EU AI Act Enforcement Creates a Three-Speed Regulatory Landscape Across Europe

5 August 2026

The implementation of the European Union’s AI Act is progressing at markedly different speeds across Member States, creating an increasingly fragmented regulatory landscape that businesses must navigate as enforcement begins to take shape. According to Deloitte Legal’s latest National Implementation of the EU AI Act across Member States – July 2026 report, Europe has effectively divided into three groups based on their readiness to enforce the new legislation.

A small group of countries has already established operational enforcement frameworks, with designated supervisory authorities, single points of contact and AI-specific sanctions either fully in force or close to implementation. Finland, Italy, Hungary, Ireland, Malta, Slovenia and Cyprus are identified as the most advanced jurisdictions, providing businesses with greater regulatory certainty but also signalling that AI compliance requirements are likely to be enforced sooner in these markets.

A larger group of Member States has advanced legislation but has yet to complete the final stages of implementation. Countries including Germany, France, Poland, Spain, the Netherlands, Sweden, Czechia and Portugal have largely defined their institutional structures but are still finalising enforcement procedures, sanctions, supervisory authorities or regulatory sandboxes. As these measures become operational, companies should expect enforcement activity to accelerate rapidly.

The report also identifies a third group of countries that remain at an earlier stage of implementation. Austria, Belgium, Bulgaria, Croatia, Estonia, Romania and Slovakia continue to rely primarily on existing regulatory regimes while dedicated AI enforcement legislation and supervisory structures are still under development.

Despite these differences, almost all Member States have completed the designation of fundamental rights bodies required under Article 77 of the AI Act. However, the report highlights that the designation of market surveillance authorities and national coordination mechanisms under Article 70 remains the principal bottleneck delaying full implementation across much of the European Union.

The study notes that Member States are adopting different approaches to supervision rather than creating entirely new AI regulators. Communications authorities, digital infrastructure regulators, consumer protection agencies, cybersecurity bodies and data protection authorities are all emerging as national contact points, resulting in different regulatory entry points depending on the jurisdiction. This diversity means businesses operating across multiple EU markets will increasingly need country-specific compliance strategies rather than relying solely on a single European framework.

The report also examines the impact of the proposed Digital Omnibus package, which adjusts some implementation deadlines for high-risk AI systems and extends certain relief measures for smaller businesses. While these changes provide additional preparation time, Deloitte concludes that they do not alter the need for organisations to establish AI governance frameworks, comply with transparency obligations or prepare for the broader requirements of the AI Act.

Another significant finding is the uneven development of regulatory sandboxes across Europe. Denmark, Latvia, Lithuania and Spain already operate AI testing environments, while many other Member States have included sandboxes in legislation but have yet to launch them. Several countries remain in the planning stage, limiting opportunities for businesses to test innovative AI applications under regulatory supervision.

Looking ahead, the report recommends that companies prioritise compliance efforts in countries where enforcement structures are already operational, while building flexible AI governance programmes capable of adapting to different national requirements. It also encourages organisations to engage with regulatory sandboxes where available and to use the extended implementation timetable to strengthen AI inventories, governance processes, risk management and documentation rather than delaying compliance preparations. According to Deloitte, organisations that establish robust AI governance now will be better positioned as national enforcement frameworks continue to mature across the European Union.

Source: Deloitte

front page info
LATEST NEWS