report-ai-act-violation

How to report when someone breaks the AI Act

Your competitors can quickly report you for not complying. In Spain they do not even have to reveal their identity, and the EU whistleblower channel is anonymous for anyone working inside a company.

The Act is live, and so are the reporting channels. Some are surprisingly quick to use.

Verified 30 August 2026

First, EU level

Use these only if the target is a large AI provider rather than a company using AI.

Complaints tool
https://ai-act-complaints.integrityline.app/
Not anonymous, you must identify yourself.

Whistleblower tool
https://ai-act-whistleblower.integrityline.app/
Anonymous, for people working inside a provider.

For a normal Article 50 complaint about a publisher, an agency or a chatbot, go national instead. The AI Office will only forward it.

Where you can complain now

These are the countries where you can actually reach the responsible authority today. Only a handful have a dedicated AI Act complaint form. For the rest it is a general contact route, which still works, it is just slower.

Austria

RTR AI Service Desk. Contactable, formal designation still pending.

https://ki.rtr.at/

Cyprus

Commissioner of Communications. Dedicated national AI Act site.

https://ai.cy/
info@ocecpr.ee.cy

Czechia

Czech Telecommunication Office. Electronic submissions accepted.

https://ctu.gov.cz/en/artificial-intelligence
https://ctu.gov.cz/en/e-mailroom

Denmark

Agency for Digital Government. AI Act page with guidance.

https://digst.dk/tilsyn/ai-forordningen/
https://digst.dk/om-os/om-digitaliseringsstyrelsen/kontakt/

Finland

Traficom. Designated, general contact only.

https://www.traficom.fi/en/traficoms-contact-details

France

DGCCRF. Coordinating authority and single point of contact.

https://www.economie.gouv.fr/dgccrf

Dedicated form

Germany

Bundesnetzagentur. Dedicated AI Act complaint form. Online form only, they do not accept email. Free, no deadline.

https://www.bundesnetzagentur.de/DE/Fachthemen/Digitales/KI/18_Beschwerdestelle/start.html

Italy

Agenzia per la Cybersicurezza Nazionale.

https://www.acn.gov.it/portale/en/home
info@acn.gov.it

Latvia

Consumer Rights Protection Centre.

https://www.ptac.gov.lv/en/contacts

Complaint form

Lithuania

Communications Regulatory Authority. General complaint form available.

https://rrt.lt/veiklos-sritys/skaitmenine-erdve/di-informacija
https://rrt.lt/formos/PRy7MkYudzlfuZzM2kIsZsqlA9dPRS92_0CwQK552rE

Luxembourg

CNPD. Contactable, but the only form on the site is a GDPR complaint form.

https://cnpd.public.lu/en/support/contact.html

Malta

Malta Digital Innovation Authority.

https://www.mdia.gov.mt/malta-ai-strategy/artificial-intelligence/

Portugal

ANACOM. Reporting channel exists, not AI Act specific.

https://www.anacom.pt/render.jsp?categoryId=427803

Dedicated page

Slovenia

AKOS. Dedicated single point of contact page.

https://www.akos-rs.si/en/umetna-inteligenca/explore/single-point-of-contact
https://evloge.akos-rs.si/
info.box@akos-rs.si

Sweden

Post and Telecom Authority.

https://pts.se/en/contact/contact-us/

The remaining 8 EU countries, plus Norway

These have no direct AI Act route yet, so the best bet is the national data protection authority.

Read this first. A data protection authority is a fallback, not an equivalent. They are the right door if personal data is involved, or if they sit on that country’s Article 77 list of fundamental rights authorities. A pure labelling complaint with no personal data in it may get bounced.

Belgium

Autorité de protection des données / Gegevensbeschermingsautoriteit.

Complaint form https://www.autoriteprotectiondonnees.be/citoyen/agir/introduire-une-plainte
Contact https://www.autoriteprotectiondonnees.be/citoyen/agir/contact
contact@apd-gba.be

Bulgaria

Commission for Personal Data Protection.

https://www.cpdp.bg/
kzld@cpdp.bg

Croatia

AZOP.

https://azop.hr/
azop@azop.hr

Estonia

Andmekaitse Inspektsioon.

https://www.aki.ee/
info@aki.ee

Greece

Hellenic Data Protection Authority.

https://www.dpa.gr/
contact@dpa.gr

Hungary

NAIH.

https://naih.hu/
privacy@naih.hu

Poland

UODO.

Electronic complaint https://uodo.gov.pl/en/664/1408
Written complaint https://uodo.gov.pl/en/664/1406
Contact https://uodo.gov.pl/en/p/contact
kancelaria@uodo.gov.pl

Slovakia

Úrad na ochranu osobných údajov.

https://dataprotection.gov.sk/
statny.dozor@pdp.gov.sk

Designations are still moving. For any missing or inaccurate links, please let us know and we will change it.

Now read that list again from the other side.

Any of those forms can be filled in about you, by anyone, for free. The authority’s first question will be how the content was produced and who signed off on it. That answer is either on file or it is improvised.

Have the answer on file.

We give you a simple, tamper-evident record of who reviewed a piece of AI-assisted content, and when. So “a human reviewed this” is not just something you say when a regulator calls. It is something you can prove.

Create your account

Free for journalists, newsrooms, charities, NGOs and public bodies.

Similar Posts