AI Governance Institute
VoluntaryFrameworkEUUnacceptable riskHigh risk

AI Act Governance and Enforcement Framework

Issued by

European Commission

liveEffective 2026-08-02EU AI BoardUpdated October 2026 · Last verified October 1, 2026
Official document →

EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

The European Commission has published the official enforcement architecture for the EU AI Act, clarifying the division of supervisory powers that became applicable from 2 August 2026. The AI Office holds primary oversight responsibility for general-purpose AI models and for cross-border enforcement coordination. National competent authorities designated by each EU member state are responsible for supervising AI systems deployed within their territories, particularly high-risk systems. The European Data Protection Supervisor (EDPS) exercises authority over AI systems operated by EU institutions and bodies. Enforcement powers include requesting documentation, conducting audits, and imposing corrective measures. The Commission, through the AI Office, can also fine providers of general-purpose AI models directly, up to EUR 15 million or 3% of worldwide annual turnover (Article 101). Enterprises must be able to demonstrate compliance to whichever authority holds jurisdiction, requiring clear internal governance structures and documented evidence trails. Regulation (EU) 2026/1744, the AI Act Omnibus Amendment, has since deferred the substantive high-risk system obligations that national authorities enforce. Stand-alone Annex III systems now have until 2 December 2027, and Annex I product-embedded systems until 2 August 2028. The amendment also widened the AI Office's role. It now supervises AI systems built on a provider's own general-purpose model and AI systems built into very large online platforms and search engines, with stronger inspection powers. National authorities enforce the rules for other AI systems.

Key Requirements

  • •High-risk AI system obligations enforced under this framework are deferred by Regulation 2026/1744: stand-alone Annex III systems must comply by 2 December 2027, and Annex I product-embedded systems by 2 August 2028, not 2 August 2026 as originally scheduled.
  • •General-purpose AI model obligations, such as documentation and evaluations, have applied since 2 August 2025. The AI Office's power to fine providers applies from 2 August 2026.
  • •Submit to national competent authority supervision for high-risk AI systems deployed in each member state where the system is made available.
  • •Maintain audit-ready technical documentation, conformity assessments, and logs sufficient to satisfy requests from any of the three supervisory bodies.
  • •Respond to information requests and inspections from the AI Office or national authorities within timeframes specified under the AI Act enforcement procedures.
  • •Ensure that AI systems used by EU institutions comply with EDPS oversight requirements as a distinct regulatory obligation.
  • •Face penalties of up to EUR 35 million or 7% of global annual turnover for violations involving prohibited AI practices, with lower thresholds applying to other infringements.

What Your Organization Must Do

  • →Map each AI system to the authority that supervises it: AI Office, national competent authority, or the European Data Protection Supervisor.
  • →Diarise the deferred deadlines: 2 December 2027 for stand-alone Annex III high-risk systems, 2 August 2028 for product-embedded Annex I systems.
  • →Keep technical documentation, conformity assessments and logs audit ready for any of the three supervisory bodies.
  • →Build an internal process to answer information requests and inspections from the AI Office or national authorities on time.
  • →Check whether your systems sit on your own general-purpose model or inside a very large online platform, which shifts oversight to the AI Office.
  • →Brief leadership on exposure: up to EUR 35 million or 7% of global turnover for prohibited practices, with lower thresholds elsewhere.