AIGO — EU AI Act Governance and Enforcement Mapping
1. Document Purpose
This document provides the AIGO mapping for the governance, supervision, enforcement, institutional cooperation, market-surveillance, regulatory-authority, and penalty framework established by Regulation (EU) 2024/1689, as amended by subsequent Union legislation including Regulation (EU) 2026/1744. The mapping translates the EU AI Act governance architecture into AIGO mechanisms covering:- European AI governance;
- European AI Office;
- European Artificial Intelligence Board;
- Scientific Panel;
- Advisory Forum;
- national competent authorities;
- market-surveillance authorities;
- notifying authorities;
- fundamental-rights protection authorities;
- regulatory cooperation;
- supervisory investigations;
- information requests;
- inspections;
- corrective measures;
- commitments;
- non-compliance findings;
- administrative fines;
- periodic penalty payments;
- complaints and regulatory interaction;
- confidentiality;
- evidence preservation;
- management escalation;
- incident response;
- regulatory change management;
- assurance; and
- continual improvement.
2. Mapping Information
Regulation (EU) 2026/1744 was adopted on 8 July 2026, published on 24 July 2026, and entered into force on 27 July 2026. It substantially amended the supervisory and enforcement architecture, including new provisions addressing AI Office supervisory and enforcement powers.
3. Governance Principle
The AIGO governance model must preserve the distinction between:- the European AI Office;
- a national market-surveillance authority;
- a notifying authority;
- a fundamental-rights protection authority; or
- any other competent public authority.
4. Governance Architecture
The current EU AI Act governance architecture can be represented as:5. Regulatory Actor Model
AIGO should maintain a controlled distinction between:6. AIGO Regulatory-Authority Register
AIGO should maintain an internal register of relevant authorities. Potential fields:
This register should be maintained separately from the EU AI Act mapping registry when operationally necessary.
7. National Competent Authorities
The Commission states that Member States designate and empower national competent authorities, including market-surveillance and notifying authorities, to supervise the implementation and application of the AI Act at national level. AIGO should therefore determine:- which Member State is relevant;
- which market-surveillance authority has competence;
- whether a notifying authority is relevant;
- whether a sectoral authority has additional responsibilities;
- whether a fundamental-rights authority should be involved.
8. Market-Surveillance Authorities
Market-surveillance authorities have responsibilities concerning supervision and enforcement of AI-system requirements, including prohibitions and high-risk AI rules. AIGO should provide a regulatory interaction control capable of managing:- authority identification;
- information requests;
- evidence production;
- investigation support;
- corrective actions;
- deadlines;
- communication;
- escalation;
- closure.
9. Notifying Authorities
Notifying authorities designate and supervise notified bodies involved in conformity assessment. AIGO should distinguish:10. Fundamental-Rights Protection Authorities
The Commission identifies national authorities empowered to supervise or enforce Union-law obligations protecting fundamental rights as relevant participants in AI Act governance. These authorities can receive information, including information concerning serious incidents, from market-surveillance authorities. AIGO should therefore include a fundamental-rights escalation route. Potential triggers include:- discrimination;
- privacy violations;
- unlawful treatment;
- rights-impact incidents;
- serious impact on vulnerable groups;
- relevant high-risk AI findings.
11. European AI Office
The European AI Office is established within the European Commission and has central responsibilities for implementation and enforcement, including supervision of GPAI models and specified AI systems under Article 75. AIGO should treat the AI Office as an external statutory authority. The organization should maintain:- AI Office relationship owner;
- regulatory correspondence;
- submissions;
- notices;
- requests;
- deadlines;
- responses;
- evidence.
12. AI Office Scope
The current amended framework gives the AI Office responsibility for certain GPAI obligations and, under specified conditions, certain AI systems. The precise scope must be determined from the current legal text. Regulation (EU) 2026/1744 introduced detailed provisions concerning AI Office supervision and enforcement powers, including Articles 75a, 75b, and 75c. AIGO should therefore avoid treating “AI Office supervision” as applying identically to every AI system.13. AI Office Supervisory Powers
Under the amended framework, the AI Office can exercise specified market-surveillance powers for the AI systems within its competence, including information requests, investigations, inspections, and other supervisory measures subject to legal safeguards. AIGO should prepare organizations to manage:- requests for information;
- requests for explanations;
- document retention requirements;
- inspection support;
- investigations;
- commitments;
- corrective actions;
- non-compliance findings.
14. AI Office Information Requests
AIGO should establish: Regulatory Information Request Control The control should manage:15. Information-Request Evidence
Evidence may include:- request;
- authority identity;
- legal basis;
- scope determination;
- response;
- supporting documents;
- communications;
- submission acknowledgment;
- follow-up.
16. Preservation Requirements
Where a competent authority requests data or documents, the organization should activate evidence-preservation procedures. Potential actions include:- preservation notice;
- retention hold;
- access restriction;
- evidence copying;
- integrity verification;
- chain-of-custody tracking.
17. On-Site Inspections
Where legally required, organizations should have a controlled inspection-response process. AIGO should support:- inspection authorization verification;
- designated response team;
- authority liaison;
- evidence access;
- visitor/access records;
- secure communications;
- document preservation;
- management escalation;
- post-inspection remediation.
18. Investigation Management
Regulatory investigations should be tracked separately from ordinary internal incidents. Recommended record:19. Regulatory Commitments
The amended framework permits the AI Office to address certain proceedings through binding commitments. AIGO should maintain a dedicated commitment record or use the Change / Improvement / Approval framework to preserve:- commitment;
- legal basis;
- responsible owner;
- actions;
- deadlines;
- verification;
- evidence;
- closure.
20. Non-Compliance Findings
When an authority determines non-compliance, AIGO should create a controlled regulatory finding. Recommended fields:21. Corrective Measures
A regulatory finding should generate:22. AI Office Periodic Penalty Payments
Under the amended Article 75c framework, the AI Office may impose periodic penalty payments in specified circumstances to compel compliance with investigations, information requests, inspections, corrective actions, commitments, or decisions. The amended provision sets an upper limit of 5% of average daily income or worldwide annual turnover in the preceding financial year per day, where applicable. AIGO should therefore classify a periodic penalty-payment decision as a critical regulatory governance matter.23. AI Office Administrative Fines
The amended framework applies administrative fines to specified infringements within the AI Office’s supervisory competence. AIGO should treat a regulatory fine as:24. Article 99 Penalty Mapping
The master mapping should preserve the Article 99 penalty framework and applicable amended provisions. AIGO should not hard-code penalty amounts into operational controls because:- penalties depend on the relevant infringement;
- statutory amendments can change thresholds;
- organization characteristics can matter;
- supervisory competence can differ;
- the applicable law should control.
25. Confidentiality and Regulatory Information
Regulatory interactions can contain:- confidential business information;
- security information;
- personal data;
- model information;
- proprietary documentation.
- regulatory correspondence;
- investigation evidence;
- inspection records;
- authority submissions;
- legal advice;
- enforcement documents.
26. Procedural Rights
Organizations subject to enforcement should maintain procedural safeguards and legal-review processes. AIGO should not attempt to define legal procedural rights independently of the applicable law. Relevant governance mechanisms include:- legal review;
- authority verification;
- response approval;
- evidence preservation;
- representation;
- deadline management.
27. Coordination With Other EU Law
The amended AI Act establishes coordination mechanisms involving other Union legal frameworks, including the Digital Services Act for certain very large online platforms/search engines and AI systems connected to them. The AI Office and national authorities must coordinate with relevant authorities and take account of principles such as proportionality and ne bis in idem. AIGO should identify overlapping regulatory frameworks during applicability assessment.28. AI Act and Digital Services Act
Where an AI system:- is deployed on a very large online platform;
- is embedded in a very large online platform;
- is connected to a very large online search engine;
29. Sector-Specific Supervision
The 2026 amendments preserve certain sectoral supervisory responsibilities where specific sectoral supervision exists. AIGO should therefore identify:- sector;
- sector regulator;
- AI Act authority;
- conformity authority;
- data-protection authority;
- other relevant authorities.
30. Union Institutions
AI systems placed on the market, put into service, or used by Union institutions, bodies, offices, or agencies are subject to a distinct supervisory framework involving the European Data Protection Supervisor under the applicable AI Act provisions. This is relevant primarily to the applicable public-sector scope. AIGO should preserve the distinction between:31. European Artificial Intelligence Board
The AI Board provides EU-level coordination and supports coherent implementation across Member States. The Commission describes the AI Board as composed of representatives of EU Member States. AIGO should monitor:- AI Board recommendations;
- guidance;
- coordination positions;
- common objectives;
- subgroups;
- relevant implementation developments.
32. AI Board and AI Literacy
The amended Article 4 provides for AI Board recommendations supporting AI literacy and taking European competence frameworks into account. AIGO should therefore connect:33. AI Board and Regulatory Consistency
The AI Board should be treated as an important source for:- harmonized interpretation;
- implementation coherence;
- guidance;
- common approaches.
34. Scientific Panel
The Scientific Panel provides independent scientific expertise to support AI Act governance. AIGO should consider Scientific Panel outputs as high-value implementation information. The organization should distinguish:35. Advisory Forum
The Advisory Forum represents stakeholder perspectives and provides advice to the AI Board and Commission. AIGO may monitor relevant outputs, but should distinguish:- stakeholder advice;
- Commission guidance;
- AI Board outputs;
- binding legal requirements.
36. Regulatory Governance Information Hierarchy
AIGO should use:37. Regulatory Change Management
AIGO should maintain a formal regulatory-change process. Recommended flow:38. Regulatory Watch
The organization should monitor:- Regulation amendments;
- delegated acts;
- implementing acts;
- Commission guidance;
- AI Office publications;
- AI Board recommendations;
- authority designations;
- national implementation;
- enforcement developments;
- relevant standards;
- cross-regulatory developments.
39. Authority Designation Monitoring
Because national competent authorities have an essential enforcement function, changes in authority designation should trigger review. AIGO should maintain:- authority register;
- jurisdiction;
- scope;
- effective date;
- official source.
40. Regulatory Contact Management
AIGO should maintain controlled contact information for:- competent authority;
- regulatory liaison;
- legal counsel;
- responsible executive;
- technical contact;
- evidence coordinator.
41. Regulatory Submission Control
Control Name: Regulatory Submission and Authority Interaction Objective: Ensure that mandatory regulatory submissions and authority communications are accurate, timely, authorized, traceable, and retained. Control Owner: AI Governance Owner / Legal & Compliance. Evidence:- source request;
- draft submission;
- review;
- approval;
- submission;
- acknowledgment;
- follow-up.
42. Regulatory Deadline Control
Regulatory deadlines should be tracked separately from ordinary internal deadlines. Fields should include:- authority;
- legal basis;
- start date;
- due date;
- responsible owner;
- status;
- extension request;
- submission date;
- acknowledgment.
43. Authority Communication Evidence
AIGO should preserve:44. Regulatory Investigation Evidence
For investigations, AIGO should preserve:- requested evidence;
- evidence supplied;
- source system;
- timestamps;
- versions;
- integrity metadata;
- communications;
- legal review;
- corrective actions.
45. Regulatory Incident
A regulatory event may be recorded as an Incident where it involves:- suspected non-compliance;
- authority investigation;
- enforcement action;
- serious regulatory finding;
- missed statutory requirement.
- AI system;
- risk;
- authority;
- finding;
- evidence;
- change;
- improvement;
- assurance.
46. Regulatory Risk
AIGO should support a dedicated regulatory-risk category:REGULATORY_COMPLIANCE_RISK
Potential sources include:
- new legal requirements;
- uncertain applicability;
- inadequate controls;
- evidence gaps;
- authority findings;
- missed deadlines;
- supplier non-compliance.
47. Regulatory Risk Assessment
A regulatory risk assessment should consider:- legal exposure;
- affected AI systems;
- control maturity;
- evidence;
- probability;
- impact;
- authority interest;
- remediation;
- residual risk.
48. Enforcement Readiness
An organization should maintain an enforcement-readiness capability. Potential capabilities:- complete AI inventory;
- current applicability decisions;
- traceable evidence;
- current documentation;
- regulatory contact register;
- controlled submissions;
- incident management;
- authority-response process;
- legal escalation;
- management reporting.
49. Enforcement Readiness Assessment
A readiness assessment may evaluate:50. Enforcement Evidence Pack
For material AI systems, organizations may maintain a controlled evidence pack containing:- AI System Profile;
- classification;
- risk;
- controls;
- assessments;
- approvals;
- monitoring;
- incidents;
- changes;
- assurance;
- evidence;
- regulatory mapping.
51. Regulatory Inspection Readiness
The organization should define:- inspection lead;
- technical lead;
- legal lead;
- evidence lead;
- communications lead;
- executive sponsor.
52. Enforcement Simulation
A future assurance exercise may simulate:53. Regulatory Corrective Action
Where enforcement identifies a gap:54. Regulatory Commitment Tracking
Regulatory commitments should be managed like controlled governance obligations. Fields should include:- commitment;
- authority;
- legal basis;
- date;
- owner;
- milestone;
- evidence;
- status;
- verification.
55. Regulatory Assurance
Assurance may evaluate:- authority register;
- regulatory monitoring;
- applicability;
- submissions;
- evidence;
- deadline management;
- investigation response;
- corrective action.
56. Management Review
Management review should periodically consider:- regulatory changes;
- authority changes;
- open regulatory issues;
- investigations;
- enforcement;
- fines;
- corrective actions;
- evidence gaps;
- upcoming deadlines;
- resource requirements.
57. Regulatory Improvement
Repeated regulatory findings should drive improvement. Examples:- improve legal monitoring;
- improve applicability assessment;
- improve AI inventory;
- improve controls;
- improve evidence;
- improve authority-response procedures;
- improve supplier governance;
- improve training.
58. Governance and GPAI
The governance architecture should recognize the special role of the AI Office for GPAI. Recommended chain:05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md
59. Governance and High-Risk AI
For high-risk AI, governance should identify:- national authority;
- notifying authority where relevant;
- notified body where relevant;
- sector authority;
- fundamental-rights authority;
- legal/compliance owner.
03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md
60. Governance and Prohibited Practices
For Article 5:02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md
61. Governance and Transparency
Article 50 transparency obligations may be enforced through national authorities. AIGO should maintain the transparency evidence and monitoring required to demonstrate implementation. Detailed mapping remains in:04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md
62. Governance and AI Literacy
Article 4 supervision and enforcement are under national market-surveillance authorities, not the AI Office. The Commission states that national authorities begin supervision and enforcement from 2 August 2026. AIGO should therefore direct Article 4 regulatory issues through the relevant national authority rather than assuming the AI Office is the enforcement body.63. Authority-Cooperation Model
Where multiple authorities may be involved:64. Regulatory Coordination
The organization should designate one regulatory coordination owner to avoid inconsistent responses from different functions. The coordination owner should not prevent legally required direct communications with competent authorities.65. Regulatory Reporting Governance
Regulatory reporting should include:- trigger;
- source;
- applicability;
- deadline;
- authority;
- content;
- reviewer;
- approver;
- submission;
- evidence;
- acknowledgment.
66. Regulatory Communication Security
Regulatory communications should use:- approved channels;
- access controls;
- encryption where appropriate;
- document classification;
- secure evidence handling.
67. Governance and Evidence
Governance decisions should be traceable to regulatory sources. Recommended chain:68. Governance and Auditability
AIGO should maintain sufficient records to reconstruct:- what requirement applied;
- when it applied;
- who made the decision;
- what evidence supported the decision;
- what control was used;
- what monitoring occurred;
- what changed.
69. Governance and Legal Advice
Legal advice should remain distinct from ordinary governance records where legally privileged. AIGO should preserve necessary references to legal review without unnecessarily embedding privileged legal content in broadly accessible operational records.70. Governance and Accountability
Each regulatory obligation should have:- accountable owner;
- operational owner;
- compliance reviewer;
- evidence owner;
- assurance owner where applicable.
71. Enforcement Readiness Control Matrix
72. Regulatory Traceability Chain
The minimum chain is:73. Governance Findings
Potential AIGO findings include:74. Critical Governance Findings
Potential critical findings include:- competent authority unknown for a materially regulated AI system;
- statutory deadline missed;
- regulatory request not controlled;
- required submission not made;
- evidence subject to regulatory preservation not protected;
- enforcement finding without corrective action;
- regulatory commitment without owner;
- material regulatory change not assessed.
75. Governance Metrics
Potential management metrics include:
These metrics should not be presented as legal compliance scores.
76. Regulatory Health
A future governance-health view may classify:77. Regulatory Governance Assurance
Assurance should verify:- authority mapping;
- regulatory-change monitoring;
- deadlines;
- submissions;
- evidence;
- investigations;
- corrective actions;
- management escalation.
78. Regulatory Governance and Repository Health
Repository health should identify:- stale authority references;
- missing legal sources;
- outdated regulatory dates;
- broken links;
- outdated mapping;
- missing governance artifacts;
- unresolved enforcement findings.
79. Current Governance Baseline
The Commission’s current governance page states that the AI Office and Member State authorities are responsible for implementing, supervising, and enforcing the AI Act, while the AI Board, Scientific Panel, and Advisory Forum steer and advise on governance. The current consolidated legal framework must additionally be read with Regulation (EU) 2026/1744, which introduced more detailed AI Office supervision and enforcement powers and refined the relationship between the AI Office and national authorities.80. Digital Omnibus Impact
The 2026 amendments materially affect governance and enforcement by:- defining additional AI Office supervisory powers;
- specifying information-request powers;
- regulating inspections;
- introducing structured dialogue and commitments;
- establishing detailed AI Office non-compliance decisions;
- enabling AI Office fines and periodic penalty payments;
- clarifying cooperation with national authorities;
- refining supervision of certain AI systems;
- coordinating with other Union regulatory regimes.
81. Review Triggers
This mapping should be reviewed after:- EU AI Act amendments;
- AI Office guidance;
- AI Board recommendations;
- national authority designation changes;
- enforcement guidance;
- new implementing acts;
- new delegated acts;
- relevant regulatory decisions;
- major court decisions;
- changes to sectoral supervision;
- changes to the Digital Services Act interaction.
82. Review Frequency
Minimum review frequency:- annual;
- event-driven after regulatory changes;
- before major AIGO releases.
83. Relationship to Other EU AI Act Mappings
84. Relationship to AIGO Schemas
The mapping does not require a dedicated regulatory-enforcement schema at this stage.
85. Relationship to AIGO Tools
The governance and enforcement mapping should eventually be supported by:- Schema Validator;
- Reference Validator;
- Traceability Validator;
- Control Coverage Validator;
- Evidence Coverage Validator;
- Framework Consistency Checker;
- Document Integrity Checker;
- Repository Health Checker.
86. Validation Requirements
The mapping should satisfy:Authority Validation
Relevant authority is identified.Legal Source Validation
Authority powers and obligations trace to current law.Applicability Validation
Supervisory competence is determined.Timeline Validation
Effective dates and enforcement dates are current.Evidence Validation
Regulatory interactions can be evidenced.Traceability Validation
Requirement → authority → organization → control → evidence chain is complete.Consistency Validation
Authority names, roles, and terminology are consistent across AIGO.Change Validation
Regulatory amendments are incorporated.87. Limitations
This mapping cannot independently determine:- which authority will ultimately exercise jurisdiction in a specific factual case;
- whether a regulator’s action is legally valid;
- whether a specific enforcement decision is correct;
- whether a fine will be imposed;
- whether internal governance satisfies all regulatory procedural requirements;
- whether a particular legal interpretation will prevail.
88. Document Control
89. Document Status
Document: AIGO — EU AI Act Governance and Enforcement Mapping Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-EUAI-007
Document Type: EU AI Act Mapping
This document maps the EU AI Act governance and enforcement architecture to the AIGO AI Governance Operating Framework, including the European AI Office, AI Board, national competent authorities, market-surveillance authorities, notifying authorities, fundamental-rights authorities, regulatory interactions, investigations, corrective measures, commitments, enforcement decisions, penalties, evidence, assurance, management review, and continual improvement.
End of Document