AI Policy Wiki
Dashboard

EU AI Office — Enforcement Framework + GPAI Provider Guidelines

high confidence · updated 2026-06-06

Two companion Commission documents on EU AI Act enforcement: (1) the institutional architecture (AI Office + national competent authorities + AI Board / Scientific Panel / Advisory Forum) with enforcement-timeline milestones; (2) interpretive guidelines for providers of general-purpose AI models — who qualifies, what obligations apply, and how the GPAI Code of Practice fits in. Most concrete picture available of operational EU AI Act enforcement posture as of April 2026.

Two companion EU AI Office webpages describing the EU AI Act's operational enforcement posture as of April 2026. The first sets out the institutional enforcement architecture; the second is the Commission's interpretive guidance for providers of general-purpose AI (GPAI) models. Together with the GPAI Code of Practice, they form a layered compliance structure in which the Enforcement Framework defines who enforces, the Guidelines define what must be enforced, and the Code defines how providers demonstrate compliance. Signatories to the Code benefit from a presumption of compliance with the obligations the guidelines clarify.

Enforcement architecture

The AI Office (housed in DG CONNECT) is the exclusive supervisor for providers of general-purpose AI models subject to Articles 51–56. As of late 2025 it had 125+ staff across six units — Excellence in AI and Robotics; Regulation and Compliance; AI Safety; AI Innovation and Policy Coordination; AI for Societal Good; AI in Health and Life Science — plus a Lead Scientific Advisor and an International Affairs Advisor.

Below the AI Office, member states designate national competent authorities: market surveillance authorities, notifying authorities (for conformity-assessment bodies), and single points of contact. The designation deadline was 2 August 2025. As of March 2026, seven months past the deadline, only 8 of 27 member states had designated single points of contact. The November 2025 Digital Simplification Package responds to this fragmentation, proposing to "reinforce the AI Office's powers and centralise oversight of AI systems built on general-purpose AI models" — a shift of authority upward from the member-state level.

Three advisory bodies sit alongside the AI Office: the European Artificial Intelligence Board (member-state representatives), the Scientific Panel (independent AI experts, which advises on systemic-risk determinations for GPAI models), and the Advisory Forum (industry, SMEs, startups, civil society, and academia).

Enforcement timeline

DateMilestone
2024-08-01AI Act enters into force
2025-02-02Prohibited practices (Article 5) apply
2025-08-02GPAI obligations apply; member-state authority designation deadline
2026-08-02Commission GPAI enforcement powers activate — fines up to €15M or 3% of global turnover (GPAI-specific); up to €35M or 7% (prohibited practices)
2027-08-02Full high-risk system obligations apply; pre-2025 models must come into compliance

GPAI Provider Guidelines

The Guidelines were last updated 26 March 2026. They are Commission interpretive guidelines: not legally binding, but stating the Commission's enforcement posture and serving as a companion to the voluntary GPAI Code of Practice.

Who qualifies as a GPAI provider

The criteria fall under Article 3(63). Significant modifications to an existing GPAI model trigger provider obligations for the downstream modifier, while minor alterations or fine-tuning do not convert a deployer into a provider. Open-source models benefit from partial exemptions under specified conditions. The 26 March 2026 update refines these modifier-as-provider determinations — the question of when fine-tuning a frontier base model crosses the threshold into new provider obligations, which the Guidelines treat as a central open compliance question for EU-market deployers of Claude, GPT, Gemini, and open-weight models.

Core obligations for GPAI providers

Providers face several obligations under the Guidelines. A provider must notify the AI Office when a model crosses the systemic-risk threshold (default: 10²⁵ FLOP cumulative training compute). For systemic-risk models, the provider must submit Safety and Security Framework (SSF) documentation. All GPAI providers must publish a summary of training content (Article 53(1)(d)) and report serious incidents and near-misses. Regulator-facing documentation is submitted through the EU SEND platform, a standardised digital channel.

Compliance obligations are scaled to risk: open-source exemptions apply under specified conditions, and documentation is proportionate for non-systemic-risk providers. The GPAI Code of Practice is the approved means of demonstrating compliance with Articles 53 and 55 until harmonised standards are adopted, providing the regulatory "glide path" the Commission signaled at the Code's publication.

Unresolved implementation questions

Several elements of the framework remained unsettled as of the April 2026 documents. The shortfall in member-state designations (8 of 27) accompanies the Commission's shift of authority upward through the Digital Simplification Package. The systemic-risk threshold is itself contested: whether the 10²⁵ FLOP cutoff is the right one is debated, given that many frontier models (Opus 4.x, GPT-5.x, Gemini 3.x) sit far above it while large open-weight Chinese models (DeepSeek-V3, Kimi K2) sit near or below it, which affects the reach of Articles 53–55. The modifier-as-provider line bears directly on downstream AI-product companies and vertical applications. Uptake of the GPAI Code of Practice — signatories versus non-signatories — produces a two-tier compliance experience.

Relationships