The Week in One Line
The EU AI Act’s enforcement infrastructure already exists. National authorities, investigation powers, and fining mechanisms are not future concepts. They are operational now.
What the Act Actually Says
The enforcement structure operates at two levels:
• the EU AI Office
• national market surveillance authorities
The EU AI Office, established within the European Commission, oversees General Purpose AI model obligations and coordinates enforcement activity across member states.
At the national level, EU member states were required to designate competent authorities responsible for supervising and enforcing the Act by August 2025. Most have already done so.
Those authorities have powers to:
• conduct investigations
• request documentation
• require corrective action
• order withdrawal of systems
• impose financial penalties
Under Article 99, the penalty structure has three tiers:
• prohibited practices: up to €35 million or 7% global annual turnover
• non-compliance with high-risk obligations: up to €15 million or 3% global annual turnover
• providing misleading information: up to €7.5 million or 1% global annual turnover
The Act also includes whistleblowing mechanisms allowing individuals to report suspected violations directly to authorities.
A surprising number of organisations still speak about the AI Act as if enforcement begins years from now. Operationally, the enforcement structure already exists.
Source: artificialintelligenceact.eu – Article 99, Implementation Timeline
What This Means for Your Business
The GDPR comparison is appropriate here, but many organisations are still underestimating the operational reality.
The AI Act’s maximum penalty threshold is higher than GDPR’s.
Companies that delayed GDPR preparation until enforcement activity started are at risk of repeating the same mistake with AI governance.
This is not a future risk.
Authorities already exist. Reporting channels already exist. Investigation powers already exist.
If a company deploys non-compliant high-risk AI systems after the relevant deadlines, national authorities already have the legal power to intervene.
The whistleblowing mechanism is especially important operationally.
Employees, contractors, or affected individuals can report suspected violations directly to authorities. That means weak internal governance processes are no longer just a compliance weakness. They become a reporting risk.
Most compliance failures will probably not come from intentionally harmful AI deployments.
They will come from:
• missing documentation
• unclear ownership
• poor monitoring
• lack of escalation paths
• informal AI adoption without governance visibility
Incident reporting obligations also matter more than many companies realise. Under Article 26, deployers identifying serious incidents involving high-risk systems must notify providers and authorities without delay.
Many organisations currently do not even have a defined process for identifying what qualifies as a reportable AI incident.
This Week’s Action Point
Identify the AI Act enforcement authority in every EU country where your business operates.
Document:
• authority name
• reporting website
• contact details
• incident reporting channels
Then ask internally:
“If we had to report a serious AI incident tomorrow, who would actually own that process?”
A surprising number of organisations cannot answer that question clearly yet.
Further Reading
Article 99 – Penalties: artificialintelligenceact.eu/article/99
EU AI Act Implementation Timeline: artificialintelligenceact.eu/implementation-timeline
Whistleblowing and the EU AI Act: artificialintelligenceact.eu/whistleblowing
EU AI Office: digital-strategy.ec.europa.eu/en/policies/ai-office