Skip to content
Topic Developing

AI Office Establishment and Role

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The AI Office is a new institutional body created by the AI Act with specific establishment procedures, roles, responsibilities, and governance structures that warrant dedicated coverage distinct from general procedural frameworks.

19 linked items 18 Laws1 News

Overview

9 sources · Jul 23, 2026

Legal Framework

Article 64 of the AI Act establishes the AI Office as an independent administrative body within the European Commission, tasked with overseeing the implementation and enforcement of the AI Act's provisions on general-purpose AI (GPAI) models. The Office functions as the central Union-level authority responsible for evaluating and classifying GPAI models, particularly those presenting systemic risk.

Recital 113 elaborates on the Office's monitoring mandate, establishing a qualified alert mechanism through which the scientific panel can notify the AI Office of GPAI models that may warrant classification as carrying systemic risk. This alert system operates alongside the Office's own monitoring activities, creating a dual-track surveillance architecture. The rationale is to ensure that GPAI models meeting the systemic risk threshold—whether through training compute exceeding 10^25 FLOPs or otherwise—do not escape regulatory oversight simply because the provider failed to notify the Commission or the risk profile was not initially apparent.

The AI Office's establishment reflects a deliberate institutional choice: rather than fragmenting GPAI oversight across national competent authorities, the Act centralizes this function at Union level. This design addresses the cross-border nature of GPAI models and the technical capacity required to evaluate them, which exceeds what most national regulators can independently sustain.

Key Developments

The AI Act's institutional architecture draws from lessons in data protection enforcement, particularly the GDPR's experience with the one-stop-shop mechanism. The CJEU's jurisprudence on establishment—most notably in Google Spain (C-131/12)—established that even minimal but stable activity through a subsidiary can trigger Union jurisdiction. The AI Office's mandate similarly rests on a broad jurisdictional foundation: providers placing GPAI models on the Union market fall within its scope regardless of where the model was developed, provided there is a Union-level nexus.

The interplay between the AI Office and national authorities mirrors tensions seen in GDPR enforcement. The Office's exclusive competence over GPAI models, while national authorities handle high-risk AI system compliance, creates a bifurcated enforcement landscape that practitioners must navigate carefully. The scientific panel's qualified alert function introduces an expert-driven trigger mechanism distinct from traditional complaint-based enforcement models.

Practical Guidance

  • Providers of GPAI models must establish direct compliance channels with the AI Office, as the Office—not national authorities—holds primary enforcement competence over GPAI obligations under Article 64. This includes notification obligations when training compute thresholds are met.

  • Monitor for systemic risk designation proactively: Recital 113 makes clear that the Commission can unilaterally designate a GPAI model as carrying systemic risk if the provider failed to notify or if new information emerges. Providers should conduct internal risk assessments exceeding the statutory minimum to anticipate potential designation.

  • Engage with the scientific panel process: The qualified alert mechanism means that external expert assessment—not just the Office's own monitoring—can trigger regulatory scrutiny. Providers should maintain technical documentation robust enough to withstand independent expert review.

  • Distinguish GPAI obligations from downstream AI system obligations: The AI Office governs the model level, while national competent authorities govern AI system deployment. Providers operating at both layers must maintain separate compliance frameworks for each regulatory interface.

  • Prepare for post-market monitoring cooperation: The Office's monitoring activities under Recital 113 extend beyond initial placement on the market, requiring ongoing documentation of model modifications, capability updates, and risk profile changes throughout the model lifecycle.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 18
Art. 112(5) By 2 August 2028, the Commission shall evaluate the functioning of the AI Office, whether the AI Office has been given sufficient powers and competenc… AI Act Art. 112(11) To guide the evaluations and reviews referred to in paragraphs 1 to 7 of this Article, the AI Office shall undertake to develop an objective and parti… AI Act Art. 3(47) ‘AI Office’ means the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI mod… AI Act Art. 25(4)(cont)(1) The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply to… AI Act rec 116 Recital 116 — AI Office codes of practice development AI Act Jun 2024 rec 162 Recital 162 — Commission AI Office general-purpose model supervision AI Act Jun 2024 rec 163 Recital 163 — scientific panel monitoring support for AI Office AI Act Jun 2024 rec 108 Recital 108 — AI Office copyright compliance monitoring AI Act Jun 2024 rec 164 Recital 164 — AI Office monitoring and enforcement powers AI Act Jun 2024 art 64 AI Office AI Act Jun 2024 rec 112 Recital 112 — general-purpose AI systemic risk classification procedure AI Act Jun 2024 rec 113 Recital 113 — Commission designation of systemic risk models AI Act Jun 2024 rec 101 Recital 101 — General-purpose AI model provider transparency obligations AI Act Jun 2024 rec 107 Recital 107 — transparency training data summary AI Act Jun 2024 rec 179 Recital 179 — regulation phased application dates AI Act Jun 2024 rec 111 Recital 111 — systemic risk classification methodology for general-purpose AI models AI Act Jun 2024 rec 148 Recital 148 — AI governance framework coordination structure AI Act Jun 2024 rec 161 Recital 161 — Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 151 Recital 151 — scientific panel of independent experts AI Act Jun 2024 rec 117 Recital 117 — general-purpose AI model compliance codes AI Act Jun 2024 rec 160 Recital 160 — joint market surveillance and investigation activities AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024
News 1
Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023