The AI Act is EU law and applies identically across the union, but enforcement is national: each member state names its own supervisory authorities. Sweden has not finished doing so.
The government has given the Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS) an interim mandate as national competent authority until 31 December 2026. A public inquiry has proposed PTS for the permanent role, and that proposal is not law yet.
The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) covers AI that processes personal data, the Swedish Financial Supervisory Authority (Finansinspektionen) the financial sector, and the Swedish Medical Products Agency (Läkemedelsverket) medical devices and care.
The Swedish Board for Accreditation and Conformity Assessment (Styrelsen för ackreditering och teknisk kontroll, Swedac), the national accreditation body, accredits the notified bodies.
For most organisations the practical consequence is simple: AI supervision will largely arrive through authorities you already know.
IMY has an inspection of a region's AI transcription service in primary care underway, opened in May 2026. It rests on data protection law rather than on the AI Act, which is the useful lesson: the first supervisory pressure on AI in Sweden arrives through the GDPR.
A Swedish implementing act and a regulatory sandbox are still to come. We track both.