risk assessments, new board presentations, vendor documentation requests — and a quiet hope that inspections were still abstract.

They’re not abstract anymore.

On August 30, 2026, the European AI Office — the EU’s central enforcement body for the AI Act — began its first scheduled wave of on-site compliance inspections. Working alongside 24 national market surveillance authorities, inspectors are now physically showing up at organizations that operate high-risk AI systems. Their first targets: algorithmic credit-assessment systems in retail banking, automated resume-screening tools in human resources, and AI-powered triage systems in private healthcare.

If you’re running a credit scoring model, a lending underwriting engine, or an AML transaction monitoring system that affects EU residents — and you haven’t fully assembled your Article 11 technical documentation file — this post is for you.

What Made August 30 the Starting Gun

The EU AI Act’s timeline for high-risk AI obligations ran in phases. The GPAI (general purpose AI) rules and prohibited-AI prohibitions came first. High-risk system obligations — the full Article 8 through Article 15 compliance regime — became enforceable on August 2, 2026. That was the date by which providers had to have completed conformity assessments, registered systems in the EU database, and ensured their technical documentation was complete and current.

The European AI Office’s commitment to beginning inspections shortly after the deadline was deliberate: the August 30 start gives institutions a window to have resolved deadline-day gaps, while making clear that the post-deadline grace period has closed.

France (CNIL), Germany (BfDI), and Spain (AESIA) are leading the first wave of national-authority inspections, focusing specifically on three sectors: retail banking credit assessment, HR screening tools, and private healthcare AI. The European AI Office in Brussels is coordinating cross-border investigations for systems that operate across multiple member states.

Which Systems Are Classified as High-Risk in Financial Services

The EU AI Act’s Annex III lists the categories of AI systems that are automatically classified as high-risk. For financial services, the most directly relevant are:

Category 5 (Access to essential private services and public services and benefits):

  • 5(b): AI used in creditworthiness assessment or credit scoring — consumer loans, mortgages, credit cards, any AI that evaluates the creditworthiness of a natural person
  • 5(c): AI used in life and health insurance risk assessment

Category 1 (Biometric identification): Remote biometric identification systems deployed in real-time public spaces, and post-remote biometric verification systems not excluded by Article 6.

Note the fraud detection carve-out: Recital 58 of the Act states that fraud detection AI systems — systems that assess transaction risk without affecting individual legal rights — are not automatically high-risk. But the carve-out is narrow. An AI system that simultaneously scores creditworthiness and fraud risk must comply with high-risk requirements for the creditworthiness component. AML transaction monitoring that feeds into SAR decisions is being scrutinized more closely; seek legal analysis if you’re relying on the Recital 58 exclusion.

What Inspectors Are Actually Requesting

The first question most compliance teams have is: what do inspectors actually ask for when they show up?

Based on the August 30 inspection wave, the European AI Office and national authorities are organizing their requests around Article 11’s technical documentation requirements (Annex IV). The Annex IV dossier has eight required sections:

Annex IV SectionWhat It Contains
1. General descriptionIntended purpose, version, and deployment context
2. System designArchitecture, algorithms, design choices and rationale
3. Training dataData sources, labeling methodology, bias assessment
4. Training and testingMethodologies, metrics, test environments
5. Performance evaluationAccuracy, robustness, non-discrimination results
6. Risk managementRisk identification, mitigation measures, residual risks
7. Technical change logVersion history, significant modifications
8. Standards appliedTechnical standards or specifications used

Beyond the paper file, inspectors during this first wave have requested four specific categories of artifacts:

  1. Architecture diagrams showing how the AI system is deployed in production — not a conceptual overview, but a diagram that maps the actual data flows, input sources, and output paths in the live environment
  2. Data governance logs demonstrating that training data was managed under the Act’s requirements — data provenance records, labeling quality documentation, and evidence that data quality measures were applied
  3. Human oversight schematics — documentation of how human oversight is implemented in practice, including the roles involved, the authority to override, and records showing that oversight actually occurred in a sample of decisions
  4. Risk management records demonstrating that the risk management system described in Annex IV was operational, not merely documented

The Evidence Problem: Why Policy Documents Aren’t Enough

The most important practical insight from the inspection wave is captured in a distinction now circulating among EU AI Act compliance practitioners: auditors are not asking for documentation. They are asking for evidence.

A policy document that describes how human oversight works is documentation. A log file showing that a human reviewer accessed 847 flagged credit decisions in August 2026, with timestamps, reviewer IDs, and override records, is evidence.

A risk management plan is documentation. Records showing the plan was executed — that each identified risk was assessed, that mitigations were tested, that post-deployment monitoring is running — are evidence.

This distinction is already separating organizations that treated the August 2 deadline as a documentation exercise from those that treated it as an operational control implementation. The former produced coherent policy files. The latter have the artifacts to show inspectors.

Provider vs. Deployer: Which Obligations Apply to You?

As we covered when the August 2 deadline hit, the EU AI Act differentiates between providers and deployers, and the distinction determines your documentation obligations.

Providers (entities that developed, trained, or substantially modified the AI system and placed it on the market):

  • Must prepare and maintain the complete Annex IV technical documentation file
  • Must complete a conformity assessment (self-assessment for most financial AI systems)
  • Must affix CE marking and register the system in the EU AI database
  • Must establish a post-market monitoring system

Deployers (institutions using a third-party AI system under their own authority):

  • Must implement human oversight measures as specified by the provider
  • Must complete a Fundamental Rights Impact Assessment (FRIA) before deployment
  • Must monitor for risks and report serious incidents to market surveillance authorities
  • Must maintain logs where technically feasible
  • Must ensure personnel operating the system have adequate AI literacy

Most US fintechs operating in the EU are deployers — they license credit scoring or fraud detection models from third-party vendors. But deployer status doesn’t mean minimal documentation. Your FRIA, your human oversight implementation records, and your incident log are all fair game for inspectors.

What US Fintechs With EU Exposure Need Right Now

If your organization has EU exposure — EU customers, EU partner institutions, or models that process data related to EU residents — and you haven’t yet completed the following, the inspection wave that started August 30 is now your timeline:

Confirm your coverage position. Identify every AI system that could be classified as high-risk under Annex III. Map which systems your organization built (provider) and which you license from third parties (deployer). Confirm EU nexus with legal counsel.

Assemble the Annex IV technical documentation file. If you’re a provider, this file must exist and be current. If you’re a deployer, request the technical documentation package from your AI vendor — they’re required to provide it, and it’s a direct input to your deployer audit file.

Build your evidence layer. Policies aren’t enough. You need operational logs: human oversight interaction records, data quality audit trails, post-deployment monitoring outputs. If you haven’t implemented logging that captures these artifacts, that’s the highest-priority gap.

Complete the FRIA. Every deployer of a high-risk AI system affecting EU residents is required to conduct a Fundamental Rights Impact Assessment. The assessment evaluates whether the AI system’s deployment affects fundamental rights protected under the EU Charter — including non-discrimination rights directly relevant to credit scoring.

Establish your EU point of contact. Non-EU providers and deployers may need to designate an EU representative. Confirm the requirement applies to your structure.

So What Does This Mean for Your AI Governance Program?

The September 2026 inspection wave is the EU AI Act’s proof-of-concept enforcement moment. The first organizations selected for inspection will set the evidentiary standard — what passes muster, what doesn’t, and where the gaps are.

For teams watching the first inspections unfold, the board-level AI governance metrics that examiners have been tracking in the US are now joined by a parallel EU documentation obligation that has teeth. The EU AI Act’s penalty framework — up to €15 million or 3% of global annual turnover — is not aspirational. It’s the statutory maximum that’s now actively in play.

The organizations best positioned for this inspection wave are those that treated the August 2 deadline as an operational control implementation, not a documentation exercise. If you’re not in that position yet, the gap between your current state and what inspectors are requesting is real, measurable, and closable — but the window is narrowing.

If you’re still mapping your AI use cases, running pre-deployment assessments, or building your vendor due diligence questionnaires, the AI Risk Assessment Template includes an AI use case inventory, pre-deployment scorecard, and third-party vendor questionnaire built for exactly this environment — including worked examples for credit underwriting, AML monitoring, and fraud detection.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

My company is a US-only fintech with no EU customers. Does the EU AI Act apply to me?
If your AI system produces outputs that are used within the EU — including through a partner, platform, or API — you may fall under the Act's scope regardless of where you're headquartered. The EU AI Act applies to providers whose systems are placed on the EU market or affect EU residents, and to deployers who use covered systems in the EU. If you white-label your credit scoring model to an EU-based lender, or your fraud detection API is called by an EU institution, the Act reaches you. Confirm your EU nexus with counsel.
What is Article 11 technical documentation and how is it different from a model card or risk assessment?
Article 11 and Annex IV of the EU AI Act require a specific dossier that goes well beyond a model card. Annex IV specifies: a general description of the AI system and its intended purpose; a description of the system's elements (architecture, algorithms, training data characteristics, data labeling methodology); technical specifications of the inputs; a description of the training, testing, and validation approaches with detailed technical specifications; a description of performance metrics and testing results; a description of known risks and risk management measures; and ongoing monitoring, logging, and post-market surveillance procedures. A model card documents what a model does; the Annex IV dossier documents every decision made in building it, for the purpose of enabling a regulator to assess compliance.
What's the difference between a provider and a deployer under the EU AI Act, and which one faces inspection first?
A provider is the entity that developed, trained, or substantially modified the high-risk AI system and placed it on the market. A deployer is a business that uses the system under its own authority — typically a lender, bank, or fintech using a third-party credit model. Providers carry the heavier documentation obligation (Article 11 technical file, conformity assessment, EU database registration). Deployers carry human oversight, fundamental rights impact assessment, and AI literacy obligations. The European AI Office's first wave targets all entities with deployed high-risk systems — providers first on documentation; deployers closely behind on oversight evidence.
What are the penalties for failing an EU AI Act inspection on high-risk AI?
Under Article 99 of the EU AI Act, non-compliance with obligations for high-risk AI systems carries penalties up to €15 million or 3% of global annual worldwide turnover, whichever is higher. For large institutions, the 3% global turnover figure is the binding cap. These are not proposed penalties subject to negotiation before an order — they are the statutory maximum at which the authority can issue a fine once a violation is confirmed.
We're using a vendor's credit scoring model, not building our own. Are we still on the hook?
Yes. Under the EU AI Act, a deployer that uses a third-party high-risk AI system under its own authority bears deployer obligations regardless of who built the model. You are responsible for: ensuring human oversight measures are in place and operational, conducting a fundamental rights impact assessment before deployment, implementing the system only as specified in the provider's instructions, monitoring for risks in operation, and maintaining logs when you can technically control them. Vendor contracts should specify what the provider supplies (technical documentation, conformity assessment, instructions for use) and what you are responsible for (deployment, oversight, monitoring). If your vendor hasn't given you an Article 11 technical documentation package, ask for it now — you need it for your own audit file.
What does 'evidence vs. documentation' mean in the context of EU AI Act inspections?
Regulators at the European AI Office are not asking whether you have a policy that says you conduct human oversight. They are asking for evidence that human oversight is actually happening — audit logs showing human reviewers interacted with AI-flagged decisions, training records for staff who operate the system, documented cases where human override was exercised. The same distinction applies throughout the technical documentation: it's not enough to have a risk management plan; you need logs and records showing the plan was executed. Policy documents without operational artifacts are almost universally insufficient in the first wave of inspections.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.