The AI Act's Simplification Package Moved Frontier Enforcement to Brussels
Read as a delay, the EU's AI Act simplification package moved enforcement instead. From 2 August 2026 the Commission's own AI Office holds exclusive competence over frontier systems and can fine 3% of worldwide turnover. Exposed: model providers, platforms, deployers and national regulators.
The Digital Omnibus on AI is being read as a delay. High-risk obligations slip to December 2027 and August 2028, the rules for smaller firms loosen, and the sandbox deadline moves a year. Underneath the calendar, the enforcement map was redrawn. Regulation (EU) 2026/1744 gives the European Commission's own AI Office exclusive competence over AI systems built on general-purpose models by the same provider and over systems inside very large platforms, and on 2 August the Office's powers to demand documentation, evaluate models and fine went live. Nine of twenty-seven member states have designated the national authorities the Act requires. For the systems that matter most, compliance now runs to one address in Brussels.
Signal Identification
A regulatory pivot in the governance layer rather than the rule layer. What changed is not what is prohibited but who decides, investigates and fines. The precedent is competition and platform enforcement, where the Commission acts directly rather than through 27 authorities. The exposure is procedural: a single supervisor, direct fining power, and a capacity question nobody has answered.
What's Changing
Regulation (EU) 2026/1744 entered into force on 27 July (EUR-Lex, 08/07/2026). The Commission's own summary files the change under governance rather than simplification: “The AI Office will have extended oversight of certain AI systems, including those built on general-purpose models and embedded in large online platforms and search engines” (European Commission, 27/07/2026). Four days later it confirmed that from 2 August the Office, with national authorities, begins enforcing the Act, and pointed firms to a complaints tool, a whistleblower tool and a downstream-provider channel that all run through Brussels (European Commission, 31/07/2026).
The powers are not supervisory in the soft sense. Article 91 compels documentation, Article 92 lets the Office evaluate a model and request access “through APIs or other technical means, including source code”, Article 93 lets it demand measures up to withdrawal, and Article 101 sets fines at 3% of worldwide annual turnover or €15 million, whichever is higher, imposed by the Commission rather than a national regulator (Lawfare, 18/05/2026). The deal also equipped the Office with “powers to conduct investigations and on-site inspections, accept binding commitments, and impose fines”, leaving national authorities law enforcement, border management, judicial and financial supervision (Gibson Dunn, 27/05/2026).
The national half of the map is unfinished. Member states had until 2 August 2025 to designate a market surveillance authority and a notifying authority; as of 17 June 2026, 9 had done both, 12 had partial arrangements and 6 had designated neither, while all 27 had named fundamental-rights authorities (EU Artificial Intelligence Act, 17/06/2026). Germany's designated supervisor puts it plainly for the Annex III domains, which include critical infrastructure and law enforcement: no market surveillance structures have existed there to date, and the tasks are to be concentrated at the Bundesnetzagentur (Bundesnetzagentur, accessed 14/09/2026).
One supervisor for frontier systems, an unfinished map for everything else
Sources: the European Commission and Gibson Dunn for the split of competence and the AI Office toolkit; Lawfare for the Article 101 fine ceiling; the EU Artificial Intelligence Act tracker, updated 17 June 2026, for the designation counts.
Disruption Pathway
Stage one is the credibility window, running from August 2026 into 2027. The Office either issues Article 91 information requests to Code of Practice signatories as routine supervision or waits for a failure, and Lawfare's argument is that the choice tells providers whether the Code is a compliance instrument or a gesture (Lawfare, 18/05/2026). Stage two runs to December 2027, when Annex III high-risk duties apply and national authorities that do not yet exist are supposed to police them. Stage three is the collision: a Brussels unit with direct fining power over frontier models sitting above 27 uneven national regimes, at the point where high-risk enforcement actually begins.
Stress concentrates in three places. Capacity is the first: Pour Demain puts the requirement for the Office's systemic-risk safety unit at a minimum of 160 staff by 2030 and an annual budget in the range of €50–60 million, against a mandate the Omnibus has just widened (Pour Demain, 01/07/2026). Asymmetry is the second, because a provider whose model and downstream system share a legal entity faces one supervisor while a competitor buying that model faces a national one that may not exist. Legitimacy is the third, since penalties set by the body that investigates invite challenge. Two adaptations follow. Providers build a Brussels-facing regulatory function of the kind they already run for competition and platform law. And national authorities, rather than duplicating, position themselves as feeders into the Office.
Why This Matters Now
This lands on model providers, on the platforms that embed them, on enterprise deployers who built compliance around a national regulator, and on those regulators themselves. The decision architecture that needs revising assumes AI Act compliance is a member-state relationship, chosen with the place of establishment. For systems built on general-purpose models by their own provider, and for AI inside very large platforms, that relationship has gone. Firms should map which of their systems fall to the Office and which to a national authority, and should staff the first relationship the way they staff a competition investigation, because the procedure is borrowed from one. This report's reading is that the gap will show first as inconsistency between the two halves of the map rather than as an absence of enforcement.
Decision-action posture for this signal: Prepare — the powers are in force and the exclusive competences are settled law, but no information request, evaluation or fine has yet tested them, so the systems map and the Brussels-facing function should be built now and resourced against the first enforcement action rather than against the statute alone.
Counter-Argument
The strongest objection is that a power without staff is not a power. Lawfare records that the Office “is significantly underresourced relative to its mandate” and that the pool of evaluators qualified to assess frontier models is thinner still (Lawfare, 18/05/2026), and the capacity estimate behind that judgement asks for 160 staff by 2030 for one unit (Pour Demain, 01/07/2026). On that reading the Omnibus centralised responsibility rather than enforcement, and the practical constraint stays where it was, with 27 national authorities of uneven capability.
Both can be true, and the second is the more expensive to plan around. The Commission's early Digital Services Act proceedings produced no first-year fines and still changed platform behaviour, because answering the investigative step is itself costly. A supervisor that opens two files a year still obliges every provider to be able to answer one.
Implications
This is durable rather than cyclical, because a competence, once exclusive, is not handed back by administrative practice. The maximum penalty is 3% of worldwide annual turnover in the preceding financial year, or €15 million, whichever is higher, and it is set in Brussels (Lawfare, 18/05/2026). The inflection window runs from the first Article 91 request to the first published preliminary finding. Providers with an existing Brussels regulatory capability gain, because they have already built the function this needs. Deployers who scoped compliance around a familiar national authority lose, and so do the six member states with no authority at all, who have no seat where the cases are decided.
Early Indicators to Monitor
- The first Article 91 documentation request to a Code of Practice signatory, and whether it goes to all signatories or to one.
- The Commission opening formal proceedings against a general-purpose model provider, on the pattern of its early Digital Services Act cases.
- A staffing or budget increase for the AI Office's systemic-risk unit in the next EU budget cycle.
- The six member states without designated competent authorities naming them, or facing infringement proceedings.
- A provider separating model and downstream system into different legal entities, changing which supervisor applies.
Disconfirming Signals
- A full year to August 2027 with no information request, evaluation or formal proceeding against any general-purpose model provider.
- The Commission handing general-purpose AI supervision back to national authorities through the implementing act on the Office's powers.
- A successful annulment action narrowing the AI Office's exclusive competence.
- National authorities completing designation across the EU-27 and taking the visible enforcement lead on frontier systems.
- The Office's first case closing through informal dialogue with no published finding and no binding commitment.
Strategic Questions
- Which of our AI systems fall to the AI Office, and which to a national authority?
- Could we answer an Article 91 documentation request within its deadline today?
- Do we staff Brussels for AI as we staff it for competition, or wait for the first case?
- Does splitting model and system across entities reduce our exposure, or only our clarity?
Keywords
EU AI Act; Digital Omnibus on AI; Regulation (EU) 2026/1744; AI Office; exclusive competence; Article 91 information request; Article 101 fines; general-purpose AI; market surveillance authority; national competent authorities; very large online platforms; enforcement capacity
Bibliography
Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.
- Tier 1 Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence. EUR-Lex (08/07/2026).
- Tier 1 AI Omnibus enters into force. European Commission (27/07/2026).
- Tier 1 Commission starts enforcing AI Act rules and new transparency requirements on 2 August. European Commission (31/07/2026).
- Tier 1 Marktüberwachung: market surveillance under the AI Regulation. Evergreen reference page, accessed 14/09/2026. Bundesnetzagentur (accessed 14/09/2026).
- Tier 2 How much power does the EU AI Office actually have?. Lawfare (18/05/2026).
- Tier 2 EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes. Gibson Dunn (27/05/2026).
- Tier 2 Loss of control: closing the governance gap before the first incident. Pour Demain (01/07/2026).
- Tier 3 Overview of all AI Act national implementation plans. EU Artificial Intelligence Act (17/06/2026).