Who actually enforces this?
The AI Act is a regulation: one text, directly applicable in all 27 member states, no transposition. That makes it tempting to assume the experience of it is uniform. It is not, and the reason is one word in Article 70.
The word is "at least"
Article 70 requires each member state to establish or designate at least one notifying authority and at least one market surveillance authority, which must
exercise their powers independently, impartially and without bias
Member states also had to publish contact details for their competent authorities and single points of contact, by electronic means, by 2 August 2025, and designate one market surveillance authority as the single point of contact.
"At least one" is a floor, not a ceiling. Nothing stops a member state routing AI supervision through its existing sectoral regulators — finance, health, transport, telecoms, data protection — and ending up with a dozen or more. Nothing requires it to, either. Both choices are compliant, and member states made different ones.
Penalties are national too
Article 99(1):
Member States shall lay down the rules on penalties and other enforcement measures […] The penalties provided for shall be effective, proportionate and dissuasive.
The AI Act sets the ceilings — €15,000,000 or 3% of worldwide turnover for an Article 50 breach, whichever is higher. For SMEs, Article 99(6) inverts that to whichever is lower, and the Digital Omnibus extends the same treatment to small mid-caps — the full picture. What sits underneath the ceiling is national: who investigates, on what trigger, with what procedure, and what actually happens when they find something.
Why this is the agency's real question
If you are an agency with clients in four member states, the interesting question is not "am I covered" — you are, or you are not, and the text is the same everywhere. It is:
Who do I even ask?
In a state with one dedicated AI authority, there is one website, one inbox, one body publishing guidance. In a state that distributed supervision across sectoral regulators, the answer to "who supervises our client's e-commerce chatbot" is a research project before it is a compliance question.
That difference does not change your obligations by a comma. It changes how much work it is to get an answer, and for a small agency that is the cost that actually lands.
What we are deliberately not publishing yet
We have a country-by-country picture of which states centralised and which distributed. We are not publishing it, because the sources we have for it are law-firm summaries and industry press rather than the designation instruments themselves — and for two member states we have no source at all.
Our rule is that anything on this site can be verified by a reader in two clicks against a primary source. A table of national authorities assembled from secondary reporting fails that test, and a compliance site that publishes a plausible-looking table it cannot back is doing the thing we exist to be an alternative to.
It will go up when each row links to the member state's own instrument.
One thing we will say plainly
We describe institutional structure. We do not tell you where enforcement is weaker, and you should be wary of anyone who does. "This member state concentrated supervision in a single agency" is a fact about how a government is organised. "You are less likely to get caught there" is a guess dressed as advice, and it is a bad basis for deciding whether to spend ten minutes putting a sentence in a chat window.
Also worth stating: as of the last update to this page, Article 50 had not yet become applicable. There is no enforcement history to report, and any "AI Act fine" you have seen is either a different article or a GDPR matter.