Skip to content
Topic Regulator-defined

AI Corrective Powers

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed to specifically address the corrective and intervention powers that authorities possess to protect fundamental rights, including emergency measures, system suspensions, and market restrictions that go beyond standard inspection and monitoring activities.

11 linked items 5 Laws3 Guidance1 Enforcement2 Literature

Overview

12 sources · Jul 23, 2026

Legal Framework

Article 20 of the AI Act mandates that Member States equip market surveillance authorities with robust corrective powers to address non-compliant AI systems. Recital 159 elaborates that authorities overseeing high-risk AI applications in biometrics, law enforcement, migration, and justice must possess effective investigative and corrective powers. These powers include the authority to access all processed personal data and any information necessary for the authority to perform its tasks. The independence of these supervisory bodies, grounded in Article 16(2) TFEU and Article 39 TEU, guarantees the reliability and effectiveness of oversight. Furthermore, authorities must possess the statutory competence to bring infringements before judicial bodies and initiate legal proceedings. This ensures that when standard monitoring identifies a violation, the authority can escalate the matter to the judiciary, bridging the gap between administrative oversight and judicial enforcement.

Key Developments

The CJEU ruling in Schrems (C-362/14) established a critical precedent that supervisory authorities must possess the power to initiate judicial proceedings against infringements of data protection laws. This judicial referral requirement necessitates that AI oversight bodies are not merely advisory but possess the structural capacity to enforce fundamental rights through emergency interventions, system suspensions, and market restrictions. Historically, certain national data protection authorities lacked explicit statutory powers to bring cases before the courts, a deficiency that required legislative correction following the Schrems decision. This evolution demonstrates that EU law demands authorities be fully empowered to act decisively. Consequently, when AI systems pose systemic risks to fundamental rights, authorities can bypass standard administrative procedures and directly implement restrictive measures or seek immediate judicial intervention to halt harmful processing.

Practical Guidance

  • Maintain comprehensive logs of all personal data processed by AI systems and ensure immediate accessibility for authorities, fulfilling the access requirements mandated by Recital 159 of the AI Act.
  • Develop internal protocols for rapid compliance with emergency suspension orders, as market surveillance authorities can impose immediate restrictions on system deployment without prior negotiation.
  • Conduct periodic risk assessments specifically targeting high-risk AI applications, such as biometric identification and law enforcement tools, to mitigate the likelihood of forced corrective interventions.
  • Designate a legal liaison to manage communications with market surveillance authorities, ensuring timely responses to information requests and facilitating any necessary judicial proceedings initiated by the authority.
  • Ensure that AI system architecture includes built-in suspension mechanisms or kill switches to comply with potential authority-mandated shutdowns and market withdrawals.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 5
Art. 20(2) Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately in… AI Act Art. 44(3) Where a notified body finds that an AI system no longer meets the requirements set out in Section 2, it shall, taking account of the principle of prop… AI Act Art. 57(11) The AI regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at… AI Act Art. 73(6) Following the reporting of a serious incident pursuant to paragraph 1, the provider shall, without delay, perform the necessary investigations in rela… AI Act rec 164 Recital 164 — AI Office monitoring and enforcement powers AI Act Jun 2024 rec 66 Recital 66 — risk management requirements for high-risk AI AI Act Jun 2024 rec 159 Recital 159 — biometric AI surveillance authority powers AI Act Jun 2024 rec 156 Recital 156 — market surveillance and compliance enforcement framework AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024
Guidance 3
of the work undertaken by the chatgpt taskforce Report of the work undertaken by the ChatGPT Taskforce EDPB May 2024 strategy 2024 2027 EDPB Strategy 2024-2027 EDPB Apr 2024 of the edpb to the european commissions Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62 EDPB Dec 2021
Enforcement 1
EDPS EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft EDPS Mar 2024
Literature 2
Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023 Journal of European Competition Law & Practice Training national judges for digital competition law: the DMA, private enforcement, and the infrastructure of judicial capacity Journal of European Competition Law & Practice May 2026