In an earlier article I argued that the compliance standard has moved from "we completed the document" to "the information in the document matches reality". That leaves the question any practical person asks immediately afterwards: and how exactly will they find out?

The answer is more concrete than most expect — and more uneven. Real tools exist: a satellite reference layer, a central registry on which the Commission runs risk controls, minimum inspection rates imposed by regulation. But they are not distributed evenly, and the people using them work, from one member state to the next, in institutions so different that it is hard to call it the same system.

The pattern, in short: the Commission supplies the ammunition — data, algorithms, mandatory inspection thresholds. The member state pulls the trigger — inspection and sanction. Where national law is not ready, the ammunition exists without a trigger.

CBAM: the Commission calculates, the state executes

The first surprise for many importers: the CBAM declaration is filed with the Commission, not with the national authority. The Commission runs risk-based controls on the information and transactions recorded in the central registry and reviews declarations under a review strategy with risk factors (Art. 19). Its findings then go to the national authority.

The practical consequence is unusual: the national authority may determine, on the basis of the Commission's preliminary calculation, that further certificates must be surrendered. The ministry does not discover the discrepancy — it receives it already calculated and decides whether to enforce it.

The layer that does not exist yet

The definitive regime rests on accredited verification of emissions. The Commission's "State-of-play CBAM accreditation" document, dated 24 July 2026, shows where that infrastructure actually stands: 24 national accreditation bodies agreed to provide CBAM accreditation, but only 13 actually accept applications. Four states — Ireland, Cyprus, Estonia and Malta — decided not to offer the service at all. Romania's RENAR agreed, but is not yet accepting applications.

And the public list of accredited verifiers is, as this article goes out, empty. The Commission expects the first accreditations around September 2026 — even though accredited verification has been mandatory since 1 January 2026. The obligation began nine months ahead of the infrastructure that makes it possible.

For a sense of scale: the Commission reported that by 7 January 2026, over 12,000 economic operators had applied for CBAM authorisation and over 4,100 had obtained authorised declarant status.

Same rule, ten administrative cultures

This is where the European comparison gets interesting. From the Commission's official list, the CBAM competent authority sits in entirely different types of institution:

StateCompetent authorityType of institution
GermanyDEHStEnvironment agency
SwedenNaturvårdsverketEnvironment agency
FranceDirectorate-General for Energy and ClimateEnvironment ministry
ItalyComitato ETSEnvironment ministry
SpainMITECOEnvironment ministry
NetherlandsNEa + CustomsEmissions authority + customs
IrelandEPA + RevenueEnvironment agency + tax
PolandKOBiZE + Tax administrationEnvironmental institute + tax
RomaniaMinistry of Finance — CBAM and Green Taxation DirectorateFinance ministry

Extending the list: Austria and Finland assigned it to customs, Greece and Latvia to the tax administration, Denmark to the energy agency. Romania is the only one of the states above that administers CBAM from a pure finance ministry, through a dedicated directorate. That is not necessarily a disadvantage — a tax administration reads an import flow better than an environment agency does. But it means the questions you get at inspection will resemble a tax audit more than an environmental one, and your documentation should be built accordingly.

EUDR: the only one with a mandatory quota

EUDR carries the most explicit ammunition. The Commission supplies three things at once.

A reference layer. The JRC Observatory publishes the global forest cover map for 2020 at 10-metre resolution. Submitted polygons are compared against this layer, supplemented by Global Forest Watch deforestation alerts.

A country risk classification — high, standard or low — set by the Commission.

Minimum inspection rates tied to that classification (Art. 16): at least 1% of operators for low-risk countries, 3% for standard risk, 9% for high risk, every year. A member state cannot choose not to inspect.

Read the other way, the same figures say something else: between 91% and 99% of operators are not inspected in a given year. That sounds like a let-off. It is not — because the selection is not random. Who falls into that percentage is decided by risk analysis, and the criteria are exactly the ones the regulation makes available: country of origin, commodity, supplier history, consistency of the submitted data. Whoever has the worst-documented chain has the highest probability of being picked.

The penalty, when it comes, has an imposed floor: Art. 25 requires the maximum fine to be at least 4% of annual EU-wide turnover, plus confiscation and exclusion from the market. In Romania, enforcement falls to the Ministry of Environment through the National Forest Guard and the regional forest guards for wood products, the National Environmental Guard for other relevant products, and ANSVSA for the agri-food side. We covered the obligations in the EUDR guide for importers.

The AI Act: where divergence becomes dramatic

If CBAM differs in administrative culture, the AI Act differs in architecture. The deadline for designating national authorities was 2 August 2025. A European Parliament briefing from March 2026 records that the Commission's list contained, at that point, eight single points of contact out of 27.

And the states that have legislated chose solutions that are hard to compare with one another:

StateModelStatus at 31 July 2026
Germany Centralised on the telecoms regulator (Bundesnetzagentur), with an independent chamber for high-risk systems. The data protection authority was deliberately excluded. Law in force since 29 July 2026
Netherlands Decentralised, with the data protection authority at the centre — the exact opposite of the German choice Draft at pre-parliamentary stage; consultation closed 1 June 2026
Poland A new, dedicated collegiate body (KRiBSI), with members nominated by four existing regulators Law published 27 July 2026, in force 11 August 2026
Italy Two agencies: ACN supervises and sanctions, AgID notifies Law in force since October 2025, but the Art. 99 penalties are only delegated, deadline 10 October 2026
Ireland Distributed across sectoral authorities, plus a new national Office The AI Office, established as an independent statutory body on 30 July 2026, operational from 2 August
Denmark Three authorities, covering only the prohibited practices; the high-risk model is still undecided Law in force since 2 August 2025
Spain A dedicated agency (AESIA, established in 2023) plus sectoral authorities Bill before Congress, amendment deadline 2 September 2026 — powers not yet conferred
France Fully decentralised, no dedicated agency, roughly 17 sectoral bodies Bill adopted by the Senate in February 2026, pending at the National Assembly
Romania Decentralised across existing regulators: ANCOM, ADR, ASF, BNR, ANSPDCP, plus sectoral authorities Government memorandum, no law

The most instructive contrast is Germany versus the Netherlands. Both had to decide who supervises AI systems. Germany centralised on the telecoms regulator and kept its data protection authority out of market surveillance. The Netherlands built the exact inverse, putting the data protection authority at the centre of the arrangement. The same European obligation, two opposite philosophies about who is competent to judge an AI system.

Where Romania stands

The Romanian authorities were proposed by a government memorandum in March 2026 — the verb used in the document is "we propose", not "we designate". The memorandum acknowledges, in its own words, that Romania did not notify the Commission by the 2 August 2025 deadline.

The consequence is stated most clearly by the proposed authority itself. In its statement of 24 July 2026, ANCOM notes:

"ANCOM or the other competent authorities will be able to verify and sanction non-compliance with the Regulation only after the entry into force of the national act currently being drafted."

In other words: the Art. 50 transparency obligations apply from 2 August 2026, but the national sanctioning instrument had not been adopted when this article was published. That does not mean the obligations can be ignored — the regulation applies directly, the deadlines run, and the law, when it arrives, will not forgive the preceding period.

What this means for a company

Three practical conclusions follow from all of the above.

  1. Verification runs against data you do not control. A satellite layer, a central registry, a Commission preliminary calculation. You cannot prepare a file that "looks good" to an independent source — you can only make sure your data survives the comparison.
  2. Who inspects you depends on where you import from and where you are established. A Romanian steel importer will be dealing with a finance ministry; the same importer established in Germany would be dealing with an environment agency. Documentation should be built for the actual counterpart.
  3. The absence of a sanctioning instrument is not a postponement of the obligation. European deadlines run independently of the state of national law. The period in which nobody can fine you is exactly the period in which you should be building, not waiting.

How we can help

Speed Flow builds exactly the layer that is usually missing — the verifiable data infrastructure: CBAM Manager for collecting and validating emissions data, EUDR Manager for traceability and geolocation verification, and AI governance consulting for system inventory and classification. If you are not sure where you stand, take the quick CBAM / EUDR test — five questions, under a minute.