Madrid, 30 September 2026. The EU AI Act has moved from preparation to active enforcement. Since 2 August 2026, the European Commission can request information, require corrective measures and, where appropriate, impose sanctions. The European AI Office already has more than 150 staff and expects to grow beyond 200, with particular reinforcement of enforcement teams, technology specialists and legal profiles. Its stated objective is not to fine companies, but to ensure that models used in the EU are safe.
Oversight is becoming technical and lifecycle-based. For general-purpose AI models with systemic risk, the Office can examine how the model is developed, evaluated and how risks are mitigated across its full lifecycle when it is intended for the European market. The Commission also wants providers to report relevant incidents; serious incidents are subject to a specific reporting obligation. Inventories, traceability, risk assessment, monitoring and evidence are therefore no longer documents “for later”: they are what an organisation needs when real supervision begins.
The General-Purpose AI Code of Practice is becoming a practical reference point. Although voluntary, most providers are following it and the AI Office acknowledges that it is operating almost like a standard for demonstrating compliance in practice. External evaluators, the scientific panel, academia, industry and civil society will also support oversight, as the EU seeks to expand independent AI safety evaluation capabilities.
EU AI Act + ISO/IEC 42001: legal obligation and management system are complementary. The EU AI Act is mandatory when applicable; ISO/IEC 42001 is voluntary, but it provides a useful structure for translating legal duties into governance, accountability, risk management, controls, audit and continual improvement. The key message is straightforward: the EU is no longer only publishing rules; it is building the capacity to verify technically whether they are being followed.
| Internet Security Auditors | Prepare for real supervision EU AI Act + ISO/IEC 42001 GAP Assessment · Action Plan · Implementation · Internal Audit · Technical Audit of AI Ecosystems. Compliance is no longer only about having policies: it is about proving, with evidence, that risks are under control. |
Internet Security Auditors can support your organisation through an EU AI Act + ISO/IEC 42001 GAP Assessment, prioritised Action Plan, implementation support, internal audit and technical audit of the AI ecosystem. The objective is to enter a real supervisory environment with sufficient evidence to demonstrate that risks are governed and controls are effective.

Infographic produced by Internet Security Auditors based on the European Commission’s current AI Act implementation and enforcement timeline, the interview
with Lucilla Sioli on enforcement of the Regulation, and ISO/IEC 42001:2023.
References
📝The EU AI Act Conversations — “How Does the EU AI Office Enforce the AI Act?” (Lucilla Sioli, 29/09/2026).
🔗European Commission — AI Act regulatory framework, implementation timeline and enforcement.
🔗European Commission — “Commission starts enforcing AI Act rules and new transparency requirements on 2 August” (31/07/2026).
🔗European Commission — General-Purpose AI Code of Practice.
🔗ISO — ISO/IEC 42001:2023, Artificial intelligence management systems.
🔗Internet Security Auditors — AI Usage Compliance Assessment and Support.
🔗Internet Security Auditors — ISO/IEC 42001 AIMS Implementation.