AI Guide

Market Surveillance Authority (EU AI Act): The national body that polices AI already on the market

A market surveillance authority is the national body an EU member state designates under Article 70 of the EU AI Act to check whether AI systems already placed on the market keep complying with the regulation, and to act when they do not. It works after launch, unlike a notified body, which certifies certain systems before they reach the market. Learn below what these authorities can demand, how Germany has organized the role, and what a Mittelstand provider or deployer should have ready if one comes calling.

Key Facts
  • Article 70 of the EU AI Act required every EU member state to designate at least one market surveillance authority and a single point of contact by 2 August 2025.
  • Germany's KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG), in force since 29 July 2026, names the Bundesnetzagentur as the central market surveillance authority, single point of contact, and complaints office.
  • The Bundesnetzagentur is supported by the independent AI Market Surveillance Chamber (UKIM) and a coordination center (KoKIVO), while BaFin and the state media authorities keep sectoral oversight in finance and media.
  • Article 74 gives market surveillance authorities full access to a provider's technical documentation and training, validation, and testing datasets, and allows them to exercise these powers remotely.
  • Sprinkling Act's April 2026 EU AI Act Readiness Report, screening 50 European AI companies, found 74% trigger high-risk classification yet 96% have no dated, article-mapped compliance position an authority could review on request.

Definition: Market Surveillance Authority (EU AI Act)

A market surveillance authority is the national public body an EU member state designates under Article 70 of the EU AI Act to monitor, investigate, and enforce compliance of AI systems already placed on the market or put into service.

Core characteristics of market surveillance authority

The role is built around ongoing supervision, not a one-time approval before launch.

  • Designated by each member state and listed as its national competent authority and single point of contact
  • Empowered under Article 74 to demand technical documentation, datasets, and source code, and to act on systems remotely
  • Investigates complaints, incident reports, and market signals rather than certifying products before they ship
  • Can order corrective action, restrict or withdraw a system, or refer a case toward Article 99 fines

Market Surveillance Authority vs. Notified Body

A notified body certifies a narrow set of high-risk systems before they reach the market, under a contract the AI provider pays for. A market surveillance authority has no such contractual relationship and can open an inquiry into any deployed system, certified or not. Passing conformity assessment does not put a system beyond its reach; it only sets the baseline the authority checks against later.

Importance of market surveillance authority in enterprise AI

Enforcement only works if someone actually checks the market, and readiness on the company side is currently thin. Sprinkling Act’s April 2026 EU AI Act Readiness Report found 74% of 50 screened European AI companies trigger high-risk classification, yet 96% had no dated, article-mapped compliance position ready to show an authority, and Bitkom’s 2026 AI study found 85% of German SMEs have no documented inventory of the AI systems they run in the first place.

Methods and procedures for market surveillance authority

Authorities combine national organizational structure with EU-wide investigative powers.

Designation and organizational setup

Germany’s KI-MIG, in force since 29 July 2026, gives the Bundesnetzagentur the lead role, backed by dedicated internal structures rather than a single generalist office.

  • Bundesnetzagentur named central market surveillance authority, single point of contact, and complaints office
  • Independent AI Market Surveillance Chamber (UKIM) handles contested enforcement decisions
  • Coordination and competence center (KoKIVO) supports sector coordination and guidance
  • BaFin and the state media authorities keep responsibility for AI used in financial services and media

Investigation and documentation requests

Article 74 lets an authority request full access to a system’s technical documentation and training and validation data, exercised remotely where useful rather than only on-site.

Corrective measures and escalation

Where a system poses a risk or fails documented requirements, the authority can require corrective action or a withdrawal, and unresolved cases feed into the Article 99 fining process.

Important KPIs for market surveillance authority

Companies interacting with an authority track different indicators than during pre-market certification.

Operational response metrics

  • Time to first response after a documentation request: target days, not weeks
  • Share of Annex IV documentation that is current and retrievable on demand
  • Number of open findings from any prior inquiry, tracked to closure
  • Complaint and incident signals traceable back to a specific system owner

Strategic exposure metrics

Boards increasingly want to know how many deployed systems could survive a documentation request today. The 96% compliance-position gap that Sprinkling Act’s screening found suggests most companies would currently struggle to answer quickly.

Coordination quality metrics

Where a system touches a regulated sector, teams should track alignment between the Bundesnetzagentur and the sector regulator, since Germany’s hybrid model means BaFin or a state media authority may run the actual inquiry.

Risk factors and controls for market surveillance authority

Treating certification as permanent immunity

The most common error is assuming a CE mark or a completed conformity assessment closes the file for good.

  • Keep documentation current, not just accurate at the point of certification
  • Assign a named owner who can respond to a request without a scramble
  • Re-check classification whenever the system changes materially

Slow or uneven national capacity

Germany only reached a fully organized structure in mid-2026, and other member states remain behind, so response speed can still vary by jurisdiction.

Documentation not ready on request

A request can arrive with little warning, and teams storing documentation informally or across disconnected systems struggle to assemble a complete file inside a short deadline.

Practical example

A 140-employee manufacturer of predictive-maintenance sensors for industrial recycling equipment in North Rhine-Westphalia had classified its anomaly-detection model as a high-risk AI system under internal control. After a customer complaint about a missed fault flagged the product to the Bundesnetzagentur, the company received a documentation request under Article 74. Because the compliance owner kept Annex IV documentation and training-data records linked to the live product version, the team assembled a complete response within the requested window instead of reconstructing records under time pressure.

  • Named compliance owner responsible for keeping documentation retrievable, not just archived
  • Version-linked technical file that matches whatever build is currently deployed
  • Response playbook covering who replies, within what timeframe, and with what evidence
  • Post-inquiry review that folded the finding back into ongoing post-market monitoring

Current developments and effects

Three developments are shaping how market surveillance actually runs in 2026.

Germany’s structure went live mid-2026

The KI-MIG entered into force on 29 July 2026, well after the Article 70 designation deadline of 2 August 2025, meaning Germany operated for roughly a year under interim arrangements.

  • Bundesnetzagentur formally became the central authority in July 2026
  • UKIM and KoKIVO gave the office dedicated appeals and coordination capacity
  • Sector regulators retained their existing enforcement lanes rather than losing authority to a single office

Prohibited-practice and GPAI enforcement stayed on schedule

While the Digital Omnibus pushed most Annex III high-risk deadlines to December 2027, the prohibitions and general-purpose AI model duties that took effect earlier remain fully enforceable now, giving authorities live cases to work regardless of the extension.

Cross-border coordination is still forming

Authorities across member states are still building the administrative cooperation channels the regulation assumes, so a system sold across several EU countries can face inconsistent inquiry timelines depending on where a complaint originates.

Conclusion

A market surveillance authority is the enforcement half of the EU AI Act that most Mittelstand attention still overlooks in favor of pre-market certification questions. Its powers under Article 74 apply to any deployed system, whether or not a notified body was ever involved, and Germany’s Bundesnetzagentur has only recently stood up the full structure to use them. Readiness for an inquiry is less about the underlying AI system and more about whether documentation stays current and someone owns the response. Companies that treat market surveillance as a standing operational reality, not a one-time hurdle already cleared, are the ones an inquiry will not catch off guard.

Frequently Asked Questions

What does a market surveillance authority actually do?

It monitors AI systems already on the market, investigates complaints and incidents, and can demand documentation, order corrective action, or refer a case toward fines. It works after a system is deployed, not before.

How is a market surveillance authority different from a notified body?

A notified body certifies certain high-risk systems before market entry, under contract with the provider. A market surveillance authority has no such relationship and can investigate any deployed system at any time, certified or not.

Which authority is responsible for AI in Germany?

The Bundesnetzagentur, designated under the KI-MIG in force since 29 July 2026, acting as central market surveillance authority, single point of contact, and complaints office, except in financial services and media, where BaFin and state media authorities keep sectoral responsibility.

Does a market surveillance authority even look at companies with under 250 employees?

Yes. Article 70 and Article 74 apply regardless of company size, and complaints or incidents, not headcount, typically trigger an inquiry. Smaller Mittelstand providers and deployers of high-risk systems are within scope like anyone else.

What does it cost and how long does responding to an inquiry take?

Cost depends on how organized the documentation already is; companies with current Annex IV files and a named owner typically respond within the requested window, while those reconstructing records from scratch face far higher effort and risk missing the deadline.

Do we need our own IT team to handle a market surveillance request?

No. Most Mittelstand companies combine internal compliance ownership with an external partner for the underlying documentation. Companies like Superkind that build AI agents connected to real enterprise systems already log data flows and oversight points as part of the build, giving a request a ready evidence base instead of a blank page.

Building better software Contact us together