Sona.
World news, made local
Tech

Europe’s new AI complaint tool is not a universal help desk

The new form can send an alleged AI Act breach to the European AI Office, but the system, operator and type of complaint still determine the right route.

A conceptual AI complaint envelope enters a three-way regulatory routing switch over a map of Europe.
The EU complaint system routes allegations according to the AI system, operator and authority involved. AI generated image

A new complaint form can make a large law feel unexpectedly simple. Something involving AI went wrong, so open the European Commission’s form and report it.

The European AI Act is not organised that way. Its enforcement is split between the Commission’s AI Office, national authorities and the European Data Protection Supervisor. The new AI Act Complaint Tool, launched as enforcement powers began on 2 August, is therefore better understood as one entrance in a routed system, not a universal help desk for every bad answer, disputed bill or frustrating automated decision.

That distinction is not bureaucratic trivia. It determines who can examine the allegation and what the form can realistically do.

The Commission says natural people and organisations can use the tool to complain about alleged AI Act infringements by providers or deployers of AI systems. A submission can be made in any official EU language and supported with relevant documents. The form asks for the country where the incident occurred and a detailed description.

It is not anonymous. The complainant must provide identification and contact details so the case can be assessed. After submission, the system generates a reference number. The AI Office says it handles complaints confidentially and will say when a matter falls outside its remit. With the complainant’s prior consent, it may refer an appropriate case to a national market surveillance authority or an authority responsible for fundamental-rights law.

None of that means filing the form establishes a breach. Article 85 of the AI Act gives natural and legal persons a right to lodge a complaint when they have grounds to consider that the law has been infringed. The complaint becomes information for market surveillance. It is an allegation to be assessed, not a ruling, refund process or instant product-support ticket.

The central routing question is who controls the relevant AI system and where it sits in the Act’s enforcement structure.

The Commission’s current enforcement guide says the AI Office supervises providers of general-purpose AI models. It also covers AI systems developed by the same provider, or business group, as the underlying general-purpose model, plus systems integrated into very large online platforms or search engines designated under the Digital Services Act.

National competent authorities enforce the rules for other AI systems. Each EU member state is meant to designate market surveillance bodies and a public single point of contact. A recruitment tool, public-service system or sector-specific product may therefore belong with a national or specialist authority rather than the Commission form, depending on the facts and the applicable provisions.

A third route applies to AI used by EU institutions, bodies and agencies. The European Data Protection Supervisor is the market surveillance authority there.

The route is not always obvious from the interface. A chatbot can carry one company’s name while relying on another company’s model. An AI feature can sit inside a very large platform, inside ordinary business software or inside a public body’s service. The same visible chat box can therefore lead to a different regulator because the provider, deployer and distribution setting are different.

The Commission launched several tools together, and their names are easy to blur.

The public AI Act Complaint Tool is for identified natural or legal persons raising an alleged infringement within the AI Office’s competence. The AI Act Whistleblower Tool is different. It is for people professionally connected to providers of general-purpose models or AI systems within the Office’s remit. Eligible users can report anonymously, attach documents and use a secure inbox while protecting their identity.

There is also a separate route for downstream providers that build an AI system on somebody else’s general-purpose model. That channel concerns model-provider duties under Articles 53 to 55, including technical information, copyright policy, training-content summaries, serious-incident reporting and systemic-risk work. It requires an identified, reasoned complaint and is not the general public form.

These distinctions prevent one inbox from pretending it can resolve every layer of the AI supply chain. They also make the first useful description of a problem more concrete: the system used, the company or public body operating it, the underlying model provider if known, the country and date, and the part of the AI Act thought to be relevant.

That is not a demand for a legal brief. The Commission’s own form asks for a detailed account and allows supporting material. A clear chronology and the exact product or service are more useful than a broad claim that “the AI was unfair”. Supporting material should be relevant to the allegation and should not be treated as an invitation to upload unrelated private records.

The complaint tools arrived with a genuine enforcement milestone. From 2 August, the AI Office and national authorities began exercising powers over provisions that are now enforceable, including certain transparency rules. Chatbots and other directly interactive AI systems must inform people when they are dealing with AI unless that is already obvious in context. Deepfakes face disclosure duties, while synthetic content is subject to machine-readable marking requirements.

It would still be misleading to say every part of the AI Act switched on at once. The Commission’s current timeline puts many rules for Annex III high-risk systems at 2 December 2027 and rules for high-risk AI embedded in regulated products at 2 August 2028. Other duties, including prohibited-practice and general-purpose-model provisions, have their own application history and enforcement scope.

A complaint must therefore connect to a provision that applies to the system and time in question. The existence of a form does not pull a future obligation into force early.

The useful achievement is narrower. Europe now has a visible path for turning an alleged AI Act breach into a case that can be triaged, referred and assessed. Its first test is not whether the story sounds serious. It is whether the system, operator and rule lead to the right authority.

Editorial note. This article is general technology and regulation reporting. It is not legal advice, a determination that the AI Act applies to a particular system, or guidance on an individual complaint.

Sources

  1. European Commission, AI Act complaints tool, updated 31 July 2026 and extracted 4 August 2026. Verified: scope, identity requirement, official-language access, incident-country and detail fields, supporting documents, reference number, confidentiality and possible referral with consent
  2. European Commission, AI Act enforcement framework, updated 31 July 2026 and extracted 4 August 2026. Verified: division between the AI Office, national authorities and EDPS; AI Office remit; monitoring tools; 2 August enforcement milestone; transparency duties; and later high-risk-system dates
  3. AI Act Service Desk, Article 85, extracted 4 August 2026. Verified: right of natural and legal persons to complain when they have grounds to consider that the Act has been infringed, and the role of complaints in market surveillance
  4. European Commission, market surveillance authorities under the AI Act, extracted 4 August 2026. Verified: national enforcement role, single-point-of-contact structure, complaint function and EDPS responsibility for EU institutions
  5. European Commission, AI Act Whistleblower Tool, updated 31 July 2026 and extracted 4 August 2026. Verified: eligibility based on professional connection, anonymous reporting, EU-language support, documents and secure inbox
  6. European Commission, downstream-provider complaints channel, published 31 July 2026 and extracted 4 August 2026. Verified: distinct Article 89(2) channel, Articles 53 to 55 scope, identification and evidence requirements, and exclusion from the public form
  7. European Commission press release, published 31 July 2026 and extracted 4 August 2026. Verified: 2 August enforcement start and examples of chatbot, deepfake and machine-readable transparency requirements

Help us improve

Was this article useful?

One anonymous tap helps Sona improve future reporting, headlines and source context.

Up next

A mechanical stop interrupts an endless feed test rig representing the EU Meta design case.
Tech
The EU’s Meta case turns infinite scroll into a product design test

The Commission’s findings are preliminary, but the changes it sketches reach beyond screen-time reminders to autoplay, feed endings and recommendation logic.

Continue reading

More in Tech

A mechanical stop interrupts an endless feed test rig representing the EU Meta design case. Tech
The EU’s Meta case turns infinite scroll into a product design test
Two standardised mobile coverage map plates compare the same Australian road and location pin. Tech
Australia’s new mobile coverage maps make 4G and 5G easier to compare
A conceptual privacy iris separates a TikTok minor account from accepted contacts, a global audience and a recommendation rail. Tech
The EU’s TikTok case turns a privacy setting into a design test
Hannah Wright, Senior Editor at Sona News
Written by
Hannah Wright
Senior Editor, Sona News

British journalist and Senior Editor at Sona News, covering politics, macro-economics and institutions from London.

Read next The EU’s Meta case turns infinite scroll into a product design test