Who Will Enforce the EU AI Act? Mapping National Regulatory Authorities Across Europe

01 September 2026

Author: Orlando José Cabas Arráiz

The exponential evolution of artificial intelligence offers clear empirical benefits, yet it simultaneously presents complex legal and regulatory challenges. In response, the European Union has established a landmark framework through the Artificial Intelligence Act, designed to govern AI development and deployment across varied risk profiles. By codifying definitions, compliance requirements, and procedural mandates, the legislation creates a unified baseline across the internal market.

As the AI Act transitions into force, Member States are actively structuring their domestic regulatory architectures to enforce this framework. While the Regulation sets overarching horizontal standards at the EU level, effective enforcement depends on national bodies, specifically Market Surveillance Authorities (MSAs), Notifying Authorities, and designated National Competent Authority operating under Articles 28, 70, and 74.

To address this administrative fragmentation and track how European governments are putting AI oversight into practice, this database maps key regulatory actors across EU Member States and EEA countries. This resource tracks the emerging legal landscape, offering clear insights into national implementation strategies.

Legislative context and implementation timeline

Following the EU AI Act’s entry into force in August 2024, the regulation established a phased implementation schedule across the Single Market. Under Article 113, key provisions governing domestic governance structures, specifically the statutory designation of National Competent Authorities (Article 70), Market Surveillance Authorities (Article 74), and Notifying Authorities (Article 28), became fully applicable in August 2025. In parallel, ongoing European efforts such as the Digital Omnibus initiative aim to streamline administrative procedures and align oversight mechanisms across digital frameworks. In this evolving regulatory environment, mapping the authorities established across Member States provides a clear, real-time picture of how Europe’s AI enforcement architecture is operating in practice. 

Core metrics extracted from the database

This initiative provides a comprehensive mapping across 30 European jurisdictions, covering all 27 EU Member States alongside three EEA countries (Iceland, Liechtenstein, and Norway). In total, the database catalogs 72 distinct regulatory bodies with dedicated oversight or enforcement responsibilities under the AI Act framework. Demonstrating a high level of empirical rigour, 83.3% of these records (60 out of 72) are directly backed by primary sources, such as binding national legal texts, official decrees, or national gazettes.

From a functional standpoint, the mapping illustrates how Member States are distributing regulatory obligations. The dataset identifies 41 Market Surveillance Authorities (MSAs) designated under the Article 74 to monitor compliance and enforce requirements for high-risk AI applications. Additionally, it records 30 National Competent Authorities (NCAs) under Article 70 acting as central coordinating agencies, as well as 28 Notifying Authorities under Article 28 tasked with assessing and designating conformity assessment bodies.

Governance models: Centralised vs. Federated models

Beyond functional designations, a primary empirical finding from mapping national implementation across Europe is the clear structural preference for distributed oversight. Member States are taking two distinct structural paths:

  • Federated models (67% of mapped jurisdictions): The vast majority of Member States, including Ireland, Sweden, France, and Italy, have opted to distribute enforcement powers across existing sectoral authorities (such as data protection agencies, financial supervisors, and telecom regulators) under a designated National Competent Authority, leveraging established supervisory infrastructure.
  • Centralised models (26.7% of mapped jurisdictions): A targeted minority has created or empowered a primary entity to consolidate AI oversight—most prominently Spain with the establishment of AESIA, alongside Austria (RTR/KI-Servicestelle), Belgium (BIPT), the Netherlands (AP), Germany, Estonia, Luxembourg, and Malta.
  • Pending or undefined governance (6.6% of mapped jurisdictions): Certain jurisdictions, such as Bulgaria and Iceland, remain categorized as undefined; while foundational contact points may exist, comprehensive national governance structures have yet to be formally established.

Database architecture and methodology

To ensure methodological rigour and legal traceability, the database moves beyond a static directory by capturing the full functional and institutional profile of each regulatory actor. Rather than merely cataloging agencies, the framework maps national institutions directly to their specific statutory mandates under the AI Act, precisely distinguishing between Notifying Authorities (Article 28), National Competent Authorities (Article 70), and Market Surveillance Authorities (Article 74). This structure allows compliance teams and policy analysts to clearly differentiate overarching coordinating ministries from specialised sectoral regulators operating in areas like finance, healthcare, or workplace safety.

To account for the varying paces of national implementation across the Single Market, the dataset employs a dual-sourcing framework for verification. Primary legal instruments, including published decrees, binding national laws, and official parliamentary gazettes are cross-referenced against secondary EU-level registries and central announcements. By documenting both primary national decisions and secondary EU notifications, the architecture provides a transparent line of sight into both the official legal status of an authority at the domestic level and its current notification state within European Commission databases.

Conclusions

Certain authorities included in this database do not yet appear in centralised European Commission portals. These entities were identified through primary research into national legal frameworks and official government decisions, highlighting a natural administrative lag in centralised EU database updates while formal notification processes take place.

Where available, descriptions of authority roles, tasks, and competences have been extracted verbatim from official national legal texts and decrees. For higher-level designations, descriptions are aligned with standard functional provisions of the EU AI Act text for maximum clarity. Primary sources consist strictly of official legal instruments, published decrees, or official government portals. Secondary sources reference centralised EU registries or explanatory press releases used for cross-verification.

The transition from EU policy design to national implementation marks a critical phase in the governance of artificial intelligence across Europe. As Member States continue to formalise their regulatory bodies and complete formal notifications with European Commission registries, domestic supervisory ecosystems will become increasingly operational. Tracking these structural developments provides vital clarity for market actors, compliance specialists, and policymakers navigating the evolving legal landscape. This database will remain a living resource, updated continuously as further legal instruments and central notifications are published across the Single Market.