Who enforces the AI Act in your country — and how complaints work
Last updated 1 August 2026
Since 2 August 2026 the AI Act's transparency rules are enforceable — but who enforces them depends on where you (or your users) are. Each Member State designates its own market surveillance authorities under Article 70 of Regulation (EU) 2024/1689, and under Article 85any natural or legal person may lodge a complaint with the relevant authority if they have grounds to consider the Regulation has been infringed. The Commission expects such complaints to be “an essential contribution to an effective enforcement of the AI Act” (Commission policy page).
Below is the state of play in the six largest EU markets plus the EU level, from official sources only. Note that the designation landscape is still moving: the Commission's list of Single Points of Contact is updated continuously, and several national implementing laws are still in progress.
European Union (EU level)
- Competent authority
- AI Office (European Commission) for general-purpose AI models; European Data Protection Supervisor (EDPS) for EU institutions, bodies and agencies; the European AI Board coordinates national authorities.
- Designation status
- Operational. The Commission publishes and continuously updates the list of national Single Points of Contact.
- Complaints
- Complaints about AI systems go to the national market surveillance authority of the Member State concerned (Article 85); GPAI-model issues sit with the AI Office.
Germany (DE)
- Competent authority
- Bundesnetzagentur (Federal Network Agency) — coordinates market surveillance for the Annex III high-risk fields and is the competent authority for radio-equipment AI under Annex I; it also runs an AI Service Desk. Existing sectoral surveillance structures keep their Annex I domains.
- Designation status
- A national AI Act implementing law is still pending — Germany is not yet on the Commission's list of notified Single Points of Contact.
- Complaints
- The Bundesnetzagentur states that market surveillance authorities follow up complaints from natural and legal persons, in particular consumer complaints; its online contact form is the published channel.
France (FR)
- Competent authority
- Coordination by DGCCRF and DGE, with sectoral authorities (CNIL, Arcom and others) supervising in their existing domains; ANSSI and PEReN provide technical expertise.
- Designation status
- Designation scheme published by the Government (September 2025); the enabling bill must still pass Parliament — France is not yet on the Commission's notified list.
- Complaints
- Under the proposed scheme, businesses deal mostly with their existing sectoral regulator (e.g. CNIL in its domains, Arcom for audiovisual matters), with DGCCRF and DGE coordinating the authorities' actions.
Spain (ES)
- Competent authority
- AESIA — Agencia Española de Supervisión de Inteligencia Artificial, attached to the Ministry for Digital Transformation; holds the inspection, verification and sanctioning functions under Regulation (EU) 2024/1689.
- Designation status
- Listed as Spain's Single Point of Contact on the Commission's page, with the national designation decision pending final adoption.
- Complaints
- AESIA is the contact point for AI supervision matters in Spain; it publishes citizen and business service channels on its official site.
Italy (IT)
- Competent authority
- ACN (Agenzia per la Cybersicurezza Nazionale) — market surveillance authority and Single Point of Contact; AgID is the notifying authority. Banca d'Italia, CONSOB and IVASS retain AI market surveillance in financial services (Article 74(6)).
- Designation status
- Designated by national law: Law No. 132 of 23 September 2025, Article 20, in force since 10 October 2025.
- Complaints
- Complaints and reports concerning AI systems in Italy go to ACN (or the sectoral financial supervisors within their remit).
Poland (PL)
- Competent authority
- KRiBSI — Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (Commission for the Development and Safety of Artificial Intelligence), the market surveillance authority and Single Point of Contact under Article 70.
- Designation status
- Established by the Act on Artificial Intelligence Systems of 3 July 2026 (Journal of Laws 2026, item 1003, published 27 July 2026).
- Complaints
- Citizens, businesses and institutions can lodge complaints about AI systems directly with KRiBSI, per the Ministry of Digital Affairs.
Netherlands (NL)
- Competent authority
- Hybrid model: Autoriteit Persoonsgegevens (AP) supervises prohibited practices, most Annex III high-risk systems and the transparency obligations (chatbots, deep fakes); RDI acts as central contact point; sectoral supervisors (AFM, DNB, inspectorates) keep their domains.
- Designation status
- Implementing act (Uitvoeringswet AI-verordening) published for consultation on 20 April 2026; formal designation pending — NL is not yet on the Commission's notified list.
- Complaints
- For transparency-related concerns (Article 50 subjects such as chatbots and deep fakes), the AP is the intended supervisor; the RDI is the planned central contact point.
If a complaint lands on your desk
Market surveillance authorities can investigate, monitor remotely, access documentation, order corrective measures and fine. For Article 50 transparency breaches the ceiling is EUR 15 million or 3% of worldwide annual turnover (Article 99(4)(g)). The practical defence is dated evidence that your disclosures and marking were in place: run the free Article 50 check to get a dated obligations report, and see what belongs in an evidence pack or plans for continuous coverage. If you are a provider of generative AI, the Code of Practice on Transparency of AI-generated Content is the Commission-recognised pathway to demonstrate compliance to any of these authorities.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check