An ambitious law is only as good as the institutions capable of enforcing it. This is the transition that the European AI Act is facing right now: turning a regulation debated worldwide into a concrete network of authorities, expertise, procedures, and supervisory powers. On 7 September, the European Commission updated its overview of the market surveillance authorities designated by the Member States.

The landscape is inevitably fragmented. In some countries, the task falls to communications authorities; in others, to consumer protection bodies, data protection authorities, or new institutions dedicated to artificial intelligence. At the European level, the AI Office retains specific responsibilities, particularly regarding general-purpose models and certain categories of systems.

The risk of twenty-seven speeds

The distributed structure allows existing national expertise to be leveraged, but it exposes a well-known issue in European regulation: interpretations, resources, and enforcement speeds may vary. For a company operating across the entire single market, predictability will depend on the authorities' ability to coordinate with one another.

This is where the AI Act will truly be put to the test. Legal definitions must translate into technical procedures; someone has to know how to request documentation, evaluate systems, challenge non-compliance, and ultimately defend their decision before a judge.

From legislation to administration

The debate around AI tends to focus on grand political declarations. Enforcement, however, will come down to specialised staff, budgets, standards, and cooperation. It is less visible, but likely far more important in determining whether the European model will actually work.

Sources