AI content disclosure serviceHow it works

Regulators, country by country: who would actually come asking

Which national authorities enforce the EU's AI disclosure rules, country by country, and how enforcement actually reaches a business.

Part of our guide to the EU AI disclosure rules.

This guide is not legal advice. It is a plain-language answer to the question everyone asks once they understand the disclosure rules: fine, but who would actually come asking? Checked against the state of play in August 2026, and this is the guide most likely to change under our feet, so we review it regularly.

How enforcement is supposed to work

The AI Act splits its policing in two. The big AI model providers answer to the European Commission's AI Office directly. Everyone else, which includes every business publishing AI content on a website, answers to a national market surveillance authority in each member state, the same machinery that polices product safety. Each country was required to designate its authority by 2 August 2025.

Here is the honest picture: by that deadline, only eight of the twenty-seven member states had formally done so. A year on, the map is filling in but still uneven, which produces the strangest fact in this whole area, and the one worth reading twice. The disclosure duties applied from 2 August 2026 everywhere, regardless of whether the country in question has finished appointing its referee. EU regulations apply directly. A missing regulator delays the knock on the door; it does not suspend the rule.

The part that matters more than any regulator

Before the country tour, one short article of the Act deserves your attention, because it describes the way these rules will most likely reach an ordinary business. Article 85 says that "any natural or legal person having grounds to consider that there has been an infringement" may lodge a complaint with the relevant market surveillance authority.

Any person. Any company. That includes your competitor who resents your AI-generated content ranking above their hand-written pages, your former employee, and the client who felt misled by a team photo of people who do not exist. Enforcement agencies move at agency speed, but complaints arrive at the speed of grudges. The realistic scenario was never an inspector with a clipboard. It is a letter that begins "we received a complaint", and by then the only question that matters is what your records show.

Germany: the most organised queue in Europe

Germany is doing what Germany does: building the machinery properly, slightly late. The Bundesnetzagentur, the federal network agency that already regulates telecoms and energy, is designated as the default market surveillance authority and the single point of contact for the EU. Inside it sits a coordination and competence centre, KoKIVO, whose job is to pool AI expertise and feed interpretation to the sector regulators, so that a bank's AI questions and a builder's AI questions get consistent answers.

The implementing law, the KI-MIG, was adopted as a government draft on 10 February 2026 and is being fast-tracked through the Bundestag. Two details in it are worth any publisher's attention. It adds supplementary national fines of up to fifty thousand euros for violations not already covered by the EU fine regime, and appeals against enforcement decisions have no suspensive effect, meaning you comply first and argue afterwards. The draft also grants authorities practical powers with teeth: information requests, remote access to systems via API, and unannounced inspections. If your German-language pages carry undisclosed AI content, this is the regime they will eventually be judged under, run by an agency with twenty years of practice at fining large companies.

France: no new law, familiar inspectors

France has taken the opposite approach: no national AI law at all, and enforcement distributed across the regulators it already has. The single point of contact is the DGCCRF, the consumer protection and fair trading authority, coordinating with CNIL for data protection, ARCOM for media, ANSSI for security and sectoral bodies beyond.

The choice of the DGCCRF is the tell. France has framed AI transparency as a consumer protection matter, and the DGCCRF is an agency that runs sweeps, checks websites at scale and publishes its findings. It has spent decades policing misleading commercial practices, and an AI-generated page presenting as human work fits that job description with no stretching at all. For anyone publishing to French customers, the mental model is not "a new AI regulator finding its feet". It is the existing consumer watchdog with a new item on its checklist.

The quick tour of everywhere else

Italy moved first and hardest: a full national AI law in force since October 2025, with the national cybersecurity agency, ACN, holding market surveillance. Spain built a dedicated agency, AESIA, the first of its kind in Europe, supported by a long list of sectoral authorities. Ireland went the other way and designated fifteen existing authorities, coordinated by a National AI Office that has been operational since September 2025, which matters more than Ireland's size suggests, because so many technology companies answer to Irish regulators first. The Netherlands expects its digital infrastructure authority and data protection authority to share the job, with formal appointment still pending. Belgium is expected to hand the role to its telecoms regulator and is behind its neighbours. Poland is legislating a new commission for the purpose. Austria, at the time of checking, was still finalising its designations.

If your country, or your customers' country, is in the not-yet column, resist the obvious conclusion. The duty is in force there anyway, the complaint right of Article 85 exists there anyway, and regulators who arrive late tend to arrive with something to prove.

What this means if you publish across borders

The rules attach to your audience, not your address, so a business publishing into several EU countries is, in principle, answerable to the authority in each of them. In practice the exposure concentrates where your customers are, in the language your pages are in. A UK agency running German-language sites should think about the Bundesnetzagentur. An exporter with French customers should think about the DGCCRF. Nobody needs to memorise twenty-seven org charts; you need to know which two or three markets you actually serve, and what your records would show if a complaint landed in one of them.

Questions people actually ask

Who can actually fine us, and how much? The market surveillance authority of the member state concerned, applying the AI Act's fine regime: for the transparency duties, up to €15m or 3% of worldwide turnover, with smaller companies fined at the lower of the two. Some countries, Germany among them, are adding national fines on top for procedural offences.

Can a competitor really report us? Yes. Article 85 gives any natural or legal person the right to complain to the relevant authority, and competitors have both the motive and the attention to detail. The defence is not hoping nobody looks. It is having records that make the complaint boring.

Our country has not designated an authority yet. Are we off the hook? No. The duties apply directly since 2 August 2026 whether or not the local referee has been appointed. The gap changes when enforcement starts, not whether you are compliant, and complaints filed now will be waiting when the authority opens its doors.

We are outside the EU entirely. Which regulator would even contact us? The authority of the member state where your affected audience is. Extraterritorial enforcement takes longer and happens less often, but the nearer risk for non-EU publishers was never the regulator: it is EU clients, partners and procurement teams asking for evidence of compliance before they sign.

Will any of this actually be enforced? Enforcement is young, authorities are still staffing up, and nobody sensible expects dawn raids over a blog post. But the machinery now exists, the complaint channel is open to anyone with a grievance, and regulators historically warm up on exactly the kind of clear, checkable, visible breach that an unlabelled AI image is. The cheap time to be right is before the first letter.

What should we actually prepare? The same three things every authority on this page would ask for: an inventory of what on your sites is AI-generated, evidence of review for the text you have chosen not to label, and visible disclosures for what needs them. If you can produce those in an afternoon, every country on this page becomes a footnote.

Where we come in

Swornmark exists to make that afternoon possible: scans that inventory your sites, findings with disclosure wording drafted, a named sign-off with a record, and a certificate anyone, including a regulator, can verify. The scan is free and takes about a minute: swornmark.com.

And if you are reading this from a country we summarised in one sentence and would like the longer version, we would genuinely love a chat. Comparing regulatory horror stories across borders is something of a hobby here.


This guide is not legal advice. It was drafted with AI assistance and reviewed before publication. Swornmark holds editorial responsibility for it. The regulatory picture above was checked in August 2026 and will change; where this page and reality disagree, reality has moved, and we would appreciate the correction.

More guides