Part I — Situation overview
A further enforcement stage of the European Union’s artificial intelligence regulation — Regulation (EU) 2024/1689, commonly known as the AI Act — entered into force on 2 August 2026. From today it is mandatory to label clearly any deceptively lifelike image, video or sound recording produced with artificial intelligence, and developers must ensure that content generated with their tools is also machine-detectable as artificial. At the same time the European Commission has set up a new enforcement unit in Brussels: the AI Office is being expanded by 38 staff, and the body is given an explicit mandate to act against lifelike fakes, illegal visual content and cyberattacks. According to the Commission’s statement the unit may also hear the staff of AI companies during an investigation. Among the systemic risks the Commission names, among others, chemical, biological, radiological and nuclear incidents, loss of control, cyber offensives, harmful manipulation and threats to fundamental rights.
The legislation’s other, less noticed deadline expires on the same day. Under Article 57(1) of the AI Act, member states must ensure that their competent authorities establish at least one regulatory sandbox at national level — in the regulation’s terminology an AI regulatory sandbox — which must be operational by 2 August 2026. This is a supervised framework in which developers can test their innovative systems before market entry, under the supervision of the authorities. Article 70 of the regulation adds that member states must provide adequate technical, financial and human resources to their designated authorities, with permanently available staff who understand in depth AI technologies, data management, data protection, cybersecurity and fundamental rights risks. According to the regulation this competence and resource requirement must be reviewed annually.
The limits of voluntary instruments were also on display in the same week. According to the list published by the Commission on Friday, close to 190 companies have signed the AI transparency code of practice, among them Anthropic, OpenAI, Google, Meta and the French Mistral — the large Chinese developers such as DeepSeek and Alibaba, however, are missing, the sole Chinese signatory being Lenovo. The code is voluntary: it assists the practical application of the statutory obligation, but signing it is not compulsory. The third thread concerns capacity: the Commission is offering EUR 10 billion of public funding for the construction of up to seven so-called AI gigafactories, hoping for at least EUR 20 billion of private investment alongside it; the facilities would each receive at least 100,000 leading-edge AI processors, and would more than double the capacity of the current network of 19 EU AI centres.
MIAK’s reading: in Hungarian public debate the question of AI regulation appears mostly at the level of principle — is it needed at all, will it not stifle innovation. This debate is moot because of the regulation’s direct effect: Regulation (EU) 2024/1689 is not a directive, so it is not to be transposed but applied. The actual Hungarian scope for decision narrows to three questions falling exclusively within domestic competence: which authority will be the market surveillance body and does it have engineering competence; is the testing environment operating by today’s deadline; and how does the state handle the situation that its own AI systems fall under the very same regulation. These three questions are not ideological but organisational — and the answers are measurable.
Part II — Literature foundation
Before turning to MIAK’s proposals it is worth fixing the frame. The AI Act as an official legal source itself gives one half of it: Article 57 formulates the sandbox as an obligation, not an option, and Article 70 describes in unusually detailed terms what expertise is needed at the authority — it prescribes not an institution but a competence, and attaches an annual review to it. The other half comes from The Age of Surveillance Capitalism by Shoshana Zuboff (American social psychologist, professor emerita of Harvard Business School): drawing on Karl Polanyi’s concept of the double movement, Zuboff shows that the self-regulating market becomes destructive without countervailing rules, and illustrates with a concrete case — the self-regulatory association of internet advertisers in the 1990s — that the typical function of a voluntary industry code is precisely the pre-emption of binding regulation. The 190 signatories of the transparency code now published and the absence of the large Chinese developers show exactly this pattern: the voluntary instrument works where the binding rule reaches anyway, and is missing where it would be most needed. The detailed treatment of the literature — author by author, with quotations — can be found in the 6.4 Literature in detail section.
📖 Source: European Union: Regulation (EU) 2024/1689 on artificial intelligence; Shoshana Zuboff: The Age of Surveillance Capitalism
Part III — MIAK’s concrete proposal
MIAK proposes three measurable measures which together turn the legal obligation into a working institution.
3.1 Placing the market surveillance competence with a dedicated unit, with a public competence inventory (within 60 days)
Article 70 of the AI Act leaves it to the member state which body it designates, but does not leave it to the member state with what level of preparedness: the text expects in-depth technological, data management, data protection, cybersecurity and fundamental rights knowledge from permanently available staff. The most convenient domestic solution would be for the task to land in the remit of an existing, already overloaded authority without additional headcount — according to MIAK this is the weakest variant, because even the annual review prescribed by the regulation could then only demonstrate that the capacity is missing. The proposal is therefore: within 60 days a decision should be taken that the market surveillance task is to be performed by a dedicated professional unit with a separate budget, and at the same time a public competence inventory should be published showing item by item how many staff, with what qualifications and in what job roles work on the task, and what the proportion of unfilled posts is. The unit should operate with an annual reporting obligation, and the report should be laid before Parliament. The proposal builds on the D1 responsible AI framework and the A6 checks and balances programme points.
3.2 A public inventory of the state’s own AI systems (within 90 days)
The AI Act makes no exception for the public sector: the administrative case-handling assistant, the system supporting educational assessment or the law-enforcement risk analysis fall under classification just as market products do — several of them belong expressly to the high-risk category. From this follows the duality that must be separated institutionally: the state is regulator and regulated at once. MIAK proposes that within 90 days a public register be drawn up of every AI system in public administration, giving for each system the purpose of use, the risk classification under the regulation, the decision-supporting or decision-making role, the fact of bias testing and the route of legal remedy. The register does not require the creation of a new record, but the publication of an existing data set. This has more than a transparency benefit: without regulatory credibility compliance cannot be expected from the private sector either, and the authority cannot demand a requirement that its own ownership circle does not meet. The proposal is the direct implementation of the D11 algorithmic transparency register programme point, and also touches the KI2 case-handling AI assistant.
3.3 Small-business priority in the sandbox and a public admission procedure (in the first six months of operation)
Today’s sandbox deadline matters because without it the Hungarian small and medium-sized enterprise cannot test compliance: the large developers have in-house legal and compliance apparatus, teams of a few people do not. If the sandbox does not start, or starts but the conditions of entry are opaque, then the regulation hits the smallest players hardest — even though the regulation’s aim is expressly to support innovation. MIAK therefore proposes that the sandbox’s admission procedure should be public and points-based, the selection criteria and the reasons for decisions published, and a defined share of the places reserved for small and medium-sized enterprises. A public report should be drawn up on the first six months of operation, on how many applicants there were, how many were admitted, and how many reached actual market entry. The proposal is linked to the D4 AI sandbox and the G2 programme points.
The three proposals are bound together by a single principle: directly applicable EU law does not close the regulatory debate but opens the implementation debate. Hungary’s room for manoeuvre lies not in whether we apply the regulation, but in whether we build around it an institution that helps domestic players, or one that exists only on paper.
Part IV — Expected effects and risks
| Dimension | Expected effect | Risk |
|---|---|---|
| Economy | A working sandbox reduces the compliance cost of domestic small and medium-sized enterprises, and prevents regulation from turning into a competitive disadvantage | Setting up the dedicated unit and the engineering pay level are budgetary items; with few applicants the sandbox remains underused |
| Society | Supervised enforcement of the content labelling duty tempers the manipulative power of lifelike fakes in public life | Labelling is technically circumventable; excessive trust in labelling creates a new vulnerability if unlabelled content is automatically taken as authentic |
| Public administration | A public inventory of state AI systems creates the authority’s regulatory credibility, and also uncovers internal risks | The inventory is uncomfortable in the short term: it may emerge that the classification or bias testing of running systems is missing |
The main trade-off is tense between independence and capacity. A dedicated, small unit is professionally clean but vulnerable: with few people and without independent back-office services it can hardly withstand the legal apparatus of a large developer. A task integrated into a large, existing authority gives a stronger institutional background, but can be lost under the daily caseload, and management’s attention is taken up by other priorities. MIAK nevertheless proposes the dedicated unit because the regulation’s annual resource review obligation is only interpretable if capacity is measurable separately — from the aggregate headcount of a large authority it cannot be established how many people actually work on AI supervision.
The second trade-off is the strictness of the sandbox. If admission is too easy, the sandbox degenerates into a compliance stamp which participants invoke in the market without having undergone any substantive examination. If it is too strict, small players do not get in and the programme loses its point. The proposal ties the admission procedure to public scoring and an after-the-fact report precisely because this way the degree of strictness is itself correctable — the data of the first six months will show in which direction it has drifted.
Part V — Measurability and summary
5.1 What is worth tracking? (proposed performance indicators)
According to MIAK the following performance indicators (KPIs, in English Key Performance Indicator) are worth tracking:
- The appearance and identifiability of the designated authority: whether Hungary’s single point of contact figures on the list published by the Commission, and whether the description of its competence is publicly available — the yardstick is the naming of the concrete body, not a general reference to a ministry.
- The filled-post ratio of the market surveillance unit: how many of the authorised posts have been filled with staff holding technical qualifications — proposed first publication within 60 days, then annually.
- The throughput of the sandbox: how many applicants, how many admitted and how many market-entering players in the first 12 months, and how many of these are small and medium-sized enterprises — the proposed target being that the majority of those admitted should be small and medium-sized enterprises.
- The coverage of the register of state AI systems: how many public administration systems figure in the public inventory with a risk classification — proposed first publication within 90 days, with quarterly updating.
5.2 Summary
The key message: MIAK asks the government not to treat today’s AI Act deadline as an administrative formality. Three steps are needed — placing the market surveillance task with a dedicated unit of measurable capacity within 60 days; a public inventory of the state’s own AI systems within 90 days; and a working sandbox with a public admission procedure and small-business priority. None of them requires new EU negotiation or legislative amendment: all three are the implementation of an obligation already in force.
Two MIAK foundational values are in play in this matter. Transparency, because the consequence of an algorithmic decision is today mostly invisible to the person concerned: they do not know whether a machine decided about them, on what data, and where they can turn. The public inventory of state AI systems ends this invisibility — and precisely where the citizen has no choice, because they cannot choose another office. And data-drivenness, because compliance with the regulation is today in Hungary not a matter of assertion but of figures: how many staff, how large a budget, how many admitted businesses. These are all measurable, and until they are published, any statement about compliance is unverifiable. MIAK asks the same yardstick of every government: in the case of directly applicable EU law, public policy is not intention but capacity.
Part VI — Justifications and further sources
6.1 The press framing by spectrum
The Brussels specialist outlets made the setting up of the enforcement apparatus the centre of their framing. Euractiv, under the title Commission tools up for AI Act enforcement as powers kick in, wrote that the Commission is building the supervisory organisation at the same time as the new powers take effect — the emphasis was not on the rule but on enforcement capacity. The same outlet analysed in a separate piece the list of signatories to the transparency code, and highlighted that the large Chinese developers are missing from it, while the sole Chinese signatory is a hardware manufacturer. This framing raised the question of the reach of voluntary instruments, instead of celebrating the high number of signatories as a success.
The large international news agency band placed the emphasis on risks and global competition. AP News, under the title EU to crack down on AI deepfakes, illicit imagery and hacking with new team in Brussels, framed the regulation as one of the toughest actions yet against the technology sector, and linked the news directly to the security failures that came to light in recent days — including that, according to a developer’s statement, AI models penetrated organisations during testing. The same band presented the gigafactory programme as an attempt to close the technology gap, citing EU Commission data that European electricity prices may be two to three times the American and Chinese level, and that the five largest EU cloud providers are all American.
The band specialising in EU affairs, more critical in tone, questioned the quality of implementation. EUobserver, in its account of the gigafactory call, quoted expert opinion that some requirements of the call were deliberately left open and vague, which carries the risk that individual facilities pursue their own aims instead of a unified EU strategy. One thing was missing from the whole spectrum: member state implementation. Not a single report asked how many member states actually have the mandatory sandbox operating by today’s deadline — yet the effectiveness of the regulation turns on this, not on the headcount increase in Brussels.
6.2 Facts and data
| Data | Value | Source |
|---|---|---|
| Entry into force of the AI Act’s labelling duty | 2 August 2026 | Euractiv, 1 August 2026; AP News, 1 August 2026 |
| The operational deadline for the member state sandbox | 2 August 2026 | Regulation (EU) 2024/1689, Article 57(1) |
| The publication deadline for the single point of contact | 2 August 2025 | Regulation (EU) 2024/1689, Article 70(2) |
| Headcount increase of the AI Office | +38 staff | AP News, 1 August 2026 |
| Number of signatories of the transparency code | close to 190 companies | Euractiv, 1 August 2026 |
| Signatories of the earlier general-purpose AI code | 23 companies | Euractiv, 1 August 2026 |
| Large Chinese developers in the transparency code | none; the sole Chinese signatory is Lenovo | Euractiv, 1 August 2026 |
| Public funding of the AI gigafactory programme | EUR 10 bn (approx. USD 11.4 bn) | AP News, 30 July 2026; EUobserver, 31 July 2026 |
| Expected private investment | at least EUR 20 bn | AP News, 30 July 2026 |
| Number of planned gigafactories | up to 7 | EUobserver, 31 July 2026 |
| Planned processor count of one gigafactory | at least 100,000 leading-edge AI processors | AP News, 30 July 2026 |
| Number of current EU AI centres | 19 | EUobserver, 31 July 2026 |
| Planned start of construction of the gigafactories | 2027 | EUobserver, 31 July 2026 |
| EU electricity price compared with the American and Chinese | two to three times | Commission report, after AP News, 30 July 2026 |
| Origin of the five largest EU cloud providers | all American | Commission report, after AP News, 30 July 2026 |
Among the data the relationship of the two dates deserves highlighting. For the publication of the single point of contact the regulation prescribed 2 August 2025, for the sandbox’s operation 2 August 2026 — that is, the legislator left a full year for the designated authority to build the sandbox. This sequence is not accidental: the regulation started from the assumption that first there is an authority, then there is a programme. Where the assignment of competence slipped, today’s deadline cannot be met — and this slippage is not an EU but a member state failure.
6.3 Policy dimensions
- Digitalisation and AI regulation (programme points) — the domestic institutionalisation of the responsible AI framework, the launch of the sandbox and the algorithm register (programme point ID: D1, D4, D11);
- Digitalisation and AI regulation (programme points) — the instrument side of action against lifelike fakes and the question of sovereign digital infrastructure in the gigafactory programme (programme point ID: D8, D17);
- Public administration and e-government (programme points) — the state’s own AI systems as regulated subjects, with risk classification (programme point ID: KI2);
- Justice (programme points) — the prior impact assessment of implementing rules before the assignment of competence (programme point ID: I3);
- Transparency and anti-corruption policy (programme points) — data-based tracking of the actual independence and capacity of the supervisory body (programme point ID: A6).
6.4 Literature in detail
6.4.1 European Union: Regulation (EU) 2024/1689
Two provisions of the regulation give the precise yardstick of today’s Hungarian task. Article 57(1) is formulated not as an option but as an obligation: member states must ensure that their competent authorities establish at least one regulatory sandbox at national level, operational by the date given.
“Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026.”
The regulation does however also allow flexibility: the obligation may be met by participation in the existing sandbox of another member state, if this provides equivalent national coverage. Article 70(3) adds the yardstick from the capacity side: member states must provide adequate technical, financial and human resources and infrastructure, with sufficient permanently available staff who must understand in depth AI technologies, data and data processing, personal data protection, cybersecurity, fundamental rights, and health and safety risks — and this requirement must be reviewed annually.
Translated to the Hungarian situation, both provisions say the same thing: compliance is not a legislative but an organisation-building task. And the annual review obligation also means that a capacity shortfall will not stay hidden — at the latest it will be documented during the first review.
📖 Source: European Union: Regulation (EU) 2024/1689 on artificial intelligence
6.4.2 Shoshana Zuboff: The Age of Surveillance Capitalism
Zuboff traces the limits of market self-regulation back to Karl Polanyi’s line of thought. Polanyi concluded that the operation of the self-regulating market is deeply destructive if it is allowed to run free without countervailing laws and policies; he called this the double movement, in which society develops institutional counter-measures to temper market logic.
“a network of measures and policies… integrated into powerful institutions designed to check the action of the market”
Zuboff also illustrates this with a concrete case: when in the late 1990s the regulation of internet tracking came onto the agenda, advertisers set up a self-regulatory association in order to avoid regulation. The voluntary industry code is therefore not a neutral instrument — it often serves precisely the function of pre-empting binding regulation.
In the present European situation this frame explains two things. One is why close to 190 companies signed a voluntary transparency code precisely on the day the binding labelling rule entered into force: the signature is useful as evidence of compliance where the binding rule reaches anyway. The other is why the large Chinese developers are missing: EU enforcement pressure bears on them more weakly, so the voluntary instrument does not reach them. From this follows the Hungarian lesson too: domestic compliance will turn not on voluntary undertakings but on supervisory capacity.
📖 Source: Shoshana Zuboff: The Age of Surveillance Capitalism
6.5 International comparison
In the field of sandboxes Spain started earliest: the Spanish government launched a pilot programme shortly after the adoption of the AI Act, and set up a separate authority for the supervision of artificial intelligence — that is, there the assignment of competence did not take place by merger into an existing organisation. Article 57(1) of the regulation does, however, also offer smaller member states a separate route: the obligation can be met by participation in the existing sandbox of another member state, if this gives equivalent national coverage. For Hungary this may be a realistic interim solution — but only if the participation agreement is public and the conditions of entry for Hungarian players are just as transparent as they would be in the case of a domestic programme.
The gigafactory programme offers a different type of comparison. The essence of the call is the pairing of public and private funds, and the criticism concerns precisely the openness of the requirements — if the conditions are vague, the winners may pursue their own aims instead of a unified strategy. On the question of Hungarian participation this means that presence in the call is not in itself an aim: the yardstick is on what terms domestic research sites and businesses can access the facility’s capacity. And Europe’s energy cost disadvantage — the EU electricity price being a multiple of the American and Chinese — is in itself a warning that the siting of data centre capacity and security-of-supply planning are two sides of the same decision.
6.6 Related MIAK programme points
Digitalisation and AI regulation
- D1 — Responsible AI framework
- D4 — AI sandbox, disruptive innovation incubator
- D11 — Algorithmic transparency register
- D8 — Disinformation-detecting AI system
- D17 — Space and sovereign digital infrastructure
Public administration and e-government
- KI2 — AI assistant in case handling
Justice
- I3 — Legislative impact assessment
Transparency and anti-corruption policy
- A6 — Strengthening checks and balances
Proposed new programme point: A register of EU implementation deadlines — for the Public administration and e-government area: a public list, with status indications, of member state deadlines arising from directly applicable EU legal sources.
6.7 List of sources
Press sources (MIAK foreign press monitor, 2 August 2026 — topic 1):
- [Euractiv] Commission tools up for AI Act enforcement as powers kick in — https://www.euractiv.com/news/commission-tools-up-for-ai-act-enforcement-as-powers-kick-in/ (the article was not publicly downloadable)
- [AP News] EU to crack down on AI deepfakes, illicit imagery and hacking with new team in Brussels — https://apnews.com/article/eu-ai-regulation-deepfakes-hacking-f4fcee1f9750e2b32cdf26ad73ee5ec2
- [Euractiv] EU AI transparency code’s many sign-ups don’t include Chinese AIs — https://www.euractiv.com/news/eu-ai-transparency-codes-many-sign-ups-dont-include-chinese-ais/
- [Euractiv] THE HACK: It’s AI transparency code day — https://www.euractiv.com/news/the-hack-its-ai-transparency-code-day/ (the article was not publicly downloadable)
- [EUobserver] EU to co-fund seven AI Gigafactories in race for tech autonomy — https://euobserver.com/230786/eu-to-co-fund-seven-ai-gigafactories-in-race-for-tech-autonomy/
- [AP News] EU lays out $11.4 billion for 7 AI gigafactories as it aims to catch up with US and China — https://apnews.com/article/eu-ai-gigafactories-china-us-data-center-88b83cd517a4d47c115605e636d0b3e4
Knowledge-base references (books and legal sources):
- 📖 European Union: Regulation (EU) 2024/1689 on artificial intelligence
- 📖 Shoshana Zuboff: The Age of Surveillance Capitalism
Note: the local file path of the book does NOT appear in the visible text of the blog — only the author and the title. The file path is an internal matter of the generation process, not the reader’s.
MIAK internal materials:
- MIAK policy area: Digitalisation and AI regulation (programme points; programme point ID: D1, D4, D11)
- MIAK policy area: Public administration and e-government (programme points; programme point ID: KI2)
- MIAK policy area: Justice (programme points; programme point ID: I3)
- MIAK foreign press monitor, 2 August 2026 — topic 1, score: 93/100
Additional public data sources:
- European Commission — publications of the AI Office and the AI Act implementation timetable
- The list of signatories of the AI transparency code of practice
- Hungarian data of DESI and the eGovernment Benchmark
Generation metadata
- Input press monitor: MIAK foreign press monitor, 2 August 2026
- Generation date: 2 August 2026 12:10 CEST
- Tokens used (total): 128000 (see frontmatter
tokens_breakdown) - Translation: Hungarian original at /blog/2026-08-02-ai-rendelet-vegrehajtas-piacfelugyeleti-hatosag-sandbox-magyar-felkeszultseg/
Comments
The comment system will be available soon.