Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
REGULATION (EU) 2024/1689 - PROGRESSIVE ENTRY INTO FORCE

AI Act: map
your usage before you're asked to

The European regulation on artificial intelligence progressively governs AI systems, including those already built into your everyday tools (Microsoft 365 Copilot, for example). SYAGA helps you inventory your actual usage, understand the obligations that apply to you, and build an action plan, without jargon and without unverified numerical promises.

2024
Regulation published (2024/1689)
Tiers
Progressive application over time
EU
Horizontal scope, all sectors
Copilot
AI already present in your M365 tools

The context

A European regulation that already applies, often without the company having noticed

The European AI regulation is already published

Regulation (EU) 2024/1689 (source: EUR-Lex) governs the governance of artificial intelligence systems within the European Union. Its entry into application takes place in successive tiers depending on the type of obligation concerned.

🤖

AI is already in your current tools

Artificial intelligence features are already built into office suites widely deployed in companies, such as Microsoft 365 Copilot. Many organizations use them without having formally inventoried this scope.

📋

Few companies have mapped their AI usage

Between tools provided by vendors, internal developments, and automated agents deployed on existing platforms, the actual scope of AI systems in use is rarely documented centrally.

🔐

Anticipating is better than enduring

As with any new regulation, it is better to clarify your exposure early than to discover an obligation during an audit or a request from a client, an insurer, or a partner.

The AIACT-Express approach

A 5-step support process, calibrated with you according to your actual scope of AI systems

1
Step 1 - Scoping

Interview with management or the IT manager

Understand the context, the tools already in place, and ongoing or planned AI projects. Goal: define a realistic scope of analysis, not a theoretical list.

2
Step 2 - Mapping

Inventory of AI systems in use

Vendor tools (including AI features already included in your office suites), internal developments, automations, and agents deployed on your existing platforms.

3
Step 3 - Analysis

Qualification of your role and associated obligations

Determine, for each system identified, to what extent you are a provider or a deployer within the meaning of the regulation, and what general obligations arise for your organization.

4
Step 4 - Action plan

Prioritization of compliance actions

A structured action plan, prioritized by risk and effort, without any promise of legal outcome: sensitive points are flagged for verification by specialized legal counsel.

5
Step 5 - Handover

Presentation of the diagnosis and handover

Delivery of the mapping file and the action plan, with time for discussion to answer your teams' questions.

What you receive

Concrete working documents, tailored to your actual scope

📝

AI systems mapping

Structured inventory of the usages identified during scoping and mapping.

  • Vendor tools and integrated AI features
  • Internal developments and automated agents
  • Role identified for each system (provider / deployer)

Summary of general obligations

A plain-language document linking each identified system to the major categories of obligations under the regulation.

  • View by AI system inventoried
  • Points to have verified by a specialized lawyer
  • No sanction amount stated without legal verification
📈

Prioritized action plan

An operational roadmap for your organization.

  • Actions ranked by priority
  • Reference to the relevant scope (GDPR, IT governance)
  • Editable format for internal tracking

Scope covered

The AI Act cannot be analyzed in isolation: it interacts with texts you already know

AI

AI Act (Regulation (EU) 2024/1689)

Reference text on the governance of artificial intelligence systems within the European Union. Source: EUR-Lex.

GD

GDPR

Whenever an AI system processes personal data, GDPR obligations (Regulation (EU) 2016/679) remain applicable alongside the obligations specific to the AI Act.

GO

Existing IT governance

Mapping AI usage naturally fits into a broader IT governance approach (security policy, risk management), particularly if your organization is already concerned by NIS2 or an ISO 27001 process.

M365

AI already present in Microsoft 365

Features like Copilot introduce AI into tools already used daily. Their use falls within the scope to be mapped, even without a "visible" AI project.

A quote, not a standard rate

The scope of an AI Act diagnosis varies too much depending on the number and nature of AI systems in use to offer a generic price. We provide a quote after the scoping phase.

Custom AI Act diagnosis

Scope established with you from the scoping stage

  • Scoping and interview included
  • Mapping of identified AI systems
  • Summary of general obligations, with no invented legal figures
  • Prioritized action plan
  • Quote established after scoping, before any commitment
Request a quote

Frequently asked questions

The answers below are deliberately general. They do not constitute legal advice and do not replace the analysis of legal counsel specialized in digital law.
Is my company affected by the AI Act?
The regulation applies broadly whenever an organization develops, places on the market, or uses an artificial intelligence system within the European Union, including via features already built into existing tools (for example Microsoft 365 Copilot). Unlike other texts, the AI Act does not set a simple threshold based on number of employees or turnover: the exact scope and obligations depend on the role held (provider or deployer) and the system concerned. A diagnosis makes it possible to determine this for your organization.
What is the difference between provider and deployer?
The regulation notably distinguishes organizations that develop or place an AI system on the market (providers) from those that use it in the course of their professional activity (deployers). The obligations that apply differ according to this role. Most SMEs are primarily deployers of the tools they use daily.
What are the risks of non-compliance?
The regulation provides for a specific sanctions regime. We deliberately do not communicate any amount on this page until it has been verified and validated by specialized legal counsel for your precise situation: this is precisely one of the points the diagnosis helps clarify with the right contacts.
Does the diagnosis replace a lawyer's opinion?
No. AIACT-Express is an operational support tool (mapping, plain-language summary, action plan) and does not constitute legal advice. For any question of legal interpretation of the regulation, the involvement of a specialized lawyer remains necessary.
How much time do I need to commit my teams?
Mainly a scoping interview with management or the IT manager, then a debrief session at the end of the process. The exact volume is specified in the quote, once the scope is known.
What makes SYAGA legitimate on this subject?
SYAGA Consulting has been carrying out security and compliance audits of information systems since 2009, for organizations of various sizes. AIACT-Express relies on this same audit method (scoping, mapping, analysis, action plan) applied to the specific scope of artificial intelligence.

Regulatory watch - official sources

What the European AI text actually says, digested into plain language. Each point links to its official source (European Commission, EUR-Lex). Information collected on 17/07/2026.

📖

What is this about?

This is a European regulation (the "AI Act", text 2024/1689), published on 12 July 2024 and already "in force". It sets common rules for artificial intelligence across the whole European Union, whatever your sector of activity.
official source →

📅

The dates to remember

The regulation applies in stages: the prohibitions have been active since 2 February 2025; the governance rules and the obligations on general-purpose AI since 2 August 2025; most of the other obligations (including "high-risk" AI) take effect on 2 August 2026. Note: the Commission proposed on 19 November 2025 to adjust some of these deadlines, so these dates may still shift slightly.
official source →

📊

The 4 risk levels

The text classifies AI uses into 4 categories: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (information obligation), and minimal risk - the vast majority of current uses (for example a spam filter or a video game), which are not affected by any new rules.
official source →

🚫

What is purely prohibited

Certain uses are now outlawed everywhere in Europe: manipulating or deceiving people through AI, exploiting a person's vulnerabilities, scoring citizens with a "social score", predicting that a person will commit a crime based on their profile, mass scraping of photos from the web or CCTV footage to build facial recognition databases, analysing emotions at work or at school, or using biometrics to infer origin, religion or orientation.
official source →

If your AI is deemed "high-risk"

Examples cited by the Commission: a tool that screens CVs, that manages access to credit, or that acts as a safety component in transport. In that case, you must assess and limit the risks, use quality data, keep activity logs, document the system, clearly inform users, provide for human oversight, and ensure a good level of robustness and cybersecurity.
official source →

💰

The penalties in plain terms

For prohibited uses: up to 35 million euros or 7% of worldwide turnover (whichever is higher). For other breaches of the regulation: up to 15 million or 3%. For giving misleading information to the authorities: up to 7.5 million or 1%. For SMEs and start-ups, the LOWER of the two amounts applies (see the sourced detail further below in "The AI Act penalties, in plain terms").
official source →

🏛

Who enforces it

A "European AI Office" has been created within the European Commission (more than 125 people) to ensure consistent application of the regulation, supported by a board bringing together a representative from each Member State. Each country must also designate its own national supervisory authorities.
official source →

🤝

A voluntary approach already possible today

The Commission offers a voluntary commitment, the "AI Pact", to get ahead of compliance before the legal deadlines. More than 230 companies (large groups and SMEs) have already signed it. These commitments are not legally binding.
official source →

Who is affected by the AI Act?

Unlike GDPR or NIS2, the AI Act does not set a simple threshold based on headcount or turnover. What triggers the obligations is your role (provider or deployer) and the risk level of the AI system concerned. Information collected on 18/07/2026, official sources European Commission and EUR-Lex.

🌍 A reach that extends beyond the EU's borders

The official text is clear: the regulation applies "to both public and private actors inside and outside the EU, who place an AI system or general-purpose AI model on the EU market, or put an AI system into service or use it in the EU". In concrete terms, a company established outside the EU can be affected as soon as the output of its AI system is intended to be used within the Union.
official source →

FO The provider ("provider")

Whoever develops the AI system or places it on the market. Example given by the European Commission: "a developer of a CV-screening tool". Providers of general-purpose AI models are also covered.
official source →

DE The deployer ("deployer")

Whoever uses the system in their professional activity. Example given by the Commission: "a bank using this screening tool". Strictly personal, non-professional use is excluded from this definition.
official source →

What is excluded from the scope

  • Military, defence, national security: systems designed exclusively for these purposes, whatever the type of organisation implementing them.
  • Research and development: R&D and prototyping activities carried out before a system is placed on the market are not covered.
  • Strictly personal, non-professional use: excluded from the definition of deployer.
  • Public authorities of third countries and international organisations acting within a framework of international cooperation or agreements, subject to adequate safeguards.
  • Authentication or verification biometrics (unlocking a smartphone, border control): deemed not significantly risky, it remains outside the scope of this regulation.

official source (EUR-Lex) →  ·  official source (Commission FAQ) →

SME SMEs and start-ups: relief, not exemption

SMEs and start-ups remain within the scope of the regulation, but benefit from administrative fines proportionate to their size, lighter technical documentation obligations (the "AI omnibus" agreement), and "regulatory sandboxes" to test their AI projects under supervised conditions.
official source →

RQ The real criterion: risk level, not size

The regulation classifies all uses into 4 risk levels (unacceptable, high, limited, minimal). It is this level, determined by the nature of the system and its use, that triggers (or not) obligations, regardless of the headcount or turnover of the organisation using it.
official source →

💼 Concrete examples of sectors cited by the Commission

Indicative list of the main families of uses that may fall under "high risk", as presented by the European Commission:

  • Critical infrastructure and safety components of transport
  • Education (exam scoring, guidance of students)
  • Employment and recruitment (for example a CV-screening tool)
  • Access to essential services (for example bank credit scoring)
  • Biometrics
  • Law enforcement
  • Migration, asylum and border management
  • Administration of justice and democratic processes
  • Safety components of products already regulated (medical devices, transport)

official source →

AI Act: the questions a business owner really asks

No legal jargon: 8 concrete questions, a simple answer, and the official source (European Commission, EUR-Lex) behind each answer.

Click on a question to see the answer and its source.

I just use Copilot or ChatGPT day-to-day, am I really affected?

In the vast majority of cases, no, not by specific obligations. Using an off-the-shelf chatbot or copilot, without integrating it into or turning it into a product, remains outside the core of the regulation as long as it is not a "high-risk" AI system. You do, however, remain a "deployer" of the tool: you must use it in accordance with its instructions for use.

Do I have to train my employees on AI?

This is an obligation set out in the regulation (Article 4, "AI literacy"), in force since 2 February 2025. The idea: give your teams - those who provide, use or are affected by an AI system - the understanding needed to make informed decisions about these tools. The Commission has published a collection of practices ("living repository") to help companies organise themselves, without imposing a single training format.

If a chatbot answers my customers or an AI generates my visuals, do I have to disclose it?

Yes, from 2 August 2026 (Article 50 of the regulation). A person interacting with a chatbot must be able to know they are talking to a machine. Content generated by AI (text, image, video) must remain identifiable as such, and "deepfakes" or AI-generated texts published on matters of public interest must be clearly and visibly labelled. A voluntary code of practice on labelling this content was published on 10 June 2026 to guide companies.

Do I have to register my AI in an official European register?

Only if you are a provider of a "high-risk" AI system: in that case, registration in a public European database is mandatory. Public authorities deploying a high-risk system must also register, except for critical infrastructure. Everyday use of off-the-shelf AI tools is not covered by this register.

Are the penalties the same for an SME as for a large group?

No. The regulation sets 3 tiers of penalties (up to €35M or 7% of worldwide turnover for prohibited practices; €15M or 3% for other breaches; €7.5M or 1% for providing false information to authorities), always applying the higher of the two amounts. For SMEs and start-ups, the rule is reversed: the LOWER amount of each tier applies, never the higher. Full sourced detail in the "AI Act penalties, in plain terms" section.

Is there official free help to find out if I'm affected?

Yes. The Commission has set up an "AI Act Service Desk" offering an FAQ, a "Compliance Checker" tool to assess your own obligations, an "AI Act Explorer" to navigate the text article by article, and a form to ask a question directly to a team of experts.

I use AI to screen CVs or monitor my employees, do I have specific obligations?

Yes, these are typical uses classified as "high-risk" by the regulation. As a deployer, you must in particular assign human oversight carried out by staff who are "sufficiently equipped and empowered", inform your employees BEFORE deploying such a system in their workplace, and inform any person whenever an AI takes part in a decision that concerns them (for example screening an application). The regulation also requires transparency, technical documentation and record-keeping for these uses.

Can I test my AI before deploying it, without risking an immediate penalty?

Yes, that is precisely the role of "regulatory sandboxes" and real-world testing provided for by the regulation, designed for SMEs and start-ups. An amendment of 7 May 2026 further widened access to this scheme: more innovators can now access it, including via an EU-level sandbox, and eligibility has been extended to "small mid-caps" (small mid-sized companies).

This FAQ is an educational summary drawn from the official texts and pages cited above (European Commission, EUR-Lex). It does not replace a legal reading of the text and does not constitute legal advice. Information collected on 18/07/2026.

The AI Act timeline, in plain terms

The European AI regulation does not apply all at once: it rolls out in stages between 2024 and 2028. Here are the dates to remember, what is already active and what is coming, each with its official source. Information collected on 18/07/2026.

2024
1 August 2024 • already behind us

The regulation enters into force

The European text on artificial intelligence officially becomes a regulation in force across the European Union. This is the starting point: all subsequent deadlines are counted from this date.
official source →

2 February 2025 • in force

Prohibited uses become illegal

Manipulation of individuals, social scoring, mass facial recognition... the most dangerous practices are now outlawed everywhere in Europe (detail in the "regulatory watch" section above). The rules on AI awareness within organisations also apply from this date.
official source →

2 August 2025 • in force

European governance and generative AI regulated

The supervisory authorities provided for by the text (including the European AI Office) are officially in place, and providers of large generative AI models (such as conversational assistants) must comply with transparency and technical documentation obligations.
official source →

!
2 August 2026 • in a few days

The regulation's general deadline

This is the date that the original text set for its general application (24 months after entry into force): the obligation to inform users when facing AI, and most "high-risk" AI systems used autonomously. Part of the high-risk scope has however been postponed in the meantime (see the next two stages).
official source →

19 Nov. 2025 → 7 May 2026 • the timeline has shifted

Europe adjusts the timeline ("AI Omnibus")

On 19 November 2025, the European Commission proposed simplifying and delaying certain deadlines of the regulation, to allow time for the necessary technical standards to be ready. The European Parliament and the Council reached a political agreement on this text on 7 May 2026. Concrete consequence: two "high-risk" deadlines have been pushed back (the next two stages below). As of this page's date, this political agreement has not yet been published in its final form in the Official Journal of the EU.
official source →

2027
2 December 2027 • coming (postponed deadline)

High risk in sensitive sectors

New deadline for high-risk AI systems used notably in biometrics, critical infrastructure, education, employment, or migration/asylum/border control. These obligations, which were originally due to apply in August 2026, are postponed to this date to allow time for technical standards to be finalised.
official source →

2028
2 August 2028 • coming (postponed deadline)

AI embedded in already-regulated products (lifts, toys...)

For AI systems that are safety components in products already regulated elsewhere (lifts, toys, medical devices...), the deadline was set at August 2027 in the original text (36 months after entry into force). It is now postponed to this date.
official source →

📌

What to remember, in one sentence

The prohibitions and governance rules have been active since 2025; the regulation's general deadline falls in the very next few days (2 August 2026); and two families of high-risk systems (sensitive sectors, regulated products) get an additional delay until the end of 2027 then mid-2028, to allow time for technical standards to be ready.

The AI Act penalties, in plain terms

No panic, no shock figure: here is exactly what the European text says about fines, who imposes them, and since when they actually apply. Each amount is the one written in black and white in Regulation (EU) 2024/1689, articles 99 to 101.

€35M
or 7%of worldwide turnover

Maximum tier - fully prohibited AI practices

The higher of the two amounts is applied. It covers exclusively the 8 uses prohibited by Article 5: manipulation or deception through AI, exploitation of a person's vulnerabilities, social scoring, predicting a risk of offending based on profiling alone, mass scraping of faces to build a facial recognition database, emotion recognition at work or school, biometric categorisation of protected characteristics, and "real-time" biometric identification by law enforcement in public spaces.

Regulation (EU) 2024/1689, Article 99§3 →
€15M
or 3%of worldwide turnover

Intermediate tier - most relevant to SMEs/mid-caps

This is the tier that most directly affects companies that use an AI tool: obligations of providers (Article 16), authorised representatives (22), importers (23), distributors (24), deployers, i.e. companies using a high-risk AI system (Article 26), notified bodies, and transparency obligations towards users (Article 50 - for example disclosing that a chatbot is AI).

Regulation (EU) 2024/1689, Article 99§4 →
€7.5M
or 1%of worldwide turnover

Lowest tier - misleading information to authorities

Applies when a company provides incorrect, incomplete or misleading information to a notified body or a competent national authority that has made an official request.

Regulation (EU) 2024/1689, Article 99§5 →

For an SME, it's always the lower amount

Explicit rule in the text: for SMEs and start-ups, each fine is capped at the lower of the two terms (percentage or fixed sum), never the higher. In practice, a fine based on a percentage of your actual turnover almost always replaces the multi-million-euro cap designed for multinationals.

Regulation (EU) 2024/1689, Article 99§6 →

A fine is never automatic

The text requires the authority to take into account, before setting an amount: the gravity and duration of the breach, the number of people affected, the size and turnover of the company, whether it was intentional or negligent, the degree of cooperation with the authority, and any measures already taken to correct the issue.

Regulation (EU) 2024/1689, Article 99§7 →

Who actually enforces it

Each Member State must designate at least one national "market surveillance authority", responsible for enforcing the regulation on its territory. At European level, the European AI Office coordinates the whole. To date, no official source consulted confirms the name of the authority definitively designated for France - so we are not inventing one.

Regulation (EU) 2024/1689, Article 70 →

Already in force, not a future threat

The Article 5 prohibitions (and their fines of up to €35M) have applied since 2 February 2025. The entire penalty regime (Chapter XII, Article 99) has been in application since 2 August 2025. This is therefore not a distant deadline: the fines framework is already active today.

Regulation (EU) 2024/1689, Article 113 →

Special case: "general-purpose" AI models (GPT-type, Gemini...)

Providers of large general-purpose AI models (the "foundations" behind tools such as AI assistants) fall under a separate regime: it is the European Commission itself that can impose a fine of up to €15M or 3% of their worldwide turnover. This regime targets the model's publisher, not the company using it day-to-day.

Regulation (EU) 2024/1689, Article 101 →

No invented figures

The regulation requires each Member State to submit to the Commission every year a report on fines actually imposed. No first edition of this report has been identified to date in the official sources consulted - so we do not cite any concrete case or any amount actually imposed until it is officially published.

Regulation (EU) 2024/1689, Article 99§11 →
Amounts and articles verified by direct reading of the official text of Regulation (EU) 2024/1689 (Official Journal of the European Union of 12 July 2024, EUR-Lex CELEX 32024R1689). This section is an educational summary, it does not replace legal advice. Information verified on 18/07/2026.

Your supervisory authority, by country

In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.

CountryData protectionCybersecurity
GermanyBfDI - Die Bundesbeauftragte für den Datenschutz und die InformationsfreiheitBSI - Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security)
AustriaOsterreichische Datenschutzbehorde (DSB)CERT.at
BelgiumAutorite de la protection des donnees - Gegevensbeschermingsautoriteit (APD-GBA)Centre for Cybersecurity Belgium (CCB)
BulgariaCommission for Personal Data Protection (CPDP)CERT Bulgaria (National Cybersecurity Incident Response Team, State e-Government Agency)
CyprusOffice of the Commissioner for Personal Data Protection (Cyprus Data Protection Authority)Digital Security Authority (DSA)
CroatiaAgencija za zastitu osobnih podataka (AZOP) - Croatian Personal Data Protection AgencyNational Cyber Security Centre (NCSC-HR), operating under the Security and Intelligence Agency (SOA)
DenmarkDatatilsynetForsvarets Efterretningstjeneste (FE) - Cybersituationscenter, national CSIRT (Danish Defence Intelligence Service)
SpainAgencia Espanola de Proteccion de Datos (AEPD)INCIBE - Instituto Nacional de Ciberseguridad (Spanish National Cybersecurity Institute)
EstoniaEstonian Data Protection Inspectorate (Andmekaitse Inspektsioon)Information System Authority (RIA) - National Cyber Security Centre of Estonia (NCSC-EE), heberge CERT-EE
FinlandOffice of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)National Cyber Security Centre Finland (NCSC-FI)
FranceCNIL (Commission Nationale de l'Informatique et des Libertes)ANSSI (Agence Nationale de la Securite des Systemes d'Information)
GreeceHellenic Data Protection Authority (HDPA) - Arkhi Prostasias Dedomenon Prosopikou KharaktiraNational Cybersecurity Authority (NCSA) - Ethniki Arkhi Kyvernoasfaleias
HungaryNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - Hungarian National Authority for Data Protection and Freedom of InformationNational Cyber Security Center of Hungary (NCSC-HU / NKI), operant au sein du Special Service for National Security (SSNS)
IrelandData Protection Commission (DPC)National Cyber Security Centre (NCSC-IE), incluant le CSIRT-IE
IcelandPersonuvernd (Icelandic Data Protection Authority)CERT-IS
ItalyGarante per la protezione dei dati personaliAgenzia per la Cybersicurezza Nazionale (ACN)
LatviaData State Inspectorate (Datu valsts inspekcija)CERT.LV - Cyber Incident Response Institution of the Republic of Latvia
LiechtensteinDatenschutzstelle Fürstentum LiechtensteinCSIRT.LI (Computer Security Incident Response Team Liechtenstein / National Cyber Security Unit)
LithuaniaState Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija - VDAI)National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras - NKSC)
LuxembourgCommission Nationale pour la Protection des Données (CNPD)Agence nationale de la sécurité des systèmes d'information (ANSSI Luxembourg), sous le Haut-Commissariat à la protection nationale (HCPN)
MaltaOffice of the Information and Data Protection Commissioner (IDPC)CSIRTMalta (Critical Information Infrastructure Protection Unit, Ministry for Home Affairs and National Security)
NorwayDatatilsynetNSM (Nasjonal sikkerhetsmyndighet / National Security Authority) (to confirm)
NetherlandsAutoriteit Persoonsgegevens (AP)National Cyber Security Centre (NCSC-NL)
PolandUrząd Ochrony Danych Osobowych (UODO)CSIRT NASK (CERT Polska)
PortugalComissão Nacional de Proteção de Dados (CNPD)Centro Nacional de Cibersegurança (CNCS)
RomaniaANSPDCP - Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (National Supervisory Authority for Personal Data Processing)to confirm
SlovakiaUrad na ochranu osobnych udajov Slovenskej republikyNarodny bezpecnostny urad (National Security Authority) - SK-CERT / National Cyber Security Centre
SloveniaInformation Commissioner of the Republic of Slovenia (Informacijski pooblascenec)Government Information Security Office (GISO / URSIV - Urad Vlade RS za Informacijsko Varnost)
SwedenIntegritetsskyddsmyndigheten (IMY) - Swedish Authority for Privacy ProtectionNationellt cybersakerhetscenter (NCSC-SE), rattache a FRA, integre CERT-SE (CSIRT national)
CzechiaUrad pro ochranu osobnich udaju (UOOU) - Office for Personal Data ProtectionNarodni urad pro kybernetickou a informacni bezpecnost (NUKIB) - National Cyber and Information Security Agency

Sources: official websites of the authorities and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to confirm" labels indicate an official source not yet stabilised to date.

Ready to map your AI usage?

Write to us for an initial discussion and a personalized quote.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu