Artificial Intelligence in Australia
Appointed supervisory authority
Law / proposed law in Australia
Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.
The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.
On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.
Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.
AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.
Automated decision-making transparency under the Privacy Act
From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.
These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.
State and territory overlays
State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.
Regulatory guidance / voluntary codes in Australia
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
Appointed supervisory authority in Australia
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
Definitions in Australia
Australian legislation does not presently contain a single, generally applicable statutory definition of ‘AI system’, ‘AI technology producer’, ‘provider’, ‘deployer’ or ‘user’ for all purposes. Definitions can instead arise within particular statutes, contracts, technical standards or sector-specific rules and must be read in their own context.
The National AI Centre’s current terms page uses an Organisation for Economic Co-operation and Development (OECD)-aligned concept of an AI system: a machine-based system that infers from inputs how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments; AI systems differ in autonomy and post-deployment adaptiveness. The guidance also uses the following non-statutory role descriptions:
- AI deployer: an individual or organisation that supplies or uses an AI system to provide a product or service, whether internally or externally.
- AI technology producer: an organisation or entity that designs, develops, tests and provides AI technologies such as models and components.
- AI platform, product or service provider: an organisation or entity that provides products or services using one or more AI systems.
- AI user: an entity that uses or relies on an AI system.
The OAIC distinguishes the underlying model from the broader AI system in which it is deployed. As an explanatory matter, that broader system may also encompass data, software, interfaces and operational processes. Governance controls and human decision points may be important components of a deployment, but they should be identified as contextual system-design features rather than presented as a verbatim OAIC definition.
Prohibited activities in Australia
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
High-risk AI in Australia
Australia has no generally applicable statutory classification or compliance regime for ‘high-risk AI’. The expression is currently a governance and policy concept, except where a particular sectoral law or instrument independently imposes risk-based obligations.
The September 2024 mandatory-guardrails proposals paper suggested that a future framework could consider adverse impacts on individual rights, health and safety; groups and collective or cultural rights; and the broader economy, society, environment and rule of law, together with the severity and extent of those impacts. Those proposed criteria never became binding law and the proposal is not proceeding at this time.
The current Guidance for AI adoption uses a risk-scaled approach. Its implementation guidance is directed to more complex or higher-risk uses and recommends stronger accountability, impact analysis, risk management, information sharing, testing, monitoring and human control. As a governance matter, indicators warranting enhanced controls may include significant effects on rights or access to services; impacts on vulnerable people or communities; safety-critical functions; opaque or difficult-to-contest outcomes; large-scale or systemic deployment; material cyber or data risks; and serious consequences from error, bias or model failure.
Organisations using AI in higher-impact contexts should, as a governance recommendation rather than a general statutory command, document use cases and accountabilities, conduct proportionate impact and legal assessments, test and monitor performance, manage data quality and provenance, maintain effective escalation and override processes, enable complaints and contestability, and integrate AI controls with existing privacy, cyber, consumer, safety and sectoral compliance systems.
Controls on generative AI in Australia
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
Enforcement / fines in Australia
Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.
- A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
- Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
- Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
- Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
User transparency in Australia
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Fairness / unlawful bias in Australia
Australia does not have a single AI fairness statute. Unfair or biased AI outcomes can nevertheless engage Commonwealth, state or territory anti-discrimination laws, employment law, consumer protection, privacy, credit, education, health, administrative law and other sector-specific duties. The applicable protected attributes, tests, exemptions, remedies and responsible parties depend on the relevant statute and context.
The current Guidance for AI adoption addresses fairness through impact analysis, stakeholder engagement, risk management, testing, monitoring and human control. The OAIC identifies bias and discrimination risks where data are incomplete, inaccurate, unrepresentative or encode historical disadvantage. These are guidance propositions unless linked to a specific legal obligation.
As a governance matter, organisations deploying higher-impact AI should test for discriminatory or materially inaccurate outcomes before and after deployment; assess performance across relevant cohorts; document limitations; monitor complaints and drift; maintain escalation and contestability pathways; and ensure that human reviewers have the authority and information needed to correct inappropriate outcomes.
Human oversight in Australia
The sixth essential practice in the current Guidance for AI adoption is to maintain human control. The guidance recommends designing systems and operating processes so that people can supervise, intervene, escalate, override or stop AI use where appropriate to the system’s risk and impact.
Human involvement should be meaningful rather than ceremonial. Reviewers need appropriate expertise, authority, information, independence and time; they should understand relevant system limitations and avoid merely endorsing an automated result. The appropriate form of oversight may range from periodic monitoring for low-impact tools to mandatory approval, dual control, escalation or prohibition of autonomous action in higher-impact contexts.
For government decision-making, human oversight must be assessed alongside statutory authority, lawful delegation, procedural fairness, reasons, evidence, recordkeeping and review rights. For private-sector systems, the necessary controls depend on the consequences of the use case and the privacy, consumer, safety, discrimination, professional, cyber security and sectoral laws engaged. Human review does not cure an otherwise unlawful system or decision.
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Austria
Austria has not yet officially communicated the designation of its competent authorities under Article 70(2). While the AI Service Desk established within the telecommunications regulator RTR GmbH currently serves as the main national contact point for AI Act-related matters, no formal designation of RTR as the notifying or market surveillance authority has been identified. Furthermore, Austria has not submitted the report on the financial and human resources of their competent authorities required under Article 70(6). In addition, no AI regulatory sandbox is operational in Austria pursuant to Article 57(1).
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Belgium
Belgium is yet to officially designate the national competent authorities. The deadline in this regard has not been met (2 August 2025). Consequently, Belgium has also not provided a report to the European Commission on the status of the financial and human resources of its national competent authorities by the same deadline.
However, it is noted in the ‘Declaration of the Government’ (published on 31 January 2025) that the Belgian Institute for Postal Services and Telecommunications (BIPT) will be appointed as the main regulator for the AI Act.
Belgium has published the list of authorities in charge of the protection of fundamental rights under Article 77 of the AI Act. See here for details.
In addition, Belgium has established an Ethics Advisory Council on Data and AI appointed by the Minister of Civil Service and the State Secretary for Digitization.
Belgium has also announced that it will conduct a legal study with a view to setting up national regulatory sandboxes. It is however unlikely that Belgium will comply with the deadline of 2 August 2026 to establish at least one AI regulatory sandbox at national level.
The Flemish Government Coalition Agreement has explicitly indicated that it will not carry out so-called ‘gold-plating’, which means going beyond the requirements on AI imposed by European or other international regulation.
A supervisory body with authority for AI has not yet been appointed in Brazil by way of statutory appointment. According to the Brazilian AI Bill, once the Bill is sanctioned, the National Data Protection Authority (ANPD) will coordinate a National Artificial Intelligence Regulation and Governance System (SIA), which will be created and integrated by state sector regulation bodies and self-regulation and certification entities, the Artificial Intelligence Regulatory Cooperation Council (Cria) and the Committee of Artificial Intelligence Experts and Scientists (Cecia). Amongst the duties of the SIA will be the regulation of high-risk systems, strengthening the powers of the sectoral authorities and the ANPD, harmonising the work of regulatory bodies and carrying out periodic studies and sending an opinion to Congress every four years on the need to improve legislation on AI.
In December 2025, ANPD identified ‘artificial intelligence and emerging technologies in the context of personal data processing’ as one of its priority areas for supervisory and enforcement activities for the 2026-27 biennium, signalling increased regulatory scrutiny of AI-related data protection issues.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Bulgaria
Bulgaria has not yet formally designated the national authorities responsible for supervising and enforcing the EU AI Act. To support the implementation process, the Minister of e-Government established an inter-ministerial working group tasked with preparing the necessary legislative measures and proposals for the designation of the competent authorities.
According to the latest publicly available information, the previous administration had prepared a draft decision for designating a national market surveillance authority, in accordance with the EU AI Act. However, as of the date of this update the new government has neither adopted such a decision, nor introduced any other measures for the designation and notification of the relevant authorities.
In the financial sector, the national Financial Supervision Commission (FSC) has already adopted amendments to its Rulebook, enabling it to conduct remote supervision and on-site inspections regarding compliance with the EU AI Act in the area of investment activities. These powers will take effect once the FSC is formally designated as a competent authority under the EU AI Act.
To date, no AI regulatory sandbox has been set up in Bulgaria, and no public information has been published regarding the financial and human resources that will be allocated to the national competent authorities responsible for EU AI Act enforcement.
Bulgaria has already designated seven national public authorities to supervise and enforce the EU AI Act in respect of fundamental rights pursuant to Article 77 of the EU AI Act. These are:
- the Ombudsman;
- the Central Election Commission;
- the Commission for Protection against Discrimination;
- the Commission for Personal Data Protection;
- the Commission for Consumer Protection;
- the State Agency for Child Protection; and
- the Executive Agency ‘General Labour Inspectorate’,
all designated by Decision of the Council of Ministers No 398 of 18 June 2025.
A supervisory body with authority for AI has not yet been appointed in Canada by way of statutory appointment. For the deployment of AI in the public sector, the federal government has committed to establishing an AI Centre of Expertise on project support, knowledge sharing, and strategic guidance to support AI adoption and experimentation. In November 2025, the federal government launched its first register of AI uses in federal government, providing public transparency on how AI systems are deployed across federal departments and agencies. Bill C-34, if enacted, would establish the Digital Safety Commission of Canada as a new independent regulatory body with authority over regulated social media services and chatbot services. The Commission would be composed of three to five full-time members appointed by the Governor in Council, with renewable terms of up to five years. The Commission could issue compliance orders directing operators to take or refrain from specific actions, enforceable as Federal Court orders.
Article 14 of the Chilean AI Bill creates the 'AI Advisory Board' as a consultative and permanent body that will advise the Minister of Science, Technology, Knowledge and Innovation (Science Ministry) on matters related to the development, promotion and continuous improvement of AI systems in the country. The main functions of this entity are to:
- Present to the Science Ministry a proposed list of 'High-Risk' and 'Limited-Risk' AI systems.
- Advise the Science Ministry regarding the scope and mode of compliance with the rules to which operators of 'High-Risk' and 'Limited-Risk' AI systems shall be subject.
- Submit to the Science Ministry a proposal regarding the establishment of guidelines for the development of controlled test sites for AI systems, as well as for the establishment of minimum standards of compliance and accountability for their development.
Article 24 of the Chilean AI Bill establishes that a 'Personal Data Protection Agency' (Agency) will be responsible for the control and sanctioning of the infringements established in the Chilean AI Bill.
While a single national supervisory body with specific authority for AI has not yet been appointed in PRC, the development of AI-related regulations is undertaken collaboratively by various governmental authorities (including the Cyberspace Administration of China/CAC, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Industry and Information Technology/MIIT, the Ministry of Public Security/MPS and the National Radio and Television Administration).
In addition, National Technical Committee 260 on Cybersecurity of SAC (‘TC260’) plays a pivotal role in organising and executing technical standardisation efforts related to domestic information security matters, and formulates technical standards across an array of domains, including network security technology, security mechanisms, security services, security management and security assessments.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Croatia
Croatia is among the Member States that have not yet designated their national competent authorities. As of the date of this update, Croatia has not designated a notifying authority or a market surveillance authority under Article 70(2) of the EU AI Act. There is no publicly available information indicating that Croatia has reported to the Commission on the status of the financial and human resources of its national competent authorities pursuant to Article 70(6).
No national AI regulatory sandbox has been established or publicly announced. Under Article 57(1) of the EU AI Act, Member States were required to ensure that at least one AI regulatory sandbox is operational by 2 August 2026. However, under the Digital Omnibus for AI, which has been formally adopted and is pending publication in the Official Journal of the European Union, this deadline is postponed to 2 August 2027. The establishment of the sandbox in Croatia is expected to be addressed in the pending implementing law.
In accordance with the obligation set out in Article 77 of the EU AI Act, the Republic of Croatia has designated the following authorities for protecting fundamental rights:
- Ombudsman;
- Ombudsman for Children;
- Ombudsman for Gender Equality;
- Ombudsman for Persons with Disabilities;
- Croatian Personal Data Protection Agency;
- State Electoral Commission; and
- Agency for Electronic Media, Head of the Legal and Human Resources Department.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Cyprus
The Cyprus Deputy Ministry of Research, Innovation and Digital Policy has notified the European Commission of the national public authorities that will supervise or enforce compliance with the obligations under EU law to protect fundamental rights, in accordance with Article 77 of the EU AI Act. The designated Cyprus authorities are:
- Commissioner for Personal Data Protection;
- Commissioner for Administration and the Protection of Human Rights (Ombudsman); andAttorney-General of the Republic.
From 2 August 2026 these authorities will be granted additional powers under the EU AI Act to facilitate the exercise of their existing responsibilities to protect fundamental rights in cases where the use of AI poses high risks to these rights.
Separately, by Decision No. 97.539 dated 22 January 2025, the Council of Ministers designated the Commissioner of Communications as the Notifying Authority, a Market Surveillance Authority and the Single Point of Contact for the application of the EU AI Act in Cyprus. The Commissioner for Personal Data Protection was also designated as a Market Surveillance Authority.
The Commissioner for Personal Data Protection acts as a Market Surveillance Authority in relation to the high-risk AI systems referred to in point 1 of Annex III, insofar as those systems are used for law-enforcement purposes, and points 6, 7 and 8 of Annex III. The Commissioner is also responsible for prohibited AI practices under Article 5, insofar as they fall within the Commissioner’s areas of competence.
The European Commission’s published list of Single Points of Contact identifies the Commissioner of Communications as the Single Point of Contact for Cyprus. The available official information indicates that Cyprus met the requirements under Article 70(2) by the applicable deadline of 2 August 2025.
To support AI governance more broadly, the Government of Cyprus established a National AI Taskforce in January 2025. Chaired by the Chief Scientist for Research, Innovation and Digital Policy, the National AI Taskforce includes academic and industry experts who advise the President of the Republic of Cyprus on strategic AI policy. The National AI Taskforce holds no formal authority under the EU AI Act.
As part of Cyprus’s broader AI governance framework, the Cyprus Organisation for the Promotion of Quality, through the Cyprus Accreditation Body (CYS-CYSAB), acts as the National Accreditation Body responsible for accrediting conformity assessment bodies under the EU AI Act.
Council of Ministers Decision No. 97.539 of 22 January 2025 also provided for the commissioning of a techno-economic study concerning, among other matters, the financial and human resources required by the national competent authorities. However, no publicly available official information has been traced confirming that Cyprus submitted the report required under Article 70(6) by the deadline of 2 August 2025.
Cyprus’s National Artificial Intelligence Strategy (National AI Strategy), approved in January 2020, referred to plans to establish regulatory sandboxes to support the development and testing of innovative technologies. Although the National AI Strategy reflects an early policy intention to develop regulatory sandboxes, it predates the EU AI Act and does not establish that a sandbox per the requirements of Article 57(1) has since been established and made operational. The applicable deadline is 2 August 2026, and no publicly available official information has been traced confirming that Cyprus currently operates a national AI regulatory sandbox for the purposes of Article 57(1).
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in the Czech Republic
Based on Section 3(1)(2) of the draft Czech AI Act, the Czech Telecommunications Authority (Český telekomunikační úřad) has been designated as the main market surveillance authority, which will ensure compliance with the rules of the EU AI Act within the area of market regulation and which will also serve as the one-stop shop pursuant to Article 70(2) of the EU AI Act.
The Czech Office for Standards, Metrology and Testing (Úřad pro technickou normalizaci, metrologii a státní zkušebnictví) has been designated as the notifying authority. It will be responsible for appointing and notifying conformity assessment entities and monitoring their activities in accordance with the requirements of the EU AI Act (pursuant to Section 2(1)(2) of the draft Czech AI Act). In addition, the Office acts as the establishing authority for the regulatory sandbox mentioned in the Law / proposed law section and also carries out activities related to its operation, as far as they concern public administration (Section 15(2)(4) of the draft Czech AI Act).
On the other hand, the Czech Standardisation Agency (Česká agentura pro standardizaci) (ČAS) is responsible for the operation of the regulatory sandbox and carries out activities related to operations beyond the scope of public administration (Section 15(3)(4) of the draft Czech AI Act). ČAS has already established cooperation with the Czech Association for AI and has signed a Memorandum of Cooperation with it.
Other authorities responsible for supervising key rules include the Office for Personal Data Protection (Úřad pro ochranu osobních údajů) (Section 3(4) of the draft Czech AI Act), the Czech National Bank (Česká národní banka) (Section 3(3)), and the Public Defender of Rights (veřejný ochránce práv) (Section 4).
Given that the Czech Republic has already designated the relevant national authorities in the approved document titled 'Proposal for the Implementation of the AI Act in the Czech Republic' back in 28 May 2025, the Czech Republic has fulfilled its obligation to designate notifying authorities and market surveillance authorities, as required by Article 70(2) of the EU AI Act, within the deadline of 2 August 2025. Therefore, it can also be assumed that the Czech Republic has duly fulfilled its obligation to notify the European Commission of the identity of the relevant authorities, its obligation to publicly disclose information about those authorities, as well as its obligation to submit a report to the European Commission on the status of the financial and human resources of the competent authorities (Article 70(6) of the EU AI Act).
As regards the obligation to ensure that the relevant authorities establish at least one regulatory sandbox for AI at the national level, with functionality by 2 August 2026, the Czech Republic will not meet this deadline. Article 57(1) of the EU AI Act, containing such an obligation, will be implemented by the draft Czech AI Act referred to in the Law / proposed law section. However, the draft law is still in the legislative process; the most recent version was published as recently as 26 June 2026 and is still awaiting discussion in Parliament. Therefore, it is certain that a regulatory sandbox within the meaning of Article 57(1) will not be established by 2 August 2026. The first regulatory sandbox in the Czech Republic was launched in February 2026 by CzechInvest, the Agency for the Support of Business and Investment, however, covering only 21 selected companies.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Denmark
Under Law No. 467 of 14 May 2025, which enters into force on 2 August 2025, Denmark has designated three national competent authorities in accordance with Article 70(1) of the EU AI Act. These authorities are responsible for enforcing the EU AI Act within their respective areas of expertise.
The Danish Agency for Digital Government has been appointed as the notifying authority under Articles 28(1) and 70(1) and also serves as Denmark’s single point of contact under Article 70(2). In addition, it acts as the market surveillance authority for most prohibited AI practices, including those that manipulate human behavior, exploit vulnerabilities, or involve social scoring, as outlined in Article 5(1)(a–c), (e), and (f).
The Danish Data Protection Agency oversees prohibited AI practices that raise data protection and privacy concerns. This includes biometric categorization and unlawful data processing, as specified in Article 5(1)(d) and (g), aligning with the agency’s existing role under the GDPR.
The Danish Court Administration is responsible for supervising the use of AI systems by the courts, but only in non-judicial contexts such as administrative or support functions. Judicial decision-making remains outside the scope of this supervision to safeguard judicial independence.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Estonia
So far, as required by Article 77 of the EU AI Act, Estonia has designated the following national authorities to protect fundamental rights:
- the Data Protection Inspectorate;
- the Gender Equality and Equal Treatment Commissioner; and
- the Consumer Protection and Technical Regulatory Authority.
Estonia has not yet publicly completed the designation of national competent authority required under Article 70 of the EU AI Act, although the Consumer Protection and Technical Regulatory Authority has indicated that it will in the future act as the competent authority for the supervision of AI systems. Estonia has also launched a national assessment service for AI solutions, coordinated by the Ministry of Justice and Digital Affairs, which is relevant to the requirement under Article 57(1) of the EU AI Act for Member States to ensure that at least one AI regulatory sandbox is operational by 2 August 2026.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Finland
The Finnish authorities protecting fundamental rights under the AI Act have been appointed as of 1 January 2026 to be:
- Data Protection Ombudsman
- Non-Discrimination Ombudsman
- Ombudsman for Equality
- National Discrimination and Equality Tribunal of Finland
- Chancellor of Justice
- Parliamentary Ombudsman
- Occupational safety and health authorities (Regional State Administrative Agencies)
- Consumer Ombudsman
Traficom acts as the national single point of contact. It also monitors compliance with the transparency obligations under Article 50 of the AI Act and coordinates the implementation of the regulation in Finland.
As a market surveillance authority, the Data Protection Ombudsman monitors compliance with the prohibited AI-related practices under Article 5 of the AI Act.
The Financial Supervisory Authority is the authority which shall report to the European Central Bank.
For high-risk AI systems, the proposal suggests that the relevant market surveillance authority may be one of the following, depending on the context:
- Finnish Safety and Chemicals Agency (Tukes)
- Finnish Customs
- Finnish Transport and Communications Agency
- Finnish Medicines Agency (Fimea)
- Energy Authority
- Data Protection Ombudsman
- Finnish Supervisory Agency
- Finnish Supervisory Agency, occupational safety and health division
- Financial Supervisory Authority (FIN-FSA)
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in France
France has moved to draft a national law to designate enforcement and oversight powers for the EU AI Act. The French model is decentralised, with multiple market surveillance authorities split by sector and type of AI system addressed in the EU AI Act. For instance, prohibited AI systems relating to emotion recognition in the workplace and education institutions will be enforced by the French data protection supervisory authority (the CNIL) and high-risk AI systems related to medical devices by the ANSM, France’s National Agency for the Safety of Medicines and Health Products (ANSM).
The framework is complex but looks to uphold the intent of the legislation, which is similar in nature to product-based regulation. To help companies navigate this complex framework, the DGE has published a diagram (see here). The DGCCRF (Direction générale de la concurrence, de la consommation et de la répression des fraudes), notably in charge of fair market practices, consumer protection, and product safety across France, will be responsible for coordinating the market surveillance authorities and will, in this capacity, serve as the single point of contact pursuant to EU AI Act Article 70.2. In parallel, the DGE (a French government agency under the Ministry of the Economy) will continue to support the strategy around the implementation of this text and represent France within the AI Office. Finally, an advanced pooling of expertise and technical tools in AI and cybersecurity is being implemented by the Digital Regulation Expertise Center (PEReN) and ANSSI to support authorities in their missions to monitor the compliance of AI systems.
As of July 2026, the legislative process implementing the formal designation is still ongoing.
With respect to the deadlines set by the EU AI Act:
- France has not met the 2 August 2025 deadline for Member States to designate their national competent authorities (notifying authorities and market surveillance authorities), to communicate them to the Commission and to make their contact details publicly available (Article 70(2)). The DGE and the DGCCRF published the proposed governance scheme, together with public contact details, on 9 September 2025, but the formal designation requires the adoption of the DDADUE, which remains pending before French Parliament, therefore formal designation is now expected in the course of 2026.
- No public information has been released confirming that France submitted the report required under Article 70(6) on the financial and human resources of its competent authorities by 2 August 2025.
- There was no official confirmation that France has established an AI regulatory sandbox within the meaning of Article 57(1) of the EU AI Act. Given that the DDADUE has not yet been enacted, it appears unlikely that an operational AI regulatory sandbox will be in place by the 2 August 2026 deadline. The CNIL has, however, run sector-specific ‘sandbox’ support programmes since 2021, which may serve as a basis for the future French AI regulatory sandbox.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Germany
Once the German implementing law enters into force, BNetzA takes a central role: under the KI-MIG it is designated as the default market surveillance authority, as the notifying authority, as the single point of contact towards the EU and the other Member States, and as the central complaints body.
Existing sectoral market surveillance authorities remain competent where AI is used in, or as a safety component of, products covered by the EU harmonisation legislation listed in Annex I Section A of the EU AI Act (for example machinery, medical devices or toys), so that businesses keep their established authority.
- For AI systems used in direct connection with regulated financial services, the Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht – BaFin) – or the otherwise competent financial supervisory authority – acts as market surveillance authority.
- Where AI systems are placed on the market, put into service or used by public bodies of the Federal States, market surveillance falls to the authorities designated under Federal States law, and media-related use is supervised by the State Media Authorities.
- For certain particularly rights-sensitive high-risk systems within the meaning of Article 74(8) of the EU AI Act (such as law enforcement, migration and the administration of justice), an independent AI Market Surveillance Chamber (KI-Marktüberwachungskammer) is established within BNetzA.
- The German Accreditation Body (Deutsche Akkreditierungsstelle) will be responsible for the assessment and monitoring of conformity assessment bodies in accordance with Article 28(2) of the EU AI Act.
- Within BNetzA, a Coordination and Competence Centre (Koordinierungs- und Kompetenzzentrum – KoKIVO) will be established to support the other competent authorities, complemented by an AI Committee (Bund-Länder-Ausschuss Künstliche Intelligenz) added by the Bundestag for structured coordination between the authorities.
BNetzA is further tasked with establishing and operating at least one AI regulatory sandbox (KI-Reallabor).
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Greece
Prior to the enactment of the Greek AI Act Implementation Law, Greece had not met the 2 August 2025 deadline for designating the national competent authorities and fulfilling the related notification obligations under Article 70 of the AI Act. The Law addresses this gap by establishing the national governance framework for the supervision and enforcement of AI systems and formally designating the competent authorities referred to in this section.
In particular, the Law designates the HDPA as the competent market surveillance authority pursuant to Article 70(1) of the AI Act in respect of:
- AI systems falling within the prohibited AI practices set out in Article 5 of the AI Act;
- high-risk AI systems referred to in Annex III to the AI Act; and
- AI systems subject to transparency obligations pursuant to Article 50 of the AI Act.
An exception applies to high-risk AI systems that are safety components of, or themselves constitute, products covered by Union harmonisation legislation listed in Annex I, Section A of the AI Act. In such cases, the market surveillance authorities already designated under the relevant national sector-specific legislation retain competence to supervise AI Act compliance within their respective areas.
The HDPA is also designated as Greece’s single point of contact pursuant to Article 70(2) of the AI Act.
For conformity assessment purposes, the Hellenic Telecommunications and Post Commission (EETT) is designated as the national notifying authority under Article 28 of the AI Act, exercising all powers assigned to notifying authorities under the Regulation. The HDPA also acts as a notified body, responsible for conducting conformity assessments under Annex VII of the AI Act for high-risk AI systems intended for deployment by law enforcement, migration and asylum authorities.
Regarding the protection of fundamental rights, Greece designated the following authorities in November 2024 to supervise and enforce Union law obligations, including the right to non-discrimination, in relation to high-risk AI systems under Annex III of the AI Act:
- The Hellenic Data Protection Authority (ΑΠΔΠΧ);
- The Greek Ombudsman (Συνήγορος του Πολίτη);
- The Hellenic Authority for Communication Security and Privacy (ΑΔΑΕ); and
- The National Commission for Human Rights (EEΔΑ).
These bodies cooperate with the HDPA in its capacity as the competent market surveillance authority and exercise the powers set out in Article 77 of the AI Act.
Greece has also taken steps to strengthen its broader institutional AI governance framework. Following an announcement by the Prime Minister in June 2025, the Ministry of Digital Governance was renamed the Ministry of Digital Governance and Artificial Intelligence. At the same time, a Special Secretariat for Artificial Intelligence and Data Governance was established within the Ministry, with responsibility for supporting the development, coordination and implementation of national policies on artificial intelligence and data governance.
Notwithstanding the DPO and PCPD publishing AI guidance materials, a single supervisory body with authority for regulating and enforcing AI has not yet been appointed in Hong Kong by way of statutory appointment. The Government has indicated that it is reviewing the existing legal framework for AI, but at time of writing has not proposed the establishment of a dedicated AI regulator. Instead, at least for now:
- the PCPD will supervise compliance with personal data privacy in AI contexts; and
- otherwise, Hong Kong has adopted a sector-driven approach to AI regulation, with specific industry regulators releasing guidance, and supervising compliance, on the use and deployment of AI within their field.
The Government is in the process of establishing Hong Kong Artificial Intelligence Research and Development Institute (AIRDI), which is expected to come into full operation in the second half of 2026. While AIRDI is designed to play an important role in Hong Kong's AI ecosystem by supporting AI research and development, technology transfer, commercialisation and broader industry adoption of AI, improving the local AI governance framework, and strengthening the foundation for AI technology development, its role appears to be intended to be facilitative and advisory rather than enforcement-oriented.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Hungary
According to the Hungarian Government Decision 1301/2024 (IX. 30.) on measures necessary for the implementation of the EU AI Act, a new authority will be established under the supervision of the Ministry of National Economy, which will be liable for the implementation of the EU AI Act in Hungary. The Hungarian Artificial Intelligence Council will also be established by legislative actions, consisting of the following bodies:
- National Media and Infocommunications Authority;
- Hungarian National Bank;
- Hungarian Competition Authority;
- Hungarian National Authority for Data Protection and Freedom of Information;
- Supervisory Authority for Regulatory Affairs; and
- Digital Hungary Agency Private Limited Liability Company.
Another development followed with Government Decision 1028/2025 (II. 24.), which appointed Dr. László Palkovics as the Government Commissioner for Artificial Intelligence in Hungary. His mandate includes among others:
- coordinating the implementation of Hungary’s national AI objectives across sectors such as education, healthcare, defense, agriculture, and public administration;
- overseeing the establishment and operation of the national supervisory authority required by the EU AI Act;
- leading the formation and work of the Hungarian Artificial Intelligence Council;
- supervising the Applied AI Research Group and the development of national HPC (High Performance Computing) capacities;
- representing Hungary in EU and international AI-related forums; and
- supporting the use of AI in public administration and among enterprises, including through funding coordination and regulatory proposals.
The Commissioner operates under the direction of the Prime Minister and is supported by an 8-person secretariat within the Ministry of Energy.
Government Decision No. 1149/2025 (V. 14.) further specifies some institutional responsibilities:
- the Minister of National Economy is tasked with operating the market surveillance authority and the single point of contact under Article 70 of the AI Act;
- the National Accreditation Authority is designated as the notifying authority under Article 28; and
- the Ministry, in cooperation with the Government Commissioner, is responsible for preparing the necessary detailed legislation and assessing the budgetary implications of these tasks.
These government decisions represent only the initial steps in Hungary’s implementation of the EU AI Act. The actual legislative instruments that will establish the detailed regulatory framework and operational rules are still pending.
There is no single supervisory authority for AI in India. At the central level, MeitY is the key ministry entrusted with policy and promotion of matters relating to information technology, electronics, and internet, which includes AI and cybersecurity. It is also the nodal body responsible for the IndiaAI Mission and the India AI Governance Guidelines.
Sectoral regulators also play a role in guiding, monitoring and addressing AI-related issues within their respective domains, as discussed in the Regulatory guidance/voluntary codes section.
Privacy concerns arising from the use or misuse of AI will fall within the ambit of the Data Protection Board, which is a specific body to be constituted under the DPDPA. Consumer protection issues arising from unfair trade practices or misleading advertising involving AI may be addressed through the central consumer protection authorities and consumer forums.
Some Indian states such as Kerala and Tamil Nadu have also taken steps towards AI governance by appointing dedicated ministers/ministries for promotion and governance of AI.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Ireland
Ireland has taken a federated approach to supervision and enforcement of the EU AI Act, by formally designating the following eight competent authorities:
- Central Bank of Ireland
- Commission for Communications Regulation
- Commission for Railway Regulation
- Competition and Consumer Protection Commission
- Data Protection Commission
- Health and Safety Authority
- Health Products Regulatory Authority
- Marine Survey Office
Pursuant to Article 77, Ireland has also designated nine national public authorities to supervise and enforce in respect of fundamental rights. These are:
- The Data Protection Commission
- Coimisiún na Meán (Media Commission)
- Irish Human Rights and Equality Commission
- An Coimisiún Toghcháin (Electoral Commission)
- Ombudsman for Children
- Ombudsman for the Defence Forces
- Financial Services & Pensions Ombudsman
- Environmental Protection Agency
- Ombudsman
The Regulation of Artificial Intelligence Bill is at the preparatory stage of the legislative process, with a target for publication of Q1 2026.
The Bill is intended to give effect to the EU AI Act in Ireland, enable the designated national competent authorities to implement and enforce, and to levy penalties for breach.
The Bill will also provide for a lead authority to coordinate the other authorities. This body is expected to be a newly established Oifig Náisiúnta na hIntleachta Saorga, (National Artificial Intelligence Office).
Israel has not designated a single cross‑sector AI regulator.
In 2023, the Ministry of Science, Technology and Space established the Center for Regulation and AI Policy, which serves as a governmental knowledge and coordination hub for regulators and government ministries in the field of artificial intelligence. The Center provides expertise and policy support, assists in developing strategies for the safe use of AI and, where appropriate, innovation-supportive regulation, leads Israel’s engagement in international AI policy forums and coordinates inter-ministerial and expert advisory work in this area.
In October 2025, the Prime Minister’s Office announced a National AI Directorate to coordinate the national AI strategy across ministries, however the Directorate is not a statutory regulator. More recently, in June 2026, the Israeli government approved a comprehensive National AI Plan, to be led by the National AI Directorate, setting out strategic priorities across infrastructure, human capital, international partnerships and public services.
The PPA supervises compliance with the PPL (including for AI‑related processing).
Sector regulators may address AI within their remits using existing powers. However, no sectoral regulator has yet been statutorily appointed as an ‘AI authority’ in Israel.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Italy
Article 20 of Law No. 132/2025 designates the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) as the national authorities for artificial intelligence, without prejudice to the supervisory roles of the Bank of Italy, CONSOB, and IVASS in the banking, financial, and insurance markets, in accordance with Article 74(6) of the EU AI Act. Within this framework, AgID is entrusted with notification functions but also with responsibilities relating to the promotion of AI development, as well as the evaluation, accreditation, and monitoring of conformity assessment bodies. ACN, on the other hand, is responsible for the supervision of AI systems, exercising inspection and sanctioning powers, and acting both as the market surveillance authority and as the single point of contact with EU institutions. Sectoral regulators, the Italian Data Protection Authority, and AGCOM retain their respective competences, including the supervision of AI-related processing of personal data and the interaction between the Digital Services Act (DSA) and the EU AI Act for AI-powered online platforms and services. In this broader governance framework, the Italian AI experimentation space (‘Spazio di sperimentazione italiano per l'IA’), which is intended to serve as the regulatory sandbox envisaged under Article 57 of the EU AI Act, is currently provided for in a draft legislative decree preliminarily approved by the Italian Council of Ministers on 10 June 2026 and therefore remains subject to further review and possible amendment.
A supervisory body with authority for AI has not yet been appointed in Japan yet by way of statutory appointment.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Latvia
According to the Information Report, it is planned that there will be multiple national competent authorities ensuring the market surveillance based on the market area to be surveyed. For example, the compliance and safety of goods, the competent authority is the Consumers Rights Protection Centre, and the competent authority for the surveillance of medical devices is the Health Inspectorate. Regarding the data protection matters and forbidden AI practices, the competent authority will be the Data State Inspectorate, etc.
Whilst the majority of supervisory functions will be carried out by these authorities, other competent authorities will supervise more specific market areas, for example, railway systems, where the competent authority is the National Railway Technical Inspectorate, or marine equipment, where the competent authority will be the Maritime Administration of Latvia.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Lithuania
The Lithuanian Innovations Agency (Innovations Agency) was appointed as the notifying authority for Lithuania in accordance with the amendments to the Law on Technologies and Innovations, which will enter into force on 2 August 2025. The Innovations Agency will also act as supervisor of a sandbox regulatory environment.
The Communications Regulatory Authority (Communications Regulatory Authority) was appointed as principal supervising authority for Lithuania in accordance with the amendments to the Law on Information Society Service, which entered into force on 1 April 2025. Other sectoral authorities may exercise market-surveillance or fundamental-rights-related functions within their respective areas of competence, particularly where AI systems fall under existing sector-specific supervision.
As regards the Article 70(6) obligation for Member States to report to the European Commission by 2 August 2025, and every two years thereafter, on the status of the financial and human resources of their national competent authorities, Lithuania’s compliance is not publicly confirmable on the basis of publicly available evidence.
As regards the Article 57(1) obligation for Member States to ensure that at least one AI regulatory sandbox is established at national level and operational by 2 August 2026, Lithuania has implemented this requirement. The Innovations Agency was legally tasked with creating and supervising the sandbox, and Lithuania’s official sandbox portal was operational by May 2026, accepted applications, and described the sandbox as a controlled environment in which businesses could test AI solutions and obtain regulatory assistance.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Luxembourg
The Luxembourg Bill designates the notifying authorities responsible for evaluating and accrediting conformity assessment bodies to ensure they meet the necessary standards for certifying AI systems:
- Luxembourg Office of Accreditation and Surveillance (OLAS, Institut luxembourgeois de la normalisation, de l’accréditation, de la sécurité et qualité des produits et services);
- Luxembourg Agency for Medicines and Health Products (ALMPS, Agence luxembourgeoise des médicaments et produits de santé); and
- Luxembourg State Data Protection Commissioner’s Office (CGP, Commissariat du gouvernement à la protection des données auprès de l’État).
The National Commission for Data Protection (CNPD, Commission nationale pour la protection des données) is the notifying authority for implementing the AI Act when a high-risk AI system is intended to be deployed by law enforcement, immigration, or asylum authorities.
The market surveillance authorities will ensure that AI systems comply with the requirements of the EU AI Act within their respective areas of expertise. This includes as the default market surveillance authority and the primary point of contact in Luxembourg, the National Commission for Data Protection (CNPD, Commission nationale pour la protection des données).
Several market surveillance authorities are designated as exceptions to the CNPD’s jurisdiction:
- Judicial Supervisory Authority (JSA, Autorité de contrôle judiciaire);
- Financial Sector Supervisory Commission (CSSF, Commission de surveillance du secteur financier);
- Supervisory Authority for the Insurance Sector (CCAA, Commissariat aux assurances),
- Luxembourg Institute for Standardization, Accreditation, Safety, and Quality (ILNAS, Institut luxembourgeois de la normalisation, de l’accréditation, de la sécurité et qualité des produits et services);
- Luxembourg Institute of Regulation (ILR, Institut luxembourgeois de régulation);
- Luxembourg Agency for Medicines and Health Products (ALMPS, Agence luxembourgeoise des médicaments et produits de santé); and
- Luxembourg Independent Audiovisual Authority (ALIA, Autorité luxembourgeoise indépendante de l’audiovisuel).
Finally, the Luxembourg Bill mandates the CNPD to establish an AI regulatory sandbox, which will offer businesses and developers a controlled environment to test AI systems. The other authorities have the possibility to do the same and must collaborate with other relevant authorities when they set up a regulatory AI sandbox.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Malta
In accordance with Article 70 of the EU AI Act, the Malta Digital Innovation Authority (MDIA) and the Office of the Information Data Protection Commissioner (IDPC) have been designated as market surveillance authorities in Malta. The MDIA was designated as a market surveillance authority, and notifying authority, by virtue of Subsidiary Legislation 591.05, while the IDPC was designated as a market surveillance authority under Subsidiary Legislation 586.14. In addition, Subsidiary Legislation 591.05 provides that the assessment and monitoring activities referred to in Article 28(1) of the EU AI Act are to be carried out by Malta’s National Accreditation Board.
Whilst the national competent authorities have been designated, it is not yet clear whether Malta has complied with its obligations under Article 70(6) of the AI Act whereby it must report to the Commission on the status of the financial and human resources of such authorities.
Regulation 9 of Subsidiary Legislation 591.05 provides that the MDIA is to act as the national authority responsible for the establishment and functioning of an AI regulatory sandbox. However, this provision is not currently in force. While the MDIA already operates a Technology Sandbox, it is not yet clear whether this has been designated as Malta’s AI regulatory sandbox for the purposes of the EU AI Act, or whether a separate AI-specific sandbox will be established by the 2 August 2027 deadline.
In Malta, the authorities or bodies recognised for the task of supervising or enforcing the respect of obligations under EU law protecting fundamental rights in accordance with Article 77 of the EU AI Act are the following:
- Office of the Information and Data Protection Commissioner.
- Malta Competition and Consumer Affairs Authority.
- National Commission for the Promotion of Equality.
- Commission for the Rights of Persons with Disability.
- The Office of the Ombudsman.
- Department for Industrial and Employment Relations.
- JobsPlus Malta.
- Malta Broadcasting Authority.
- Director for the Protection of Minors.
- Electoral Commission Malta.
A supervisory body with the authority for AI has not yet been appointed in Mauritius by way of statutory appointment.
However, on 10 April 2026, the AI Unit was set up under the aegis of the Ministry of Information Technology, Communication and Innovation, with the aim of accelerating the transition to a digitally advanced economy. It acts as a cross-cutting enabler, integrating AI across all national digital projects and ensuring AI technologies are responsibly and effectively harnessed to improve public services, economic productivity and social well-being.
A supervisory body with authority for AI has not yet been appointed in Mexico by way of statutory appointment.
No supervisory authority specifically dedicated to AI has been designated in Morocco. Oversight is therefore exercised under existing regulatory frameworks.
Where an AI use involves the processing of personal data, it falls within the competence of the national data protection authority. In addition, other authorities may exercise oversight within their respective areas of competence, to the extent that an AI use falls within their scope. These include, in particular, the General Directorate for Information Systems Security in matters relating to information systems security, the Moroccan Office of Industrial and Commercial Property in the field of industrial property, and the Moroccan Copyright Office in relation to copyright.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in the Netherlands
In the Netherlands, the competent authorities for supervising and enforcing the EU AI Act have not yet been formally appointed. The government is in the process of developing a proposal. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur) have advised the government to appoint multiple supervisors, adopting a sectoral and centrally coordinated approach to AI supervision.
New Zealand does not have a dedicated AI regulator. Oversight of AI-related matters is distributed across existing sectoral regulators where their mandate interacts with AI, including the Office of the Privacy Commissioner (OPC) (privacy and personal information), the Financial Markets Authority (financial services), and the Commerce Commission (consumer protection). Other bodies with relevant sectoral mandates include the Human Rights Commission, and the Reserve Bank of New Zealand (RBNZ) (prudential oversight), as well as industry governance bodies with profession-specific oversight, such as the New Zealand Law Society.
In the public service, the Government Chief Digital Officer coordinates AI policy. Recently, Te Aka Matua o te Ture (the New Zealand Law Commission) has been instructed by the Minister of Justice to review the legal issues related to the use of automated decision-making by government. This is a significant instruction as Te Aka Matua o te Ture is an independent, statutory body established to advise on and review legislation.
More generally, New Zealand’s regulatory approach remains principles-based and light-touch, with no immediate plans for a dedicated AI regulator. The July 2024 Cabinet Paper and July 2025 AI Strategy (each discussed in the Regulatory Guidance / Voluntary Codes section) confirmed the Government’s preference for leveraging existing regulatory frameworks rather than introducing economy-wide AI-specific legislation.
No supervisory body has been officially appointed with specific authority over AI. However, various regulators exercise oversight over AI within their respective areas of regulatory purview. The Central Bank of Nigeria (CBN), for instance, regulates the use of AI in financial services, as underlined by its Baseline Standards for Automated Anti-Money Laundering (AML) Solutions issued in March 2026, which set minimum requirements for financial institutions on the deployment of automated AML/CFT/CPF solutions (including AI) covering customer identification and verification, risk profiling, transaction monitoring, sanctions screening, and real-time reporting. Similarly, the Nigeria Data Protection Commission exercises regulatory oversight over AI to the extent that its deployment impacts the processing of personal data.
The NCC has regulatory oversight over AI if used in the telecommunications sector. This is underlined by its issuance of the Internet Code of Practice, 2026, which includes some provisions governing the use of AI and emerging technologies by Internet Access Service Providers in the sector. NITDA also plays a role in AI policy development through its National Centre for Artificial Intelligence and Robotics (NCAIR).
The Norwegian Communications Authority (Nkom) has been appointed as the supervisory authority for Norway according to the proposal for the Norway AI Act.
There was a 2 August 2025 deadline for EU Member States to report to the Commission on the status of the financial and human resources of the national competent authorities (EU AI Act Article 70(6)). This deadline has not been met in Norway, as the EU AI Act has not yet been implemented into Norwegian law. However, Norway is expected to comply with the reporting requirements under Article 70(6) once the Act has been incorporated into the EEA Agreement and implemented into national law.
There was a 2 August 2025 deadline for EU Member States to designate national competent authorities (notifying authorities and market surveillance authorities), communicate them to the Commission, and make their contact details publicly available (Article 70(2) of the EU AI Act). In Norway. Nkom has been designated as the competent supervisory authority, and compliance with Article 70(2) is expected following implementation of the Act.
There is a 2 August 2027 deadline for EU Member States to ensure that their competent authorities have established at least one AI regulatory sandbox at national level, which should be operational by this date (Article 57(1) of the EU AI Act). In Norway, this requirement is expected to be met. Norway has established AI Norway (KI-Norge) as a national arena for AI governance and innovation, including an AI Sandbox where businesses can test and develop AI systems in a controlled environment.
Pursuant to Article 4 of the AI Law, the National Authority, as the governing body of the National System of Digital Transformation, is the technical and regulatory authority at the national level responsible for directing, evaluating and supervising the use and promotion of the development of artificial intelligence and emerging technologies, in order to achieve the country's objectives in terms of digital transformation and sustainable development objectives in accordance with current regulations.
Article 4 of the AI Law states that the National Authority, within the framework of the digital transformation, is appointed to develop and articulate actions to promote and encourage:
- The development of artificial intelligence and its adoption as a tool to boost the country's development and welfare.
- The training of professionals with competence in the exploitation, development and use of AI in the country.
- The creation and strengthening of digital infrastructure as an enabler for the development of AI.
- The development of a data infrastructure in order to make high quality, reusable and accessible public data available.
- The adoption of ethical guidelines for a sustainable, transparent and replicable use of AI.
- A collaborative AI ecosystem at national and international level.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Poland
Pursuant to the Draft Act, a new body, the Artificial Intelligence Development and Safety Commission (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji), will be set up to oversee AI systems market. The President of the Commission will be appointed by the Prime Minister for a term of five years from among candidates selected through an open and competitive selection process.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Portugal
The Portuguese Government designated the National Communications Authority (Autoridade Nacional de Comunicações) (ANACOM) as the market surveillance authority in Portugal.
In this regard, on 16 June 2026, ANACOM decided to open a public consultation until 16 July 2026 on the draft recommendations for the implementation of Article 5 of the EU AI Act. The draft recommendations are aimed at public and private organisations in Portugal and provide guidance on identifying, classifying, recording and withdrawing prohibited AI systems, in line with the European Commission’s Guidelines on prohibited artificial intelligence practices. The document also notes the need for multidisciplinary internal procedures, coordination with AI literacy measures, attention to agentic AI functionalities, and annual reviews of AI systems. Notwithstanding, ANACOM in these draft recommendations highlights that Article 5 of the EU AI Act may be modified as a result of the Digital Omnibus Proposal. A final version of the recommendations will be adopted following the conclusion of the public consultation period.
Portugal has identified the following entities protecting fundamental rights in relation to Article 77 of the EU AI Act:
- National Communications Authority (Autoridade Nacional de Comunicações) (ANACOM) - serving as the liaison with the other designated entities.
- General Inspectorate of Finance (Inspeção-Geral das Finanças) (IGF).
- National Security Office (Gabinete Nacional de Segurança) (GNS).
- Media Regulatory Authority (Entidade Reguladora para a Comunicação Social) (ERC).
- General Inspection of National Defence (Inspeção-Geral da Defesa Nacional) (IGDN).
- General Inspection of Justice Services (Inspeção-Geral dos Serviços de Justiça) (IGSJ).
- Judicial Police (Polícia Judiciária) (PJ).
- Inspectorate-General for Internal Administration (Inspeção-Geral da Administração Interna) (IGAI).
- Inspectorate-General for Education and Science (Inspeção-Geral da Educação e Ciência) (IGEC).
- Health Regulatory Authority (Entidade Reguladora da Saúde) (ERS).
- Food and Economic Safety Authority (Autoridade de Segurança Alimentar e Económica) (ASAE).
- General Inspectorate of the Ministry of Labour, Solidarity and Social Security (Inspeção-Geral do Ministério do Trabalho, Solidariedade e Segurança Social) (IGMTSSS).
- Authority for Labour Conditions (Autoridade para as Condições do Trabalho) (ACT).
- Energy Services Regulatory Authority (Entidade Reguladora dos Serviços Energéticos) (ERSE).
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
SDAIA is the competent authority overseeing data and AI in Saudi Arabia.
It supervises three key entities:
- The National Data Management Office (NDMO) operates under SDAIA's oversight and is tasked with developing and implementing data policies which underpin entities' responsible use of data.
- The National Center for AI (NCAI) is tasked with developing and deploying innovative data and AI-driven solutions to enhance decision-making and improve overall government performance.
- The National Information Center (NIC) provides national digital infrastructure and data services to support government entities, enabling secure data integration, analytics, and digital service delivery.
A single supervisory body with authority for AI has not yet been appointed in Singapore by way of statutory appointment. Instead, at least for now, Singapore adopts a sector-driven approach to AI regulation, with specific industry regulators releasing guidance on the use and deployment of AI within their field.
While the National Artificial Intelligence Council (NAIC) led by the Prime Minister was established in February 2026 to provide strategic direction and drive AI development in four key sectors (advanced manufacturing, connectivity, finance, and healthcare), it mainly serves a policy coordination function rather than a supervisory authority.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in the Slovak Republic
The proposed legislation establishes the Office for Digital Integrity (Úrad digitálnej integrity) (Office) as the authority responsible for AI governance in Slovakia. The office should serve as the central state administration authority for artificial intelligence, data governance and data management. Its powers include coordinating national AI policy, exercising market surveillance, conducting inspections, imposing sanctions, issuing methodological guidance and representing Slovakia in European AI governance structures.
It seems that Slovakia has failed to satisfy the statutory deadlines to (we were unable to get the confirmation from the respective Ministry):
- report to the European Commission on the allocation of financial and human resources to national competent authorities; and
- formally designate notifying authorities and market surveillance authorities, notify the Commission thereof, and publish their contact details.
Furthermore, Slovakia is projected to miss the deadline requiring competent authorities to establish at least one operational national AI regulatory sandbox.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
The Agency for Communication Networks and Services of the Republic of Slovenia (Agencija za komunikacijska omrežja in storitve Republike Slovenije) is designated as the single contact point of the Republic of Slovenia for the implementation of the EU AI Act in accordance with the SLO AI Act.
All supervisory authorities in Slovenia are:
- the Agency for Communication Networks and Services of the Republic of Slovenia (Agencija za komunikacijska omrežja in storitve Republike Slovenije);
- the Information Commissioner (Informacijski pooblaščenec);
- the Bank of Slovenia (Banka Slovenije);
- the Insurance Supervisory Agency (Agencija za zavarovalni nadzor); and
- the Market Inspectorate of the Republic of Slovenia (Tržni inšpektorat Republike Slovenije).
No supervisory body has been officially appointed with specific authority over AI in South Africa. The withdrawn draft policy envisaged the establishment of various entities to regulate AI such as:
- National AI Commission (a policy-making body);
- AI Ethics Board (to enforce ethical governance);
- AI Regulatory Authority (to monitor and enforce compliance);
- AI Ombudsperson Office (to allow individuals to challenge AI-driven decisions and receive redress);
- AI Insurance Superfund (to compensate individuals or entities harmed by AI-driven outcomes);
- National AI Safety Institute (for international collaboration on AI); and
- Integrated AI-Powered Monitoring Centre (to improve efficiency in service delivery).
There is currently debate regarding whether to establish new regulatory authorities or leverage the existing regulatory authorities. If new authorities are established, these will most likely fall under the authority of the DCDT.
There is currently no single primary supervisory authority under the AI Act in Korea. The Minister of MSIT has overall responsibility for AI policy coordination, enforcement of the AI Act, and operation of the AI Safety Institute. However, it is expected that regulatory agencies will continue to handle specific issues according to their respective domains. For example, PIPC will handle personal information-related issues, KMCC communication regulation issues, and the Korea Fair Trade Commission (KFTC) fair trade issues. The National AI Strategy Committee (NAISC), chaired by the President and comprising ministers and private-sector experts, provides high-level policy deliberation and coordination.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Spain
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) was formally established by the Supervisory Agency Royal Decree, which came into effect on 3 September 2023.
According to the Supervisory Agency Royal Decree, AESIA was scheduled to commence its operations on 3 December 2023. However, according to publicly available information, its operations effectively began in February 2025.
AESIA operates under the Ministry of Economic Affairs and Digital Transformation, specifically through the State Secretariat for Digitalisation and Artificial Intelligence. Headquartered in A Coruña, AESIA's responsibilities include overseeing, advising and providing training to both public and private entities to ensure the effective implementation of national and European AI regulations. Additionally, AESIA is tasked with conducting inspections, verifications, and imposing sanctions in accordance with European law.
European Level
The European Commission established the European AI Office (AI Office) on 24 January 2024. The AI Office is a European Commission function and forms part of the Directorate-General for Communications Networks, Content and Technology; it must therefore operate in accordance with the Commission's internal processes. The AI Office is responsible for assisting the European Commission with the oversight, monitoring and enforcement of requirements for GPAI models and systems. It is primarily made up of hired full-time staff from a range of backgrounds such as technology specialists, economists, policy specialists and lawyers.
In addition, the European Artificial Intelligence Board (AI Board) has also been established. The AI Board's core responsibility is to advise and assist the Commission and Member States to facilitate the consistent and effective application of the EU AI Act. The AI Board will include a representative from each Member State and the AI Office and the European Data Protection Supervisor shall participate as non-voting observers.
Member State Level
Article 70 of the EU AI Act concerns the designation of national competent authorities by EU Member States. It specifies that each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of the general supervision and enforcement of the EU AI Act. Where multiple market surveillance authorities are appointed, one of the market surveillance authorities must act as the single point of contact. The authorities must operate independently and without bias. Member States were required to notify the Commission of their appointed authorities and publicly available information on how to contact them by 2 August 2025. The designation of national authorities has been slower than expected, which may affect early enforcement consistency.
Supervisory authority in Sweden
On 4 June 2026, the Swedish Government appointed several national competent authorities under Article 70(1) of the EU AI Act. The Swedish Post and Telecom Authority (PTS), IMY, the Swedish Financial Supervisory Authority, the Swedish Medical Products Agency and Swedac have been assigned roles as market surveillance authorities and/or notifying authorities, with PTS also appointed as the single point of contact under Article 70(2) and tasked with establishing an AI regulatory sandbox under Article 57.
As regards the statutory deadlines, Sweden has met the Article 70(2) designation requirement only late, since the national competent authorities were appointed on 4 June 2026, after the 2 August 2025 deadline.
Sweden has tasked PTS with establishing the national AI regulatory sandbox, and PTS is preparing for that role by gathering input on the design of the Swedish sandbox. PTS describes the sandbox as a controlled environment in which providers and organisations may develop, test and validate AI systems under regulatory guidance before market release.
At present, the Electronic Transactions Development Agency (ETDA) has been assigned to review draft laws related to AI in Thailand. Sectoral regulators may also issue AI-related guidelines. For example, the Bank of Thailand (BOT) has issued the AI-related guidance in the financial sector, and the National Cyber Security Agency (NCSA) has issued the guidelines on the cybersecurity aspects of AI use.
The AI Governance Center (AIGC), under the Electronic Transactions Development Agency (ETDA), has also been established to perform key missions related to AI. These include developing a governance framework for AI in electronic transactions, providing consultation on AI policy and governance, and sharing knowledge on AI applications.
A supervisory body with authority for AI has not yet been appointed in Türkiye by way of statutory appointment. However, by Presidential Decree published on 25 December 2025, new AI directorates were established within the executive branch to broaden technology governance. These directorates may assume coordinating or oversight functions for AI-related matters, though their precise powers and relationship to any future AI-specific regulatory authority remain to be defined by implementing legislation.
There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI (and therefore there is no appointed supervisory body with authority for regulating AI).
However, a dedicated government ministry – the Artificial Intelligence, Digital Economy and Remote Work Applications Office (Ministry of AI) – has been established to drive the UAE’s AI initiatives. The Ministry of AI plays a crucial role in shaping policies and strategies relating to AI at a federal level. There are also authorities established in each emirate that are responsible for developing strategies and policies for AI in their respective emirate. For example, the Artificial Intelligence and Advanced Technology Council (AIATC) has been established in Abu Dhabi for “everything related to projects, investments and research related to artificial intelligence and advanced technology”.
The Commissioner of Data Protection is the supervisory authority responsible for regulating data protection in the DIFC, including the provisions in the DIFC’s Data Protection Regulations relating to the processing of personal data in connection with AI systems.
A single supervisory body with authority for AI has not yet been appointed in the UK by way of statutory appointment – see the Enforcement / Fines section.
However, Lord Holmes’ proposed AI (Regulation) Bill seeks to create a central statutory AI Authority, which would coordinate oversight across sectors and set governance standards. In July 2026, the new Government under Prime Minister Andy Burnham appointed Kanishka Narayan MP as Minister for AI, with a portfolio including AI opportunities, the AI Security Institute, semiconductors and online safety.
The US has no centralised federal regulator specifically dedicated to AI. Instead, federal oversight of AI remains distributed across multiple agencies and advisory bodies. For example, the Trump Administration’s December 2025 EO pushed a national policy framework and strategies to challenge state AI laws but did not suggest the need for a new regulator to oversee such efforts; it relies instead on existing agencies and officials.
Similarly, most states do not charge a single agency with oversight or responsibility for AI-related matters. A growing number of states have adopted AI-specific statutes that embed regulatory or enforcement authority in existing agencies or frameworks, such as consumer protection, and that sometimes designate specialised oversight bodies in particular market sectors.
For example, Colorado’s AG will enforce the State’s new automated decision-making technology law under the Colorado Consumer Protection Act, with no private right of action, and the Texas Attorney General has exclusive authority to enforce the Texas Responsible AI Governance Act (TRAIGA); Utah, meanwhile, has designated oversight through its Department of Commerce and an emerging Office of AI Policy. New York’s RAISE Act will create a new agency, within a larger, existing one, to implement that law. At the local level, New York City’s Local Law 144 assigns enforcement to NYC’s Department of Consumer and Worker Protection (DCWP).
In other states, AGs are actively leveraging existing consumer protection, privacy, and anti-discrimination laws to investigate and enforce against AI-related harms. In addition to engaging AGs, several states have empowered consumer protection agencies or other regulatory bodies to oversee AI-related compliance, resulting in a decentralised enforcement landscape where responsibilities vary by jurisdiction.