The Hague: The European Union’s flagship Artificial Intelligence Act has entered its first full year of phased enforcement, and the early evidence assembled by national supervisory authorities suggests that compliance trajectories diverge sharply between sectors. The European AI Office, hosted within DG CONNECT, this week published its inaugural annual report documenting more than 1,400 risk classifications submitted by deployers of general-purpose AI systems since the regulation’s high-risk provisions took effect.
The Dutch Autoriteit Persoonsgegevens, which serves as the country’s designated AI market surveillance authority, recorded a notable concentration of compliance inquiries from the healthcare diagnostics and human-resources screening sectors, domains where the regulation imposes the most stringent obligations around data governance, human oversight, and post-market monitoring. By contrast, deployment of foundation models in business-to-business analytics has proceeded with markedly fewer formal interactions with regulators, reflecting either better internal compliance or, as some civil society organisations argue, gaps in supervisory capacity.
A particularly contested area concerns the interaction between the AI Act’s transparency obligations and existing intellectual property frameworks. The European Commission’s implementing decision on training-data disclosure, adopted in April, requires providers of general-purpose models to publish sufficiently detailed summaries of copyrighted material used in training. Industry associations including DigitalEurope have argued the threshold remains ambiguous; rightsholder coalitions, conversely, contend that the published summaries to date have been too aggregated to permit meaningful enforcement of opt-out rights under the 2019 Copyright Directive.
The AI Office’s annual report also surfaces an emerging coordination challenge with sectoral regulators. Where AI systems intersect with medical devices, the Medical Device Coordination Group retains primary oversight; intersection with financial services brings in the European Banking Authority and ESMA. The result is a layered supervisory architecture that, while necessary, has produced documented instances of conflicting guidance. A working group on cross-regulatory coherence is expected to release its first set of joint interpretations before the summer recess.
Capacity remains the unspoken constraint. Member State authorities have collectively recruited approximately 320 specialised staff for AI supervision, against the Commission’s earlier indicative target of more than 500. Smaller Member States, notably the Baltic three and Malta, have entered formal cooperation arrangements to pool expertise rather than build parallel national capacity, a model that the AI Office has cautiously endorsed.
The first wave of administrative penalties is expected later this year. The European Data Protection Supervisor, acting in coordination with national authorities, has indicated that initial enforcement priorities will focus on prohibited practices under Article 5, notably social scoring and emotion recognition in workplace contexts, before turning to high-risk obligations. Maximum fines under the regulation reach 35 million euro or 7 percent of global turnover, whichever is higher, for the most serious infringements.
Whether the AI Act’s framework will retain its current shape under the pressure of rapid model evolution remains open. The general-purpose AI Code of Practice, originally conceived as a soft-law bridge to formal enforcement, has been described by senior Commission officials as a living instrument that may require periodic revision. The institutional architecture is, in effect, learning while operating.




