Skip to main content
When the EU AI Office Gets New Powers and No One NoticesEU AI Act & GPAI
5 min readFor AI Governance Leaders

When the EU AI Office Gets New Powers and No One Notices

What Happened

Between November 2025 and January 2026, the European Commission quietly restructured AI Act enforcement. This was done through two moves: the Digital Omnibus on AI (published 19 November 2025) and enhanced inspection powers for the AI Office detailed in a second Council compromise text. The AI Office gained authority to examine company books, question staff, take data copies, and request national watchdogs to investigate on its behalf. Meanwhile, the Digital Omnibus proposed amendments to "simplify" the AI Act, with high-risk AI rules set to apply from 2 August 2026.

This isn't a breach or system failure. It's a governance failure: stakeholders discovered fundamental changes to enforcement authority and compliance obligations buried in omnibus legislation, with insufficient time to assess the impact before application dates arrived.

Timeline

  • 2 August 2025: General-Purpose AI Model provider rules take effect
  • 19 November 2025: Commission publishes Digital Omnibus on AI
  • 30 January 2026: AI Office launches Signatory Taskforce for General-Purpose AI Code of Practice compliance
  • 2 August 2026: High-risk AI system obligations scheduled to apply
  • Present: Harmonised standards still unpublished; national competent authorities not fully designated

Which Controls Failed or Were Missing

Stakeholder Notification and Comment Period

The omnibus approach compressed review timelines for changes affecting fundamental rights safeguards. Access Now and civil society organizations discovered the proposed deletion of Article 49(2) transparency requirements only after publication. This provision requires providers to disclose when they exempt high-risk AI systems from certain obligations. Without it, market surveillance authorities can't track exemptions across member states, and the public can't identify which providers opted out of high-risk categories.

Impact Assessment for Structural Changes

The omnibus introduced what ALLAI characterized as "significant structural changes amounting to deregulation" without corresponding impact analysis. Extending SME-style compliance privileges to Small Mid-Caps would apply lighter obligations to approximately 99 percent of EU companies, tying compliance to organizational size rather than risk level. The AI Act's risk-tiering principle explicitly rejects this approach: a high-risk AI system poses equivalent harm regardless of provider size.

Coordination Between Standards Development and Enforcement Timelines

High-risk AI obligations apply on 2 August 2026, yet harmonised standards remain unpublished. DIGITALEUROPE noted that European machinery manufacturers, medical technology firms, and industrial software developers can't demonstrate conformity without these standards. The enforcement structure itself remains incomplete, with national competent authorities not fully designated.

Separation of Simplification from Deregulation

The omnibus framed changes as "simplification to reduce regulatory burden" while simultaneously weakening core safeguards. Downgrading AI literacy from a binding requirement to a policy objective eliminates accountability mechanisms. Removing fundamental rights authorities' direct documentation access threatens their independence. Eliminating registration requirements for self-assessed non-high-risk systems removes the primary control preventing misclassification.

What the Relevant Standards Require

ISO/IEC 42001 (AI Management System)

Clause 6.1 requires organizations to determine risks and opportunities when planning the AI Management System. This includes considering "legal and regulatory requirements" and "changes to these requirements." The omnibus changes occurred too rapidly for organizations to update risk assessments, particularly regarding enforcement authority scope and exemption disclosure obligations.

Clause 8.2.3 addresses AI system impact assessment, requiring organizations to "identify and analyze the intended and reasonably foreseeable unintended impacts" of AI systems. The structural changes in the omnibus create reasonably foreseeable impacts (surveillance gaps, market distortions favoring non-transparent providers) that were not assessed before the proposal.

EU AI Act Article 9 (Risk Management System)

Article 9 requires high-risk AI system providers to establish, implement, document, and maintain a risk management system. This system must be "a continuous iterative process run throughout the entire lifecycle of a high-risk AI system." When enforcement authority changes and exemption disclosure requirements disappear mid-lifecycle, providers can't maintain continuous risk management. They're managing compliance to a moving target without visibility into which peer organizations claimed exemptions.

EU AI Act Article 49(2) (Transparency of Exemptions)

The proposed deletion targets this provision specifically. Article 49(2) requires providers who consider their AI system not high-risk (despite falling within Annex III categories) to document this assessment and make it available to national competent authorities. Without this requirement, market surveillance authorities lack the oversight needed to identify cross-member-state discrepancies in classification decisions.

Lessons and Action Items for Your Team

Map Your Exposure to Omnibus Changes Now

Review the Digital Omnibus provisions against your current AI system inventory. Identify systems where you've relied on Article 49(2) transparency for classification decisions. Document which systems would lose registration requirements under the self-assessment exemption. Calculate what percentage of your AI systems fall under the expanded Small Mid-Cap privileges.

Don't wait for the final omnibus text. Your risk assessment under ISO/IEC 42001 Clause 6.1 must account for regulatory uncertainty itself as a risk factor.

Establish Exemption Disclosure as Internal Policy

Even if Article 49(2) gets deleted, maintain internal documentation of classification decisions and exemption rationales. Your audit trail protects you when enforcement authority centralizes. The AI Office's enhanced inspection powers include examining company books and questioning staff. If you can't explain why you classified a system as non-high-risk, the inspection becomes adversarial.

Make exemption documentation part of your Technical Documentation (Annex IV) template regardless of legal requirement.

Challenge Size-Based Compliance Privileges

If your organization qualifies as a Small Mid-Cap, resist the temptation to claim lighter obligations for high-risk systems. The AI Act's risk-tiering framework ties obligations to system risk, not provider size. A hiring algorithm that discriminates harms candidates identically whether deployed by a 200-person company or a 20,000-person enterprise.

Your AI Management System under ISO/IEC 42001 should define risk controls based on impact severity and likelihood, not organizational characteristics.

Separate Standards Compliance from Legal Compliance

ALLAI warns that linking obligations to standards "risks discouraging proactive compliance and delaying safety-by-design." Harmonised standards provide safe harbor, not minimum requirements. If you wait for standards publication to begin conformity work, you've already failed the continuous risk management obligation in Article 9.

Build your validation evidence and robustness testing protocols now using ISO/IEC 23894 (AI risk management guidance) and ISO/IEC 5338 (AI system lifecycle processes). When harmonised standards arrive, map your existing controls to them rather than starting from scratch.

Demand Enforcement Visibility

The centralization of inspection powers within the AI Office creates a single point of contact but also a single point of opacity. Your market surveillance strategy must account for potential conflicts between national competent authorities and the AI Office, particularly for systems built on General-Purpose AI Models within complex corporate structures.

If your organization operates across multiple member states or within a broader undertaking (as the Council compromise text defines it), clarify which enforcement body has primary jurisdiction before they clarify it for you during an inspection.

The omnibus incident reveals how quickly "simplification" becomes deregulation when stakeholders lack time to distinguish burden reduction from safeguard removal. Your governance controls must be stronger than the minimum legal requirement, because that minimum is currently in flux.

You Might Also Like