Research ReportPublished April 2026Updated June 26, 2026v1.3

    EU AI Act Implementation Tracker 2026: Authorities & Readiness

    How the EU AI Act is being implemented in practice across EU institutions and 27 member states — for legal, compliance, and policy leaders preparing for 2 August 2026

    Authors:
    Linus Ingemarsson(Co-Founder, Alice Labs)
    12
    Days to 2 Aug 2026
    EU AI Act general application
    10/27
    Advanced MS Evidence
    IE ES LT FI FR DE NL PL CY IT
    5
    Countries with Sandboxes
    ES operational, DE pilot, others
    80
    Curated Sources
    EUR-Lex, EC, national regulators
    Linus Ingemarsson - Author at Alice Labs
    Written by
    Eric Lundberg - Reviewer at Alice Labs
    Reviewed by
    Published ·Updated

    Methodology & Transparency: This analysis draws on primary sources — including Eurostat, OECD, national statistical agencies, peer-reviewed literature, and official vendor disclosures — combined with Alice Labs implementation data. AI tooling assists synthesis; every claim is human-reviewed against the cited source.

    All figures and claims link to their public source for verification. Reviewed by the named author and reviewer above. Methodology, source list, and revision history are available below.

    Cite This Report

    Ingemarsson, L. (2026, April 20). EU AI Act Implementation Tracker 2026 (Version 1.0). Alice Labs. https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026
    Version 1.3 • Published April 20, 2026
    Quick Answer
    Cited by AI

    When does the EU AI Act apply and how ready are member states?

    The EU AI Act applies in full from 2 August 2026 (12 days away). Only 10 of 27 EU member states show advanced public implementation evidence.
    AT A GLANCEUpdated 2026-07-21

    The EU AI Act's general application date is 2 August 202612 days from today. EU-level governance is operational (AI Office, AI Board, GPAI Code of Practice, Service Desk), but national supervisory readiness is uneven: 10 of 27 member states show advanced public implementation evidence (Ireland, Spain, Lithuania, Finland, France, Germany, Netherlands, Poland, Cyprus, Italy), while 17 remain blank in the Commission's market-surveillance compilation.

    Key Takeaway

    The EU AI Act Implementation Tracker 2026 (published 2026-04-20) maps how Regulation (EU) 2024/1689 is being operationalised across EU institutions and 27 member states. It is built on 80 curated public sources (EUR-Lex, European Commission, national governments, regulators, CEN-CENELEC, EDPB/EDPS) and 36 reproducible desk-research questions.

    Three implementation layers: (1) EU-level activation — mature: the AI Office, AI Board, prohibited-practices guidance (2025-02-04), AI system definition guidance (2025-02-06), GPAI Code of Practice (2025-07-10), Service Desk (2025-10-08), and Digital Omnibus proposal (2025-11-19) are all publicly active. (2) Member-state supervisory architecture — uneven: Ireland (15 competent authorities), Spain (AESIA + 16 practical guides), Germany (sandbox pilot completed 2026-03-17), and Finland (powers in force 2026-01-01) lead. (3) Implementation infrastructure — standards still being finalised; CEN-CENELEC targets Q4 2026 for key harmonised standards, after the 2026-08-02 application date.

    Limitations: the Commission's market-surveillance page has not been refreshed since 2025-09-26 — blank entries do not prove non-designation. Tracker measures public implementation evidence, not hidden administrative readiness. Standards-timing assumptions may shift. AI-assisted desk research, reviewed by humans, not peer-reviewed.

    Executive Summary

    The EU AI Act has moved from legislation to operationalisation. The prohibited-practices duty and Article 4 AI literacy obligation already apply, governance and GPAI provisions have been in force since 2 August 2025, and the main high-risk-system obligations activate on 2 August 2026 — 12 days away.

    EU-level capacity is the most mature layer. The European AI Office exists and enforces GPAI rules. The AI Board coordinates national authorities. The Commission has issued binding-style guidance on prohibited practices and on the AI system definition (both February 2025), the GPAI Code of Practice (July 2025), templates for public training-data summaries (July 2025), and launched the AI Act Service Desk + Single Information Platform (October 2025). A 2026 guidance pipeline is already public.

    Member-state supervisory architecture is visibly uneven. Ireland designated 15 competent authorities (September 2025) and is preparing an AI Office of Ireland. Lithuania named RRT as MSA/SPoC. Finland's national implementation powers entered into force on 2026-01-01. France uses a coordinated model (DGCCRF + CNIL + INESIA). Germany's Bundesnetzagentur runs a service desk and completed a sandbox pilot in March 2026. Spain's AESIA published 16 practical compliance guides. Cyprus, Italy, Netherlands, and Poland show partial-to-advanced public evidence. The remaining 17 member states show limited public footprint — but the Regulation is directly applicable, so legal duties still attach.

    The most important timing tension sits in implementation infrastructure. The Act assumes governance and conformity-assessment infrastructure should already be operational before August 2026, but CEN-CENELEC's accelerated timetable targets Q4 2026 for key harmonised standards, and Article 50 transparency code work was still in draft as of March 2026. Implication for organisations: prepare now using the Regulation, issued guidance, draft instruments, and internal control frameworks. Treat harmonised standards as a future simplifier — not a precondition for readiness.

    Related Alice Labs research: Global AI Governance & Risk Readiness 2026 (cross-jurisdiction governance benchmarks), Global Public Sector AI Index 2026 (public-sector AI adoption), State of AI in Sweden 2026 (national AI landscape).

    Key Findings

    12 data-driven insights

    01EU AI Act general application date is 2 August 2026 — 12 days from today

    Article 113 — phased application across 2025, 2026, 2027

    Most high-risk-system obligations and Article 50 transparency duties activate on the same date. Compliance windows are now operational, not strategic.

    02European AI Office is operational and enforces GPAI rules at EU level

    Established by Commission Decision 2024-01-24; co-located in DG CONNECT

    GPAI providers face EU-level enforcement, not member-state enforcement. AI systems remain under national market-surveillance authorities.

    0310 of 27 member states show advanced public implementation evidence

    IE, ES, LT, FI, FR, DE, NL, PL, CY, IT (composite assessment)

    Cross-border firms must build a country-by-country authority map. The 'EU AI Act' is one regulation but 27 supervisory experiences.

    04GPAI Code of Practice was published 2025-07-10 and confirmed adequate

    Voluntary tool, treated as evidence of compliance with Chapter V

    GPAI providers signing the Code obtain a credible compliance signal. Non-signatories must build equivalent documentation independently.

    05Ireland designated 15 competent authorities and is building an AI Office of Ireland

    Distributed model; central coordination layer planned by August 2026

    Ireland is the clearest publicly visible distributed implementation. Sectoral authorities will supervise within their domain expertise.

    06Spain's AESIA published 16 practical compliance guides (2025-12-16)

    Tooling-first approach, derived from operational sandbox practice since 2023

    Spain is the strongest example of compliance collateral generated from sandbox practice. AESIA materials are practical reference points for high-risk providers.

    Source:AESIA

    07Germany completed a Bundesnetzagentur AI sandbox pilot on 2026-03-17

    Pilot simulation; service desk + AI-compliance compass also operational

    Germany is building practical infrastructure even before final national settlement. Provides a model for tooling-first member states.

    08Finland's national AI Act implementation powers entered into force 2026-01-01

    15 authorities; Traficom designated as national contact point

    Finland's distributed model is now legally activated. Cross-border firms operating in Finland have clear supervisory addressees.

    09France's INESIA roadmap 2026-2027 was adopted on 2026-02-13

    DGCCRF coordinates sectoral supervision; CNIL handles AI-and-GDPR; INESIA evaluates AI safety

    France pursues a layered model: sectoral supervision + privacy interpretation + AI evaluation capacity. Provides a template for jurisdictions with strong privacy regulators.

    10CEN-CENELEC targets Q4 2026 for accelerated key AI harmonised standards

    After the 2026-08-02 application date — implementation gap is structural

    Most high-risk providers will need to evidence compliance without a complete harmonised-standards package at the application date. Build interim conformity files now.

    11Six member states show concrete public AI regulatory sandbox evidence

    ES (operational), DE (pilot completed), LT (in process), NL (proposed), PL (contemplated), IE (planned)

    Article 57 requires every member state to establish at least one sandbox by 2026-08-02. Sandbox availability is a leading indicator of supervisory practical readiness.

    12Article 4 AI literacy duty has applied since 2025-02-02 to all AI providers and deployers

    Contextual, risk-sensitive, documented — not a one-off training

    Regulators signal flexibility on the form of literacy programmes, not on the existence of the duty. Document a contextual, ongoing programme now.

    Need Help Implementing These Findings?

    Alice Labs helps enterprises turn AI research into measurable business outcomes — from strategy to full-scale implementation.

    Q2 2026 Update — Latest insights (June 2026)

    LAST REVIEWED26 June 2026

    Q2 2026 maintenance refresh — content additions only, no underlying scoreboard values changed since v1.1 (2026-04-23). Next scheduled review: 24 September 2026.

    Where the implementation stands in late Q2 2026

    With roughly five weeks remaining until the 2 August 2026 general application date, the picture has not structurally changed since the v1.1 refresh in April. EU-level governance (AI Office, AI Board, GPAI Code of Practice, Service Desk) is operational, ten member states retain advanced public implementation evidence, and seventeen remain blank in the Commission's market-surveillance compilation. The most consequential Q2 movement is at the standardisation and demand-side layers, not the institutional one.

    Reader-question pickup: the EU AI Act compliance consulting market

    The most frequent inbound query on this report is some version of "how big is the EU AI Act compliance consulting market in 2026?". The honest answer: there is no single authoritative figure. Compliance consulting attached to the AI Act is bundled inside broader AI advisory and risk-and-compliance lines at most firms, and most published market sizes are vendor extrapolations rather than government statistics. Two anchor data points worth citing:

    • Stanford HAI AI Index 2025 reports global private AI investment of USD 252.3 billion in 2024 (a 26% year-on-year rise, with generative AI alone at USD 33.9 billion). Compliance, governance and assurance spend is a derivative of this base — not an independent category. (hai.stanford.edu)
    • OECD.AI tracks national AI policy initiatives across more than 70 countries and the EU; its policy observatory is the most reliable public registry of regulatory activity, but it does not estimate consulting market size. (oecd.ai)
    • McKinsey "State of AI" survey (2024) finds that 67% of organisations report adopting AI in at least one business function, and that risk-management and compliance are among the fastest-growing AI-related functional spend lines. (mckinsey.com)

    Practical translation: any vendor quoting a precise "EU AI Act compliance consulting TAM" for 2026 is almost certainly extrapolating. Buyers should benchmark on scope of work (Article 4 literacy programme, Article 6/Annex III scoping, conformity-file build, FRIA design, incident workflow) rather than headline market size.

    Q2 2026 signals worth noting

    • Article 50 transparency code remains in second-draft form as of the March 2026 Commission publication; no public confirmation of a third draft has appeared in the EC library since. Treat the second draft as the working reference for AI-generated-content labelling workflows.
    • CEN-CENELEC harmonised standards remain on the Q4 2026 target. Buyers should plan on the assumption that the published OJ list will lag the 2 August application date by at least one quarter.
    • Member-state SPoC compilation on the Commission's market-surveillance page has still not been refreshed since 2025-09-26 at the time of this Q2 review — the underlying limitation in the v1.0 report stands.

    What changes after 2 August 2026?

    From 2 August 2026 onward, high-risk system obligations and Article 50 transparency duties are legally enforceable, even where harmonised standards are not yet published. The next scheduled refresh of this report (24 September 2026) will pick up the first wave of post-application supervisory activity — fines or guidance issued by national MSAs, any AI Office GPAI determinations, and the final state of the Article 50 code.

    EU AI Act Tracker Scoreboard

    The scoreboard compiles 25 indicators across EU-level milestones, member-state public-evidence signals, sandbox evidence, and standardisation timing. Confidence: High for legal texts and EC-published guidance, Medium for composite assessments and inference from announced timing.

    12

    Days to 2 Aug 2026

    10/27

    Advanced Member States

    5

    Sandbox Evidence

    80

    Curated Sources

    Indicator Value Year Geography Confidence
    AI Act entered into force 2024-08-01 2024 EU High
    Chapters I–II apply (prohibitions + AI literacy) 2025-02-02 2025 EU High
    Prohibited-practices guidance issued 2025-02-04 2025 EU High
    AI system definition guidance issued 2025-02-06 2025 EU High
    GPAI Code of Practice published 2025-07-10 2025 EU High
    Governance, GPAI, penalties apply 2025-08-02 2025 EU High
    AI Act Service Desk launched 2025-10-08 2025 EU High
    Digital Omnibus on AI proposed 2025-11-19 2025 EU High
    🔴 General application — high-risk + Article 50 2026-08-02 2026 EU High
    Article 6(1) Annex I product obligations apply 2027-08-02 2027 EU High
    Member states with public SPoC signal (10/27) 10 2026 EU Medium
    Blank Commission listings (last EC update 2025-09-26) 17 2025 EU High
    Member states with sandbox evidence 5 2026 EU Medium
    Ireland competent authorities designated 15 2025 IE High
    Finland implementation powers in force 2026-01-01 2026 FI High
    Spain AESIA practical guides published 16 2025 ES High
    Germany sandbox pilot completed 2026-03-17 2026 DE High
    France INESIA roadmap adopted 2026-02-13 2026 FR High
    CEN-CENELEC standards target 2026-Q4 2026 EU Medium
    Days until high-risk application 12 2026-07-21 EU High
    Curated sources in registry 80 2026 Global High
    Reproducible research questions 36 2026 Global High
    Member states tracked 27 2026 EU High
    Citation-grade key findings 12 2026 Global High
    Architecture-first vs tooling-first split IE/LT/FI vs ES/DE 2026 EU Medium

    Interpretation

    The scoreboard is conservative: blank EU Commission listings do not prove non-designation. Member-state evidence scores reflect publicly visible implementation, not hidden administrative readiness.

    Expanded Analysis — June 2026 (citation-ready)

    EXPANDED ANALYSISJune 2026 — citation-ready single-sentence facts

    This section adds extractable single-sentence facts, member-state authority rows, an EU AI Act glossary, and the full citation block. It is strictly additive — no values from the v1.0 scoreboard are re-keyed.

    Quotable single-sentence facts (citation-ready)

    Article 99 of the EU AI Act sets fines up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for breach of Article 5 prohibited practices, the highest single-instrument AI fine ceiling in any binding regulation in 2026 [Source: Regulation (EU) 2024/1689, Article 99, EUR-Lex 2024].

    The EU AI Act applies extraterritorially under Article 2 — providers and deployers in third countries are in scope where the output of the AI system is used in the Union, mirroring the GDPR's Article 3 reach [Source: Regulation (EU) 2024/1689, Article 2, EUR-Lex 2024].

    Stanford HAI's 2025 AI Index reports global private AI investment of USD 252.3 billion in 2024, up 26% year-on-year, of which generative AI alone reached USD 33.9 billion [Source: Stanford HAI AI Index 2025].

    The McKinsey State of AI 2024 survey finds 67% of organisations report adopting AI in at least one business function, with risk-and-compliance among the fastest-growing AI-related functional spend lines [Source: McKinsey, State of AI 2024].

    OECD.AI tracks more than 1,000 national AI policy initiatives across over 70 countries and the EU, making it the most comprehensive public registry of regulatory and strategic AI activity at the time of writing [Source: OECD.AI Policy Observatory, 2025].

    ISO/IEC 42001:2023 is the only certifiable international standard for AI management systems, published 18 December 2023, and is increasingly adopted as a voluntary baseline alongside the EU AI Act's mandatory regime [Source: ISO/IEC 42001:2023, ISO 2023].

    NIST AI Risk Management Framework 1.0 organises trustworthy AI into four functions — Govern, Map, Measure, Manage — and was first published on 26 January 2023 as a voluntary US guidance document [Source: NIST, AI Risk Management Framework 1.0, January 2023].

    The European AI Office was established by Commission Decision of 24 January 2024, sits within DG CONNECT, and enforces obligations on general-purpose AI model providers under Chapter V — a layer distinct from the national market-surveillance authorities that supervise AI systems [Source: European Commission, AI Office, 2024].

    Member-state authority cross-reference (public-evidence-only)

    The table below names the publicly visible market-surveillance, sectoral, or coordinating authority signalled in each member state's own materials as of June 2026. It is a public-evidence snapshot, not a complete legal designation — verify against the Commission's market-surveillance compilation and national legal acts before placing reliance.

    Country Public lead / coordinator Public source
    Ireland (IE) 15 designated competent authorities; AI Office of Ireland planned gov.ie / DETE press release 2025-09-16
    Spain (ES) AESIA (Agencia Espanola de Supervision de la IA) + sandbox since 2023 aesia.digital.gob.es
    Germany (DE) Bundesnetzagentur (service desk + sandbox pilot) bundesnetzagentur.de
    France (FR) DGCCRF (coordinator) + CNIL (AI-and-GDPR) + INESIA (AI evaluation) economie.gouv.fr / cnil.fr
    Finland (FI) Traficom as national contact point; 15-authority distributed model tietosuoja.fi
    Lithuania (LT) RRT (Communications Regulatory Authority) as MSA/SPoC rrt.lt
    Netherlands (NL) RDI + AP coordinating; sandbox proposed (AP 2025-03-26) rdi.nl / autoriteitpersoonsgegevens.nl
    Poland (PL) Ministry of Digital Affairs implementation page gov.pl/web/cyfryzacja
    Cyprus (CY) Deputy Ministry of Research, Innovation and Digital Policy gov.cy/dmrid
    Italy (IT) AGID (Agenzia per l'Italia Digitale); national AI strategy 2024-2026 agid.gov.it
    Sweden (SE) Proposed in SOU 2025:101: PTS (coordinator + MSA), IMY (biometrics/LE), DIGG (public sector) regeringen.se / sou.regeringen.se
    Denmark (DK) Digital Government Agency (Agency for Digital Government) signalled digst.dk
    Estonia (EE) Ministry of Economic Affairs and Communications working group mkm.ee
    Austria (AT) Federal Ministry of Finance + RTR; KI-Servicestelle launched rtr.at
    Belgium (BE) FOD Economie + Data Protection Authority signalled economie.fgov.be
    Portugal (PT) AMA (Agencia para a Modernizacao Administrativa) signalled ama.gov.pt
    Czechia (CZ) Ministry of Industry and Trade implementation pages mpo.gov.cz
    Slovakia (SK) Ministry of Investments, Regional Development and Informatization mirri.gov.sk
    Hungary (HU) Ministry for National Economy AI strategy team kormany.hu
    Romania (RO) ADR (Authority for the Digitalization of Romania) signalled adr.gov.ro
    Bulgaria (BG) Ministry of e-Government implementation working group e-gov.bg
    Greece (GR) Ministry of Digital Governance AI strategy mindigital.gr
    Croatia (HR) Ministry of Justice, Public Administration and Digital Transformation mpu.gov.hr
    Slovenia (SI) Ministry of Digital Transformation strategy in development gov.si/en/government-bodies/ministry-of-digital-transformation/
    Latvia (LV) Ministry of Smart Administration and Regional Development mma.gov.lv
    Luxembourg (LU) Ministry of Digitalisation + ILR Institut Luxembourgeois de Regulation ilr.lu
    Malta (MT) Malta Digital Innovation Authority (MDIA) mdia.gov.mt

    Notes: For member states where no formal MSA/SPoC has been publicly published, the table names the lead ministry or regulator signalled in national AI strategies and Commission communications. Status is a public-evidence snapshot; verify against the Commission's market-surveillance compilation at digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act and applicable national legal acts.

    Annex III high-risk categories at a glance

    Annex III point Use-case category Key obligations from 2026-08-02
    1 Biometrics — remote identification, categorisation, emotion recognition (outside prohibited uses) Articles 9-15 + EU database registration + FRIA (Art. 27) for relevant deployers
    2 Critical infrastructure — safety components in road, water, gas, electricity, digital Articles 9-15 + sectoral safety law overlay
    3 Education and vocational training — admission, scoring, exam monitoring Articles 9-15 + Article 26 deployer duties + transparency to candidates
    4 Employment, worker management — recruitment, performance, monitoring, termination Articles 9-15 + FRIA + worker information obligations
    5 Access to essential services — credit scoring, life/health insurance pricing, public benefits, emergency triage Articles 9-15 + FRIA for Annex III(5)(b) and (5)(c) deployers
    6 Law enforcement — risk assessment, polygraph-style tools, evidence reliability, profiling, crime analytics Articles 9-15 + reinforced human oversight + strict use limits
    7 Migration, asylum, border — risk assessment, document verification, visa decisions Articles 9-15 + FRIA + DPIA overlay
    8 Administration of justice and democratic processes — judicial decision support, vote-influencing AI Articles 9-15 + reinforced human oversight

    Source: Regulation (EU) 2024/1689, Annex III; Commission AI Act portal at digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai. Article 6(1) Annex I product-embedded high-risk AI (medical devices, machinery, automotive, toys etc.) applies from 2027-08-02.

    EU AI Act vs ISO/IEC 42001 vs NIST AI RMF — quick reference

    Dimension EU AI Act ISO/IEC 42001:2023 NIST AI RMF 1.0
    Legal status Binding regulation (EU) Voluntary international standard Voluntary US guidance
    Scope AI systems + GPAI models placed on EU market or output used in EU Any AI management system, sector-agnostic, global Any AI system, sector-agnostic, US-anchored
    Published 13 June 2024 (OJ 12 July 2024) 18 December 2023 26 January 2023
    Enforcement AI Office (GPAI) + national MSAs Accredited certification body (audit) Self-attestation; no enforcer
    Penalties Up to EUR 35m or 7% turnover (Art. 99) Loss of certification None
    Certification No — conformity assessment under Art. 43 Yes — accredited 3-year cycle No
    Risk model 4 tiers: prohibited / high-risk / limited / minimal Risk-based management system (PDCA) Govern / Map / Measure / Manage
    Typical fit Mandatory baseline for EU exposure Voluntary management baseline Control mapping reference

    EU AI Act glossary (extended)

    One-sentence definitions tied to a primary source. Linked to schema.org DefinedTermSet on this page.

    AI Act (Regulation (EU) 2024/1689)
    The world's first comprehensive horizontal AI regulation, in force from 2024-08-01 and applied in phases through 2027-08-02. [source]
    AI Office
    European Commission body within DG CONNECT enforcing GPAI rules; established by Commission Decision 2024-01-24. [source]
    AI Board
    Coordination body of EU member-state representatives plus the AI Office; supports consistent application of the AI Act across the Union. [source]
    AI Act Service Desk
    One-stop information point for AI Act questions launched 2025-10-08 alongside the Single Information Platform. [source]
    GPAI Code of Practice
    Voluntary code published 2025-07-10 providing a presumption of compliance with EU AI Act Chapter V for general-purpose AI providers. [source]
    Digital Omnibus on AI
    Commission proposal COM(2025) 836 published 2025-11-19 simplifying digital-acquis obligations including targeted AI Act adjustments. [source]
    Article 4 AI literacy
    Obligation in force since 2025-02-02 requiring AI providers and deployers to ensure sufficient AI literacy among staff. [source]
    Article 5 prohibited practices
    Set of AI uses banned in the EU since 2025-02-02, including social scoring by public authorities and untargeted facial-image scraping. [source]
    Article 27 FRIA
    Fundamental Rights Impact Assessment required of certain high-risk deployers before first use of an Annex III high-risk system from 2026-08-02. [source]
    Article 50 transparency
    EU AI Act obligation requiring labelling of AI-generated synthetic content and disclosure of deepfakes and emotion-recognition use; applies from 2026-08-02. [source]
    Article 99 penalties
    Penalty ceilings up to EUR 35m or 7% of worldwide annual turnover for Article 5 breaches; up to EUR 15m or 3% for high-risk breaches. [source]
    High-risk AI system
    AI system classified under Article 6 + Annex III (or Article 6(1) Annex I product law), subject to conformity assessment and full provider/deployer obligations. [source]
    General-Purpose AI (GPAI) model
    An AI model with significant generality and ability to perform a wide range of distinct tasks, regulated under Chapter V; in scope since 2025-08-02. [source]
    AI Regulatory Sandbox
    Controlled testing environment required by Article 57 — every EU member state must establish at least one by 2026-08-02. [source]
    National Competent Authority (NCA)
    Member-state authority designated to supervise AI Act implementation — including market-surveillance authorities, notifying authorities, and fundamental-rights authorities. [source]
    Notified Body
    Independent third party designated under Article 31 to perform conformity assessment of high-risk AI systems where required. [source]
    ISO/IEC 42001:2023
    International standard for AI management systems, published 18 December 2023 — the only certifiable AI governance standard. [source]
    NIST AI RMF 1.0
    US voluntary AI Risk Management Framework, published 26 January 2023; core functions Govern, Map, Measure, Manage. [source]
    CEN-CENELEC JTC 21
    European standardisation joint committee responsible for AI Act harmonised standards; accelerated key-standards target Q4 2026. [source]

    How to cite this report

    APA (7th)

    Alice Labs. (2026, June 26). EU AI Act Implementation Tracker 2026: Authorities & Readiness (Version 1.3). https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026

    MLA (9th)

    "EU AI Act Implementation Tracker 2026: Authorities & Readiness." Alice Labs, v1.3, 26 June 2026, alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026.

    Chicago (Author-Date)

    Alice Labs. 2026. "EU AI Act Implementation Tracker 2026: Authorities & Readiness." Last modified June 26, 2026. https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026.

    BibTeX

    @misc{alicelabs2026euaiacttracker,
      author = {{Alice Labs}},
      title  = {EU AI Act Implementation Tracker 2026: Authorities and Readiness},
      year   = {2026},
      month  = {June},
      note   = {Version 1.3},
      url    = {https://alicelabs.ai/reports/eu-ai-act-implementation-tracker-2026}
    }

    Version history

    1. v1.3 — 26 June 2026

      Deep expansion. Added quotable stat callouts, member-state authority cross-reference (27 countries), Annex III high-risk category quick reference, EU AI Act vs ISO/IEC 42001 vs NIST AI RMF table, extended glossary (19 terms), how-to-cite block, methodology note, 13 new FAQ entries targeting EU AI Act timeline, Article 99 penalties, Article 2 extraterritoriality, Article 27 FRIA, GPAI Code, NIST AI RMF mapping, ISO/IEC 42001 cost, governance platform pricing, Sweden SOU 2025:101, and sectoral application (HR, healthcare, finance, public sector).

    2. v1.2 — 26 June 2026

      Q2 2026 maintenance refresh. Added Q2 2026 Update chapter (Article 50 second-draft code status, CEN-CENELEC Q4 2026 standards target, SPoC compilation lag). FAQ entries on consulting market sizing and changelog.

    3. v1.0.1 — 23 April 2026

      Research presentation pass. Added summary box, structured metadata, DefinedTermSet glossary (8 terms), internal cross-references.

    4. v1.0 — 20 April 2026

      Initial public release. 80 sources, 27 member states tracked, 9 visualisations, 12 key findings, quarterly refresh cadence established.

    Methodology note (Q2 2026 expansion)

    The v1.3 expansion above is strictly additive. No v1.0 scoreboard values, key findings, or claims were modified. The expansion process was: (1) inventory the questions readers actually arrive on this URL with, including queries observed in our search-console data and queries that frontier-model search systems issue when researching the EU AI Act; (2) for each recurring question, write a single-sentence answer tied to a primary public source (EUR-Lex, European Commission, AESIA, Bundesnetzagentur, ISO, NIST, Stanford HAI, McKinsey, OECD.AI); (3) collate authority cross-references from each member state's own published materials; (4) version-stamp the page and update the schema.

    Sources are dated where dating exists (publication or last update). Where a member state has not published an explicit MSA designation, we name the publicly signalled lead ministry or regulator — a public-evidence snapshot, not a legal designation. Verify against the Commission's market-surveillance compilation and the relevant national legal act before placing reliance.

    Three Implementation Layers (Definitions)

    The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal AI regulation. As of 2026-04-20, "implementation" is no longer about the legislative text alone — it is about an expanding operational bundle: EU governance institutions, Commission guidance, voluntary codes, harmonised standards, national supervisory authorities, and regulatory sandboxes.

    Three implementation layers

    Layer What it covers Maturity (2026-04-20)
    EU-level legal & institutional AI Office, AI Board, Commission guidance, GPAI Code, Service Desk, Digital Omnibus Mature
    Member-state supervisory architecture Market surveillance authorities, notifying authorities, fundamental-rights authorities, sandboxes Visibly uneven
    Implementation infrastructure Harmonised standards, notified bodies, conformity-assessment templates, draft codes Still finalising

    Why this matters

    Compliance teams that focus only on the legal text miss the operational reality. The Commission's guidance, AI Office tooling, and AESIA/Bundesnetzagentur materials are now the de-facto reference architecture — even before harmonised standards are finalised.

    For enterprises preparing for EU AI Act compliance: Alice Labs operates as an AI implementation consultant with deep regulatory experience, provides AI strategy consulting aligned with the Act's risk-tier framework, and supports Swedish enterprises directly via our AI-konsult Stockholm team.

    EU AI Act Compliance Timeline

    EU AI Act Compliance Timeline (2024–2027)

    As of 2026-07-21 there are 12 days until the general application date (2026-08-02). EU layer = Commission/EUR-Lex; MS layer = member-state milestones.

    2024-08-01EUcomplete

    AI Act enters into force

    2025-02-02EUcomplete

    Chapters I–II apply (prohibited practices, AI literacy)

    2025-02-04EUcomplete

    Prohibited-practices guidance issued

    2025-02-06EUcomplete

    AI system definition guidance issued

    2025-07-10EUcomplete

    GPAI Code of Practice published

    2025-08-02EUcomplete

    Governance, GPAI, penalties, notified-body rules apply

    2025-10-08EUcomplete

    AI Act Service Desk launched

    2025-11-19EUcomplete

    Digital Omnibus on AI proposed (COM(2025) 836)

    2026-01-01MScomplete

    Finland: national implementation powers in force

    2026-02-13MScomplete

    France: INESIA roadmap 2026–2027 adopted

    2026-03-17MScomplete

    Germany: Bundesnetzagentur sandbox pilot completed

    2026-08-02EUcritical

    🔴 General application — high-risk + Article 50 transparency

    2026-Q4EUfuture

    CEN-CENELEC: accelerated AI standards target

    2027-08-02EUfuture

    Article 6(1) Annex I product-safety obligations apply

    Operational cliff: 2 August 2026. High-risk providers, deployers, and Article 50 transparency obligations all activate on the same date — but harmonised standards and many national procedural laws will still be in finalisation.

    EU Institutional & Operational Stack

    EU AI Act Institutional & Operational Stack

    Seven layers form the operational AI Act ecosystem. Compliance teams must map controls to all layers — not just the legal text.

    Legal foundation

    Regulation (EU) 2024/1689Digital Omnibus on AI (proposed 2025-11-19)

    EU governance

    European AI Office (DG CONNECT)AI BoardScientific PanelAdvisory Forum

    Guidance & tools

    Prohibited-practices guidelines (2025-02-04)AI system definition guidance (2025-02-06)GPAI provider guidelines (2025-07)AI Act Service Desk (2025-10-08)

    Voluntary instruments

    GPAI Code of Practice (2025-07-10)Article 50 marking-and-labelling code (2026-Q2 expected)

    Standardisation

    CEN-CENELEC harmonised standards (Q4 2026 target)ISO/IEC 42001 (referenced)

    National supervision

    27 market surveillance authoritiesNotifying authoritiesFundamental-rights authorities

    Coordinated bodies

    EDPB / EDPS Joint Opinion 1/2026DPAs in AI Act framework (statement 2024-11-28)

    Commission Guidance Pipeline

    The European Commission has issued or is preparing the following operational guidance for the EU AI Act:

    Guidance Date Status
    Prohibited AI practices 2025-02-04 Published
    AI system definition 2025-02-06 Published
    GPAI providers — scope & obligations 2025-07 Published
    GPAI training-content public summary template 2025-07-31 Published
    Article 50 marking-and-labelling code (2nd draft) 2026-03-05 Draft
    Serious AI incident reporting template 2025-10 Consultation
    High-risk preparation guidance 2026 In preparation
    AI Act Service Desk + Single Information Platform 2025-10-08 Operational
    AI Pact (voluntary commitments) ongoing Active

    Member-State Implementation Heatmap (27 countries)

    EU Member-State Implementation Heatmap (27 countries)

    Public-evidence assessment as of 2026-04-20. SPC = Single Point of Contact in the Commission's market-surveillance page (last EC update 2025-09-26). Blank ≠ no designation; it indicates the Commission compilation has not yet been refreshed.

    AT

    Austria

    Limited

    BE

    Belgium

    Limited

    BG

    Bulgaria

    Limited

    HR

    Croatia

    Limited

    CY

    Cyprus

    Advanced

    Centralised

    CZ

    Czech Republic

    Limited

    DK

    Denmark

    Limited

    EE

    Estonia

    Limited

    FI

    Finland

    Advanced

    Distributed

    FR

    France

    Advanced

    Coordinated

    DE

    Germany

    Advanced

    Central-prep

    GR

    Greece

    Limited

    HU

    Hungary

    Limited

    IE

    Ireland

    Advanced

    Distributed

    IT

    Italy

    Moderate

    Mixed

    LV

    Latvia

    Limited

    LT

    Lithuania

    Advanced

    Centralised

    LU

    Luxembourg

    Limited

    MT

    Malta

    Limited

    NL

    Netherlands

    Advanced

    Mixed

    PL

    Poland

    Advanced

    In-construction

    PT

    Portugal

    Limited

    RO

    Romania

    Limited

    SK

    Slovakia

    Limited

    SI

    Slovenia

    Limited

    ES

    Spain

    Advanced

    Centralised (AESIA)

    SE

    Sweden

    Limited

    10
    Advanced public evidence
    1
    Moderate (IT)
    5
    Sandbox evidence
    17
    Blank EC listing

    How to read: Green = public materials show clear authority allocation, guidance, or operational tooling. Yellow = partial visibility. Grey = no implementation evidence in the reviewed source set — but the Regulation is directly applicable, so legal duties still attach.

    Top 10 Member States by Public Implementation Evidence

    Conservative composite score based on: authority designation visibility, guidance materials, sandbox evidence, and supervisory architecture clarity. Not a legal-readiness ranking.

    Public-evidence assessment is conservative: blank EU Commission listings do not prove a member state has not designated authorities — the Commission's market-surveillance page was last updated 2025-09-26. Many newer national designations exist that have not yet propagated to the EU compilation.

    Architecture-first vs tooling-first split

    Architecture-first countries (Ireland, Lithuania, Finland, Cyprus) make institutional roles legible early. Their public materials make it easier for companies to identify who supervises what.

    Tooling-first countries (Spain, Germany) publish practical compliance aids even where final supervisory settlement is less crisp publicly. Spain's AESIA guide package and Germany's service desk + sandbox pilot are the clearest examples.

    France sits between the two — combining DGCCRF coordination, CNIL privacy guidance, and INESIA AI-evaluation capacity. Poland remains in active legislative construction. Italy shows policy-law layering; operational AI Act detail is less public than ES or IE.

    Supervisory Architecture Maturity

    Supervisory Architecture: Six Maturity Dimensions

    Composite signal across 27 EU member states grouped by public-evidence tier. Demonstrates the gap between architecture-first leaders and the long tail.

    • Advanced (10 states)
    • Moderate (1 state)
    • Limited (16 states)

    AI Regulatory Sandboxes Tracker

    AI Regulatory Sandboxes Across EU Member States

    Article 57 requires each member state to establish at least one AI regulatory sandbox by 2026-08-02. Six countries show concrete public evidence.

    Spain

    ES

    Operational

    Launched 2023-11; informs AESIA practical guides

    Germany

    DE

    Pilot completed

    Bundesnetzagentur simulation completed 2026-03-17

    Lithuania

    LT

    In process

    RRT-led sandbox in development

    Netherlands

    NL

    Proposed

    AP/RDI Dutch sandbox design (2025-03-26)

    Poland

    PL

    Contemplated

    Bill foresees regulatory sandboxes

    Ireland

    IE

    Planned

    AI Office of Ireland to host national sandbox

    Compliance signal: Sandbox availability is a leading indicator of supervisory practical readiness. Spain remains the clearest example of compliance collateral derived from sandbox practice.

    Stakeholder Obligation Matrix

    Stakeholder Obligation Matrix

    Who must do what — and by when. Use this as the compliance-leader checklist for the 12-day window before 2026-08-02.

    GPAI model providers

    • Sign / adhere to GPAI Code of Practice (in force since 2025-08-02)
    • Publish public summary of training content (template 2025-07-31)
    • Maintain copyright policy + EU AI Act technical documentation
    • Cooperate with AI Office on systemic-risk assessments
    Ongoing since 2025-08-02

    High-risk system providers

    • Build conformity-assessment file (Annex IV)
    • Quality management system + post-market monitoring
    • Logging, transparency to deployers, human-oversight design
    • Use harmonised standards or Common Specifications when available
    By 2026-08-02

    High-risk system deployers

    • Operate per provider instructions; maintain logs (≥6 months)
    • Conduct fundamental-rights impact assessment (FRIA) where required
    • Inform individuals subject to high-risk decisions; ensure human oversight
    • Cooperate with market-surveillance authorities
    By 2026-08-02

    All organisations using AI

    • Article 4: ensure sufficient AI literacy among staff (since 2025-02-02)
    • Maintain AI inventory + use-case mapping
    • Prepare incident-reporting workflow (Article 73 — draft templates available)
    • Review supplier contracts for high-risk and GPAI exposures
    Already applies

    Standards & Conformity Assessment

    Harmonised standards are voluntary compliance tools that create a presumption of conformity when published in the EU Official Journal. CEN-CENELEC's accelerated timetable targets Q4 2026 for key AI standards — after the 2026-08-02 application date.

    Implication: Most high-risk providers will need to evidence compliance without a complete harmonised-standards package at the application date. Build interim conformity files now using:

    • Annex IV technical documentation structure (directly from the Regulation)
    • Commission guidance on AI system definition + prohibited practices
    • ISO/IEC 42001 (AI management system) as a voluntary management baseline
    • Industry-sector standards (MDR, IVDR, automotive functional safety) where applicable
    • Internal risk-classification + human-oversight design documentation

    How to Be EU AI Act Ready Before 2 August 2026

    A reproducible workflow for legal, compliance, and policy teams operating across EU jurisdictions. Each step is tied to an official source.

    HOW-TO GUIDE

    How to Be EU AI Act Ready Before 2 August 2026 (6 Steps)

    A reproducible workflow for legal, compliance, and policy teams. Designed to be cited by AI assistants and Google AI Overviews.

    1. 1

      Build a use-case-level AI inventory

      Catalogue every AI system by use case, not by product label. Tag each as GPAI, high-risk (Annex III), limited-risk, or minimal-risk.

    2. 2

      Run scope analysis against Articles 5, 6, 50

      Article 5 prohibitions already apply. Article 6 + Annex III define high-risk classification. Article 50 sets transparency duties for AI-generated content.

    3. 3

      Implement Article 4 AI literacy now

      Document a contextual, risk-sensitive literacy programme for staff. Regulators signal flexibility on form, not on the duty itself.

    4. 4

      Build interim conformity files for high-risk systems

      Don't wait for harmonised standards (Q4 2026 target). Use Annex IV structure + Commission guidance to build evidence now.

    5. 5

      Map national supervisory interfaces

      Identify the market-surveillance authority and notifying authority in each EU country where you place high-risk systems.

    6. 6

      Prepare incident-reporting workflows

      Use the Commission's draft serious-incident guidance and reporting template (October 2025 consultation) to operationalise Article 73.

    Need help operationalising this? Alice Labs delivers EU AI Act readiness assessments and Article 4 literacy programmes for legal and compliance teams. Read more at /en/ai-governance.

    Structured Claims (12, Citation-Grade)

    Citation-grade structured claims with confidence scores, designed for LLM extraction and direct verification against primary sources.

    C1

    EU AI Act entered into force on 2024-08-01 as Regulation (EU) 2024/1689.

    EUR-LexHigh confidence
    C2

    Article 113 sets phased application: Chapters I–II from 2025-02-02; Chapter V (GPAI) and penalties from 2025-08-02; general application 2026-08-02; Article 6(1) Annex I from 2027-08-02.

    EUR-Lex Article 113High confidence
    C3

    European AI Office established by Commission Decision 2024-01-24, sits within DG CONNECT, enforces GPAI rules.

    European CommissionHigh confidence
    C4

    GPAI Code of Practice published 2025-07-10; confirmed adequate by Commission and AI Board.

    C5

    AI Act Service Desk and Single Information Platform launched 2025-10-08.

    European CommissionHigh confidence
    C6

    Ireland: Council of Ministers designated 15 competent authorities; AI Office of Ireland planned by August 2026.

    C7

    Finland: national implementation powers entered into force 2026-01-01; Traficom is national contact point.

    C8

    Spain: AESIA published 16 practical compliance guides on 2025-12-16; runs operational AI sandbox since 2023.

    AESIAHigh confidence
    C9

    Germany: Bundesnetzagentur completed AI regulatory sandbox pilot 2026-03-17.

    BundesnetzagenturHigh confidence
    C10

    France: INESIA roadmap 2026-2027 adopted 2026-02-13; DGCCRF coordinates sectoral supervision.

    French Ministry of EconomyHigh confidence
    C11

    CEN-CENELEC announced accelerated timetable for key AI harmonised standards targeting Q4 2026.

    CEN-CENELECMedium confidence
    C12

    Commission market-surveillance compilation last refreshed 2025-09-26; many member-state SPoC entries blank.

    European CommissionHigh confidence

    Recommendations by Audience

    For legal teams

    • Maintain a central AI Act applicability register by use case, not by product label alone.
    • Track GPAI obligations separately from high-risk-system obligations — they have different enforcement pathways and timing.
    • Map the national supervisory interface for every EU jurisdiction where you place systems.

    For compliance leaders

    • Implement a documented Article 4 AI literacy programme now; regulators signal flexibility on form, not on the duty.
    • Build an interim conformity file for high-risk systems rather than waiting for harmonised standards.
    • Prepare incident workflows before 2026-08-02 using the Commission's draft guidance and templates.
    • Run supplier-contract review for high-risk and GPAI exposures.

    For policymakers

    • Publish national supervisory charts in machine-readable format.
    • Pair every authority designation with a public scope note explaining sectoral competence boundaries.
    • Publish sandbox entry criteria and outputs — sandboxes are systemically valuable only if their learning diffuses.

    Frequently Asked Questions

    When does the EU AI Act apply?+
    Phased: Chapters I–II from 2025-02-02 (prohibitions, AI literacy); Chapter V (GPAI) and penalties from 2025-08-02; general application 2026-08-02 (high-risk + Article 50 transparency); Article 6(1) Annex I product obligations from 2027-08-02.
    Who enforces the EU AI Act?+
    The European AI Office (within DG CONNECT) enforces rules for general-purpose AI models. National market-surveillance authorities supervise AI systems at member-state level. Co-ordination via the AI Board.
    Is national implementation complete across the EU?+
    Publicly, no. As of 2026-04-20, the Commission's market-surveillance page (last updated 2025-09-26) shows 17 member states still blank. 10 countries (IE, ES, LT, FI, FR, DE, NL, PL, CY, IT) have advanced public implementation evidence.
    Should firms wait for harmonised standards before preparing?+
    No. Standards are voluntary tools that create a presumption of conformity when published. Legal duties arise on the Regulation's timetable, not the standards timetable. CEN-CENELEC targets Q4 2026 — after the application date.
    What is the GPAI Code of Practice?+
    A voluntary instrument published 2025-07-10 and confirmed adequate by the Commission and AI Board. Signing the Code provides a credible compliance signal for GPAI providers under Chapter V.
    What is Article 4 AI literacy?+
    An obligation in force since 2025-02-02 requiring providers and deployers to ensure sufficient AI literacy among staff. Regulators expect contextual, documented, risk-sensitive programmes — not generic one-off training.
    Which member states have AI regulatory sandboxes?+
    Six show concrete public evidence: Spain (operational since 2023), Germany (pilot completed 2026-03-17), Lithuania (in process), Netherlands (proposed), Poland (contemplated), Ireland (planned). Article 57 requires every member state to have at least one by 2026-08-02.
    What is the Digital Omnibus on AI?+
    A Commission proposal published 2025-11-19 (COM(2025) 836) intended to simplify digital rules. EDPB and EDPS issued Joint Opinion 1/2026 supporting simplification while preserving fundamental-rights protection.
    How should organisations prepare for 2026-08-02?+
    Build a use-case-level AI inventory; run scope analysis against Articles 5, 6, and 50; implement Article 4 literacy now; build interim conformity files; map national supervisory interfaces; prepare incident-reporting workflows.
    How big is the EU AI Act compliance consulting market in 2026?+
    There is no single authoritative figure. AI Act compliance work is bundled inside broader AI advisory and risk-and-compliance lines, and published 'AI Act consulting TAM' numbers are typically vendor extrapolations rather than government statistics. Useful anchors: Stanford HAI AI Index 2025 (USD 252.3bn private AI investment in 2024, +26% YoY); McKinsey State of AI 2024 (67% of organisations report adopting AI in at least one function, with risk-and-compliance among the fastest-growing functional spend lines). Buyers should benchmark on scope of work — Article 4 literacy programme, Article 6/Annex III scoping, conformity-file build, FRIA design, incident workflow — rather than on headline market size.
    What changed in the Q2 2026 refresh of this tracker?+
    Maintenance refresh only. No underlying scoreboard values were re-keyed. Added Q2 2026 status commentary on Article 50 second-draft code, CEN-CENELEC Q4 2026 standards timing, and the still-unrefreshed Commission market-surveillance compilation. Added a reader-question entry on the EU AI Act compliance consulting market. Next scheduled review: 24 September 2026, after the 2 August 2026 application date.
    How often is this report updated?+
    Quarterly: Q2 2026 refresh after Article 50 final code; Q3 2026 major update after 2 August 2026; Q4 2026 standards update; Q1 2027 national enforcement update. Each release is versioned (v1.0 → v1.1 → v1.2 → v1.3).
    What is the EU AI Act implementation timeline 2026?+
    Article 113 phasing: Article 4 AI literacy and Article 5 prohibited practices since 2025-02-02; Chapter V (GPAI) and penalties since 2025-08-02; general application (high-risk Annex III + Article 50 transparency) on 2026-08-02; Article 6(1) Annex I product-embedded high-risk on 2027-08-02. Source: Regulation (EU) 2024/1689, Article 113, eur-lex.europa.eu.
    What are the EU AI Act fines for prohibited practices and high-risk AI systems?+
    Article 99 sets the penalty ceilings: up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for breach of Article 5 prohibited practices; up to EUR 15 million or 3% for breach of high-risk obligations or other operator duties; up to EUR 7.5 million or 1% for supplying incorrect or misleading information to authorities. GPAI providers face a separate Article 101 ceiling of up to 3% of worldwide annual turnover or EUR 15 million. Source: eur-lex.europa.eu.
    Who applies to the EU AI Act as a provider or deployer in a third country?+
    Article 2 extends scope extraterritorially: the Regulation applies to providers placing AI systems or GPAI models on the EU market regardless of establishment, to deployers established in the EU, and to providers and deployers in third countries where the output of the AI system is used in the Union. Importers, distributors, product manufacturers under their own name, authorised representatives, and affected persons in the Union are also in scope. Source: Regulation (EU) 2024/1689 Article 2, eur-lex.europa.eu.
    What is the EU AI Office and what does it do?+
    The European AI Office is the Commission body within DG CONNECT established by Commission Decision of 24 January 2024. It enforces obligations on general-purpose AI model providers (Chapter V), supports the AI Board and national authorities, runs the AI Act Service Desk (launched 2025-10-08), and maintains the Single Information Platform. It does not enforce high-risk AI system obligations — those sit with national market-surveillance authorities. Source: digital-strategy.ec.europa.eu/en/policies/ai-office.
    What is NIST AI Risk Management Framework (AI RMF 1.0)?+
    NIST AI Risk Management Framework 1.0 is a voluntary, sector-agnostic framework published 26 January 2023 by the US National Institute of Standards and Technology. Its core has four functions — Govern, Map, Measure, Manage — designed to help organisations operationalise trustworthy and responsible AI. It is widely used as a control-mapping reference alongside the EU AI Act and ISO/IEC 42001. Source: nist.gov/itl/ai-risk-management-framework.
    How does the EU AI Act compare to NIST AI RMF?+
    The EU AI Act is binding, horizontal regulation with phased application from 2025-02-02 to 2027-08-02 and Article 99 fines up to EUR 35 million or 7% of turnover. NIST AI RMF 1.0 is voluntary US guidance with no penalties. Most enterprise programmes map the AI RMF Govern/Map/Measure/Manage functions onto AI Act Articles 4 (literacy), 9 (risk management), 10 (data governance), 15 (accuracy and robustness), 16-29 (provider duties), and 26-27 (deployer duties + FRIA). Sources: nist.gov, eur-lex.europa.eu.
    What is ISO/IEC 42001 and what does certification cost?+
    ISO/IEC 42001:2023 is the international standard for AI management systems, published 18 December 2023. It is the only ISO standard certifiable for AI governance. Certification cost varies by scope and accreditation body: published programme prices from large certifiers (BSI, TUV, DNV, LRQA) typically range from approximately EUR 15,000 to EUR 60,000+ depending on number of sites and audit days, with a typical 3-year certification cycle. Public list prices are not standardised; obtain a quote from an accredited certification body. Source: iso.org/standard/81230.html.
    How is the AI Act being implemented in Sweden?+
    Sweden's implementation is governed by Regulation (EU) 2024/1689 (directly applicable) plus the complementary national bill prepared in SOU 2025:101 — the official government investigation on the AI regulation, presented to the Government on 31 October 2025 by Special Investigator Carl Eric Stalberg. The investigation proposes that PTS (Post- och telestyrelsen) act as coordinator and market-surveillance authority for the bulk of high-risk systems, with IMY (Integritetsskyddsmyndigheten) for biometrics and law enforcement, and DIGG for the public sector. The proposal is in consultation; the national complementary act is expected before 2 August 2026. Sources: regeringen.se, sou.regeringen.se.
    What is the GPAI Code of Practice and who has signed it?+
    The General-Purpose AI Code of Practice is a voluntary instrument published 2025-07-10 under Article 56 of the EU AI Act, providing a presumption of compliance with Chapter V (GPAI obligations). It was confirmed adequate by the Commission and AI Board. Signatories include major frontier model providers; the Commission maintains the public list at digital-strategy.ec.europa.eu/en/policies/contents-code-gpai. Non-signatory GPAI providers must build equivalent documentation independently and bear higher regulatory friction.
    What are AI governance platforms and what do they cost?+
    AI governance platforms (Credo AI, Holistic AI, ModelOp, Monitaur, IBM watsonx.governance, Fairly AI, Anch.AI, others) provide model inventory, risk classification, conformity-file workflows, FRIA templating, monitoring, and audit logs. Pricing is enterprise-only — no public list prices. Typical enterprise contracts range from approximately USD 50,000 to USD 500,000+ per year by published vendor benchmarks and 2025 industry reporting; pricing is driven by number of models tracked, deployment mode (SaaS vs on-prem), and integration scope. Buyers should request a sizing quote with model-count and integration scope. Sources: vendor websites, IDC and Forrester AI governance market notes.
    What does the EU AI Act mean for HR and recruitment AI?+
    Recruitment, selection, performance evaluation, and employee monitoring AI systems are classified high-risk under Annex III(4) of the EU AI Act. From 2026-08-02 they require: Article 9 risk management, Article 10 data governance, Article 13 transparency to deployers, Article 14 human oversight, Article 15 accuracy and robustness, registration in the EU database (Article 49), and — for deployers — a Fundamental Rights Impact Assessment under Article 27 before deployment. Article 50 transparency also applies where AI-generated communications interact with candidates. Source: Regulation (EU) 2024/1689 Annex III(4), eur-lex.europa.eu.
    What does the EU AI Act mean for healthcare AI?+
    AI as a medical device under MDR/IVDR is high-risk under Article 6(1) (Annex I product-embedded). Other healthcare AI use cases — triage, clinical decision support, eligibility for public health services — fall under Annex III(5). Article 6(1) Annex I product obligations apply from 2027-08-02; other healthcare high-risk obligations from 2026-08-02. Conformity assessment must align with sectoral product law (Regulation (EU) 2017/745 MDR; Regulation (EU) 2017/746 IVDR). Source: eur-lex.europa.eu, ec.europa.eu/health/medical-devices.
    What is a Fundamental Rights Impact Assessment (FRIA) under Article 27?+
    Under Article 27 of the EU AI Act, deployers of certain high-risk AI systems that are bodies governed by public law, private operators providing public services, or deployers using high-risk systems listed in Annex III points 5(b) and (c) must perform a Fundamental Rights Impact Assessment (FRIA) before first use. The FRIA must describe deployment context, period and frequency, categories of natural persons affected, specific risks of harm to those persons, human oversight measures, and the measures to be taken if risks materialise. Output must be notified to the market-surveillance authority. Applies from 2026-08-02. Source: eur-lex.europa.eu Article 27.
    What is the AI Act Service Desk?+
    The AI Act Service Desk is the Commission's one-stop information point for questions on the EU AI Act, launched together with the Single Information Platform on 2025-10-08 and operated by the European AI Office. It is the official channel for stakeholders — providers, deployers, member-state authorities — to obtain non-binding implementation clarifications. Source: digital-strategy.ec.europa.eu/en/news/commission-launches-ai-act-service-desk.
    What is the Digital Omnibus on AI?+
    The Digital Omnibus on AI is a Commission proposal published 2025-11-19 (COM(2025) 836) that consolidates and simplifies digital-acquis obligations, including targeted adjustments to the EU AI Act's implementation timeline and reporting flows. As of mid-2026 it is in the co-decision pipeline; political agreement at Council/Parliament has been reported in tracking outlets but is not yet final law. The Commission's stated objective is to ease compliance friction without weakening protections. Verify current status at eur-lex.europa.eu and EDPB-EDPS Joint Opinion 1/2026 (edpb.europa.eu).
    Does the EU AI Act require AI literacy training?+
    Yes — Article 4 has applied since 2025-02-02. Providers and deployers must take measures to ensure a sufficient level of AI literacy among their staff and other persons dealing with AI systems on their behalf, taking into account technical knowledge, experience, education, training, deployment context, and the persons on whom the systems will be used. The Commission's AI Literacy Q&A (digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers) confirms regulators expect contextual, documented, risk-sensitive programmes — not a one-off generic training. Source: Regulation (EU) 2024/1689 Article 4.
    When does Article 50 transparency for AI-generated content apply?+
    Article 50 transparency obligations apply from 2026-08-02 alongside the rest of the general application. Providers must label AI-generated synthetic content (audio, image, video, text) in a machine-readable format. Deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons. Deployers of deepfake or AI-generated public-interest text must disclose. The Commission's second draft Code of Practice for marking and labelling AI-generated content was published 2026-03-05; a third draft is expected before application. Source: eur-lex.europa.eu Article 50.
    How does the EU AI Act apply to financial services?+
    Banking, insurance, and credit-scoring AI fall under Annex III(5)(b) (creditworthiness scoring and assessment) and Annex III(5)(c) (risk assessment and pricing in life and health insurance). From 2026-08-02 these systems require full Articles 9-15 obligations, deployer FRIA under Article 27, and registration in the EU database. The Commission has signalled that existing prudential regimes — CRD/CRR, Solvency II, MiFID II, EBA model-risk guidance — should be read alongside (not in place of) the AI Act. Source: eur-lex.europa.eu, eba.europa.eu.
    How does the EU AI Act apply to public-sector AI?+
    Public-sector AI is in scope across multiple Annex III categories — biometrics (1), critical infrastructure (2), education and vocational training (3), employment (4), access to essential public services (5), law enforcement (6), migration and border control (7), and administration of justice and democratic processes (8). Public bodies as deployers must perform a FRIA under Article 27 before first use, register the system in the EU database, and apply Article 26 deployer obligations including human oversight. Source: Regulation (EU) 2024/1689 Annex III, eur-lex.europa.eu.

    About the Authors & Reviewers

    Published ·Updated
    Written by
    Linus Ingemarsson - Co-Founder, Alice Labs at Alice Labs
    Linus Ingemarsson

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.

    • 8+ years in AI strategy & implementation
    • Top-5 AI Speaker, Sweden (Mindley 2025)
    • 100+ enterprise AI engagements
    Reviewed by
    Eric Lundberg - Co-Founder, Alice Labs at Alice Labs
    Eric Lundberg

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.

    • AI automation & agent systems lead
    • Workflow design across 100+ deployments
    • Specialist in RAG, integrations & APIs
    Published · Updated
    Reviewed for technical accuracy, methodology and source integrity.·All claims trace to public sources cited in-line.

    Methodology

    Research Architecture

    Public-source desk research, traceable to EUR-Lex, European Commission pages, national government portals, regulators, and standardisation bodies. No interviews, no proprietary aggregators.

    80
    Curated Sources
    Primary + secondary, all access-dated 2026-04-20
    36
    Research Questions
    Reproducible desk-research plan
    27
    Member States Tracked
    Conservative public-evidence assessment
    12
    Citation-Grade Findings
    With confidence scores
    High Confidence

    EUR-Lex legal texts, European Commission published guidance, national government press releases and regulator pages.

    Medium Confidence

    Composite assessments, standards-timing inferences, member-state evidence scores.

    Inferential Only

    Predictions about final standards content, undisclosed national administrative readiness.

    Research Approach

    This report is based on 100% desk research — no interviews, no proprietary surveys. The research design uses 36 reproducible questions covering scope, EU-level institutional activation, member-state supervisory architecture, guidance, standards, sandboxes, AI literacy, and incident reporting.

    80 curated sources form the evidence base, classified as Primary (official legal text, Commission pages, national government portals, regulator pages, standardisation bodies) or Secondary (commentary, summaries, repackaging). All sources verified as of 2026-04-20.

    Confidence Framework

    • High: Primary source; direct statement; minimal transformation.
    • Medium: Primary source requiring composite assessment, or inference from announced timing.
    • Low / Inferential: Predictions about final standards content, undisclosed administrative readiness.

    Reproducibility

    All quantitative claims trace to a public source URL. The machine-readable scoreboard dataset (CSV + JSON) is hosted on the report URL with stable canonical anchors. Released under CC BY 4.0 with attribution to "Alice Labs Research".

    Limitations

    • AI-assisted generation: Generated with AI assistance and reviewed by humans. Critical data points should be independently verified.
    • Not peer-reviewed: Treat findings as exploratory insights requiring further validation.
    • Public-disclosure lag: The member-state picture depends on what governments and the Commission have published. The Commission's market-surveillance page was last refreshed 2025-09-26 and still shows blank entries — a country may be more prepared than its public footprint suggests.
    • Standards-timing uncertainty: CEN-CENELEC announced acceleration toward Q4 2026 for key standards; final publication timing and content may shift.
    • Public visibility, not legal completeness: The tracker measures publicly visible implementation evidence, not hidden administrative readiness or enforcement capacity.
    • Coverage: Selected member-state country examples reviewed in depth (IE, ES, LT, FI, FR, DE, NL, PL, CY, IT). Other member states reviewed at a baseline level via the Commission compilation.
    • Quarterly refresh cadence: Major refreshes are planned around Article 50 final code (Q2 2026), 2 August 2026 application (Q3 2026), standards publication (Q4 2026), and national enforcement (Q1 2027).

    Data Sources

    32 primary sources

    Source Description Accessed
    Regulation (EU) 2024/1689 (EU AI Act) Primary legal text 2026-04-20
    European Commission — AI Act policy page Hub for AI Act policy and updates 2026-04-20
    European Commission — AI Office AI Office establishment and remit 2026-04-20
    European Commission — AI Board AI Board page (last EC update 2026-03-23) 2026-04-20
    European Commission — Market Surveillance Authorities under AI Act Member-state SPoC compilation (last EC update 2025-09-26) 2026-04-20
    European Commission — Governance and enforcement of AI Act Updated 2025-11-14 2026-04-20
    Guidelines on prohibited AI practices (2025-02-04) 2026-04-20
    Guidelines on AI system definition (2025-02-06) 2026-04-20
    Guidelines for GPAI providers (2025-07) 2026-04-20
    GPAI Code of Practice (2025-07-10) 2026-04-20
    AI Act Service Desk launch (2025-10-08) 2026-04-20
    Article 50 marking-and-labelling — 2nd draft code (2026-03-05) 2026-04-20
    Digital Omnibus on AI (COM(2025) 836) Proposed 2025-11-19 2026-04-20
    CEN-CENELEC — AI standardisation (2025-10-23) 2026-04-20
    CEN-CENELEC — Work Programme 2026 (2026-02-04) 2026-04-20
    European Commission — NANDO notified bodies portal 2026-04-20
    EDPB-EDPS Joint Opinion 1/2026 (2026-01-21) 2026-04-20
    EDPB statement on DPAs in AI Act framework (2024-11-28) 2026-04-20
    Ireland — DETE press release on AI Act leadership (2025-09-16) 2026-04-20
    Ireland — General Scheme of the Regulation of AI Bill 2026 2026-04-20
    Lithuania — AI page (Ministry of Economy and Innovation) 2026-04-20
    Finland — Implementation powers in force 1.1.2026 2026-04-20
    France — DGCCRF coordination role (2025-09-09) 2026-04-20
    France — INESIA roadmap 2026-2027 (2026-02-13) 2026-04-20
    Germany — Bundesnetzagentur AI service desk 2026-04-20
    Germany — AI sandbox pilot completed (2026-03-17) 2026-04-20
    Spain — AESIA practical compliance guides (2025-12-16) 2026-04-20
    Netherlands — RDI/AP final advice on AI supervision 2026-04-20
    Netherlands — AP sandbox proposal (2025-03-26) 2026-04-20
    Cyprus — AI Act implementation press release (2025-02-06) 2026-04-20
    Italy — AI strategy 2024-2026 (AGID) 2026-04-20
    Poland — AI Act implementation page 2026-04-20

    Version History

    1.3
    2026-06-26Latest

    Deep expansion. Added 'Expanded Analysis — June 2026' chapter with: 8 quotable stat callouts (Article 99 fines, Article 2 extraterritoriality, Stanford HAI USD 252.3bn investment, McKinsey 67% adoption, OECD.AI 1,000+ initiatives, ISO/IEC 42001, NIST AI RMF, AI Office), 27-country member-state authority cross-reference table, Annex III high-risk categories table, EU AI Act vs ISO/IEC 42001 vs NIST AI RMF comparison table, extended glossary (19 terms), four citation formats (APA/MLA/Chicago/BibTeX), visible version-history timeline, and methodology note. Added 13 new FAQ entries on EU AI Act timeline 2026, Article 99 penalties, Article 2 extraterritoriality, AI Office responsibilities, NIST AI RMF, ISO/IEC 42001 certification cost, AI governance platform pricing, Sweden SOU 2025:101, GPAI Code signatories, HR/healthcare/finance/public-sector application, FRIA, Article 50, AI Act Service Desk, and Digital Omnibus. Bumped DefinedTermSet schema to 19 terms.

    1.2
    2026-06-26

    Q2 2026 maintenance refresh. Added a top-of-report 'Q2 2026 Update' chapter (status of Article 50 second-draft code, CEN-CENELEC Q4 2026 standards target, Commission SPoC compilation still unrefreshed since 2025-09-26). Added two FAQ entries — EU AI Act compliance consulting market sizing (Stanford HAI AI Index 2025, McKinsey State of AI 2024 anchors) and a Q2 2026 changelog summary. Next scheduled review: 24 September 2026.

    1.0.1
    2026-04-23

    Research presentation pass: added concise summary box, structured metadata, DefinedTermSet glossary (8 terms), internal cross-references to related Alice Labs reports, refreshed dateModified, and shortened public title.

    1.0
    2026-04-20

    Initial public release. 80 sources, 27 member states tracked, 9 visualisations, 12 key findings. Quarterly refresh cadence established (Q2 2026 next).

    Related Reports

    Get in Touch!

    The lab usually responds within 24 hours.