AI Act enforcement in Belgium

What is AI Act enforcement in Belgium?

The AI Act is a European regulation, but the people who knock on your door are national. Every member state has to name a market surveillance authority that inspects AI systems, handles complaints and imposes fines, plus a notifying authority that accredits the bodies certifying high-risk systems. Belgium has said which regulator it wants for that job, and as of 4 September 2026 the law that gives it the powers has still not been passed. So the duties in the regulation apply to your company in full, while the office that is supposed to check them is not yet legally in place.

Enforcement runs on two floors. The European Commission's AI Office polices the large model providers directly. Everything else, so the chatbot on your site, the screening tool in your HR software, the camera analytics in your shop, belongs to national authorities. Your dealings, if you ever have any, will almost always be with the Belgian floor.

The EU floor: the AI Office, the AI Board and the Commission

The AI Office is a unit inside the Commission with well over a hundred staff. It supervises providers of general-purpose AI models, so OpenAI, Google, Anthropic, Mistral and the like, on its own. Article 101 lets the Commission fine those providers up to 15 million euros or 3 percent of worldwide turnover, whichever is higher, without going through a national authority. The Digital Omnibus of July 2026 widened that remit: the AI Office now also has exclusive supervision over certain AI systems built by those same providers on top of their own models, and over AI systems inside very large online platforms and search engines, and it can add periodic penalty payments while an infringement continues.

For a Belgian SME the practical meaning is simple. If the problem sits in the model itself, in ChatGPT or Gemini or Claude, it is the AI Office's case and you are not the one being investigated. If the problem sits in what your company built or bought around such a model, it is national.

The AI Board has one representative per member state, with the AI Office as secretariat, and its job is to keep 27 national authorities reading the regulation the same way. It has a standing sub-group on market surveillance for exactly that.

The Commission's guidelines matter more than their name suggests. The guidelines on prohibited practices, on the definition of an AI system, and the code of practice on Article 50 labelling are what a national inspector will use as a yardstick. The Commission also runs the AI Act Service Desk, a portal with a compliance checker and a contact form where the AI Office answers questions from companies.

The Belgian floor: who has been named, and what is legal today

The federal government agreement of 31 January 2025 gave the role of central AI Act authority to BIPT, the regulator for telecom and post. In the model the government described, BIPT coordinates, supplies technical AI expertise to the sector regulators and is the single contact point between them, while FOD Economie coordinates the implementation and prepares the law. Minister Clarinval, answering a parliamentary question in December 2025, said that no new market surveillance authorities would be created: the existing sector regulators keep their domain and get AI added to it.

Some of that allocation follows from the regulation itself. Article 74 makes the financial supervisor the market surveillance authority for high-risk AI used by banks and insurers, so in Belgium that points to FSMA and the Nationale Bank. For the Annex III uses in policing, migration and justice the member state has to appoint either the data protection authority or another body; which one Belgium picks is unconfirmed.

What has been done: FOD Economie published the Article 77 list of Belgian bodies that protect fundamental rights and can ask the market surveillance authority for documentation or for a technical test of a high-risk system. It runs to around thirty names across the federal, regional and community levels, from the Gegevensbeschermingsautoriteit, Unia and Myria to the labour inspection, the Centre for Cybersecurity Belgium and the Vlaamse Toezichtcommissie.

What has not been done: the designation law. The EU deadline was 2 August 2025. At the end of July 2026 VRT NWS reported that Belgium still had no officially appointed supervisor, and Etienne Mignolet of FOD Economie confirmed that the reading of a legal vacuum is correct and that, from 2 August 2026, the rights in the regulation can only be enforced through the courts. FOD Economie's own FAQ, last updated on 3 September 2026, still describes the Belgian governance framework as ongoing work. Who supervises AI in education and employment services, which are regional competences, depends on a federal-regional agreement that was not yet concluded either.

Unconfirmed as of this writing: the exact text of the bill, the date it goes to parliament, and whether BIPT ends up as the formal single point of contact under Article 70 or only as the technical coordinator.

What an investigation looks like

How it starts: complaints under Article 85

Article 85 gives any natural or legal person who believes the regulation has been infringed the right to lodge a complaint with the market surveillance authority. The authority has to take the complaint into account in its surveillance work and handle it under its own procedures. That includes competitors. A candidate who suspects your video interview tool scores emotions, a customer who got no answer to "am I talking to a bot", a rival who thinks your AI-generated product images carry no label: all three have standing.

Until the Belgian law passes, there is no office to send that complaint to. The routes that do exist today are the courts, the Gegevensbeschermingsautoriteit whenever personal data are involved, and the sector regulator where one already has AI on its plate. The obligations bind you either way.

The inspection itself

Article 74 plugs the AI Act into the general EU market surveillance regulation, the same toolkit used for toys and machinery. That regulation lets the authority demand documents and data, carry out unannounced on-site inspections, enter business premises, buy samples under a cover identity to test them, and order online content taken down. The AI Act adds full access, on request, to the provider's technical documentation and to the training, validation and testing datasets. Source code can be requested too, but only with a reasoned request, when other ways of checking have been exhausted.

For a deployer the questions will be more modest and mostly about paper: the instructions for use from your vendor, the record of who oversees the system, the logs the system generates (the AI Act asks deployers of high-risk systems to keep them for at least six months), the notice you show users, and the registration of the system in the EU database that Article 71 makes publicly searchable. If the authority finds something wrong, Article 79 lets it order corrective action within 15 working days, or withdrawal or recall of the system, and it has to inform the Commission and the other member states when the problem is likely to cross borders. Serious incidents travel the other way: a provider has to report them to the market surveillance authority of the country where they happened, within 15 days as a rule, and a deployer who spots one has to inform the provider and the authority, and suspend use as soon as the system looks like a risk.

How fines are set, and the SME rule

Article 99 sets three ceilings. Prohibited practices: 35 million euros or 7 percent of worldwide annual turnover. Breaching the obligations of providers, deployers, importers and distributors, and the transparency duties: 15 million euros or 3 percent. Giving wrong or incomplete information to an authority: 7.5 million euros or 1 percent. For large companies the higher of the two figures is the ceiling. For SMEs and start-ups the regulation flips it: the lower of the two applies.

Work it through for a company with 2.5 million euros of turnover that runs a chatbot without disclosure. Tier two, so 3 percent of 2.5 million is 75,000 euros, and that is below 15 million, so 75,000 euros is the maximum. Not the fine, the maximum. Article 99 lists what the authority has to weigh: the nature, gravity and duration of the breach, whether it was intentional or negligent, what you did to limit the harm, how you cooperated, whether you had been fined before, and how the breach came to light. A company that reported the problem itself and fixed it inside the 15 working days sits at the opposite end of that scale from one that ignored two letters.

Member states decide for themselves whether public bodies can be fined at all, and they report every fine to the Commission each year, so a Belgian fine will show up in an EU-wide overview.

The Gegevensbeschermingsautoriteit versus the market surveillance authority

The two regulators will often look at the same system, and the cleanest way to tell them apart is to ask what each one can inspect and fine.

The Gegevensbeschermingsautoriteit acts under GDPR, and its trigger is personal data, whatever the technology. Its Inspectiedienst can access the personal data and any information it needs, enter premises and data processing equipment, and audit. Its Geschillenkamer can warn, reprimand, order a processing stopped or restricted, and fine up to 20 million euros or 4 percent of worldwide turnover, whichever is higher. There is no SME discount in GDPR. It cannot judge whether your system meets the AI Act's product rules, and it has no view on an AI system that touches no personal data.

The market surveillance authority acts under the AI Act, and its trigger is the AI system as a product: its risk class, its documentation, its data, its human oversight, its labels. It can see training data and, in the last resort, source code. It can order a system corrected, withdrawn or recalled, and it fines under the three tiers above, with the SME rule. It has nothing to say about your legal basis for processing or your retention periods.

Take a CV-screening tool. The Gegevensbeschermingsautoriteit can ask why you process candidate data this way and whether a data protection impact assessment exists. The market surveillance authority can ask whether the system is registered, who oversees it and what the vendor's documentation says about bias testing. One failure can produce two files, and the AI Act explicitly leaves the GDPR remedies untouched. The two authorities are also meant to talk: the Gegevensbeschermingsautoriteit is on the Article 77 list and can request the market surveillance authority's documentation, or ask it to test a system.

What a Belgian SME should have ready

None of this needs a lawyer on retainer. It needs a folder that exists before the letter arrives.

  • A named contact. One person who answers when a regulator, a vendor or an employee raises an AI question, and who knows where the folder is.

  • An AI inventory. Every AI system in use, what it is used for, whether you are provider or deployer, which risk class it falls in and which obligations that triggers today. The Commission's compliance checker on the AI Act Service Desk is a fair first pass.

  • One oversight line per system. For each entry in the inventory: who watches the output, what they are allowed to override, and who can switch it off. Written down, with a date.

  • Vendor documentation on file. The instructions for use, the vendor's statement on risk class and on Article 50 labelling, and its answer to the question whether it does anything on the Article 5 list. A written answer, not a phone call.

  • Logs and notices. Where the logs live and how long they are kept, and a copy of the notice users see.

  • The incident route. Who you call at the vendor, how you suspend the system, and, once Belgium has its authority, where the report goes. FOD Economie's AI pages are where the designation law will be announced; until then the Gegevensbeschermingsautoriteit and the courts are the enforcement you can actually meet.

Last Updated: September 3, 2026 Back to Dictionary
Keywords
ai act enforcement in belgium market surveillance authority bipt fod economie ai office ai act gdpr high-risk ai system gpai prohibited ai practices transparency obligation regulation