Member State Tracker · Updated 19 April 2026
EU AI Act Member State Implementation Tracker
The EU AI Act is a Regulation, directly applicable across all 27 Member States without transposition. But implementation still varies: every Member State must designate national competent authorities, establish market surveillance structures, and set up regulatory sandboxes. This tracker maps what each major Member State has done, and what it means for cross-border compliance.
At a glance, the six largest markets, April 2026
| Member State | National Law? | Authority Model | Status |
|---|---|---|---|
| 🇩🇪 Germany | KI-VO Durchführungsgesetz (Feb 2026) | Centralised, Bundesnetzagentur | Law passed; authority designated |
| 🇮🇪 Ireland | Statutory instrument route | Distributed, 15 competent authorities | Framework published |
| 🇫🇷 France | Under drafting | Hybrid, CNIL leads, sectoral cooperation | Framework in progress |
| 🇪🇸 Spain | AESIA established (2023) | Centralised, AESIA (first dedicated AI agency in EU) | Authority operational |
| 🇮🇹 Italy | DDL AI in parliamentary process | Dual, ACN (cybersecurity) + AgID (digital agency) | Authority split under discussion |
| 🇳🇱 Netherlands | Not separately legislating | Distributed, Autoriteit Persoonsgegevens leads | Authority designation pending formal confirmation |
🇩🇪 Germany, the centralised model
Germany passed the KI-VO Durchführungsgesetz (AI Regulation Implementation Act) on 11 February 2026, making it the first major Member State to enact dedicated national implementing legislation. The law centralises AI Act market surveillance in the Bundesnetzagentur (Federal Network Agency), the same body that handles telecoms and electricity regulation.
Key features of the German approach:
- Single point of contact, the Bundesnetzagentur is the designated market surveillance authority for AI systems, including high-risk AI. This simplifies enforcement for German-established providers compared to the distributed model.
- Sectoral regulators retain expertise, BaFin (financial supervision), BfArM (medical devices), KBA (vehicles) continue to handle AI in their regulated sectors with coordination obligations to the Bundesnetzagentur.
- Länder-level coordination, federal structure means state-level authorities (Datenschutzbehörden) coordinate on data protection aspects of AI.
- Notified body ecosystem, TÜV SÜD, TÜV Rheinland, DEKRA, and DIN CERTCO are the principal notified bodies expected to seek designation for AI Act conformity assessment.
What German buyers should know: The centralised Bundesnetzagentur model is attractive for compliance teams but creates capacity risk. One authority handling all non-sectoral AI systems for an economy of 84 million people will face significant queue times for proactive engagement. Proactive compliance and clean documentation will pay off disproportionately in Germany.
🇮🇪 Ireland, the distributed model
Ireland took the opposite path. Rather than designate a single market surveillance authority, Ireland designated 15 separate competent authorities, each responsible for the AI systems falling within their existing sector. The structure tracks the sectoral regulators Ireland already uses: the Data Protection Commissioner for data-intensive AI, the Central Bank for financial services AI, ComReg for communications, the HPRA for health products, and so on.
Key features of the Irish approach:
- Sectoral expertise preserved, each authority already has deep knowledge of its domain. An AI system used for medical triage is assessed by the HPRA, not a generalist AI authority.
- Coordination challenge, cross-sectoral AI systems may involve two or more authorities simultaneously.
- National Standards Authority of Ireland (NSAI), accreditation and standards body; will designate notified bodies.
- AI Advisory Council established, provides cross-government strategic advice; not a regulator.
What Irish-established providers should know: The distributed model means your first action is to identify which authority (or authorities) supervise your specific AI use case. A SaaS platform offering AI-assisted recruitment to customers in multiple sectors may interact with several authorities. Map this early.
🇫🇷 France, hybrid under construction
France has not yet enacted a dedicated implementing law as of April 2026. The working assumption is a hybrid model with the CNIL (Commission Nationale de l'Informatique et des Libertés) leading AI market surveillance, leveraging its GDPR expertise, with cooperation obligations to sectoral regulators (AMF for financial, ANSM for health products, Autorité des Télécoms / ARCEP for communications).
France has consistently pushed for a strong AI governance posture and is home to Mistral AI, which gives the French government direct exposure to GPAI provider economics. The Conseil d'État and the Autorité de la Concurrence have both issued relevant guidance.
Watch for: The Loi de finances 2026 may include implementing provisions. An AI-specific statute is possible but not confirmed.
🇪🇸 Spain, first mover on the dedicated AI agency model
Spain was the first EU Member State to establish a dedicated AI agency. The Agencia Española de Supervisión de Inteligencia Artificial (AESIA) was created by Royal Decree 729/2023 and is headquartered in A Coruña. AESIA is fully operational and has been issuing pre-AI-Act guidance since 2024.
Key features:
- Dedicated AI expertise, staff specifically recruited for AI oversight, not repurposed from telecom or data protection backgrounds.
- AEPD coordination, the Spanish data protection authority retains GDPR jurisdiction; AESIA handles AI-specific matters with inter-authority agreements.
- AI regulatory sandbox, Spain launched the EU's first AI regulatory sandbox under the AI Act framework in December 2023 (pre-dating full Act applicability).
- Active enforcement posture, AESIA has publicly signalled it will prioritise high-risk AI in employment and public services for early inspections post-August 2026.
🇮🇹 Italy, institutional question mark
Italy's implementation path has been politically contested. The government's Disegno di Legge (DDL) on AI is proceeding through parliamentary review. The current structure envisages a dual model with:
- Agenzia per la Cybersicurezza Nazionale (ACN), cybersecurity agency assuming a role in AI system oversight
- Agenzia per l'Italia Digitale (AgID), digital agency handling broader public-sector AI governance
- Data protection aspects remain with the Garante per la Protezione dei Dati Personali
This creates a three-way structure that industry stakeholders have criticised for coordination complexity. The final model may consolidate before implementation is complete.
🇳🇱 Netherlands, 🇸🇪 Sweden, 🇧🇪 Belgium, 🇩🇰 Denmark, the distributed majority
Most remaining Member States are following variants of the distributed model:
- Netherlands, Autoriteit Persoonsgegevens (AP) expected to take a leading coordinating role; sectoral authorities retain jurisdiction
- Sweden, Integritetsskyddsmyndigheten (IMY) coordinates with sectoral regulators
- Belgium, complex federal structure requires coordination between federal (BIPT, APD/GBA) and regional authorities
- Denmark, Datatilsynet coordinates; sectoral regulators (Finanstilsynet for finance, Lægemiddelstyrelsen for pharma) handle sector-specific AI
🇪🇺 What this means for cross-border compliance
For providers and deployers operating in multiple Member States, three principles apply:
1. Single compliance framework, multiple authorities
Your obligations under the AI Act are identical regardless of where you operate in the EU. You build one compliance programme. But you may interact with multiple national authorities, particularly for cross-border incident reporting under Article 73.
2. The "main establishment" rule under Article 3(46)
Your primary regulatory interlocutor is the market surveillance authority in your Member State of main establishment. For providers established outside the EU, this is the Member State where your authorised representative is established (Article 22).
3. GPAI goes directly to the AI Office
GPAI providers report to the European AI Office (within DG CONNECT) rather than national authorities. This is a notable exception to the Member State model.
Regulatory sandbox availability
Under Article 57, every Member State must establish at least one AI regulatory sandbox. Under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), the deadline moved from 2 August 2026 to 2 August 2027 (12-month deferral), and a new EU-level sandbox operated by the AI Office is also created. Early-mover sandboxes (in order of operational date):
- Spain, operational since December 2023 (piloted before full Act applicability)
- Germany, Federal and Länder-level sandboxes launching through 2026
- France, CNIL regulatory sandbox extended to cover AI use cases
- Norway (EEA), Norwegian Data Protection Authority sandbox active since 2020
Sandboxes offer a risk-managed way to deploy high-risk AI under regulatory supervision. For smaller providers, this can materially reduce compliance cost, but access is competitive and the programmes are small in scale.
Sources and verification
- Regulation (EU) 2024/1689, Article 70 (Member State obligation to designate competent authorities)
- German KI-VO Durchführungsgesetz, Bundestag drucksache, adopted 11 February 2026
- Irish Department of Enterprise, Trade and Employment, national framework publication, 2025
- AESIA (Agencia Española de Supervisión de Inteligencia Artificial), Royal Decree 729/2023
- European Commission, national competent authority registry (updated periodically)
- IAPP daily tracker on Member State implementation developments
This tracker is updated monthly. Next scheduled update: 19 May 2026, covering Q2 developments including the Digital Omnibus trilogue outcome and any new national law adoptions. Subscribe to the weekly newsletter for real-time updates between monthly editions.
One Compliance Programme, 27 Member States
Our Full Readiness Bundle includes the vendor questionnaire, Annex IV technical documentation checklist, and board briefing template, everything a cross-border compliance programme needs to deliver consistently across Member State authorities.