The Loom · #4

The EU AI Board Met and Set No New Deadline — Read the Signal

The EU AI Board's September meeting made no new law. What it built instead — enforcement coordination — is the part small AI adopters should read.

Published September 25, 2026 · written and approved by RiskWoven, sources checked when published

EU AI Act calendar, August to November 2026: transparency rules enforced 2 August, AI Board met 17 September, next meeting 18 November

Thread

On 17 September 2026 the EU AI Board met under the Irish Presidency, its ninth meeting since the AI Act's enforcement phase began. The European Commission briefed members on frontier AI capabilities and recent incidents, and the Board discussed market-surveillance coordination among member states, a proposed secondment of national surveillance staff to the European Data Protection Supervisor, and infrastructure for testing frontier-model cybersecurity. Coverage published four days later concluded the meeting produced no binding rule, no new company obligation, and no revised compliance date: an enforcement signal, not a change to the Act's timetable. That timetable already has teeth. The Commission started enforcing transparency rules on 2 August 2026, requiring interactive AI systems to disclose that users are dealing with AI, and AI-generated content to carry machine-readable marks. Over 180 organisations have signed the Commission's Code of Practice supporting that rule. The Board's tenth meeting is set for 18 November, during the Apply AI Summit in Brussels.

Pattern

Nothing here targets a 20-to-500-person company outside the EU on its face, and that is exactly how it gets missed. The transparency rule already in force is not limited to European companies: it reaches any provider or deployer whose AI system interacts with people located in the EU, which now includes most companies running a support chatbot, an AI sales assistant, or an AI-drafted marketing footer on a public website. A company with customers in Germany or France and a chatbot that never says it is a bot is out of compliance today, not on some future date to plan around. The same is true of AI-generated images, video, or audio published without the required machine-readable mark. Most small and mid-size companies adopted these tools through a vendor's default settings, not a compliance review, so the gap is usually invisible until someone asks. The Board's own meeting notes point at where scrutiny goes next: market-surveillance authorities are being staffed and coordinated right now, which is the quiet phase before the visible one. A company with no compliance team has no one whose job it is to notice that a March chatbot rollout became a September obligation. That is the exposure: not a new rule, but an old rollout that quietly became regulated.

Knot

Most coverage of this meeting ran a version of "no new deadlines," which reads as no news. That framing measures the wrong thing. Deadlines are not what makes a rule enforceable; enforcement capacity is, and that is precisely what the Board spent 17 September building: coordinating market-surveillance authorities across member states and proposing to second staff to the European Data Protection Supervisor so surveillance work actually gets done. A regulation with a deadline but no inspectors is a press release. A regulation with coordinated, staffed inspectors and a deadline that already passed in August is something else. Read that way, "no new deadline" is not a pause, it is the sound of an enforcement machine being assembled quietly enough that the trade press calls it uneventful. The pattern is familiar from other regimes: GDPR's first eighteen months produced few fines and a great deal of "toothless" commentary, right up until the infrastructure caught up and the fines did too. Companies that treat a quiet enforcement period as a compliance grace period are reading the absence of headlines as an absence of exposure. The more defensible reading is the opposite: an August deadline that has already passed, combined with September's coordination work, is the setup for the first visible enforcement action, not a sign there won't be one.

Stitch

This week, check one thing: does every AI-facing tool your company runs — chatbot, AI email drafter, AI-generated image or video used in marketing — actually disclose that it is AI? Most vendor defaults do not turn this on by themselves. If you cannot answer for every tool in under five minutes, you do not have visibility, which is itself the finding. RiskWoven's free 12-question scan is built for exactly this gap: it takes stock of the AI tools already running in your company and flags which ones carry an unmet disclosure obligation, before a regulator or a customer's procurement team asks first.

Quick check

  1. Does every chatbot or AI assistant on your site tell users they're talking to AI?
  2. Is AI-generated marketing content (image, video, or audio) on your channels labeled as such?
  3. If a customer or regulator asked which AI tools your company uses today, could you list them in under five minutes?

Answer no to any of these? The free 12-question scan shows where to start.

Sources

  1. European Commission, "Commission starts enforcing AI Act rules and new transparency requirements on 2 August"
  2. quasa.io, "The EU AI Board turns to enforcement but its September meeting set no new deadline," 21 Sep 2026
  3. completeaitraining.com, "EU AI Board discusses frontier AI capabilities and cybersecurity action plan under Irish presidency"
Share on LinkedInRun the free 12-question scan
Post text to copy
The EU AI Board met on 17 September and set no new deadline. Most coverage read that as "nothing happened."

Wrong lens. The Board spent the meeting coordinating market-surveillance authorities across EU states and proposing to second staff to the European Data Protection Supervisor — building enforcement capacity, not writing new law.

Meanwhile the deadline that already matters passed quietly on 2 August: chatbots and AI assistants must disclose they're AI, and AI-generated content needs a machine-readable mark. That rule reaches any company with customers in the EU, not just EU-based ones.

Most small and mid-size companies adopted these tools through a vendor's default settings, not a compliance review — so the gap stays invisible until someone asks.

Full issue, with the compliance timeline: riskwoven.com/loom

#AIGovernance #EUAIAct #Compliance