Security & Compliance

Who enforces the AI Act in Sweden? PTS and the new map

By Technspire TeamAugust 5, 202614 views

On 2 August 2026 the EU AI Act crossed its largest applicability milestone, and Sweden's national enforcement structure finally has a concrete shape. The government inquiry on the AI Act, delivered as SOU 2025:101 in October 2025, proposes a new supplementary Swedish law that designates Post- och telestyrelsen (PTS) as the coordinating market surveillance authority, spreads sectoral supervision across eleven authorities, appoints two notifying authorities, and puts PTS in charge of a national regulatory sandbox for AI. The law was written to enter into force on 2 August 2026, the same day most of the regulation started applying. It has not been formally adopted yet, and that gap matters. If your team runs chatbots on Azure OpenAI, agents in Copilot Studio, or anything that generates content for Swedish users, you now know who your regulator will be, what already applies, and how much runway you have for the rest.

What changed on 2 August 2026, and what did not

Two things happened in the last two weeks of July that reshaped this deadline, so it is worth being precise about the state of play as of this week.

First, the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the AI Act's general application date. It postpones the compliance deadline for standalone high-risk AI systems under Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in products already covered by EU product safety law under Annex I to 2 August 2028. The recitals name the reasons plainly: harmonised standards are late and many member states are late designating their national competent authorities.

Second, everything else scheduled for 2 August 2026 went ahead. The transparency obligations in Article 50 now apply: anyone interacting with a chatbot or a similar AI system must be told they are talking to an AI, and providers of generative systems face marking obligations for synthetic content. The European Commission's AI Office gained its full enforcement powers over providers of general-purpose AI models, including the ability to request information and impose fines. And the governance and penalty framework that member states were supposed to have in place became live, with the AI Act's caps of up to 35 million euros or 7 percent of global turnover for prohibited practices and up to 15 million euros or 3 percent for most other infringements.

So the popular reading that "the AI Act got delayed" is only a third right. High-risk conformity work got a longer runway. Transparency duties and general-purpose AI enforcement did not, and they apply to systems Swedish enterprises already run in production today.

The Swedish enforcement map from SOU 2025:101

Sweden chose not to build a single new AI authority. The inquiry, Utredningen om AI-förordningen, handed over its final report Anpassningar till AI-förordningen (SOU 2025:101) on 6 October 2025, and its proposal collects the national rules in one new supplementary law and one new ordinance. The architecture is decentralised on purpose: supervision follows existing sectoral competence, with PTS holding it together.

  • PTS as the hub. Post- och telestyrelsen is proposed as the market surveillance authority with principal responsibility for the AI Act, the coordinating authority for the whole system, and Sweden's single point of contact towards the Commission and other member states. PTS also picks up market surveillance in specific areas such as AI in critical infrastructure, and it is the authority the public will be directed to.
  • Eleven market surveillance authorities. The inquiry proposes a system of eleven marknadskontrollmyndigheter, so financial services, medical products, and other regulated sectors keep their existing supervisors for AI questions inside their domain. For high-risk AI systems specifically, the Chambers Artificial Intelligence 2026 guide highlights PTS, Integritetsskyddsmyndigheten (IMY), and Finansinspektionen as the authorities that will oversee them.
  • Two notifying authorities. Swedac (Styrelsen för ackreditering och teknisk kontroll) and Läkemedelsverket are proposed as notifying authorities, responsible for the conformity assessment side of the machinery.
  • A registration duty. In its role as market surveillance authority for point 2 of Annex III (critical infrastructure), PTS would run registration, and certain operators would be obliged to notify themselves and their AI systems to PTS.
  • Sanctions. The inquiry proposes national rules on supervision and sanction fees, including sanctions for prohibited AI practices and for deficient documentation of high-risk AI, within the caps the regulation sets.

The Swedish AI sandbox

The AI Act requires every member state to have at least one AI regulatory sandbox operational by 2 August 2027. Under the Swedish proposal, PTS is responsible for establishing it, while the other market surveillance authorities are required to participate in individual sandbox projects that touch their sectors. For product teams this is worth planning around rather than just observing. A sandbox gives you supervised space to develop and test an AI system against the regulation together with the authority, and documented sandbox participation is the kind of evidence that shortens later conformity discussions. If you have a borderline high-risk use case on your 2027 roadmap, a Swedish sandbox slot is a legitimate de-risking tool, and the queue will not be empty.

The catch: the law was not in force on deadline day

Here is the part the summaries skip. The supplementary law was designed to enter into force on 2 August 2026, but as of this week it has not been formally adopted. The Chambers guide, published in May 2026, recorded that the laws "have not yet been formally adopted." PTS's own AI page, updated on 31 July 2026, confirms the supplementary legislation is not in force and describes the bridge Sweden is using instead: PTS and the other proposed authorities hold interim government assignments, running until 31 December 2026, to act as national competent authorities while the legislative process completes. The SOU went through consultation in early 2026, with remissvar filed in February, and the government bill is the remaining step.

Sweden has company. The AI Act required member states to designate market surveillance and notifying authorities by 2 August 2025, and according to the tracking by artificialintelligenceact.eu only nine of twenty-seven member states had clearly designated both types by that deadline. The Digital Omnibus recitals cite exactly this delay as a justification for postponing the high-risk regime.

What does this mean practically for a Swedish IT leader? Three things. The identity of your future regulator is settled in all but formality, so build your compliance contacts and documentation around PTS and your sectoral supervisor now. The obligations that already apply, Article 50 transparency above all, flow directly from the EU regulation and do not wait for Swedish adoption; an EU regulation applies without national transposition. And the enforcement capacity behind those obligations is still ramping up, which makes this a window to fix gaps before supervision has a full toolkit, not a reason to defer the work.

Which authority will supervise you? A working decision guide

Rule of thumb: your AI supervision will follow your existing sectoral supervision. If you already answer to a regulator for the activity the AI system supports, expect that regulator to own the AI question too, with PTS as coordinator and default contact point when no sectoral authority fits.

  • General enterprise AI, chatbots, agents, no regulated sector: PTS, as coordinating authority and single point of contact.
  • AI in critical infrastructure (Annex III point 2): PTS directly, including the proposed registration and notification duty.
  • AI processing personal data, biometric or emotion-recognition questions, workplace monitoring: expect IMY involvement, both through its proposed high-risk oversight role and through GDPR, which never stopped applying.
  • Banks, insurers, payment and credit institutions: Finansinspektionen for AI in scope of its supervision, for example credit scoring, which sits in Annex III.
  • Medical devices with AI: Läkemedelsverket territory, on the notifying-authority side and in the sectoral machinery that already governs MDR products.
  • Conformity assessment and certification questions: Swedac and Läkemedelsverket as the two proposed notifying authorities.
  • General-purpose AI models themselves: not a national question at all. The Commission's AI Office supervises GPAI providers, which for most Swedish enterprises means your model providers (for example the providers behind the models you consume through Azure) carry that relationship, not you.

Keep the usual caveat in view: this is the inquiry's proposed allocation, and details can move before the law is adopted. The direction, PTS at the centre with sectoral authorities around it, has been stable since October 2025 and survived consultation, so it is a sound planning assumption.

What Swedish Azure teams should do this quarter

The combination of "transparency applies now" and "high-risk moved to December 2027" gives you an unusually clear work plan.

  • 1. Close the Article 50 gap first. Inventory every user-facing AI touchpoint: Azure OpenAI chat frontends, Copilot Studio agents, Teams bots, website assistants. Each needs clear disclosure that the user is interacting with an AI, unless that is obvious from context. If you generate synthetic audio, image, or video content, review the marking obligations with your provider's tooling.
  • 2. Build the AI inventory with roles attached. For each system, record whether you are provider or deployer under the AI Act, which Annex III category it could fall under, and which Swedish authority the decision guide above points to. This inventory is the backbone of every later obligation.
  • 3. Use the high-risk runway deliberately. December 2027 for Annex III systems is enough time to do risk management, data governance, logging, and human oversight properly on Azure, with tools you already have: Azure AI Foundry evaluations, Application Insights for logging, Purview for data governance. It is not enough time if you start in mid-2027.
  • 4. Do not let the AI Act eclipse GDPR. IMY's supervision continues regardless of AI Act timing, and most enterprise AI risk in Sweden today is still personal-data risk. DPIAs for AI systems remain the sharpest compliance instrument you have.
  • 5. Put the regulator map into procurement. When buying AI-powered SaaS or consulting, ask vendors which AI Act role they take, how they meet Article 50, and what documentation they will hand you for your own deployer obligations. Public-sector buyers should start writing these questions into upphandling requirements now.
  • 6. Track the Swedish bill and the sandbox. Watch for the government proposition that turns SOU 2025:101 into law, and register interest early if a sandbox project could de-risk a 2027 launch. PTS's interim assignment runs to 31 December 2026, which suggests the government's own working assumption for adoption.

Direct takeaways

  • PTS is set to be Sweden's coordinating AI Act authority and single point of contact, with eleven market surveillance authorities and two notifying authorities (Swedac and Läkemedelsverket) around it.
  • The Swedish supplementary law was aimed at 2 August 2026 but is not yet adopted; PTS and peers act under interim assignments through 31 December 2026.
  • Article 50 transparency obligations and Commission enforcement over general-purpose AI apply EU-wide as of 2 August 2026, national law or not.
  • The Digital Omnibus moved high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Treat that as build time, not snooze time.
  • A PTS-run Swedish AI sandbox must be operational by 2 August 2027 and is worth a slot on your roadmap if you have borderline high-risk use cases.

Sources