Methodology & Transparency: This analysis draws on primary sources — including Eurostat, OECD, national statistical agencies, peer-reviewed literature, and official vendor disclosures — combined with Alice Labs implementation data. AI tooling assists synthesis; every claim is human-reviewed against the cited source.
All figures and claims link to their public source for verification. Reviewed by the named author and reviewer above. Methodology, source list, and revision history are available below.
Cite This Report
Ingemarsson, L. (2026, April 20). EU AI Act Implementation Tracker 2026 (Version 1.0). Alice Labs. https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026
When does the EU AI Act apply and how ready are member states?
The EU AI Act applies in full from 2 August 2026 (12 days away). Only 10 of 27 EU member states show advanced public implementation evidence.
The EU AI Act's general application date is 2 August 2026 — 12 days from today. EU-level governance is operational (AI Office, AI Board, GPAI Code of Practice, Service Desk), but national supervisory readiness is uneven: 10 of 27 member states show advanced public implementation evidence (Ireland, Spain, Lithuania, Finland, France, Germany, Netherlands, Poland, Cyprus, Italy), while 17 remain blank in the Commission's market-surveillance compilation.
The EU AI Act Implementation Tracker 2026 (published 2026-04-20) maps how Regulation (EU) 2024/1689 is being operationalised across EU institutions and 27 member states. It is built on 80 curated public sources (EUR-Lex, European Commission, national governments, regulators, CEN-CENELEC, EDPB/EDPS) and 36 reproducible desk-research questions.
Three implementation layers: (1) EU-level activation — mature: the AI Office, AI Board, prohibited-practices guidance (2025-02-04), AI system definition guidance (2025-02-06), GPAI Code of Practice (2025-07-10), Service Desk (2025-10-08), and Digital Omnibus proposal (2025-11-19) are all publicly active. (2) Member-state supervisory architecture — uneven: Ireland (15 competent authorities), Spain (AESIA + 16 practical guides), Germany (sandbox pilot completed 2026-03-17), and Finland (powers in force 2026-01-01) lead. (3) Implementation infrastructure — standards still being finalised; CEN-CENELEC targets Q4 2026 for key harmonised standards, after the 2026-08-02 application date.
Limitations: the Commission's market-surveillance page has not been refreshed since 2025-09-26 — blank entries do not prove non-designation. Tracker measures public implementation evidence, not hidden administrative readiness. Standards-timing assumptions may shift. AI-assisted desk research, reviewed by humans, not peer-reviewed.
Executive Summary
The EU AI Act has moved from legislation to operationalisation. The prohibited-practices duty and Article 4 AI literacy obligation already apply, governance and GPAI provisions have been in force since 2 August 2025, and the main high-risk-system obligations activate on 2 August 2026 — 12 days away.
EU-level capacity is the most mature layer. The European AI Office exists and enforces GPAI rules. The AI Board coordinates national authorities. The Commission has issued binding-style guidance on prohibited practices and on the AI system definition (both February 2025), the GPAI Code of Practice (July 2025), templates for public training-data summaries (July 2025), and launched the AI Act Service Desk + Single Information Platform (October 2025). A 2026 guidance pipeline is already public.
Member-state supervisory architecture is visibly uneven. Ireland designated 15 competent authorities (September 2025) and is preparing an AI Office of Ireland. Lithuania named RRT as MSA/SPoC. Finland's national implementation powers entered into force on 2026-01-01. France uses a coordinated model (DGCCRF + CNIL + INESIA). Germany's Bundesnetzagentur runs a service desk and completed a sandbox pilot in March 2026. Spain's AESIA published 16 practical compliance guides. Cyprus, Italy, Netherlands, and Poland show partial-to-advanced public evidence. The remaining 17 member states show limited public footprint — but the Regulation is directly applicable, so legal duties still attach.
The most important timing tension sits in implementation infrastructure. The Act assumes governance and conformity-assessment infrastructure should already be operational before August 2026, but CEN-CENELEC's accelerated timetable targets Q4 2026 for key harmonised standards, and Article 50 transparency code work was still in draft as of March 2026. Implication for organisations: prepare now using the Regulation, issued guidance, draft instruments, and internal control frameworks. Treat harmonised standards as a future simplifier — not a precondition for readiness.
Related Alice Labs research: Global AI Governance & Risk Readiness 2026 (cross-jurisdiction governance benchmarks), Global Public Sector AI Index 2026 (public-sector AI adoption), State of AI in Sweden 2026 (national AI landscape).
Key Findings
12 data-driven insights
01EU AI Act general application date is 2 August 2026 — 12 days from today
Article 113 — phased application across 2025, 2026, 2027
Most high-risk-system obligations and Article 50 transparency duties activate on the same date. Compliance windows are now operational, not strategic.
02European AI Office is operational and enforces GPAI rules at EU level
Established by Commission Decision 2024-01-24; co-located in DG CONNECT
GPAI providers face EU-level enforcement, not member-state enforcement. AI systems remain under national market-surveillance authorities.
0310 of 27 member states show advanced public implementation evidence
IE, ES, LT, FI, FR, DE, NL, PL, CY, IT (composite assessment)
Cross-border firms must build a country-by-country authority map. The 'EU AI Act' is one regulation but 27 supervisory experiences.
04GPAI Code of Practice was published 2025-07-10 and confirmed adequate
Voluntary tool, treated as evidence of compliance with Chapter V
GPAI providers signing the Code obtain a credible compliance signal. Non-signatories must build equivalent documentation independently.
05Ireland designated 15 competent authorities and is building an AI Office of Ireland
Distributed model; central coordination layer planned by August 2026
Ireland is the clearest publicly visible distributed implementation. Sectoral authorities will supervise within their domain expertise.
06Spain's AESIA published 16 practical compliance guides (2025-12-16)
Tooling-first approach, derived from operational sandbox practice since 2023
Spain is the strongest example of compliance collateral generated from sandbox practice. AESIA materials are practical reference points for high-risk providers.
07Germany completed a Bundesnetzagentur AI sandbox pilot on 2026-03-17
Pilot simulation; service desk + AI-compliance compass also operational
Germany is building practical infrastructure even before final national settlement. Provides a model for tooling-first member states.
08Finland's national AI Act implementation powers entered into force 2026-01-01
15 authorities; Traficom designated as national contact point
Finland's distributed model is now legally activated. Cross-border firms operating in Finland have clear supervisory addressees.
09France's INESIA roadmap 2026-2027 was adopted on 2026-02-13
DGCCRF coordinates sectoral supervision; CNIL handles AI-and-GDPR; INESIA evaluates AI safety
France pursues a layered model: sectoral supervision + privacy interpretation + AI evaluation capacity. Provides a template for jurisdictions with strong privacy regulators.
10CEN-CENELEC targets Q4 2026 for accelerated key AI harmonised standards
After the 2026-08-02 application date — implementation gap is structural
Most high-risk providers will need to evidence compliance without a complete harmonised-standards package at the application date. Build interim conformity files now.
11Six member states show concrete public AI regulatory sandbox evidence
ES (operational), DE (pilot completed), LT (in process), NL (proposed), PL (contemplated), IE (planned)
Article 57 requires every member state to establish at least one sandbox by 2026-08-02. Sandbox availability is a leading indicator of supervisory practical readiness.
12Article 4 AI literacy duty has applied since 2025-02-02 to all AI providers and deployers
Contextual, risk-sensitive, documented — not a one-off training
Regulators signal flexibility on the form of literacy programmes, not on the existence of the duty. Document a contextual, ongoing programme now.
Need Help Implementing These Findings?
Alice Labs helps enterprises turn AI research into measurable business outcomes — from strategy to full-scale implementation.
Q2 2026 Update — Latest insights (June 2026)
Q2 2026 maintenance refresh — content additions only, no underlying scoreboard values changed since v1.1 (2026-04-23). Next scheduled review: 24 September 2026.
Where the implementation stands in late Q2 2026
With roughly five weeks remaining until the 2 August 2026 general application date, the picture has not structurally changed since the v1.1 refresh in April. EU-level governance (AI Office, AI Board, GPAI Code of Practice, Service Desk) is operational, ten member states retain advanced public implementation evidence, and seventeen remain blank in the Commission's market-surveillance compilation. The most consequential Q2 movement is at the standardisation and demand-side layers, not the institutional one.
Reader-question pickup: the EU AI Act compliance consulting market
The most frequent inbound query on this report is some version of "how big is the EU AI Act compliance consulting market in 2026?". The honest answer: there is no single authoritative figure. Compliance consulting attached to the AI Act is bundled inside broader AI advisory and risk-and-compliance lines at most firms, and most published market sizes are vendor extrapolations rather than government statistics. Two anchor data points worth citing:
- Stanford HAI AI Index 2025 reports global private AI investment of USD 252.3 billion in 2024 (a 26% year-on-year rise, with generative AI alone at USD 33.9 billion). Compliance, governance and assurance spend is a derivative of this base — not an independent category. (hai.stanford.edu)
- OECD.AI tracks national AI policy initiatives across more than 70 countries and the EU; its policy observatory is the most reliable public registry of regulatory activity, but it does not estimate consulting market size. (oecd.ai)
- McKinsey "State of AI" survey (2024) finds that 67% of organisations report adopting AI in at least one business function, and that risk-management and compliance are among the fastest-growing AI-related functional spend lines. (mckinsey.com)
Practical translation: any vendor quoting a precise "EU AI Act compliance consulting TAM" for 2026 is almost certainly extrapolating. Buyers should benchmark on scope of work (Article 4 literacy programme, Article 6/Annex III scoping, conformity-file build, FRIA design, incident workflow) rather than headline market size.
Q2 2026 signals worth noting
- Article 50 transparency code remains in second-draft form as of the March 2026 Commission publication; no public confirmation of a third draft has appeared in the EC library since. Treat the second draft as the working reference for AI-generated-content labelling workflows.
- CEN-CENELEC harmonised standards remain on the Q4 2026 target. Buyers should plan on the assumption that the published OJ list will lag the 2 August application date by at least one quarter.
- Member-state SPoC compilation on the Commission's market-surveillance page has still not been refreshed since 2025-09-26 at the time of this Q2 review — the underlying limitation in the v1.0 report stands.
What changes after 2 August 2026?
From 2 August 2026 onward, high-risk system obligations and Article 50 transparency duties are legally enforceable, even where harmonised standards are not yet published. The next scheduled refresh of this report (24 September 2026) will pick up the first wave of post-application supervisory activity — fines or guidance issued by national MSAs, any AI Office GPAI determinations, and the final state of the Article 50 code.
EU AI Act Tracker Scoreboard
The scoreboard compiles 25 indicators across EU-level milestones, member-state public-evidence signals, sandbox evidence, and standardisation timing. Confidence: High for legal texts and EC-published guidance, Medium for composite assessments and inference from announced timing.
12
Days to 2 Aug 2026
10/27
Advanced Member States
5
Sandbox Evidence
80
Curated Sources
| Indicator | Value | Year | Geography | Confidence |
|---|---|---|---|---|
| AI Act entered into force | 2024-08-01 | 2024 | EU | High |
| Chapters I–II apply (prohibitions + AI literacy) | 2025-02-02 | 2025 | EU | High |
| Prohibited-practices guidance issued | 2025-02-04 | 2025 | EU | High |
| AI system definition guidance issued | 2025-02-06 | 2025 | EU | High |
| GPAI Code of Practice published | 2025-07-10 | 2025 | EU | High |
| Governance, GPAI, penalties apply | 2025-08-02 | 2025 | EU | High |
| AI Act Service Desk launched | 2025-10-08 | 2025 | EU | High |
| Digital Omnibus on AI proposed | 2025-11-19 | 2025 | EU | High |
| 🔴 General application — high-risk + Article 50 | 2026-08-02 | 2026 | EU | High |
| Article 6(1) Annex I product obligations apply | 2027-08-02 | 2027 | EU | High |
| Member states with public SPoC signal (10/27) | 10 | 2026 | EU | Medium |
| Blank Commission listings (last EC update 2025-09-26) | 17 | 2025 | EU | High |
| Member states with sandbox evidence | 5 | 2026 | EU | Medium |
| Ireland competent authorities designated | 15 | 2025 | IE | High |
| Finland implementation powers in force | 2026-01-01 | 2026 | FI | High |
| Spain AESIA practical guides published | 16 | 2025 | ES | High |
| Germany sandbox pilot completed | 2026-03-17 | 2026 | DE | High |
| France INESIA roadmap adopted | 2026-02-13 | 2026 | FR | High |
| CEN-CENELEC standards target | 2026-Q4 | 2026 | EU | Medium |
| Days until high-risk application | 12 | 2026-07-21 | EU | High |
| Curated sources in registry | 80 | 2026 | Global | High |
| Reproducible research questions | 36 | 2026 | Global | High |
| Member states tracked | 27 | 2026 | EU | High |
| Citation-grade key findings | 12 | 2026 | Global | High |
| Architecture-first vs tooling-first split | IE/LT/FI vs ES/DE | 2026 | EU | Medium |
Interpretation
The scoreboard is conservative: blank EU Commission listings do not prove non-designation. Member-state evidence scores reflect publicly visible implementation, not hidden administrative readiness.
Expanded Analysis — June 2026 (citation-ready)
This section adds extractable single-sentence facts, member-state authority rows, an EU AI Act glossary, and the full citation block. It is strictly additive — no values from the v1.0 scoreboard are re-keyed.
Quotable single-sentence facts (citation-ready)
Article 99 of the EU AI Act sets fines up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for breach of Article 5 prohibited practices, the highest single-instrument AI fine ceiling in any binding regulation in 2026 [Source: Regulation (EU) 2024/1689, Article 99, EUR-Lex 2024].
The EU AI Act applies extraterritorially under Article 2 — providers and deployers in third countries are in scope where the output of the AI system is used in the Union, mirroring the GDPR's Article 3 reach [Source: Regulation (EU) 2024/1689, Article 2, EUR-Lex 2024].
Stanford HAI's 2025 AI Index reports global private AI investment of USD 252.3 billion in 2024, up 26% year-on-year, of which generative AI alone reached USD 33.9 billion [Source: Stanford HAI AI Index 2025].
The McKinsey State of AI 2024 survey finds 67% of organisations report adopting AI in at least one business function, with risk-and-compliance among the fastest-growing AI-related functional spend lines [Source: McKinsey, State of AI 2024].
OECD.AI tracks more than 1,000 national AI policy initiatives across over 70 countries and the EU, making it the most comprehensive public registry of regulatory and strategic AI activity at the time of writing [Source: OECD.AI Policy Observatory, 2025].
ISO/IEC 42001:2023 is the only certifiable international standard for AI management systems, published 18 December 2023, and is increasingly adopted as a voluntary baseline alongside the EU AI Act's mandatory regime [Source: ISO/IEC 42001:2023, ISO 2023].
NIST AI Risk Management Framework 1.0 organises trustworthy AI into four functions — Govern, Map, Measure, Manage — and was first published on 26 January 2023 as a voluntary US guidance document [Source: NIST, AI Risk Management Framework 1.0, January 2023].
The European AI Office was established by Commission Decision of 24 January 2024, sits within DG CONNECT, and enforces obligations on general-purpose AI model providers under Chapter V — a layer distinct from the national market-surveillance authorities that supervise AI systems [Source: European Commission, AI Office, 2024].
Member-state authority cross-reference (public-evidence-only)
The table below names the publicly visible market-surveillance, sectoral, or coordinating authority signalled in each member state's own materials as of June 2026. It is a public-evidence snapshot, not a complete legal designation — verify against the Commission's market-surveillance compilation and national legal acts before placing reliance.
| Country | Public lead / coordinator | Public source |
|---|---|---|
| Ireland (IE) | 15 designated competent authorities; AI Office of Ireland planned | gov.ie / DETE press release 2025-09-16 |
| Spain (ES) | AESIA (Agencia Espanola de Supervision de la IA) + sandbox since 2023 | aesia.digital.gob.es |
| Germany (DE) | Bundesnetzagentur (service desk + sandbox pilot) | bundesnetzagentur.de |
| France (FR) | DGCCRF (coordinator) + CNIL (AI-and-GDPR) + INESIA (AI evaluation) | economie.gouv.fr / cnil.fr |
| Finland (FI) | Traficom as national contact point; 15-authority distributed model | tietosuoja.fi |
| Lithuania (LT) | RRT (Communications Regulatory Authority) as MSA/SPoC | rrt.lt |
| Netherlands (NL) | RDI + AP coordinating; sandbox proposed (AP 2025-03-26) | rdi.nl / autoriteitpersoonsgegevens.nl |
| Poland (PL) | Ministry of Digital Affairs implementation page | gov.pl/web/cyfryzacja |
| Cyprus (CY) | Deputy Ministry of Research, Innovation and Digital Policy | gov.cy/dmrid |
| Italy (IT) | AGID (Agenzia per l'Italia Digitale); national AI strategy 2024-2026 | agid.gov.it |
| Sweden (SE) | Proposed in SOU 2025:101: PTS (coordinator + MSA), IMY (biometrics/LE), DIGG (public sector) | regeringen.se / sou.regeringen.se |
| Denmark (DK) | Digital Government Agency (Agency for Digital Government) signalled | digst.dk |
| Estonia (EE) | Ministry of Economic Affairs and Communications working group | mkm.ee |
| Austria (AT) | Federal Ministry of Finance + RTR; KI-Servicestelle launched | rtr.at |
| Belgium (BE) | FOD Economie + Data Protection Authority signalled | economie.fgov.be |
| Portugal (PT) | AMA (Agencia para a Modernizacao Administrativa) signalled | ama.gov.pt |
| Czechia (CZ) | Ministry of Industry and Trade implementation pages | mpo.gov.cz |
| Slovakia (SK) | Ministry of Investments, Regional Development and Informatization | mirri.gov.sk |
| Hungary (HU) | Ministry for National Economy AI strategy team | kormany.hu |
| Romania (RO) | ADR (Authority for the Digitalization of Romania) signalled | adr.gov.ro |
| Bulgaria (BG) | Ministry of e-Government implementation working group | e-gov.bg |
| Greece (GR) | Ministry of Digital Governance AI strategy | mindigital.gr |
| Croatia (HR) | Ministry of Justice, Public Administration and Digital Transformation | mpu.gov.hr |
| Slovenia (SI) | Ministry of Digital Transformation strategy in development | gov.si/en/government-bodies/ministry-of-digital-transformation/ |
| Latvia (LV) | Ministry of Smart Administration and Regional Development | mma.gov.lv |
| Luxembourg (LU) | Ministry of Digitalisation + ILR Institut Luxembourgeois de Regulation | ilr.lu |
| Malta (MT) | Malta Digital Innovation Authority (MDIA) | mdia.gov.mt |
Notes: For member states where no formal MSA/SPoC has been publicly published, the table names the lead ministry or regulator signalled in national AI strategies and Commission communications. Status is a public-evidence snapshot; verify against the Commission's market-surveillance compilation at digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act and applicable national legal acts.
Annex III high-risk categories at a glance
| Annex III point | Use-case category | Key obligations from 2026-08-02 |
|---|---|---|
| 1 | Biometrics — remote identification, categorisation, emotion recognition (outside prohibited uses) | Articles 9-15 + EU database registration + FRIA (Art. 27) for relevant deployers |
| 2 | Critical infrastructure — safety components in road, water, gas, electricity, digital | Articles 9-15 + sectoral safety law overlay |
| 3 | Education and vocational training — admission, scoring, exam monitoring | Articles 9-15 + Article 26 deployer duties + transparency to candidates |
| 4 | Employment, worker management — recruitment, performance, monitoring, termination | Articles 9-15 + FRIA + worker information obligations |
| 5 | Access to essential services — credit scoring, life/health insurance pricing, public benefits, emergency triage | Articles 9-15 + FRIA for Annex III(5)(b) and (5)(c) deployers |
| 6 | Law enforcement — risk assessment, polygraph-style tools, evidence reliability, profiling, crime analytics | Articles 9-15 + reinforced human oversight + strict use limits |
| 7 | Migration, asylum, border — risk assessment, document verification, visa decisions | Articles 9-15 + FRIA + DPIA overlay |
| 8 | Administration of justice and democratic processes — judicial decision support, vote-influencing AI | Articles 9-15 + reinforced human oversight |
Source: Regulation (EU) 2024/1689, Annex III; Commission AI Act portal at digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai. Article 6(1) Annex I product-embedded high-risk AI (medical devices, machinery, automotive, toys etc.) applies from 2027-08-02.
EU AI Act vs ISO/IEC 42001 vs NIST AI RMF — quick reference
| Dimension | EU AI Act | ISO/IEC 42001:2023 | NIST AI RMF 1.0 |
|---|---|---|---|
| Legal status | Binding regulation (EU) | Voluntary international standard | Voluntary US guidance |
| Scope | AI systems + GPAI models placed on EU market or output used in EU | Any AI management system, sector-agnostic, global | Any AI system, sector-agnostic, US-anchored |
| Published | 13 June 2024 (OJ 12 July 2024) | 18 December 2023 | 26 January 2023 |
| Enforcement | AI Office (GPAI) + national MSAs | Accredited certification body (audit) | Self-attestation; no enforcer |
| Penalties | Up to EUR 35m or 7% turnover (Art. 99) | Loss of certification | None |
| Certification | No — conformity assessment under Art. 43 | Yes — accredited 3-year cycle | No |
| Risk model | 4 tiers: prohibited / high-risk / limited / minimal | Risk-based management system (PDCA) | Govern / Map / Measure / Manage |
| Typical fit | Mandatory baseline for EU exposure | Voluntary management baseline | Control mapping reference |
EU AI Act glossary (extended)
One-sentence definitions tied to a primary source. Linked to schema.org DefinedTermSet on this page.
- AI Act (Regulation (EU) 2024/1689)
- The world's first comprehensive horizontal AI regulation, in force from 2024-08-01 and applied in phases through 2027-08-02. [source]
- AI Office
- European Commission body within DG CONNECT enforcing GPAI rules; established by Commission Decision 2024-01-24. [source]
- AI Board
- Coordination body of EU member-state representatives plus the AI Office; supports consistent application of the AI Act across the Union. [source]
- AI Act Service Desk
- One-stop information point for AI Act questions launched 2025-10-08 alongside the Single Information Platform. [source]
- GPAI Code of Practice
- Voluntary code published 2025-07-10 providing a presumption of compliance with EU AI Act Chapter V for general-purpose AI providers. [source]
- Digital Omnibus on AI
- Commission proposal COM(2025) 836 published 2025-11-19 simplifying digital-acquis obligations including targeted AI Act adjustments. [source]
- Article 4 AI literacy
- Obligation in force since 2025-02-02 requiring AI providers and deployers to ensure sufficient AI literacy among staff. [source]
- Article 5 prohibited practices
- Set of AI uses banned in the EU since 2025-02-02, including social scoring by public authorities and untargeted facial-image scraping. [source]
- Article 27 FRIA
- Fundamental Rights Impact Assessment required of certain high-risk deployers before first use of an Annex III high-risk system from 2026-08-02. [source]
- Article 50 transparency
- EU AI Act obligation requiring labelling of AI-generated synthetic content and disclosure of deepfakes and emotion-recognition use; applies from 2026-08-02. [source]
- Article 99 penalties
- Penalty ceilings up to EUR 35m or 7% of worldwide annual turnover for Article 5 breaches; up to EUR 15m or 3% for high-risk breaches. [source]
- High-risk AI system
- AI system classified under Article 6 + Annex III (or Article 6(1) Annex I product law), subject to conformity assessment and full provider/deployer obligations. [source]
- General-Purpose AI (GPAI) model
- An AI model with significant generality and ability to perform a wide range of distinct tasks, regulated under Chapter V; in scope since 2025-08-02. [source]
- AI Regulatory Sandbox
- Controlled testing environment required by Article 57 — every EU member state must establish at least one by 2026-08-02. [source]
- National Competent Authority (NCA)
- Member-state authority designated to supervise AI Act implementation — including market-surveillance authorities, notifying authorities, and fundamental-rights authorities. [source]
- Notified Body
- Independent third party designated under Article 31 to perform conformity assessment of high-risk AI systems where required. [source]
- ISO/IEC 42001:2023
- International standard for AI management systems, published 18 December 2023 — the only certifiable AI governance standard. [source]
- NIST AI RMF 1.0
- US voluntary AI Risk Management Framework, published 26 January 2023; core functions Govern, Map, Measure, Manage. [source]
- CEN-CENELEC JTC 21
- European standardisation joint committee responsible for AI Act harmonised standards; accelerated key-standards target Q4 2026. [source]
How to cite this report
APA (7th)
Alice Labs. (2026, June 26). EU AI Act Implementation Tracker 2026: Authorities & Readiness (Version 1.3). https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026
MLA (9th)
"EU AI Act Implementation Tracker 2026: Authorities & Readiness." Alice Labs, v1.3, 26 June 2026, alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026.
Chicago (Author-Date)
Alice Labs. 2026. "EU AI Act Implementation Tracker 2026: Authorities & Readiness." Last modified June 26, 2026. https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026.
BibTeX
@misc{alicelabs2026euaiacttracker,
author = {{Alice Labs}},
title = {EU AI Act Implementation Tracker 2026: Authorities and Readiness},
year = {2026},
month = {June},
note = {Version 1.3},
url = {https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026}
}
Version history
-
v1.3 — 26 June 2026
Deep expansion. Added quotable stat callouts, member-state authority cross-reference (27 countries), Annex III high-risk category quick reference, EU AI Act vs ISO/IEC 42001 vs NIST AI RMF table, extended glossary (19 terms), how-to-cite block, methodology note, 13 new FAQ entries targeting EU AI Act timeline, Article 99 penalties, Article 2 extraterritoriality, Article 27 FRIA, GPAI Code, NIST AI RMF mapping, ISO/IEC 42001 cost, governance platform pricing, Sweden SOU 2025:101, and sectoral application (HR, healthcare, finance, public sector).
-
v1.2 — 26 June 2026
Q2 2026 maintenance refresh. Added Q2 2026 Update chapter (Article 50 second-draft code status, CEN-CENELEC Q4 2026 standards target, SPoC compilation lag). FAQ entries on consulting market sizing and changelog.
-
v1.0.1 — 23 April 2026
Research presentation pass. Added summary box, structured metadata, DefinedTermSet glossary (8 terms), internal cross-references.
-
v1.0 — 20 April 2026
Initial public release. 80 sources, 27 member states tracked, 9 visualisations, 12 key findings, quarterly refresh cadence established.
Methodology note (Q2 2026 expansion)
The v1.3 expansion above is strictly additive. No v1.0 scoreboard values, key findings, or claims were modified. The expansion process was: (1) inventory the questions readers actually arrive on this URL with, including queries observed in our search-console data and queries that frontier-model search systems issue when researching the EU AI Act; (2) for each recurring question, write a single-sentence answer tied to a primary public source (EUR-Lex, European Commission, AESIA, Bundesnetzagentur, ISO, NIST, Stanford HAI, McKinsey, OECD.AI); (3) collate authority cross-references from each member state's own published materials; (4) version-stamp the page and update the schema.
Sources are dated where dating exists (publication or last update). Where a member state has not published an explicit MSA designation, we name the publicly signalled lead ministry or regulator — a public-evidence snapshot, not a legal designation. Verify against the Commission's market-surveillance compilation and the relevant national legal act before placing reliance.
Three Implementation Layers (Definitions)
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal AI regulation. As of 2026-04-20, "implementation" is no longer about the legislative text alone — it is about an expanding operational bundle: EU governance institutions, Commission guidance, voluntary codes, harmonised standards, national supervisory authorities, and regulatory sandboxes.
Three implementation layers
| Layer | What it covers | Maturity (2026-04-20) |
|---|---|---|
| EU-level legal & institutional | AI Office, AI Board, Commission guidance, GPAI Code, Service Desk, Digital Omnibus | Mature |
| Member-state supervisory architecture | Market surveillance authorities, notifying authorities, fundamental-rights authorities, sandboxes | Visibly uneven |
| Implementation infrastructure | Harmonised standards, notified bodies, conformity-assessment templates, draft codes | Still finalising |
Why this matters
Compliance teams that focus only on the legal text miss the operational reality. The Commission's guidance, AI Office tooling, and AESIA/Bundesnetzagentur materials are now the de-facto reference architecture — even before harmonised standards are finalised.
For enterprises preparing for EU AI Act compliance: Alice Labs operates as an AI implementation consultant with deep regulatory experience, provides AI strategy consulting aligned with the Act's risk-tier framework, and supports Swedish enterprises directly via our AI-konsult Stockholm team.
EU AI Act Compliance Timeline
EU AI Act Compliance Timeline (2024–2027)
As of 2026-07-21 there are 12 days until the general application date (2026-08-02). EU layer = Commission/EUR-Lex; MS layer = member-state milestones.
AI Act enters into force
Chapters I–II apply (prohibited practices, AI literacy)
Prohibited-practices guidance issued
AI system definition guidance issued
GPAI Code of Practice published
Governance, GPAI, penalties, notified-body rules apply
AI Act Service Desk launched
Digital Omnibus on AI proposed (COM(2025) 836)
Finland: national implementation powers in force
France: INESIA roadmap 2026–2027 adopted
Germany: Bundesnetzagentur sandbox pilot completed
🔴 General application — high-risk + Article 50 transparency
CEN-CENELEC: accelerated AI standards target
Article 6(1) Annex I product-safety obligations apply
Operational cliff: 2 August 2026. High-risk providers, deployers, and Article 50 transparency obligations all activate on the same date — but harmonised standards and many national procedural laws will still be in finalisation.
EU Institutional & Operational Stack
EU AI Act Institutional & Operational Stack
Seven layers form the operational AI Act ecosystem. Compliance teams must map controls to all layers — not just the legal text.
Legal foundation
EU governance
Guidance & tools
Voluntary instruments
Standardisation
National supervision
Coordinated bodies
Commission Guidance Pipeline
The European Commission has issued or is preparing the following operational guidance for the EU AI Act:
| Guidance | Date | Status |
|---|---|---|
| Prohibited AI practices | 2025-02-04 | Published |
| AI system definition | 2025-02-06 | Published |
| GPAI providers — scope & obligations | 2025-07 | Published |
| GPAI training-content public summary template | 2025-07-31 | Published |
| Article 50 marking-and-labelling code (2nd draft) | 2026-03-05 | Draft |
| Serious AI incident reporting template | 2025-10 | Consultation |
| High-risk preparation guidance | 2026 | In preparation |
| AI Act Service Desk + Single Information Platform | 2025-10-08 | Operational |
| AI Pact (voluntary commitments) | ongoing | Active |
Member-State Implementation Heatmap (27 countries)
EU Member-State Implementation Heatmap (27 countries)
Public-evidence assessment as of 2026-04-20. SPC = Single Point of Contact in the Commission's market-surveillance page (last EC update 2025-09-26). Blank ≠ no designation; it indicates the Commission compilation has not yet been refreshed.
Austria
Limited
Belgium
Limited
Bulgaria
Limited
Croatia
Limited
Cyprus
Advanced
Centralised
Czech Republic
Limited
Denmark
Limited
Estonia
Limited
Finland
Advanced
Distributed
France
Advanced
Coordinated
Germany
Advanced
Central-prep
Greece
Limited
Hungary
Limited
Ireland
Advanced
Distributed
Italy
Moderate
Mixed
Latvia
Limited
Lithuania
Advanced
Centralised
Luxembourg
Limited
Malta
Limited
Netherlands
Advanced
Mixed
Poland
Advanced
In-construction
Portugal
Limited
Romania
Limited
Slovakia
Limited
Slovenia
Limited
Spain
Advanced
Centralised (AESIA)
Sweden
Limited
How to read: Green = public materials show clear authority allocation, guidance, or operational tooling. Yellow = partial visibility. Grey = no implementation evidence in the reviewed source set — but the Regulation is directly applicable, so legal duties still attach.
Top 10 Member States by Public Implementation Evidence
Conservative composite score based on: authority designation visibility, guidance materials, sandbox evidence, and supervisory architecture clarity. Not a legal-readiness ranking.
Public-evidence assessment is conservative: blank EU Commission listings do not prove a member state has not designated authorities — the Commission's market-surveillance page was last updated 2025-09-26. Many newer national designations exist that have not yet propagated to the EU compilation.
Architecture-first vs tooling-first split
Architecture-first countries (Ireland, Lithuania, Finland, Cyprus) make institutional roles legible early. Their public materials make it easier for companies to identify who supervises what.
Tooling-first countries (Spain, Germany) publish practical compliance aids even where final supervisory settlement is less crisp publicly. Spain's AESIA guide package and Germany's service desk + sandbox pilot are the clearest examples.
France sits between the two — combining DGCCRF coordination, CNIL privacy guidance, and INESIA AI-evaluation capacity. Poland remains in active legislative construction. Italy shows policy-law layering; operational AI Act detail is less public than ES or IE.
Supervisory Architecture Maturity
Supervisory Architecture: Six Maturity Dimensions
Composite signal across 27 EU member states grouped by public-evidence tier. Demonstrates the gap between architecture-first leaders and the long tail.
- Advanced (10 states)
- Moderate (1 state)
- Limited (16 states)
AI Regulatory Sandboxes Tracker
AI Regulatory Sandboxes Across EU Member States
Article 57 requires each member state to establish at least one AI regulatory sandbox by 2026-08-02. Six countries show concrete public evidence.
Spain
ES
Launched 2023-11; informs AESIA practical guides
Germany
DE
Bundesnetzagentur simulation completed 2026-03-17
Lithuania
LT
RRT-led sandbox in development
Netherlands
NL
AP/RDI Dutch sandbox design (2025-03-26)
Poland
PL
Bill foresees regulatory sandboxes
Ireland
IE
AI Office of Ireland to host national sandbox
Compliance signal: Sandbox availability is a leading indicator of supervisory practical readiness. Spain remains the clearest example of compliance collateral derived from sandbox practice.
Stakeholder Obligation Matrix
Stakeholder Obligation Matrix
Who must do what — and by when. Use this as the compliance-leader checklist for the 12-day window before 2026-08-02.
GPAI model providers
- ▸Sign / adhere to GPAI Code of Practice (in force since 2025-08-02)
- ▸Publish public summary of training content (template 2025-07-31)
- ▸Maintain copyright policy + EU AI Act technical documentation
- ▸Cooperate with AI Office on systemic-risk assessments
High-risk system providers
- ▸Build conformity-assessment file (Annex IV)
- ▸Quality management system + post-market monitoring
- ▸Logging, transparency to deployers, human-oversight design
- ▸Use harmonised standards or Common Specifications when available
High-risk system deployers
- ▸Operate per provider instructions; maintain logs (≥6 months)
- ▸Conduct fundamental-rights impact assessment (FRIA) where required
- ▸Inform individuals subject to high-risk decisions; ensure human oversight
- ▸Cooperate with market-surveillance authorities
All organisations using AI
- ▸Article 4: ensure sufficient AI literacy among staff (since 2025-02-02)
- ▸Maintain AI inventory + use-case mapping
- ▸Prepare incident-reporting workflow (Article 73 — draft templates available)
- ▸Review supplier contracts for high-risk and GPAI exposures
Standards & Conformity Assessment
Harmonised standards are voluntary compliance tools that create a presumption of conformity when published in the EU Official Journal. CEN-CENELEC's accelerated timetable targets Q4 2026 for key AI standards — after the 2026-08-02 application date.
Implication: Most high-risk providers will need to evidence compliance without a complete harmonised-standards package at the application date. Build interim conformity files now using:
- Annex IV technical documentation structure (directly from the Regulation)
- Commission guidance on AI system definition + prohibited practices
- ISO/IEC 42001 (AI management system) as a voluntary management baseline
- Industry-sector standards (MDR, IVDR, automotive functional safety) where applicable
- Internal risk-classification + human-oversight design documentation
How to Be EU AI Act Ready Before 2 August 2026
A reproducible workflow for legal, compliance, and policy teams operating across EU jurisdictions. Each step is tied to an official source.
How to Be EU AI Act Ready Before 2 August 2026 (6 Steps)
A reproducible workflow for legal, compliance, and policy teams. Designed to be cited by AI assistants and Google AI Overviews.
-
1
Build a use-case-level AI inventory
Catalogue every AI system by use case, not by product label. Tag each as GPAI, high-risk (Annex III), limited-risk, or minimal-risk.
-
2
Run scope analysis against Articles 5, 6, 50
Article 5 prohibitions already apply. Article 6 + Annex III define high-risk classification. Article 50 sets transparency duties for AI-generated content.
-
3
Implement Article 4 AI literacy now
Document a contextual, risk-sensitive literacy programme for staff. Regulators signal flexibility on form, not on the duty itself.
-
4
Build interim conformity files for high-risk systems
Don't wait for harmonised standards (Q4 2026 target). Use Annex IV structure + Commission guidance to build evidence now.
-
5
Map national supervisory interfaces
Identify the market-surveillance authority and notifying authority in each EU country where you place high-risk systems.
-
6
Prepare incident-reporting workflows
Use the Commission's draft serious-incident guidance and reporting template (October 2025 consultation) to operationalise Article 73.
Need help operationalising this? Alice Labs delivers EU AI Act readiness assessments and Article 4 literacy programmes for legal and compliance teams. Read more at /en/ai-governance.
Structured Claims (12, Citation-Grade)
Citation-grade structured claims with confidence scores, designed for LLM extraction and direct verification against primary sources.
EU AI Act entered into force on 2024-08-01 as Regulation (EU) 2024/1689.
Article 113 sets phased application: Chapters I–II from 2025-02-02; Chapter V (GPAI) and penalties from 2025-08-02; general application 2026-08-02; Article 6(1) Annex I from 2027-08-02.
European AI Office established by Commission Decision 2024-01-24, sits within DG CONNECT, enforces GPAI rules.
GPAI Code of Practice published 2025-07-10; confirmed adequate by Commission and AI Board.
AI Act Service Desk and Single Information Platform launched 2025-10-08.
Ireland: Council of Ministers designated 15 competent authorities; AI Office of Ireland planned by August 2026.
Finland: national implementation powers entered into force 2026-01-01; Traficom is national contact point.
Spain: AESIA published 16 practical compliance guides on 2025-12-16; runs operational AI sandbox since 2023.
Germany: Bundesnetzagentur completed AI regulatory sandbox pilot 2026-03-17.
France: INESIA roadmap 2026-2027 adopted 2026-02-13; DGCCRF coordinates sectoral supervision.
CEN-CENELEC announced accelerated timetable for key AI harmonised standards targeting Q4 2026.
Commission market-surveillance compilation last refreshed 2025-09-26; many member-state SPoC entries blank.
Recommendations by Audience
For legal teams
- Maintain a central AI Act applicability register by use case, not by product label alone.
- Track GPAI obligations separately from high-risk-system obligations — they have different enforcement pathways and timing.
- Map the national supervisory interface for every EU jurisdiction where you place systems.
For compliance leaders
- Implement a documented Article 4 AI literacy programme now; regulators signal flexibility on form, not on the duty.
- Build an interim conformity file for high-risk systems rather than waiting for harmonised standards.
- Prepare incident workflows before 2026-08-02 using the Commission's draft guidance and templates.
- Run supplier-contract review for high-risk and GPAI exposures.
For policymakers
- Publish national supervisory charts in machine-readable format.
- Pair every authority designation with a public scope note explaining sectoral competence boundaries.
- Publish sandbox entry criteria and outputs — sandboxes are systemically valuable only if their learning diffuses.
Frequently Asked Questions
When does the EU AI Act apply?+
Who enforces the EU AI Act?+
Is national implementation complete across the EU?+
Should firms wait for harmonised standards before preparing?+
What is the GPAI Code of Practice?+
What is Article 4 AI literacy?+
Which member states have AI regulatory sandboxes?+
What is the Digital Omnibus on AI?+
How should organisations prepare for 2026-08-02?+
How big is the EU AI Act compliance consulting market in 2026?+
What changed in the Q2 2026 refresh of this tracker?+
How often is this report updated?+
What is the EU AI Act implementation timeline 2026?+
What are the EU AI Act fines for prohibited practices and high-risk AI systems?+
Who applies to the EU AI Act as a provider or deployer in a third country?+
What is the EU AI Office and what does it do?+
What is NIST AI Risk Management Framework (AI RMF 1.0)?+
How does the EU AI Act compare to NIST AI RMF?+
What is ISO/IEC 42001 and what does certification cost?+
How is the AI Act being implemented in Sweden?+
What is the GPAI Code of Practice and who has signed it?+
What are AI governance platforms and what do they cost?+
What does the EU AI Act mean for HR and recruitment AI?+
What does the EU AI Act mean for healthcare AI?+
What is a Fundamental Rights Impact Assessment (FRIA) under Article 27?+
What is the AI Act Service Desk?+
What is the Digital Omnibus on AI?+
Does the EU AI Act require AI literacy training?+
When does Article 50 transparency for AI-generated content apply?+
How does the EU AI Act apply to financial services?+
How does the EU AI Act apply to public-sector AI?+
About the Authors & Reviewers

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.
- 8+ years in AI strategy & implementation
- Top-5 AI Speaker, Sweden (Mindley 2025)
- 100+ enterprise AI engagements

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.
- AI automation & agent systems lead
- Workflow design across 100+ deployments
- Specialist in RAG, integrations & APIs
Methodology
Research Architecture
Public-source desk research, traceable to EUR-Lex, European Commission pages, national government portals, regulators, and standardisation bodies. No interviews, no proprietary aggregators.
EUR-Lex legal texts, European Commission published guidance, national government press releases and regulator pages.
Composite assessments, standards-timing inferences, member-state evidence scores.
Predictions about final standards content, undisclosed national administrative readiness.
Research Approach
This report is based on 100% desk research — no interviews, no proprietary surveys. The research design uses 36 reproducible questions covering scope, EU-level institutional activation, member-state supervisory architecture, guidance, standards, sandboxes, AI literacy, and incident reporting.
80 curated sources form the evidence base, classified as Primary (official legal text, Commission pages, national government portals, regulator pages, standardisation bodies) or Secondary (commentary, summaries, repackaging). All sources verified as of 2026-04-20.
Confidence Framework
- High: Primary source; direct statement; minimal transformation.
- Medium: Primary source requiring composite assessment, or inference from announced timing.
- Low / Inferential: Predictions about final standards content, undisclosed administrative readiness.
Reproducibility
All quantitative claims trace to a public source URL. The machine-readable scoreboard dataset (CSV + JSON) is hosted on the report URL with stable canonical anchors. Released under CC BY 4.0 with attribution to "Alice Labs Research".
Limitations
- AI-assisted generation: Generated with AI assistance and reviewed by humans. Critical data points should be independently verified.
- Not peer-reviewed: Treat findings as exploratory insights requiring further validation.
- Public-disclosure lag: The member-state picture depends on what governments and the Commission have published. The Commission's market-surveillance page was last refreshed 2025-09-26 and still shows blank entries — a country may be more prepared than its public footprint suggests.
- Standards-timing uncertainty: CEN-CENELEC announced acceleration toward Q4 2026 for key standards; final publication timing and content may shift.
- Public visibility, not legal completeness: The tracker measures publicly visible implementation evidence, not hidden administrative readiness or enforcement capacity.
- Coverage: Selected member-state country examples reviewed in depth (IE, ES, LT, FI, FR, DE, NL, PL, CY, IT). Other member states reviewed at a baseline level via the Commission compilation.
- Quarterly refresh cadence: Major refreshes are planned around Article 50 final code (Q2 2026), 2 August 2026 application (Q3 2026), standards publication (Q4 2026), and national enforcement (Q1 2027).
Data Sources
32 primary sources
Version History
Deep expansion. Added 'Expanded Analysis — June 2026' chapter with: 8 quotable stat callouts (Article 99 fines, Article 2 extraterritoriality, Stanford HAI USD 252.3bn investment, McKinsey 67% adoption, OECD.AI 1,000+ initiatives, ISO/IEC 42001, NIST AI RMF, AI Office), 27-country member-state authority cross-reference table, Annex III high-risk categories table, EU AI Act vs ISO/IEC 42001 vs NIST AI RMF comparison table, extended glossary (19 terms), four citation formats (APA/MLA/Chicago/BibTeX), visible version-history timeline, and methodology note. Added 13 new FAQ entries on EU AI Act timeline 2026, Article 99 penalties, Article 2 extraterritoriality, AI Office responsibilities, NIST AI RMF, ISO/IEC 42001 certification cost, AI governance platform pricing, Sweden SOU 2025:101, GPAI Code signatories, HR/healthcare/finance/public-sector application, FRIA, Article 50, AI Act Service Desk, and Digital Omnibus. Bumped DefinedTermSet schema to 19 terms.
Q2 2026 maintenance refresh. Added a top-of-report 'Q2 2026 Update' chapter (status of Article 50 second-draft code, CEN-CENELEC Q4 2026 standards target, Commission SPoC compilation still unrefreshed since 2025-09-26). Added two FAQ entries — EU AI Act compliance consulting market sizing (Stanford HAI AI Index 2025, McKinsey State of AI 2024 anchors) and a Q2 2026 changelog summary. Next scheduled review: 24 September 2026.
Research presentation pass: added concise summary box, structured metadata, DefinedTermSet glossary (8 terms), internal cross-references to related Alice Labs reports, refreshed dateModified, and shortened public title.
Initial public release. 80 sources, 27 member states tracked, 9 visualisations, 12 key findings. Quarterly refresh cadence established (Q2 2026 next).