Skip to content
Topic Developing

AI Act Procedures

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic is needed to capture the procedural architecture that underpins all compliance, assessment, and enforcement activities under the AI Act.

22 linked items 21 Laws1 News

Overview

9 sources · Jul 23, 2026

Legal Framework

The procedural architecture of the AI Act is anchored in several key provisions. Article 46 establishes a derogation mechanism from the conformity assessment procedure, permitting departures from standard assessment requirements under defined circumstances. This provision functions as a safety valve where strict adherence to the full conformity assessment would be impractical or disproportionate, while still maintaining regulatory oversight. Article 40 addresses harmonised standards and standardisation deliverables, creating a framework whereby compliance with adopted technical standards confers a presumption of conformity with the Act's substantive requirements. The interplay between these provisions forms the backbone of how providers demonstrate compliance: either through standardised assessment pathways or through reliance on harmonised standards that translate legal obligations into technical specifications.

The broader procedural framework also draws on established data protection mechanisms. The representative regime mirrors the GDPR model under Article 27 GDPR, where non-EU entities must designate a representative who can be approached by supervisory authorities and must cooperate on all compliance measures. Similarly, the role of approved codes of conduct, certification mechanisms, and standard contractual clauses — instruments familiar from GDPR Articles 40, 42, and 46 — reappears as appropriate safeguards that can be deployed without prior supervisory authorisation, provided they have already received regulatory approval through other channels.

Key Developments

The integration of GDPR-style procedural tools into the AI Act reflects lessons from nearly a decade of enforcement under the 1995 Privacy Directive and subsequently the GDPR. The Working Party 29 (predecessor to the EDPB) established in Opinion 1/2010 that joint controllership arrangements cannot override an individual's right to exercise GDPR rights against any controller party — a principle carried forward into the AI Act's shared responsibility framework. This means that procedural arrangements between multiple AI system providers or deployers cannot contractually limit regulatory access to any single party.

The exemption framework for small and medium-sized enterprises — drawing from the GDPR's proportionate approach under Article 30(5) GDPR — illustrates a consistent regulatory philosophy: reduced administrative burdens for organisations with fewer than 250 employees, unless processing involves risks to rights and freedoms, special categories of personal data, or criminal conviction data. This threshold-based approach is expected to inform how AI Act procedural requirements are calibrated for smaller providers.

Practical Guidance

  • Designate an EU representative if established outside the EU: Providers of AI systems placed on the EU market must appoint a representative who maintains records of compliance activities and serves as the contact point for supervisory authorities, paralleling the Article 27 GDPR representative model.

  • Leverage harmonised standards under Article 40: Where harmonised standards have been adopted for your AI system category, demonstrating compliance with those standards creates a presumption of conformity and can streamline the conformity assessment pathway.

  • Document derogations carefully under Article 46: If invoking a derogation from the conformity assessment procedure, maintain detailed records of the factual basis and notify the relevant authority, as unauthorised departures carry significant enforcement risk.

  • Use pre-approved safeguards to reduce authorisation friction: Approved codes of conduct, certification mechanisms, and standard contractual clauses can be deployed without separate supervisory approval, reducing procedural delays in cross-border AI deployments.

  • Preserve individual rights access pathways: Any procedural arrangement between joint providers or deployers must preserve the ability of affected individuals to exercise their rights against any party, regardless of internal allocation of responsibilities.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 21
Art. 112(4)(c) adopted harmonised standards and common specifications developed to support this Regulation; AI Act Art. 3(22) ‘notified body’ means a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation; AI Act Art. 3(25) ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI… AI Act Art. 3(55) ‘AI regulatory sandbox’ means a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the… AI Act rec 125 Recital 125 — High-risk AI systems conformity assessment procedure AI Act Jun 2024 art 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox AI Act Jun 2024 art 27 Fundamental rights impact assessment for high-risk AI systems AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 art 46 Derogation from conformity assessment procedure AI Act Jun 2024 art 40 Harmonised standards and standardisation deliverables AI Act Jun 2024 rec 126 Recital 126 — notified body requirements and notification procedure AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 139 Recital 139 — AI regulatory sandboxes innovation objectives AI Act Jun 2024 rec 117 Recital 117 — general-purpose AI model compliance codes AI Act Jun 2024 rec 140 Recital 140 — AI sandbox personal data reuse AI Act Jun 2024 rec 141 Recital 141 — real world testing conditions without sandbox AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 rec 173 Recital 173 — Commission delegated powers to adapt AI rules AI Act Jun 2024 rec 138 Recital 138 — national AI regulatory sandboxes for innovation AI Act Jun 2024 rec 121 Recital 121 — standardisation for regulatory compliance and innovation AI Act Jun 2024 rec 122 Recital 122 — high-risk AI compliance presumption AI Act Jun 2024 rec 50 Recital 50 — high-risk classification of safety-related AI systems AI Act Jun 2024 rec 78 Recital 78 — conformity assessment cybersecurity high-risk AI AI Act Jun 2024 art 32 Presumption of conformity with requirements relating to notified bodies AI Act Jun 2024 Show 1 more →
News 1
Autoriteit Persoonsgegevens De FRIA voor AI-systemen komt eraan: bereid u voor Autoriteit Persoonsgegevens Aug 2026 NL