Skip to main content

04 · Governance & the AI Office

Sources
note

Governance chapter (Chapter VII) became applicable 2 August 2025. Regulation (EU) 2026/1744 defers Chapter III high-risk Sections 1–3 to 2 December 2027 for Annex III and 2 August 2028 for Annex I.

The governance structure at a glance

The AI Act creates a layered governance system with EU-level and national-level actors.

European AI Office (EU-level)

  • Sits within the European Commission (DG CONNECT)
  • Supervises and enforces obligations on GPAI model providers across all 27 member states
  • Also enforces the rules for AI systems developed by the provider, or a provider in the same group, of the underlying GPAI model, and for AI systems integrated into designated VLOPs or VLOSEs
  • Evaluates GPAI models and investigates providers within its remit
  • Can issue decisions and impose fines on providers within its remit
  • Coordinates with national authorities
  • Publishes guidelines, codes of practice, and support tools
  • Maintains the AI Act Service Desk
  • Contact: CNECT-AIOFFICE@ec.europa.eu
  • Page: https://digital-strategy.ec.europa.eu/en/policies/ai-office

Regulation (EU) 2026/1744 reinforces the AI Office's powers for AI systems falling under Article 75 supervision, including stronger investigation, monitoring and EU-level sandbox roles. This is narrower than centralising oversight of every GPAI-based system.

GPAI model evaluations and enforcement proceedings

Commission Implementing Regulation (EU) 2026/1755 was published on 21 July 2026 and entered into force on 10 August 2026. It sets the procedure for:

  • Commission access to GPAI models for evaluation, which may include APIs, internal access, source code, model weights, hosting infrastructure and access to inspect or modify system state;
  • selecting independent experts and protecting business secrets;
  • opening and closing Article 101 fining proceedings;
  • providers' right to be heard, including at least 21 days for written observations on preliminary findings;
  • access to the case file, confidentiality and five-year limitation periods for imposing and enforcing penalties.

AI Board

  • Composed of one high-level representative from each member state
  • Advises and assists Commission on consistent application of the Act
  • Coordinates between national authorities
  • Covers the whole Act, not just GPAI

Scientific Panel of Independent Experts

  • Body of independent AI scientists
  • Alerts AI Office to potential systemic risks from GPAI models
  • Supports model evaluations and technical assessments
  • A "qualified alert" from the panel can trigger an AI Office investigation

Advisory Forum

  • Consultative body
  • Industry, civil society, academia
  • Advises AI Board and Commission

National-level enforcement

  • Each member state must designate:
    • Notifying authority: assesses and designates notified bodies
    • Market surveillance authority: monitors compliance of AI systems on the market
  • EDPB's recommended model: existing data protection authorities (DPAs) as market surveillance authorities for AI systems impacting personal data rights
  • National authorities enforce the rules for other AI systems outside the AI Office's and EDPS's remits
  • Member states must have national penalty laws in place (as of 2 Aug 2025)
  • The Commission maintains an evolving list of national market-surveillance single points of contact; some national designations remain pending

Penalties

ViolationMaximum fine
Prohibited practices (Article 5)€35M or 7% global annual turnover
GPAI/high-risk AI Act violations€15M or 3% global annual turnover
Providing incorrect/misleading information to authorities€7.5M or 1% global annual turnover

For SMEs and start-ups, the base Act caps fines at whichever is lower. Regulation (EU) 2026/1744 extends that lower-of treatment for certain fines to SMCs.

Regulatory sandboxes

  • At least one national AI regulatory sandbox must be operational by 2 August 2027.
  • The AI Office may establish a Union-level sandbox for AI systems covered by Article 75(1), with priority access for SMEs, start-ups and SMCs.
  • Allow providers to test AI in real-world conditions under regulatory supervision
  • Simplified rules for sandbox participants

Enforcement and reporting channels

  • The AI Act Complaint Tool accepts complaints from natural and legal persons about AI systems supervised by the AI Office.
  • The AI Act Whistleblower Tool provides a secure reporting channel for eligible people professionally connected to providers or deployers.
  • The downstream-provider complaints channel lets providers of AI systems built on GPAI models report alleged provider infringements of Articles 53 to 55 under Article 89(2).

Key articles

TopicArticle(s)
AI Office establishment and tasksArt. 64
AI BoardArt. 65
Scientific PanelArt. 68
Advisory ForumArt. 67
National competent authoritiesArt. 70
Notifying authoritiesArts. 27–30
Market surveillanceArts. 74–78
GPAI supervision and enforcementArts. 88–94; Implementing Regulation (EU) 2026/1755
PenaltiesArts. 99–100
Governance chapter applicationArt. 113(b)
SandboxesArt. 57