Chapter 8 of 11
Governance and Enforcement: AI Office, AI Board, and National Authorities
Behind the rules sits a new governance ecosystem; see how the European AI Office, national authorities, and market surveillance bodies will interact with your organization in practice.
Step 1 – The New AI Governance Map Under the EU AI Act
Why Governance Matters
The EU AI Act now has a dedicated governance system. You must know who can supervise your AI use, what they can ask, and how EU and national bodies coordinate enforcement.
Four Main Layers
There are four layers: 1) European Commission – AI Office, 2) European AI Board, 3) Scientific/technical expert structures, and 4) National authorities and market surveillance bodies.
Who You Meet Most Often
Most organizations mainly interact with national competent and market surveillance authorities. GPAI and systemic-risk providers may also deal directly with the AI Office.
A Regulation, Not a Directive
The AI Act is an EU Regulation, directly applicable across Member States. It replaces a patchwork of general product safety rules with a unified AI-specific framework.
Step 2 – The European AI Office: Role and Powers
What Is the AI Office?
The European AI Office sits inside the European Commission. It oversees general-purpose AI, drafts guidance, and coordinates AI Act enforcement across the EU.
Focus on GPAI and Systemic Risk
The AI Office supervises providers of general-purpose AI models, especially very large, systemic-risk models. It can request technical documentation and risk assessments.
Guidance and Rules
The AI Office drafts implementing acts, delegated acts, guidelines, and codes of practice that clarify how to comply, especially for GPAI providers and users.
Enforcement Impact on You
GPAI providers may face direct investigations and fines proposed by the AI Office. Deployers feel the impact through guidance, databases, and model-level decisions.
Step 3 – European AI Board and Expert Structures
Who Is on the AI Board?
The European AI Board includes one representative from each Member State’s national authority, plus the European Commission as chair and secretariat.
Board’s Core Mission
The Board promotes consistent application of the AI Act. It issues opinions and recommendations and helps resolve cross-border enforcement disagreements.
Expert Structures
Scientific and technical expert panels support the AI Office and AI Board by evaluating GPAI models and advising on standards and risk metrics.
Impact on You
You may not meet the Board directly, but its opinions guide how your national authority interprets your obligations and what “good practice” looks like.
Step 4 – National Competent Authorities and Market Surveillance
Meet Your Main Regulators
National competent authorities and market surveillance authorities are your primary supervisors for AI Act compliance in each EU Member State.
Role of NCAs
NCAs oversee compliance, receive incident reports, run investigations, and publish national guidance. They may be existing digital, data, or sector regulators.
Role of MSAs
MSAs focus on product safety and conformity. They can request technical documentation, inspect systems, test products, and order corrective measures or recalls.
Sector Regulators
In finance, health, or transport, your usual sector regulator may also act as the AI Act authority, supervising AI systems used in that sector.
Step 5 – How These Bodies Interact: Three Practical Scenarios
Scenario A: Cross-Border Bank
A bank uses a high-risk credit-scoring AI in several countries. NCAs and MSAs in each state supervise; they coordinate via the AI Board and may loop in the AI Office if a GPAI model is involved.
Scenario B: GPAI Coding Assistant
A startup providing a GPAI coding assistant is directly supervised by the AI Office for model-level duties, while national authorities oversee how clients deploy the tool.
Scenario C: Hospital Sandbox
A hospital and startup test a high-risk diagnostic AI in a national sandbox. They co-design tests with the NCA, while lessons feed into the AI Board and AI Office guidance.
Key Takeaway
Your regulator mix depends on your role (provider, deployer, GPAI provider), the AI risk level, and sector. Governance is multi-layered but coordinated.
Step 6 – Map Your Own Organization’s Regulators
Use this thought exercise to connect the governance framework to your own (real or hypothetical) organization.
- Identify your role(s)
- Are you mainly a deployer (using AI from vendors)?
- A provider (developing and placing AI systems on the EU market)?
- A GPAI provider (developing general-purpose or foundation models)?
- Some combination of these?
- List your sectors and countries
- In which sectors do you operate (finance, health, retail, public sector, manufacturing, etc.)?
- In which EU Member States do you have customers, users, or operations?
- Research likely national authorities
- For each country, look up:
- The likely national competent authority for AI (often a digital, innovation, or consumer protection authority).
- Relevant sector regulators (e.g., financial supervisor, health authority, transport safety agency).
- Note any market surveillance authorities that already supervise your non-AI products.
- Draw your own governance map
- On a sheet of paper or a simple diagram tool, place:
- Your organization at the center.
- Around it, the AI Office (if you are a GPAI provider or use GPAI heavily).
- The European AI Board as a coordination layer (even if you will not contact it directly).
- Your NCAs, MSAs, and sector regulators in each key Member State.
- Reflect (short written note)
- Write 3–5 bullet points on:
- Which authority you are most likely to hear from first in case of an AI-related issue.
- Which AI use cases in your organization are most likely to attract regulatory attention.
- Whether you might benefit from joining a regulatory sandbox in any Member State.
If you are doing this as a class activity, compare maps with a partner and discuss where your governance landscapes look similar or different.
Step 7 – Regulatory Sandboxes, Guidance, and Soft Law
What Is a Sandbox?
Regulatory sandboxes are controlled environments run by national authorities where you can test AI systems with close regulatory supervision and tailored conditions.
Why Join a Sandbox?
Sandboxes give early feedback on compliance, help design documentation and oversight, and signal that you take AI Act obligations seriously.
Guidance and Soft Law
The AI Office, AI Board, and NCAs issue guidelines, codes of practice, and refer to harmonized standards. These shape what “good compliance” looks like in practice.
Link to Your AI Lifecycle
Use sandboxes and guidance during design and testing, and follow national rules for deployment, monitoring, and incident reporting.
Step 8 – Enforcement Tools: Investigations, Corrective Measures, and Fines
Investigations
Authorities can request documentation, inspect your premises, and test your AI systems. You must respond accurately and on time.
Corrective Measures
If you are non-compliant, regulators can order fixes, restrict or ban use, withdraw systems from the market, or require you to inform affected users.
Fines
The AI Act allows high administrative fines, scaled to global turnover, especially for serious infringements like prohibited practices or key GPAI failures.
Be Prepared
Keep documentation and logs, set up incident reporting, and assign a regulatory contact point to handle information requests and investigations.
Step 9 – Quick Check: Who Does What?
Test your understanding of the main governance bodies under the AI Act.
Which statement best describes the role of the European AI Office compared to national competent authorities?
- The AI Office replaces national authorities and directly enforces all AI Act obligations in every Member State.
- The AI Office focuses on GPAI and cross-border coordination, while national authorities supervise most providers and deployers within their territory.
- The AI Office only writes voluntary guidelines and has no enforcement-related powers.
Show Answer
Answer: B) The AI Office focuses on GPAI and cross-border coordination, while national authorities supervise most providers and deployers within their territory.
The AI Office does not replace national authorities. It leads on GPAI, systemic risks, and EU-wide coordination, while national competent and market surveillance authorities supervise most day-to-day compliance in their own Member States.
Step 10 – Key Terms Review
Flip through these flashcards to reinforce core governance and enforcement concepts from the AI Act.
- European AI Office
- A specialized structure within the European Commission that leads on general-purpose AI supervision, systemic risks, and cross-border coordination, and supports guidance, investigations, and enforcement under the AI Act.
- European AI Board
- An EU-level coordination body composed of national authorities and the Commission. It issues opinions and recommendations to ensure consistent application of the AI Act across Member States.
- National Competent Authority (NCA)
- A national regulator designated by each Member State to supervise AI Act compliance, receive incident reports, conduct investigations, and often run regulatory sandboxes.
- Market Surveillance Authority (MSA)
- A national authority responsible for checking that products, including AI systems as products or safety components, comply with EU rules. It can inspect, test, and order corrective measures or withdrawals.
- Regulatory Sandbox (AI Act context)
- A controlled environment run by a national authority where organizations can develop and test AI systems under supervision, with tailored regulatory conditions but preserved safety and fundamental rights protections.
- General-Purpose AI (GPAI) Provider
- An organization that develops and places on the market a general-purpose AI model that can be used for many downstream tasks. Under the AI Act, such providers face specific obligations and oversight by the AI Office.
Key Terms
- European AI Board
- EU coordination body of national AI authorities and the Commission that promotes consistent application of the AI Act and issues opinions and recommendations.
- European AI Office
- Specialized body within the European Commission that oversees general-purpose AI, systemic risks, and coordinates AI Act implementation and enforcement at EU level.
- Regulatory Sandbox
- A supervised environment set up by a regulator where organizations can test innovative AI systems under controlled conditions, with tailored regulatory requirements.
- Corrective Measures
- Actions ordered by authorities to remedy non-compliance, such as bringing a system into conformity, restricting or banning its use, or withdrawing it from the market.
- Administrative Fines
- Monetary penalties imposed by authorities for breaches of the AI Act, calibrated to be effective, proportionate, and dissuasive, sometimes based on global annual turnover.
- Systemic-risk GPAI model
- A general-purpose AI model whose capabilities, scale, or impact create significant systemic risks across sectors and Member States, triggering additional obligations and oversight.
- General-Purpose AI (GPAI)
- AI models that can be used for a wide range of tasks and applications, including foundation models; they are subject to specific obligations under the AI Act.
- National Competent Authority (NCA)
- Regulator designated by each EU Member State to supervise AI Act compliance in its territory, including investigations and guidance.
- Market Surveillance Authority (MSA)
- National authority that checks whether products, including AI systems as products or safety components, comply with EU rules and can order corrective actions.