Article 70 of 11362%
Article 70: Designation of national competent authorities and single points of contact
EU Official:
Title VIII: Post-Market Monitoring & Surveillance
Article 70 requires each Member State to designate at least one notifying authority and one market surveillance authority as national competent authorities, plus a single point of contact.
Official text
||
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF)→Official guidance on this article
6- Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)Explicitly marks the dividing line between the role of the EDPS as data protection supervisor and its role as competent authority for EU institutions under the AI Act, so it is clear which supervision track applies whenPublishedGuidelinesEDPS (European Data Protection Supervisor)28 Oct 2025
- Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act frameworkSubstantiates why the data protection authority should also be the single point of contact under Article 70(2) and that the EDPS is the competent authority under Article 70(9) for EU institutions.PublishedOpinionEDPB (European Data Protection Board)16 Jul 2024
- Cabinet takes step towards supervision of European AI rulesExplains the political choice behind the designation of national competent authorities, namely to align with supervisors that organisations already know instead of establishing a new AI supervisorPublishedNational guidanceGovernment of the Netherlands (State Secretary for Digital Economy and Sovereignty)20 Apr 2026
- AI-verordening (Rijksinspectie Digitale Infrastructuur)Describes how the Netherlands fulfils the designation of national competent authorities and market supervisors, with a coordinating role for the Digital Infrastructure Inspectorate and Personal Data Authority alongside sectoral supervisorsPublishedNational guidanceDutch Authority for Digital Infrastructure (RDI)
- Final advice on the design of AI supervision in the NetherlandsIs the underlying supervisor advice on which the later designation of ten national competent authorities is basedPublishedOpinionDutch Authority for Digital Infrastructure (RDI) and Dutch Data Protection Authority (AP)7 Nov 2024
- Public consultation on the Dutch AI Regulation Implementation Act (Uitvoeringswet AI-verordening)Fulfils the Member State obligation to designate national competent authorities by naming ten existing Dutch supervisors as market supervisory authoritiesConsultationNational guidanceMinistry of Justice and Security / Government of the Netherlands (through internetconsultatie.nl)20 Apr 2026
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related blog posts
Related articles
Frequently asked questions
What authorities must Member States designate under Article 70 AI Act?+
Article 70 requires each Member State to designate at least one notifying authority and one market surveillance authority as national competent authorities, plus a single point of contact.
Do SMEs also need to comply with Article 70 of the AI Act?+
Article 70 of the AI Act does not provide a general exemption for SMEs. However, the AI Act includes supportive measures and potentially lighter obligations for small and medium-sized enterprises, depending on their role in the AI value chain.
How does Article 70 of the AI Act relate to the GDPR?+
Article 70 of the AI Act complements the GDPR. While the GDPR protects personal data, the AI Act focuses on the safety and trustworthiness of AI systems. Organisations must comply with both regulations when their AI system processes personal data.
What are the deadlines for Article 70 of the AI Act?+
The AI Act follows a phased implementation. Prohibited AI practices apply from February 2025, obligations for high-risk AI systems from August 2026, and other provisions take effect gradually. The specific deadline for Article 70 depends on the category of the obligation.
Does Article 70 of the AI Act also apply to AI systems I purchase?+
Yes, Article 70 of the AI Act may also be relevant when you purchase AI systems. As a deployer, you have your own obligations under the AI Act, regardless of whether you developed the system yourself or purchased it from a provider.
What is the difference between provider and deployer under Article 70 of the AI Act?+
Under Article 70 of the AI Act, the provider is the entity that develops or places the AI system on the market, while the deployer is the entity that uses the system under its own authority. Both roles carry different obligations.
What documentation does Article 70 of the AI Act require?+
Article 70 of the AI Act requires that relevant documentation is maintained as part of the compliance process. This may include technical documentation, instructions for use, logs or declarations of conformity, depending on the classification of the AI system.
How do I document compliance with Article 70 of the AI Act?+
You document compliance with Article 70 of the AI Act by establishing a risk management system, maintaining technical documentation, and conducting internal audits. Keep all relevant documents for the period prescribed by the AI Act.