The enforcement of the AI Act is shared between the European Commission’s AI Office, the European Data Protection Supervisor, and national competent authorities designated by the Member States.
As Artificial Intelligence (AI) grows increasingly capable and integrated into everyday life, enforcement of the AI Act helps ensure that AI is developed, deployed, and used safely, giving people and businesses across the EU greater confidence in this technology.
Which authorities are responsible for enforcement? #
The AI Office enforces the rules for:
- Providers of general-purpose AI (GPAI) models, including the most advanced models which may pose systemic risks (GPAI models can perform many kinds of tasks and can be integrated into different AI systems)
- AI systems developed by the same provider – or a provider within the same business group – of the underlying GPAI model
- AI systems integrated into very large online platforms (VLOPS) or very large online search engines (VLOSES) designated under theDigital Services Act (DSA)
The [national competent authorities](https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act) enforce the rules for other AI systems.
The [European Data Protection Supervisor (EDPS)](https://www.edps.europa.eu/artificial-intelligence/artificial-intelligence-act_en) enforces the rules for AI systems used by EU institutions.
| The text below provides an overview of the enforcement tools and timeline. It does not replace or affect the actual provisions of the AI Act. It was prepared by the Commission services for information purposes only and does not bind the Commission in any way. |
AI Office's enforcement powers #
Under the AI Act, the AI Office has both investigative and sanctioning powers.
Investigative powers
In the context of both GPAI models and AI systems, the AI Office can send requests for information (RFIs) to verify providers’ compliance with the AI Act. RFIs can be issued as simple RFIs by the AI Office or, more formally, by decision of the Commission. For simple RFIs, fines can be imposed if a provider’s reply is incorrect or misleading. For RFIs issued by decision, fines can also be imposed if the provider fails to reply or replies incompletely.
In the context of GPAI models, the AI Office can:
- Perform model evaluations andissue requests for access (RFAs): The AI Office – or independent experts appointed by it – can require providers to grant access to their models in order to conduct evaluations.
- Request providers to take measures , including, if necessary,restrict the public availability of a model .
In the context of AI systems, the AI office can conduct interviews of any person who might have information related to an investigation (and who consents to be interviewed), as well as conduct inspections of providers premises.
Sanctioning powers
If the AI Office establishes an intentional or negligent breach of the AI Act, the Commission may adopt a decision imposing penalties on the provider of the relevant AI system or GPAI model. The amount of the penalty will be determined by the nature, gravity, and duration of the infringement. Infringements involving prohibited AI practices are subject to the highest penalties, of up to €35 million or 7% of the offender's total worldwide annual turnover, whichever is higher. Other breaches, including of the obligations for GPAI models, may result in fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Failure to comply with a RFI, or providing incorrect, incomplete, or misleading information, may lead to fines. The same maximum penalties referred above apply for GPAI models. For AI systems, fines can reach up to €7.5 million or 1% of worldwide annual turnover, whichever is higher.
Monitoring tools #
The AI Office has launched several tools for individuals and businesses to support its enforcement and monitoring actions:
- The AI Act Complaint Tool allows natural and legal persons to submit a complaint concerning alleged infringements of the AI Act by providers of AI systems supervised by the AI Office.
- The AI Act Whistleblower Tool where individuals who are connected to providers of AI systems or GPAI models in a professional capacity may securely report violations of the AI Act.
- The complaints channel for downstream providers using general-purpose AI models allows providers of an AI system containing an integrated GPAI model from another provider to submit a complaint related toArticles 53 to 55 of the AI Act .
AI Act's enforcement timeline #
The AI Act provisions apply progressively. The enforcement powers of the AI Office and the national competent authorities of the Member States apply from 2 August 2026, when certain provisions of the AI Act become enforceable. In particular:
- Prohibited AI practices that are deemedunacceptable due to their potential risks to European values and fundamental rights: The AI Act bans AI systems that can, among others, manipulate people, exploit their vulnerabilities, unfairly score them in ways that threaten their rights, or perform individual predictive policing based solely on profiling.
- Obligations for providers GPAI models : These obligations includerules on transparency of GPAI models for downstream providers of AI systems and respect for copyright. They also includerules on security and safety for themost advanced GPAI models , which protect users against risks of large-scale harm (such as risks from chemical, biological, radiological, and nuclear incidents, loss of control,cyber offense , harmful manipulation and other systemic risks – including fundamental rights). TheGPAI Code of Practice operationalises these obligations.
- Transparency requirements for certain AI systems: For instance, chatbots shall inform people that they are interacting with AI (not an human), deepfakes shall be labelled, machine-readable marks shall be embedded in synthetic content. TheCode of Practice on transparency of AI-generated content operationalises these obligations.
The enforcement powers for other provisions of the AI Act will start to apply only when those provisions become applicable.
- The prohibitions related to thegeneration or manipulation of non-consensual intimate material andchild sexual abuse material (CSAM) apply from 2 December 2026 .
- The rules for high-risk AI systems listed inAnnex III to the AI Act apply from 2 December 2027, while the rules for high-risk AI systems embedded into regulated products apply from 2 August 2028.
Related Content #
Big Picture
Dig deeper
The AI Act's governance architecture is an essential pillar of its enforcement.
Last update
24 August 2026