Who Enforces the EU AI Act? It Depends Which Country You're In
If your company operates in more than one EU country, or sells into more than one, you have probably already noticed that "who enforces GDPR" has a clean, one-line answer: your national data protection authority, coordinated under a one-stop-shop mechanism that has run since 2018. Ask the equivalent question about the EU AI Act, and the answer changes depending on which member state you are standing in. That is not a gap in this article; it is a genuine feature, or side effect, of how the Regulation was written. Understanding why makes the rest of your compliance planning considerably less confusing.
The Act tells states what to decide, not what to decide
Article 70 of Regulation (EU) 2024/1689 required every member state to designate at least one notifying authority and at least one market surveillance authority by 2 August 2025. What it deliberately did not do is specify which existing body, or whether a new one, should take on that role. States could reuse an existing regulator, split responsibilities across several sector regulators, or stand up a dedicated new agency from scratch. All three approaches are now live somewhere in the EU, which is exactly why a single, EU-wide answer to "who enforces this" does not exist yet, and may never fully converge the way GDPR enforcement has.
Three institutional models, three different countries
Germany went the route of a dedicated central coordinator drawn from an existing regulator's remit. The Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), which entered into force in July 2026, named the Bundesnetzagentur as Germany's central AI Act market surveillance authority, acting as the catch-all for the high-risk categories listed in Annex III. Sector regulators that already had a foothold keep it: BaFin retains oversight of AI used in already-harmonised financial products, and GDPR itself continues to be enforced by the federal and state data protection authorities (BfDI and the Landesdatenschutzbehörden), not by the Bundesnetzagentur. It was not the only option on the table — Germany's Datenschutzkonferenz argued in a May 2024 position paper for handing AI Act powers to the existing data protection authorities instead — which is a useful reminder that even within one country, the current split was a choice among genuine alternatives, not the only possible outcome.
Spain took the opposite path: rather than assign the role to an existing body, it created one. The Agencia Española de Supervisión de Inteligencia Artificial (AESIA), established by Real Decreto 729/2023 and based in A Coruña, is the first dedicated national AI-supervision agency of its kind anywhere in the EU. GDPR enforcement stays with the AEPD, Spain's existing data protection authority. The two are coordinating in public, and Spain's draft AI law reportedly provides for a joint commission to avoid duplicated investigations of the same system, but as of this writing that coordination is a work in progress, not a finished mechanism.
France went a third way: no single new body at all. The Article 70 minimum was satisfied by parcelling responsibility out to the sector regulators that already had jurisdiction over the relevant activity. The CNIL, France's data protection authority, plays the leading role in practice because most AI systems process personal data one way or another, but the DGCCRF covers consumer-facing practices, ACPR and AMF cover credit and financial scoring, ANSM covers AI-assisted medical devices, and ARCOM covers certain audiovisual and platform content uses. The regulator that already supervised your sector before the AI Act existed is, in France's model, generally still the one that supervises it now.
The one authority that is the same everywhere: the EU AI Office
There is exactly one piece of this picture that does not vary by member state. General-purpose AI models with systemic risk are supervised centrally by the European Commission's AI Office, not by any national authority. The AI Office organises much of that oversight through the GPAI Code of Practice, open for signature since August 2025 and enforceable from August 2026. If your company builds or fine-tunes a large general-purpose model, the AI Office is your counterparty regardless of where in the EU you are based. If you are an SME using AI tools built by someone else, in the vast majority of cases this authority is not the one you need to track day to day — but it is worth knowing it exists, because it is the one constant in an otherwise fragmented map.
Fragmented enforcement does not mean untested enforcement
It would be a mistake to read "still forming" as "not really happening yet." Enforcement on AI systems that process personal data has already produced real, contested outcomes: a widely reported €15 million fine issued against OpenAI by Italy's data protection authority, the Garante, in December 2024 over ChatGPT's training practices, was later annulled by a Rome court in 2026. That reversal is a useful data point in itself — it shows regulators are actively testing the boundaries of their authority under both GDPR and the AI Act, and that early enforcement actions can be overturned on appeal rather than standing as settled precedent. Treat any single case, including this one, as a directional signal about where scrutiny is heading, not as a fixed rulebook.
What this means if you operate across borders
For a company operating in one country, the practical task is simple to state even if the underlying law is not: find out which of your local authorities has taken on the AI Act role, and treat your existing data protection authority relationship as the starting point regardless of who else turns out to be involved. For a company operating across several EU member states, the same AI system, say, a hiring-screening tool or a credit-scoring model, can in principle answer to a different authority, on a different timeline, in each country where you deploy it. That is not a hypothetical edge case; it follows directly from member states having taken genuinely different institutional paths, as Germany, Spain, and France illustrate. Building one clean piece of documentation for that system, rather than reconstructing your evidence file per country if you are ever asked, is the most durable hedge against that fragmentation.
A checklist for your own exposure
You do not need Europe's enforcement map to be finished before getting your own documentation in order. Six questions are worth answering now:
- For each country you operate in, do you know which authority has taken on AI Act market surveillance, and is it the same one that already enforces GDPR for you there?
- If you operate in Germany, have you checked whether your use case falls under the Bundesnetzagentur's catch-all role or a sector regulator like BaFin?
- If you operate in Spain, do you know whether AESIA or the AEPD, or both, would be the first point of contact for your kind of AI system?
- If you operate in France, have you identified which sector regulator — CNIL, DGCCRF, ACPR/AMF, ANSM, or ARCOM — is most likely to be relevant to your use case?
- Does any AI system you use qualify as general-purpose with systemic risk, putting it under the EU AI Office rather than any national authority?
- Could you produce one piece of documentation per AI system today, usable across every country you operate in, rather than starting from scratch if a regulator in any one of them asks first?
General information, not legal advice: enforcement architecture across the EU is still settling, country by country, and this article reflects the picture as of when it was written rather than a fixed, final map. Where Komplya publishes material like this, we distinguish content that has been formally reviewed against primary sources from material that remains a working draft, so you can weigh it accordingly.
Which authority would actually look at your AI systems depends on where you operate and what those systems do — not on a single EU-wide rulebook. A short questionnaire on your real AI use cases is the fastest way to get a plain-language read on your likely exposure, country by country, rather than trying to reverse-engineer it from regulatory announcements as they trickle in.