Who enforces the EU AI Act? The authorities, and what changed on 2 August 2026
The EU AI Act stopped being a future problem on 2 August 2026. That is the Regulation's general application date under Article 113, and the European Commission marked it plainly: from that date "the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act."
Which raises the question most compliance plans skip: who, specifically, enforces it against you? The answer is not one regulator. It is three, split by what you are and what your AI is.
The short answer
| Who they supervise | Authority | Fine ceiling |
|---|---|---|
| Providers and deployers of AI systems | Your Member State's market surveillance authority | Up to €35M or 7% (prohibitions); €15M or 3% (most other duties) |
| Providers of general-purpose AI models | The AI Office (European Commission) | Up to €15M or 3% (Article 101) |
| EU institutions, bodies, offices and agencies | The European Data Protection Supervisor | Up to €1.5M (prohibitions); €750,000 (other breaches) — Article 100 |
For a normal company, the first row is the one that matters. Your regulator is national, not Brussels.
Your national market surveillance authority
This is the authority that can inspect you, demand documentation, evaluate your system, order corrective measures, and fine you.
Article 70 requires each Member State to establish or designate at least one notifying authority and at least one market surveillance authority as national competent authorities. One of the market surveillance authorities also acts as the single point of contact — the address for the outside world, including for complaints.
Two things follow that companies routinely get wrong:
- Your regulator may not be an "AI regulator". Member States were free to hand the job to an existing body. Germany gave it to the telecoms and networks regulator. Spain built a new agency. Ireland spread it across fifteen bodies with a coordinating office. There is no single European template.
- It may not be only one body. Sector regulators frequently keep their patch — financial supervisors for AI in banking and insurance, data protection authorities for their own remit. A single AI system can therefore sit under more than one authority.
The deadline for all of this was 2 August 2025, including the duty to publish contact details electronically. Which brings us to the awkward part.
Not every Member State is ready
The designation deadline passed a year ago, and it was widely missed.
As of a 17 June 2026 survey by the independent AI Act tracker artificialintelligenceact.eu, 9 Member States had designated both required authorities, 12 had only partial designations or pending legislation, and 6 had designated neither. (Those counts are an independent tracker's, not an official Commission figure — treat them as a directional picture rather than a legal statement.) By contrast, all 27 Member States had designated their fundamental-rights authorities, whose deadline fell earlier.
This is not a reason to relax. Three points:
- The obligations apply to you regardless. The AI Act is a Regulation. It binds you directly whether or not your government has finished naming its regulator.
- The gap is closing fast, and retroactively. Authorities that stand up in late 2026 will be looking at conduct from August 2026 onward.
- Complaints do not wait for tidy institutions. See below.
Germany, as the worked example
Germany finished its national plumbing with days to spare. The KI-MIG — the Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz — was signed on 22 July 2026, published as BGBl. 2026 I Nr. 223, and entered into force on 29 July 2026, four days before the Act's general application date.
Its § 2(1) is close to a one-liner: "Die Bundesnetzagentur ist die für die Einhaltung der Verordnung (EU) 2024/1689 zuständige Marktüberwachungsbehörde, soweit in diesem Gesetz nichts anderes bestimmt ist" — the Bundesnetzagentur is the market surveillance authority responsible for compliance with the AI Act, unless the law provides otherwise. That proviso is exactly where the sector carve-outs hang. Under § 6(1) it is also the single point of contact under Article 70(2). Financial-sector AI supervision goes to BaFin.
If you sell into Germany, that is your regulator's name. See our fuller guide to the AI Act in Germany.
The AI Office, and the powers it just gained
The AI Office is the Commission's central enforcement body. Its core remit is general-purpose AI models — it can request technical documentation, evaluate models, require corrective measures, and fine providers up to €15M or 3% under Article 101. Those fining powers were carved out of the 2 August 2025 start date and switched on with everything else on 2 August 2026.
The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — widened that remit. The AI Office now also takes exclusive supervisory competence over AI systems built on a GPAI model where the system and the model come from the same provider or the same group of undertakings, and over AI integrated into very large online platforms and search engines designated under the Digital Services Act.
The practical read: if you build your own foundation model and ship products on top of it, your regulator may be Brussels rather than your national authority. If you build on someone else's model, it is your national authority. (This expansion is reported consistently across legal analyses of the Omnibus; the underlying amendment sits in Regulation (EU) 2026/1744 — worth confirming against the text for your own structure.)
Three ways a problem reaches an authority
Enforcement is not only inspectors knocking. There are three inbound channels, and two of them are open to anyone.
1. Complaints — Article 85. "Any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority." That is a very low bar: a customer, a competitor, an advocacy group, or a former employee can file one, and the authority handles it within its ordinary market surveillance procedures.
2. Whistleblowers — Article 87. The whole article reads: "Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements." Because Article 87 falls under the Regulation's general application date, the EU Whistleblower Directive's protections attach to AI Act reports from 2 August 2026. The AI Office also runs an AI Act Whistleblower Tool — an encrypted channel where people professionally connected to providers within its remit can report anonymously, in any EU language, and follow up while staying anonymous.
3. Serious incident reports — Article 73. Providers of high-risk systems must report serious incidents to the market surveillance authority themselves. Note the sequencing: the high-risk obligations were deferred by the Digital Omnibus to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), so this channel opens with them, not in 2026.
Channels one and two are live now. You do not control who uses them.
What actually applies to you today
Enforcement starting is not the same as every obligation starting. As of 2 August 2026:
| Obligation | Status |
|---|---|
| Article 5 prohibitions | Applied since 2 Feb 2025 — enforceable |
| Article 4 AI literacy | Applied since 2 Feb 2025, softened by the Omnibus |
| GPAI model rules | Applied since 2 Aug 2025; Commission fines from 2 Aug 2026 |
| Article 50 transparency | Applies from 2 Aug 2026 |
| High-risk (Annex III) | Deferred to 2 Dec 2027 |
| High-risk (Annex I, embedded) | Deferred to 2 Aug 2028 |
The trap is assuming the high-risk delay bought you time across the board. It did not. Transparency duties are live, and they reach almost every company running a chatbot or generating content — see what Article 50 requires. For the amounts attached to each breach, see the fine structure.
What to do this month
- Name your authority. Identify the market surveillance authority and single point of contact in every Member State you sell into. If your government has not designated one, note that and re-check quarterly — it will appear.
- Check whether you are national or Brussels. If you provide a GPAI model, or ship systems built on your own group's model, the AI Office may be your supervisor directly.
- Assume a complaint can arrive tomorrow. Article 85 and Article 87 are open channels with no threshold. The people best placed to file are your own staff and your competitors.
- Close the transparency gap first. It is the obligation that is live, broad, and cheap to breach visibly.
The fastest way to see which obligations and which authority actually apply to you: answer a few questions about your AI use. To be told when an authority is designated, a national law lands, or a deadline moves, join the waitlist. If you are still working out whether any of this reaches you, start with which obligations apply to your company.
The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
Who enforces the EU AI Act?
Three sets of authorities, split by what is being supervised. National market surveillance authorities in each Member State enforce the rules against providers and deployers of AI systems. The European Commission's AI Office enforces the rules on general-purpose AI models, and — after the Digital Omnibus — on AI systems built on a GPAI model by the same provider or group of undertakings. The European Data Protection Supervisor enforces the Act against EU institutions, bodies, offices and agencies.
When did EU AI Act enforcement start?
2 August 2026. Article 113 sets the Regulation's general application date as 2 August 2026, and the European Commission confirmed that from that date the AI Office, together with national authorities, began enforcing the AI Act. Some parts started earlier: the prohibitions and AI literacy from 2 February 2025, and the general-purpose AI rules, governance framework and penalty regime from 2 August 2025.
Who do I contact about the EU AI Act in my country?
Your Member State's single point of contact. Under Article 70 each Member State must designate at least one notifying authority and at least one market surveillance authority, and one market surveillance authority acts as the single point of contact. Member States had to make contact details publicly available by 2 August 2025, and the Commission maintains a list. In Germany, for example, it is the Bundesnetzagentur.
Can someone report my company for an AI Act breach?
Yes, by two separate routes. Under Article 85, any natural or legal person with grounds to consider there has been an infringement may submit a complaint to the relevant market surveillance authority. Separately, Article 87 applies the EU Whistleblower Directive (EU) 2019/1937 to reports of AI Act infringements, and the AI Office runs an anonymous whistleblower tool for reports within its remit.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.