European Union

The EU AI Office: What It Does and Why It Matters to You

The EU AI Office is the body actually running enforcement, guidance, and Code of Practice oversight for the AI Act — here's what it does, who it can act against, and why it's not just another EU acronym to skim past.

Operational since June 2024; GPAI enforcement powers live since Aug 2026Effective January 24, 2024
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash

A lot of compliance teams treat "the AI Office" as shorthand for "whoever polices the EU AI Act" — the general-purpose EU AI cop, in the same category as a data protection authority. That's the wrong mental model, and it matters because it can lead a team to either overestimate their exposure to an office that has no jurisdiction over them, or underestimate it because they assumed some other regulator was watching. The AI Office's direct enforcement power is narrow and specific: it's the sole EU-level authority over providers of general-purpose AI models, full stop. Everything else in the Act — prohibited practices, high-risk system obligations, the rules most companies actually spend their compliance budget on — is enforced by national authorities in each member state, not by the AI Office.

Getting this distinction right up front changes how you read everything else about EU AI Act enforcement: who might actually contact you, what they can ask for, and what happens if you ignore them.

Where the AI Office sits and how it got there

The AI Office isn't a new independent EU agency, and it wasn't created by the AI Act's text itself. The European Commission stood it up ahead of time, by Commission Decision C(2024) 390 of January 24, 2024 — about seven months before the AI Act entered into force in August 2024. It sits inside DG CONNECT, the Commission's Directorate-General for Communications Networks, Content and Technology, and its internal units became operational in mid-2024.

That structural detail is easy to skip past, but it explains the Office's character: it isn't a court, a data-protection-style independent authority, or a standalone regulator with its own founding statute. It's a Commission body, exercising Commission powers, built specifically to handle the parts of AI Act enforcement that make more sense centralized at EU level than fragmented across 27 national regulators.

What it actually has power to do: GPAI supervision and enforcement

The reason centralization made sense for one category and not others comes down to how general-purpose AI models actually get deployed. A single foundation model gets embedded into products across every member state simultaneously — which is exactly the kind of enforcement problem that doesn't fit a national-by-national structure. Twenty-seven separate national authorities independently investigating the same GPAI provider would be redundant at best and produce conflicting findings at worst. So the AI Act (Article 64) makes the AI Office the sole EU-level authority for supervising general-purpose AI model providers, and gives it real teeth to go with that scope: it can request technical documentation, run or require model evaluations, investigate suspected infringements — including in response to alerts from the Scientific Panel — require corrective and risk-mitigation measures, and, ultimately, issue fines.

Those fines aren't symbolic. Under Article 101, the Commission — acting through the AI Office — can impose penalties on GPAI model providers of up to €15 million or 3% of global annual turnover, whichever is higher. Those enforcement powers became legally applicable on August 2, 2026, a year after the underlying GPAI obligations themselves took effect, giving providers an adjustment period before the fining power actually switched on.

Picture a hypothetical company, Meridian AI, that trains and releases a foundation model crossing the compute threshold the Act uses to presume "high-impact capabilities" — the trigger for systemic-risk classification. After that classification, Meridian AI has a two-week window to notify the Commission. If the AI Office later has reason to question whether Meridian's adversarial testing and incident-reporting practices actually meet the Article 55 systemic-risk obligations, it's the AI Office — not a national regulator in whichever country Meridian happens to be headquartered — that requests the technical documentation, and the AI Office that would ultimately assess a fine if the shortfall is real. That's the practical shape of what "sole EU-level authority" means: one point of contact, one set of enforcement powers, regardless of how many member states the model's outputs reach. For the underlying obligations being enforced here, see our breakdown of the Article 51-56 GPAI obligations track.

What it doesn't enforce: high-risk systems stay with national authorities

Here's the boundary that resolves the opening misconception. Enforcement of Article 5's prohibited practices and of high-risk system obligations under Article 6 doesn't run through the AI Office at all. Each member state has to designate its own national competent authorities — at minimum one market surveillance authority and one notifying authority — and it's those national bodies that inspect, investigate, and levy fines for violations in that category, using the same Article 99 tiered fine structure (up to €35 million or 7% of turnover for prohibited practices; up to €15 million or 3% for most other high-risk obligations; up to €7.5 million or 1% for supplying misleading information to authorities).

The AI Office's role toward that much larger population of companies is coordination and guidance, not direct enforcement: it publishes guidelines, templates, and — as with the GPAI Code of Practice, which spells out exactly what a signatory commits to in exchange for a presumption of conformity — codes of practice that shape how obligations get interpreted consistently across the EU. If your company builds or deploys a high-risk HR screening tool but doesn't provide a general-purpose AI model of its own, the AI Office isn't the body that's going to show up with a documentation request. Your national market surveillance authority is.

The AI Board, the Advisory Forum, and the Scientific Panel — how they're different from the Office

Part of why "the AI Office" gets used as a catch-all is that the AI Act actually stood up four related bodies around the same time, and they get conflated in casual conversation. They're not interchangeable, and only one of them can fine anyone.

The European Artificial Intelligence Board, established under Articles 65 and 66, is a coordination body with one representative from each EU member state, each appointed for a three-year term, with one member serving as chair. Its job is helping member states apply the Act consistently — issuing recommendations, sharing best practices, and advising the Commission on emerging issues. The AI Office itself only sits in on Board proceedings as a non-voting observer, alongside the European Data Protection Supervisor.

The Advisory Forum is a much larger, general advisory body — roughly 174 members drawn from industry, civil society, and academia, including SMEs and startups, selected from well over 700 applications. It advises both the Commission and the Board on implementation questions. It has no enforcement role of any kind.

The Scientific Panel of independent experts is the technical body specifically tied to GPAI enforcement: up to 60 independent experts, appointed for renewable two-year terms, chosen with attention to gender balance and geographic representation. It advises the AI Office and national authorities on systemic-risk classification, model evaluation methodology, and cross-border market surveillance issues — feeding technical judgment into the AI Office's enforcement decisions without making those decisions itself.

Of the four, the AI Office is the only one that can open an investigation and impose a fine. The other three exist to inform, coordinate, and advise around it.

What this means for your compliance program

If your organization provides a general-purpose AI model — including through fine-tuning that produces a materially new model, not just an off-the-shelf integration — the AI Office is your direct regulator for that activity. Track its published guidelines and Code of Practice signatory status the way you'd track guidance from any primary regulator, because it's the body that can request your documentation and the body that decides whether a fine is warranted.

If your organization deploys or builds high-risk AI systems without providing a general-purpose model of your own, your operative point of contact is your national market surveillance authority, not the AI Office. The Office's output — guidelines, templates, codes of practice — is still worth reading, because it shapes how your national authority is likely to interpret the same obligations. But it's reference material for a conversation your national regulator is running, not a body that's going to contact you directly. Getting that distinction right is the difference between watching the right regulator and watching the wrong one.

Frequently asked questions

Is the EU AI Office a new independent regulator, like a data protection authority?
No. It's a structure inside the European Commission itself, sitting within the Directorate-General for Communications Networks, Content and Technology (DG CONNECT), established by Commission Decision C(2024) 390 of January 24, 2024. It exercises Commission powers rather than standing apart from the Commission the way an independent national regulator — a data protection authority, for instance — would.
Can the AI Office fine my company directly?
Only if your company is a provider of a general-purpose AI model. For that category, the AI Office — acting on the Commission's behalf — can impose fines of up to €15 million or 3% of global annual turnover, whichever is higher, under Article 101. Those enforcement powers became applicable on August 2, 2026. For high-risk system obligations or prohibited-practice violations under Article 5, fining authority sits with your national market surveillance authority, not the AI Office.
What's the difference between the AI Office and the European AI Board?
The AI Office is a Commission body with direct GPAI enforcement power. The AI Board, covered in Articles 65 and 66, is a coordination body made up of one representative from each EU member state, focused on consistent application of the AI Act across the Union — it advises the Commission, shares best practices, and issues recommendations, but it doesn't fine anyone. The AI Office itself only participates in Board meetings as a non-voting observer.
Does the AI Office have any role if my company only builds high-risk AI systems, not general-purpose models?
Indirectly, yes. The AI Office issues guidelines, templates, and codes of practice that shape how high-risk obligations get interpreted across the EU. But direct supervision and enforcement of high-risk-system obligations — inspections, investigations, corrective orders — happens through your national market surveillance authority, not the AI Office.
What is the Scientific Panel and does it have enforcement power?
The Scientific Panel is a group of up to 60 independent technical experts, appointed for renewable two-year terms, that advises the AI Office and national authorities on systemic-risk classification and model evaluation methodology for general-purpose AI models. It doesn't itself impose fines or open investigations — it's a technical advisory body that feeds into the AI Office's enforcement decisions, not a decision-maker in its own right.

Sources & references

  1. Official source
  2. Regulation (EU) 2024/1689, Articles 64-66 and 101 (full text, EUR-Lex)
  3. European Commission — AI Office
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Engineers and compliance staff reviewing technical documentation for a general-purpose AI model
Photo: selcuk sarikoz via Unsplash
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Governome Editorial Team · 9 min read
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Compliance team reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Governome Editorial Team · 7 min read
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
Governome Editorial Team · 2 min read
European Union policy officials reviewing a phased regulatory implementation schedule
Photo: Zoshua Colah via Unsplash
The EU AI Act's original phased schedule got rewritten mid-2026: the Digital Omnibus on AI pushed the high-risk-system deadline from August 2026 to December 2027, and the product-embedded high-risk deadline from August 2027 to August 2028. Article 5 prohibited practices, GPAI obligations, and the governance framework weren't touched. Here's what's actually in force right now, what moved, what didn't, and why.
Governome Editorial Team · 8 min read
Legal and compliance staff reviewing the commitments in the EU's GPAI Code of Practice
Photo: Anastassia Anufrieva via Unsplash
The EU AI Act's General-Purpose AI Code of Practice gets covered as a headline — 'OpenAI and Anthropic signed a pledge' — when it's actually three chapters of specific, auditable commitments tied to Article 53 and 55 obligations. Here's what a signatory agrees to do, chapter by chapter, and what happens to a provider that skips it or signs only part.
Governome Editorial Team · 7 min read