Skip to content
The rules

Which authority supervises the AI Act in Sweden

Sweden has divided the AI Act between five authorities. The split follows the point numbers in Annex III rather than industry, which is why schools and waterworks got the same regulator.

Andreas Olsson10 min read

Screen print in which a school, a water tower, an office block and a radio mast are linked by lines that meet at a single gold point.

Key insights


  • On 4 June 2026 the Swedish government allocated responsibility under the AI Act to five authorities: PTS, IMY, Finansinspektionen, the Medical Products Agency and Swedac.
  • The split follows the point numbers in Annex III rather than industry. The telecoms regulator PTS got five points, among them education, recruitment and emergency call triage.
  • PTS also received the transparency obligations in Article 50(1), (2) and (4), the single point of contact role, and the task of setting up a regulatory sandbox.
  • Credit scoring in point 5(b) is divided: Finansinspektionen has it inside its own supervised perimeter, IMY has the rest.
  • The allocation is a government assignment and not a statute, and it expires on 31 December 2026. The Annex III high risk requirements only start to apply on 2 December 2027.

The question sounds simple and has not had an answer. Which authority calls if your AI becomes a supervision case? Since June there is an answer in Sweden, and it cannot be derived from the industry you are in.

The AI Act itself is directly applicable in every member state, but it leaves the choice of national competent authorities to each of them. Sweden made that choice on 4 June 2026 in government decision III:50, reference Fi2026/01365. The decision was published on 12 June. Five authorities got a part each: the Swedish Post and Telecom Authority (PTS), the Swedish Authority for Privacy Protection (IMY), the financial supervisor Finansinspektionen, the Swedish Medical Products Agency, and Swedac, the national accreditation body. The decision ends with a sentence that matters as much as the allocation does: the assignment runs until 31 December 2026.

How Sweden divided the AI Act

The allocation is not made per sector. It is made per point number in Annex III, the list in the AI Act that enumerates the use cases in which a system is high risk under Article 6(2).

The decision writes out the point numbers and nothing about what the points contain. PTS gets points 2 to 4, 5(a) and 5(d). Finansinspektionen gets point 5(b) within the scope of the authority's own activities, and point 5(c). IMY gets points 1 and 5(b), except for the area Finansinspektionen is responsible for, and points 6 to 8.

Point in Annex IIIWhat the area coversMarket surveillance
1Biometrics, in so far as their use is permitted by lawIMY
2Critical infrastructurePTS
3Education and vocational trainingPTS
4Employment, workers' management and access to self-employmentPTS
5(a)Essential public benefits and servicesPTS
5(b)CreditworthinessFinansinspektionen inside its supervised perimeter, otherwise IMY
5(c)Life and health insuranceFinansinspektionen
5(d)Emergency calls and dispatch triagePTS
6Law enforcementIMY
7Migration, asylum and border controlIMY
8Administration of justice and democratic processesIMY

The Medical Products Agency and Swedac are not in the table, and that is not an oversight. The other route into the high risk regime runs through Article 6(1), that is AI sitting inside, or itself constituting, a product with its own product legislation. There responsibility is assigned per legal act rather than per point. The Medical Products Agency has medical devices under Regulations (EU) 2017/745 and (EU) 2017/746 and is the notifying authority for them. PTS has, on the same route, products covered by the Radio Equipment Directive (2014/53/EU). Swedac carries out no market surveillance at all, but is the notifying authority for everything else, meaning the body that designates the conformity assessment bodies.

That radio route has since become narrower than it was when the decision was written. Regulation (EU) 2026/1744, the digital omnibus on AI adopted on 8 July 2026, added a rule that a product required to undergo third party conformity assessment solely because of risks other than health and safety, in particular risks relating to radio spectrum distribution or electromagnetic interference, does not meet the condition that makes the embedded AI system high risk.

What the telecoms regulator actually got

Five points, and three of them have nothing to do with electronic communications.

Point 3 is education and vocational training. It covers systems that determine admission to education or assign people to it, that evaluate learning outcomes, that assess the level of education a person should receive, and that monitor prohibited behaviour during tests. It applies at every level of the education system.

Point 4 is employment, workers' management and access to self-employment. It covers recruitment and selection, expressly including targeted job advertisements, filtering of applications and evaluation of candidates, as well as decisions affecting the terms of employment, promotion, termination, allocation of tasks and monitoring of performance.

Point 5(a) is the assessment by public authorities of eligibility for essential public benefits and services, healthcare included, and the decisions to grant, reduce, revoke or reclaim them. Point 5(d) is the evaluation and classification of emergency calls and the dispatch priority that follows, triage in emergency healthcare included. Point 2 is safety components in the operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.

The telecoms regulator supervises AI in schools, in recruitment and in decisions on social assistance.

The assignment to PTS does not stop there, and the rest is in the same decision. The authority has market surveillance of the prohibited practices in Article 5 within those same areas. It has the transparency obligations in Article 50(1), (2) and (4), meaning the duty to let a person know they are speaking to an AI system, to mark synthetic audio, image, video and text in a machine readable format, and to disclose a deep fake. It is to be the single point of contact under Article 70(2), the address the Commission and other member states turn to. And it is to set up a regulatory sandbox under Article 57, the controlled environment where systems may be tested before they are placed on the market.

That makes PTS something other than one of five. The authority is at once the broadest supervisor, the only point of contact outward, and the host of the environment where new systems are tried. The Swedish Post and Telecom Authority and the Agency for Digital Government merge on 1 January 2027, and the government intends to name the merged agency Digitaliseringsmyndigheten.

Where credit scoring splits

Point 5(b), creditworthiness and credit scoring, is the only point two authorities share. The decision gives Finansinspektionen the part that falls within the scope of the authority's own activities, and IMY the rest.

That boundary means the same kind of system can have two different supervisors depending on who runs it. A bank that scores creditworthiness sits under Finansinspektionen, because the bank already does. An operator making the same assessment without being supervised by Finansinspektionen ends up with IMY.

The question is settled not by what the system does but by who uses it. It is the only point where the government let the identity of the operator decide the supervisor, and that makes it the point at which an organisation is most likely to get its own authority wrong.

What the inquiry proposed, and what became of it

The allocation did not come from nowhere. SOU 2025:101, the Swedish public inquiry on adapting national law to the AI Act, was delivered in October 2025. It proposed that PTS be the market surveillance authority with principal responsibility for the AI Act, and that PTS, IMY and Finansinspektionen share responsibility for market surveillance of high risk systems under Annex III.

The government followed it in the main, and on the transparency obligations literally. The inquiry proposed that PTS and IMY share responsibility for the Article 50 transparency obligations, and the decision does exactly that: PTS got 50(1), (2) and (4), IMY got 50(3), which covers emotion recognition and biometric categorisation and therefore sits in IMY's own area. The transparency obligations started to apply on 2 August 2026, with one exception: providers of systems placed on the market before that date have until 2 December 2026 to meet the marking obligation in Article 50(2). Two differences are worth noting.

The inquiry proposed that nine existing market surveillance authorities take on high risk under Section A of Annex I, that is AI in products. The decision names only two product areas, medical devices to the Medical Products Agency and radio equipment to PTS. That silence does not leave the question unanswered. Article 74(3) provides that the market surveillance authority for systems related to products in Section A of Annex I is the authority already responsible for market surveillance under that product legislation, unless the member state designates another. Section B, meaning vehicles, aviation, rail, marine equipment and machinery, sits outside that rule: under Article 2(2) only a handful of the AI Act's provisions apply to those products.

The inquiry gave Finansinspektionen points 5(b) and 5(c) outright. The decision added the qualifier about the authority's own activities to 5(b), and thereby created the split between Finansinspektionen and IMY that the inquiry did not have.

The assignment is not a statute, and it ends at the turn of the year

Here is the objection that carries weight, and it is the strongest one in the whole question.

What the government decided is an assignment to five authorities, not a statute. A government assignment governs what an authority shall do. The powers to do it do not come from there. They come from Article 74(1), which makes the market surveillance regulation (EU) 2019/1020 applicable to AI systems. What is missing is the penalties. Article 99 puts it on the member states to lay them down, and that takes Swedish legislation. No bill building on SOU 2025:101 has been presented.

An assignment says who is to look. What it costs to be caught is still written nowhere.

Add that the assignment expires on 31 December 2026 by its own wording, and the objection writes itself: why learn an allocation that has no penalties behind it and runs out in a few months?

The sandbox makes the contradiction concrete. The duty to have at least one regulatory sandbox per member state already existed, with 2 August 2026 as the deadline. The omnibus moved it to 2 August 2027. The assignment to set the sandbox up ends seven months before the new deadline.

The counterweight is the calendar. The high risk requirements for Annex III start to apply on 2 December 2027, eleven months after the assignment has run out. In the time between, classifications have to be made, documentation built and impact assessments written. The allocation in force today is the only indication there is of where that work will be read, and it sits so close to the inquiry's proposal that it would be unusual if the permanent arrangement looked materially different.

And one thing applies already. The prohibitions in Article 5 have applied since 2 February 2025, and the decision allocates supervision of those too: PTS and Finansinspektionen get the prohibitions within their own areas, IMY everything else. Two prohibitions are newer than that. The omnibus added prohibitions on AI that generates non consensual intimate material and child sexual abuse material, and both of those apply only from 2 December 2026.

The dates that govern AI Act supervision in Sweden

  1. The Article 5 prohibitions start to apply
  2. The government allocates responsibility to five authorities
    Government decision III:50, Fi2026/01365. Published on 12 June.
  3. The AI Act applies in general
  4. The two new Article 5 prohibitions start to apply
    Added by Regulation (EU) 2026/1744. The same date ends the transition for the Article 50(2) marking obligation.
  5. The assignment to the five authorities ends
  6. The regulatory sandbox must be operational
  7. Annex III high risk requirements start to apply
  8. Annex I high risk requirements start to apply

Source: Government decision III:50 Fi2026/01365 of 4 June 2026 and Regulation (EU) 2024/1689 Article 113 as amended by Regulation (EU) 2026/1744

The question that decides which authority is yours

Two organisations in the same industry can end up with different authorities, and two in entirely different industries with the same one. The road to the answer never runs through the industry. It runs through three questions, in this order.

Which use case is it, not which system? A recruitment tool is point 4 whether it is sold as an HR system, as an advertising platform, or as a feature in something you already have. It is the use that is listed in Annex III, not the product category.

Is the AI inside a product with its own legislation? Then Article 6(1) and Annex I apply instead. The decision names two areas, medical devices with the Medical Products Agency and radio equipment with PTS. For other products in Section A of Annex I the general rule in Article 74(3) applies: the authority is the one that already has market surveillance of the product. If the product sits in Section B, meaning vehicles, aviation, rail, marine equipment or machinery, only a handful of the Act's provisions apply to it at all. That difference also settles which date applies, 2 December 2027 for Annex III and 2 August 2028 for Annex I.

Are you already supervised by someone? It matters in exactly one place, creditworthiness in point 5(b), and there it settles the whole answer.

An organisation that can answer those three knows which authority will read its classification, and therefore which language the classification has to be written in. One that cannot has an inventory problem rather than an authority problem, and the inventory is the first step in the governance work.


Common questions

Five, under government decision III:50 of 4 June 2026, reference Fi2026/01365. PTS, IMY and Finansinspektionen are market surveillance authorities for their own sets of points in Annex III. The Medical Products Agency covers AI in medical devices and is the notifying authority for them. Swedac carries out no market surveillance; it is the notifying authority for everything else. The assignment runs until 31 December 2026.

Annex III lists eight areas in which an AI system is high risk under Article 6(2): biometrics, critical infrastructure, education, employment, access to essential services and benefits, law enforcement, migration and asylum, and administration of justice and democratic processes. The classification turns on the use case, not on how advanced the technology is. The requirements for these systems start to apply on 2 December 2027.

The Swedish Post and Telecom Authority, PTS. Employment is point 4 in Annex III, and that point is part of the assignment the government gave PTS on 4 June 2026. The point covers targeted job advertisements, filtering of applications, evaluation of candidates, and decisions on promotion and termination. That the authority otherwise works on electronic communications has no bearing on the allocation.

The Swedish Post and Telecom Authority, PTS. Education is point 3 in Annex III and is part of the PTS assignment. The point covers systems that determine admission to education, that evaluate learning outcomes, that assess the level of education a person should receive, and that monitor prohibited behaviour during tests. It applies at every level of the education system.

Six things. Market surveillance of points 2, 3, 4, 5(a) and 5(d) in Annex III, that is critical infrastructure, education, employment, essential public benefits and emergency services. Market surveillance of the prohibited practices in Article 5 within those same areas. Market surveillance of high risk systems in products covered by the Radio Equipment Directive. The transparency obligations in Article 50(1), (2) and (4). The single point of contact role under Article 70(2). And setting up a regulatory sandbox under Article 57.

The Swedish Authority for Privacy Protection has points 1 and 6 to 8 in Annex III, that is biometrics, law enforcement, migration and asylum, and administration of justice, plus the part of point 5(b) on creditworthiness that falls outside the supervised perimeter of Finansinspektionen. IMY also has the transparency obligation in Article 50(3), which covers emotion recognition and biometric categorisation, and it is responsible for the prohibited practices in Article 5 in everything that PTS and Finansinspektionen did not get.

High risk AI systems under Article 6(1) that relate to products covered by Regulation (EU) 2017/745 on medical devices and Regulation (EU) 2017/746 on in vitro diagnostic medical devices. The agency is also the notifying authority for the bodies that assess conformity of such systems. It has no point in Annex III.

Until 31 December 2026, by its own wording. It is a government assignment and not a statute. The Swedish public inquiry on adapting national law to the AI Act, SOU 2025:101, proposes a permanent arrangement in legislation, but no bill building on it has been presented. The Annex III high risk requirements start to apply on 2 December 2027, that is after the assignment has expired.

The Swedish Post and Telecom Authority and the Agency for Digital Government merge on 1 January 2027, and the government intends to name the merged agency Digitaliseringsmyndigheten.


If this lands on your desk, we should talk.

Ampliro Insights

New analysis, roughly weekly.

We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.

We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.