Skip to content

Regulation Tracker / EU AI Act / Chapter VII · Section 2

Article 70
Designation of national competent authorities and single points of contact

Chapter VII — AI Office, Section 2 — Designation of national competent authorities and single points of contact. 4 distinct duties, powers or definitions are coded from this article, applying from 2025-08-02.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 3 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. Each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of this Regulation. Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and tasks, and to ensure the application and implementation of this Regulation. The members of those authorities shall refrain from any action incompatible with their duties. Provided that those principles are observed, such activities and tasks may be performed by one or more designated authorities, in accordance with the organisational needs of the Member State.

2. Member States shall communicate to the Commission the identity of the notifying authorities and the market surveillance authorities and the tasks of those authorities, as well as any subsequent changes thereto. Member States shall make publicly available information on how competent authorities and single points of contact can be contacted, through electronic communication means by 2 August 2025. Member States shall designate a market surveillance authority to act as the single point of contact for this Regulation, and shall notify the Commission of the identity of the single point of contact. The Commission shall make a list of the single points of contact publicly available.

3. Member States shall ensure that their national competent authorities are provided with adequate technical, financial and human resources, and with infrastructure to fulfil their tasks effectively under this Regulation. In particular, the national competent authorities shall have a sufficient number of personnel permanently available whose competences and expertise shall include an in-depth understanding of AI technologies, data and data computing, personal data protection, cybersecurity, fundamental rights, health and safety risks and knowledge of existing standards and legal requirements. Member States shall assess and, if necessary, update competence and resource requirements referred to in this paragraph on an annual basis.

4. National competent authorities shall take appropriate measures to ensure an adequate level of cybersecurity.

5. When performing their tasks, the national competent authorities shall act in accordance with the confidentiality obligations set out in Article 78.

6. By 2 August 2025, and once every two years thereafter, Member States shall report to the Commission on the status of the financial and human resources of the national competent authorities, with an assessment of their adequacy. The Commission shall transmit that information to the Board for discussion and possible recommendations.

7. The Commission shall facilitate the exchange of experience between national competent authorities.

8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs, including start-ups, and SMCs, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.

9. Where Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as the competent authority for their supervision.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 70(1)Governance institutionalNot tier-specific

    Each Member State must establish or designate at least one notifying authority and at least one market surveillance authority, which must exercise powers independently, impartially and without bias.

    "Each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of this Regulation. Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and"
    Who
    Member State, National competent authority
    From
    (Art. 113(b))
    Legal practice
    Institutional — Institutional governance mechanics; indirect relevance to legal practices through oversight and guidance.
  2. Art. 70(2)Cooperation with authoritiesNot tier-specific

    Member States must communicate authority identities and tasks and later changes to the Commission, publish contact information by 2 August 2025, designate a single point of contact and notify it, and the Commission must publish the list.

    "Member States shall communicate to the Commission the identity of the notifying authorities and the market surveillance authorities and the tasks of those authorities, as well as any subsequent changes thereto. Member States shall make publicly available information on how competent authorities and single points of contact can be contacted, through electronic"
    Who
    Member State, Commission
    From
    (Art. 113(b))
    Legal practice
    Institutional — Institutional governance mechanics; indirect relevance to legal practices through oversight and guidance.
  3. Art. 70(3)Governance institutionalNot tier-specific

    Member States must resource national competent authorities, assess resources annually, ensure adequate cybersecurity and confidentiality, and report resource status to the Commission every two years from 2 August 2025 for Board discussion.

    "Member States shall ensure that their national competent authorities are provided with adequate technical, financial and human resources, and with infrastructure to fulfil their tasks effectively under this Regulation. In particular, the national competent authorities shall have a sufficient number of personnel permanently available whose competences and expertise shall include an in-depth"
    Who
    Member State, National competent authority, Commission
    From
    (Art. 113(b))
    Legal practice
    Institutional — Institutional governance mechanics; indirect relevance to legal practices through oversight and guidance.
    See
    Art. 78
  4. Art. 70(7)Support measureNot tier-specific

    The Commission must facilitate exchanges among national competent authorities, national authorities may provide guidance and consult other Union-law authorities where relevant, and the EDPS supervises Union institutions, bodies, offices and agencies.

    "The Commission shall facilitate the exchange of experience between national competent authorities."
    Who
    Commission, National competent authority, Member State, Union institution
    From
    (Art. 113(b))
    Legal practice
    Institutional — Institutional governance mechanics; indirect relevance to legal practices through oversight and guidance.

Cite

Regulation (EU) 2024/1689, Article 70 (Designation of national competent authorities and single points of contact), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_70 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-70, accessed 2026-09-08, CC BY 4.0.