Brussels Just Sent Its First Round of AI Audit Letters — Here’s Who Got One

AI customer support

Never lose a customer to a missed message

An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.

Try it free →replio.live

The European Commission’s AI Office has opened its first wave of formal compliance checks under the bloc’s AI Act. Sending information requests to more than 30 AI model providers. These EU AI Act compliance audits mark the first concrete use of the law’s investigative powers since high-risk obligations became applicable in August.

Compliance documents reviewed during EU AI Act compliance audits

How the EU AI Act compliance audits are structured

The European AI Office in Brussels is working alongside 24 national market surveillance authorities on the first scheduled inspection wave. France’s CNIL, Germany’s BfDI and Spain’s AESIA are focusing their initial requests on three specific sectors. Automated resume screening tools used in human resources, algorithmic credit assessment systems in retail banking. And aI triage tools deployed in private healthcare clinics. Those three sectors were chosen because they combine high-risk classification under the Act with large numbers of affected consumers.

Regulators are examining whether providers maintained the technical documentation required under Article 11 and Annex IV of the Act. That includes version-controlled model weights, pre-processing scripts and detailed descriptions of human-override mechanisms built into each system.

Which AI systems fall under scrutiny

The scope of the audits covers systems deployed after 2 August 2026. The date high-risk obligations under the Act became fully applicable. Any model released or meaningfully updated since that date in one of the three targeted sectors is now subject to inspection. Providers outside those three sectors are not exempt long-term. Regulators have signaled this is the first of several planned waves rather than a one-time exercise.

Legal advisers working with AI vendors say the sector selection was deliberate. Resume screening, credit scoring and medical triage all involve automated decisions that directly affect individual consumers’ access to jobs. Loans and healthcare, making them the clearest test cases for whether the Act’s human-oversight requirements function in practice rather than only on paper. A weak response from providers in these three sectors would likely accelerate scrutiny of AI systems in other consumer-facing industries sooner than originally planned.

How this differs from August’s transparency rules

This audit wave is distinct from the transparency requirements that took effect in late August. This focused on disclosure obligations for general-purpose AI models regardless of sector. The current compliance checks go further, testing whether companies can actually produce the technical documentation the law requires. Not just whether they have published the right disclosures. Companies that met the August transparency deadline are not automatically in the clear for this new documentation-focused review.

That distinction matters for compliance planning. A company can publish a fully compliant transparency notice while still lacking the underlying version-controlled documentation regulators are now requesting. That is because the two requirements test different things. What a company tells the public versus what a company can actually prove internally. Companies that treated the August deadline as the finish line for EU AI Act compliance are now discovering it was closer to a starting point.

Compliance consultants working with mid-size AI vendors report a scramble in the days since the requests went out. As legal and engineering teams try to reconstruct documentation for models that were built and shipped quickly during the competitive rush of the past two years. For companies that treated documentation as an afterthought while racing to deploy. The audit letters have turned into an unplanned. Resource-intensive project with a regulator-set deadline rather than an internal one.

Smaller AI startups face a particular bind. Unlike the largest labs. Many lack dedicated compliance staff and had assumed enforcement would focus first on the biggest. Most visible model providers. The decision to open initial audits within three sector-specific use cases rather than by company size caught some smaller vendors in HR-tech and health-tech off guard. That is because a startup with a single flagship product in one of these three sectors now faces the same documentation demands as a much larger competitor.

Simple to send.
Safe to verify.

OTPs over WhatsApp, one API call away

Try it free →replio.live

What happens next for audited companies

Companies that receive information requests typically have a defined window to respond with documentation before regulators decide whether to escalate to a formal investigation. The EU AI Act allows for significant fines for non-compliance, scaled to global revenue for the largest providers. Given that this is the first wave of a stated multi-wave process. How these initial 30-plus companies respond is likely to shape enforcement patterns for every subsequent round. That includes in sectors beyond the three targeted so far.

Frequently asked questions

Who is conducting the EU AI Act compliance audits?
The European Commission’s AI Office in Brussels, working with 24 national market surveillance authorities including France’s CNIL, Germany’s BfDI and Spain’s AESIA.

Which sectors are being audited first?
Automated resume screening in HR, algorithmic credit assessment in retail banking, and AI triage tools in private healthcare clinics.

What documentation are regulators requesting?
Technical files required under Article 11 and Annex IV, including version-controlled model weights, pre-processing scripts and descriptions of human-override mechanisms.

Which AI systems are covered?
Systems deployed after 2 August 2026, when high-risk obligations under the EU AI Act became fully applicable.

Is this different from the August transparency rules?
Yes. The August rules covered disclosure obligations for general-purpose models, while this audit wave tests whether companies can produce required technical documentation.

Related coverage

Sources

WhatsApp OTP API

Verification your users actually receive.

Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

Try it free →replio.live

Author: Francisca Samuel

Francisca Samuel is an editor at Tamara News, where she covers immigration, travel, business and technology news for readers across Africa and the Gulf.