Most deployers in Europe still do not know which national body will supervise their compliance. This tracker exists to answer that question for every Member State. The designation picture below was re-read at national sources on 17 August 2026, and it had moved substantially since this page was first written: four Member States that this tracker described as pending have since enacted or designated. Where a claim could not be confirmed at a national source, this document now says so instead of carrying the old entry forward.

Key takeaways

  • Article 70 required Member States to designate national competent authorities by 2 August 2025. That deadline passed. As of 17 August 2026 the group with a designation resting on an enacted law or a published government decision includes Cyprus, Denmark, Finland, Germany, Hungary, Ireland, Italy, Lithuania, Malta, Poland and Sweden.
  • Three further Member States, Luxembourg, Slovenia, and Spain, have designations pending final adoption, acknowledged by the European Commission's official list but not yet fully notified.
  • The rest are in various stages of legislative drafting or consultation, or have published nothing actionable. Among these are France, the Netherlands and Spain, all with published draft schemes and none with a completed designation.
  • Italy enacted the first dedicated national AI law in the EU on 10 October 2025, designating the National Cybersecurity Agency (ACN) as market surveillance authority and single point of contact.
  • The absence of a designated authority does not suspend AI Act obligations. The Article 99 penalty regime has applied since 2 August 2026 as Regulation law, in respect of the obligations that are themselves in application: the Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and Article 4 AI literacy. Annex III duties are not among them until 2 December 2027.
  • Deployers operating across multiple Member States face genuine multi-authority exposure. Even where the primary supervisor is in the deployer's home Member State, Article 74 enables affected-state authorities to coordinate enforcement and request information from the lead supervisor.
  • The penalty ceiling for deployer obligation violations under Article 99(2) is EUR 15 million or 3 per cent of worldwide annual turnover, whichever is higher. Every deployer should be able to name the authority most likely to enforce that ceiling against it, in every Member State where it operates.
  • Update, 17 August 2026: the Digital Omnibus entered into force on 27 July 2026, six days before the original deadline, correcting the 3 August entry below. Annex III high-risk obligations are deferred to 2 December 2027. The Article 99 penalty regime itself was not deferred; it applies from 2 August 2026 to the obligations that are in application.

Why Member State implementation matters

The EU AI Act is a Regulation, not a Directive. That means it does not require transposition into national law to produce legal effect. From the dates specified in Article 113, the obligations it contains apply directly to providers, deployers, importers, and distributors throughout the EU without any intervening national act. Unlike GDPR, where national data protection laws were necessary to fill in specific fields, the AI Act's core requirements are self-executing.

What Member States must do, under Article 70, is not transpose the Regulation but designate the national bodies responsible for enforcing it. At minimum, each Member State must designate one notifying authority (responsible for overseeing conformity assessment bodies) and one market surveillance authority (responsible for enforcing the Act against providers and deployers in the market). Where multiple market surveillance authorities are appointed, one must be nominated as the single point of contact for coordination with the European Commission and the AI Office.

The enforcement consequences of this structure are direct. When a deployer in Paris deploys a high-risk AI system in an employment screening context, the authority that will conduct any enforcement inquiry is the French market surveillance authority, not the AI Office in Brussels. When that deployer expands to deploy the same system in Amsterdam, the Dutch authority becomes relevant in parallel. The legal standard is uniform across all 27 jurisdictions because it is set by a single Regulation, but the enforcement entity, its powers, its institutional culture, and its enforcement priorities vary by Member State.

Article 70(2) adds a further layer. For AI systems used in specific high-risk categories involving personal data, including biometric identification, law enforcement, and a number of employment and financial screening applications, data protection authorities are designated as market surveillance authorities. This means the GDPR supervisory structure is directly embedded into AI Act enforcement for the most sensitive use cases.

The penalty exposure routed through national authorities under Article 99(2) reaches EUR 15 million or 3 per cent of worldwide annual turnover for deployer obligation violations. A deployer who has not identified the relevant national authority, not consulted its published guidance, and not structured its compliance documentation with that authority's expectations in mind is operating with a material and avoidable exposure gap.

The implementation timeline

Regulation (EU) 2024/1689 entered into force on 1 August 2024. Its obligations have applied in three phases.

The first phase covered the prohibited AI practices in Article 5: social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (with narrow exceptions), subliminal manipulation techniques causing harm, and exploitation of vulnerabilities of specific groups. These prohibitions have applied since 2 February 2025. Supervision and enforcement of them commenced on 2 August 2026.

The second phase, activating on 2 August 2025, covered the obligations for providers of general-purpose AI models under Chapter V. These obligations apply to providers of foundation models and large language models placing systems on the EU market, and are supervised primarily by the AI Office within the European Commission. The codes of practice for high-capability models were developed during this period.

The third phase split in two. The Article 50 transparency obligations and the Article 99 penalty regime activated on 2 August 2026 as originally scheduled and are in application now. The provider obligations in Chapter III (Articles 9 through 17) and the deployer obligations in Article 26, as they apply to the systems listed in Annex III, were deferred by the Digital Omnibus to 2 December 2027. This is the phase for which most organisations across the EU are building compliance programmes, and it is the phase the designation gaps below now have to close against.

A further deferral applies to high-risk AI systems embedded in the regulated products listed in Annex I, including machinery, medical devices, aviation equipment, and toys. These systems face a final deadline of 2 August 2028, moved by the Digital Omnibus from 2 August 2027.

Comparative status: all 27 Member States

The table below maps the designation status across all 27 Member States. Fifteen entries were re-read at national sources on 17 August 2026 and are dated in the table. The remainder still rest on the position as at April 2026 and are marked as such; treat those as a lead, not as a finding. Where nothing could be confirmed at a national source, the entry says "Pending verification" rather than naming a likely authority.

Note on methodology: the European Commission's list of market surveillance authorities under the AI Act carries a last update of 26 September 2025 and is no longer a reliable current picture; this tracker previously described it as updated continuously, which was wrong. Entries dated 17 August 2026 below were read at the Member State's own ministry, regulator, parliament or official gazette. Entries not so dated rest on the April 2026 research and have not been re-verified. Omissions or corrections can be sent to the editorial desk via the contact page.

Member State Designated Authority Designation Status National Legislation Official Contact
Austria Pending verification. AI Service Desk established under RTR (Broadcasting and Telecommunications Regulator). Pending No implementing act enacted, confirmed by RTR itself. A parliamentary motion to name the authority (517/A(E) XXVIII. GP) was postponed in committee again on 3 June 2026. The KI-Beirat sits at RTR. The Datenschutzbehoerde already holds market surveillance competence for certain law enforcement and border high-risk systems under existing Austrian law. Verified 17 August 2026. rtr.at
Belgium Pending verification. This tracker previously named BIPT as the proposed primary market surveillance authority. That could not be confirmed on any Belgian official domain on 17 August 2026, including BIPT's own AI Act page, and it has been withdrawn. Proposed No implementing law enacted. FOD Economie states only that implementation of the governance framework is under way. The BIPT designation attributed here to a Government Declaration of 31 January 2025 could not be found at source and appears to have been a conflation with BIPT's Data Act coordinator role. Verified 17 August 2026. bipt.be
Bulgaria Pending verification. Ministry of Electronic Governance identified as lead coordinator. Pending No implementing act enacted. 9 fundamental rights protection bodies designated. Pending verification
Croatia Pending verification. Central State Office for Digital Society Development identified as lead. Pending No implementing act enacted. Ministry of Justice designated 7 fundamental rights protection bodies. Pending verification
Cyprus Commissioner of Communications (ΕΠΙΤΡΟΠΟΣ ΕΠΙΚΟΙΝΩΝΙΩΝ). Formally notified to European Commission. Formally Designated Formal notification made to Commission. 3 fundamental rights bodies identified (subject to revision). mcit.gov.cy
Czech Republic MPO is the confirmed lead ministry by government decision of 28 May 2025. The draft AI law names CTU as single point of contact, CNB and UOOU as sectoral market surveillance authorities, and UNMZ as notifying body. UOOU and the Public Defender of Rights are the two fundamental rights bodies. Verified 17 August 2026. Pending No implementing act enacted. NAIS 2030 approved by government resolution no. 520 of 24 July 2024. Verified 17 August 2026. Pending verification
Denmark Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen designated as market surveillance authorities for Article 5. Digitaliseringsstyrelsen is the central contact point and national coordinating supervisory authority, announced 2 September 2025. Supervision of high-risk systems and transparency obligations is still open. Verified 17 August 2026. Partial LOV nr 467 of 14 May 2025 enacted, enforcement provisions in force 2 August 2025. A follow-on bill, L 111 (2025/26), grants the future market surveillance authorities their powers; its adoption status could not be confirmed at ft.dk on 17 August 2026 and is not stated here. Verified 17 August 2026. digst.dk
Estonia Pending verification. Ministry of Economic Affairs and Communications and Ministry of Justice identified as leads. Pending No implementing act enacted. 3 bodies designated for fundamental rights protection. Pending verification
Finland Finnish Transport and Communications Agency (Traficom) as Article 70(2) national contact point, coordinating implementation. Supervision distributed to existing sectoral market surveillance authorities including Tukes, Fimea and the Data Protection Ombudsman. The count of ten previously given here could not be confirmed at a Finnish official source and has been withdrawn. Verified 17 August 2026. Formally Designated Government Proposal HE 46/2025, TaVM 18/2025, EV 162/2025. National implementing acts in force 1 January 2026. Note that Finland is blank on the European Commission's market surveillance authority list, so this designation rests on Finnish law rather than on Commission notification. Verified 17 August 2026. traficom.fi
France No authority formally designated. In the DGE draft scheme, DGCCRF is the coordinator and single point of contact, DGE is the French representative to the European AI Board, and CNIL is proposed for biometric and emotion prohibited practices plus high-risk employment, education, justice and democracy systems. The scheme applies only if Parliament accepts it. Verified 17 August 2026. Overdue DGE draft designation of 17 market surveillance authorities published 9 September 2025. Provisions subsequently withdrawn from the parliamentary bill and re-tabled. No implementing law enacted. Verified 17 August 2026. entreprises.gouv.fr (DGE, draft scheme)
Germany Bundesnetzagentur (BNetzA) is the market surveillance authority, the contact point and the complaints body. On Article 28 notification, the notifying authority sits with the authorities already designated for the relevant Annex I legislation; BNetzA holds it for Directive 2014/53/EU. Under the KI-MIG, notification duties sit with the authorities already designated for the relevant Annex I legislation. Germany's national accreditation body, DAkkS, accredits conformity assessment bodies and holds no notification role. Verified 17 August 2026. Formally Designated KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG) enacted. Bundestag adopted it on 11 June 2026, Drucksache 21/4594, committee version 21/6407. Promulgated BGBl. I 2026 Nr. 223, in force 29 July 2026. Verified 17 August 2026. bundesnetzagentur.de
Greece Pending verification. Ministry of Digital Governance identified as lead. 4 fundamental rights bodies designated. Pending No implementing act enacted. Pending verification
Hungary Minister for National Economy (primary MSA and single point of contact). National Accreditation Authority (NAH) as notifying authority. Hungarian National Bank for financial sector AI. Formally Designated Act LXXV of 2025 entered into force 1 December 2025. Hungarian Artificial Intelligence Council established for strategic oversight. kormany.hu
Ireland 15 national competent authorities, designated 16 September 2025, including the Data Protection Commission and the Central Bank of Ireland. The AI Office of Ireland, established under the Regulation of Artificial Intelligence Act 2026, is the single point of contact and has been operational since 2 August 2026. The health bodies are the Health and Safety Authority, the HSE and the HPRA; HIQA is not among them. Verified 17 August 2026. Formally Designated Government approved a roadmap designating an initial eight bodies on 4 March 2025; the full fifteen followed on 16 September 2025. The Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July 2026 and establishes the AI Office of Ireland. Verified 17 August 2026. enterprise.gov.ie
Italy National Cybersecurity Agency (ACN) as market surveillance authority and single point of contact. Agency for Digital Italy (AgID) as notifying authority. Formally Designated Law No. 132/2025 entered into force 10 October 2025. First dedicated national AI law in EU. Coordination Committee at Presidency of Council of Ministers. acn.gov.it
Latvia The Consumer Rights Protection Centre (Pateretaju tiesibu aizsardzibas centrs) appears on the European Commission's market surveillance authority list without a pending marker. This tracker previously recorded Latvia as pending, which the Commission's own list contradicts. Verified 17 August 2026. Pending No implementing act enacted. Latvian National Accreditation Bureau designated for accreditation functions. Pending verification
Lithuania Communications Regulatory Authority (RRT) as market surveillance authority and single point of contact. Innovation Agency as notifying authority. Formally Designated Parliamentary amendments to Law on Technology and Innovation and Law on Information Society Services passed January 2025. AI regulatory sandbox established. rrt.lt
Luxembourg National Commission for Data Protection (CNPD) as primary market surveillance authority and single point of contact. CSSF for financial sector. Judicial Supervisory Authority for court AI. Pending Final Adoption Projet de loi 8476, deposited 23 December 2024, still in committee. Most recent step is the Conseil d'Etat opinion of 10 July 2026. Named authorities: CNPD, CSSF, Institut Luxembourgeois de Regulation, ALIA and the Autorite de controle judiciaire. Verified 17 August 2026. cnpd.public.lu
Malta Malta Digital Innovation Authority (MDIA) as market surveillance authority and notifying authority. Information and Data Protection Commissioner for personal data AI systems. Formally Designated Formal designation completed. 10 fundamental rights protection bodies identified. MDIA has operated since 2018 under the Innovative Technology Arrangements and Services Act. mdia.gov.mt
Netherlands The published draft bill names ten market surveillance authorities: AP, RDI, ILT, IGJ, NVWA, NLA, AFM, DNB, PGHR and ABRvS, with AP and RDI coordinating. ACM is not among them. This tracker previously carried the five-authority model from the November 2025 advisory, which the draft bill superseded. Verified 17 August 2026. Overdue The Uitvoeringswet AI-verordening went to internet consultation from 20 April to 1 June 2026. It remains a draft bill, not law, and the supervisory split it proposes is not settled. Verified 17 August 2026. autoriteitpersoonsgegevens.nl
Poland Commission for the Development and Safety of AI (KRiBSI) is the market surveillance authority under the enacted law, with the Minister for Digital Affairs as notifying authority. KRiBSI is not yet constituted: its chair is appointed by the Sejm with Senate consent, expected October 2026, operational November 2026. Verified 17 August 2026. Formally Designated Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji, Dz.U. 2026 poz. 1003, published 27 July 2026, in force 11 August 2026. Penalty provisions apply from 28 October 2026. KRiBSI composition: UOKiK, KNF, KRRiT and UKE representatives. Verified 17 August 2026. Pending verification
Portugal ANACOM is the cross-cutting coordinator of the 14 designated fundamental rights bodies and ran a public consultation on draft Article 5 implementing recommendations, decided 16 June 2026. The Ministry of Youth and Modernisation holds the AI portfolio. AMA was named here as lead in earlier versions of this tracker and appears in no official AI Act material; that attribution is withdrawn. Whether ANACOM is the Article 70 authority is not confirmed. Verified 17 August 2026. Pending No implementing act enacted. Pending verification
Romania Pending formal designation. Authority for the Digitalization of Romania (ADR) proposed as lead under draft national strategy. Overdue Draft bill Pl-x nr. 184/2025 registered in Senate March 2025, unapproved as of April 2026. National AI Strategy 2024 to 2027 published. Pending verification
Slovakia Pending verification. Ministry of Investment, Regional Development and Informatics identified as lead. 2 fundamental rights bodies designated. Pending No implementing act enacted. CERAI ethics commission established 2020. AISlovakia platform operational. Pending verification
Slovenia AKOS (Agency for Communication Networks and Services) proposed as market surveillance authority. Pending Final Adoption Acknowledged in Commission's pending list. Expert council establishment underway. 10 fundamental rights bodies designated. akos-rs.si
Spain AESIA (Agencia Española de Supervisión de Inteligencia Artificial) is the central body in the draft law, which also designates Banco de España, AEPD and the CGPJ as market surveillance authorities in their own domains. Verified 17 August 2026. Pending Final Adoption On 26 May 2026 the Consejo de Ministros approved the Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial and sent it to the Congreso de los Diputados. Final designation depends on its passage. Verified 17 August 2026. aesia.digital.gob.es
Sweden Five national competent authorities assigned by government decision of 12 June 2026 (Fi2026/01365): PTS, Integritetsskyddsmyndigheten, Finansinspektionen, Lakemedelsverket and Swedac. PTS holds the main responsibility and is the intended single point of contact, on an interim mandate running to 31 December 2026. Digg is not designated. The count of four fundamental rights bodies previously stated here could not be confirmed and is withdrawn. Verified 17 August 2026. Proposed Designated by government decision, not by statute. The underlying inquiry, SOU 2025:101 of 6 October 2025, proposes eleven market surveillance authorities and two notifying authorities; no implementing act is enacted. Ministry of Finance is the lead ministry. Verified 17 August 2026. pts.se

Status legend: Formally Designated = notified to Commission or equivalent formal act. Pending Final Adoption = acknowledged in Commission's pending list. Proposed = published in official government document but not legally enacted. Partial = one authority designated, remainder pending. Pending = no confirmed authority. Overdue = August 2025 deadline passed with no credible progress.

The five most-developed Member States

Italy

Italy holds a singular position in EU AI Act implementation. Law No. 132/2025, signed into law on 10 October 2025, made Italy the first EU Member State to enact dedicated and comprehensive national AI legislation complementing the Regulation. The law does not attempt to replicate the AI Act's requirements, which apply directly, but addresses areas the Regulation leaves to national discretion: sectoral rules for specific high-risk applications, governance of AI in the public sector, obligations for AI use in medical, legal, and media contexts, and the designation of national supervisory bodies.

The National Cybersecurity Agency (ACN) is designated as both market surveillance authority and single point of contact with EU institutions. This choice reflects Italy's view that AI risk is principally a cybersecurity and critical infrastructure concern rather than primarily a data protection matter. The Agency for Digital Italy (AgID) serves as notifying authority. A Coordination Committee at the Presidency of the Council of Ministers provides cross-government oversight. The Garante per la protezione dei dati personali retains its GDPR supervisory function and its Article 70(2) role as market surveillance authority for personal data-intensive AI use cases, operating in parallel with ACN.

Deployers in Italy should direct AI Act compliance enquiries to ACN for general high-risk AI matters and to the Garante for any system processing personal data in a high-risk context. ACN has begun publishing operational guidance for sectors identified in the national AI law, including healthcare and media.

Ireland

Ireland's implementation is notable for both its speed and its structural ambition. The government approved a roadmap on 4 March 2025 designating an initial eight bodies, and completed the designation of 15 national competent authorities on 16 September 2025, rather than creating a single new body. The rationale was explicit: existing sectoral expertise should not be duplicated when it already exists within established regulators.

Ireland was among the first Member States to meet the designation milestone. The Data Protection Commission, which already supervises a substantial share of EU GDPR enforcement given the concentration of technology companies in Dublin, takes responsibility for AI systems involving personal data. The Central Bank of Ireland covers financial services AI. The health bodies are the Health and Safety Authority, the Health Service Executive and the Health Products Regulatory Authority. An earlier version of this tracker named HIQA in that role; HIQA is not among the fifteen and that sentence has been removed.

The Regulation of Artificial Intelligence Act 2026 was signed into law on 21 July 2026 and establishes the AI Office of Ireland, which coordinates the 15 authorities and is the single point of contact. It has been operational since 2 August 2026. An earlier version of this tracker named the Minister for Enterprise, Tourism and Employment as the single point of contact; that is superseded. Given Ireland's role as European headquarters for most of the world's largest AI system providers, the DPC's AI Act posture will have outsized practical significance for the European enforcement landscape.

Germany

Germany has completed formal designation. The KI-MIG (KI-Marktüberwachungs- und Innovationsförderungsgesetz) was adopted by the Bundestag on 11 June 2026, Drucksache 21/4594, committee version 21/6407, promulgated as BGBl. I 2026 Nr. 223 and in force since 29 July 2026. It makes the Bundesnetzagentur (Federal Network Agency, BNetzA) the market surveillance authority, the contact point and the complaints body, and the operator of the national AI regulatory sandbox and the Koordinierungs- und Kompetenzzentrum KI-VO (KoKIVO). An earlier version of this tracker described the KI-MIG as a draft in consultation; it is law.

The BfDI retains its role as the data protection authority and will function as a market surveillance authority for personal data-intensive high-risk AI systems under Article 70(2). The BSI (Federal Office for Information Security) retains oversight where AI systems intersect with cybersecurity obligations. Germany's federal structure means that Länder-level sectoral regulators will also play roles in specific domains. The BNetzA's designation as coordinating authority is designed to impose coherence on this distributed system.

Deployers operating in Germany now have a named counterpart. Treat the BNetzA as the contact for general AI Act matters and the BfDI for any AI system processing personal data. On Article 28 notification, the notifying authority sits with the authorities already designated for the relevant Annex I legislation; BNetzA holds it for Directive 2014/53/EU. Germany's national accreditation body, DAkkS, accredits conformity assessment bodies under Regulation (EC) 765/2008 and the AkkStelleG. It holds no notification role under Article 28.

France

France's implementation has been characterised by ambition in design and delay in execution. The Directorate-General for Enterprises (DGE) published a detailed draft on 9 September 2025 proposing 17 market surveillance authorities. In that scheme the DGCCRF is the coordinator and the single point of contact under Article 70(2), the DGE is the French representative to the European AI Board, and CNIL is proposed for biometric and emotion prohibited practices together with high-risk employment, education, justice and democracy systems. The scheme applies only if Parliament accepts it.

The political complication is that the designation provisions were withdrawn from the bill submitted to Parliament and re-tabled, leaving the September 2025 draft without legislative authority. As of 17 August 2026, France remains without formally designated authorities, a year after the Article 70 deadline. The CNIL continues to operate as the de facto interim supervisory body for AI systems involving personal data, but its formal authority under the AI Act awaits a parliamentary act.

Deployers in France should treat CNIL as the most likely enforcement contact for personal data AI systems and maintain documentation sufficient to answer a CNIL inquiry under its existing GDPR powers. Do not describe CNIL as the French AI Act authority or as the single point of contact. The published draft gives the coordinating role and the single point of contact to the DGCCRF, and nothing is adopted.

Netherlands

The Netherlands has taken one of the most analytically thorough approaches to implementation while remaining formally undesignated. In November 2025, the Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) published a joint advisory to the Minister of Economic Affairs and the State Secretary for Legal Protection recommending a five-authority co-supervision model: AP, RDI, ACM, AFM and DNB. That advisory has since been superseded by the draft bill, which names ten market surveillance authorities: AP, RDI, ILT, IGJ, NVWA, NLA, AFM, DNB, PGHR and ABRvS, with AP and RDI coordinating. ACM is not among them.

The Uitvoeringswet AI-verordening, the national legislative vehicle for formal designation, went to internet consultation from 20 April to 1 June 2026 and remains a draft bill. The AP's Department for the Coordination of Algorithmic Oversight (DCA) functions as a practical coordination point in the interim. With Annex III now activating on 2 December 2027, the Dutch timetable has more room than it did, but nothing is designated.

Deployers in the Netherlands are in an unusual position: the most likely enforcement authority is known (AP for personal data AI systems) and has published relevant interim guidance, but the formal designation giving it full Article 70 powers has not been made. The AP operates under GDPR powers in the meantime, which substantially overlap with the AI Act's requirements for personal data-intensive systems.

The cross-border deployer's reading guide

A deployer that operates AI systems in more than one Member State faces a structural compliance question that the AI Act does not resolve with complete clarity: which authority is your primary supervisor, and when does a second authority's role become active?

The general rule, derived from Article 70(3) and the market surveillance coordination provisions in Articles 74 and 75, is that a deployer's primary supervisor is the market surveillance authority of the Member State where the deployer is established. If the deployer is not established in the EU, the primary supervisor is in the Member State where the affected persons are located, or where the system has its most significant impact.

A secondary authority becomes active when a deployer's AI system affects persons in its territory. Under Article 74, where a national authority has reasonable grounds to believe that an AI system presents a risk and the system is being used in its territory, it may require the deployer to provide information, conduct a technical assessment, and take corrective measures. This can occur even when the deployer's primary supervisor is in another Member State.

Article 75 provides for mutual assistance between national authorities. An authority in one Member State can request investigatory action from an authority in another, and the requested authority is required to act within specified timeframes. This mechanism creates genuine multi-authority exposure for deployers whose systems operate across borders. A complaint filed in any Member State where the system is deployed can initiate a process that reaches back to the deployer's home authority.

For deployers with operations concentrated in one Member State, the practical implication is simpler: focus compliance investment on understanding the designated authority in that Member State, engage with its published guidance early, and maintain documentation that could be produced to a secondary authority if required. For deployers with genuinely pan-European deployment, a compliance programme that is defensible to the most demanding designated authority in the operating footprint will be adequate for all others, since the substantive standard is uniform.

The European Artificial Intelligence Board, established under Article 65, provides the coordination layer above the national authorities. Its role is non-enforcement: it provides opinions, recommends guidelines, and supports the Commission in developing delegated acts. But its outputs on the application of the classification rules and the documentation standards will be the reference documents that national authorities use when assessing deployer compliance. Monitoring Board publications and Commission implementing guidelines is part of the compliance infrastructure for any multi-market deployer.

What to do if your designated authority has not been finalised

For deployers in a Member State that has not yet completed formal designation, the practical question is how to direct compliance investment and engagement in the absence of a formally designated counterpart.

The first step is to identify which existing sectoral authority most closely corresponds to the AI use case being deployed. In virtually every Member State, the data protection authority already has oversight capacity over AI systems involving personal data, derived from its GDPR mandate. For most high-risk AI deployers, this authority is the most likely interim enforcement contact.

The second step is to consult whatever interim guidance the likely authority has published. Several data protection authorities, including the German BfDI and the Dutch AP, have published AI-specific guidance documents that overlap substantially with AI Act requirements. CNIL has published detailed technical recommendations on AI systems developed with personal data. These documents represent the expectations of the bodies most likely to conduct early enforcement, even before formal designation is complete.

The third step is to maintain the minimum operator file described in Article 26 regardless of authority designation status. The AI Act obligations do not depend on formal authority designation. A deployer who holds a current risk record, an oversight register, a map of the instructions for use received from the provider, a logging schedule, and an incident protocol is in a defensible position regardless of which authority eventually conducts an inquiry. A deployer who has waited for formal designation to begin compliance work is not.

The fourth step is to subscribe to official channels from the likely supervisory authority. Most data protection authorities and digital regulators publish newsletters, consultation notices, and guidance documents. Designations, when they are completed, will be announced through these channels before they appear in secondary sources.

Finally, deployers in undesignated Member States should not interpret the absence of a formal authority as effective suspension of the AI Act. The European Commission retains oversight capacity, including through the AI Office, and has indicated that it will monitor Member State implementation progress. Cross-border coordination mechanisms remain available to fully designated authorities in other Member States. The risk of enforcement action does not wait for national designation to be complete.

Resources by Member State

The following are official publications from designated or proposed national authorities. Links are provided for verification and direct engagement.

Frequently asked questions

Which EU Member States have formally designated national supervisory authorities under the EU AI Act?

As of April 2026, three Member States have formally notified the European Commission of their market surveillance authorities: Cyprus (Commissioner of Communications), Italy (National Cybersecurity Agency, ACN), and Ireland (Minister for Enterprise, Tourism and Employment with 15 sectoral competent authorities). Lithuania, Finland, Malta, and Hungary have completed or substantially completed designation through national implementing legislation. Three further states (Luxembourg, Slovenia, Spain) have designations pending final adoption acknowledged by the Commission.

What is the Article 70 deadline for Member States to designate national competent authorities?

Article 70(1) of Regulation (EU) 2024/1689 required Member States to designate at least one market surveillance authority and one notifying authority by 2 August 2025. That deadline has passed. Most Member States are in breach of it. Deployers cannot treat the missed deadline as reducing their own compliance obligations, which run directly under the Regulation regardless of national designation status.

Which country was the first EU Member State to pass national AI legislation implementing the EU AI Act?

Italy enacted Law No. 132/2025, which entered into force on 10 October 2025, making it the first EU Member State to adopt a dedicated comprehensive national AI framework. The law designates the National Cybersecurity Agency (ACN) as market surveillance authority and single point of contact, and the Agency for Digital Italy (AgID) as notifying authority.

What is Germany's national authority for the EU AI Act?

Germany's draft implementing act (KI-MIG) proposes the Federal Network Agency (Bundesnetzagentur) as primary market surveillance authority and single point of contact. The BfDI covers data protection-related AI oversight. The implementing act had not passed Parliament as of April 2026 and formal designation remains pending.

What is France's supervisory authority structure for the EU AI Act?

France has not formally designated its authorities. A September 2025 DGE draft proposed 17 authorities including CNIL for 15 personal data use cases, but those provisions were withdrawn from the parliamentary bill. CNIL continues to publish guidance and operates as the practical interim contact for AI systems involving personal data.

How does the EU AI Act apply to deployers operating in multiple Member States?

The deployer's primary supervisor is in the Member State where it is established. Secondary authorities in other states where the system operates can initiate their own market surveillance activities under Article 74 and can request cooperation from the primary supervisor under Article 75. Cross-border deployers must maintain compliance documentation sufficient to respond to any authority in any jurisdiction where their system is deployed.

What penalty exposure do deployers face if their Member State has not designated a supervisory authority?

The Article 99 penalty regime has applied since 2 August 2026 as Regulation law, regardless of whether the Member State has completed designation. It bites on the obligations that are in application: the Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and Article 4 AI literacy. Annex III high-risk obligations are deferred to 2 December 2027 and cannot attract a penalty before then. Existing sectoral regulators hold interim oversight capacity where designation is incomplete.

What is Ireland's approach to EU AI Act implementation?

Ireland approved a roadmap on 4 March 2025 and designated 15 national competent authorities on 16 September 2025, drawn from existing sectoral regulators including the DPC and the Central Bank. The AI Office of Ireland, established under the Regulation of Artificial Intelligence Act 2026, coordinates them and is the single point of contact. It has been operational since 2 August 2026.

What national AI Act implementing legislation has Hungary passed?

Hungary enacted Act LXXV of 2025 on 1 December 2025. The Act designates the Minister for National Economy as primary market surveillance authority, the National Accreditation Authority (NAH) as notifying authority, and the Hungarian National Bank for financial sector AI. It also establishes a Hungarian Artificial Intelligence Council for strategic governance.

What should deployers do if their Member State has not yet designated a national supervisory authority?

Identify the sectoral authority most likely to exercise interim oversight (usually the data protection authority for personal data AI). Consult its published guidance. Maintain the minimum Article 26 operator file. Subscribe to official channels for designation announcements. Do not interpret the absence of a designated authority as suspension of AI Act obligations.

Footnotes and source verification

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L, 2024/1689.
  2. Article 70(1), Regulation (EU) 2024/1689: designation deadline of 2 August 2025.
  3. European Commission, Market Surveillance Authorities under the AI Act (continuously updated): digital-strategy.ec.europa.eu. As of September 2025 update cited in this article: Cyprus (Commissioner of Communications), Italy (ACN), Ireland (Minister for Enterprise) formally notified. Luxembourg, Slovenia, Spain pending final adoption.
  4. EU Artificial Intelligence Act portal, Overview of all AI Act National Implementation Plans: artificialintelligenceact.eu. As of May 2025 snapshot: 3 states with clear designation, 10 partial, 14 unclear.
  5. Italy: Law No. 132/2025, entered into force 10 October 2025. Source: Norton Rose Fulbright, "Italy enacts Law No. 132/2025 on Artificial Intelligence": nortonrosefulbright.com.
  6. Italy ACN designation: Article 20, Law No. 132/2025. Analysis: Cleary Gottlieb, "Italy Adopts the First National AI Law in Europe Complementing the EU AI Act": clearygottlieb.com.
  7. Ireland: DETE announcement, 16 September 2025, "Ireland leads the way in EU AI regulation": enterprise.gov.ie.
  8. Ireland distributed model: Matheson, "Ireland Adopts Distributed Model for AI Oversight": matheson.com.
  9. Ireland National AI Office: Technology's Legal Edge, "Ready, set, regulate": technologyslegaledge.com.
  10. Germany KI-MIG: Simmons + Simmons, "Germany's Implementation Act for the EU AI Act": simmons-simmons.com. Pinsent Masons: pinsentmasons.com.
  11. France DGE draft: MIAI, "EU AI Act Implementation: France Still Without Designated National Competent Authorities": ai-regulation.com.
  12. CNIL Q&A on EU AI Act: cnil.fr.
  13. Netherlands AP/RDI advisory (November 2025): Autoriteit Persoonsgegevens, Department for Coordination of Algorithmic Oversight: autoriteitpersoonsgegevens.nl.
  14. Netherlands implementing act timeline (Q4 2026): Regulations.AI, Netherlands AI Regulation Overview: regulations.ai.
  15. Hungary Act LXXV/2025: CMS, "Hungary implements institutional framework for EU AI Act" (November 2025): cms-lawnow.com.
  16. Lithuania designation: Parliamentary amendments, January 2025. RRT and Innovation Agency. Source: AICR Consulting summary and Ministry of the Economy and Innovation: eimin.lrv.lt.
  17. Luxembourg CNPD: Arendt, "New Luxembourg bill designates national authorities under the AI Act": arendt.com. Pinsent Masons: pinsentmasons.com.
  18. Spain AESIA: Established September 2023 as autonomous public agency. Acknowledged in Commission pending list. EU AI Act portal, artificialintelligenceact.eu national plans.
  19. Belgium BIPT: Government Declaration of 31 January 2025. BIPT AI Act guidance page: bipt.be.
  20. Finland: Government Proposal HE 46/2025. Presidential assent 22 December 2025. Finnish Government announcement: valtioneuvosto.fi.
  21. Poland KRiBSI: Draft Act on AI Systems, June 2025 revision. Source: blog.ai-laws.org, "Unfinished Architecture? Poland's Draft Act on AI Systems": blog.ai-laws.org.
  22. Romania: No formal designation. Draft bill Pl-x nr. 184/2025. EuroCloud analysis: eurocloud.org.
  23. Malta MDIA: formally designated. MDIA established under Innovative Technology Arrangements and Services Act. Source: EU AI Act portal national plans.
  24. Articles 74 and 75, Regulation (EU) 2024/1689: cross-border market surveillance coordination mechanisms.
  25. Article 99(2), Regulation (EU) 2024/1689: EUR 15 million or 3 per cent of worldwide annual turnover for provider and deployer obligation violations.