As of August 2, the European Union’s AI Office has moved beyond its advisory origins and begun wielding full enforcement powers over artificial intelligence models deemed to pose “systemic risk.” Established on January 24, 2024, the office spent two and a half years preparing to coordinate the AI Act’s rollout and now operates as a genuine regulatory police force, with the ability to levy fines up to €15 million or 3% of a company’s global annual turnover (whichever is higher), demand sensitive documentation, and even access source code.
The AI Office’s remit extends far beyond punishment. It serves as the EU’s institutional voice on AI policy, representing the European Commission in forums such as the OECD, G7, G20, the Council of Europe, and ISO/IEC, as well as in an international network of national institutes that evaluate risks in cutting-edge AI models. To fulfil its mission, the office has three principal tools. Under Article 91 of the AI Act, it can require developers of the most powerful models to hand over all documentation mandated by Articles 53 and 55, including technical specifications, capability assessments, risk analyses, and any additional information it deems necessary. It can also commission independent evaluations—potentially including access to source code—and may call on external experts to assist. Finally, it can impose fines for non-compliance; merely refusing a document request or supplying incorrect, incomplete, or misleading information is itself a sanctionable offence.
The office currently employs 145 people: technology specialists, policy experts, lawyers, economists, and administrative staff, organised into six units and two advisory positions. It plans to add 38 more recruits, with 34 dedicated to regulation and compliance and a further 38 focused solely on monitoring the safety of the most advanced models—a number which, while growing, remains modest given the scale of the oversight task. Surrounding the AI Office are complementary bodies such as the AI Board, the Scientific Panel, and the Advisory Forum, which provide guidance on the broader governance of the AI Act. The Commission has also introduced a whistleblower tool enabling tech sector employees to report breaches, and a confidential compliance tool for users to alert authorities about potentially illegal behaviour.
National market surveillance authorities handle other AI systems. In France, the data protection watchdog CNIL was designated the reference authority for AI Act enforcement after an 18-month arbitration process. It is supported by around fifteen sectoral bodies: the DGCCRF for deceptive commercial practices, Arcom for audiovisual content and deepfakes, the ACPR and AMF for financial services, and the ANSM and HAS for health-related applications.