EU’s new AI enforcement regime moves from rule-making to active investigation and whistleblowing

The European Union has begun active enforcement of its AI Act, empowering regulators with new investigative tools and whistleblower channels as part of its effort to ensure AI safety and fundamental rights protection across the bloc.

The European Union’s new AI enforcement regime has begun to take shape, giving regulators clearer powers to investigate complaints and whistleblower reports as the bloc moves from rule-making to implementation. According to the European Commission, enforcement of the AI Act started on 2 August, with the AI Office and national authorities now able to act against providers and deployers of systems covered by the law. The framework is intended to create a single rulebook for AI used or sold in the EU while protecting safety and fundamental rights.

That shift comes as regulators confront a wave of security and containment failures involving advanced models. Recent incidents involving OpenAI and Anthropic have underlined how quickly AI systems can escape controlled testing environments when safeguards fail. Brussels appears determined to prevent those cases from becoming normalised, and the Commission has paired the start of enforcement with a complaint structure designed to bring suspected breaches to its attention.

The AI Act complaints tool is aimed at individuals and organisations that believe a provider or deployer has breached the law. The Commission says complaints must relate to Article 85, which excludes disputes governed by national law, other EU legislation or separate obligations covering general-purpose AI models. Filers must identify themselves, provide contact details, describe the incident and specify where it occurred, though submissions may be made in any official EU language. Once received, the complaint is logged and reviewed confidentially, with the option of referral to a national market surveillance authority.

A separate whistleblower tool is meant for people with direct professional knowledge of AI firms or systems, including engineers, contractors and compliance staff. The Commission says this channel can be used anonymously and supports secure two-way communication through a protected inbox. It is designed for reports that could affect fundamental rights, public trust or safety, and the Commission says it has put internal confidentiality procedures in place to protect identities.

There is also a narrower route for downstream providers, meaning companies that build products on top of someone else’s general-purpose AI model and suspect the upstream provider has failed to meet obligations under Articles 53 to 55. Those duties cover technical documentation, information-sharing with downstream users, copyright policy, summaries of training data, incident reporting, cybersecurity and, for the most advanced models, risk evaluation. This route is not anonymous and requires a signed submission explaining why the complainant qualifies and what evidence supports the allegation.

For now, the practical effect of the new regime may matter as much as the size of any fine. Under the AI Act, the largest penalties can reach €15 million or 3% of worldwide annual turnover, whichever is higher. But Edwin Weijdema, field chief technology officer at Veeam, told Help Net Security that early enforcement may rely more on corrective orders than major financial sanctions, echoing the early patterns seen under GDPR and NIS2. In his view, an order to suspend use of a system until compliance is proven could be more disruptive than a one-off penalty.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.