LinkedInInstagramXTikTok

Who enforces the EU AI Act in Sweden? The five authorities and what they supervise

Why it matters that Sweden has five AI regulators, not one

Most businesses reading about the EU AI Act picture a single regulator. Sweden does not work that way. In June 2026 the government designated five national competent authorities, each with a defined slice of the Act, and the slices are drawn by article and by Annex III category rather than by industry.

The practical consequence is that two AI systems in the same company can answer to two different regulators. A bank running a credit-scoring model deals with Finansinspektionen; the same bank’s biometric access control sits with Integritetsskyddsmyndigheten. Knowing which door you are knocking on is not a formality — it determines who you notify, who inspects you and who you argue with.

The decision behind the split

The designation was made by government decision Uppdrag att vara nationella behöriga myndigheter enligt AI-förordningen, diarienummer Fi2026/01365, published on 12 June 2026. It names Post- och telestyrelsen (PTS), Integritetsskyddsmyndigheten (IMY), Finansinspektionen, Läkemedelsverket and Styrelsen för ackreditering och teknisk kontroll (Swedac).

Two features of that decision deserve attention before anything else. First, it is an assignment, not legislation — a regeringsuppdrag rather than a statute. Second, it is explicitly time-limited: the assignment runs to 31 December 2026. It is a bridge, put in place because Sweden’s permanent supplementary legislation is not finished.

Who supervises what

Post- och telestyrelsen

PTS carries the widest brief. It is the single point of contact under Article 70(2), which makes it Sweden’s addressable interface toward the Commission, the AI Office, the AI Board and other Member States’ authorities. It also leads a national coordination function across the Swedish authorities, and holds the assignment to establish Sweden’s AI regulatory sandbox.

On supervision, PTS covers the Article 5 prohibitions as they relate to Annex III points 2 to 4, 5(a) and 5(d), and the corresponding high-risk systems under Article 6(2) — critical infrastructure, education and vocational training, employment and worker management, essential public assistance benefits and services, and emergency response dispatch and triage. It also supervises high-risk AI under Article 6(1) tied to the Radio Equipment Directive.

Note carefully what the contact point role is not. It does not give PTS authority over the other authorities’ areas. Coordination here means convening, not directing.

Integritetsskyddsmyndigheten

IMY is the residual authority for prohibited practices: it covers all Article 5 prohibitions except those allocated to PTS and Finansinspektionen. That default position makes IMY Sweden’s primary prohibited-practices regulator in practice.

On high-risk systems under Article 6(2), IMY takes Annex III point 1 (biometrics), point 5(b) outside Finansinspektionen’s supervisory scope, and points 6, 7 and 8 — law enforcement, migration, asylum and border control, and the administration of justice and democratic processes.

Finansinspektionen

Finansinspektionen covers the financial slice: Article 5 as it relates to Annex III point 5(b) within its supervisory scope and point 5(c), and the corresponding high-risk systems under Article 6(2). In plain terms, that is creditworthiness assessment and credit scoring of natural persons, and risk assessment and pricing for life and health insurance.

For banks, lenders, insurers and fintechs, this is the single most useful fact in this article. Your AI Act regulator is the regulator you already have.

Läkemedelsverket and Swedac

Läkemedelsverket supervises high-risk AI under Article 6(1) tied to the Medical Devices Regulation and the In Vitro Diagnostic Regulation, and acts as the notifying authority for conformity assessment bodies in that field. Swedac is the notifying authority for conformity assessment bodies covering the remaining high-risk AI. Sweden therefore has no single notifying authority — the function is split between the two.

The Article 50 transparency split

The transparency duties in Article 50 are divided between two regulators, and this catches people out. PTS holds Article 50(1), 50(2) and 50(4) — disclosure that a person is interacting with an AI system, machine-readable marking of synthetic content, and deepfake and AI-generated text disclosure. IMY holds Article 50(3), the duty to inform people exposed to emotion recognition and biometric categorisation systems.

So a company running a customer chatbot and an emotion-recognition tool has two different supervisors for what feels like one obligation.

The gap: Sweden cannot yet fine anyone

This is the part most commentary leaves out, and it is the part businesses most need to understand — in both directions.

Article 99 of the AI Act obliges Member States to lay down rules on penalties. Sweden has not done so. Under Swedish constitutional principle an administrative sanction charge requires a statutory basis, and no such statute exists for the AI Act. The inquiry report SOU 2025:101 proposed the missing machinery — a coordinating market surveillance authority, eleven market surveillance authorities in total, and powers of anmärkning, sanktionsavgift and föreläggande med eller utan vite — and proposed entry into force on 2 August 2026. That date passed without a proposition.

The result is an enforcement trough: designated authorities, an interim mandate, and no penalty toolkit. What the five authorities can do today is investigate, receive complaints, engage informally and act as the EU interface.

The wrong conclusion to draw is that nothing applies. The obligations in the AI Act are directly applicable EU law and bind you from their own dates regardless of what Sweden has legislated. What is missing is the Swedish machinery for punishing breaches, not the breaches themselves. Nothing suggests a future Swedish act will forgive the interim period, and none of this touches your civil or contractual exposure to customers and counterparties.

What Sweden has actually legislated

One piece is enacted. Proposition 2025/26:150 on the police use of AI for real-time facial recognition entered into force on 1 July 2026, implementing the narrow Article 5(1)(h) exception and the Article 5(3) prior-authorisation requirement, with prosecutors authorising preventive use and courts authorising investigative use. Sweden’s supplementary framework is therefore not a complete void — it is one enacted sliver and a large unlegislated remainder.

Practical example

A Stockholm insurtech runs three AI systems: a pricing model for health insurance, a chatbot on its website, and a document-classification tool used internally.

The pricing model falls in Annex III point 5(c), so Finansinspektionen is the supervisor, and the high-risk obligations apply from 2 December 2027 following the Digital Omnibus deferral. The chatbot engages Article 50(1), which applied from 2 August 2026 and is supervised by PTS — a live obligation today, not a 2027 one. The document tool is most likely neither high-risk nor caught by Article 50, and needs a documented classification rather than a compliance programme.

Three systems, two regulators, two very different timelines, and only one of them urgent. That triage is the work.

Common mistakes companies make

The first is assuming IMY handles everything because it handles the GDPR. IMY has a substantial AI Act role, but critical infrastructure, education, employment and most transparency duties sit with PTS, and financial use cases sit with Finansinspektionen.

The second is reading the absence of Swedish sanctions as an absence of obligation. The duties bind now; only the Swedish penalty machinery is missing.

The third is treating the current allocation as settled. The assignment expires on 31 December 2026 and SOU 2025:101 proposes a different structure, including a formally designated coordinating authority and nine further sectoral regulators. Build your compliance around the obligations, not around the current org chart.

The fourth is missing that Article 50 is split by sub-paragraph. Companies notify PTS about an emotion-recognition question and lose weeks.

Recommended actions

Inventory your AI systems and map each one to an Annex III point, then to the authority that holds it. That mapping is your regulator list, and it is not obvious from the outside. Where a system is not high-risk, write down why — a documented classification is itself a compliance artefact.

Deal with Article 50 first, because it is the obligation that is actually live. Confirm your chatbot disclosure, synthetic content marking and any emotion-recognition notices, and remember that systems on the market before 2 August 2026 have a transitional period running to 2 December 2026 for machine-readable marking.

Use the runway to December 2027 on classification, data governance and documentation rather than waiting for Swedish legislation. Watch two dates: 31 December 2026, when the interim mandate must be renewed or replaced, and the eventual proposition following SOU 2025:101. And if you are building Annex III systems, register your interest with PTS on the sandbox, which must be operational by 2 August 2027.

Frequently asked questions

Can a Swedish authority fine us for an AI Act breach today?

No. Sweden has not enacted the penalty rules Article 99 requires, and an administrative sanction charge needs a statutory basis in Swedish law. The authorities can investigate, request information and engage with you, but there is currently no Swedish basis for an AI Act sanktionsavgift. This is a gap in enforcement machinery, not in the obligations, and it is expected to close.

Which authority do we contact if we are not sure?

PTS is the single point of contact under Article 70(2) and leads the national coordination function, so it is the sensible first call when the allocation is genuinely unclear. If your use case is financial, go directly to Finansinspektionen; if it involves biometrics, law enforcement or migration, go to IMY.

Does the designation change after December 2026?

It may. The assignment runs to 31 December 2026 and was made pending permanent legislation. SOU 2025:101 proposes a broader structure with a formally designated coordinating market surveillance authority and additional sectoral regulators. Until a proposition is presented and passed, the current five-authority allocation is what applies.

Conclusion

Sweden has five AI Act authorities, an allocation drawn by article and Annex III category rather than by sector, a transparency regime split between two of them, and no power to fine anyone until Parliament legislates. For businesses that combination is unusual but not comfortable: the obligations are live and directly applicable, the runway to December 2027 is short for anyone with high-risk systems, and the supervisory map will likely change again once SOU 2025:101 produces a bill. Lawgent helps businesses identify which Swedish authority supervises each of their AI systems, prepare for the obligations that are already in force, and build compliance that survives the coming change in the supervisory structure.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop