Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →AI Act Governance and Enforcement Framework
Issued by
European Commission
This framework defines how the EU AI Act is supervised and enforced across member states and at the Union level. Enforcement responsibility is distributed among the AI Office, the European Data Protection Supervisor, and national competent authorities. Enterprises deploying or developing AI systems within the EU must understand which authority has jurisdiction over their systems and ensure they are audit-ready accordingly.
Applies To
Overview
The European Commission has published the official enforcement architecture for the EU AI Act, clarifying the division of supervisory powers that became applicable from 2 August 2026. The AI Office holds primary oversight responsibility for general-purpose AI models and for cross-border enforcement coordination. National competent authorities designated by each EU member state are responsible for supervising AI systems deployed within their territories, particularly high-risk systems. The European Data Protection Supervisor exercises authority over AI systems operated by EU institutions and bodies. Enforcement powers include the ability to request documentation, conduct audits, impose corrective measures, and recommend financial penalties aligned with those set out in the AI Act itself. Enterprises must be able to demonstrate compliance to whichever authority holds jurisdiction, requiring clear internal governance structures and documented evidence trails.
Key Requirements
- •Comply with AI Office oversight for general-purpose AI models (GPAIMs), including documentation and evaluation obligations, from 2 August 2026.
- •Submit to national competent authority supervision for high-risk AI systems deployed in each member state where the system is made available.
- •Maintain audit-ready technical documentation, conformity assessments, and logs sufficient to satisfy requests from any of the three supervisory bodies.
- •Respond to information requests and inspections from the AI Office or national authorities within timeframes specified under the AI Act enforcement procedures.
- •Ensure that AI systems used by EU institutions comply with EDPS oversight requirements as a distinct regulatory obligation.
- •Face penalties of up to EUR 35 million or 7% of global annual turnover for violations involving prohibited AI practices, with lower thresholds applying to other infringements.
What Your Organization Must Do
- →Map every AI system in use or under development to the correct supervisory authority (AI Office, EDPS, or national competent authority) based on system type, deployment context, and geography.
- →Assign named internal owners to each regulatory reporting line so that requests from any supervisory body are routed and responded to without delay.
- →Audit existing technical documentation and conformity assessment records against the evidentiary standards required for AI Office and national authority inspections.
- →Establish a model risk management register that tracks risk tier classifications, audit history, and any remediation actions taken, updated on a continuous basis.
- →Update internal escalation protocols to reflect the tripartite enforcement structure, ensuring legal, compliance, and technical teams understand which body has authority over each system category.
- →Review and revise vendor and partner contracts to require that third-party AI providers supply documentation sufficient to satisfy supervisory information requests from any relevant authority.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Which authority supervises general-purpose AI models under the EU AI Act enforcement framework?
- The AI Office holds primary oversight responsibility for general-purpose AI models, including documentation and evaluation obligations. National competent authorities handle high-risk AI systems deployed within their respective member states. Knowing this distinction is critical before mapping your compliance reporting lines.
- When does the EUAIAEF enforcement architecture become applicable?
- The supervisory powers defined under this framework became applicable from 2 August 2026. Enterprises deploying or developing AI systems in the EU should treat that date as the hard deadline for audit readiness across all three supervisory bodies.
- What penalties apply under the EU AI Act for prohibited AI practice violations?
- Violations involving prohibited AI practices can result in fines of up to EUR 35 million or 7% of global annual turnover, whichever is higher. Lower penalty thresholds apply to other categories of infringement, such as non-compliance with obligations for high-risk systems.
- Does the EDPS have enforcement authority over private companies using AI under this framework?
- No. The European Data Protection Supervisor exercises authority specifically over AI systems operated by EU institutions and bodies, not private sector enterprises. Private companies deploying high-risk AI systems answer to national competent authorities in each member state where the system is available.
- How should multinational companies structure compliance when operating AI systems across multiple EU member states?
- Each member state designates its own national competent authority, so a system deployed in multiple jurisdictions may face parallel supervisory relationships. Companies should map each deployment to its relevant national authority, assign internal owners per reporting line, and maintain documentation sufficient to satisfy any of those bodies independently.
- What documentation must enterprises maintain to satisfy AI Office inspection requests?
- Enterprises must keep audit-ready technical documentation, conformity assessments, and system logs that meet the evidentiary standards set out in the AI Act enforcement procedures. A continuously updated model risk register tracking risk classifications, audit history, and remediation actions provides a defensible foundation for any supervisory inquiry.
