Skip to content
Topic Contested in court

Authority Access Rights to AI Systems and Documentation

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during oversight activities, which is a critical component of the cooperation framework but not fully captured by existing topics.

14 linked items 10 Laws3 Guidance1 Literature

Overview

9 sources · Jul 23, 2026

Legal Framework

Authority access rights to AI systems and documentation operate at the intersection of the AI Act and Regulation (EU) 2019/1020 on market surveillance and compliance of products. The AI Act incorporates the market surveillance architecture of Regulation 2019/1020, which grants competent authorities broad powers to access premises, inspect facilities, request documentation, examine source code, and obtain data samples necessary to verify conformity with regulatory requirements.

Article 85 of the AI Act establishes the right of any natural or legal person to lodge complaints with market surveillance authorities, creating a bottom-up trigger for oversight investigations. These complaints must be handled under the dedicated procedures established by national market surveillance authorities pursuant to Regulation 2019/1020. Recital 36 extends this framework specifically to biometric identification systems, requiring notification to both the market surveillance authority and the national data protection authority for each use of real-time biometric identification systems, with annual reporting obligations to the Commission.

Recital 130 introduces a narrow exception: market surveillance authorities may authorize the placing on the market of AI systems that have not undergone conformity assessment under exceptional circumstances involving public security, protection of life, environmental protection, or critical infrastructure — underscoring that authority access rights include both enforcement and emergency authorization functions.

Key Developments

The AI Act's enforcement architecture remains in its early implementation phase, but the underlying market surveillance framework under Regulation 2019/1020 has generated established practice that directly informs AI system oversight. Market surveillance authorities have consistently exercised powers to demand technical documentation, access testing environments, and inspect product facilities — a pattern that will extend to AI system providers and deployers.

The dual-track oversight model — where market surveillance authorities and national data protection authorities share competence for AI systems processing personal data — creates a practical requirement for coordinated authority access. Where an AI system implicates both conformity assessment failures and GDPR violations, organizations should expect parallel or joint inspections, document requests, and data access demands from both authority types.

Practical Guidance

  • Maintain a continuously updated documentation repository covering technical files, conformity assessments, risk management documentation, and post-market monitoring logs, structured for rapid production to market surveillance authorities on demand.
  • Establish internal protocols designating responsible personnel and escalation chains for responding to authority access requests within the timelines expected under Regulation 2019/1020 procedures.
  • For providers of biometric identification systems, implement automated notification workflows to both the market surveillance authority and the national data protection authority, and maintain annual reporting records as required by Recital 36.
  • Prepare access-ready testing environments that allow authorities to inspect AI system behavior, including source code review capabilities, without exposing production data or trade secrets beyond what is legally required.
  • Document any reliance on the Recital 130 exceptional authorization pathway with detailed justification linking the deployment to public security, life protection, environmental protection, or critical infrastructure protection.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 10
Art. 3(26) ‘market surveillance authority’ means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020… AI Act Art. 3(48) ‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union… AI Act Art. 5(4) Without prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for law enforcement p… AI Act Art. 22(4) The authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligati… AI Act art 85 Right to lodge a complaint with a market surveillance authority AI Act Jun 2024 rec 170 Recital 170 — complaint rights for AI regulation infringement AI Act Jun 2024 rec 36 Recital 36 — biometric system use notification and reporting AI Act Jun 2024 rec 130 Recital 130 — rapid deployment of innovative AI systems AI Act Jun 2024 rec 141 Recital 141 — real world testing conditions without sandbox AI Act Jun 2024 rec 156 Recital 156 — market surveillance and compliance enforcement framework AI Act Jun 2024 rec 161 Recital 161 — Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 159 Recital 159 — biometric AI surveillance authority powers AI Act Jun 2024 rec 153 Recital 153 — national competent authorities designation AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024
Guidance 3
§3 Adopted gait, fingerprints, DNA, voice, keystrokes and other biometric or behavioural signals - in any context. A ban is equally recommended on AI sys… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) §45 However, the EDPB and the EDPS underline that some provisions of the P roposal defining the tasks and powers of the different competent authorities un… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024 annual report 2021 EDPB Annual Report 2021 EDPB May 2022
Literature 1
Zeszyt Prawniczy UAM Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act Zeszyt Prawniczy UAM Dec 2025