Summary
- The EU AI Board has reviewed Commission enforcement priorities, market surveillance, and implementation of transparency requirements.
- Frontier-model incidents and cybersecurity evaluation are now part of the Board’s operational agenda.
- Regulators are also working on coordination between national authorities as AI Act supervision becomes more practical and cross-border.
European AI regulation is moving into the less visible work of enforcement, market surveillance, incident handling, and administrative coordination as the institutions responsible for the AI Act begin turning several years of legislation into an operating supervisory system.
The European Commission said the EU AI Board used its ninth meeting on 17 September to review enforcement priorities, AI Act implementation, frontier-model incidents, cybersecurity, and cooperation between member states. The meeting was chaired under the Irish Presidency of the Council, while Moldova attended for the first time as an observer.
The agenda reflects the next phase of the AI Act, in which obligations debated as legislative proposals increasingly have to work as practical controls. Transparency requirements became applicable on 2 August, while regulators now have to decide how supervision should operate when model providers, downstream products, and users span several jurisdictions.
Discussions covered market surveillance, governance around conformity assessment, recommendations supporting AI literacy, implementation of transparency measures, and the possibility of seconding national market-surveillance officials to the European Data Protection Supervisor.
Frontier models enter ordinary supervision
The Commission also briefed the Board on new frontier-AI capabilities and recent incidents, moving model behaviour directly into a forum initially associated heavily with implementation of the AI Act. Effective enforcement cannot depend solely on checking whether providers have produced the right documentation if regulators lack the technical ability to understand what increasingly capable systems can do.
That problem becomes sharper as models acquire stronger coding, cybersecurity, and autonomous-operation capabilities. European institutions are already building more direct testing capacity around frontier models, moving supervision closer to technical evaluation rather than relying entirely on provider statements.
The Board was also updated on the Commission’s cybersecurity and AI action plan, including work on evaluation infrastructure for frontier systems. Preparing Europe’s security ecosystem for models that can assist defenders while also expanding what attackers can automate connects AI regulation with institutions that have historically dealt with cybersecurity separately.
Those overlaps create practical questions of jurisdiction because the same AI deployment may sit within product-safety, data-protection, cybersecurity, sector-specific, and AI-specific rules. An incident can involve a developer in one country, a deployer in another, and affected users across several more.
National enforcement needs European coordination
The AI Act leaves important supervisory responsibilities with national authorities, although the largest providers and deployment chains operate across the single market. Market surveillance will therefore test whether regulators can share information and reach sufficiently consistent conclusions without recreating national fragmentation.
The secondment programme discussed by the Board would place officials from market-surveillance authorities inside the EDPS, creating a practical route for regulatory knowledge to circulate. Administrative arrangements of that kind rarely attract much public attention, but they can determine whether enforcement converges or becomes materially different from one member state to another.
Conformity assessment raises a related problem. Certain systems must be assessed before reaching the market, but AI products can change through software updates, model replacements, or dependence on upstream services that are themselves updated. Regulators therefore have to decide when an assessment remains valid and when a changed system requires another look.
AI literacy requirements extend the regime further into organisations deploying the technology. Governance that exists only at legal or board level is unlikely to solve an operational problem if employees use models without understanding their limitations, data risks, or the points at which human review remains necessary.
Implementation is becoming the harder test
Europe spent years debating whether the AI Act was too restrictive, too permissive, or too complicated. Enforcement will provide a more tangible measure because organisations will encounter the regime through supervisory requests, investigations, conformity processes, documentation, and decisions over what qualifies as adequate risk management.
The Board’s attention to frontier incidents also illustrates how quickly implementation is being pulled beyond the legislation’s original timetable. Model capabilities have continued to advance while obligations entered force in stages, leaving regulators to apply a fixed statutory framework to systems that can change considerably between releases.
At the same time, European governments are trying to expand domestic AI capacity through compute investment, industrial programmes, and support for regional developers. Those objectives do not always sit comfortably together: authorities want stronger oversight while policymakers also want European companies to develop and deploy AI more quickly.
The tenth AI Board meeting is expected on 18 November alongside the Apply AI Summit in Brussels. By then, the credibility of Europe’s regulatory regime will depend increasingly on whether institutions can supervise AI consistently and technically, rather than on the breadth of the legislation they have already written.












