Fines of up to €15 million, access to the source code, and investigative powers over the world’s most secretive AI models: as of August 2, the AI Office stops being merely a policy study desk and becomes a bona fide policing authority over AI models deemed to carry a “systemic risk.”
That policing body, however, did not spring up spontaneously. The structure has existed since January 24, 2024, to provide an entity capable of coordinating the implementation of the AI Act and delivering technical and governance expertise. Two and a half years of maturation, in short, before it finally earned its full policing powers.
Because its remit is not limited to enforcement. The AI Office also serves as the EU’s institutional voice on AI policy, representing the Commission in major international forums (OECD, G7, G20, Council of Europe, ISO/IEC) or in the international network gathering the national institutes responsible for assessing the risks of the most advanced AI models.
What the AI Office Can Require
As part of its mission, the AI Office has three main levers.
First, it can require the developers of the world’s most powerful AI models to hand over all documentation necessary to assess their conformity. Article 91 of the regulation allows it to demand the entire set of documents a supplier was obliged to produce under Articles 53 and 55 of the text; technical documentation, capability assessments, risk analyses, or any additional information deemed necessary.
The AI Office can then commission independent assessments of these models, including access to their source code, drawing on external experts if needed to act on its behalf.
Finally, it can impose fines of up to 3% of the company’s worldwide annual turnover, or €15 million, whichever is higher, in cases of non-compliance. Refusing to respond to a request for documentation or providing incorrect, incomplete, or misleading information constitutes grounds for sanction in itself.
At the national level, it is the market surveillance authorities of each Member State that take over for the other AI systems.
In France, CNIL has been designated as the reference authority for the implementation of the AI Act in France. This competence was secured after a year and a half of arbitration. About fifteen sectoral authorities support it depending on the domain: DGCCRF for deceptive commercial practices, ARCOM for audiovisual content and deepfakes, ACPR and AMF for finance, ANSM and HAS for health.
A Team of 145 Experts
To fulfill this role, the AI Office promises 38 additional hires. This would bring its headcount to 145 people; including 34 in regulation and compliance, and 38 dedicated solely to monitoring the safety of the most advanced models. A figure that remains modest in light of the magnitude of the task.
Around the AI Office also orbit other bodies such as the AI Board, the Scientific Panel, and the Advisory Forum, charged with guiding and advising the overall governance of the AI Act.
Beyond the traditional investigatory powers, the Commission has set up tools to surface information: a whistleblower mechanism allowing employees in the tech sector to report breaches and a compliance tool intended for users who wish to alert authorities confidentially about activities deemed illegal.