Skip to main content

AIGO — EU AI Act Governance and Enforcement Mapping

1. Document Purpose

This document provides the AIGO mapping for the governance, supervision, enforcement, institutional cooperation, market-surveillance, regulatory-authority, and penalty framework established by Regulation (EU) 2024/1689, as amended by subsequent Union legislation including Regulation (EU) 2026/1744. The mapping translates the EU AI Act governance architecture into AIGO mechanisms covering:
  • European AI governance;
  • European AI Office;
  • European Artificial Intelligence Board;
  • Scientific Panel;
  • Advisory Forum;
  • national competent authorities;
  • market-surveillance authorities;
  • notifying authorities;
  • fundamental-rights protection authorities;
  • regulatory cooperation;
  • supervisory investigations;
  • information requests;
  • inspections;
  • corrective measures;
  • commitments;
  • non-compliance findings;
  • administrative fines;
  • periodic penalty payments;
  • complaints and regulatory interaction;
  • confidentiality;
  • evidence preservation;
  • management escalation;
  • incident response;
  • regulatory change management;
  • assurance; and
  • continual improvement.
This document is an operational governance mapping. It does not confer statutory authority on an organization or its internal governance bodies, and it is not legal advice. The European Commission currently describes the AI Act as operating through a two-tiered governance structure in which national competent authorities oversee and enforce rules concerning AI systems while the European AI Office governs and enforces GPAI obligations and certain other AI systems within its competence. The AI Board supports EU-wide coherence, while the Scientific Panel and Advisory Forum provide expert and stakeholder input.

2. Mapping Information

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published on 24 July 2026, and entered into force on 27 July 2026. It substantially amended the supervisory and enforcement architecture, including new provisions addressing AI Office supervisory and enforcement powers.

3. Governance Principle

The AIGO governance model must preserve the distinction between:
and:
An AIGO Governance Board, AI Governance Owner, Risk Committee, or similar internal body does not acquire the statutory powers of:
  • the European AI Office;
  • a national market-surveillance authority;
  • a notifying authority;
  • a fundamental-rights protection authority; or
  • any other competent public authority.

4. Governance Architecture

The current EU AI Act governance architecture can be represented as:
The actual supervisory chain depends on the AI system, actor, sector, and applicable statutory provisions.

5. Regulatory Actor Model

AIGO should maintain a controlled distinction between:
The organization should record the applicable external authority rather than using generic labels such as “regulator” where a more specific designation is available.

6. AIGO Regulatory-Authority Register

AIGO should maintain an internal register of relevant authorities. Potential fields: This register should be maintained separately from the EU AI Act mapping registry when operationally necessary.

7. National Competent Authorities

The Commission states that Member States designate and empower national competent authorities, including market-surveillance and notifying authorities, to supervise the implementation and application of the AI Act at national level. AIGO should therefore determine:
  • which Member State is relevant;
  • which market-surveillance authority has competence;
  • whether a notifying authority is relevant;
  • whether a sectoral authority has additional responsibilities;
  • whether a fundamental-rights authority should be involved.

8. Market-Surveillance Authorities

Market-surveillance authorities have responsibilities concerning supervision and enforcement of AI-system requirements, including prohibitions and high-risk AI rules. AIGO should provide a regulatory interaction control capable of managing:
  • authority identification;
  • information requests;
  • evidence production;
  • investigation support;
  • corrective actions;
  • deadlines;
  • communication;
  • escalation;
  • closure.

9. Notifying Authorities

Notifying authorities designate and supervise notified bodies involved in conformity assessment. AIGO should distinguish:
from:
These are separate governance mechanisms.

10. Fundamental-Rights Protection Authorities

The Commission identifies national authorities empowered to supervise or enforce Union-law obligations protecting fundamental rights as relevant participants in AI Act governance. These authorities can receive information, including information concerning serious incidents, from market-surveillance authorities. AIGO should therefore include a fundamental-rights escalation route. Potential triggers include:
  • discrimination;
  • privacy violations;
  • unlawful treatment;
  • rights-impact incidents;
  • serious impact on vulnerable groups;
  • relevant high-risk AI findings.

11. European AI Office

The European AI Office is established within the European Commission and has central responsibilities for implementation and enforcement, including supervision of GPAI models and specified AI systems under Article 75. AIGO should treat the AI Office as an external statutory authority. The organization should maintain:
  • AI Office relationship owner;
  • regulatory correspondence;
  • submissions;
  • notices;
  • requests;
  • deadlines;
  • responses;
  • evidence.

12. AI Office Scope

The current amended framework gives the AI Office responsibility for certain GPAI obligations and, under specified conditions, certain AI systems. The precise scope must be determined from the current legal text. Regulation (EU) 2026/1744 introduced detailed provisions concerning AI Office supervision and enforcement powers, including Articles 75a, 75b, and 75c. AIGO should therefore avoid treating “AI Office supervision” as applying identically to every AI system.

13. AI Office Supervisory Powers

Under the amended framework, the AI Office can exercise specified market-surveillance powers for the AI systems within its competence, including information requests, investigations, inspections, and other supervisory measures subject to legal safeguards. AIGO should prepare organizations to manage:
  • requests for information;
  • requests for explanations;
  • document retention requirements;
  • inspection support;
  • investigations;
  • commitments;
  • corrective actions;
  • non-compliance findings.

14. AI Office Information Requests

AIGO should establish: Regulatory Information Request Control The control should manage:
The control should preserve the regulator’s original request and the organization’s response.

15. Information-Request Evidence

Evidence may include:
  • request;
  • authority identity;
  • legal basis;
  • scope determination;
  • response;
  • supporting documents;
  • communications;
  • submission acknowledgment;
  • follow-up.
Sensitive information should be access-controlled.

16. Preservation Requirements

Where a competent authority requests data or documents, the organization should activate evidence-preservation procedures. Potential actions include:
  • preservation notice;
  • retention hold;
  • access restriction;
  • evidence copying;
  • integrity verification;
  • chain-of-custody tracking.
The Document Integrity and Evidence frameworks should support these activities.

17. On-Site Inspections

Where legally required, organizations should have a controlled inspection-response process. AIGO should support:
  • inspection authorization verification;
  • designated response team;
  • authority liaison;
  • evidence access;
  • visitor/access records;
  • secure communications;
  • document preservation;
  • management escalation;
  • post-inspection remediation.
AIGO internal approval is not a prerequisite for a lawful regulatory inspection.

18. Investigation Management

Regulatory investigations should be tracked separately from ordinary internal incidents. Recommended record:
The Incident and Assurance models can support this workflow.

19. Regulatory Commitments

The amended framework permits the AI Office to address certain proceedings through binding commitments. AIGO should maintain a dedicated commitment record or use the Change / Improvement / Approval framework to preserve:
  • commitment;
  • legal basis;
  • responsible owner;
  • actions;
  • deadlines;
  • verification;
  • evidence;
  • closure.
A binding regulatory commitment must not be treated as an ordinary internal improvement recommendation.

20. Non-Compliance Findings

When an authority determines non-compliance, AIGO should create a controlled regulatory finding. Recommended fields:

21. Corrective Measures

A regulatory finding should generate:
The regulatory authority’s required corrective action remains authoritative. An organization must not substitute its own internal interpretation for the authority’s binding decision.

22. AI Office Periodic Penalty Payments

Under the amended Article 75c framework, the AI Office may impose periodic penalty payments in specified circumstances to compel compliance with investigations, information requests, inspections, corrective actions, commitments, or decisions. The amended provision sets an upper limit of 5% of average daily income or worldwide annual turnover in the preceding financial year per day, where applicable. AIGO should therefore classify a periodic penalty-payment decision as a critical regulatory governance matter.

23. AI Office Administrative Fines

The amended framework applies administrative fines to specified infringements within the AI Office’s supervisory competence. AIGO should treat a regulatory fine as:
A fine should not be closed merely because the payment was made. The underlying governance issue should be addressed.

24. Article 99 Penalty Mapping

The master mapping should preserve the Article 99 penalty framework and applicable amended provisions. AIGO should not hard-code penalty amounts into operational controls because:
  • penalties depend on the relevant infringement;
  • statutory amendments can change thresholds;
  • organization characteristics can matter;
  • supervisory competence can differ;
  • the applicable law should control.
The legal source should remain authoritative.

25. Confidentiality and Regulatory Information

Regulatory interactions can contain:
  • confidential business information;
  • security information;
  • personal data;
  • model information;
  • proprietary documentation.
AIGO should control access to:
  • regulatory correspondence;
  • investigation evidence;
  • inspection records;
  • authority submissions;
  • legal advice;
  • enforcement documents.

26. Procedural Rights

Organizations subject to enforcement should maintain procedural safeguards and legal-review processes. AIGO should not attempt to define legal procedural rights independently of the applicable law. Relevant governance mechanisms include:
  • legal review;
  • authority verification;
  • response approval;
  • evidence preservation;
  • representation;
  • deadline management.

27. Coordination With Other EU Law

The amended AI Act establishes coordination mechanisms involving other Union legal frameworks, including the Digital Services Act for certain very large online platforms/search engines and AI systems connected to them. The AI Office and national authorities must coordinate with relevant authorities and take account of principles such as proportionality and ne bis in idem. AIGO should identify overlapping regulatory frameworks during applicability assessment.

28. AI Act and Digital Services Act

Where an AI system:
  • is deployed on a very large online platform;
  • is embedded in a very large online platform;
  • is connected to a very large online search engine;
the organization should assess whether additional regulatory authorities and coordination mechanisms apply. The AI Act mapping should not be treated as the sole regulatory map.

29. Sector-Specific Supervision

The 2026 amendments preserve certain sectoral supervisory responsibilities where specific sectoral supervision exists. AIGO should therefore identify:
  • sector;
  • sector regulator;
  • AI Act authority;
  • conformity authority;
  • data-protection authority;
  • other relevant authorities.
A “single regulator” assumption should be avoided.

30. Union Institutions

AI systems placed on the market, put into service, or used by Union institutions, bodies, offices, or agencies are subject to a distinct supervisory framework involving the European Data Protection Supervisor under the applicable AI Act provisions. This is relevant primarily to the applicable public-sector scope. AIGO should preserve the distinction between:
and:

31. European Artificial Intelligence Board

The AI Board provides EU-level coordination and supports coherent implementation across Member States. The Commission describes the AI Board as composed of representatives of EU Member States. AIGO should monitor:
  • AI Board recommendations;
  • guidance;
  • coordination positions;
  • common objectives;
  • subgroups;
  • relevant implementation developments.
AI Board material should be labelled appropriately as guidance or coordination unless it has another legal status.

32. AI Board and AI Literacy

The amended Article 4 provides for AI Board recommendations supporting AI literacy and taking European competence frameworks into account. AIGO should therefore connect:

33. AI Board and Regulatory Consistency

The AI Board should be treated as an important source for:
  • harmonized interpretation;
  • implementation coherence;
  • guidance;
  • common approaches.
AIGO regulatory monitoring should incorporate material Board outputs.

34. Scientific Panel

The Scientific Panel provides independent scientific expertise to support AI Act governance. AIGO should consider Scientific Panel outputs as high-value implementation information. The organization should distinguish:
from:

35. Advisory Forum

The Advisory Forum represents stakeholder perspectives and provides advice to the AI Board and Commission. AIGO may monitor relevant outputs, but should distinguish:
  • stakeholder advice;
  • Commission guidance;
  • AI Board outputs;
  • binding legal requirements.

36. Regulatory Governance Information Hierarchy

AIGO should use:
Lower-level material must not be represented as changing higher-level legal obligations.

37. Regulatory Change Management

AIGO should maintain a formal regulatory-change process. Recommended flow:
This should use the AIGO Change Management Schema.

38. Regulatory Watch

The organization should monitor:
  • Regulation amendments;
  • delegated acts;
  • implementing acts;
  • Commission guidance;
  • AI Office publications;
  • AI Board recommendations;
  • authority designations;
  • national implementation;
  • enforcement developments;
  • relevant standards;
  • cross-regulatory developments.
The regulatory watch should preserve source and review date.

39. Authority Designation Monitoring

Because national competent authorities have an essential enforcement function, changes in authority designation should trigger review. AIGO should maintain:
  • authority register;
  • jurisdiction;
  • scope;
  • effective date;
  • official source.
The Commission provides a consolidated list of identified national authorities and continues to update the governance information.

40. Regulatory Contact Management

AIGO should maintain controlled contact information for:
  • competent authority;
  • regulatory liaison;
  • legal counsel;
  • responsible executive;
  • technical contact;
  • evidence coordinator.
Personal information should be controlled.

41. Regulatory Submission Control

Control Name: Regulatory Submission and Authority Interaction Objective: Ensure that mandatory regulatory submissions and authority communications are accurate, timely, authorized, traceable, and retained. Control Owner: AI Governance Owner / Legal & Compliance. Evidence:
  • source request;
  • draft submission;
  • review;
  • approval;
  • submission;
  • acknowledgment;
  • follow-up.

42. Regulatory Deadline Control

Regulatory deadlines should be tracked separately from ordinary internal deadlines. Fields should include:
  • authority;
  • legal basis;
  • start date;
  • due date;
  • responsible owner;
  • status;
  • extension request;
  • submission date;
  • acknowledgment.
Missed regulatory deadlines should trigger a high-severity incident or governance escalation.

43. Authority Communication Evidence

AIGO should preserve:
Evidence should be protected against unauthorized modification.

44. Regulatory Investigation Evidence

For investigations, AIGO should preserve:
  • requested evidence;
  • evidence supplied;
  • source system;
  • timestamps;
  • versions;
  • integrity metadata;
  • communications;
  • legal review;
  • corrective actions.
The Evidence Schema should support appropriate regulatory evidence records.

45. Regulatory Incident

A regulatory event may be recorded as an Incident where it involves:
  • suspected non-compliance;
  • authority investigation;
  • enforcement action;
  • serious regulatory finding;
  • missed statutory requirement.
The Incident record should link to:
  • AI system;
  • risk;
  • authority;
  • finding;
  • evidence;
  • change;
  • improvement;
  • assurance.

46. Regulatory Risk

AIGO should support a dedicated regulatory-risk category: REGULATORY_COMPLIANCE_RISK Potential sources include:
  • new legal requirements;
  • uncertain applicability;
  • inadequate controls;
  • evidence gaps;
  • authority findings;
  • missed deadlines;
  • supplier non-compliance.

47. Regulatory Risk Assessment

A regulatory risk assessment should consider:
  • legal exposure;
  • affected AI systems;
  • control maturity;
  • evidence;
  • probability;
  • impact;
  • authority interest;
  • remediation;
  • residual risk.
Legal risk ratings should be clearly distinguished from legal conclusions.

48. Enforcement Readiness

An organization should maintain an enforcement-readiness capability. Potential capabilities:
  • complete AI inventory;
  • current applicability decisions;
  • traceable evidence;
  • current documentation;
  • regulatory contact register;
  • controlled submissions;
  • incident management;
  • authority-response process;
  • legal escalation;
  • management reporting.

49. Enforcement Readiness Assessment

A readiness assessment may evaluate:

50. Enforcement Evidence Pack

For material AI systems, organizations may maintain a controlled evidence pack containing:
  • AI System Profile;
  • classification;
  • risk;
  • controls;
  • assessments;
  • approvals;
  • monitoring;
  • incidents;
  • changes;
  • assurance;
  • evidence;
  • regulatory mapping.
This should be generated or assembled from authoritative records rather than maintained as an uncontrolled duplicate.

51. Regulatory Inspection Readiness

The organization should define:
  • inspection lead;
  • technical lead;
  • legal lead;
  • evidence lead;
  • communications lead;
  • executive sponsor.
The process should be tested periodically.

52. Enforcement Simulation

A future assurance exercise may simulate:
Simulation evidence can be retained as Assurance evidence.

53. Regulatory Corrective Action

Where enforcement identifies a gap:
The corrective action should remain open until the defined closure conditions are satisfied.

54. Regulatory Commitment Tracking

Regulatory commitments should be managed like controlled governance obligations. Fields should include:
  • commitment;
  • authority;
  • legal basis;
  • date;
  • owner;
  • milestone;
  • evidence;
  • status;
  • verification.

55. Regulatory Assurance

Assurance may evaluate:
  • authority register;
  • regulatory monitoring;
  • applicability;
  • submissions;
  • evidence;
  • deadline management;
  • investigation response;
  • corrective action.
For material regulatory matters, independent legal or compliance assurance may be appropriate.

56. Management Review

Management review should periodically consider:
  • regulatory changes;
  • authority changes;
  • open regulatory issues;
  • investigations;
  • enforcement;
  • fines;
  • corrective actions;
  • evidence gaps;
  • upcoming deadlines;
  • resource requirements.
Material enforcement activity should be escalated promptly rather than waiting for the next scheduled management review.

57. Regulatory Improvement

Repeated regulatory findings should drive improvement. Examples:
  • improve legal monitoring;
  • improve applicability assessment;
  • improve AI inventory;
  • improve controls;
  • improve evidence;
  • improve authority-response procedures;
  • improve supplier governance;
  • improve training.

58. Governance and GPAI

The governance architecture should recognize the special role of the AI Office for GPAI. Recommended chain:
The detailed GPAI mapping is maintained in: 05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md

59. Governance and High-Risk AI

For high-risk AI, governance should identify:
  • national authority;
  • notifying authority where relevant;
  • notified body where relevant;
  • sector authority;
  • fundamental-rights authority;
  • legal/compliance owner.
The detailed high-risk mapping is maintained in: 03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md

60. Governance and Prohibited Practices

For Article 5:
An internal governance body cannot authorize a prohibited practice. Detailed provisions remain in: 02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md

61. Governance and Transparency

Article 50 transparency obligations may be enforced through national authorities. AIGO should maintain the transparency evidence and monitoring required to demonstrate implementation. Detailed mapping remains in: 04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md

62. Governance and AI Literacy

Article 4 supervision and enforcement are under national market-surveillance authorities, not the AI Office. The Commission states that national authorities begin supervision and enforcement from 2 August 2026. AIGO should therefore direct Article 4 regulatory issues through the relevant national authority rather than assuming the AI Office is the enforcement body.

63. Authority-Cooperation Model

Where multiple authorities may be involved:
AIGO should preserve the legal competence of each authority.

64. Regulatory Coordination

The organization should designate one regulatory coordination owner to avoid inconsistent responses from different functions. The coordination owner should not prevent legally required direct communications with competent authorities.

65. Regulatory Reporting Governance

Regulatory reporting should include:
  • trigger;
  • source;
  • applicability;
  • deadline;
  • authority;
  • content;
  • reviewer;
  • approver;
  • submission;
  • evidence;
  • acknowledgment.

66. Regulatory Communication Security

Regulatory communications should use:
  • approved channels;
  • access controls;
  • encryption where appropriate;
  • document classification;
  • secure evidence handling.

67. Governance and Evidence

Governance decisions should be traceable to regulatory sources. Recommended chain:

68. Governance and Auditability

AIGO should maintain sufficient records to reconstruct:
  • what requirement applied;
  • when it applied;
  • who made the decision;
  • what evidence supported the decision;
  • what control was used;
  • what monitoring occurred;
  • what changed.

69. Governance and Legal Advice

Legal advice should remain distinct from ordinary governance records where legally privileged. AIGO should preserve necessary references to legal review without unnecessarily embedding privileged legal content in broadly accessible operational records.

70. Governance and Accountability

Each regulatory obligation should have:
  • accountable owner;
  • operational owner;
  • compliance reviewer;
  • evidence owner;
  • assurance owner where applicable.
Roles should be represented in the Governance Schema.

71. Enforcement Readiness Control Matrix


72. Regulatory Traceability Chain

The minimum chain is:
For enforcement:

73. Governance Findings

Potential AIGO findings include:

74. Critical Governance Findings

Potential critical findings include:
  • competent authority unknown for a materially regulated AI system;
  • statutory deadline missed;
  • regulatory request not controlled;
  • required submission not made;
  • evidence subject to regulatory preservation not protected;
  • enforcement finding without corrective action;
  • regulatory commitment without owner;
  • material regulatory change not assessed.

75. Governance Metrics

Potential management metrics include: These metrics should not be presented as legal compliance scores.

76. Regulatory Health

A future governance-health view may classify:
The Repository Health Checker may aggregate these results.

77. Regulatory Governance Assurance

Assurance should verify:
  • authority mapping;
  • regulatory-change monitoring;
  • deadlines;
  • submissions;
  • evidence;
  • investigations;
  • corrective actions;
  • management escalation.

78. Regulatory Governance and Repository Health

Repository health should identify:
  • stale authority references;
  • missing legal sources;
  • outdated regulatory dates;
  • broken links;
  • outdated mapping;
  • missing governance artifacts;
  • unresolved enforcement findings.

79. Current Governance Baseline

The Commission’s current governance page states that the AI Office and Member State authorities are responsible for implementing, supervising, and enforcing the AI Act, while the AI Board, Scientific Panel, and Advisory Forum steer and advise on governance. The current consolidated legal framework must additionally be read with Regulation (EU) 2026/1744, which introduced more detailed AI Office supervision and enforcement powers and refined the relationship between the AI Office and national authorities.

80. Digital Omnibus Impact

The 2026 amendments materially affect governance and enforcement by:
  • defining additional AI Office supervisory powers;
  • specifying information-request powers;
  • regulating inspections;
  • introducing structured dialogue and commitments;
  • establishing detailed AI Office non-compliance decisions;
  • enabling AI Office fines and periodic penalty payments;
  • clarifying cooperation with national authorities;
  • refining supervision of certain AI systems;
  • coordinating with other Union regulatory regimes.
AIGO governance and enforcement mappings must therefore be reviewed against the amended text, not the 2024 governance model alone.

81. Review Triggers

This mapping should be reviewed after:
  • EU AI Act amendments;
  • AI Office guidance;
  • AI Board recommendations;
  • national authority designation changes;
  • enforcement guidance;
  • new implementing acts;
  • new delegated acts;
  • relevant regulatory decisions;
  • major court decisions;
  • changes to sectoral supervision;
  • changes to the Digital Services Act interaction.

82. Review Frequency

Minimum review frequency:
  • annual;
  • event-driven after regulatory changes;
  • before major AIGO releases.
Event-driven review takes precedence.

83. Relationship to Other EU AI Act Mappings


84. Relationship to AIGO Schemas

The mapping does not require a dedicated regulatory-enforcement schema at this stage.

85. Relationship to AIGO Tools

The governance and enforcement mapping should eventually be supported by:
  • Schema Validator;
  • Reference Validator;
  • Traceability Validator;
  • Control Coverage Validator;
  • Evidence Coverage Validator;
  • Framework Consistency Checker;
  • Document Integrity Checker;
  • Repository Health Checker.

86. Validation Requirements

The mapping should satisfy:

Authority Validation

Relevant authority is identified. Authority powers and obligations trace to current law.

Applicability Validation

Supervisory competence is determined.

Timeline Validation

Effective dates and enforcement dates are current.

Evidence Validation

Regulatory interactions can be evidenced.

Traceability Validation

Requirement → authority → organization → control → evidence chain is complete.

Consistency Validation

Authority names, roles, and terminology are consistent across AIGO.

Change Validation

Regulatory amendments are incorporated.

87. Limitations

This mapping cannot independently determine:
  • which authority will ultimately exercise jurisdiction in a specific factual case;
  • whether a regulator’s action is legally valid;
  • whether a specific enforcement decision is correct;
  • whether a fine will be imposed;
  • whether internal governance satisfies all regulatory procedural requirements;
  • whether a particular legal interpretation will prevail.
Those matters require current law, authority decisions, factual circumstances, and appropriate legal review.

88. Document Control


89. Document Status

Document: AIGO — EU AI Act Governance and Enforcement Mapping Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-EUAI-007 Document Type: EU AI Act Mapping This document maps the EU AI Act governance and enforcement architecture to the AIGO AI Governance Operating Framework, including the European AI Office, AI Board, national competent authorities, market-surveillance authorities, notifying authorities, fundamental-rights authorities, regulatory interactions, investigations, corrective measures, commitments, enforcement decisions, penalties, evidence, assurance, management review, and continual improvement. End of Document