Skip to main content
Europe's AI Act Rollout: What Italy's First-Mover Advantage RevealsCompliance & Audit
5 min readFor AI Governance Leaders

Europe's AI Act Rollout: What Italy's First-Mover Advantage Reveals

The European Union's AI Act became binding law in August 2024. By October 2025, only Italy had passed implementing legislation, with Law No. 132/2025 coming into force on October 10, 2025. What can your compliance team learn from the gap between regulatory intent and operational reality?

The Challenge

The AI Act requires each member state to designate market surveillance authorities, notifying authorities, and a single point of contact before enforcement begins. Yet, as of mid-2026, implementation remains uneven. While Italy moved decisively, other states are still drafting proposals or debating agency roles.

This isn't just an administrative delay. The regulation's effectiveness depends on coherent cross-border enforcement. If your AI system operates in multiple jurisdictions, you face a coordination problem: which authority reviews your conformity assessment? Who handles post-market surveillance if an incident occurs? What happens when national interpretations diverge?

The challenge is structural. The AI Act delegates implementation to national governments but doesn't prescribe organizational models. Some states are building centralized structures around single agencies. Others are distributing responsibilities across existing regulators. A few have yet to commit to either approach.

Environment and Constraints

Consider the constraints facing national governments:

Existing regulatory architecture. Most member states already have data protection authorities, telecommunications regulators, financial supervisors, and product safety agencies. The question is how to map AI governance onto institutions with established mandates and limited resources.

Technical complexity. AI systems cut across sectors. A General-Purpose AI Model might be used in healthcare, finance, and critical infrastructure simultaneously. Designating a single market surveillance authority means choosing an agency with cross-sectoral expertise or accepting fragmented oversight.

Political coordination. Implementation requires legislative action or executive decrees. In some states, this means navigating coalition governments, parliamentary processes, or federal-state negotiations. For instance, Germany's draft AI Market Surveillance and Innovation Promotion Act, adopted by the Federal Cabinet on February 10, 2026, still requires passage through the Bundestag and Bundesrat.

Approaches Taken

Three distinct implementation models have emerged:

Centralized model (Italy, Cyprus, Lithuania). Italy designated the National Cybersecurity Agency (ACN) as the market surveillance authority and single point of contact, with the Agency for Digital Italy (AgID) as notifying authority. This approach concentrates expertise but requires the lead agency to develop capacity across all AI risk categories.

Decentralized model (Finland, Ireland, Netherlands). Finland's Law 1377/2025 appointed multiple existing market surveillance authorities, with the Finnish Transport and Communications Agency (Traficom) as the single point of contact. Ireland designated 15 existing bodies as market surveillance authorities under Statutory Instrument No 366 of 2025. This distributes the burden but creates coordination overhead.

Hybrid or unclear status (majority of member states). As of mid-2026, countries including Austria, Belgium, Bulgaria, Croatia, Estonia, Greece, and Romania have not yet appointed authorities. Some have published legislative proposals or established working groups. Others have indicated which ministry is coordinating implementation but haven't formalized designations.

Results and Observations

Italy's early implementation shows that a centralized model can move quickly when political will exists. The law entered into force within 14 months of the AI Act's adoption. However, speed doesn't guarantee operational readiness. The National Cybersecurity Agency now faces the task of building AI-specific validation expertise, developing sector-specific guidance, and coordinating with the five authorities listed in the European Commission's consolidated list for Italy.

Denmark's Law No. 467, effective August 2, 2025, designates the Danish Agency for Digital Government as the coordinating authority alongside the Data Protection Authority and Court Administration. Denmark also established a working group to engage civil society, industry, public institutions, and academia regularly, signaling an intent to build stakeholder engagement into ongoing implementation.

Finland's approach, effective January 1, 2026, distributed responsibilities across eight published authorities with two additional authorities in the Commission's consolidated list. This model uses existing sectoral expertise but requires Traficom to coordinate across agencies with different cultures and processes.

The Netherlands published draft legislation in April 2026 proposing ten sectoral authorities acting as both market surveillance and notifying authorities, including the Data Protection Authority and the State Inspectorate for Digital Infrastructure. The Dutch Data Protection Authority and the State Inspectorate for Digital Infrastructure share the coordinating role.

Lessons Learned

No member state has published a formal retrospective, but the implementation timeline itself reveals lessons:

Early designation doesn't mean operational capacity. Appointing an authority is a legal act. Building the technical staff, validation protocols, and cross-agency coordination mechanisms to enforce the AI Act is a multi-year operational project. States that moved quickly on designation now face the harder work of capability-building.

Decentralization requires governance overhead. Finland's model distributes risk across agencies but requires Traficom to maintain coherence. Ireland's 15-authority structure will need clear escalation paths, shared technical standards, and a mechanism for resolving jurisdictional disputes.

Stakeholder engagement takes time. Denmark's working group model and Norway's AI Norway initiative (established within the Norwegian Digitalisation Agency) suggest that states are recognizing the need for ongoing dialogue with industry, academia, and civil society, not just one-time consultation during drafting.

Takeaways for Your Compliance Team

If you're operating across multiple EU member states, you can't wait for harmonization to emerge organically. Here's what the current landscape demands:

Map your authority landscape now. For each jurisdiction where you deploy AI systems, identify which agencies appear in the European Commission's consolidated list. Track legislative proposals and government announcements. Don't assume that the data protection authority will be your primary contact; telecommunications regulators, sectoral supervisors, and newly created AI agencies are all in play.

Prepare for asymmetric enforcement. States with centralized models and early implementation will likely begin active market surveillance sooner. States with decentralized models may take longer to coordinate but could bring more sectoral expertise to specific use cases. Your conformity assessment and Technical Documentation (Annex IV) should be portable across these models.

Build relationships before incidents occur. If you're a provider of high-risk AI systems or General-Purpose AI Models, you'll interact with national authorities for conformity assessments, post-market surveillance, and potentially incident reporting. Establish contact with designated authorities early. Understand their interpretation of key requirements, their preferred documentation formats, and their expectations for responsible disclosure.

Don't rely on single-country precedent. Italy's implementation doesn't set binding precedent for other member states. Each country's legislative choices will reflect its existing regulatory culture, institutional capacity, and political priorities. Your compliance program needs to flex across these variations.

Monitor the single point of contact. The AI Act requires each state to designate a single point of contact for cross-border coordination. This is your escalation path when you encounter conflicting guidance or jurisdictional uncertainty. Track which agencies hold this role and how they're staffing it.

The AI Act promised harmonization. What it's delivering, at least in the near term, is coordinated fragmentation. Your compliance strategy needs to account for that reality.

You Might Also Like