Written and maintained by CASRAI Editorial Board
Last updated
The EU AI Office is not the EU AI Act — it’s the body inside the European Commission that implements and enforces it. This guide covers the institution: what it is, where it sits, what powers it has, and how it works with enforcement bodies at the national level. For the Act’s substantive rules themselves, see the GPAI Code of Practice (which the AI Office facilitates) and the high-risk compliance checklist (which national authorities, not the AI Office, mostly enforce).
What the EU AI Office is
The AI Office was established within the European Commission by Commission Decision C(2024) 390 of 24 January 2024. It sits inside the Commission’s Directorate-General for Communications Networks, Content and Technology (DG CONNECT), rather than existing as a separate agency. The Commission describes the Office as employing more than 125 staff — technology specialists, lawyers, policy specialists, economists, and administrative staff — organized into six operating units (covering areas such as excellence in AI and robotics, regulation and compliance, AI safety, innovation and policy coordination, AI for societal good, and AI in health and life sciences) plus a Lead Scientific Adviser and an International Affairs Adviser. As with any staffing figure, treat this as a snapshot rather than a fixed number.
The Office is one part of a wider governance structure the AI Act sets up around it. Two other bodies sit alongside it: a Scientific Panel of independent AI experts, and an Advisory Forum representing industry, academia, and civil society stakeholders. Neither has enforcement power of its own; both feed technical input and stakeholder perspective into decisions the Office and the Commission make.
What it actually does: exclusive authority over GPAI models
The AI Act’s enforcement is split by AI system type, and the Office’s distinctive role is that it — not any national authority — holds exclusive power to supervise and enforce the Act’s rules for general-purpose AI (GPAI) models. In practice that covers a specific toolkit:
- Requesting information. The Office can require a GPAI provider to hand over technical documentation and compliance data.
- Evaluating models directly. It develops its own tools, methodologies, and benchmarks for assessing a model’s capabilities and reach, and can conduct evaluations itself — after consulting the AI Board — through APIs or other means such as source-code access, rather than relying solely on a provider’s self-reported documentation.
- Demanding mitigation. Where an evaluation turns up a serious and substantiated concern of systemic risk, the Commission can require the provider to take mitigation measures.
- Restricting or pulling a model. If mitigation isn’t enough, the Commission can restrict, recall, or withdraw the GPAI model from the market.
- Fining providers directly. Under Article 101, the Commission can fine a GPAI provider up to €15,000,000 or 3% of its annual total worldwide turnover in the preceding financial year, whichever is higher — for intentional or negligent violations, failure to provide requested documentation, ignoring enforcement measures, or refusing model access for evaluation.
The Office also acts as secretariat to the European Artificial Intelligence Board, the body that coordinates national authorities: it convenes Board meetings, prepares the agenda, and supports the Board’s work, though the Board itself is composed of one representative per member state, with the European Data Protection Supervisor and the AI Office participating as non-voting observers.
This exclusivity is specific to GPAI models. It’s why the two other CASRAI guides on the EU AI Act — on the GPAI Code of Practice and the high-risk compliance checklist — point to different enforcement paths: the Code of Practice is a GPAI instrument the AI Office itself facilitated under Article 56, while high-risk system compliance is mostly a national-authority matter, described below.
How this relates to national enforcement
For everything that isn’t a general-purpose AI model — which is most of the Act, including high-risk AI systems under Annexes I and III — enforcement sits with each EU member state rather than with the AI Office. Each member state was required to designate its national competent authorities by 2 August 2025, and that designation splits into two roles:
- Market surveillance authorities supervise and enforce compliance with the Act’s rules for AI systems generally, including the Act’s prohibited-practice rules and its rules for high-risk AI.
- Notifying authorities designate and supervise notified bodies — the independent bodies that carry out pre-market conformity assessment for certain high-risk systems.
Violations that fall to national authorities carry their own, separate penalty structure under Article 99: fines of up to €35,000,000 or 7% of worldwide annual turnover for the most serious violations, such as breaches of the Act’s prohibited-AI-practice rules. That’s a higher ceiling than the Article 101 figure for GPAI providers, reflecting that Article 99 covers the Act’s most serious prohibited-practice violations generally, not GPAI-specific conduct.
The AI Office isn’t absent from this national-level enforcement, though its role there is coordinating rather than deciding: it provides coordination support for joint investigations that market surveillance authorities run on their own, or jointly with the Commission, when a high-risk AI system is found to present a serious risk across several member states.
The practical split, then: exactly one AI Office handles GPAI models EU-wide, while every member state runs its own market surveillance and notifying authorities for everything else, with the AI Office coordinating rather than substituting for that national layer.
Why this distinction matters for compliance tracking
An organization that develops, deploys, or procures AI needs to know which enforcement body actually has jurisdiction over which parts of its stack — a GPAI model embedded in a product answers to the AI Office directly, while the high-risk system built around it may answer to a national market surveillance authority instead. Getting that wrong means tracking compliance against the wrong body’s expectations. CASRAI’s NIKOLAI element dictionary defines the vocabulary organizations use to describe AI-governance metadata — including provenance and compliance-status elements — consistently enough to keep that kind of distinction traceable across a supply chain rather than lost at each handoff.
For the substantive rules these two enforcement paths apply, see the GPAI Code of Practice guide and the high-risk compliance checklist. For the broader cluster of EU AI Act and frontier-AI-governance content, see the Frontier AI Safety & Governance pillar.
FAQ
Is the EU AI Office the same thing as the EU AI Act?
No. The AI Act (Regulation (EU) 2024/1689) is the binding law. The AI Office is the body within the European Commission that implements and enforces it — primarily for general-purpose AI models, where it holds exclusive enforcement authority.
Can the AI Office fine any AI provider?
No. Its direct fining power under Article 101 applies specifically to providers of general-purpose AI models. Fines for most other AI Act violations, including breaches of the Act’s high-risk and prohibited-practice rules, are enforced by national market surveillance authorities under Article 99, which carries a higher ceiling — up to €35,000,000 or 7% of worldwide turnover.
Where does the AI Office sit within the European Commission?
Within the Directorate-General for Communications Networks, Content and Technology (DG CONNECT). It was established by Commission Decision C(2024) 390 of 24 January 2024.
Does the AI Office replace national AI regulators?
No. Each EU member state still designates its own market surveillance authorities and notifying authorities, which handle enforcement for AI systems other than general-purpose AI models. The AI Office coordinates and supports cross-border joint investigations but doesn’t substitute for that national layer.
What is the European Artificial Intelligence Board?
A coordination body with one representative per EU member state, plus the European Data Protection Supervisor and the AI Office participating as non-voting observers. The AI Office acts as its secretariat, convening meetings and preparing the agenda, but the Board itself is a member-state coordination forum rather than an AI Office subunit.







