The AI Office is the European Commission's centre of expertise and enforcement for artificial intelligence (AI), set up to apply the European Union's (EU) AI Act to the developers of the largest models. It supervises providers of general-purpose AI models - the systems behind chatbots, image generators and a growing share of advertising tools - and can demand documents, test models and fine providers up to 3% of worldwide annual turnover. A model released once is used in all 27 member states at the same moment, so Article 88 of the Act gives the Commission exclusive powers over these providers. In law the office is not an agency. The Act defines it as "the Commission's function" and states that references to it "shall be construed as references to the Commission".
How supervision works
The office sits inside the Directorate-General for Communications Networks, Content and Technology (DG CNECT). Its Commission web page, updated on September 8, 2026, lists six units, among them regulation and compliance and AI safety, a lead scientific adviser and more than 125 staff.
Supervision starts with classification. Commission guidelines of July 18, 2025 treat a model trained with more than 10^23 floating-point operations (FLOP) that can generate text, images or video as general-purpose. Above 10^25 FLOP a model is presumed to carry systemic risk, and its provider must notify the Commission within two weeks. Every general-purpose provider owes technical documentation, a copyright policy and a public summary of training content under Article 53; systemic-risk providers must also evaluate and red-team their models, report serious incidents and ensure adequate cybersecurity under Article 55.
Compliance is meant to run largely through codes of practice, which the office facilitates under Article 56 and which signatories can use to demonstrate compliance. Where problems arise, Articles 89 to 94 set out an escalation ladder: complaints from downstream providers that build on a model; qualified alerts from a scientific panel of independent experts; document requests; evaluations, if necessary by independent experts; and measures up to restricting, withdrawing or recalling a model. Fines under Article 101 reach 3% of turnover or EUR 15 million, whichever is higher, and cover misleading answers as well as substantive breaches.
Commission Implementing Regulation (EU) 2026/1755 of July 20, 2026 sets the procedure: access through application programming interfaces (APIs), source code or model weights; checks on experts' ties to the provider covering at least 12 months; and at least 21 days, in no more than 50 pages, to answer preliminary findings.
Since July 27, 2026 the office has had a second, wider remit. The Digital Omnibus on AI, Regulation (EU) 2026/1744, rewrote Article 75 to give it exclusive competence over two kinds of AI system: those built on a general-purpose model by the same provider or group, and those that constitute or sit inside a very large online platform or search engine designated under the Digital Services Act (DSA). New Articles 75a to 75d add inspections of premises, binding commitments, corrective orders and periodic penalties of up to 5% of average daily turnover.
From agency plan to Commission function
The Commission's AI Act proposal of April 21, 2021 contained no office, only a board of national supervisors chaired by the Commission. Parliament's position of June 14, 2023, adopted by 499 votes to 28, envisaged an AI Office with "legal personality" that would "act in full independence", according to law firm K&L Gates. The December 2023 compromise placed the office inside the Commission instead.
The Commission created it by decision on January 24, 2024, before the Act was adopted. Unveiling the structure on May 29, 2024, Thierry Breton, then internal market commissioner, spoke of "its 140 talented women and men". Lucilla Sioli, previously director for AI and digital industry, was named head. The Act entered into force on August 1, 2024.
The first large job was the General-Purpose AI Code of Practice, drafted from September 30, 2024 with nearly 1,000 participants in working groups chaired by independent experts including Yoshua Bengio. Due by May 2, 2025, the final code arrived on July 10, 2025, with chapters on transparency, copyright, and safety and security. The Commission and the AI Board declared it adequate on August 1, a day before obligations applied. Some 26 companies signed, according to Euronews, including Amazon, Google, Microsoft and OpenAI; xAI signed only the safety chapter. Meta refused, with Joel Kaplan, its chief global affairs officer, saying the code introduced "measures which go far beyond the scope of the AI Act".
Simplification followed: a consultation on September 16, 2025, the omnibus proposal on November 19, 2025, a provisional deal on May 7, 2026 and adoption on July 8.
Why advertisers and publishers follow it
For two years the office reached marketers indirectly, through the models in their tools. Google, which committed to sign the code on July 30, 2025, runs Gemini models that write ad copy in AI Max and Performance Max. The code's copyright chapter commits signatories to crawlers that respect robots.txt, the file publishers use to refuse AI training.
Article 50, applicable since August 2, 2026, made the link direct by requiring machine-readable marking of AI output and visible labels on deepfakes. The office facilitated a transparency code, published with Commission guidelines on July 20, 2026 that deny advertising the lighter regime for artistic works, alongside free labelling icons. About 190 organisations had signed by the end of July, according to the Commission, among them Google and Meta. Interactive Advertising Bureau (IAB) Austria has since concluded that agencies, not clients, usually carry the labelling duty, and VIA Nederland mapped four disclosure triggers.
The platform remit matters more. The office's complaint tool lists designated services including Facebook, Instagram, YouTube, Google Search, Amazon Store, TikTok and Bing. Ranking systems, creative generators and automated bidding engines inside them now answer to Brussels; advertisers using them stay with national regulators unless they are also the provider. ChatGPT, built by OpenAI on its own models, already fell within that remit before its designation as a very large online search engine on August 31, 2026 added DSA duties.
Capacity, independence and process
Capacity draws the most criticism. Article 64 promises the office "adequate resources", yet in January 2025 Axel Voss, a member of the European Parliament and shadow rapporteur on the Act, called it "massively understaffed", with 30 of 85 staff on implementation, according to the Center for European Policy Analysis. The September 2026 figure of more than 125 remains below the 140 Breton cited. The UK's AI Security Institute, which cannot fine anyone, has more than 100 technical specialists and GBP 66 million a year, according to the Ada Lovelace Institute. Two posts vacant at launch were filled late: Matthieu Delescluse became head of the AI safety unit in December 2025, according to MLex, and Oxford professor Alessandro Abate was named lead scientific adviser in August 2026, according to the University of Oxford. The Commission put the omnibus workload at 53 full-time posts, 38 of them new.
Independence is the second objection. Parliament's proposed independent agency became part of a directorate-general that also funds AI research. Sioli has defended the pairing: "we look at the innovation policy and the trust policy as two sides of the same coin," she told the Center for Strategic and International Studies in August 2025.
Process is the third. Corporate Europe Observatory and LobbyControl reported in April 2025 that model providers got dedicated workshops with the code's chairs while civil society submitted questions in advance. "It really shows how they see civil society input: as secondary at best," said Dinah van der Geest of Article 19. A coalition of 39 creative-sector groups rejected the code, guidelines and training-data template; Angela Mills Wade of the European Publishers Council said the coalition "strongly reject[s] any claim that the Code of Practice strikes a fair and workable balance". From the other side, AI & Partners objected to draft procedural rules seeking "all levels of access granted to employees". The final text raised the minimum reply period from 14 days to 21.
Not the same as
European Artificial Intelligence Board. One representative per member state, chaired by a member state. The office provides its secretariat and attends without a vote.
National market surveillance authorities. Member-state regulators that supervise most AI systems, including high-risk uses and deployers such as agencies. The office's exclusive remit is the exception.
Scientific panel. Sixty independent experts appointed on June 1, 2026 for two-year terms. The panel can issue qualified alerts to the office but cannot enforce.
AI Security Institute. The UK body, renamed from AI Safety Institute in February 2025, tests frontier models but has no regulatory powers.
Recent developments
Enforcement powers took effect on August 2, 2026; models on the market before August 2, 2025 have until August 2, 2027. The Commission's AI Act service desk said technical compliance dialogues would remain "a first tool of choice". Three complaint routes, including an anonymous whistleblower inbox, opened on July 31.
At the end of August the office sent requests for information to more than 30 AI providers, covering safety and security as well as copyright and transparency, according to Agence Europe, citing Commission spokesperson Thomas Regnier. "Our goal is to ensure that AI in Europe is developed, released and used safely and transparently," Henna Virkkunen, executive vice-president for tech sovereignty, said, according to Al Jazeera. Requests are not findings of breach.
The next marker is December 2, 2026, when generative systems already on the market must meet marking requirements and bans on AI tools producing non-consensual intimate imagery and child sexual abuse material apply.
Timeline
- April 21, 2021: The Commission proposes the AI Act, with a board of national supervisors and no AI Office
- June 14, 2023: The European Parliament adopts its position by 499 votes to 28, proposing an independent AI Office with legal personality
- December 8, 2023: Council and Parliament reach a provisional agreement on the AI Act
- January 24, 2024: The Commission adopts the decision establishing the AI Office
- February 21, 2024: The decision enters into force
- May 29, 2024: The Commission unveils the office's structure and names Lucilla Sioli as head
- June 16, 2024: The office's organisational structure takes effect
- August 1, 2024: The AI Act, Regulation (EU) 2024/1689, enters into force
- September 30, 2024: Drafting of the General-Purpose AI Code of Practice begins
- May 2, 2025: The AI Act's deadline for codes of practice passes
- July 10, 2025: The final General-Purpose AI Code of Practice is published
- July 18, 2025: The Commission publishes guidelines on obligations for general-purpose AI providers
- August 1, 2025: The Commission and the AI Board confirm the code as adequate; some 26 companies have signed
- August 2, 2025: Obligations for general-purpose AI model providers apply
- September 16, 2025: The Commission opens a consultation on a digital omnibus
- November 19, 2025: The Commission proposes the Digital Omnibus on AI
- December 2025: Matthieu Delescluse is appointed head of the AI safety unit
- March 12, 2026: A draft implementing regulation on evaluations and proceedings is published
- March 18, 2026: Parliament committees back the omnibus report by 101 votes to 9
- May 7, 2026: Council and Parliament reach a provisional agreement on the omnibus
- June 1, 2026: The Commission appoints 60 experts to the scientific panel
- July 8, 2026: Regulation (EU) 2026/1744 is adopted
- July 20, 2026: Implementing Regulation (EU) 2026/1755 is adopted; the transparency code and Article 50 guidelines are published
- July 24, 2026: The omnibus is published in the Official Journal
- July 27, 2026: The omnibus enters into force, extending the office's exclusive competence to AI systems
- July 31, 2026: The office opens three complaint channels; about 190 organisations have signed the transparency code
- August 2, 2026: Commission enforcement powers over general-purpose AI providers and Article 50 obligations apply
- August 2026: Alessandro Abate is named lead scientific adviser
- Late August 2026: The office sends requests for information to more than 30 AI providers
- August 31, 2026: ChatGPT is designated a very large online search engine under the DSA
- December 2, 2026: New prohibitions and the marking deadline for existing generative systems apply
- August 2, 2027: Compliance deadline for general-purpose models placed on the market before August 2, 2025
Related PPC Land coverage
- EU clarifies AI model thresholds in new regulatory guidelines - The compute thresholds for general-purpose and systemic-risk models and the two-week notification rule.
- Explaining systemic risk - How systemic risk differs between the AI Act's model-based regime and the DSA's service-based one.
- Explaining VLOP - The DSA designation of very large online platforms and the 45 million user threshold.
- AI Office gains 5% daily penalty power over Google and Meta AI systems - The consolidated AI Act text, new Articles 75a to 75d and what they mean for advertising systems on designated platforms.
- EU publishes final General-Purpose AI Code of Practice - The three chapters of the July 2025 code and the process that produced it.
- Commission releases AI Act guidelines and Meta won't sign code of practice - The July 2025 guidelines for general-purpose AI providers and Meta's refusal to sign.
- Commission launches major effort to simplify EU digital rules - The September 2025 consultation that opened the digital omnibus process.
- EU Parliament committee backs AI Act delay with fixed 2027 deadline - The March 2026 committee vote on the omnibus and its limits on the office's remit.
- EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 - The May 2026 provisional deal and the staffing the Commission estimated for the office's new tasks.
- Google raises security to level 2+ for 3 types of dangerous AI capability - Google's Frontier Safety Framework, its code commitment and the Gemini models behind its ad products.
- Explaining robots.txt - The crawler exclusion file and its place in the code's copyright commitments.
- EU AI content rules force publishers to label or risk 3% of turnover - The July 2026 transparency code and Article 50 guidelines and what they require of deployers.
- EU publishes free AI labelling icons ahead of August 2026 deadline - The Commission's icons for AI-generated and AI-modified content.
- Google signs EU AI code as advertisers face 3% turnover fines August 2 - Google's signature of the transparency code and the code's drafting chairs.
- Meta faces 3% turnover fines in 5 days as it signs EU AI content code - Meta's signature of the transparency code after the presumption deadline.
- Agencies, not clients, usually carry AI label duty, IAB Austria guide says - How IAB Austria allocates Article 50 duties among agencies, brands and publishers.
- Dutch trade body maps 4 AI disclosure triggers for ad agencies - VIA Nederland's guidance on when agencies must disclose AI use.
- EU AI Office opens three complaint routes covering Google and Meta systems - The general complaints tool, downstream provider channel and whistleblower inbox.
- ChatGPT faces EU risk rules after declaring 159.1 million users - The August 2026 DSA designation of ChatGPT, Reddit and Roblox.
- European creators reject AI Act implementation measures - The 39-organisation coalition that rejected the code, guidelines and training-data template.
- EU draft reveals how Brussels will probe and fine AI model providers - The March 2026 draft on model access, expert independence, limitation periods and hearing rights.
Summary
Who. The AI Office, part of the European Commission's DG CNECT, headed at launch by Lucilla Sioli and staffed by more than 125 people in six units. It supervises providers of general-purpose AI models such as OpenAI, Google, Anthropic, Meta and Mistral and, since July 2026, AI systems built on a provider's own models or integrated into designated platforms.
What. A Commission function rather than an independent agency, with exclusive powers to request information, evaluate models, order measures and fine providers up to 3% of worldwide turnover, and to impose periodic penalties of up to 5% of average daily turnover under the omnibus. It also facilitates codes of practice, including the transparency code behind AI labels in advertising.
When. Established by decision on January 24, 2024 and operational from June 16, 2024. Supervision of general-purpose models began on August 2, 2025, enforcement powers on August 2, 2026, and the first requests for information followed at the end of August 2026.
Where. In Brussels, across all 27 member states and over any provider whose models or systems are used in the EU, wherever it is established.
Why. Models are released once and used everywhere, so the EU centralised their supervision. For advertisers and publishers the office now shapes AI labelling duties, training-data transparency and the rules for AI inside the largest platforms advertisers buy on.
Discussion