EU AI Office (European Commission)

Type: regulator Sector: EU AI regulation First seen: 2026-03-20 Last updated: 2026-08-03

Updated 2026-08-03 based on S-2026-07-31-ec-ai-act-enforcement-begins — the Commission confirmed (press release, 31 July 2026) that the AI Office, together with national authorities, began enforcing the AI Act on 2 August 2026, with the Article 50 transparency obligations applying from the same date (now past as of this run). The AI Office’s GPAI enforcement powers (technical-documentation requests, model evaluations, corrective measures, fines) are now live, and the Commission published a first list of 180+ organisations that have signed the voluntary Code of Practice on transparency of AI-generated content. Positions bullet, tracked-change entry and Source link added; reinforcing — moves the AI Office’s remit from “enforcement signalled” to “enforcement commenced”; no contradiction. Updated 2026-07-30 based on S-2026-07-20-eu-ai-office-transparency-guidelines — the Commission/AI Office published final Guidelines on the Article 50 transparency obligations for providers and deployers of AI systems on 20 July 2026, clarifying the scope of the obligations 13 days before they start to apply on 2 August 2026. This moves the Article 50 transparency track from the 8 May 2026 draft guidelines and the 10 June 2026 voluntary content-marking Code to final published interpretive Guidelines. Positions bullet, tracked-change entry and a Source link added; reinforcing — no contradiction. Updated 2026-07-24 based on S-2026-06-29-council-ai-omnibus-final-adoption — the Council gave final adoption to the Digital Omnibus on AI (“Omnibus VII”) on 29 June 2026. Materially for the AI Office: the enacted text clarifies the AI Office’s competence over AI systems built on same-provider GPAI models by listing exceptions where national authorities remain competent — including financial institutions (alongside law enforcement, border management and judicial authorities). It also postpones the national AI-sandbox deadline to 2 August 2027 (⚠️ supersedes the 2 Aug 2026 date in Positions), cuts the AI-generated-content transparency grace period to 3 months (new deadline 2 December 2026), and confirms the CSAM/deepfake ban from December 2026. Positions bullets, tracked-change entries and a Source link added. Reinforcing on the AI Office’s remit; the sandbox-date change is a supersession, handled explicitly. Updated 2026-07-09 based on S-2026-07-07-ec-ai-cybersecurity-action-plan — the Commission presented the EU Action Plan on Cybersecurity and Artificial Intelligence (7 July 2026). Materially for the AI Office: the Commission will help establish an EU evaluation capacity to strengthen third-party assessment of advanced-AI capabilities and risks, explicitly “supporting the regulatory function of the AI Office”, plus an ENISA structured-access blueprint and an ENISA/JRC secure testing platform (Q4 2026). New Positions bullet, tracked-change entry and Source link added. Reinforcing (extends the AI Office’s evaluation/oversight remit); no contradiction. Updated 2026-07-01 based on S-2026-07-01-ec-highrisk-consultation-extension-confirmed — direct retrieval of the primary Commission consultation page confirms the high-risk classification guidelines consultation was extended from 23 June to 23 July 2026, with final guidelines adopted by end-2026. ✅ Resolves the tension flagged on 2026-06-26. Tracked-change entry updated. Updated 2026-06-26 based on S-2026-06-26-ec-high-risk-guidelines-page — direct retrieval of the Commission’s high-risk classification guidelines policy page provides primary evidence on the contested consultation deadline: the page states the consultation is “open until 23 June 2026”, but is itself stamped “Last update 19 May 2026”, so it corroborates the original 23 June date without disproving the separately-reported extension to 23 July 2026. ⚠️ Tension preserved (see EU AI Act). Tracked-change note and source link added. Updated 2026-06-16 based on S-2026-06-eu-ai-office-external-evaluators — the AI Office is gathering expert input on independence and qualification requirements for external evaluators of GPAI models with systemic risk (workshop scheduled 15 July 2026), advancing the still-incomplete GPAI systemic-risk evaluation machinery. Positions bullet and tracked-change entries added. ⚠️ Search-derived; exact instrument and dates unconfirmed against a primary page. Updated 2026-06-12 based on S-2026-06-10-eu-ai-office-content-marking-code-final — the AI Office published the final voluntary Article 50 Code of Practice on marking and labelling of AI-generated content on 10 June 2026 (press release IP/26/1328), with a signature process and a standard set of EU labelling icons. This confirms and supersedes the prior run’s ⚠️ unverified flag. Position bullet and tracked-change entry updated. Updated 2026-06-11 based on S-2026-06-11-eu-ai-office-content-marking-code — the AI Office’s Article 50 Code of Practice on marking and labelling of AI-generated content reached its closing-plenary / final-publication window (May–June 2026 per the official policy page, last updated 22 May 2026); two working groups (providers: machine-readable marking; deployers: deepfake / public-interest-text disclosure) feed a voluntary compliance tool for Article 50(2)/(4), with the transparency rules applying 2 August 2026. ⚠️ A secondary source claims the final code was published ~10 June 2026; not confirmed on the official page — flagged pending verification. Position bullet and tracked-change entry added. Updated 2026-06-08 based on S-2026-05-22-eu-ai-office-prohibitions-highrisk-review — Commission’s first Article 112(1) annual review report on the prohibitions and high-risk list (22 May 2026) added; positions bullet and tracked-change entry added.

Snapshot

The European Commission’s AI Office is the EU body responsible for EU AI Act implementation, GPAI oversight, the GPAI Code of Practice, and supplementary guidance including Article 50 transparency and watermarking. Pivotal to the wiki because every AI Act timeline decision flows through the AI Office, including the contested Digital Omnibus delay proposal.

Positions / Claims they advance

  • Full enforcement of obligations for GPAI providers — including fines — begins 2 August 2026 [S-2026-04-29-eu-ai-office-gpai].
  • Pre-2 August 2025 GPAI models on the market have until 2 August 2027 [S-2026-04-29-eu-ai-office-gpai].
  • Member States must have AI regulatory sandboxes in place by 2 August 2026superseded (2026-07-24): the adopted Digital Omnibus postpones the national AI-sandbox establishment deadline to 2 August 2027 [S-2026-06-29-council-ai-omnibus-final-adoption]; original date [S-2025-11-19-eu-digital-omnibus].
  • Under the adopted Digital Omnibus (29 June 2026), the AI Office’s supervisory competence over AI systems built on same-provider GPAI models is clarified, with exceptions where national authorities remain competent — including financial institutions, law enforcement, border management and judicial authorities [S-2026-06-29-council-ai-omnibus-final-adoption]. The regulation also cuts the AI-generated-content transparency grace period to 3 months (new deadline 2 December 2026) and confirms the CSAM/deepfake-nudification ban from December 2026 [S-2026-06-29-council-ai-omnibus-final-adoption].
  • Guidelines on the scope of obligations for GPAI providers published in all 24 EU official languages [S-2026-04-29-eu-ai-office-gpai].
  • Article 50 transparency / labelling Code of Practice in working-group iteration November 2025 – May 2026; guidelines in preparation for Q2 2026 publication; November 2026 watermarking referenced [S-2026-04-29-eu-ai-office-gpai]. The drafting exercise reached its Closing Plenary / final-code publication window (May–June 2026), organised around a Providers working group (machine-readable marking of audio/image/video/text, effective/interoperable/robust/reliable as technically feasible) and a Deployers working group (deepfake and AI-generated public-interest-text disclosure); the final code, once Commission-approved, is a voluntary tool to demonstrate compliance with Article 50(2)/(4), with parallel Commission guidelines covering scope [S-2026-06-11-eu-ai-office-content-marking-code]. The final Code was published on 10 June 2026 (press release IP/26/1328): voluntary, with signatories committing to visually disclose AI-generated content via a standard set of EU AI Office icons, plus a signature process, Q&A and an info session — confirming the publication previously flagged as unverified [S-2026-06-10-eu-ai-office-content-marking-code-final].
  • EU AI Continent Action Plan published 9 April 2026.
  • Targeted consultation on AI energy consumption (April 2026).
  • AI Office / Commission missed the statutory 2 February 2026 deadline to publish Article 6 high-risk classification guidelines [S-2026-04-29-eu-ai-office-gpai]. ⚠️ Update: draft guidelines on high-risk classification were subsequently issued 19 May 2026, with a targeted stakeholder consultation open until 23 June 2026; the guidelines are non-binding but reflect the Commission’s interpretation and “will guide enforcement” [S-2026-05-19-eu-ai-office-high-risk-draft].
  • Non-compliance fines: up to 6% of global annual turnover (GPAI) [S-2026-04-29-eu-ai-office-gpai].
  • In June 2026 began gathering expert input on independence and qualification requirements for external evaluators of GPAI models with systemic risk, with a dedicated workshop scheduled 15 July 2026 — operationalising the GPAI Code of Practice Safety & Security commitment that signatories grant independent external evaluators access to advanced model versions, and moving to coordinate consistent standards for an external-evaluation ecosystem regarded as still immature [S-2026-06-eu-ai-office-external-evaluators].
  • Under the EU Action Plan on Cybersecurity and Artificial Intelligence (7 July 2026), the Commission will help establish an EU evaluation capacity for third-party assessment of advanced-AI capabilities and risks, explicitly to support the AI Office’s regulatory function, alongside an ENISA structured-access blueprint for advanced AI and an ENISA/JRC secure testing platform (Q4 2026) for critical sectors; the plan builds on the AI Act, Cyber Resilience Act, NIS2 and Cyber Solidarity Act [S-2026-07-07-ec-ai-cybersecurity-action-plan].
  • Published final Guidelines on the Article 50 transparency obligations for providers and deployers of AI systems on 20 July 2026, clarifying the scope of the duties ahead of the 2 August 2026 applicability date: providers must inform users when they are directly interacting with an AI and add machine-readable marks to AI-generated/manipulated content; deployers must disclose deep fakes, AI-generated public-interest content published without human review or editorial control, and emotion-recognition / biometric-categorisation systems. Accompanied by an Article 50 Q&A, a Quick Facts page and the (10 June 2026) voluntary Code of Practice on Transparency of AI-Generated Content [S-2026-07-20-eu-ai-office-transparency-guidelines].
  • Confirmed (press release, 31 July 2026) that enforcement of the AI Act by the AI Office and national authorities began on 2 August 2026, alongside the start of the Article 50 transparency obligations: interactive AI must disclose it is AI, deep fakes must be labelled, and AI-generated/altered content must carry machine-readable marks. The AI Office’s enforcement powers over GPAI models (documentation requests, model evaluations, corrective measures, fines) are now live, and the Commission published a first list of more than 180 organisations that have signed the voluntary Code of Practice on transparency of AI-generated content [S-2026-07-31-ec-ai-act-enforcement-begins].
  • Adopted its first Article 112(1) annual review report on the Article 5 prohibitions and Annex III high-risk list (22 May 2026), concluding substantive review is early-stage (prohibitions only applied since 2 Feb 2025; enforcement not yet in force; needs ≥1 year of practice and the high-risk classification guidelines); flags a CSAM / non-consensual-intimate-content gap (addressed by the 7 May AI Omnibus) and positions sandboxes as the evidence-collection mechanism [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review].

Relationships

  • regulates → EU AI Act — administers and enforces the regulation (GPAI oversight, Code of Practice, guidance).
  • part-of → European Commission — parent body.
  • partners-with → EU Council — co-legislator on Digital Omnibus.
  • partners-with → European Parliament — co-legislator on Digital Omnibus.
  • relates-to → CEN-CENELEC JTC 21 — harmonised standards (notably prEN 18286).
  • relates-to → EBA — AI Act mapping exercise outputs.
  • relates-to → ESMA — coordinated supervisory implementation.

Tracked changes

  • 2025-08-02 — GPAI provider obligations begin to apply.
  • 2025-11-19 — Commission adopts Digital Omnibus on AI simplification proposal.
  • 2026-02-02 — Statutory deadline for Article 6 high-risk classification guidelines missed.
  • 2026-03-13 — Code of Practice 2nd draft on marking and labelling; Council position on Digital Omnibus.
  • 2026-03-26 — European Parliament adopts position on Digital Omnibus.
  • 2026-04-09 — EU AI Continent Action Plan published.
  • 2026-04-28 (target) — Trilogue first agreement on Digital Omnibus.
  • 2026-05-19 — Commission issues draft guidelines on the classification of high-risk AI systems with worked examples; targeted consultation open until 23 June 2026 [S-2026-05-19-eu-ai-office-high-risk-draft].
  • 2026-05-22 — Commission adopts first Article 112(1) annual review report on the prohibitions and high-risk list [S-2026-05-22-eu-ai-office-prohibitions-highrisk-review].
  • 2026-05–06 (May–June 2026) — Closing Plenary / publication window for the final Article 50 Code of Practice on marking and labelling of AI-generated content (publication date unconfirmed at the time) [S-2026-06-11-eu-ai-office-content-marking-code].
  • 2026-06-10 — Final Article 50 Code of Practice on marking and labelling of AI-generated content published (voluntary; EU labelling icons; signature process); press release IP/26/1328 [S-2026-06-10-eu-ai-office-content-marking-code-final].
  • 2026-06 — Call for expert input on independence and qualification requirements for external evaluators of GPAI models with systemic risk [S-2026-06-eu-ai-office-external-evaluators].
  • 2026-06-23 → extended to 2026-07-23 — Consultation on draft high-risk classification guidelines: originally set to close 23 June 2026, extended to 23 July 2026 (confirmed on the primary Commission consultation page, retrieved 1 July 2026); final guidelines to be adopted end-2026 [S-2026-07-01-ec-highrisk-consultation-extension-confirmed][S-2026-05-19-eu-ai-office-high-risk-draft].
  • 2026-06-29Council gives final adoption to the Digital Omnibus on AI (Omnibus VII); clarifies AI Office competence over same-provider GPAI-based systems with a financial-institutions carve-out to national authorities, postpones national AI sandboxes to 2 Aug 2027, cuts the AI-content transparency grace period to 3 months (deadline 2 Dec 2026), and confirms the CSAM/deepfake ban from Dec 2026. Act reported signed 8 July 2026, awaiting OJ publication [S-2026-06-29-council-ai-omnibus-final-adoption].
  • 2026-07-07 — Commission presents the EU Action Plan on Cybersecurity and Artificial Intelligence; announces an EU evaluation capacity supporting the AI Office, an ENISA structured-access blueprint, and an ENISA/JRC secure testing platform (Q4 2026) [S-2026-07-07-ec-ai-cybersecurity-action-plan].
  • 2026-07-15 (scheduled) — Workshop on qualification requirements for external evaluators of GPAI models with systemic risk [S-2026-06-eu-ai-office-external-evaluators].
  • 2026-07-20Final Guidelines on Article 50 transparency obligations published (scope clarification for providers and deployers; interactive-AI notice, machine-readable marking, deep-fake / public-interest / emotion-recognition disclosures), 13 days before the 2 Aug 2026 applicability date; press release IP/26/1653 [S-2026-07-20-eu-ai-office-transparency-guidelines].
  • 2026-07-31 — Commission press release confirms AI Act enforcement (AI Office + national authorities) and Article 50 transparency obligations commence 2 August 2026; interactive-AI disclosure, deep-fake labelling and machine-readable marking now live; GPAI enforcement powers active; first list of 180+ signatories to the voluntary content-transparency Code of Practice; press release IP/26/1714 [S-2026-07-31-ec-ai-act-enforcement-begins].
  • 2026-08-02Core AI Act obligations apply; GPAI enforcement begins (confirmed commenced per the 31 July 2026 press release). (Sandbox requirement moved to 2 Aug 2027 by the adopted Digital Omnibus [S-2026-06-29-council-ai-omnibus-final-adoption].)
  • 2026-12-02 (scheduled) — New deadline for providers’ transparency solutions for AI-generated content (grace period cut to 3 months); CSAM/deepfake-nudification ban applies from December 2026 [S-2026-06-29-council-ai-omnibus-final-adoption].
  • 2027-08-02 (scheduled) — National AI regulatory sandboxes required (postponed from 2 Aug 2026) [S-2026-06-29-council-ai-omnibus-final-adoption].
  • 2026-11 (referenced) — Watermarking requirement.
  • 2027-08-02 (scheduled) — Legacy GPAI models compliance deadline.

Sources