AI Office enforcement: the AI Act’s new powers over platform AI

AI Office enforcement: exclusive competence over platform AI from 2 August 2026

In short: AI Office enforcement covers a company only where it built the AI system on its own general-purpose AI model, or where the system operates inside a platform designated under the Digital Services Act. Every other business remains subject to national regulation. The difference matters, because the AI Office can enter and seal premises and fine any applicable breach of the EU AI Act.

By Rob Bratby, Managing Partner, Bratby Law. Lexology Global Elite Thought Leader for Data Protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A company using AI in its products will ask one question about the enforcement changes of 2 August 2026: is the European Commission now my regulator? For almost every business the answer is no. The boundary turns not on the size of the product or the number of European users, but on who built the model beneath it and where the system is deployed. The co-legislators replaced Article 75 of the EU AI Act in the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, and Chapter IX of the Act, which contains Article 75, applies from 2 August. From that date the Commission’s AI Office directly supervises a defined set of AI systems, with powers no national regulator has.

Who remains subject to national regulation

Most companies. A business that builds its product on a model bought from a third party is subject, for that product, to the market surveillance authority of the relevant Member State, exactly as before. So is a business that deploys AI internally. The Commission has no general supervisory role over AI systems, and nothing in the Omnibus changed that for the ordinary buyer or builder.

Under the replaced Article 75(1) the AI Office takes exclusive competence over AI systems in two cases only. The first is where a provider built the system on its own general-purpose AI model, or on one from a provider in the same corporate group. Build your own engine and your own car, and Brussels supervises the car; buy the engine in, and your national regulator does. The second is where the system constitutes, or is integrated into, a very large online platform or search engine designated under the Digital Services Act, the regime whose enforcement pattern we examined in the AliExpress fine. The Commission designates those by decision under Article 33(6) and publishes the list; designation is not a self-assessment, and a service outside the list is outside this limb.

The same-undertaking test is a group-level one, and wider than the Commission’s own description of it. In its announcement of 31 July 2026 the Commission described the competence as covering systems offered by the same provider as the underlying model, where the enacted text covers a provider forming part of the same undertaking, and the Commission marks its enforcement framework page as published for information only. A group holding its model in one entity and its customer-facing products in another is inside AI Office enforcement on the enacted wording and outside it on the announcement. Read the Regulation, not the press release.

Even inside the two limbs, AI Office enforcement applies to providers, and to a deployer only where the deployer is also the provider or belongs to the same group. A designated platform that buys in a third party’s moderation tool remains subject to national supervision for its deployer obligations, while the tool’s provider is supervised by the AI Office for the same system.

What AI Office enforcement looks like for those inside

The boundary matters because of what AI Office enforcement involves. A national market surveillance authority supervises through information requests and corrective measures; the co-legislators gave the AI Office, for the systems within Article 75(1), the toolkit of a competition investigator. Under Article 75a(4) its officials may enter any business premises, land or property in the Union, take copies of books, data and other records, require oral explanations on the spot, and seal premises, books or records. Where national law requires judicial authorisation, Article 75a(4) provides that the national court may not review the necessity of the inspection; it says nothing about that court’s other grounds of control. Under Article 75a(1) the AI Office may reclaim from the operator the totality of the costs of its supervision and enforcement activities.

The fining base is wider too. Under Article 75c(4)(a) the AI Office may fine an operator within its competence at the Article 99(4) tier, up to 15 million euros or 3% of worldwide annual turnover, whichever is higher, for infringing any applicable provision of the Regulation, including provisions Article 99(4) does not list. For an operator under national supervision that list is exhaustive; for an operator under AI Office supervision it is not. Under Article 75c(5) the AI Office may also impose periodic penalty payments of up to 5% of average daily worldwide turnover for each day of non-compliance. An operator stays exposed for five years from the infringement under Article 75c(8), the Court of Justice may cancel, reduce or increase a penalty under Article 75c(6), and the Commission must publish its decisions naming the parties under Article 75d(4).

Two boundaries on those powers are worth stating as plainly as the powers themselves. They apply only to operators within Article 75(1): every one of Articles 75a to 75d is expressly gated on it. And they do not apply to providers of the models themselves, whose duties the Commission enforces separately through information requests, model evaluations and fines under Articles 91 to 93 and 101, with no power of entry. A pure model provider cannot receive a dawn raid under this Regulation; a group that ships both a model and products built on it can, as provider of the products. The model-side regime, and what companies building on those models can demand from their suppliers, is covered in GPAI enforcement: a year of duties, and now the power to fine.

Your positionYour supervisorEntry and sealing powers?
You build products on a third party’s AI modelNational market surveillance authorityNo; Article 99(4) fine list is exhaustive
You deploy AI internally, bought or vendor-builtNational market surveillance authority (Article 26 deployer duties)No
You build products on your own general-purpose AI model, or one from your groupAI Office, exclusively (Article 75(1)(a), four carve-outs)Yes; fines widened to any applicable provision
Your AI system operates inside a designated platform or search engineAI Office, exclusively (Article 75(1)(b), no carve-outs)Yes; fines widened to any applicable provision
You provide a general-purpose AI model and nothing built on itEuropean Commission through the AI Office (Article 88(1)), under Articles 91 to 93 and 101No power of entry; documentary and access-based enforcement

The carve-outs, and the platform exception to them

The same-undertaking limb has four carve-outs, which return a system to national or sectoral supervision even where the group built both model and product: Annex I products; critical digital infrastructure under point 2 of Annex III; AI systems provided by law enforcement authorities, border management authorities and financial institutions, so far as those systems fall under Article 74(6); and the administration of justice under point 8 of Annex III. Those carve-outs apply to that limb alone, so a system integrated into a designated platform is subject to AI Office enforcement even where it would have been carved out standing alone.

Under Article 75(1e) the AI Office is also responsible for third-party conformity assessment of the systems within its competence, entrusting the work to notified bodies that act on the Commission’s behalf, with fees levied on the provider, so a provider within the two limbs loses the ability to choose its own notified body in its own Member State.

What recital 32 does and does not do

A designated platform faces two Commission regimes over the same technology, because under Article 56(2) of the Digital Services Act the Commission already supervises the platform obligations of designated services. The co-legislators addressed the overlap in recital 32 rather than in the articles. The recital puts the risk assessment, mitigation and audit obligations in Articles 34, 35 and 37 of the Digital Services Act first, asks authorities to observe ne bis in idem and to take account of fines already imposed on the same provider for the same conduct, and says information obtained under one Regulation is used for the purposes of the other only where the undertaking agrees.

None of that is operative text. A recital is a legitimate aid to interpretation, but it cannot create a right the operative provisions withhold. An operator can rely on ne bis in idem without the Omnibus, because Article 50 of the Charter of Fundamental Rights protects it, and on Article 75a(8) for the evidence limit. For the order of play it has nothing but the recital, so a platform arguing that the Digital Services Act cycle must run first argues from a recital alone. The Commission can open two workstreams over one recommender system, a position designated gatekeepers already know from the parallel Digital Markets Act track.

Viewpoint

I read the boundary of AI Office enforcement as the point most businesses will get wrong, in their favour or against it. A structuring decision taken years ago, about which group company holds the model and which holds the products, now determines which regulator a business faces and with what powers.

The consequences of the boundary are sharpest at Article 75c(4)(a). Two operators can breach the same provision of the same Regulation, and only the one inside Article 75(1) faces the Article 99(4) tier for it. The co-legislators deferred the high-risk requirements and widened the fining power in the same instrument, and the two changes point in opposite directions for the same operator.

In our experience advising on regulated market entry, clients ask last which regulator they will be dealing with, and it is usually the question that determines how the matter runs. For a group planning where to hold its model and its products, that relationship is now partly a structuring choice.

I would watch the decision to put the sequencing rule in recital 32 rather than in the articles. Will the first designated platform facing parallel Digital Services Act and AI Act proceedings be able to hold the Commission to a recital?

Frequently asked questions

We build AI products on a third party’s model. Is the Commission now our regulator?

No. The AI Office’s exclusive competence covers systems built on the provider’s own general-purpose AI model or one from its group, and systems inside designated platforms. A product built on a bought-in model remains subject to the national market surveillance authority, and the Article 99(4) fine list remains exhaustive for it.

We only use AI internally. Does any of this apply to us?

Not this part. An internal deployer remains subject to national supervision for its Article 26 deployer duties. The AI Office supervises a deployer only where the deployer is also the provider of the system or part of the provider’s group.

Can the AI Office raid a company that only provides a model?

No. The entry and sealing powers in Article 75a(4) are gated on the AI Office’s competence over AI systems under Article 75(1). Against a pure model provider the Commission enforces through information requests, model evaluations and required measures under Articles 91 to 93, and fines under Article 101. A group shipping both a model and products built on it can face the entry power, as provider of the products.

Did the Digital Omnibus amend the Digital Services Act or the GDPR?

No. Regulation (EU) 2026/1744 amends the EU AI Act, the EASA Basic Regulation and the Machinery Regulation. It cross-refers to the Digital Services Act and the GDPR without amending either, and it does not amend the Digital Markets Act. AI Office enforcement operates alongside those regimes.

Our EU AI Act guide sets out the wider framework, including the risk tiers, the timetable and how the UK position differs. For advice on which regulator supervises your AI product, on structuring a group that builds both models and products, or on the interaction between the EU AI Act, the Digital Services Act and UK data protection duties, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts