When the Regulator Comes Knocking: How AI Act Market Surveillance Works
Market surveillance authorities are getting ready to enforce the EU AI Act. What happens during an inspection? What triggers regulatory attention? And how can organizations prepare before authorities arrive?
The Enforcement Era Is Here
For two years, the AI Act has been primarily a compliance exercise — organizations have focused on understanding requirements, building documentation, and preparing for conformity assessment. But as the August 2026 deadline passes and market surveillance authorities become fully operational across the EU, the regulation enters its enforcement phase.
Understanding how EU market surveillance actually works — what triggers regulatory attention, what an inspection looks like, and what authorities can do — is essential preparation for every organization operating high-risk AI systems.
Who Are the Market Surveillance Authorities?
The AI Act establishes a two-tier enforcement structure. For most AI systems, enforcement is handled by national market surveillance authorities (MSAs) designated by each EU member state. Only GPAI models are directly supervised by the European AI Office in Brussels.
National MSA Approaches
- New dedicated agency (Spain's AESIA model): A new authority created specifically for AI Act enforcement with specialized technical and legal expertise
- Existing regulator expanded (Finland's Traficom): An existing sectoral regulator takes on AI Act responsibilities
- Distributed model (Germany): Multiple existing authorities share responsibilities by sector
What Triggers an Investigation?
1. Serious Incident Reports
When a provider or deployer files an Article 73 serious incident report, this automatically triggers regulatory engagement. Authorities assess its severity and may open a formal investigation if the incident suggests systemic non-compliance or ongoing risks.
2. Complaints from Affected Persons
Members of the public who believe they have been harmed by a high-risk AI system can file complaints with national MSAs. Expect concentrated complaints in high-volume sectors — credit scoring (rejected loan applicants), employment AI (unsuccessful job candidates), and healthcare AI (patients disputing clinical AI decisions).
3. Whistleblower Reports
The AI Act incorporates EU Whistleblower Directive protections. Former employees, contractors, and third parties with knowledge of non-compliance can report to authorities with legal protection. This makes internal AI governance culture a key risk factor.
4. Proactive Market Surveillance
Authorities will conduct planned inspections, particularly in high-priority sectors: employment and recruitment AI, credit and insurance AI, biometric identification systems, and healthcare AI with patient safety implications.
What Happens During an Inspection
Stage 1: Information Request
Authorities begin with a formal request for documentation: technical documentation per Annex IV, the EU Declaration of Conformity, conformity assessment records, quality management system documentation, post-market monitoring data, and instructions for use. Organizations should expect to respond within 15-30 days.
Stage 2: Document Review
Authorities review the submitted documentation against AI Act requirements, checking whether technical documentation covers all Annex IV elements, whether risk management meets Article 9, whether training data governance meets Article 10, and whether the conformity assessment was correctly applied.
Stage 3: On-Site Inspection
For more serious concerns, authorities may conduct on-site inspections where they can interview technical staff, compliance officers, and senior management; review technical systems and monitoring infrastructure; test the AI system directly; and assess whether human oversight mechanisms function as documented.
Stage 4: Independent Testing
Authorities can commission accredited testing bodies to conduct technical assessments, or use their own technical capacity to evaluate system performance and fairness, comparing real-world performance against the metrics claimed in technical documentation.
Regulatory Powers
| Measure | When Applied |
|---|---|
| Written warning | Minor non-compliances, first offence, good-faith effort demonstrated |
| Mandatory corrective action | Confirmed non-compliance requiring specific remediation |
| Use restriction | System poses risks; restricted pending remediation |
| Market withdrawal | System poses serious risks; must be removed from market |
| Administrative fine | Confirmed violations; proportionate to severity and organization size |
Factors That Mitigate Penalties
Organizations that demonstrate good-faith compliance efforts receive significantly more favorable treatment. Mitigating factors include voluntary cooperation with the investigation, proactive disclosure of compliance gaps, evidence of a genuine compliance program (budget, staffing, documented processes), prompt corrective action, no prior violations, and demonstrated harm prevention.
Building Enforcement Readiness
- Maintain audit-ready documentation: All technical documentation, risk assessments, and monitoring logs should be organized for rapid retrieval
- Designate a regulatory interface team: Identify in advance who will manage regulatory communications — legal counsel, the CAIO, and a technical lead
- Conduct internal mock audits: Periodically conduct internal compliance reviews that simulate a regulatory inspection
- Build relationships with national MSAs: Many member state authorities actively seek industry engagement through public consultations and sandbox programs
- Establish incident response protocols: Have a clear process for when a complaint is received, an incident is reported, or an inspection is announced
The question is no longer whether the AI Act will be enforced — it's when your sector and your systems will attract attention. The organizations best positioned are those that have built genuine compliance programs, not just compliance theatre.
Need help preparing for AI Act market surveillance? Browse our directory of AI compliance experts who can conduct pre-inspection readiness reviews.