The Loom · #4
The EU AI Board Met and Set No New Deadline — Read the Signal
The EU AI Board's September meeting made no new law. What it built instead — enforcement coordination — is the part small AI adopters should read.
Thread
On 17 September 2026 the EU AI Board met under the Irish Presidency, its ninth meeting since the AI Act's enforcement phase began. The European Commission briefed members on frontier AI capabilities and recent incidents, and the Board discussed market-surveillance coordination among member states, a proposed secondment of national surveillance staff to the European Data Protection Supervisor, and infrastructure for testing frontier-model cybersecurity. Coverage published four days later concluded the meeting produced no binding rule, no new company obligation, and no revised compliance date: an enforcement signal, not a change to the Act's timetable. That timetable already has teeth. The Commission started enforcing transparency rules on 2 August 2026, requiring interactive AI systems to disclose that users are dealing with AI, and AI-generated content to carry machine-readable marks. Over 180 organisations have signed the Commission's Code of Practice supporting that rule. The Board's tenth meeting is set for 18 November, during the Apply AI Summit in Brussels.
Pattern
Nothing here targets a 20-to-500-person company outside the EU on its face, and that is exactly how it gets missed. The transparency rule already in force is not limited to European companies: it reaches any provider or deployer whose AI system interacts with people located in the EU, which now includes most companies running a support chatbot, an AI sales assistant, or an AI-drafted marketing footer on a public website. A company with customers in Germany or France and a chatbot that never says it is a bot is out of compliance today, not on some future date to plan around. The same is true of AI-generated images, video, or audio published without the required machine-readable mark. Most small and mid-size companies adopted these tools through a vendor's default settings, not a compliance review, so the gap is usually invisible until someone asks. The Board's own meeting notes point at where scrutiny goes next: market-surveillance authorities are being staffed and coordinated right now, which is the quiet phase before the visible one. A company with no compliance team has no one whose job it is to notice that a March chatbot rollout became a September obligation. That is the exposure: not a new rule, but an old rollout that quietly became regulated.
Knot
Most coverage of this meeting ran a version of "no new deadlines," which reads as no news. That framing measures the wrong thing. Deadlines are not what makes a rule enforceable; enforcement capacity is, and that is precisely what the Board spent 17 September building: coordinating market-surveillance authorities across member states and proposing to second staff to the European Data Protection Supervisor so surveillance work actually gets done. A regulation with a deadline but no inspectors is a press release. A regulation with coordinated, staffed inspectors and a deadline that already passed in August is something else. Read that way, "no new deadline" is not a pause, it is the sound of an enforcement machine being assembled quietly enough that the trade press calls it uneventful. The pattern is familiar from other regimes: GDPR's first eighteen months produced few fines and a great deal of "toothless" commentary, right up until the infrastructure caught up and the fines did too. Companies that treat a quiet enforcement period as a compliance grace period are reading the absence of headlines as an absence of exposure. The more defensible reading is the opposite: an August deadline that has already passed, combined with September's coordination work, is the setup for the first visible enforcement action, not a sign there won't be one.
Stitch
This week, check one thing: does every AI-facing tool your company runs — chatbot, AI email drafter, AI-generated image or video used in marketing — actually disclose that it is AI? Most vendor defaults do not turn this on by themselves. If you cannot answer for every tool in under five minutes, you do not have visibility, which is itself the finding. RiskWoven's free 12-question scan is built for exactly this gap: it takes stock of the AI tools already running in your company and flags which ones carry an unmet disclosure obligation, before a regulator or a customer's procurement team asks first.
Quick check
- Does every chatbot or AI assistant on your site tell users they're talking to AI?
- Is AI-generated marketing content (image, video, or audio) on your channels labeled as such?
- If a customer or regulator asked which AI tools your company uses today, could you list them in under five minutes?
Answer no to any of these? The free 12-question scan shows where to start.
Sources
- European Commission, "Commission starts enforcing AI Act rules and new transparency requirements on 2 August"
- quasa.io, "The EU AI Board turns to enforcement but its September meeting set no new deadline," 21 Sep 2026
- completeaitraining.com, "EU AI Board discusses frontier AI capabilities and cybersecurity action plan under Irish presidency"