The EU Commission’s AI Office receives new powers for direct oversight of major providers of generative AI systems, fundamentally reorienting European control strategy.
The adoption of AI systems is systematically outpacing established governance and oversight mechanisms in organizations, creating risks for data protection, compliance, and transparency.
From July 2025, companies must train all employees in cybersecurity and AI governance under NIS2 and the EU AI Act, with documented programs and penalty risks for non-compliance.
In 2026, AI funding will only be granted to projects with demonstrable development risk, with the EU AI Act—which is being phased in starting 2025—serving as the baseline for eligible solutions.
The code of conduct provides signatories with direct compliance evidence to EU authorities, eliminating separate individual audits in each member state.