Market Surveillance Authority
A Market Surveillance Authority is a national body designated by an EU Member State to supervise and enforce rules that apply to products and systems placed on the EU market, including AI systems under the EU AI Act. In practice, this means checking that products meet applicable requirements and taking action when they do not. The specific authority varies by Member State, and in some cases an existing regulator (such as a national data protection authority) may be designated for AI-related supervision.
Under the EU AI Act framework, a Market Surveillance Authority is a national authority within each EU Member State responsible for supervising compliance with, and enforcing, the applicable rules governing AI systems placed on or made available in the EU market. These authorities operate within the broader EU product market surveillance architecture, which establishes cooperation processes across Member State enforcement, customs, and regulatory bodies. Member States designate which body serves this function, and designations may fall to sector-specific or existing regulators (for example, in the Netherlands, reporting indicates the national data protection authority is a likely candidate, though such designations should be confirmed against each Member State's implementing measures). Note that this term is specific to the EU regulatory context; it is not a model risk management concept and should not be conflated with internal validation or oversight functions. Precise scope, enforcement powers, and designations continue to develop as the AI Act is implemented across Member States.
Why it matters
Market Surveillance Authorities are a central mechanism through which the EU AI Act moves from written requirements to actual enforcement. For organizations placing AI systems on the EU market, the MSA is the national body that can check whether a product meets applicable requirements and take action when it does not. Understanding which authority holds this role in a given Member State is therefore a practical prerequisite for anticipating supervisory scrutiny, preparing for potential inspections, and understanding the consequences of non-compliance.
The significance is heightened by the decentralized nature of the arrangement: rather than a single EU-wide regulator, each Member State designates its own authority, and the specific body varies by country. In some cases an existing regulator, such as a national data protection authority, may be designated for AI-related supervision. As reported, the Dutch Data Protection Authority is a likely candidate in the Netherlands, though such designations should be confirmed against each Member State's implementing measures. This variation means that an organization operating across multiple Member States may face different supervisory bodies with potentially different practices, making it important to track designations jurisdiction by jurisdiction.
Because the AI Act is still being implemented across Member States, the precise scope, enforcement powers, and designations of MSAs continue to develop. Organizations should treat current understanding as provisional and monitor each Member State's implementing measures, rather than assuming a uniform or settled enforcement landscape across the EU.
Who it's relevant to
Inside MSA
Common questions
Answers to the questions practitioners most commonly ask about MSA.