The AI Act is EU law and applies identically across the union, but enforcement is national. Sweden has named its authorities, but not in statute.
On 4 June 2026 the government allocated responsibility to five authorities in decision III:50. The split follows the point numbers in Annex III rather than sectors, which is what makes it impossible to guess.
The Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS) took critical infrastructure, education, employment, essential public services and emergency services, and is also the single point of contact. The Swedish Financial Supervisory Authority (Finansinspektionen) took creditworthiness inside its own supervised perimeter and insurance, and the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) took biometrics, law enforcement, migration and justice. The Swedish Medical Products Agency (Läkemedelsverket) has medical devices. Swedac carries out no market surveillance; it designates and notifies the conformity assessment bodies.
The assignment is not a statute and expires on 31 December 2026. The powers follow from Article 74(1) and the market surveillance regulation (EU) 2019/1020, but the penalties need Swedish legislation that does not yet exist.
The practical consequence is not the one people guess. A school and a waterworks have the same supervisor, and it is the telecoms regulator. The Swedish Post and Telecom Authority and the Agency for Digital Government merge on 1 January 2027, and the government intends to name the merged agency Digitaliseringsmyndigheten.
IMY has an inspection of a region's AI transcription service in primary care underway, opened in May 2026. It rests on data protection law rather than on the AI Act, which is the useful lesson: the first supervisory pressure on AI in Sweden arrives through the GDPR.
A Swedish implementing act and a regulatory sandbox are still to come. We track both.