TL;DR
Enforcement of the AI Act began on 2 August 2026, run by the European Commission’s AI Office alongside national authorities. Three reporting routes are now open: a general complaints tool, an anonymous channel for insiders, and a narrower one for downstream providers. Penalties top out at €15 million or 3% of global annual turnover, whichever is larger.
The three routes
The complaints tool lets individuals and organisations flag suspected breaches by providers or deployers within the Office’s remit. Submissions have to fall inside Article 85, which excludes anything grounded in national law, other EU legislation, or the general-purpose model duties handled separately under Articles 53 to 55. Anonymity is not on offer here: complainants provide identification and contact details, set out what happened and where, and may write in any official language of the Union. Each submission gets a reference number and a confidential review, with referral onward to a national market surveillance body where warranted.
The whistleblower channel targets engineers, contractors and compliance staff with a professional connection to providers of general-purpose models or systems the Office oversees. Its defining feature is anonymity — a secure inbox lets the sender follow progress and respond to questions without ever being identified.
The downstream route is the most technical. A company building on someone else’s general-purpose model can complain under Article 89(2) where it suspects the upstream provider has broken Articles 53 to 55, which cover technical documentation, information owed to downstream users, copyright policy, training data summaries, incident reporting and cybersecurity, and risk evaluation for systemic-risk models. Filing means qualifying yourself, arguing the case, attaching evidence, and emailing a signed form to the Office.
What enforcement is likely to look like
Veeam field CTO Edwin Weijdema expects the first year to bring far more corrective orders than headline fines, reasoning from how enforcement of GDPR and NIS2 unfolded. The greater commercial exposure, he argues, is not the penalty but an instruction to stop running a system until you can demonstrate compliance — a disruption capable of hurting more than a one-off payment.
Looking forward
Recent containment failures at OpenAI and Anthropic are exactly what Brussels designed this regime to catch. For UK firms the practical point is jurisdictional: selling AI into the EU brings these duties regardless of the UK’s lighter-touch stance, and the anonymous channel means a report can just as easily originate inside a British supplier’s own staff.