Skip to main content
Authority

EU AI Office

The European AI Office is a body inside the European Commission, not an EU agency. It directly supervises general-purpose AI models. It does not supervise the AI systems inside your bank or insurer: those are supervised by your existing financial regulator, and their compliance date moved from August 2026 to 2 December 2027.

Checked by Remmert
6 min read

What is the AI Office?

The AI Office is a body inside the European Commission, not a separate EU agency. It was established by a Commission Decision of 24 January 2024 and sits inside DG CNECT (Commission Decision). It employs more than 125 staff across six units: Excellence in AI and Robotics, Regulation and Compliance, AI Safety, AI Innovation and Policy Coordination, AI for Societal Good, and AI in Health and Life Science, plus a Lead Scientific Adviser. It is recruiting around 40 additional contractual agents for enforcement roles, with an application deadline of 8 September 2026 (AI Office).

It is supported by an AI Board of member state representatives, which had met eight times by 11 June 2026, and a scientific panel of 60 independent experts established under Commission Implementing Regulation (EU) 2025/454.

Last updated 17 August 2026. Written three weeks after Regulation (EU) 2026/1744 entered into force on 27 July 2026 and two weeks after AI Act enforcement began on 2 August 2026.

Who actually supervises AI in a financial institution?

Not the AI Office. Its direct competence covers general-purpose AI models, including those with systemic risk. High-risk AI systems are supervised by national market surveillance authorities, and Article 74(6) of Regulation (EU) 2024/1689 routes financial institutions to their existing supervisor: the authority already responsible for prudential or conduct supervision under EU financial services law acts as the AI Act market surveillance authority for that institution's high-risk AI systems.

In practice:

  • Germany. BaFin was designated market surveillance authority for AI systems used by financial entities under the German AI Act implementing law, in force since 29 July 2026 (BaFin press release).
  • Netherlands. The draft implementing act published for consultation on 20 April 2026 designates ten authorities, including AFM and DNB for the financial sector, with the AP and RDI coordinating. The Dutch bill has not yet passed. It must still clear both chambers.

If you are a Dutch institution asking who your AI supervisor is, the honest answer as at August 2026 is: probably the AFM or DNB, but the law saying so is not yet in force.

Which AI uses in finance are high-risk?

Annex III of the AI Act names two use cases that sit squarely in financial services: creditworthiness evaluation of natural persons, and risk assessment and pricing in relation to life and health insurance (Commission AI Act FAQ).

Separately, three prohibited practices reach into finance and have applied since 2 February 2025: social scoring, whether by public or private actors; exploitation of vulnerabilities or manipulation through subliminal techniques; and biometric categorisation inferring protected characteristics. The AI literacy obligation in Article 4 has applied since the same date, and it applies to every deployer, not only to high-risk users.

What does the AI Office publish?

The General-Purpose AI Code of Practice, published in final form on 10 July 2025 and due for review at least every two years; guidelines, most recently on the Article 50 transparency obligations, published 20 July 2026; templates, including the model training-content summary; standardisation requests to CEN-CENELEC; and the AI Act Service Desk, a single information platform with an AI Act Explorer and a compliance checker at ai-act-service-desk.ec.europa.eu.

The GPAI Code of Practice has 21 confirmed signatories, with one further partial signatory to the safety and security chapter only. The separate Code of Practice on Transparency of AI-generated Content had roughly 180 to 190 signatory organisations as at 31 July 2026.

What has the AI Office published recently?

As at 17 August 2026. Fed by our monitoring pipeline, not hand-maintained.

DatePublication or milestone

What is the AI Act timeline, as it now stands?

This is the section most often out of date elsewhere: the schedule changed three weeks before this page was written. Regulation (EU) 2024/1689 has applied since 1 August 2024 as originally adopted.

DateWhat applies

What changed under the Digital Omnibus?

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was proposed 19 November 2025, adopted 8 July 2026, and has been in force since 27 July 2026.

ObligationOriginal dateNew date

Nothing else moved. Prohibitions, AI literacy, general-purpose AI obligations and the Article 50 transparency requirements all apply on their original dates. If you deploy a customer-facing chatbot, the transparency duty to disclose that it is AI has applied since 2 August 2026: the delay does not touch it.

What are the penalties?

Article 99 sets three tiers, each expressed as the higher of a fixed amount and a percentage of global annual turnover, with SMEs subject to the lower of the two:

  • prohibited practices and data-governance violations: up to €35 million or 7%
  • other obligations, including most high-risk system duties: up to €15 million or 3%
  • supplying incorrect or misleading information to authorities: up to €7.5 million or 1%

Who imposes them depends on what is being enforced. The Commission, through the AI Office, enforces against providers of general-purpose AI models. For high-risk systems, the fine comes from the national market surveillance authority. For a financial institution, that is its own financial supervisor. We found no published AI Office enforcement action as at 17 August 2026.

What changes for a mid-sized institution?

The Act gives SMEs simplified compliance pathways for some of the more burdensome obligations, technical documentation among them. Article 57 requires every member state to establish at least one AI regulatory sandbox, and the Digital Omnibus expands sandbox access beyond SMEs to small mid-cap companies. In the Netherlands, the AP and RDI are due to launch a joint sandbox during 2026.

The more consequential change for a mid-sized bank or insurer is the fifteen-month extension on Annex III. Credit-scoring and insurance-pricing models that were due to meet high-risk requirements this month now have until 2 December 2027, which is either relief or a planning trap, depending on whether the extra time gets used.

What can GenCompl.ai do for you?

We track the AI Act file across three moving parts at once: the EU text and its amendments, the national implementing laws that decide who supervises you, and the guidance stream from the AI Office. Each is dated separately, because they do not move together. Germany's implementing law was in force on 29 July 2026 while the Dutch equivalent was still a bill. That gap is exactly the sort of thing a single "AI Act compliance" checklist hides.

Regulations

  • EU Artificial Intelligence Act (EU AI Act)

    The EU AI Act is Regulation (EU) 2024/1689. On 2 August 2026 its transparency rules and enforcement machinery took effect, but the high-risk regime for credit scoring and life and health insurance pricing did not: Regulation (EU) 2026/1744 moved it to 2 December 2027. Prohibitions have applied since February 2025.

    NextNew Art. 5 prohibitions; Art. 50(2) marking deadline for pre-existing generative systems

    Checked