The EU AI Act Member State Authorities are the national supervisory bodies designated by each European Union member state to enforce the Artificial Intelligence Act (AI Act), a regulation that entered into force on 1 August 2024. These authorities are responsible for monitoring compliance with the Act's risk-based requirements, conducting investigations, and imposing penalties for violations within their respective jurisdictions. The regulation establishes a framework where each member state must designate at least one national competent authority, which typically includes a market surveillance authority and a notifying authority, to oversee AI systems placed on the market or used within that state.
The AI Act, proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. It covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context. The Act can apply extraterritorially to providers from outside the EU if they have users within the EU, similar to the EU's General Data Protection Regulation.
Designation and Structure
Each member state is required to designate national competent authorities to implement and enforce the AI Act. The designation process involves establishing a market surveillance authority, which handles compliance checks and enforcement actions, and a notifying authority, which manages the assessment and notification of conformity assessment bodies. In many member states, these functions are assigned to existing regulatory agencies, such as data protection authorities or consumer protection bodies, while others have created dedicated AI oversight offices. The authorities operate independently in their enforcement duties but coordinate through the European Artificial Intelligence Board, which promotes national cooperation and ensures consistent application of the regulation across the EU.
The national authorities have the power to request documentation and information from AI providers and deployers, conduct unannounced inspections, and access datasets used for training and testing AI systems. They can also issue warnings, impose corrective measures, and order the withdrawal or recall of non-compliant AI products from the market. The Act requires these authorities to have sufficient resources and expertise to carry out their functions, including technical knowledge of Artificial intelligence systems and their associated risks.
Enforcement Powers
The enforcement powers of member state authorities vary depending on the risk category of the AI system. For high-risk applications, authorities can require conformity assessments, mandate corrective actions, and suspend or prohibit the use of systems that pose significant threats to health, safety, or fundamental rights. For unacceptable-risk applications that are banned under the Act, authorities have the power to order immediate removal and can impose substantial fines. The Act sets penalty frameworks that member states must implement, with fines for non-compliance reaching up to a percentage of the offending company's global annual turnover or a fixed amount, whichever is higher.
Authorities also handle citizen complaints about AI systems and must provide explanations of decisions made by high-risk AI that affect individuals' rights. They are required to establish accessible procedures for reporting violations and to protect whistleblowers who report non-compliance. The enforcement approach follows a product-safety model, where regulatory duties are assigned to providers and deployers, and these duties become more demanding as the potential impact on health, safety, or fundamental rights increases.
Coordination with the European Artificial Intelligence Board
The European Artificial Intelligence Board serves as the central coordination mechanism for member state authorities. It facilitates the exchange of information, develops guidance on consistent interpretation of the Act, and helps resolve disputes between national authorities. The Board also advises the European Commission on technical standards and implementation issues. Member state authorities are required to participate actively in Board activities and to share information about enforcement actions, market surveillance findings, and emerging risks related to AI systems.
The Board plays a particularly important role in cases involving general-purpose AI models, such as Large language model systems, which may be deployed across multiple member states. When a systemic risk is identified, the Board coordinates joint investigations and ensures that enforcement actions are consistent across jurisdictions. This coordination is essential because the Act's extraterritorial application means that providers from outside the EU, including companies like OpenAI and Google DeepMind, may be subject to oversight by multiple national authorities simultaneously.
Risk-Based Oversight Responsibilities
The oversight responsibilities of member state authorities are structured according to the Act's four risk levels plus the general-purpose AI category. For unacceptable-risk applications, which are banned except for specific exemptions, authorities must actively monitor and enforce prohibitions on AI systems that manipulate human behaviour, use real-time remote biometric identification in public spaces, or engage in social scoring. For high-risk applications in areas such as health, education, recruitment, critical infrastructure management, law enforcement, or justice, authorities verify compliance with quality, transparency, human oversight, and safety obligations, and may require Fundamental Rights Impact Assessments before deployment.
Limited-risk systems, including those that generate or manipulate images, sound, or videos such as deepfakes, are subject to transparency obligations, and authorities ensure that users are informed when interacting with AI systems. Minimal-risk applications, such as AI used in video games or spam filters, are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules. For general-purpose AI, authorities oversee transparency requirements, including training data summaries and copyright policies, with additional evaluations required for high-capability models that pose systemic risks.
Penalties and Corrective Measures
The Act requires member states to establish effective, proportionate, and dissuasive penalties for violations. The specific penalty amounts are determined by national law, but the Act sets maximum levels that member states must implement. For violations involving unacceptable-risk AI applications, fines can reach up to 7% of the offending company's global annual turnover or €35 million, whichever is higher. For violations of other obligations, such as those related to high-risk systems or general-purpose AI, fines can reach up to 3% of global annual turnover or €15 million. Supplying incorrect or misleading information to authorities can result in fines up to 1% of global annual turnover or €7.5 million.
Authorities also have the power to impose corrective measures beyond financial penalties, including requiring providers to bring AI systems into compliance, restricting or prohibiting the placing on the market of non-compliant systems, and ordering recalls of products already in use. In urgent cases where an AI system poses a serious risk, authorities can take immediate action before completing a full assessment, subject to subsequent review.
Implementation Timeline and Transition
The provisions of the AI Act are being implemented gradually over 6 to 36 months from the entry into force on 1 August 2024. Member state authorities were required to be designated and operational within the first months of implementation. The prohibitions on unacceptable-risk applications became applicable after six months, while obligations for general-purpose AI and high-risk systems are being phased in over longer periods. The Act's draft was revised to address the rise in popularity of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework, and this revision added the general-purpose AI category in 2023.
During the transition period, member state authorities are developing their operational procedures, hiring technical staff, and establishing cooperation protocols with other regulatory bodies. They are also preparing guidance documents for businesses operating within their jurisdictions and participating in the development of harmonised standards that will support compliance assessments. The gradual implementation is designed to give both authorities and regulated entities time to adapt to the new requirements while ensuring that the most serious risks are addressed promptly.
Relationship with Other Regulatory Bodies
Member state authorities under the AI Act operate alongside other regulatory bodies with related responsibilities. They coordinate with data protection authorities, particularly for AI systems that process personal data, and with sector-specific regulators in areas such as healthcare, financial services, and transportation. The Act also interacts with existing product safety legislation, and authorities must ensure that their enforcement actions are consistent with other EU regulations. In cases where AI systems are used in conjunction with other technologies, such as Machine learning models deployed through cloud services from providers like Amazon Web Services or Microsoft Azure, authorities may need to coordinate across multiple regulatory frameworks.
The Act's extraterritorial application means that authorities may also cooperate with regulators in non-EU countries, particularly for AI providers based in the United States, China, or other major AI development hubs. This international dimension adds complexity to enforcement, as authorities must balance the Act's requirements with the legal frameworks of other jurisdictions while ensuring that EU citizens are protected from harmful AI applications.