Home / Enforcement

Who actually regulates you, where

Many Member States missed the August 2025 designation deadline — enforcement capacity is uneven, and no official source shows it cleanly. We track designation status per country, continuously.

11
fully designated
10
partial / pending
6
unclear

National authorities — all 27 Member States

CY Cyprus Commissioner of Communications (OCECPR) DESIGNATED verified 07-21 DK Denmark Agency for Digital Government (coordinating MSA) + Datatilsynet DESIGNATED verified 07-16 FI Finland Traficom (coordinating MSA) within a decentralised sectoral model DESIGNATED verified 07-21 HU Hungary Minister for Enterprise Development (MSA + SPOC); National Accreditation Authority (notifying) DESIGNATED verified 07-21 IE Ireland Distributed model — 15 sectoral MSAs; Minister for Enterprise, Tourism and Employment as SPOC DESIGNATED verified 07-21 IT Italy AgID + ACN under national AI law DESIGNATED verified 07-16 LV Latvia Consumer Rights Protection Centre (PTAC) as single point of contact; ~12 sectoral MSAs DESIGNATED verified 07-21 LT Lithuania Communications Regulatory Authority (RRT); Innovation Agency Lithuania (notifying) DESIGNATED verified 07-21 MT Malta Malta Digital Innovation Authority (MDIA) DESIGNATED verified 07-16 SI Slovenia AKOS (Agency for Communication Networks and Services) DESIGNATED verified 07-21 ES Spain AESIA — dedicated AI supervision agency DESIGNATED verified 07-16 CZ Czechia Czech Telecommunication Office proposed as coordinating MSA PARTIAL verified 07-16 FR France DGCCRF lead candidate — designation in progress PARTIAL verified 07-16 DE Germany Federal Network Agency (BNetzA) lead — sectoral split PARTIAL verified 07-16 LU Luxembourg CNPD as MSA and single point of contact — pending final adoption PARTIAL verified 07-21 NL Netherlands AP + RDI proposed as joint coordinators; RDI as SPOC — bill not yet in force PARTIAL verified 07-21 PL Poland KRiBSI (new AI commission) — law passed, awaiting signature PARTIAL verified 07-21 PT Portugal ANACOM announced as supervisory authority and SPOC PARTIAL verified 07-21 RO Romania ANCOM proposed as MSA and SPOC; ADR as notifying authority PARTIAL verified 07-21 SK Slovakia Office for Digital Integrity at MIRRI SR; MIRRI SR as general MSA and SPOC PARTIAL verified 07-21 SE Sweden PTS proposed as coordinating MSA and SPOC; distributed sectoral model PARTIAL verified 07-21 AT Austria AI service desk live; MSA designation pending UNCLEAR verify before relying BE Belgium BIPT earmarked as lead regulator; not formally appointed UNCLEAR verify before relying BG Bulgaria Designation in progress; lead authority not yet confirmed UNCLEAR verify before relying HR Croatia Designation in progress; lead authority not yet confirmed UNCLEAR verify before relying EE Estonia No authority formally designated; TTJA expected but not confirmed UNCLEAR verify before relying GR Greece No authority designated; Ministry of Digital Governance coordinating UNCLEAR verify before relying
Muted rows are past their re-verification window — shown as "verify before relying", never silently as current.
Sources: Commission Art. 70/77 lists · national gazettes · cross-checked vs IAPP directory · verified 2026-07-21
THE COMMISSION'S LIST LAGS NATIONAL LAW

Checking a single source will mislead you. Several Member States have designations in force under domestic law that had not yet appeared on the Commission's notified list when we last verified — Denmark, Finland, Hungary and Malta among them. Others appear on neither list because no authority has been appointed at all. We reconcile the Commission's list against national instruments and say which is which, rather than reporting one and calling it the picture.

FINE BANDS — ART. 99
Prohibited practices€35M / 7%
Most other breaches€15M / 3%
Misleading information€7.5M / 1%
Higher of the two; SMEs/SMCs pay the lower. Enforceable from Aug 2, 2026.
THE NOTIFIED-BODY BOTTLENECK

The AI conformity-assessment ecosystem is still being built (NANDO register, Art. 35). Most Annex III systems can self-assess (Annex VI) — third parties are mainly required for remote biometric ID and Annex I products. Whether capacity exists by Dec 2027 / Aug 2028 is an open question we track.

WHO ENFORCES WHAT

AI Office: GPAI models + GPAI-based systems (expanded by Omnibus). National MSAs: everything else — plus carve-outs where they stay competent even for GPAI systems: law enforcement, border, judicial, financial.

GPAI supervision →