The European AI Office began on-site compliance audits of major cloud providers on Tuesday, examining data portability practices and documentation for high-risk artificial intelligence systems hosted in European Union regions. The inspections combine enforcement powers under the EU AI Act with parallel requirements from the Data Act that took effect in January.

Director-general Lucilla Sioli said auditors will review whether Amazon Web Services, Microsoft Azure, Google Cloud, Oracle, and OVHcloud charge prohibitive egress fees and whether application programming interfaces lock customers into proprietary formats. Providers received preliminary questionnaires in May; on-site visits run through September.

AI Act Scope

Cloud platforms are not automatically high-risk providers, but they must maintain technical documentation when hosting customer workloads classified as high-risk — including biometric identification, critical infrastructure management, and certain employment screening tools. Auditors will sample tenant configurations and request evidence that platform terms require downstream customers to comply.

Penalties reach 35 million euros or 7 percent of global turnover for the most serious AI Act violations. Data Act fines are lower but attach to switching barriers that EU competition officials believe suppress multi-cloud adoption.

Industry Response

Microsoft published a European Cloud Customer Bill of Rights in June pledging zero egress fees for customers switching providers within ninety days. Amazon announced a similar program limited to regulated industries. Google said existing free transfer tiers satisfy Data Act requirements. Advocacy group CISPE argued the pledges contain loopholes for database replication services.

U.S. officials raised concerns at the U.S.-EU Trade and Technology Council that audits could discriminate against American hyperscalers. Brussels countered that inspections apply equally to European OVHcloud.

Enterprise Implications

Chief information officers must inventory AI workloads by risk tier before year-end registration deadlines. Legal teams are drafting addenda requiring vendors to notify tenants if regulators request access to configuration data.

Consultancies including Deloitte and Accenture reported surging demand for EU AI Act readiness assessments, pricing engagements in the six-figure range for multinational banks.

What Comes Next

Preliminary audit findings may publish in October, potentially triggering formal infringement procedures before year-end. The office plans to hire 140 additional inspectors by 2027 as general-purpose AI model rules phase in.

For global technology policy, the audits test whether Europe can enforce digital sovereignty goals without fragmenting cloud markets so severely that European startups lose access to cutting-edge infrastructure.

Smaller European SaaS vendors asked auditors to examine whether hyperscaler marketplace listings bury compliance documentation for third-party models sold alongside infrastructure. The European AI Office said marketplace governance falls within scope when platforms profit from model distribution fees.

Cross-Border Services

Multinational banks asked whether audits extend to workloads processed in U.S. regions for European customers, a hybrid architecture common in global systemically important institutions. The AI Office said jurisdiction follows customer establishment location regardless of processing geography when EU personal data is involved.

Cloud providers hired former regulators in Brussels to manage inspector relationships, mirroring compliance buildouts that followed GDPR enforcement waves in 2018.

Draft audit findings may appear before European Parliament digital markets hearings in October, according to officials familiar with the inspection schedule.