AI Act Procedures
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic is needed to capture the procedural architecture that underpins all compliance, assessment, and enforcement activities under the AI Act.
Overview
9 sources · Jul 23, 2026Legal Framework
The procedural architecture of the AI Act is anchored in several key provisions. Article 46 establishes a derogation mechanism from the conformity assessment procedure, permitting departures from standard assessment requirements under defined circumstances. This provision functions as a safety valve where strict adherence to the full conformity assessment would be impractical or disproportionate, while still maintaining regulatory oversight. Article 40 addresses harmonised standards and standardisation deliverables, creating a framework whereby compliance with adopted technical standards confers a presumption of conformity with the Act's substantive requirements. The interplay between these provisions forms the backbone of how providers demonstrate compliance: either through standardised assessment pathways or through reliance on harmonised standards that translate legal obligations into technical specifications.
The broader procedural framework also draws on established data protection mechanisms. The representative regime mirrors the GDPR model under Article 27 GDPR, where non-EU entities must designate a representative who can be approached by supervisory authorities and must cooperate on all compliance measures. Similarly, the role of approved codes of conduct, certification mechanisms, and standard contractual clauses — instruments familiar from GDPR Articles 40, 42, and 46 — reappears as appropriate safeguards that can be deployed without prior supervisory authorisation, provided they have already received regulatory approval through other channels.
Key Developments
The integration of GDPR-style procedural tools into the AI Act reflects lessons from nearly a decade of enforcement under the 1995 Privacy Directive and subsequently the GDPR. The Working Party 29 (predecessor to the EDPB) established in Opinion 1/2010 that joint controllership arrangements cannot override an individual's right to exercise GDPR rights against any controller party — a principle carried forward into the AI Act's shared responsibility framework. This means that procedural arrangements between multiple AI system providers or deployers cannot contractually limit regulatory access to any single party.
The exemption framework for small and medium-sized enterprises — drawing from the GDPR's proportionate approach under Article 30(5) GDPR — illustrates a consistent regulatory philosophy: reduced administrative burdens for organisations with fewer than 250 employees, unless processing involves risks to rights and freedoms, special categories of personal data, or criminal conviction data. This threshold-based approach is expected to inform how AI Act procedural requirements are calibrated for smaller providers.
Practical Guidance
Designate an EU representative if established outside the EU: Providers of AI systems placed on the EU market must appoint a representative who maintains records of compliance activities and serves as the contact point for supervisory authorities, paralleling the Article 27 GDPR representative model.
Leverage harmonised standards under Article 40: Where harmonised standards have been adopted for your AI system category, demonstrating compliance with those standards creates a presumption of conformity and can streamline the conformity assessment pathway.
Document derogations carefully under Article 46: If invoking a derogation from the conformity assessment procedure, maintain detailed records of the factual basis and notify the relevant authority, as unauthorised departures carry significant enforcement risk.
Use pre-approved safeguards to reduce authorisation friction: Approved codes of conduct, certification mechanisms, and standard contractual clauses can be deployed without separate supervisory approval, reducing procedural delays in cross-border AI deployments.
Preserve individual rights access pathways: Any procedural arrangement between joint providers or deployers must preserve the ability of affected individuals to exercise their rights against any party, regardless of internal allocation of responsibilities.