EU AI Act Governance

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Governance structure for the EU AI Act: European AI Office, AI Board, Scientific Panel, Advisory Forum, national competent authorities, Notified Bodies. Penalty framework. Coordination mechanisms.

European AI Office

Established 2024 within Commission DG CNECT (Communications Networks, Content and Technology).

Mandate

  • Oversee GPAI obligations across the Union
  • Manage harmonized standards process
  • Coordinate Codes of Practice
  • Support implementation across Member States
  • Operate the EU-wide AI database (high-risk system registration)
  • Coordinate with national authorities

Powers

  • Request information from GPAI providers
  • Conduct model evaluations (for systemic-risk GPAI)
  • Issue Codes of Practice
  • Designate GPAI as systemic risk (Article 51(1)(b))
  • Coordinate enforcement actions involving GPAI

Structure

  • Director (Lucilla Sioli appointed 2024)
  • Technical staff including ML / AI engineers, policy specialists
  • Operational since late 2024; staffing ramp-up through 2025-2026

Independence

AI Office is within Commission DG CNECT. Not an independent agency. Coordination with Member States via AI Board.

AI Board (Article 65)

Composition

Representatives from each Member State (typically one representative + alternate). European Data Protection Supervisor as observer. AI Office representative.

Mandate

  • Coordinate national-level implementation
  • Issue opinions, recommendations
  • Contribute to harmonized standards process
  • Coordinate enforcement actions cross-border
  • Advise Commission on uniform application

Operation

Regular meetings. Subgroups for specific topics. Operational since 2024-2025.

Scientific Panel (Article 68)

Composition

Independent experts selected by Commission based on scientific or technical AI expertise.

Mandate

  • Provide technical advice to AI Office and AI Board
  • Assess capabilities of GPAI models for systemic-risk designation
  • Issue qualified alerts (Article 90) when GPAI poses risks
  • Contribute to evaluation methodology development

Operation

Members appointed for renewable terms. Confidentiality obligations.

Advisory Forum (Article 67)

Composition

Balanced selection of stakeholders: industry, startups, SMEs, civil society, academia. Members appointed by Commission.

Mandate

  • Provide stakeholder advice to AI Board and Commission
  • Inform on technical and regulatory questions
  • Contribute to implementation guidance

National Competent Authorities

Each Member State designates one or more national competent authorities (Article 70):

  • Notifying authority — responsible for setting up and carrying out procedures for assessment, designation, notification of conformity assessment bodies (Notified Bodies). Monitoring of Notified Bodies.
  • Market surveillance authority — responsible for market surveillance per Regulation (EU) 2019/1020 (Market Surveillance Regulation). Investigates AI Act violations, takes enforcement action.

Member States with federal structure (Germany, Spain) may designate multiple authorities. Centralized states (France) typically designate fewer authorities.

Coordination

National authorities cooperate with AI Office and each other. Cross-border enforcement coordination via AI Board.

Member State examples

  • Germany: BNetzA (Bundesnetzagentur) designated as principal market surveillance authority; sector-specific authorities for specific areas (BaFin for financial, BfDI for personal data, etc.).
  • France: CNIL designated with AI Office of CNIL leading AI Act work.
  • Spain: AESIA (Agencia Española de Supervisión de Inteligencia Artificial) established as dedicated agency.
  • Other Member States: varied structures.

Member State designations were due in mid-2025; some lagging but most operational by late 2025.

Notified Bodies (Article 31)

Role

Third-party conformity assessment bodies designated by Member States for specific high-risk AI categories (where third-party assessment required).

Designation

  • Member State accredits or designates bodies
  • Bodies must meet competence requirements
  • Bodies notified to Commission and other Member States
  • Listed in Notified Bodies database

Operation

For high-risk AI systems subject to third-party assessment:

  • Conformity assessment per Annex VI or VII
  • Issuance of conformity certificates
  • Surveillance during certificate validity

Capacity

As of 2026, Notified Body capacity for AI Act is limited. Designations ongoing; expected expansion through 2026-2027. Capacity bottleneck for high-risk obligation enforcement.

Penalty framework (Article 99)

Penalty tiers

  • Prohibited practices (Article 5 violations): up to €35M or 7% of global annual turnover (whichever higher).
  • Other obligation violations (high-risk system requirements, transparency obligations, GPAI obligations, deployer obligations): up to €15M or 3% of global annual turnover.
  • Incorrect, incomplete, misleading information supplied to authorities: up to €7.5M or 1% of global annual turnover.

SME / startup cap (Article 99(6))

For SMEs and startups, penalties are limited to the lower of:

  • The fixed amount
  • The percentage of global annual turnover

This provides relative protection for smaller entities; protection is real but not unlimited.

Penalty determination

Article 99(7): factors considered include:

  • Nature, gravity, duration of infringement
  • Whether other penalties already applied
  • Size, turnover, market share of operator
  • Other aggravating or mitigating factors

Member State application

Member States set the rules on penalties (Article 99). They may also apply different / additional penalties under national law.

Periodic penalty payments

Article 100: market surveillance authorities can impose periodic penalty payments to compel compliance (e.g., for failure to provide information).

Enforcement coordination

AI Office leading role

For GPAI obligations and cross-border systemic-risk cases, AI Office takes leading role.

National authority leading role

For most other enforcement (use-case-specific high-risk systems, prohibited practices, transparency obligations, deployer obligations), national authorities lead.

Cross-border coordination

When violations cross borders, coordination via:

  • AI Board
  • Market surveillance Cooperation under Regulation 2019/1020
  • Mutual assistance procedures

Public interest interventions

Article 73(7-9): Commission can intervene in case of widespread issues.

Complaints and remedies

Right to lodge complaint (Article 85)

Natural persons can lodge complaints with market surveillance authorities for alleged AI Act violations.

Right to explanation (Article 86)

Affected persons of high-risk AI systems have right to clear and meaningful explanation of decision-making.

Reporting of violations (Article 87)

Whistleblower-style protection for reporting AI Act violations (via Directive 2019/1937 reporting framework).

Enforcement trajectory

Current state (2026-05-12)

  • Prohibited practices enforced since 2 February 2025 (limited public enforcement activity visible).
  • GPAI obligations applicable since 2 August 2025 (compliance activity by major providers visible).
  • Governance bodies operational.
  • National authorities mostly designated.

Approaching milestones

  • 2 August 2026: high-risk system obligations operational. Major enforcement-capacity stress test.
  • 2 August 2027: Annex I product-embedded high-risk + pre-existing GPAI compliance.

Pattern likely to mirror GDPR

  • Initial guidance focus (Commission, AI Office, national authority publications).
  • First enforcement actions on clearest violations.
  • Cumulative penalty totals building over years.
  • Major decisions setting interpretive precedents.

SRE and AI-agent fit notes

Implications for compliance work

  • AI Office is the primary GPAI contact for vendor-relationship issues.
  • National authorities are the primary contact for use-case-specific compliance.
  • Penalty tiers create proportional risk exposure. Even small organizations face material exposure for prohibited practices.
  • SME cap provides some protection but isn't unlimited.
  • Complaints mechanism is a vector for surfacing issues — affected users can complain.
  • Right to explanation has implications for high-risk AI system UX.

Implications for procurement

  • Customers will increasingly require AI Act compliance evidence as enforcement ramps.
  • Vendor-side enforcement actions become public; affect vendor reputation and procurement decisions.
  • Code of Practice signature status is a public signal.

Stefan-context implementation sketch

  • Track Anthropic / OpenAI / Google AI Office interactions and Code of Practice signature status as part of vendor due diligence.
  • For client engagements: client may be subject to AI Act obligations; understand client's classification analysis and compliance evidence requirements.
  • For potential incidents: understand the incident reporting flow (provider obligation; deployer cooperation expected).

See also