Decoding the world of cybersecurity

EU details AI Act enforcement powers

The European Commission has detailed how AI Act investigations, model evaluations, inspections and fines will work as key enforcement provisions take effect across the EU.

EU details AI Act enforcement powers
Summary
  • The AI Office can request information, evaluate general-purpose AI models and, in some cases, require restrictions on model availability.
  • Enforcement powers applying from 2 August include security and safety obligations for advanced general-purpose AI models.
  • The most serious AI Act breaches can attract penalties of up to €35 million or 7% of worldwide annual turnover.

The European Union’s AI Act has moved from compliance planning into active supervision, with the European Commission setting out the investigative and sanctioning powers available to authorities as key parts of the legislation begin to bite.

The European Commission published an updated enforcement framework on 24 August explaining how responsibilities are divided between its AI Office, national competent authorities and the European Data Protection Supervisor.

The AI Office has direct enforcement responsibility for providers of general-purpose AI models, including the most advanced models that can create systemic risks. It also oversees certain AI systems supplied by the same provider or business group as the underlying general-purpose model, as well as systems integrated into very large online platforms and search engines designated under the Digital Services Act.

Its investigative tools extend beyond requests for paperwork. The office can issue requests for information, conduct or commission model evaluations and require providers to grant access to models. It can also ask providers to take measures in response to problems and, where necessary, restrict public availability of a model.

For AI systems within its remit, the office can interview people who may hold relevant information, subject to consent, and conduct inspections of providers’ premises. National authorities retain enforcement responsibility for other AI systems, while the European Data Protection Supervisor covers AI used by EU institutions.

The initial enforcement phase began on 2 August, when the AI Office and national authorities gained powers over provisions already in force. The 24 August framework now sets out how those powers can be exercised in practice.

Those provisions include obligations on providers of general-purpose AI models and security and safety requirements for the most advanced models where systemic risks could include cyber offence, loss of control, harmful manipulation or chemical, biological, radiological and nuclear harms.

That brings cybersecurity into the enforcement architecture as more than a general governance principle. Providers of models judged capable of systemic harm face requirements around identifying, assessing and mitigating serious risks, while regulators have powers to inspect evidence, evaluate models and seek corrective measures.

Financial exposure is substantial. Breaches involving prohibited AI practices can attract penalties of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Other violations, including obligations applying to general-purpose models, can lead to fines of up to €15 million or 3% of global annual turnover. Separate penalties can apply where providers fail to respond properly to formal information requests.

The Commission has also established complaint and whistleblowing mechanisms. Individuals and organisations can submit complaints about alleged breaches involving providers supervised by the AI Office, while people professionally connected to AI providers can report suspected violations through a dedicated whistleblower tool. A separate channel allows downstream providers to raise issues involving general-purpose models integrated into their systems.

The division of responsibility means companies deploying AI across Europe will not encounter a single regulator for every use case. Enforcement will depend on the type of model or system, who provides it and where it is used. That increases the importance of knowing which organisation in an AI supply chain carries each legal obligation, particularly where a general-purpose model is embedded inside a separately supplied enterprise service.

The Commission’s framework also makes clear that the AI Act remains on a phased timetable. Some provisions are already enforceable, while rules for many high-risk systems will apply later. Organisations may therefore be operating under a mixture of current duties and future requirements depending on the technology involved.

The practical shift is that the EU now has authorities able to demand information, inspect providers, evaluate models and impose sanctions. The AI Act is no longer solely a programme of future compliance dates; parts of its supervisory machinery are already operating.

×