# AI Act Procedures — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-act-procedural-framework
> Sources are cited per item. Verify against the official texts before relying on them.

The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic is needed to capture the procedural architecture that underpins all compliance, assessment, and enforcement activities under the AI Act.

## Overview

## Legal Framework

The procedural architecture of the AI Act is anchored in several key provisions. Article 46 establishes a derogation mechanism from the conformity assessment procedure, permitting departures from standard assessment requirements under defined circumstances. This provision functions as a safety valve where strict adherence to the full conformity assessment would be impractical or disproportionate, while still maintaining regulatory oversight. Article 40 addresses harmonised standards and standardisation deliverables, creating a framework whereby compliance with adopted technical standards confers a presumption of conformity with the Act's substantive requirements. The interplay between these provisions forms the backbone of how providers demonstrate compliance: either through standardised assessment pathways or through reliance on harmonised standards that translate legal obligations into technical specifications.

The broader procedural framework also draws on established data protection mechanisms. The representative regime mirrors the GDPR model under Article 27 GDPR, where non-EU entities must designate a representative who can be approached by supervisory authorities and must cooperate on all compliance measures. Similarly, the role of approved codes of conduct, certification mechanisms, and standard contractual clauses — instruments familiar from GDPR Articles 40, 42, and 46 — reappears as appropriate safeguards that can be deployed without prior supervisory authorisation, provided they have already received regulatory approval through other channels.

## Key Developments

The integration of GDPR-style procedural tools into the AI Act reflects lessons from nearly a decade of enforcement under the 1995 Privacy Directive and subsequently the GDPR. The Working Party 29 (predecessor to the EDPB) established in Opinion 1/2010 that joint controllership arrangements cannot override an individual's right to exercise GDPR rights against any controller party — a principle carried forward into the AI Act's shared responsibility framework. This means that procedural arrangements between multiple AI system providers or deployers cannot contractually limit regulatory access to any single party.

The exemption framework for small and medium-sized enterprises — drawing from the GDPR's proportionate approach under Article 30(5) GDPR — illustrates a consistent regulatory philosophy: reduced administrative burdens for organisations with fewer than 250 employees, unless processing involves risks to rights and freedoms, special categories of personal data, or criminal conviction data. This threshold-based approach is expected to inform how AI Act procedural requirements are calibrated for smaller providers.

## Practical Guidance

- **Designate an EU representative if established outside the EU**: Providers of AI systems placed on the EU market must appoint a representative who maintains records of compliance activities and serves as the contact point for supervisory authorities, paralleling the Article 27 GDPR representative model.

- **Leverage harmonised standards under Article 40**: Where harmonised standards have been adopted for your AI system category, demonstrating compliance with those standards creates a presumption of conformity and can streamline the conformity assessment pathway.

- **Document derogations carefully under Article 46**: If invoking a derogation from the conformity assessment procedure, maintain detailed records of the factual basis and notify the relevant authority, as unauthorised departures carry significant enforcement risk.

- **Use pre-approved safeguards to reduce authorisation friction**: Approved codes of conduct, certification mechanisms, and standard contractual clauses can be deployed without separate supervisory approval, reducing procedural delays in cross-border AI deployments.

- **Preserve individual rights access pathways**: Any procedural arrangement between joint providers or deployers must preserve the ability of affected individuals to exercise their rights against any party, regardless of internal allocation of responsibilities.

## Legislation (full text of key provisions)

### Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

*Source: AI Act, aiact-art-59-en, 2024-06-12 — https://overview.legal/posts/92939*

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Derogation from conformity assessment procedure

*Source: AI Act, aiact-art-46-en, 2024-06-12 — https://overview.legal/posts/92688*

### Harmonised standards and standardisation deliverables

*Source: AI Act, aiact-art-40-en, 2024-06-12 — https://overview.legal/posts/92589*

### Presumption of conformity with requirements relating to notified bodies

*Source: AI Act, aiact-art-32-en, 2024-06-12 — https://overview.legal/posts/92508*

Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements.

### Recital 125 — High-risk AI systems conformity assessment procedure

*Source: AI Act, aiact-rec-125-en, 2024-06-12 — https://overview.legal/posts/93932*

Given the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 126 — notified body requirements and notification procedure

*Source: AI Act, aiact-rec-126-en, 2024-06-12 — https://overview.legal/posts/93934*

In order to carry out third-party conformity assessments when so required, notified bodies should be notified under this Regulation by the national competent authorities, provided that they comply with a set of requirements, in particular on independence, competence, absence of conflicts of interests and suitable cybersecurity requirements. Notification of those bodies should be sent by national competent authorities to the Commission and the other Member States by means of the electronic notification tool developed and managed by the Commission pursuant to Article R23 of Annex I to Decision No 768/2008/EC.

### Recital 81 — provider quality management system

*Source: AI Act, aiact-rec-81-en, 2024-06-12 — https://overview.legal/posts/93844*

The provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.

### Recital 139 — AI regulatory sandboxes innovation objectives

*Source: AI Act, aiact-rec-139-en, 2024-06-12 — https://overview.legal/posts/93960*

The objectives of the AI regulatory sandboxes should be to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase with a view to ensuring compliance of the innovative AI systems with this Regulation and other relevant Union and national law. Moreover, the AI regulatory sandboxes should aim to enhance legal certainty for innovators and the competent authorities’ oversight and understanding of the opportunities, emerging risks and the impacts of AI use, to facilitate regulatory learning for authorities and undertakings, including with a view to future adaptions of the legal framework, to support cooperation and the sharing of best practices with the authorities involved in the AI regulatory sandbox, and to accelerate access to markets, including by removing barriers for SMEs, including start-ups. AI regulatory sandboxes should be widely available throughout the Union, and particular attention should be given to their accessibility for SMEs, including start-ups. The participation in the AI regulatory sandbox should focus on issues that raise legal uncertainty for providers and prospective providers to innovate, experiment with AI in the Union and contribute to evidence-based regulatory learning. The supervision of the AI systems in the AI regulatory sandbox should therefore cover their development, training, testing and validation before the systems are placed on the market or put into service, as well as the notion and occurrence of substantial modification that may require a new conformity assessment procedure. Any significant risks identified during the development and testing of such AI systems should result in adequate mitigation and, failing that, in the suspension of the development and testing process. Where appropriate, national competent authorities establishing AI regulatory sandboxes should cooperate with other relevant authorities, including those supervising the protection of fundamental rights, and could allow for the involvement of other actors within the AI ecosystem such as national or European standardisation organisations, notified bodies, testing and experimentation facilities, research and experimentation labs, European Digital Innovation Hubs and relevant stakeholder and civil society organisations. To ensure uniform implementation across the Union and economies of scale, it is appropriate to establish common rules for the AI regulatory sandboxes’ implementation and a framework for cooperation between the relevant authorities involved in the supervision of the sandboxes. AI regulatory sandboxes established under this Regulation should be without prejudice to other law allowing for the establishment of other sandboxes aiming to ensure compliance with law other than this Regulation. Where appropriate, relevant competent authorities in charge of those other regulatory sandboxes should consider the benefits of using those sandboxes also for the purpose of ensuring compliance of AI systems with this Regulation. Upon agreement between the national competent authorities and the participants in the AI regulatory sandbox, testing in real world conditions may also be operated and supervised in the framework of the AI regulatory sandbox.

## Recent developments

### De FRIA voor AI-systemen komt eraan: bereid u voor

*Source: Autoriteit Persoonsgegevens, 2026-08-17 — https://overview.legal/posts/291285 — original: https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor*

Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als publieke of private organisatie een beoordelingssysteem voor financiële risico’s gebruiken? Dan moet u vanaf december 2027 vooraf beoordelen welke gevolgen dit AI-systeem kan hebben voor de grondrechten van mensen. Zo’n beoordeling heet een ‘fundamental rights impact assessment’ (FRIA), oftewel een ‘grondrechteneffectbeoor

## Related topics

- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Notified Bodies for AI Systems** — https://overview.legal/topics/notified-bodies-ai
  This topic is needed to comprehensively cover the role, responsibilities, and obligations of notified bodies in the AI Act conformity assessment framework, incl
- **AI Standards** — https://overview.legal/topics/harmonised-standards-ai
  This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their deve
- **Conformity Body Notification** — https://overview.legal/topics/conformity-assessment-body-notification
  This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Ac
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their

---
Generated by overview.legal · https://overview.legal/topics/ai-act-procedural-framework · 2026-08-22
