AI compliance is no longer only about preparing for future rules.
People can now report suspected AI Act violations.
Since 2 August 2026, the European Commission's AI Office and national authorities have begun exercising enforcement powers under the EU AI Act.
The Commission has also launched dedicated complaint and whistleblower channels.
For businesses, this changes the practical question from:
"Are we ready for the AI Act?"
to:
"Could we explain and evidence what we are doing if someone raised a concern tomorrow?"
There is now a legal right to complain
Article 85 of the EU AI Act gives any natural or legal person who has grounds to believe the Regulation has been infringed the right to submit a complaint to the relevant market surveillance authority.
That could include an individual, organisation or company.
But this does not mean every complaint about every AI system goes directly to the European AI Office.
Responsibility depends on the system and the provision involved.
National competent authorities supervise many AI systems, while the European AI Office has direct enforcement responsibilities in specific areas.
The AI Office now has three reporting routes
The European Commission has introduced several mechanisms.
AI Act Complaint Tool
Individuals and organisations can submit complaints concerning alleged AI Act infringements that fall within the AI Office's enforcement remit.
Complainants must identify themselves and provide contact details.
Complaints can be submitted in any official EU language and supported with relevant documents.
AI Act Whistleblower Tool
People professionally connected to providers of GPAI models or AI systems within the European AI Office’s enforcement remit can report suspected violations through this tool.
Unlike the general complaint channel, this system allows anonymous reporting.
Supporting documents can also be submitted securely.
GPAI downstream-provider complaints
Companies building AI systems on top of general-purpose AI models have a separate complaint route.
Under Article 89(2), a downstream provider can raise concerns where it believes a GPAI model provider has failed to meet obligations covering areas such as technical information, copyright, training-data summaries, cybersecurity or systemic-risk requirements.
This is particularly relevant to AI companies integrating third-party foundation models into their own products.
Why this matters to ordinary businesses
Most organisations are not developing frontier AI models.
But complaint risk is wider than model development.
Customers may question an AI-powered interaction.
Employees may raise concerns about workplace AI.
Candidates may challenge AI-supported recruitment processes.
Business partners may ask how an automated decision was made.
And regulators may request information after receiving a complaint.
The practical risk is not simply having an AI system.
It is being unable to explain:
- what the system does
- why it is being used
- what data it receives
- who is responsible
- what human oversight exists
- what controls the organisation has implemented
Four things businesses should do now
1. Know where AI is being used
A complaint should not be the first time management discovers that a department has introduced an AI tool.
Maintain a practical AI inventory.
2. Assign ownership
Each significant AI use should have someone responsible for its purpose, risks and controls.
"IT manages it" is rarely enough.
3. Keep useful evidence
Retain relevant policies, vendor information, risk assessments, training records and decisions about important AI uses.
Good governance should be explainable after the fact.
4. Create an AI escalation route
Employees should know where to report concerns internally.
Customer-facing teams should know where AI-related complaints should go.
Do not allow a potentially significant AI issue to remain inside an ordinary customer-service queue.
This does not mean every complaint becomes an enforcement case
A complaint is not proof that an organisation has breached the AI Act.
Authorities assess whether the issue falls within their remit and whether further action is appropriate.
The Commission also states that complaints falling outside the AI Office's competence may, with appropriate consent and where relevant, be referred to another authority.
The important change is that formal reporting channels now exist.
Blanche perspective
AI governance is increasingly becoming evidence-based.
A policy saying "we use AI responsibly" is difficult to rely on if nobody can show which systems are used, who approved them or what controls were considered.
Businesses do not need to build a regulatory department.
But they should be able to answer five questions:
- What AI do we use?
- Why do we use it?
- Who owns it?
- What could go wrong?
- What did we do about that risk?
If those answers are documented, responding to a customer concern, internal report or regulator becomes considerably easier.
Sources
Primary and authoritative sources used for this Insight.
- EUR-Lex: AI Act consolidated 27 July 2026, Article 85 (binding EU law)
- European Commission: AI Act Complaints Tool
- European Commission: AI Act Whistleblower Tool
- European Commission: The enforcement framework of the AI Act
- European Commission: Complaints channel for downstream providers using GPAI models
- European Commission: Enforcement and transparency rules from 2 August, 31 July 2026
- European Commission: AI Board holds its ninth meeting, 18 September 2026