# AI Office Establishment and Role — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-office-establishment-role
> Sources are cited per item. Verify against the official texts before relying on them.

The AI Office is a new institutional body created by the AI Act with specific establishment procedures, roles, responsibilities, and governance structures that warrant dedicated coverage distinct from general procedural frameworks.

## Overview

## Legal Framework

Article 64 of the AI Act establishes the AI Office as an independent administrative body within the European Commission, tasked with overseeing the implementation and enforcement of the AI Act's provisions on general-purpose AI (GPAI) models. The Office functions as the central Union-level authority responsible for evaluating and classifying GPAI models, particularly those presenting systemic risk.

Recital 113 elaborates on the Office's monitoring mandate, establishing a qualified alert mechanism through which the scientific panel can notify the AI Office of GPAI models that may warrant classification as carrying systemic risk. This alert system operates alongside the Office's own monitoring activities, creating a dual-track surveillance architecture. The rationale is to ensure that GPAI models meeting the systemic risk threshold—whether through training compute exceeding 10^25 FLOPs or otherwise—do not escape regulatory oversight simply because the provider failed to notify the Commission or the risk profile was not initially apparent.

The AI Office's establishment reflects a deliberate institutional choice: rather than fragmenting GPAI oversight across national competent authorities, the Act centralizes this function at Union level. This design addresses the cross-border nature of GPAI models and the technical capacity required to evaluate them, which exceeds what most national regulators can independently sustain.

## Key Developments

The AI Act's institutional architecture draws from lessons in data protection enforcement, particularly the GDPR's experience with the one-stop-shop mechanism. The CJEU's jurisprudence on establishment—most notably in *Google Spain* (C-131/12)—established that even minimal but stable activity through a subsidiary can trigger Union jurisdiction. The AI Office's mandate similarly rests on a broad jurisdictional foundation: providers placing GPAI models on the Union market fall within its scope regardless of where the model was developed, provided there is a Union-level nexus.

The interplay between the AI Office and national authorities mirrors tensions seen in GDPR enforcement. The Office's exclusive competence over GPAI models, while national authorities handle high-risk AI system compliance, creates a bifurcated enforcement landscape that practitioners must navigate carefully. The scientific panel's qualified alert function introduces an expert-driven trigger mechanism distinct from traditional complaint-based enforcement models.

## Practical Guidance

- **Providers of GPAI models must establish direct compliance channels with the AI Office**, as the Office—not national authorities—holds primary enforcement competence over GPAI obligations under Article 64. This includes notification obligations when training compute thresholds are met.

- **Monitor for systemic risk designation proactively**: Recital 113 makes clear that the Commission can unilaterally designate a GPAI model as carrying systemic risk if the provider failed to notify or if new information emerges. Providers should conduct internal risk assessments exceeding the statutory minimum to anticipate potential designation.

- **Engage with the scientific panel process**: The qualified alert mechanism means that external expert assessment—not just the Office's own monitoring—can trigger regulatory scrutiny. Providers should maintain technical documentation robust enough to withstand independent expert review.

- **Distinguish GPAI obligations from downstream AI system obligations**: The AI Office governs the model level, while national competent authorities govern AI system deployment. Providers operating at both layers must maintain separate compliance frameworks for each regulatory interface.

- **Prepare for post-market monitoring cooperation**: The Office's monitoring activities under Recital 113 extend beyond initial placement on the market, requiring ongoing documentation of model modifications, capability updates, and risk profile changes throughout the model lifecycle.

## Legislation (full text of key provisions)

### AI Office

*Source: AI Act, aiact-art-64-en, 2024-06-12 — https://overview.legal/posts/93030*

### Recital 116 — AI Office codes of practice development

*Source: AI Act, aiact-rec-116-en, 2024-06-12 — https://overview.legal/posts/93914*

The AI Office should encourage and facilitate the drawing up, review and adaptation of codes of practice, taking into account international approaches. All providers of general-purpose AI models could be invited to participate. To ensure that the codes of practice reflect the state of the art and duly take into account a diverse set of perspectives, the AI Office should collaborate with relevant national competent authorities, and could, where appropriate, consult with civil society organisations and other relevant stakeholders and experts, including the Scientific Panel, for the drawing up of such codes. Codes of practice should cover obligations for providers of general-purpose AI models and of general-purpose AI models presenting systemic risks. In addition, as regards systemic risks, codes of practice should help to establish a risk taxonomy of the type and nature of the systemic risks at Union level, including their sources. Codes of practice should also be focused on specific risk assessment and mitigation measures.

### Recital 162 — Commission AI Office general-purpose model supervision

*Source: AI Act, aiact-rec-162-en, 2024-06-12 — https://overview.legal/posts/94006*

To make best use of the centralised Union expertise and synergies at Union level, the powers of supervision and enforcement of the obligations on providers of general-purpose AI models should be a competence of the Commission. The AI Office should be able to carry out all necessary actions to monitor the effective implementation of this Regulation as regards general-purpose AI models. It should be able to investigate possible infringements of the rules on providers of general-purpose AI models both on its own initiative, following the results of its monitoring activities, or upon request from market surveillance authorities in line with the conditions set out in this Regulation. To support effective monitoring of the AI Office, it should provide for the possibility that downstream providers lodge complaints about possible infringements of the rules on providers of general-purpose AI models and systems.

### Recital 163 — scientific panel monitoring support for AI Office

*Source: AI Act, aiact-rec-163-en, 2024-06-12 — https://overview.legal/posts/94008*

With a view to complementing the governance systems for general-purpose AI models, the scientific panel should support the monitoring activities of the AI Office and may, in certain cases, provide qualified alerts to the AI Office which trigger follow-ups, such as investigations. This should be the case where the scientific panel has reason to suspect that a general-purpose AI model poses a concrete and identifiable risk at Union level. Furthermore, this should be the case where the scientific panel has reason to suspect that a general-purpose AI model meets the criteria that would lead to a classification as general-purpose AI model with systemic risk. To equip the scientific panel with the information necessary for the performance of those tasks, there should be a mechanism whereby the scientific panel can request the Commission to require documentation or information from a provider.

### Recital 108 — AI Office copyright compliance monitoring

*Source: AI Act, aiact-rec-108-en, 2024-06-12 — https://overview.legal/posts/93898*

With regard to the obligations imposed on providers of general-purpose AI models to put in place a policy to comply with Union copyright law and make publicly available a summary of the content used for the training, the AI Office should monitor whether the provider has fulfilled those obligations without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. This Regulation does not affect the enforcement of copyright rules as provided for under Union law.

### Recital 164 — AI Office monitoring and enforcement powers

*Source: AI Act, aiact-rec-164-en, 2024-06-12 — https://overview.legal/posts/94010*

The AI Office should be able to take the necessary actions to monitor the effective implementation of and compliance with the obligations for providers of general-purpose AI models laid down in this Regulation. The AI Office should be able to investigate possible infringements in accordance with the powers provided for in this Regulation, including by requesting documentation and information, by conducting evaluations, as well as by requesting measures from providers of general-purpose AI models. When conducting evaluations, in order to make use of independent expertise, the AI Office should be able to involve independent experts to carry out the evaluations on its behalf. Compliance with the obligations should be enforceable, inter alia, through requests to take appropriate measures, including risk mitigation measures in the case of identified systemic risks as well as restricting the making available on the market, withdrawing or recalling the model. As a safeguard, where needed beyond the procedural rights provided for in this Regulation, providers of general-purpose AI models should have the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020, which should apply mutatis mutandis, without prejudice to more specific procedural rights provided for by this Regulation.

### Recital 112 — general-purpose AI systemic risk classification procedure

*Source: AI Act, aiact-rec-112-en, 2024-06-12 — https://overview.legal/posts/93906*

It is also necessary to clarify a procedure for the classification of a general-purpose AI model with systemic risks. A general-purpose AI model that meets the applicable threshold for high-impact capabilities should be presumed to be a general-purpose AI models with systemic risk. The provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a general-purpose AI model will meet the requirements that lead to the presumption. This is especially relevant in relation to the threshold of floating point operations because training of general-purpose AI models takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers of general-purpose AI models are able to know if their model would meet the threshold before the training is completed. In the context of that notification, the provider should be able to demonstrate that, because of its specific characteristics, a general-purpose AI model exceptionally does not present systemic risks, and that it thus should not be classified as a general-purpose AI model with systemic risks. That information is valuable for the AI Office to anticipate the placing on the market of general-purpose AI models with systemic risks and the providers can start to engage with the AI Office early on. That information is especially important with regard to general-purpose AI models that are planned to be released as open-source, given that, after the open-source model release, necessary measures to ensure compliance with the obligations under this Regulation may be more difficult to implement.

### Recital 113 — Commission designation of systemic risk models

*Source: AI Act, aiact-rec-113-en, 2024-06-12 — https://overview.legal/posts/93908*

If the Commission becomes aware of the fact that a general-purpose AI model meets the requirements to classify as a general-purpose AI model with systemic risk, which previously had either not been known or of which the relevant provider has failed to notify the Commission, the Commission should be empowered to designate it so. A system of qualified alerts should ensure that the AI Office is made aware by the scientific panel of general-purpose AI models that should possibly be classified as general-purpose AI models with systemic risk, in addition to the monitoring activities of the AI Office.

### Recital 101 — General-purpose AI model provider transparency obligations

*Source: AI Act, aiact-rec-101-en, 2024-06-12 — https://overview.legal/posts/93884*

Providers of general-purpose AI models have a particular role and responsibility along the AI value chain, as the models they provide may form the basis for a range of downstream systems, often provided by downstream providers that necessitate a good understanding of the models and their capabilities, both to enable the integration of such models into their products, and to fulfil their obligations under this or other regulations. Therefore, proportionate transparency measures should be laid down, including the drawing up and keeping up to date of documentation, and the provision of information on the general-purpose AI model for its usage by the downstream providers. Technical documentation should be prepared and kept up to date by the general-purpose AI model provider for the purpose of making it available, upon request, to the AI Office and the national competent authorities. The minimal set of elements to be included in such documentation should be set out in specific annexes to this Regulation. The Commission should be empowered to amend those annexes by means of delegated acts in light of evolving technological developments.

### Recital 107 — transparency training data summary

*Source: AI Act, aiact-rec-107-en, 2024-06-12 — https://overview.legal/posts/93896*

In order to increase transparency on the data that is used in the pre-training and training of general-purpose AI models, including text and data protected by copyright law, it is adequate that providers of such models draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model. While taking into due account the need to protect trade secrets and confidential business information, this summary should be generally comprehensive in its scope instead of technically detailed to facilitate parties with legitimate interests, including copyright holders, to exercise and enforce their rights under Union law, for example by listing the main data collections or sets that went into training the model, such as large private or public databases or data archives, and by providing a narrative explanation about other data sources used. It is appropriate for the AI Office to provide a template for the summary, which should be simple, effective, and allow the provider to provide the required summary in narrative form.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

## Related topics

- **GPAI Systemic Risk** — https://overview.legal/topics/general-purpose-ai-models-systemic-risk
  This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic ris
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Authority Cooperation** — https://overview.legal/topics/cooperation-with-authorities-ai
  This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authoritie
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des

---
Generated by overview.legal · https://overview.legal/topics/ai-office-establishment-role · 2026-08-22
