Nine Regulators, Eighteen Empty Chairs
On 2 August 2026 the enforcement powers under the EU AI Act began to apply. The AI Office took supervision of general purpose AI models, and national authorities in each member state took everything else, with penalties reaching €35m or 7% of worldwide turnover. Member states were supposed to have designated those authorities by 2 August 2025. On the most recent public count, nine of the twenty-seven had designated a full set. Six had designated none at all.
The temptation is to read that as a year of grace. It is the opposite, and the reason is in a detail almost nobody has noticed: on the one obligation where the deadline has already passed and been met, every single member state complied.
What the map actually looks like
The Act requires each member state to appoint two things: a market surveillance authority, which supervises AI systems on the market and takes enforcement action, and a notifying authority, which designates and monitors the bodies that carry out conformity assessments. Together they are the national competent authorities. The deadline was 2 August 2025.
As at the most recent published survey by the Future of Life Institute, updated on 17 June 2026, nine member states had both in place. Twelve had partial clarity, meaning draft legislation, an announcement, or one of the two appointed. Six had neither.
Among the nine, the choices are instructive. Italy was the first member state to pass a national implementing law and handed market surveillance to its National Cybersecurity Agency. Finland took the opposite approach, spreading supervision across existing sectoral regulators with its transport and communications agency as the single point of contact. Ireland designated fifteen existing bodies. Cyprus gave all three roles to one Commissioner of Communications.
Among the twelve, Germany's draft bill naming the Bundesnetzagentur was adopted by the federal cabinet in February 2026 and still has to pass both houses. Poland's act cleared its lower house in June and awaits the upper. The Netherlands published draft legislation in April proposing ten sectoral authorities.
Among the six, there is nothing to report, which is the point.
Why an absent regulator is worse than a present one
Three consequences follow, and none of them is favourable to a business that would rather wait.
The obligation applied on the date regardless. Enforcement machinery being late does not move a duty. It moves the moment somebody notices. When the six appoint, and they will, they inherit conduct that has been in scope since August 2026, and they will be new authorities with a mandate to establish themselves. New regulators do not open their accounts with a warning letter about a marginal case. They open with something that makes the point.
The feedback loop is missing, and that is what you actually need. Firms do not learn what a regulation means from its text. They learn it from decisions, guidance and enforcement priorities. With nine authorities active and eighteen silent, the interpretations that harden into the European standard over the next two years will be written by whoever moves first. On current form that is Italy's cybersecurity agency, Finland's decentralised sectoral regulators and Ireland's fifteen bodies. If your business sells into the EU and has no read on how any of those three think, you are not ahead of the regulation. You are simply not being watched yet.
The character of the regulator shapes the questions. This is the part that survives all the uncertainty about timing. Italy chose a cybersecurity agency, and a cybersecurity agency asks about resilience, incident handling and technical controls. Several states chose telecoms regulators, who are experienced at technical conformity and inexperienced at fundamental rights. Spain built a dedicated AI supervisor. The same AI system, sold into three of those markets, will be examined by three institutions with different instincts about what matters. Harmonised law does not produce harmonised scrutiny.
The exception that undoes the comfortable reading
There is one designation duty under the Act whose deadline has already passed and been met in full. Article 77 required member states to identify the national public authorities that supervise and enforce fundamental rights obligations in relation to high-risk AI, and to publish the list by 2 November 2024.
All twenty-seven have done it. The Commission maintains a consolidated list, and it runs to hundreds of bodies: data protection authorities, equality bodies, ombudsmen, labour inspectorates, consumer regulators. These are not new institutions waiting to be built. They are existing regulators with existing powers, existing caseloads and existing complaint channels, and under Article 77 they can request and access documentation created or maintained under the AI Act where it is necessary to their mandate.
So the honest picture is not an empty room. It is a room where the market surveillance chair is vacant in eighteen countries and the fundamental rights chairs are all occupied, in every country, and have been for nearly two years. An organisation using AI in recruitment, credit, insurance pricing, access to services or workplace monitoring is already within reach of a regulator that exists, is funded and takes complaints from the public.
Waiting for the market surveillance authority to be appointed is waiting for the wrong regulator.
What this means for a UK business
Your regulator is chosen by your customer's address, not yours. A British firm placing an AI system on the EU market answers to the authority of the state where that happens. Sell into Italy, Finland and Ireland and you are inside three supervisory regimes built on three different philosophies. That is not one compliance programme with a European label on it.
The uneven map is a planning input, not a risk rating. There is a temptation to sequence EU market entry by how lightly supervised a state currently looks. It is a poor trade. The obligations are harmonised even where the enforcement is not, the gap is closing on a timetable you do not control, and a sales strategy that quietly depends on nobody checking is not one a board should be asked to approve.
The commercial pressure will not come from a regulator first. It will come from a customer. Procurement teams in Italy, Ireland and Finland are already operating under a designated authority and are already being told to ask suppliers about it. Those questions reach you well before any enforcement action does, and the firm that can answer them from a maintained file wins work from the firm that cannot.
What leaders should do now
- List the member states you actually operate in, and name the authority for each. Not "the EU". The specific body, or the fact that there is not one yet. That list is a one-page exercise and most organisations have never done it.
- Classify your AI systems against Annex III before somebody else does. Recruitment, credit, insurance, education, essential services and workplace management are the categories where the fundamental rights authorities already have jurisdiction. If anything you run falls there, the relevant regulator exists today.
- Read the regulator, not just the regulation. Where a market surveillance authority has been designated, look at what that institution did before AI. A cybersecurity agency, a telecoms regulator and a data protection authority will each open with the questions they already know how to ask.
- Build the evidence file once and reuse it. System inventory, purpose, data sources, human oversight arrangements, testing records, incident handling. The same pack answers a customer questionnaire, an Article 77 request and a market surveillance enquiry. Assembling it under time pressure costs several times more.
- Put a review date in the diary rather than a watching brief. Eighteen designations are outstanding and the position moves monthly. Someone should own checking it quarterly, because the day your market gets an active regulator is the day your exposure changes without anything in your business changing.
Three questions for the board
- In which EU member states do we place AI systems on the market, and can we name the supervisory authority in each, or confirm that one has not yet been designated?
- Does anything we operate fall within the Annex III high-risk categories, and if so, which existing fundamental rights regulators already have jurisdiction over it today?
- If a customer in Italy or Ireland asked us next month for evidence of how we govern the AI in our product, what could we send without starting a project?
The strategic takeaway
The gap between a law applying and a law being enforced is the most misread period in any regulatory cycle. It looks like slack and it behaves like debt. Obligations accrue, evidence that should have been generated contemporaneously is not, and the reckoning arrives when an institution with something to prove starts work on a backlog.
The firms that come out of this well will not be the ones that guessed the timetable correctly. They will be the ones that built the evidence file while it was cheap, because the same file answers a customer, a court and a regulator, and only one of those three is currently running late.
Confidence note
Confirmed. That the AI Act required member states to designate a market surveillance authority and a notifying authority by 2 August 2025, and that many did not. That as of 17 June 2026, the date of the most recent update to the Future of Life Institute's national implementation tracker, nine member states had designated both, twelve had partial clarity and six had designated neither. That all twenty-seven member states have designated their Article 77 fundamental rights authorities, for which the deadline was 2 November 2024, and that the Commission maintains a consolidated list. That enforcement powers of the AI Office and national competent authorities apply from 2 August 2026, that the AI Office supervises general purpose AI models centrally, and that penalties run to €35m or 7% of worldwide annual turnover for prohibited practices, €15m or 3% for high-risk breaches and €7.5m or 1% for supplying incorrect or misleading information. That Italy was the first member state to pass a national implementing law, designating its National Cybersecurity Agency as market surveillance authority and the Agency for Digital Italy as notifying authority. That Finland's law took effect on 1 January 2026 under a decentralised model with Traficom as single point of contact. That Ireland designated fifteen existing bodies. That Cyprus gave all three roles to the Commissioner of Communications. That Germany's draft naming the Bundesnetzagentur was adopted by the federal cabinet on 10 February 2026 and still requires passage through the Bundestag and Bundesrat.
Assessed. That newly designated authorities will enforce more assertively than established ones is our assessment based on the general pattern of regulatory start-up behaviour, not a documented position of any authority. The characterisation of institutional background as a predictor of enforcement focus is likewise our inference from the type of bodies chosen, and has not been tested by decisions, because there are not yet enough decisions to test it against.
Not known. The current designation count. Our figure is dated 17 June 2026 and the position moves as national legislation passes, so it is likely that more states have completed since. No public enforcement decision under the AI Act had been reported at the time of writing, so nothing here is drawn from actual regulatory practice. Whether the Commission will take infringement action against member states that have not designated, and on what timetable, is not known.
Can you name your supervisory authority in every EU market you sell into?
Garzon Cyber Solutions is built to put questions like this on the risk register with an owner, map the controls to what regulators, customers and insurers actually ask for, and place the people who keep the answer current. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Future of Life Institute, "Overview of all AI Act National Implementation Plans", last updated 17 June 2026 · European Commission, "The enforcement framework of the AI Act" · European Commission, consolidated list of Article 77 fundamental rights authorities · EU Artificial Intelligence Act, Article 99, Penalties · EU Artificial Intelligence Act, Article 70, Designation of national competent authorities · EU Artificial Intelligence Act, Article 77, Authorities protecting fundamental rights