Back to blog
September 9, 2026EU AI Act Weekly Radar

EU AI Act Weekly Radar: Enforcement Infrastructure Comes Into Focus as National Implementation Signals Build

This week’s EU AI Act radar points to a more operational phase: the Commission updated its enforcement contact map, while Poland’s DPA previewed how national oversight may connect AI Act and GDPR practice.

EU AI ActAI Act enforcementMarket surveillance authoritiesNational implementationGDPR and AI governanceRegulatory sandboxesPolandAI compliance

The EU AI Act moved a little further from framework to operating reality this week.

Two updates stood out. First, the European Commission refreshed its page on Market Surveillance Authorities under the AI Act, giving companies a clearer view of the national authorities and single points of contact that will handle supervision and enforcement across Member States. Second, Poland’s data protection authority, UODO, announced a 30 September webinar on the path “OD AI ACT DO KRAJOWYCH REGULACJI”, offering an early signal of how one national authority is thinking about AI Act implementation alongside privacy supervision.

Taken together, these developments matter because they shift attention from abstract compliance planning to a more practical question: who will ask for what, under which national setup, and how should providers and deployers prepare now?

1. The Commission’s updated enforcement map is a practical compliance signal

The European Commission’s updated page on Market Surveillance Authorities under the AI Act is not just an administrative directory. It is a visible sign that AI Act enforcement capacity is being organized at Member State level, with named single points of contact and market surveillance authorities expected to play central roles in supervision. According to the Commission page, those authorities may investigate compliance and seek access to documentation, datasets, and source code. The same page also notes that where Member States have not made the required national designations, that gap can lead to infringement action by the Commission.

For legal, product, and governance teams, that has several immediate implications.

Enforcement is becoming operational, not merely prospective

The update suggests that businesses should no longer treat AI Act enforcement as a distant issue tied only to future headline cases. Even at this stage, the Commission is helping create the institutional map through which oversight will happen in practice. That matters especially for organizations that are building or deploying AI systems across multiple EU markets, because the effective supervisory touchpoint may vary by country.

Documentation readiness is now central

The Commission page highlights that authorities may access documentation, datasets, and source code. That should reinforce a simple point: organizations need an internal record structure that can withstand regulatory scrutiny. Even where a business is still refining how it classifies systems or allocates provider/deployer roles, it should be thinking now about evidence ownership, retention, and retrieval.

National designations are a governance issue in their own right

The Commission’s note that missing designations can trigger infringement action is important beyond public law process. It shows that the EU is not leaving implementation entirely to informal national pacing. If a Member State is late or incomplete in building its AI Act supervisory architecture, the Commission may act. For companies, that means the enforcement environment may continue to change quickly as national structures are formalized.

In short, the Commission update is a reminder that the AI Act is increasingly about institutional readiness as much as legal interpretation. See the European Commission’s Market Surveillance Authorities under the AI Act page for the underlying update (European Commission).

2. Poland offers an early view of how national implementation may work in practice

The second notable development came from UODO, Poland’s data protection authority, which announced a 30 September webinar on AI Act-to-national-law implementation. The notice is significant less for the event itself than for the topics on its agenda.

According to UODO, the webinar will address:

  • the DPA’s role in Poland’s AI oversight system,
  • cooperation with KRiBSI,
  • AI-related privacy risks including deepfakes,
  • joint GDPR/AI Act risk assessment, and
  • regulatory sandboxes.

That combination is revealing.

AI Act supervision is likely to be interdisciplinary at national level

The UODO agenda suggests that national implementation may not sit in a narrow, standalone AI silo. Instead, at least in Poland’s emerging discussion, AI Act oversight is being framed alongside privacy, institutional cooperation, and practical risk assessment. That is especially relevant for businesses that have treated AI governance and data protection compliance as separate workstreams.

Deepfakes and privacy risk are becoming part of day-to-day AI governance

The agenda’s express reference to deepfakes is notable because it points toward a supervisory focus on concrete harms and use cases, not only system architecture or abstract risk categories. For organizations using generative tools, synthetic media, or identity-adjacent features, this is a reminder that AI governance questions may quickly overlap with privacy, transparency, and misuse concerns.

Sandboxes remain part of the implementation conversation

The mention of regulatory sandboxes also matters for SMEs and startups. It suggests that at least some national authorities are still thinking about implementation not only in terms of policing, but also in terms of structured engagement with innovation. That does not reduce obligations, but it may shape how smaller organizations plan market entry, testing, and regulator engagement.

The UODO announcement therefore provides an early practical signal: national AI Act implementation may be built through cooperation between authorities, with privacy regulators taking an active role in the broader governance landscape. The source update is available from UODO (UODO).

3. What these two updates mean together

Read side by side, the Commission and UODO updates tell a coherent story about the current phase of the AI Act.

From rulebook to supervisory plumbing

The Commission update is about who the authorities are and what powers they may use. The UODO webinar agenda is about how authorities may think and work together once that oversight architecture is active. One is the map; the other is an early glimpse of operational culture.

Cross-functional compliance is becoming unavoidable

The UODO agenda’s link between AI oversight, GDPR risk assessment, deepfakes, and sandboxes aligns with the Commission’s emphasis on documentation and investigatory access. Put differently, the organizations best placed for the next phase will not be those with a single AI policy deck, but those with joined-up processes across legal, privacy, engineering, product, and public affairs.

Multi-jurisdictional businesses need country-level visibility

The Commission’s list of national contact points underscores that AI Act compliance will still have a strong national implementation layer. The Poland update shows why that matters: enforcement style, authority coordination, and thematic emphasis may differ in meaningful ways from one jurisdiction to another.

4. Practical takeaways for providers and deployers

Based on this week’s updates alone, several preparation steps stand out.

1) Map your likely supervisory interfaces

If your organization places AI systems on the EU market or deploys them in multiple Member States, identify which national authorities are listed by the Commission and determine who inside your organization owns those relationships.

2) Stress-test your evidence trail

Because the Commission page notes powers to access documentation, datasets, and source code, companies should be able to answer basic operational questions quickly: where technical records sit, who can produce them, what review process applies, and how confidentiality or access controls are managed internally.

3) Align AI governance with privacy governance

The UODO agenda is a useful reminder that AI Act compliance may not be reviewed in isolation. If your AI risk process is disconnected from GDPR risk assessment, incident handling, or content authenticity controls, national implementation may expose that gap.

4) Watch for national institutional design, not only EU-level guidance

Much AI Act commentary focuses on EU-level texts and guidance. This week’s signals point in a complementary direction: companies should also track which national authorities are designated, how they divide responsibilities, and where they signal practical priorities.

5) Keep an eye on sandbox opportunities, especially if you are an SME

The UODO reference to regulatory sandboxes suggests that implementation conversations are still leaving room for structured innovation support. For startups and SMEs, that may become an important channel for early regulator engagement.

5. Why this matters for the broader AI Act timeline

Even without new headline guidance on high-risk classification, Article 6, Annex III, transparency duties, or GPAI obligations in this week’s source set, the enforcement picture is still advancing. That is the key point.

The AI Act’s real-world impact depends not only on the text of obligations, but also on the machinery that makes those obligations actionable: designated authorities, points of contact, investigatory powers, inter-agency cooperation, and national implementation practices. This week’s developments show that this machinery is gradually becoming more visible.

For businesses, that means compliance maturity should now include at least three layers:

  • understanding the legal framework,
  • organizing internal records and accountability, and
  • monitoring the national authorities that will interpret and enforce the rules in practice.

Bottom line

This week’s EU AI Act radar is less about new substantive duties and more about enforcement readiness.

The European Commission’s updated overview of market surveillance authorities highlights where AI Act supervision will sit and underscores that authorities may seek deep access to compliance materials. Poland’s UODO, meanwhile, is signaling a national implementation approach that connects AI oversight with privacy, deepfakes, cross-authority cooperation, joint risk assessment, and sandboxes.

For lextrace readers, the message is straightforward: the compliance question is no longer only *what does the AI Act require?* It is increasingly also *which authority will ask, how will they coordinate, and is your organization ready to show its work?*