Signal Scanner · REGULATION, STANDARDS & POLICY CHANGE · 14 September 2026

The AI Act's Simplification Package Moved Frontier Enforcement to Brussels

Read as a delay, the EU's AI Act simplification package moved enforcement instead. From 2 August 2026 the Commission's own AI Office holds exclusive competence over frontier systems and can fine 3% of worldwide turnover. Exposed: model providers, platforms, deployers and national regulators.

The Digital Omnibus on AI is being read as a delay. High-risk obligations slip to December 2027 and August 2028, the rules for smaller firms loosen, and the sandbox deadline moves a year. Underneath the calendar, the enforcement map was redrawn. Regulation (EU) 2026/1744 gives the European Commission's own AI Office exclusive competence over AI systems built on general-purpose models by the same provider and over systems inside very large platforms, and on 2 August the Office's powers to demand documentation, evaluate models and fine went live. Nine of twenty-seven member states have designated the national authorities the Act requires. For the systems that matter most, compliance now runs to one address in Brussels.

Signal Identification

A regulatory pivot in the governance layer rather than the rule layer. What changed is not what is prohibited but who decides, investigates and fines. The precedent is competition and platform enforcement, where the Commission acts directly rather than through 27 authorities. The exposure is procedural: a single supervisor, direct fining power, and a capacity question nobody has answered.

Time horizon: 1-4 years (Regulation (EU) 2026/1744 in force 27 July 2026; AI Office enforcement powers live 2 August 2026; Annex III high-risk duties 2 December 2027; Annex I 2 August 2028)
credibility window2026202720282029to 2030
Plausibility band: High
LowMediumHigh
Geographic / Jurisdictional Scope: Primary: the EU-27, where the regulation applies directly and the AI Office supervises from Brussels. Spillover: the United States and the United Kingdom, home to most providers of the models the Office now supervises, and the EEA EFTA states where the Act is still under scrutiny for incorporation.
PrimaryEU-27
SpilloverUnited StatesUnited KingdomEEA EFTA
Sectors exposed:
Frontier model providersVery large online platforms and search enginesEnterprise AI deployersNational market surveillance and data protection authoritiesConformity assessment bodiesLegal and compliance functionsAI assurance and evaluation firmsPublic sector AI buyers

What's Changing

Regulation (EU) 2026/1744 entered into force on 27 July (EUR-Lex, 08/07/2026). The Commission's own summary files the change under governance rather than simplification: “The AI Office will have extended oversight of certain AI systems, including those built on general-purpose models and embedded in large online platforms and search engines” (European Commission, 27/07/2026). Four days later it confirmed that from 2 August the Office, with national authorities, begins enforcing the Act, and pointed firms to a complaints tool, a whistleblower tool and a downstream-provider channel that all run through Brussels (European Commission, 31/07/2026).

The powers are not supervisory in the soft sense. Article 91 compels documentation, Article 92 lets the Office evaluate a model and request access “through APIs or other technical means, including source code”, Article 93 lets it demand measures up to withdrawal, and Article 101 sets fines at 3% of worldwide annual turnover or €15 million, whichever is higher, imposed by the Commission rather than a national regulator (Lawfare, 18/05/2026). The deal also equipped the Office with “powers to conduct investigations and on-site inspections, accept binding commitments, and impose fines”, leaving national authorities law enforcement, border management, judicial and financial supervision (Gibson Dunn, 27/05/2026).

The national half of the map is unfinished. Member states had until 2 August 2025 to designate a market surveillance authority and a notifying authority; as of 17 June 2026, 9 had done both, 12 had partial arrangements and 6 had designated neither, while all 27 had named fundamental-rights authorities (EU Artificial Intelligence Act, 17/06/2026). Germany's designated supervisor puts it plainly for the Annex III domains, which include critical infrastructure and law enforcement: no market surveillance structures have existed there to date, and the tasks are to be concentrated at the Bundesnetzagentur (Bundesnetzagentur, accessed 14/09/2026).

One supervisor for frontier systems, an unfinished map for everything else

ENFORCEMENT OF THE AI ACT FROM 2 AUGUST 2026 AI OFFICE, EXCLUSIVE COMPETENCE Systems built on general-purpose models by the same provider Systems inside very large online platforms NATIONAL AUTHORITIES Everything else, including high-risk systems Law enforcement, borders, courts, finance In 6 member states, none designated yet AI Office tools: documentation requests · model evaluations including source code · binding commitments · fines to 3% of worldwide turnover AUTHORITIES DESIGNATED ACROSS THE EU-27, JUNE 2026 Market surveillance and notifying authorities 9 designated 12 partial 6 none Fundamental rights authorities 27 designated Bar width is proportional to the number of member states, out of 27.

Sources: the European Commission and Gibson Dunn for the split of competence and the AI Office toolkit; Lawfare for the Article 101 fine ceiling; the EU Artificial Intelligence Act tracker, updated 17 June 2026, for the designation counts.

Disruption Pathway

Stage one is the credibility window, running from August 2026 into 2027. The Office either issues Article 91 information requests to Code of Practice signatories as routine supervision or waits for a failure, and Lawfare's argument is that the choice tells providers whether the Code is a compliance instrument or a gesture (Lawfare, 18/05/2026). Stage two runs to December 2027, when Annex III high-risk duties apply and national authorities that do not yet exist are supposed to police them. Stage three is the collision: a Brussels unit with direct fining power over frontier models sitting above 27 uneven national regimes, at the point where high-risk enforcement actually begins.

Stress concentrates in three places. Capacity is the first: Pour Demain puts the requirement for the Office's systemic-risk safety unit at a minimum of 160 staff by 2030 and an annual budget in the range of €50–60 million, against a mandate the Omnibus has just widened (Pour Demain, 01/07/2026). Asymmetry is the second, because a provider whose model and downstream system share a legal entity faces one supervisor while a competitor buying that model faces a national one that may not exist. Legitimacy is the third, since penalties set by the body that investigates invite challenge. Two adaptations follow. Providers build a Brussels-facing regulatory function of the kind they already run for competition and platform law. And national authorities, rather than duplicating, position themselves as feeders into the Office.

Why This Matters Now

This lands on model providers, on the platforms that embed them, on enterprise deployers who built compliance around a national regulator, and on those regulators themselves. The decision architecture that needs revising assumes AI Act compliance is a member-state relationship, chosen with the place of establishment. For systems built on general-purpose models by their own provider, and for AI inside very large platforms, that relationship has gone. Firms should map which of their systems fall to the Office and which to a national authority, and should staff the first relationship the way they staff a competition investigation, because the procedure is borrowed from one. This report's reading is that the gap will show first as inconsistency between the two halves of the map rather than as an absence of enforcement.

Decision-action posture for this signal: Prepare — the powers are in force and the exclusive competences are settled law, but no information request, evaluation or fine has yet tested them, so the systems map and the Brussels-facing function should be built now and resourced against the first enforcement action rather than against the statute alone.

Counter-Argument

The strongest objection is that a power without staff is not a power. Lawfare records that the Office “is significantly underresourced relative to its mandate” and that the pool of evaluators qualified to assess frontier models is thinner still (Lawfare, 18/05/2026), and the capacity estimate behind that judgement asks for 160 staff by 2030 for one unit (Pour Demain, 01/07/2026). On that reading the Omnibus centralised responsibility rather than enforcement, and the practical constraint stays where it was, with 27 national authorities of uneven capability.

Both can be true, and the second is the more expensive to plan around. The Commission's early Digital Services Act proceedings produced no first-year fines and still changed platform behaviour, because answering the investigative step is itself costly. A supervisor that opens two files a year still obliges every provider to be able to answer one.

Implications

This is durable rather than cyclical, because a competence, once exclusive, is not handed back by administrative practice. The maximum penalty is 3% of worldwide annual turnover in the preceding financial year, or €15 million, whichever is higher, and it is set in Brussels (Lawfare, 18/05/2026). The inflection window runs from the first Article 91 request to the first published preliminary finding. Providers with an existing Brussels regulatory capability gain, because they have already built the function this needs. Deployers who scoped compliance around a familiar national authority lose, and so do the six member states with no authority at all, who have no seat where the cases are decided.

Early Indicators to Monitor

Disconfirming Signals

Strategic Questions

Keywords

EU AI Act; Digital Omnibus on AI; Regulation (EU) 2026/1744; AI Office; exclusive competence; Article 91 information request; Article 101 fines; general-purpose AI; market surveillance authority; national competent authorities; very large online platforms; enforcement capacity

Bibliography

Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.


Prepared by Shaping Tomorrow: 14 September 2026