The EU’s long-awaited AI Act finally gets teeth on Sunday. The freshly appointed AI Office, together with national authorities, begins enforcing rules designed to make artificial intelligence safer and more transparent.

Under the new rules, organisations will have to tell users if they are dealing with AI chatbots or other interactive AI systems, and not a human. So-called deepfakes—images, videos, or audio that have been edited or generated using AI—will have to be labelled with machine-readable marks to make them easier to detect. And, from a copyright perspective, providers will have to publish a detailed summary of the content used to train their models.

Break these rules and the AI Office, which is part of the European Commission, will be able to pull models off the EU market and impose fines of up to three per cent of annual total turnover. 

According to Brando Benifei (S&D/ITA), rapporteur for the file, the AI Office is the world’s first authority with real investigative and enforcement powers over advanced AI models. “Recent incidents involving OpenAI hacking agents and the Claude Mythos saga show why corporate self-reporting is not enough. The Commission must give the Office the political backing, resources, and technical expertise to act immediately, secure model access, conduct independent evaluations, and impose corrective measures. The world is watching,” he told EU Perspectives.

You might be interested

Meet the AI watchdog

Part of the work of the office will be to conduct safety evaluations and order corrective measures. To this end, the AI Office will have the power to demand information from model providers.

“Effective enforcement will also depend on member states ensuring that national competent authorities are properly designated and adequately resourced,” said the Commission. However some have voiced concerns that the AI Office itself is not “adequately resourced”. With a team of fewer than 40, the Commission is on a recruitment drive to secure people with the appropriate skills and experience to police the whole sector.

They will be supported by a Scientific Panel, an expert advisory body made up of 60 independent AI experts led by Professor Alessandro Abate of the University of Oxford’s Department of Computer Science as Lead Scientific Adviser. 

“Harms can occur if AI is not properly designed and used, and the most advanced models create risks on an entirely new scale. Europe anticipated this development,” said Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy

Not all AI is created equal

Not every part of the AI Act is taking effect at once. The AI Act is a risk-based framework, distinguishing between different AI models. The the rules that come into force on Sunday cover only providers of “general-purpose AI” (GPAI) models.

The AI Omnibus postponed the application of the rules on “high-risk AI systems” to 2 December 2027. It also delayed the rules for high-risk AI systems integrated into regulated products to 2 August 2028. 

Nonetheless, general purpose AI models are among the largest, wealthiest and most dangerous parts of the AI ecosystem. They may pose systemic risks including to European cybersecurity and AI acting outside human control. 

Certain AI practices are also explicitly banned, including systems that “manipulate people, exploit vulnerabilities in harmful ways, or unfairly score people in ways that threaten their rights”.

How will it work?

The enforcement will go hand-in-hand with a voluntary Code of Practice that more than 180 organisations have signed up to including Anthropic, Google, IBM, Mistral, OpenAI and Microsoft.

There is also a Complaint Tool where third party individuals or companies can report alleged infringements of the AI Act by providers of AI systems. People working within companies providing general-purpose AI models can use the Whistleblower Tool to report possible violations of the Act securely. 

Finally, responsibility for enforcing the rules for AI systems offered by the same provider as the underlying general-purpose AI model, or those systems integrated into very large online platforms/search engines falls to the AI Office. National competent authorities enforce the rules for other AI systems.

According to the Commission, the measures are intended to reduce deception and manipulation and help people make informed choices. They also give businesses clearer obligations and a practical way to show compliance. “As AI grows increasingly capable and integrated into everyday life, the AI Act helps ensure that AI is developed, deployed, and used safely, giving people and businesses across the EU greater confidence in the technology.”