# Who enforces the EU AI Act: National authorities, the AI Office, and market surveillance > Enforcement of the EU AI Act runs on two levels. Each EU member state designates a notifying authority and a market surveillance authority under Article 70. At EU level, the AI Office and the European Artificial Intelligence Board coordinate implementation, and the AI Office directly polices providers of general-purpose AI models. **Author:** Maarten Stolk **Last reviewed:** 28 July 2026 **Source:** https://deeploy.ai/eu-ai-act-hub/articles/who-enforces-the-eu-ai-act-national-authorities-the-ai-office-and-market-surveillance/ ## **Two layers, not just one regulator** The EU AI Act splits enforcement across two levels rather than routing it through a single regulator.  At the national level, Article 70 requires every member state to designate at least one notifying authority and at least one market surveillance authority, with one of them acting as the country's single point of contact for the Act. These are the bodies that handle the bulk of day-to-day enforcement: reviewing high-risk system documentation, investigating complaints, and issuing fines under Article 99. Read how the [Netherlands](https://deeploy.ai/eu-ai-act-hub/articles/eu-ai-act-in-the-netherlands-which-authorities-supervise-what/) applied this enforcement. At the EU level, Chapter VII establishes a smaller set of bodies with a coordinating role, and for one category of provider, a directly enforcing one. The AI Office, based within the European Commission, oversees consistent implementation across member states and directly enforces the rules for providers of general-purpose AI models. Therefore, the European Artificial Intelligence Board brings together representatives of each member state to advise the Commission and coordinate national practice.  Both layers already became operational earlier than most of the substantive obligations they will eventually enforce: the governance chapter behind them applied from 2 August 2025, a full year before most high-risk system requirements themselves became binding. ## **The two EU AI Act enforcement layers at a glance**   | **Level** | **Body** | **Role** | **Legal basis** | | --- | --- | --- | --- | | EU | **AI Office** | Based in the European Commission; oversees consistent implementation across member states; directly enforces obligations on providers of general-purpose AI models | Article 64, Article 88 | | EU | **European Artificial Intelligence Board** | One representative per member state; advises the Commission and coordinates national practice | Article 65, Article 66 | | EU | **Advisory Forum** | Stakeholder body advising the Commission and the Board | Article 67 | | EU | **Scientific Panel of Independent Experts** | Technical experts supporting enforcement and advising on general-purpose AI models, including systemic-risk questions | Article 68 | | National | **Notifying authority** | Sets up and runs the procedures for assessing, designating, and monitoring notified bodies | Article 3(19), Article 70 | | National | **Market surveillance authority** | Investigates, inspects, and enforces compliance within its member state, including issuing fines | Article 3(26), Article 70 | | National | **Single point of contact** | One authority per member state designated as the main contact for the Act | Article 70(2) | | EU institutions | **European Data Protection Supervisor** | Acts as the competent authority when an EU institution, body, office, or agency is itself the operator | Article 70(9) | **What this means in practice:** Most organisations will never deal with the AI Office directly. If you build a recruitment tool, a credit-scoring model, or an internal HR system, the authority that shows up at your door is your own country's market surveillance body, the same kind of regulator that already polices product safety or financial conduct. The AI Office is reserved for one specific and much smaller group: the handful of companies that build the underlying general-purpose AI models everyone else builds on top of. ## **How national authorities are set up** - Every member state had to designate its notifying authority and market surveillance authority, and make their contact details public, by 2 August 2025. - Member states can appoint any existing public body for these roles, chosen to fit their own institutional structure. Germany, for example, assigned its Federal Accreditation Body as notifying authority and its Federal Network Agency as market surveillance authority. - Independent monitoring around the August 2025 deadline found designation was uneven across the EU, with a number of member states still finalising their choice of authority close to, or after, the deadline itself. - The notifying authority and the market surveillance authority can be the same body or two different ones, depending on how a given member state organises its administration. ## **Who enforces what** The split comes down to who your organisation is. National market surveillance authorities enforce Article 99 fines within their own territory, and this covers the bulk of cases: prohibited practices, high-risk system obligations, and Article 50 transparency rules.  Providers of general-purpose AI models are the one clear exception. The AI Office enforces Article 101 fines against them directly, under Article 88, without routing the matter through national authorities at all. The Digital Omnibus extended that direct reach further, giving the AI Office exclusive competence over any AI system built on a general-purpose AI model where the model and the system come from the same provider. A few sectors sit outside this split regardless of what else changes. National authorities keep their existing competence over law enforcement, border management, judicial authorities, and financial institutions, even where an AI Office carve-out might otherwise apply. And in the one case where an EU institution, body, office, or agency is itself the operator of an AI system, the European Data Protection Supervisor steps in as the competent authority, standing in for a national one. ## **When these bodies started operating** - Chapter VII, which establishes the AI Office, the Board, the Advisory Forum, the Scientific Panel, and the national competent authority framework, applied from 2 August 2025. - That is the same date Chapter V (GPAI obligations) and most of Chapter XII (penalties, covering Articles 99 and 100) became applicable, a full year ahead of the general 2 August 2026 date most high-risk system obligations follow. - Article 101, the fine specific to GPAI providers, is the one exception within that August 2025 group: it applies from 2 August 2026 instead. In practice, this means the enforcement architecture, the authorities, their powers, and the general fine mechanism, was in place before most of the specific obligations under Annex III became binding, obligations now deferred further to 2 December 2027 for stand-alone systems and 2 August 2028 for Annex I embedded systems under the Digital Omnibus. ## **How Deeploy's AI governance software helps to adhere to the EU AI Act** Regulators, whether national or the AI Office, tend to arrive at the same underlying question: not what the system was designed to do, but what it has actually been doing in production. That distinction is where a policy document stops being sufficient on its own. Deeploy turns logs, drift signals, and documentation into a standing record of a system's real-world behaviour, so that record already exists in a usable form whenever a review calls for it, rather than being assembled under time pressure after the fact. ## Frequently asked questions ## Frequently asked questions ### Does the Netherlands have its own separate AI law? Not in the sense of a substantive AI law. The EU AI Act is directly applicable. The Netherlands is finalising an implementation law, the Uitvoeringswet AI-verordening, that designates which national authorities can supervise it and issue fines, rather than writing new substantive AI rules of its own. ### Is there one dedicated Dutch AI regulator? No. The Dutch AI draft law splits supervision across eight existing sector-specific authorities rather than creating a new one, so organisations continue to deal with the regulator they already know for their sector. ### Who is the single point of contact for the Netherlands under the EU AI Act? The Dutch Authority for Digital Infrastructure (RDI) is designated as the single point of contact under Article 70(2), working jointly with the Dutch Data Protection Authority (AP) to coordinate the overall system. ### Which Dutch authority handles AI used in banking or insurance? The Authority for the Financial Markets (AFM) and the Dutch Central Bank (DNB) are designated to supervise high-risk AI, prohibited practices, and transparency obligations in financial services. ### Has the Dutch implementation law been finalised? No. The draft went out for public consultation on 20 April 2026 and was expected to reach the House of Representatives in the fourth quarter of 2026, but had not been adopted as of July 2026. ### Does the delay in Dutch implementation mean prohibited AI practices aren't enforced in the Netherlands? No. The Article 5 prohibitions have applied since 2 February 2025 regardless of national implementing legislation, and the AP has been preparing to supervise them since before that date. What the draft law settles is the formal legal basis for which authority issues fines and takes enforcement action nationally.