1 October 2026
One EU AI Act. Who Has the Expertise to Apply It?
Europe has harmonised the rules—but credible enforcement will depend on whether regulators, sandboxes, providers and notified bodies can access equally strong technical expertise.

One EU AI Act. Who Has the Expertise to Apply It?
The EU can harmonise AI rules. It cannot automatically harmonise the expertise used to apply them.
Who assesses whether a high-risk AI system complies?
Often, the provider itself.
Conformity assessment demonstrates and documents that a system meets the Act’s requirements before it is placed on the market or put into service. For most standalone high-risk systems, the provider follows an internal-control procedure. A notified body is required only in specified cases, including certain biometric systems when relevant standards or common specifications are unavailable, not fully applied or restricted. (Annex III from 2 December 2027.)
Sandbox participation is optional. It can support testing and evidence, but does not replace conformity assessment.
Most market surveillance is carried out by Member State authorities; the AI Office and EDPS cover specified categories.
The competence question therefore spans providers, notified bodies, sandbox teams and regulators.
The Act requires notified bodies to have the necessary competence and permanent availability of sufficient administrative, technical, legal and scientific personnel. National authorities must have adequate resources and expertise in AI, data, cybersecurity, fundamental rights, health and safety, standards and law. Sandbox authorities must also be sufficiently resourced.
Based on my reading, the Act does not create one EU-wide qualification for individual reviewers or guarantee equal technical depth across Member States. There is no blanket national compliance approval: the provider remains responsible for conformity. Even so, one jurisdiction may feel easier if its sandbox team asks fewer questions, its authorities demand less evidence or its enforcement is slower.
Sandbox participation is mutually recognised across the EU and can provide limited protection from administrative fines, but it neither establishes conformity nor prevents later scrutiny.
AI changes quickly. Expertise cannot be recruited once and treated as permanent.
The risk is not 27 AI Acts. It is uneven expertise under one AI Act.
Unevenness can fail in both directions: weak scrutiny may allow unsafe systems through, while excessive caution may burden lower-risk systems. Companies may face inconsistent evidence demands, repeat testing and delays.
No Member State can maintain every AI specialism in-house.
Europe needs shared, continuously updated technical-assurance capacity. A federated network could connect national authorities, sandboxes and notified bodies with Centres of Excellence, universities and sector testbeds.
It could provide pre-qualified, conflict-checked specialists; develop common testing and peer-review methods; and keep them current as models, vulnerabilities, incidents, standards and guidance evolve.
One AI Act needs shared capacity for credible, timely technical judgement.
Can Europe build it?


