The September meeting shows where implementation attention is moving

The EU AI Board met on 17 September 2026 to review current AI policy implementation priorities. The Commission's published summary identifies enforcement activities, AI Act implementation, market-surveillance cooperation, governance for pre-market conformity assessment, AI literacy recommendations and support for transparency rules among the issues discussed.

The meeting note does not create new legal obligations or publish a ranked enforcement programme. It does, however, show the subjects receiving coordination attention from the Commission, Member States and the Board after enforcement powers began to apply on 2 August 2026.

For an SME, the sensible response is not to predict which authority will act first. It is to make the existing evidence base easier to retrieve, explain and test.

What is enforceable now

The Commission explains that enforcement is shared between the AI Office, national competent authorities and the European Data Protection Supervisor. Which authority is relevant depends on the system, the organisation's role and the context in which it is used.

From 2 August 2026, enforcement powers apply to provisions including prohibited practices, obligations for providers of general-purpose AI models and transparency requirements for certain AI systems. Other provisions follow the applicable timetable, including later dates for high-risk systems.

SMEs should therefore avoid treating the AI Act as a single future deadline. Record which current and future obligations may apply to each system, the basis for that view and the date it was last reviewed.

Business inference one: evidence retrieval is becoming operational

The enforcement framework gives the AI Office powers to request information and, within its remit, conduct investigations. That makes fast, accurate evidence retrieval a practical capability rather than a filing exercise.

Maintain a current AI inventory, named business and compliance owners, role assessment, intended-purpose record, supplier and model identifiers, applicable-obligation view, risk decisions, control evidence and change history. Give each record a version, owner and review date.

This is an inference from the published enforcement framework, not a claim that every SME will receive a request. The value is broader: the same pack supports customer due diligence, board oversight and incident response.

Business inference two: transparency should be tested in the real journey

The Board discussed measures supporting transparency rules that became applicable on 2 August. The Commission's Article 50 guidance covers direct AI interaction, machine-readable marking, emotion recognition and biometric categorisation notices, deepfake disclosure and certain public-interest text.

A policy or supplier statement alone cannot show that a user sees the right disclosure at the right point. Test the actual web, mobile, voice and embedded journeys used by customers and staff. Preserve screenshots, output samples, test conditions, results and remediation records.

Where a supplier controls part of the experience, document the boundary between its responsibilities and yours. Re-run the test after model, interface, integration or publishing changes.

Business inference three: prepare for coordinated market surveillance

Market-surveillance cooperation and governance around pre-market conformity assessment were explicit agenda items. SMEs supplying or deploying AI across more than one Member State should expect consistent records to matter across markets, even though national authorities retain important enforcement roles.

Use one controlled evidence index rather than separate, contradictory questionnaire folders. Localise only where the system, language, deployment context or authority requires it, and record why the local variation exists.

Suppliers should also know which upstream party can answer technical questions, how quickly evidence can be obtained and what contractual rights support access during an investigation or customer review.

A 30-day SME action plan

In week one, confirm the AI inventory and accountable owners. In week two, map currently applicable transparency and prohibited-practice controls. In week three, run one evidence-retrieval exercise and one end-to-end transparency test. In week four, close critical gaps and report unresolved actions to leadership.

Keep the output small and reviewable: a system register, obligation view, evidence index, test record, issue log and dated decision note. The aim is not to manufacture paperwork; it is to show how the organisation knows its systems, makes decisions and verifies controls.

For the next step, use our complaint-response playbook and supplier transparency acceptance test. AI Act Ready helps SMEs turn changing regulatory attention into an evidence-led operating routine.