Authority Access Rights to AI Systems and Documentation
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during oversight activities, which is a critical component of the cooperation framework but not fully captured by existing topics.
Overview
10 sources · Aug 27, 2026Legal Framework
Authority access to AI systems and documentation is governed primarily by Article 22 and Article 26 of the AI Act. Article 22 requires providers of high-risk AI systems established outside the Union to appoint an authorised representative who must maintain documentation at the disposal of competent authorities for a decade after market placement:
"keep at the disposal of the competent authorities and national authorities or bodies referred to in Article 74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into service"
— AI Act Art. 22(3)(b)
Upon a reasoned request, the authorised representative must also:
"provide a competent authority, upon a reasoned request, with all the information and documentation"
— AI Act Art. 22(3)(c)
Article 26 imposes parallel duties on deployers, who must monitor operation and report risks to market surveillance authorities. Where a deployer identifies that a high-risk system may present a risk:
"they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system"
— AI Act Art. 26(5)
Key Developments
The EDPB-EDPS Joint Opinion 5/2021 raised early concerns about the independence of competent authorities, noting that the AI Act proposal did not require supervisory authorities to be independent — a departure from Regulation 2019/1020. The EDPB's Statement 3/2024 reinforced that:
"a prominent role of the DPAs at national level should be recognised, in particular due to the experience and expertise"
— EDPB Statement 3/2024 §5
This signals that data protection authorities are positioned to play a central enforcement role, though the exact scope of their access rights relative to other market surveillance authorities remains unresolved.
Status of the Debate
This topic is contested. The AI Act establishes multiple authority types — market surveillance authorities, competent authorities, and DPAs — with overlapping but not identical access powers. No court has yet interpreted the boundaries between these authorities' respective rights to access AI systems, facilities, and documentation. The core open question is whether DPAs, acting as market surveillance authorities under the AI Act, can exercise the full range of inspection powers available under Regulation 2019/1020, or whether their access is constrained to data protection-specific grounds. A national court decision or preliminary ruling clarifying the interaction between these regulatory regimes would resolve the ambiguity.
Practical Guidance
- Maintain a 10-year documentation repository: Providers and authorised representatives must keep technical documentation, EU declarations of conformity, and provider contact details available for competent authorities for a decade after market placement under Article 22(3)(b).
- Establish a reasoned-request response protocol: Article 22(3)(c) requires provision of information upon a "reasoned request" — build internal procedures to verify the legal basis and scope of any authority request before disclosing technical documentation.
- Implement deployer monitoring and reporting pipelines: Under Article 26(5), deployers must inform both the provider and the relevant market surveillance authority without undue delay when they identify a risk; maintain pre-configured escalation channels to meet this deadline.
- Track national designations of market surveillance authorities: Member States are still designating MSAs under the AI Act; monitor national implementing legislation to identify which authority holds access rights over your AI systems.
Nothing of this type on this topic.