EUAIACTUS.COM

Enforcement architecture · September 2026

The AI Act now has a clearer national enforcement map.

The European Commission's market-surveillance page, updated 7 September 2026, identifies national Single Points of Contact and shows where some designation decisions remain pending final adoption.

Source update: 7 September 2026 · Legally reviewed: 26 September 2026.

Who enforces what

National market surveillance authorities supervise AI systems; the AI Office supervises GPAI models.

The Commission describes national market surveillance authorities as the bodies responsible for implementing, supervising and enforcing AI Act rules for AI systems in Member States. The European AI Office has the central supervision and enforcement role for general-purpose AI models.

Investigation powers

Authorities can investigate non-compliance, conduct remote monitoring and obtain access to documentation, data sets and source code within the legal framework.

Corrective measures and penalties

Authorities can require corrective action and enforce applicable rules, including through penalties where the legal conditions are met.

Complaints matter

Natural and legal persons can bring complaints where they have grounds to consider that the AI Act has been infringed, making complaint-handling part of the practical enforcement landscape.

Cross-border cooperation

Authorities cooperate through the European AI Board and existing EU mechanisms to support consistent enforcement across Member States.

September 2026 status

The national map is still evolving.

The Commission's list is continuously updated. Some Single Points of Contact are marked as pending final national designation, while other Member States already show a named authority. Companies should verify the current authority for the relevant Member State at the time an issue arises rather than relying on a static internal list.

Operational implication

Enforcement readiness now needs an authority map, not only an obligation map.

  • Identify the Member States where relevant AI systems are placed, deployed or affect users.
  • Record the current Single Point of Contact and sector-specific authority where applicable.
  • Maintain regulator-ready documentation and clear ownership for information requests.
  • Coordinate AI Act response procedures with privacy, product-safety and sector-regulator escalation paths.