Skip to main content
Category: EU AI Act & GPAI

Market Surveillance Authority

Also known as: MSA, Market Surveillance Authorities, national market surveillance authority
Simply put

A Market Surveillance Authority is a national body designated by an EU Member State to supervise and enforce rules that apply to products and systems placed on the EU market, including AI systems under the EU AI Act. In practice, this means checking that products meet applicable requirements and taking action when they do not. The specific authority varies by Member State, and in some cases an existing regulator (such as a national data protection authority) may be designated for AI-related supervision.

Formal definition

Under the EU AI Act framework, a Market Surveillance Authority is a national authority within each EU Member State responsible for supervising compliance with, and enforcing, the applicable rules governing AI systems placed on or made available in the EU market. These authorities operate within the broader EU product market surveillance architecture, which establishes cooperation processes across Member State enforcement, customs, and regulatory bodies. Member States designate which body serves this function, and designations may fall to sector-specific or existing regulators (for example, in the Netherlands, reporting indicates the national data protection authority is a likely candidate, though such designations should be confirmed against each Member State's implementing measures). Note that this term is specific to the EU regulatory context; it is not a model risk management concept and should not be conflated with internal validation or oversight functions. Precise scope, enforcement powers, and designations continue to develop as the AI Act is implemented across Member States.

Why it matters

Market Surveillance Authorities are a central mechanism through which the EU AI Act moves from written requirements to actual enforcement. For organizations placing AI systems on the EU market, the MSA is the national body that can check whether a product meets applicable requirements and take action when it does not. Understanding which authority holds this role in a given Member State is therefore a practical prerequisite for anticipating supervisory scrutiny, preparing for potential inspections, and understanding the consequences of non-compliance.

The significance is heightened by the decentralized nature of the arrangement: rather than a single EU-wide regulator, each Member State designates its own authority, and the specific body varies by country. In some cases an existing regulator, such as a national data protection authority, may be designated for AI-related supervision. As reported, the Dutch Data Protection Authority is a likely candidate in the Netherlands, though such designations should be confirmed against each Member State's implementing measures. This variation means that an organization operating across multiple Member States may face different supervisory bodies with potentially different practices, making it important to track designations jurisdiction by jurisdiction.

Because the AI Act is still being implemented across Member States, the precise scope, enforcement powers, and designations of MSAs continue to develop. Organizations should treat current understanding as provisional and monitor each Member State's implementing measures, rather than assuming a uniform or settled enforcement landscape across the EU.

Who it's relevant to

Compliance and regulatory affairs teams
Teams responsible for placing AI systems on the EU market need to identify which MSA supervises their products in each relevant Member State, since the designated body varies by country. This informs how they prepare for supervisory engagement and respond to enforcement action. Because designations and enforcement powers are still developing, these teams should confirm the current position against each Member State's implementing measures rather than assuming a uniform arrangement.
Legal and policy specialists
Legal advisers tracking EU AI Act implementation must understand that market surveillance is decentralized across Member States and coordinated through the broader EU product market surveillance architecture. They should note where an existing regulator, such as a national data protection authority, is a likely or confirmed designee, while treating unconfirmed reporting as provisional pending official implementing measures.
AI governance and risk professionals
Those building organizational AI governance programs should recognize the MSA as an external supervisory and enforcement body specific to the EU context, distinct from internal validation, oversight, or model risk management functions. Mapping the relevant external authorities helps align internal controls with the enforcement environment they are likely to encounter, without conflating external supervision with internal assurance activities.

Inside MSA

Designated national authority role
In the context of the EU AI Act, a market surveillance authority is a body designated by an EU Member State to supervise and enforce compliance for products or systems placed on the market within its jurisdiction. The specific institutional arrangements are set by each Member State, so the identity and structure of these authorities can vary across the EU.
Enforcement and supervisory powers
Market surveillance authorities are typically empowered to investigate, request documentation and information, and take corrective or restrictive action regarding non-compliant products. The precise scope of powers depends on the applicable legal instrument and jurisdiction, and should be verified against the governing legislation rather than assumed to be uniform.
Scope tied to placing on the market
The function is generally connected to products or systems that are made available or put into service in a given market. This orientation distinguishes it from internal organizational oversight and situates it as an external, public-authority form of supervision.
Relationship to conformity and compliance obligations
Market surveillance activity commonly follows from obligations imposed on providers or operators to meet defined requirements before and after a product reaches the market. The authority's role is to check adherence to those obligations, not to author them.

Common questions

Answers to the questions practitioners most commonly ask about MSA.

Is a Market Surveillance Authority the same as the body that certifies or approves an AI system before it goes to market?
No, and conflating the two is a common error. As commonly defined in the EU AI Act framework, a Market Surveillance Authority is primarily concerned with post-market oversight—monitoring products already placed on the market and taking enforcement action where non-compliance is found. This is typically distinct from pre-market conformity assessment activities, which in many cases involve notified bodies or the provider's own self-assessment. The distinction between pre-market conformity assessment and post-market surveillance matters for understanding when and how an authority intervenes.
Does the existence of a Market Surveillance Authority mean AI risks are eliminated once a system is on the market?
No. Market surveillance is an enforcement and oversight mechanism intended to detect and address non-compliance and reduce risk exposure; it does not eliminate risk. Its activities—such as monitoring, investigation, and corrective measures—are measures that manage or mitigate risk rather than guarantee that a compliant or safe outcome will result. Treating surveillance as a guarantee of safety misstates its function.
Which authority acts as the Market Surveillance Authority in a given jurisdiction, and how do we identify it?
The designation of a Market Surveillance Authority is typically a matter for the relevant jurisdiction to determine, and arrangements can vary by sector and by member state within the EU. Organizations should identify the specific authority applicable to their product category and geography rather than assuming a single universal body. Where the responsible authority is unclear, this should be confirmed against the applicable national implementing measures rather than assumed.
What kinds of information might a Market Surveillance Authority request from us?
In many frameworks, market surveillance functions rely on providers and other operators being able to supply documentation and information demonstrating compliance upon request. Organizations should ensure that governance documentation, technical records, and evidence of controls are maintained and retrievable in a form that can be produced if requested. The specific documentation expectations depend on the applicable regulatory instrument and product classification, so scope these requirements to your jurisdiction and sector.
How should our internal governance functions coordinate with potential market surveillance engagement?
Because market surveillance concerns post-market oversight, it is useful to assign clear internal responsibility for responding to inquiries and for triggering corrective action. This typically intersects with second and third line of defense functions, though the AI governance function (organizational accountability and oversight structures) is distinct from model risk management activities (identification, measurement, monitoring, and control of model-related risk). Organizations should define which function owns external regulatory communication without collapsing these roles into one another.
What corrective measures might follow a market surveillance finding of non-compliance?
Enforcement outcomes vary by jurisdiction and by the applicable legal instrument, and can range from requiring corrective action to more restrictive measures affecting a product's availability. Because the precise powers and procedures depend on the governing law and its national implementation, organizations should confirm the specific measures available to the relevant authority rather than assuming a standard set. Building an internal process for implementing and documenting corrective action supports readiness, but the applicable consequences should be verified against the controlling regulation.

Common misconceptions

A market surveillance authority is the same as an organization's internal AI governance or model risk management function.
A market surveillance authority is an external public body exercising supervisory and enforcement functions over products placed on a market. This is distinct from an organization's internal AI governance (its own policies, accountability structures, and oversight) and from model risk management (internal identification, measurement, monitoring, and control of model risk). The internal functions manage risk within the firm; the market surveillance authority supervises compliance from outside, and the two should not be conflated.
There is a single, uniform market surveillance authority that applies across all jurisdictions and regulatory frameworks.
As commonly used in the EU AI Act context, market surveillance authorities are designated at the Member State level, so their identity, structure, and specific powers can differ. The term should not be treated as interchangeable across frameworks such as the NIST AI RMF, ISO/IEC 42001, or supervisory guidance like SR 11-7, which involve different issuing bodies, jurisdictions, and legal status.
Oversight by a market surveillance authority guarantees that a product is free of risk.
Supervision and enforcement are measures intended to check compliance and reduce or manage risk, not to eliminate it. The existence of an authority does not certify that a product carries no residual risk, and compliance status should not be read as an absolute assurance of safety or performance.

Best practices

Verify which specific national or regional body acts as the market surveillance authority for the relevant jurisdiction and product category, rather than assuming a single uniform authority applies.
Maintain clear internal separation between the organization's own AI governance and model risk management functions and the external supervisory role of a market surveillance authority, and document how each interacts.
Confirm the scope of the authority's powers against the governing legal instrument before assuming what documentation, cooperation, or corrective actions may be required.
Keep compliance evidence and technical documentation organized and readily producible, anticipating that a market surveillance authority may request information or conduct investigations.
Track jurisdiction-specific designations and any changes to them, since institutional arrangements can vary and evolve across Member States or regulatory regimes.
Treat compliance with market surveillance requirements as a risk-reduction measure and continue internal monitoring, rather than treating external oversight as an elimination of residual risk.