The EU AI Act Enforcement Gap: Which Countries Are Ready for the AI Act

AI-generated illustration of AI Act Readiness Index scoring methodology and analysis

This analysis reflects the state of EU AI Act enforcement readiness as of 1 April 2026, based on the first edition of the index. The index has since been updated (May 2026) to reflect new designations, legislative developments, and the Digital Omnibus agreement of 7 May 2026, which pushes the high-risk enforcement deadline from August 2026 to December 2027. For current scores and findings, see the EU AI Act Enforcement Readiness Index.

The EU AI Act becomes fully applicable in four months. Not every Member State is ready.

August 2, 2026 is four months away — the date when the AI Act becomes fully applicable. Member States were required to designate their national competent authorities a full year earlier, by August 2, 2025. Not all of them met that deadline.

I’ve built an AI Act Readiness Index covering all 27 EU Member States, scoring each country on a 100-point scale across seven dimensions: authority designation, institutional capacity, published guidance, national legislation, regulatory sandboxes, public signals, and market activity.

Here are the results.

Only 3 countries reach “Ready” status — Denmark and Spain (both 90 points) and Lithuania (85). These have fully designated authorities, enacted legislation, operational sandboxes, and comprehensive guidance for businesses.

5 countries rank “Advanced” — Italy, Ireland, Germany, Finland, and Slovenia. Strong institutional frameworks, but still ramping up operational capacity.

12 countries fall in the “Emerging” band. Basic structures exist, but limited operational signals.

7 countries remain “Low” — minimal visible preparation or enforcement infrastructure.

One finding stands out: several Member States have yet to formally designate a competent authority at all. That is not a minor administrative gap — it directly affects enforcement capacity from August 2026 onward.

For SMEs operating across multiple EU jurisdictions, this has a practical implication: where you operate will affect your actual compliance risk in the early enforcement phase. A business operating only in a “Low” country faces a different near-term reality than one operating across several “Ready” jurisdictions.

The index is based exclusively on publicly available and verifiable sources — official government announcements, European Commission monitoring, national legislation, and legal commentary from major EU law firms.

Full index with country scores and methodology: ovidiusuciu.com/ai-act-readiness-index


Why This Index Exists

When the AI Act’s implementation timeline began to crystallize, most of the available analysis focused on what businesses need to do — obligations, risk categories, compliance checklists. Far less attention went to the other side of the equation: whether the authorities responsible for enforcement are actually in place and operational.

I built the AI Act Readiness Index to fill that gap. The goal was a consolidated, evidence-based picture of where each of the 27 Member States stands on enforcement preparedness — built exclusively on verifiable public signals: official government announcements, designation notifications to the European Commission, published guidance, enacted legislation, sandbox confirmations, and visible institutional activity.

The index is designed to be updated quarterly as the enforcement landscape develops. This is the first edition, based on data verified as of March 28, 2026.


Methodology

The index scores each Member State on a 100-point scale across seven dimensions:

Authority Status (20 points) — whether a national competent authority has been officially designated and notified to the European Commission. This carries the highest weight because designation is the foundational legal requirement for enforcement.

Institutional Capacity (15 points) — whether a lead body has been identified, the institutional structure defined, and resourcing signals are visible.

Guidance and Support (15 points) — whether official guidance has been published for businesses and deployers operating under the regulation.

National Legislation (10 points) — whether implementation laws have been enacted or are in active consultation.

Regulatory Sandboxes (10 points) — whether testing environments are operational or formally planned.

Public Signals (15 points) — visible preparation activity and enforcement readiness beyond formal designation.

Market Activity (15 points) — AI ecosystem development and industry engagement as an indirect indicator of regulatory maturity.

Countries are classified into four readiness bands based on their total score: Ready (85–100 points), Advanced (65–80 points), Emerging (35–64 points), and Low (15–30 points).

All scores are based on publicly available and verifiable sources, including European Commission implementation monitoring, national government announcements, the IAPP DPA Directory, national legislation, EU AI Act Service Desk listings, regulatory sandbox announcements, and legal commentary from major EU law firms. The index prioritises source quality over quantity and scores countries conservatively where public information is limited or ambiguous.


Key Findings

Three conclusions stand out from the data.

Enforcement readiness varies significantly across the EU. The gap between the best-prepared and least-prepared Member States is not marginal — it is structural. A small group of countries has built genuinely operational enforcement capacity, with designated authorities, enacted legislation, published guidance, and active regulatory sandboxes. The majority are still building. Several have barely started.

Several Member States have yet to designate a competent authority. The August 2, 2025 deadline for designation has passed. Countries that missed it are not simply behind on paperwork — they lack the legal and institutional foundation for enforcement. Until a competent authority is formally designated and notified to the European Commission, enforcement of the AI Act in that jurisdiction remains structurally uncertain.

SMEs operating across multiple jurisdictions should expect uneven enforcement intensity. The AI Act is a single regulation, but it will not be enforced uniformly across the EU — at least not in the early phase. Where a business operates, where its AI systems are deployed, and which national authority has jurisdiction will affect its practical compliance exposure. This is particularly relevant for SMEs that operate in several Member States but lack the resources to monitor regulatory developments in each one.


The Readiness Bands: Where Each Country Stands

Ready (85–90 points): Denmark, Spain, Lithuania

Three Member States reach the highest readiness band. Denmark (90) and Spain (90) share the top score, followed by Lithuania (85).

What distinguishes this group is not just formal designation but operational depth. All three have fully designated authorities, comprehensive guidance published for businesses, enacted or advanced national legislation, and active regulatory sandboxes. Spain’s dedicated AI authority — the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) — is among the most operationally developed in the EU. Denmark and Lithuania have moved quickly relative to their size, combining strong institutional frameworks with visible enforcement signals.

Advanced (65–80 points): Italy, Ireland, Germany, Finland, Slovenia

Five countries rank in the Advanced band. These are not laggards — they have strong institutional foundations and clear preparation activity. But they are still building operational capacity rather than having it fully in place.

Finland deserves a specific mention: it was the first EU Member State to achieve fully operational status, with its authority confirmed as operational on December 22, 2025. That early mover position is reflected in its score, though gaps in guidance and market activity keep it in the Advanced rather than Ready band.

Germany’s designation of the Bundesnetzagentur (BNetzA) as market surveillance authority and GPAI model supervisor gives it a credible institutional base, but guidance for businesses remains limited compared to the Ready group. Ireland’s position reflects its dual role as home to many major AI developers’ European headquarters, giving enforcement there outsized significance relative to its size. Italy presents a more complex picture, with authority responsibilities still being clarified between AgID and AGCM.

Emerging (35–64 points): Poland, Malta, Netherlands, Sweden, France, Portugal, Hungary, Luxembourg, Cyprus, Estonia, Belgium, Czech Republic

The largest group falls in the Emerging band. Basic frameworks are in place in several cases, but operational signals remain limited. France is the most notable country in this band given its size and AI ambitions — its awaiting designation status reflects an ongoing institutional process rather than settled enforcement architecture. The Netherlands scores in this band despite relatively strong market activity, held back by pending designation and limited published guidance. Sweden’s position is similarly explained by absent formal designation despite visible policy engagement.

Low (15–30 points): Latvia, Slovakia, Austria, Bulgaria, Croatia, Greece, Romania

Seven countries show minimal visible preparation or enforcement infrastructure, all with awaiting designation status. For businesses operating exclusively in these jurisdictions, enforcement risk in the immediate post-August 2026 period is lower — not because the regulation does not apply, but because the enforcement architecture is not yet in place.


What This Means for SMEs

The AI Act is a single regulation with uniform obligations across the EU. Enforcement is not uniform — and in the early phase after August 2026, that distinction matters.

For SMEs operating in a single Member State, the practical implication is straightforward: your compliance exposure is shaped in part by where your national competent authority stands. A business in a Ready jurisdiction should expect enforcement to be operational and active relatively quickly. A business in a Low jurisdiction may face a longer runway before enforcement mechanisms are fully functional — but that is not a reason to delay compliance preparation. The regulation applies regardless of whether the authority is ready to enforce it.

For SMEs operating across multiple Member States, the picture is more complex. Different authorities, different levels of operational readiness, and potentially different interpretations of shared obligations create a fragmented enforcement landscape. Monitoring developments in each relevant jurisdiction is not straightforward for a small business without dedicated legal or compliance resources.

Three practical points follow from the data:

First, authority designation status is a live variable. Several countries currently awaiting designation may move quickly in the coming months as the August deadline approaches. The readiness picture in June 2026 may look meaningfully different from today’s.

Second, the absence of a designated authority does not create a compliance-free zone. The regulation is in force. Obligations apply. Enforcement will follow once the institutional infrastructure catches up.

Third, for SMEs with cross-border exposure, understanding which national authority has jurisdiction over your specific AI systems — and what that authority’s current operational status is — is a concrete and actionable compliance step.


A Note on the Timeline: Postponement Is Advancing but Not Yet Final

Update: The Digital Omnibus agreement was reached on 7 May 2026. The December 2027 deadline is now confirmed pending formal vote and publication in the Official Journal.

On March 26, 2026, the European Parliament adopted its position on the Digital Omnibus on AI — a simplification package that includes postponement of certain high-risk AI system obligations — by 569 votes in favour, 45 against, and 23 abstentions. The Council adopted its own negotiating mandate on March 13. Trilogue negotiations between the two institutions and the European Commission have now formally begun.

The core proposal on the table: fixed alternative application dates of December 2, 2027 for high-risk AI systems listed in the regulation, and August 2, 2028 for systems covered by EU sectoral safety legislation. The rationale is that key harmonised standards are unlikely to be finalised by the current August 2, 2026 deadline.

This is not yet law. Trilogue negotiations must conclude and the final text must be formally adopted. But the direction is clear and the political majority is strong.

For SMEs, the practical implication is this: prohibited practices have been in force since February 2025. GPAI model obligations apply since August 2025. What August 2, 2026 brings is the full applicability of remaining provisions — including high-risk system rules and the Commission’s enforcement powers over GPAI. If the Digital Omnibus trilogue concludes in time, certain high-risk obligations may be postponed to December 2027. But the postponement is not yet law, and if trilogue fails to conclude, existing obligations remain unchanged.


What Comes Next

The enforcement landscape will continue to shift between now and August 2026 and beyond. Several Member States currently awaiting designation are likely to move before the full applicability date — political pressure and Commission scrutiny will accelerate some processes that have stalled.

A few signals worth watching in the coming months:

France’s designation process is the most significant pending development given the country’s size and the number of AI businesses operating there. A formal designation decision would move it meaningfully up the readiness scale.

The trilogue outcome on the Digital Omnibus will reshape the compliance calendar for high-risk AI systems. A concluded agreement before August 2026 would give businesses operating in that category significantly more time. A failed trilogue would leave the original timeline intact.

Regulatory sandboxes are an underrated signal of genuine enforcement intent. The Council’s negotiating position proposes postponing sandbox establishment requirements until December 2027 — if adopted, this would affect how several countries in the Emerging band are scored in future editions of this index.

The AI Act Readiness Index will be updated quarterly. The next edition will reflect the state of play as of June 2026 — six weeks before full applicability — and will track which countries have closed the gaps identified here, and how the trilogue outcome has affected the overall enforcement picture.


Conclusion

The EU AI Act is a single regulation. Its enforcement will not be uniform — at least not initially. The gap between the most prepared and least prepared Member States is structural, and it will take time to close.

For businesses operating in Europe, this is not an argument for waiting. Obligations apply regardless of whether the authority responsible for enforcing them is ready. But understanding where your jurisdiction stands — and what that means for your practical compliance exposure — is a concrete and useful starting point.

The data is there. The index will be updated as the picture develops.