Feature AI Risk
The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.
The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.
Table of Contents
TL;DR
- On August 30, 2026, the European AI Office began its first wave of on-site inspections under the EU AI Act, working with 24 national market surveillance authorities across member states.
- The initial targets are algorithmic credit-assessment systems, automated resume-screening tools, and AI-powered healthcare triage — all classified as high-risk under Annex III.
- Inspectors are requesting Article 11 technical documentation: architecture diagrams, data governance logs, human oversight records, and risk management artifacts — and they want evidence the documents match production systems, not just policy statements.
- Penalties reach €15 million or 3% of global annual turnover for high-risk system violations. The compliance runway closed August 2.
The August 2 compliance deadline passed five weeks ago. For most fintech and financial services AI teams, that deadline came and went with a lot of internal activity — updated risk assessments, new board presentations, vendor documentation requests — and a quiet hope that inspections were still abstract.
They’re not abstract anymore.
On August 30, 2026, the European AI Office — the EU’s central enforcement body for the AI Act — began its first scheduled wave of on-site compliance inspections. Working alongside 24 national market surveillance authorities, inspectors are now physically showing up at organizations that operate high-risk AI systems. Their first targets: algorithmic credit-assessment systems in retail banking, automated resume-screening tools in human resources, and AI-powered triage systems in private healthcare.
If you’re running a credit scoring model, a lending underwriting engine, or an AML transaction monitoring system that affects EU residents — and you haven’t fully assembled your Article 11 technical documentation file — this post is for you.
What Made August 30 the Starting Gun
The EU AI Act’s timeline for high-risk AI obligations ran in phases. The GPAI (general purpose AI) rules and prohibited-AI prohibitions came first. High-risk system obligations — the full Article 8 through Article 15 compliance regime — became enforceable on August 2, 2026. That was the date by which providers had to have completed conformity assessments, registered systems in the EU database, and ensured their technical documentation was complete and current.
The European AI Office’s commitment to beginning inspections shortly after the deadline was deliberate: the August 30 start gives institutions a window to have resolved deadline-day gaps, while making clear that the post-deadline grace period has closed.
France (CNIL), Germany (BfDI), and Spain (AESIA) are leading the first wave of national-authority inspections, focusing specifically on three sectors: retail banking credit assessment, HR screening tools, and private healthcare AI. The European AI Office in Brussels is coordinating cross-border investigations for systems that operate across multiple member states.
Which Systems Are Classified as High-Risk in Financial Services
The EU AI Act’s Annex III lists the categories of AI systems that are automatically classified as high-risk. For financial services, the most directly relevant are:
Category 5 (Access to essential private services and public services and benefits):
- 5(b): AI used in creditworthiness assessment or credit scoring — consumer loans, mortgages, credit cards, any AI that evaluates the creditworthiness of a natural person
- 5(c): AI used in life and health insurance risk assessment
Category 1 (Biometric identification): Remote biometric identification systems deployed in real-time public spaces, and post-remote biometric verification systems not excluded by Article 6.
Note the fraud detection carve-out: Recital 58 of the Act states that fraud detection AI systems — systems that assess transaction risk without affecting individual legal rights — are not automatically high-risk. But the carve-out is narrow. An AI system that simultaneously scores creditworthiness and fraud risk must comply with high-risk requirements for the creditworthiness component. AML transaction monitoring that feeds into SAR decisions is being scrutinized more closely; seek legal analysis if you’re relying on the Recital 58 exclusion.
What Inspectors Are Actually Requesting
The first question most compliance teams have is: what do inspectors actually ask for when they show up?
Based on the August 30 inspection wave, the European AI Office and national authorities are organizing their requests around Article 11’s technical documentation requirements (Annex IV). The Annex IV dossier has eight required sections:
| Annex IV Section | What It Contains |
|---|---|
| 1. General description | Intended purpose, version, and deployment context |
| 2. System design | Architecture, algorithms, design choices and rationale |
| 3. Training data | Data sources, labeling methodology, bias assessment |
| 4. Training and testing | Methodologies, metrics, test environments |
| 5. Performance evaluation | Accuracy, robustness, non-discrimination results |
| 6. Risk management | Risk identification, mitigation measures, residual risks |
| 7. Technical change log | Version history, significant modifications |
| 8. Standards applied | Technical standards or specifications used |
Beyond the paper file, inspectors during this first wave have requested four specific categories of artifacts:
- Architecture diagrams showing how the AI system is deployed in production — not a conceptual overview, but a diagram that maps the actual data flows, input sources, and output paths in the live environment
- Data governance logs demonstrating that training data was managed under the Act’s requirements — data provenance records, labeling quality documentation, and evidence that data quality measures were applied
- Human oversight schematics — documentation of how human oversight is implemented in practice, including the roles involved, the authority to override, and records showing that oversight actually occurred in a sample of decisions
- Risk management records demonstrating that the risk management system described in Annex IV was operational, not merely documented
The Evidence Problem: Why Policy Documents Aren’t Enough
The most important practical insight from the inspection wave is captured in a distinction now circulating among EU AI Act compliance practitioners: auditors are not asking for documentation. They are asking for evidence.
A policy document that describes how human oversight works is documentation. A log file showing that a human reviewer accessed 847 flagged credit decisions in August 2026, with timestamps, reviewer IDs, and override records, is evidence.
A risk management plan is documentation. Records showing the plan was executed — that each identified risk was assessed, that mitigations were tested, that post-deployment monitoring is running — are evidence.
This distinction is already separating organizations that treated the August 2 deadline as a documentation exercise from those that treated it as an operational control implementation. The former produced coherent policy files. The latter have the artifacts to show inspectors.
Provider vs. Deployer: Which Obligations Apply to You?
As we covered when the August 2 deadline hit, the EU AI Act differentiates between providers and deployers, and the distinction determines your documentation obligations.
Providers (entities that developed, trained, or substantially modified the AI system and placed it on the market):
- Must prepare and maintain the complete Annex IV technical documentation file
- Must complete a conformity assessment (self-assessment for most financial AI systems)
- Must affix CE marking and register the system in the EU AI database
- Must establish a post-market monitoring system
Deployers (institutions using a third-party AI system under their own authority):
- Must implement human oversight measures as specified by the provider
- Must complete a Fundamental Rights Impact Assessment (FRIA) before deployment
- Must monitor for risks and report serious incidents to market surveillance authorities
- Must maintain logs where technically feasible
- Must ensure personnel operating the system have adequate AI literacy
Most US fintechs operating in the EU are deployers — they license credit scoring or fraud detection models from third-party vendors. But deployer status doesn’t mean minimal documentation. Your FRIA, your human oversight implementation records, and your incident log are all fair game for inspectors.
What US Fintechs With EU Exposure Need Right Now
If your organization has EU exposure — EU customers, EU partner institutions, or models that process data related to EU residents — and you haven’t yet completed the following, the inspection wave that started August 30 is now your timeline:
Confirm your coverage position. Identify every AI system that could be classified as high-risk under Annex III. Map which systems your organization built (provider) and which you license from third parties (deployer). Confirm EU nexus with legal counsel.
Assemble the Annex IV technical documentation file. If you’re a provider, this file must exist and be current. If you’re a deployer, request the technical documentation package from your AI vendor — they’re required to provide it, and it’s a direct input to your deployer audit file.
Build your evidence layer. Policies aren’t enough. You need operational logs: human oversight interaction records, data quality audit trails, post-deployment monitoring outputs. If you haven’t implemented logging that captures these artifacts, that’s the highest-priority gap.
Complete the FRIA. Every deployer of a high-risk AI system affecting EU residents is required to conduct a Fundamental Rights Impact Assessment. The assessment evaluates whether the AI system’s deployment affects fundamental rights protected under the EU Charter — including non-discrimination rights directly relevant to credit scoring.
Establish your EU point of contact. Non-EU providers and deployers may need to designate an EU representative. Confirm the requirement applies to your structure.
So What Does This Mean for Your AI Governance Program?
The September 2026 inspection wave is the EU AI Act’s proof-of-concept enforcement moment. The first organizations selected for inspection will set the evidentiary standard — what passes muster, what doesn’t, and where the gaps are.
For teams watching the first inspections unfold, the board-level AI governance metrics that examiners have been tracking in the US are now joined by a parallel EU documentation obligation that has teeth. The EU AI Act’s penalty framework — up to €15 million or 3% of global annual turnover — is not aspirational. It’s the statutory maximum that’s now actively in play.
The organizations best positioned for this inspection wave are those that treated the August 2 deadline as an operational control implementation, not a documentation exercise. If you’re not in that position yet, the gap between your current state and what inspectors are requesting is real, measurable, and closable — but the window is narrowing.
If you’re still mapping your AI use cases, running pre-deployment assessments, or building your vendor due diligence questionnaires, the AI Risk Assessment Template includes an AI use case inventory, pre-deployment scorecard, and third-party vendor questionnaire built for exactly this environment — including worked examples for credit underwriting, AML monitoring, and fraud detection.
Sources:
- EU AI Act — Article 11: Technical Documentation
- EU AI Act Compliance for High-Risk AI Systems, September 2026 — Cloud Security Alliance
- AI Regulation News September 2026: Global Update & Deadlines — Cubbbix
- EU AI Act High-Risk AI Compliance Checklist 2026 — CodeSecAI
- EU AI Act August 2026 Deadline: What Financial Services Firms Must Do — Finextra
- EU AI Act for Credit Scoring — Openlayer
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
My company is a US-only fintech with no EU customers. Does the EU AI Act apply to me?
What is Article 11 technical documentation and how is it different from a model card or risk assessment?
What's the difference between a provider and a deployer under the EU AI Act, and which one faces inspection first?
What are the penalties for failing an EU AI Act inspection on high-risk AI?
We're using a vendor's credit scoring model, not building our own. Are we still on the hook?
What does 'evidence vs. documentation' mean in the context of EU AI Act inspections?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026
AI Risk
The FTC Just Put AI Pricing on Notice. What the Personalized Pricing Statement Means for Your Fintech.
On August 19, 2026, the FTC proposed an enforcement policy on personalized pricing — using AI and consumer data to set individualized prices. The comment deadline is September 18. Here's what the financial services exception means, where the line blurs with AI, and what your compliance program needs to document.
Sep 4, 2026