The Week in One Line
Enforcement of the AI Act began on 2 August, but for most companies the authority that supervises them is national, not European — and the Commission's own published list of those national authorities is still mostly empty.
What the Act Actually Says
Enforcement is split three ways. The AI Office at the European Commission enforces the rules for providers of general-purpose AI models, for AI systems built by the same provider or business group as the underlying GPAI model, and for AI systems integrated into very large online platforms and search engines designated under the Digital Services Act. The European Data Protection Supervisor enforces the rules for AI systems used by EU institutions, bodies and agencies. National competent authorities enforce the rules for everything else.
That last category is where almost every ordinary business sits. If you run a chatbot, document extraction, or an internal AI tool, your supervisor is national, not the AI Office. And those authorities have real powers: remote monitoring, access to a provider's documentation, data sets and source code, corrective measures, and penalties.
The national list is mostly empty. Article 70 required each Member State to designate at least one notifying authority and at least one market surveillance authority, name one as a Single Point of Contact, notify the Commission, and publish the contact details. The deadline was 2 August 2025 — a year before enforcement began. The Commission publishes the resulting list.
At the time of writing it shows a named Single Point of Contact for eight of the twenty-seven Member States, three of those marked as still pending final adoption. The remaining nineteen are blank, including Czechia, Slovakia, Germany, France, the Netherlands and Poland.
One caveat, stated plainly: the Commission's list carries a last-update date of 26 September 2025. So we cannot tell from it whether a Member State has designated an authority that has not been published yet, or has not designated one. What is verifiable is that a company in most Member States cannot currently look up its supervisor on the official EU page.
The penalty tiers, for context. Prohibited AI practices carry fines of up to EUR 35 million or 7 percent of total worldwide annual turnover. Other breaches, including Article 50 transparency and the GPAI model obligations, up to EUR 15 million or 3 percent. Supplying incorrect, incomplete or misleading information in reply to a request for information can reach EUR 7.5 million or 1 percent for AI systems.
Two things about those numbers. For most organisations it is "whichever is higher" — but under Article 99(6), for SMEs and start-ups it is whichever is lower. And that third tier attaches to your answer, not only to the underlying conduct.
Whistleblower protection arrived quietly. Legal protection against retaliation under the EU Whistleblower Directive now extends to reports concerning AI Act infringements; before 2 August, confidentiality was the primary protection available. The AI Office runs an anonymous whistleblower channel for people professionally connected to AI providers, alongside a separate, non-anonymous complaints form — that one narrower in scope, covering infringements under Article 85 that fall to the AI Office.
Sources: European Commission, The enforcement framework of the AI Act; Market Surveillance Authorities under the AI Act; AI Act Whistleblower Tool; AI Act Article 70 and Article 99.
What This Means for Your Business
You have probably been reading the wrong guidance. Coverage of enforcement has focused on the AI Office, because that is where the GPAI story is. But if you are a deployer running AI in an ordinary business, your supervisor is national — and how it interprets and prioritises will differ from one Member State to the next.
A missing name on a webpage is not a delay. The obligations apply regardless of whether your Member State has published a contact point. It does not pause Article 50, and it will not be a defence.
The first contact is a letter, not an inspection. The request for information is the AI Office's first listed investigative power. It arrives with a deadline, and the accuracy of your answer is itself a penalised matter. In my own work the pattern is consistent, though I offer it as experience rather than data: the problem is rarely unwillingness to comply. It is that nobody owns the letter, and an answer that should take three days takes six weeks — with parts of it wrong.
This Week's Action Point
Spend one hour producing a single page that answers four questions.
- Which AI systems do we operate, and for each, are we provider or deployer?
- Which authority supervises each of them — the AI Office, our national market surveillance authority, or the EDPS?
- Who owns the reply if a request for information arrives, and who signs it?
- Where does the evidence live — model documentation, logs, data sources, disclosure text?
If your Member State has no published Single Point of Contact, write down the ministry or agency you believe is responsible and mark it unconfirmed. An honest gap is more useful than a blank one.
I have turned this into a one-page routing sheet — Who Regulates Your AI System — with the AI Office versus national authority split, a provider-or-deployer test, and a request-for-information readiness checklist. It is linked in the comments of today's post. Free, no form, no sign-up.
Further Reading
- The enforcement framework of the AI Act — European Commission
- Market Surveillance Authorities under the AI Act — the list itself
- Article 74 — market surveillance and control of AI systems
- Article 99 — penalties, including the SME rule in 99(6)
- AI Act complaints tool — European Commission
One question I would like your answer to: do you know which authority supervises the AI systems your organisation runs? I am curious how many people can answer that without looking it up — and if you are in a Member State with no published contact point, how you handled it. Reply or leave it in the comments. I read every one.
Next Tuesday
The request for information: what one actually contains, and what a good answer looks like.
Matúš Paško — I design enterprise AI systems that have to run in production under real compliance and reliability constraints. If you are working through what the AI Act means for systems you already operate, my calendar link is in my profile — a short call is usually enough to get you oriented.
#EUAIAct #AIGovernance #AICompliance #Article70 #EnterpriseAI