Governance, Enforcement, Penalties, and Sandboxes

Who actually runs the AI Act — the AI Office, the Board, and national market surveillance authorities — how enforcement escalates from evaluation to Union-wide safeguard, what individuals can claim under Articles 85–87, the three-tier penalty regime, the sandbox and real-world-testing machinery, and how the Act meshes with GDPR, DSA, product liability, and the Digital Omnibus.

Content current as of 2026-09.

Lessons

  1. The governance stack: from AI Office to your national regulator
  2. Market surveillance powers and the escalation ladder
  3. What individuals get: complaints, explanations, and whistleblowers
  4. Penalties: three tiers and a calculator mindset
  5. Sandboxes and real-world testing
  6. The wider EU stack and the Digital Omnibus