EU AI Act moves from law to first coordinated enforcement action.
The European Commission announced a joint enforcement action with the French, Dutch, and Irish national supervisory authorities in February 2026, targeting an alleged Article 5 prohibited use case at a consumer facing platform operating across three member states. The request for information asks for evidence of prohibition classification, user consent state at each interaction, and per decision policy application. It is the first cross border coordinated action of its kind under the Act.
Two governance leads inside major EU banks told the Financial Times, off the record, that the shape of the request is what their internal AI risk teams have been preparing for. The rest of the market is beginning that work now, under a compressed clock. The Commission has signaled that further joint actions will follow through 2026.
EU digital strategy · AI Act →Regulators are not asking for architectural diagrams. They are asking for logs, per interaction, per policy, per user. That is a runtime property, not a policy document.
Our EU customers keep this record by default because the checkpoint they run on every AI interaction produces it as a byproduct. The rest of the market is doing forensics on incomplete data. A quiet reality of the next twelve months is that companies with a record will negotiate; companies without one will settle.
- use.case: Article 5 classification, updated when the policy revision changes
- consent.state: exact consent version at the moment of interaction
- policy.applied: allow, transform, or block with rule reference
- data.residency: jurisdiction the interaction was executed in
- export: RFI ready packet for Commission or national authority on one query
EU footprint on any AI capability?
Thirty minutes on the RFI shape and the record you would send back.
Book a working session →