TL;DR: The EU AI Act splits enforcement between national market surveillance authorities (MSAs) and the EU AI Office. MSAs handle most high-risk AI enforcement in the country where a system is placed on the market. The AI Office has exclusive authority over general-purpose AI (GPAI) model providers. Non-EU companies must appoint an EU representative under Article 25. Germany, France, the Netherlands, Belgium, and Ireland each have designated or interim authorities, but most member states are still finalising their national structures ahead of August 2026.
When the EU AI Act takes effect for GPAI models and high-risk AI systems in August 2026, one of the first questions companies ask is: who actually comes after me if I am not compliant? The answer is more layered than most compliance guides explain.
Unlike GDPR, where the lead supervisory authority model concentrates enforcement for multi-country data processing in one place, the EU AI Act uses a market surveillance model. Enforcement happens where your AI system is placed on the market or deployed, and the authority responsible is the one in that member state. That means a company selling into eight EU countries could, in theory, face oversight from eight different national bodies.
This guide walks through how the two-tier enforcement structure works, which authorities are leading in the major EU economies, and what your obligations are if you are a non-EU company.
How the two-tier enforcement structure works
The EU AI Act creates two separate layers of enforcement authority.
The first layer covers the vast majority of AI systems: high-risk AI systems listed in Annex III, limited-risk systems with transparency obligations, and general obligations for deployers. This layer is handled by national market surveillance authorities (MSAs) in each member state. Member states must designate at least one MSA. Some have designated multiple authorities with split competences by sector.
The second layer covers general-purpose AI models specifically: the foundation models and large language models that underlie many applications. The EU AI Office, a unit of the European Commission, holds exclusive competence here. It can investigate GPAI model providers directly, conduct evaluations of frontier models, and impose fines without going through national authorities.
The two tiers interact through a coordination mechanism. If a national authority finds that a product using a GPAI model has a problem that traces back to the model itself, it can refer the matter to the AI Office. Conversely, findings about GPAI models can inform national enforcement actions against deployers who use those models.
The EU AI Office: what it covers and how it operates
The AI Office sits within the European Commission's DG CNECT. It became operational in early 2024 and is building its enforcement capacity ahead of the August 2026 GPAI obligations.
Its primary enforcement powers concern GPAI model providers under Articles 51-55 of the EU AI Act. This covers providers of models with significant capabilities (those trained above compute thresholds set in Article 51) and frontier models with systemic risk. The AI Office can:
- Request technical documentation, including training data summaries and capability evaluations
- Conduct or commission evaluations of GPAI models
- Issue orders requiring providers to take corrective measures
- Impose fines up to 15 million euros or 3 percent of global annual turnover for non-compliance with GPAI obligations, and up to 3 percent for incorrect information
For companies that are pure deployers of GPAI models (not providers), the AI Office is not your direct enforcement body. Your national MSA handles deployer obligations.
Country-by-country guide to national market surveillance authorities
Germany
Germany has moved faster than most member states. The Federal Network Agency (Bundesnetzagentur, BNetzA) has been designated as the lead market surveillance authority for the EU AI Act. BNetzA already has experience with market surveillance in telecom and energy regulation.
The Federal Data Protection Commissioner (BfDI) retains a coordination role on AI matters that intersect with personal data processing, but BNetzA holds primary jurisdiction for AI Act enforcement purposes. Germany's AI supervision will likely integrate with existing sectoral frameworks: the financial regulator BaFin will keep authority over AI in financial services to the extent that existing financial legislation applies.
For most companies placing high-risk AI systems on the German market, BNetzA is the first contact point for AI Act matters.
France
France's enforcement picture is less settled. The country has not yet designated a single lead AI Act MSA. In the interim, competences are split:
- CNIL (the data protection authority) has jurisdiction over AI systems that process personal data, drawing on its GDPR powers and its AI-specific guidance published in 2024-2025.
- ANSSI (the national cybersecurity agency) covers cybersecurity-adjacent AI, especially for critical infrastructure.
- A new dedicated AI authority has been discussed but was not formally established at time of writing.
France is expected to designate its MSA structure by mid-2026. Until then, companies selling into France should treat CNIL as the most likely first-response authority for high-risk AI systems involving personal data, which covers most Annex III categories.
Italy
Italy designated the Agenzia per l'Italia Digitale (AgID) in coordination with the national cybersecurity agency (ACN) to prepare the country's AI Act implementation. The exact MSA designation was still being confirmed through national legislation as of Q2 2026. Italian data protection authority Garante maintains oversight where AI processing intersects with GDPR.
Spain
Spain created the Agency for the Supervision of Artificial Intelligence (AESIA) in 2023, making it one of the first EU member states to establish a dedicated AI regulator. AESIA is the designated MSA for AI Act purposes. It has been publishing guidance for Spanish companies and is expected to be one of the more active national enforcers.
Netherlands
The Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) has been designated as the Netherlands' primary MSA. The Dutch Data Protection Authority (AP) retains its GDPR enforcement role for AI systems involving personal data. The Netherlands is a significant hub for technology companies and is expected to see active enforcement given the concentration of EU operations there.
Belgium
Belgium is particularly relevant for companies that have their EU headquarters in Brussels or Ghent, given the concentration of EU institutions and multinationals. The Belgian Digital Regulatory Institute (BIPT) has been involved in AI Act preparatory discussions. Belgium has been slower than Germany and Spain in formally designating its MSA structure.
For companies whose EU-level AI governance decisions are made from Belgian offices, Belgian MSA authority may apply alongside the AI Office's GPAI competences.
Ireland
Ireland's position matters enormously for US technology companies. Many major tech firms incorporated their EU entities in Ireland, giving the Irish Data Protection Commission (DPC) lead supervisory authority under GDPR. The AI Act does not replicate this lead-authority model for AI enforcement, so the Irish MSA's jurisdiction is limited to AI systems placed on the Irish market, not necessarily the entire EU.
This is a meaningful difference from GDPR. A US company with an Irish EU entity cannot assume that Ireland is its single point of AI Act contact. If that company's AI system is deployed in Germany, BNetzA can investigate regardless of where the company is incorporated.
The Health Information and Quality Authority (HIQA) and the National Cyber Security Centre (NCSC) have sector-specific roles that may intersect with AI Act enforcement for medical and critical infrastructure AI.
How to identify which authority applies to your company
The determining factor is where your AI system is placed on the market, not where you are incorporated. "Placed on the market" means made available for the first time in exchange for payment or free of charge to a deployer in the EU.
If you sell or license a high-risk AI system to customers in multiple EU countries, the MSA in each of those countries has jurisdiction for their portion of the market. In practice, investigations are typically initiated by the MSA of the country where a complaint arises or where the harm occurs.
For GPAI model providers, the AI Office has EU-wide jurisdiction regardless of which countries your model is used in.
For deployers (companies using third-party AI systems in their own operations), the relevant MSA is in the country where the deployer is established and where the system is being used.
What national authorities can do during an investigation
National MSAs under the EU AI Act have broad investigation powers. They can:
- Request access to technical documentation, including the technical file required under Annex IV
- Request information from providers, deployers, importers, and distributors
- Conduct on-site inspections of facilities where AI systems are developed or operated
- Access source code where necessary to assess conformity
- Issue orders requiring corrective action, including modifications to AI systems
- Impose provisional bans on making a system available on the market pending investigation
- Refer cases to the AI Office where GPAI models are involved
- Propose fines to national courts or impose them directly depending on national implementing legislation
Fines are scaled by violation type. Prohibited-practice violations (Article 5) carry fines up to 35 million euros or 7 percent of global annual turnover. GPAI violations carry up to 15 million euros or 3 percent. Providing incorrect information carries up to 7.5 million euros or 1 percent.
Registration and notification obligations
Before an investigation ever starts, providers of high-risk AI systems have registration obligations. The EU AI Act database (EUID) is the central registry where providers and deployers register their systems before placing them on the market.
Registration is handled through the AI Office's portal. Providers register their system's details, including system name, version, purpose, categories of data used, conformity assessment status, and contact details. Deployers in certain categories (public sector use of Annex III systems) must also register.
See the high-risk AI documentation templates for August 2026 for what information the registration requires.
Article 25: the EU representative requirement for non-EU companies
If your company is not established in the EU but your AI system is placed on the EU market, Article 25 requires you to appoint an authorised representative. This is a mandatory obligation, not optional.
The authorised representative must be:
- A natural person or legal entity established in the EU
- Formally mandated in writing by the provider
- Authorised to act on the provider's behalf for AI Act compliance purposes
The representative holds a copy of the technical documentation and the EU declaration of conformity. They are the primary contact for national MSAs and the AI Office. They can be named on enforcement orders alongside the provider and may be held jointly liable for non-compliance.
EU representatives are distinct from GDPR representatives under Article 27 GDPR, though the same firm can fulfil both roles if properly appointed.
For practical purposes, most US, UK, and Asian tech companies selling into the EU will need to contract with a law firm or specialist compliance firm in a member state to serve as their EU AI Act representative. Costs vary but are typically comparable to GDPR representative arrangements.
How to cooperate with an investigation
If your company receives a request from a national MSA, the most important steps are:
Identify the scope immediately. What system is being investigated? What conduct is alleged? Which authority is asking? Multiple authorities may be involved if your system is deployed across countries.
Gather your technical documentation. The EU AI Act requires providers to maintain a technical file under Article 11 and Annex IV. This file should be available and up to date. Authorities typically ask for it first. Gaps in documentation are themselves grounds for enforcement action.
Engage legal representation in the relevant member state. National AI Act investigations follow national procedural law in most respects. You need local counsel familiar with both EU AI Act obligations and the administrative procedures of the specific authority.
Cooperate fully with information requests. Obstruction or failure to respond to information requests is a separate ground for fines. Authorities generally treat cooperative responses more favourably in assessing proportionate remedies.
Check your Annex III classification. Investigations often begin because an authority believes a system is high-risk but was not treated as such by the provider. Have your classification rationale documented.
See the EU AI Act deployer evidence gaps guide for the documentation most frequently missing when investigations begin.
What to do right now
For most companies, the practical steps ahead of August 2026 are:
- Identify which EU countries your AI systems are placed on the market in.
- Note the designated or interim MSA for each country (Germany: BNetzA; Spain: AESIA; Netherlands: RDI; others: check national implementing legislation).
- Confirm whether you are a GPAI provider and if so, prepare for AI Office oversight separately.
- If you are non-EU established, appoint an EU authorised representative under Article 25.
- Ensure your technical documentation is complete and accessible.
- Register applicable high-risk AI systems in the EU AI Act database.
The EU AI Act August 2026 compliance checklist covers the full set of steps with timelines.
Related Reading
- EU AI Act August 2026 compliance checklist
- What to expect from EU AI Act first enforcement actions in Q3 2026
- High-risk AI documentation templates for August 2026
- GPAI compliance checklist for August 2026
- Deployer evidence gaps for SMEs
- GDPR Article 30 records of processing for AI tools
- Annex III high-risk AI systems explained
- EU AI Act SME support and regulatory sandboxes: what small businesses
- EU AI Act Conformity Assessment: What It Is and Who Must Do It
- EU AI Act prohibited practices Article 5 guide 2026
- EU AI Act enforcement starts August 2, 2026: what it means and what to d
- EU AI Act August 2026: 6-week compliance sprint checklist
- AI incident response plan: what regulators expect when your AI system fails
- EU AI Act compliance checklist 2026: 35 items for providers and deployers
- FTC's $930K Active Listening settlement: what AI-washing enforcement now looks like
- CNIL Targets Credit Scoring AI First: EU AI Act Enforcement Is Real
- EU AI Act first enforcement actions in Q3 2026: what small teams should expect
