EU AI OFFICE
- Status
- ACTIVE — European Commission department; appointments and structure effective 16 June 2024; GPAI enforcement powers applicable since 2 August 2025
- Hazard — Reach
- 82
- RCH / FND / ENT
- 8 / 8 / 7
- Conduct
- STATE-INSTRUMENT — FULLY STAFFED BEFORE ITS FIRST CASE
Institutional Archetype
THE STANDING ARMY — The archetype is the enforcer raised in advance of the war. The UK built a grader that tests on access the labs volunteer; the US built a grader whose purpose turns over with the administration; Brussels built the third thing — an office inside the Commission that can compel. By the statute’s own grant, the AI Office holds “the ability to conduct evaluations of GPAI models, request information and measures from model providers, and apply sanctions.” That is the structural power: not any single evaluation, but the conversion of model-grading from a courtesy the labs extend into an obligation the regulator enforces. The instrument is the office itself — six units, two advisors, more than 125 staff, standing — and the leverage is that everything the other graders ask for, this one can demand.
Mandate & Origin
The AI Office was announced in May 2024 as an internal department of the European Commission, its appointments and unit structure taking effect on 16 June 2024 — six weeks before the AI Act it enforces entered into force. Lucilla Sioli, a career Commission official from the digital directorate, was named to lead it. The launch plan: five main departments, each under a director, covering regulation and compliance, safety, excellence and robotics, AI for societal good, and innovation — 140 staff planned, roughly 80 of them still to be recruited at launch. The Commission’s current description: more than 125 staff — technology specialists, lawyers, policy specialists, economists — across six units and two advisors, with a mandate that includes “developing tools, methodologies and benchmarks for evaluating capabilities and reach of general-purpose AI models, and classifying models with systemic risks.” Its enforcement powers over GPAI models became applicable on 2 August 2025.
Funding & Backers
The office is funded by the Commission budget — a line item, not a ledger. The ledger worth reading runs the other direction: the regulator is itself a funder of the evaluation layer it relies on. METR — the independent evaluator that tests frontier models from the labs — names the European AI Office among its backers on its own about page, alongside the UK AI Security Institute. The enforcement office that grades the labs helps pay the third-party grader that also grades the labs. Nothing about the arrangement is concealed; METR discloses it. But the shape is worth stating plainly: in the evaluation economy this drawer documents, the EU AI Office sits on both sides of the counter — buyer of evaluations and enforcer of the regime that makes evaluations mandatory.
Actions & Leadership Choices
Founding purpose, judged on evidence. The office exists because the AI Act’s GPAI chapter needed an enforcer that member states could not each build separately — supervising frontier models is beyond any single national market-surveillance authority, and centralizing it in the Commission is the coherent design. Judged on its deeds, its first two years were spent building: recruiting toward 140, publishing guidance, drafting the Code, standing up the benchmark-and-evaluation capacity the statute promises. All of that is what a serious regulator does before its rules bite.
Consequential actions, and the docket that isn’t. The flagship deed is the GPAI Code of Practice (10 July 2025) and the signature campaign around it — a genuine institutional achievement measured in stakeholders convened and labs signed. What the record does not yet contain is enforcement: as of mid-2026, no public fine had been issued under the AI Act by the office or anyone else. When the Union moved against a frontier AI system in January 2026 — the Grok proceedings over AI-generated non-consensual imagery — it moved under the Digital Services Act, the older statute, precisely because the AI Act’s teeth had not yet engaged for that class of system. The standing army watched the first battle fought by the neighboring garrison. The office’s whole enforcement record is, so far, capacity.
Leadership choices. The office’s leadership is the Commission’s own bench — Lucilla Sioli, the career official who ran the digital directorate’s AI portfolio, moved over to run the enforcement arm of the law her directorate helped negotiate. That is the quiet contrast with the graders next door: the UK institute’s senior bench was seconded from the frontier labs, the US institute’s directorship turns over with elections, and the EU office is staffed by the permanent civil service that wrote the rules it now enforces. No revolving door with industry on the record here — the door revolves within the building, from drafting desk to enforcement desk. Continuity is the choice, and continuity cuts both ways: insulation from the labs, and no daylight between legislator and enforcer.
CONDUCT verdict: STATE-INSTRUMENT — FULLY STAFFED BEFORE ITS FIRST CASE. A coherently designed supranational enforcer, staffed by the civil service that drafted its statute, holding the West’s only compulsory model-evaluation and sanction authority, funding the independent evaluator, convening the code the labs sign — with an enforcement docket that is, two years in, still empty. The malice is not asserted; the sequence is the finding. The capability was built first. What it is eventually used for will be decided by people who have not arrived yet.
Sources: European AI Office — European Commission; AI Office set-up announced, Lucilla Sioli to be in charge — Euronews, 29 May 2024; The General-Purpose AI Code of Practice — European Commission; Meet the Chairs leading the development of the first General-Purpose AI Code of Practice — European Commission; AI Pact — European Commission; Meta says it won’t sign Europe AI agreement — CNBC, 18 Jul 2025; Introduction to the Code of Practice — artificialintelligenceact.eu; Implementation timeline — artificialintelligenceact.eu; Enforcement of Chapter V under the EU AI Act — artificialintelligenceact.eu; About METR — funder disclosure; EU Commission to open proceedings against Grok — RTÉ, 26 Jan 2026; EU investigation into Grok may expose problems with DSA — Compliance Week.
Get updates on the Evil Robots series
Newsletter essays on AI escape, deception, and the humans who built them.