Skip to main content
Should the AI Office Enforce Before It's Fully Resourced?EU AI Act & GPAI
5 min readFor AI Governance Leaders

Should the AI Office Enforce Before It's Fully Resourced?

The EU AI Office gained full enforcement powers over General-Purpose AI Models on August 2nd. The question now is whether the Office should act aggressively or wait until it's fully equipped.

This isn't just theoretical. The Office is tasked with overseeing some of the world's most powerful AI systems while still hiring staff, establishing technical capabilities, and defining enforcement protocols. Opinions vary on what responsible implementation looks like.

The Timing Dilemma

The AI Office faces a timing challenge. Incidents involving General-Purpose AI Models are increasing. The code of practice is finalized, and guidelines are published, but the Office's technical infrastructure and staffing are still developing.

Should enforcement wait for readiness, or does waiting create more risk than acting?

Your answer will shape how you advise your organization on compliance timelines, documentation priorities, and engagement with EU authorities.

The Case for Immediate Enforcement

Some argue that waiting sends the wrong message. The AI Act was concluded before the European elections of June 2024, and the code of practice involved extensive industry input. Providers have had time to prepare.

The threat landscape won't pause for administrative convenience. Consider incidents like agents compromising websites and non-consensual content generation. Each month of delayed enforcement is a month where high-risk deployments proceed without oversight.

This view holds that the Office should use information requests, preliminary assessments, and transparency enforcement immediately. You don't need a fully staffed lab to verify whether a provider submitted required documentation or responded to an incident report. Early action's deterrent effect matters more than the precision of early penalties.

Credibility is at stake. The world is watching whether Europe can operationalize what it legislated. If the AI Office waits 18 months to issue its first enforcement action, the regulation loses impact before it gains it. Industry learns that compliance is optional until enforcement becomes routine.

For governance teams, this means treating August 2nd as a hard deadline. Your Technical Documentation (Annex IV) should be audit-ready now. Your incident response protocols should assume the Office will ask questions within days, not quarters. Your risk assessments for systemic risk models should be complete, not in draft.

The Case for Capacity-First Implementation

The counter-argument is that premature enforcement could lead to worse outcomes than delayed enforcement.

The AI Office is building novel oversight capabilities. There's no template for evaluating whether a foundation model's red teaming was sufficient or whether its training data filtering met copyright obligations. These are complex, legally novel judgments.

Acting before the scientific panel is fully operational and before technical testing infrastructure exists risks arbitrary decisions. Worse, it risks decisions that get overturned on procedural grounds, weakening the Office's authority for years.

This view emphasizes that the EU AI Act is a multi-year implementation project. The high-risk AI system requirements don't fully apply until 2027, because complex technical standards take time to develop. Why should General-Purpose AI Model oversight be different?

There's also a risk of fragmentation. If the AI Office acts without clear methodologies, national authorities will interpret requirements differently. A model approved in one member state could face challenges in another. The single market benefit of EU-wide regulation disappears.

For practitioners, this suggests a phased approach. Prioritize transparency obligations and documentation completeness now. Expect substantive technical assessments to ramp up over 12 to 18 months. Use this period to refine your internal validation processes, knowing that enforcement standards will clarify through early cases.

Oversight of rapidly evolving AI systems requires specialized expertise in ML security, bias evaluation, capability assessment, and adversarial testing. Building that capacity responsibly takes time. Rushing it produces checklist compliance, not meaningful risk reduction.

Where Practitioners Actually Land

Most governance teams are preparing for hybrid enforcement: aggressive on process, gradual on substance.

They expect the AI Office to act quickly on transparency failures, documentation gaps, and incident response obligations. These don't require deep technical assessment. If your model meets the systemic risk threshold and you haven't submitted required information, expect consequences.

But they're not expecting immediate judgments on whether your red teaming was adequate or your capability evaluations sufficient. Those determinations require the Office to develop assessment frameworks, validate methodologies, and build technical capacity.

This creates a practical compliance priority: get your procedural house in order immediately, while continuing to strengthen your substantive risk management over the next year.

That means your code of practice compliance documentation should be complete. Your designated contact points should be established. Your incident logging should be operational. Your systemic risk self-assessment should be on file, even if you expect to refine it.

But it also means you're not waiting for perfect clarity before acting. You're building risk management capabilities that exceed what you expect enforcement to require in year one, knowing that standards will tighten.

Our Take

The AI Office should enforce procedural requirements immediately and build toward substantive technical enforcement over 12 months.

Here's why: transparency and documentation obligations are the foundation of everything else. If providers won't submit basic information, technical oversight is impossible. Early enforcement on process creates the conditions for credible technical oversight later.

But attempting complex technical judgments before methodologies are validated risks undermining the entire framework. Better to be deliberate about building assessment capabilities than to rush into enforcement actions that don't hold up.

For your team, this means:

  • Document everything now. Assume any gap in your Technical Documentation (Annex IV) or code of practice compliance records will be identified in the next six months.
  • Engage proactively. If you're operating a systemic risk model, establish communication channels with the AI Office before they request information. Demonstrate good faith compliance.
  • Build ahead of enforcement. Your risk management should be more rigorous than what you expect the AI Office to require in 2025. Standards will tighten, and you want to be ahead of the curve, not catching up.

The timing dilemma is real, but it's not binary. Enforcement can be both immediate and thoughtful if it sequences correctly. The AI Office's credibility depends on acting where it has clear authority while building capacity for the harder technical judgments ahead.

Your compliance strategy should mirror that approach: be ready for process enforcement now, while preparing for substantive technical oversight that will define the regulation's effectiveness over the next several years.

You Might Also Like