Governance structure for the EU AI Act: European AI Office, AI Board, Scientific Panel, Advisory Forum, national competent authorities, Notified Bodies. Penalty framework. Coordination mechanisms.
European AI Office
Established 2024 within Commission DG CNECT (Communications Networks, Content and Technology).
Mandate
- Oversee GPAI obligations across the Union
- Manage harmonized standards process
- Coordinate Codes of Practice
- Support implementation across Member States
- Operate the EU-wide AI database (high-risk system registration)
- Coordinate with national authorities
Powers
- Request information from GPAI providers
- Conduct model evaluations (for systemic-risk GPAI)
- Issue Codes of Practice
- Designate GPAI as systemic risk (Article 51(1)(b))
- Coordinate enforcement actions involving GPAI
Structure
- Director (Lucilla Sioli appointed 2024)
- Technical staff including ML / AI engineers, policy specialists
- Operational since late 2024; staffing ramp-up through 2025-2026
Independence
AI Office is within Commission DG CNECT. Not an independent agency. Coordination with Member States via AI Board.
AI Board (Article 65)
Composition
Representatives from each Member State (typically one representative + alternate). European Data Protection Supervisor as observer. AI Office representative.
Mandate
- Coordinate national-level implementation
- Issue opinions, recommendations
- Contribute to harmonized standards process
- Coordinate enforcement actions cross-border
- Advise Commission on uniform application
Operation
Regular meetings. Subgroups for specific topics. Operational since 2024-2025.
Scientific Panel (Article 68)
Composition
Independent experts selected by Commission based on scientific or technical AI expertise.
Mandate
- Provide technical advice to AI Office and AI Board
- Assess capabilities of GPAI models for systemic-risk designation
- Issue qualified alerts (Article 90) when GPAI poses risks
- Contribute to evaluation methodology development
Operation
Members appointed for renewable terms. Confidentiality obligations.
Advisory Forum (Article 67)
Composition
Balanced selection of stakeholders: industry, startups, SMEs, civil society, academia. Members appointed by Commission.
Mandate
- Provide stakeholder advice to AI Board and Commission
- Inform on technical and regulatory questions
- Contribute to implementation guidance
National Competent Authorities
Each Member State designates one or more national competent authorities (Article 70):
- Notifying authority — responsible for setting up and carrying out procedures for assessment, designation, notification of conformity assessment bodies (Notified Bodies). Monitoring of Notified Bodies.
- Market surveillance authority — responsible for market surveillance per Regulation (EU) 2019/1020 (Market Surveillance Regulation). Investigates AI Act violations, takes enforcement action.
Member States with federal structure (Germany, Spain) may designate multiple authorities. Centralized states (France) typically designate fewer authorities.
Coordination
National authorities cooperate with AI Office and each other. Cross-border enforcement coordination via AI Board.
Member State examples
- Germany: BNetzA (Bundesnetzagentur) designated as principal market surveillance authority; sector-specific authorities for specific areas (BaFin for financial, BfDI for personal data, etc.).
- France: CNIL designated with AI Office of CNIL leading AI Act work.
- Spain: AESIA (Agencia Española de Supervisión de Inteligencia Artificial) established as dedicated agency.
- Other Member States: varied structures.
Member State designations were due in mid-2025; some lagging but most operational by late 2025.
Notified Bodies (Article 31)
Role
Third-party conformity assessment bodies designated by Member States for specific high-risk AI categories (where third-party assessment required).
Designation
- Member State accredits or designates bodies
- Bodies must meet competence requirements
- Bodies notified to Commission and other Member States
- Listed in Notified Bodies database
Operation
For high-risk AI systems subject to third-party assessment:
- Conformity assessment per Annex VI or VII
- Issuance of conformity certificates
- Surveillance during certificate validity
Capacity
As of 2026, Notified Body capacity for AI Act is limited. Designations ongoing; expected expansion through 2026-2027. Capacity bottleneck for high-risk obligation enforcement.
Penalty framework (Article 99)
Penalty tiers
- Prohibited practices (Article 5 violations): up to €35M or 7% of global annual turnover (whichever higher).
- Other obligation violations (high-risk system requirements, transparency obligations, GPAI obligations, deployer obligations): up to €15M or 3% of global annual turnover.
- Incorrect, incomplete, misleading information supplied to authorities: up to €7.5M or 1% of global annual turnover.
SME / startup cap (Article 99(6))
For SMEs and startups, penalties are limited to the lower of:
- The fixed amount
- The percentage of global annual turnover
This provides relative protection for smaller entities; protection is real but not unlimited.
Penalty determination
Article 99(7): factors considered include:
- Nature, gravity, duration of infringement
- Whether other penalties already applied
- Size, turnover, market share of operator
- Other aggravating or mitigating factors
Member State application
Member States set the rules on penalties (Article 99). They may also apply different / additional penalties under national law.
Periodic penalty payments
Article 100: market surveillance authorities can impose periodic penalty payments to compel compliance (e.g., for failure to provide information).
Enforcement coordination
AI Office leading role
For GPAI obligations and cross-border systemic-risk cases, AI Office takes leading role.
National authority leading role
For most other enforcement (use-case-specific high-risk systems, prohibited practices, transparency obligations, deployer obligations), national authorities lead.
Cross-border coordination
When violations cross borders, coordination via:
- AI Board
- Market surveillance Cooperation under Regulation 2019/1020
- Mutual assistance procedures
Public interest interventions
Article 73(7-9): Commission can intervene in case of widespread issues.
Complaints and remedies
Right to lodge complaint (Article 85)
Natural persons can lodge complaints with market surveillance authorities for alleged AI Act violations.
Right to explanation (Article 86)
Affected persons of high-risk AI systems have right to clear and meaningful explanation of decision-making.
Reporting of violations (Article 87)
Whistleblower-style protection for reporting AI Act violations (via Directive 2019/1937 reporting framework).
Enforcement trajectory
Current state (2026-05-12)
- Prohibited practices enforced since 2 February 2025 (limited public enforcement activity visible).
- GPAI obligations applicable since 2 August 2025 (compliance activity by major providers visible).
- Governance bodies operational.
- National authorities mostly designated.
Approaching milestones
- 2 August 2026: high-risk system obligations operational. Major enforcement-capacity stress test.
- 2 August 2027: Annex I product-embedded high-risk + pre-existing GPAI compliance.
Pattern likely to mirror GDPR
- Initial guidance focus (Commission, AI Office, national authority publications).
- First enforcement actions on clearest violations.
- Cumulative penalty totals building over years.
- Major decisions setting interpretive precedents.
SRE and AI-agent fit notes
Implications for compliance work
- AI Office is the primary GPAI contact for vendor-relationship issues.
- National authorities are the primary contact for use-case-specific compliance.
- Penalty tiers create proportional risk exposure. Even small organizations face material exposure for prohibited practices.
- SME cap provides some protection but isn't unlimited.
- Complaints mechanism is a vector for surfacing issues — affected users can complain.
- Right to explanation has implications for high-risk AI system UX.
Implications for procurement
- Customers will increasingly require AI Act compliance evidence as enforcement ramps.
- Vendor-side enforcement actions become public; affect vendor reputation and procurement decisions.
- Code of Practice signature status is a public signal.
Stefan-context implementation sketch
- Track Anthropic / OpenAI / Google AI Office interactions and Code of Practice signature status as part of vendor due diligence.
- For client engagements: client may be subject to AI Act obligations; understand client's classification analysis and compliance evidence requirements.
- For potential incidents: understand the incident reporting flow (provider obligation; deployer cooperation expected).