As of August 2, 2025, only 8 out of 27 Member States had designated their national authorities for the AI Act. This delay does not alleviate your obligations: the regulation applies directly to companies, regardless of national institutional readiness.
In brief
- The designation of competent national authorities, required by August 2, 2025, under Article 70, was not met by the majority of Member States.
- To date, only 8 out of 27 Member States have officially appointed their single point of contact to the European Commission, revealing a significant institutional delay.
- Company obligations remain unchanged: the AI Act applies directly, regardless of the level of preparation of national authorities.
- The absence of designated authorities leads to uneven enforcement and uncertainty regarding the distribution of audits and responsibilities across states.
- France (DGCCRF), Spain (AESIA), and Germany (Bundesnetzagentur) are among the few countries to have implemented their frameworks.
- This institutional delay reinforces the relevance of the Digital Omnibus, which proposes a postponement of obligations, highlighting the difficulty of enforcing the regulation without operational authorities.
August 2, 2025, marked the deadline imposed on every European Union Member State to appoint its competent national authorities responsible for enforcing the AI Act. This designation was to include a single point of contact, a market surveillance authority, and a notifying authority, with official communication to the European Commission. Yet, by this deadline, only 8 out of 27 Member States had fulfilled this obligation, revealing a significant gap between the regulatory text and the European institutional reality.
Article 70: Requirements for Member States
**Article 70 of Regulation (EU) 2024/1689** specifies that each Member State was required, by August 2, 2025, to:
- Appoint at least one **market surveillance authority** to monitor the compliance of AI systems within its territory;
- Designate a **notifying authority** responsible for accrediting certification bodies for high-risk systems;
- Communicate the identity of its **single point of contact** (SPOC) to the European Commission;
- Publish the contact details of these authorities in an accessible online format.
These entities are essential for ensuring the practical application of the AI Act: they will conduct audits, impose corrective measures, issue sanctions, and collaborate with the European AI Office. Without them, the regulatory framework lacks an effective national relay.
Member States: Where do we stand on authority designation?
Among the few Member States that met the deadline, several models stand out:
France
France has implemented a multi-authority coordination model. The **DGCCRF** (General Directorate for Competition, Consumer Affairs and Fraud Control) acts as the single point of contact. Other regulators intervene depending on the domain: the **CNIL** for data protection, **ANSSI** for cybersecurity, **ARCOM** for digital content, and the **HAS** for health. The **DGE** represents France within the European AI Board.
Germany
In Germany, the **Bundesnetzagentur** (Federal Network Agency) is responsible for market surveillance, while the **Deutsche Akkreditierungsstelle** is the notifying authority. The adoption of the **KI-MIG** bill in February 2026 marks a key milestone in national transposition.
Spain
Spain has chosen to create the **AESIA** (Spanish Agency for the Supervision of AI), which cooperates with the AEPD (data protection), the Bank of Spain, and the CNMV.
Ireland
Ireland has opted for a decentralized approach, designating fifteen authorities coordinated by the **National AI Office** since September 2025.
Despite these advances, the majority of Member States do not yet have an operational framework, creating institutional uncertainty less than five months before the set deadline.
Causes of the delay and the Digital Omnibus challenge
Several factors explain this widespread delay:
- **Lack of harmonized standards**: Without technical standards finalized by CEN-CENELEC, national authorities lack clear benchmarks to assess the compliance of high-risk systems.
- **Lack of specialized resources**: The required skills (AI, cybersecurity, data protection, law) are rare and difficult to mobilize quickly in the public sector.
- **Organizational complexity**: States with federal or highly decentralized structures struggle to determine whether to adapt an existing authority or create a new one.
This context reinforces the logic of the **Digital Omnibus**: how can the regulation be enforced if national authorities are not ready? This situation has notably motivated the proposal to postpone obligations regarding high-risk systems to December 2027.
> This delay is not a sign of weakness, but a recognition of the complexity of the AI Act. It is better to have a solid operational framework than to rush a partial or ineffective application.
Practical consequences for companies
Many companies are wondering: can the absence of operational national authorities justify delaying compliance?
The answer is clearly negative, for three main reasons:
1. The AI Act applies immediately and directly
Unlike directives that require transposition, the AI Act is directly applicable in all Member States. The absence of a designated national authority has no impact on the entry into force of your legal obligations.
2. The AI Office takes over in case of national deficiency
The **AI Office**, strengthened by the Digital Omnibus, has direct prerogatives for GPAI models and systems integrated into large platforms. It can conduct audits and take measures even in the absence of designated national authorities.
3. Your contractual and commercial obligations are already effective
Beyond the regulatory framework, your clients (especially large groups and public actors) require AI Act compliance in tenders and contracts. Non-compliance exposes you to immediate commercial risks, regardless of the institutional calendar.
Recommended actions in this transitional context
The institutional delay should not change your compliance strategy, but it offers an opportunity to better anticipate:
1. **Identify the competent authority for your sector**: If your state has appointed its authorities, determine which one will be in charge of your systems (in France: CNIL, HAS, ARCOM, DGCCRF depending on the domain).
2. **Build good-faith documentation**: In the event of an initial audit, being able to present an inventory of your AI systems, a risk analysis, and a dated compliance plan constitutes protection.
3. **Continue compliance without waiting**: The classification of your systems (Annex III), the documentation of human oversight measures, and the update of your legal notices (Article 50) are independent of the designation of authorities.
4. **Stay informed of national developments**: Designations are published as they occur. Regularly consult the compaia AI Act timeline to follow news on national authorities.
To structure your approach, the free compaia diagnostic allows you to classify your systems, identify your obligations, and start your documentation without waiting for the official designation of your national authority.
FAQ
If my Member State has not yet designated its authorities, can I be sanctioned?
In theory, yes: the AI Act applies directly in every Member State. However, initial audits will primarily be carried out where authorities are in place. But the absence of immediate control does not constitute a legal exemption: non-compliance remains sanctionable.
Who monitors GPAI models if national authorities are not ready?
The AI Office at the European level supervises GPAI models, pursuant to Articles 51 to 56. Since August 2025, it can investigate and sanction directly, regardless of the preparation of national authorities.
What is the competent authority for a French company?
In France, the DGCCRF is designated as the single point of contact. Depending on the sector, the CNIL (personal data), the HAS (health), the ARCOM (digital content), or the ACPR (finance) may be competent. ANSSI and PEReN support technical aspects.
Does the Member State delay justify postponing my operational compliance?
No. The AI Act is directly binding. The delay of national authorities may temporarily limit audits, but it does not reduce your legal exposure or your contractual obligations. Anticipation remains the best strategy.
Does the Digital Omnibus also suspend company obligations while waiting for authorities?
No. The Digital Omnibus proposes to postpone application deadlines, but not to wait for the establishment of national authorities. If the postponement is adopted, it will apply to everyone, regardless of the institutional progress. Consult the full AI Act regulation timeline to follow the evolution of the regulatory calendar.