04 · Governance & the AI Office
- EC AI Office page + AI Act enforcement framework + Regulation (EU) 2026/1744 + Commission Implementing Regulation (EU) 2026/1755
- Governance chapter became applicable: 2 August 2025
- Last verified: 2026-09-07
Governance chapter (Chapter VII) became applicable 2 August 2025. Regulation (EU) 2026/1744 defers Chapter III high-risk Sections 1–3 to 2 December 2027 for Annex III and 2 August 2028 for Annex I.
The governance structure at a glance
The AI Act creates a layered governance system with EU-level and national-level actors.
European AI Office (EU-level)
- Sits within the European Commission (DG CONNECT)
- Supervises and enforces obligations on GPAI model providers across all 27 member states
- Also enforces the rules for AI systems developed by the provider, or a provider in the same group, of the underlying GPAI model, and for AI systems integrated into designated VLOPs or VLOSEs
- Evaluates GPAI models and investigates providers within its remit
- Can issue decisions and impose fines on providers within its remit
- Coordinates with national authorities
- Publishes guidelines, codes of practice, and support tools
- Maintains the AI Act Service Desk
- Contact: CNECT-AIOFFICE@ec.europa.eu
- Page: https://digital-strategy.ec.europa.eu/en/policies/ai-office
Regulation (EU) 2026/1744 reinforces the AI Office's powers for AI systems falling under Article 75 supervision, including stronger investigation, monitoring and EU-level sandbox roles. This is narrower than centralising oversight of every GPAI-based system.
GPAI model evaluations and enforcement proceedings
Commission Implementing Regulation (EU) 2026/1755 was published on 21 July 2026 and entered into force on 10 August 2026. It sets the procedure for:
- Commission access to GPAI models for evaluation, which may include APIs, internal access, source code, model weights, hosting infrastructure and access to inspect or modify system state;
- selecting independent experts and protecting business secrets;
- opening and closing Article 101 fining proceedings;
- providers' right to be heard, including at least 21 days for written observations on preliminary findings;
- access to the case file, confidentiality and five-year limitation periods for imposing and enforcing penalties.
AI Board
- Composed of one high-level representative from each member state
- Advises and assists Commission on consistent application of the Act
- Coordinates between national authorities
- Covers the whole Act, not just GPAI
Scientific Panel of Independent Experts
- Body of independent AI scientists
- Alerts AI Office to potential systemic risks from GPAI models
- Supports model evaluations and technical assessments
- A "qualified alert" from the panel can trigger an AI Office investigation
Advisory Forum
- Consultative body
- Industry, civil society, academia
- Advises AI Board and Commission
National-level enforcement
- Each member state must designate:
- Notifying authority: assesses and designates notified bodies
- Market surveillance authority: monitors compliance of AI systems on the market
- EDPB's recommended model: existing data protection authorities (DPAs) as market surveillance authorities for AI systems impacting personal data rights
- National authorities enforce the rules for other AI systems outside the AI Office's and EDPS's remits
- Member states must have national penalty laws in place (as of 2 Aug 2025)
- The Commission maintains an evolving list of national market-surveillance single points of contact; some national designations remain pending
Penalties
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Article 5) | €35M or 7% global annual turnover |
| GPAI/high-risk AI Act violations | €15M or 3% global annual turnover |
| Providing incorrect/misleading information to authorities | €7.5M or 1% global annual turnover |
For SMEs and start-ups, the base Act caps fines at whichever is lower. Regulation (EU) 2026/1744 extends that lower-of treatment for certain fines to SMCs.
Regulatory sandboxes
- At least one national AI regulatory sandbox must be operational by 2 August 2027.
- The AI Office may establish a Union-level sandbox for AI systems covered by Article 75(1), with priority access for SMEs, start-ups and SMCs.
- Allow providers to test AI in real-world conditions under regulatory supervision
- Simplified rules for sandbox participants
Enforcement and reporting channels
- The AI Act Complaint Tool accepts complaints from natural and legal persons about AI systems supervised by the AI Office.
- The AI Act Whistleblower Tool provides a secure reporting channel for eligible people professionally connected to providers or deployers.
- The downstream-provider complaints channel lets providers of AI systems built on GPAI models report alleged provider infringements of Articles 53 to 55 under Article 89(2).
Key articles
| Topic | Article(s) |
|---|---|
| AI Office establishment and tasks | Art. 64 |
| AI Board | Art. 65 |
| Scientific Panel | Art. 68 |
| Advisory Forum | Art. 67 |
| National competent authorities | Art. 70 |
| Notifying authorities | Arts. 27–30 |
| Market surveillance | Arts. 74–78 |
| GPAI supervision and enforcement | Arts. 88–94; Implementing Regulation (EU) 2026/1755 |
| Penalties | Arts. 99–100 |
| Governance chapter application | Art. 113(b) |
| Sandboxes | Art. 57 |