AI Corrective Powers
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed to specifically address the corrective and intervention powers that authorities possess to protect fundamental rights, including emergency measures, system suspensions, and market restrictions that go beyond standard inspection and monitoring activities.
Overview
12 sources · Jul 23, 2026Legal Framework
Article 20 of the AI Act mandates that Member States equip market surveillance authorities with robust corrective powers to address non-compliant AI systems. Recital 159 elaborates that authorities overseeing high-risk AI applications in biometrics, law enforcement, migration, and justice must possess effective investigative and corrective powers. These powers include the authority to access all processed personal data and any information necessary for the authority to perform its tasks. The independence of these supervisory bodies, grounded in Article 16(2) TFEU and Article 39 TEU, guarantees the reliability and effectiveness of oversight. Furthermore, authorities must possess the statutory competence to bring infringements before judicial bodies and initiate legal proceedings. This ensures that when standard monitoring identifies a violation, the authority can escalate the matter to the judiciary, bridging the gap between administrative oversight and judicial enforcement.
Key Developments
The CJEU ruling in Schrems (C-362/14) established a critical precedent that supervisory authorities must possess the power to initiate judicial proceedings against infringements of data protection laws. This judicial referral requirement necessitates that AI oversight bodies are not merely advisory but possess the structural capacity to enforce fundamental rights through emergency interventions, system suspensions, and market restrictions. Historically, certain national data protection authorities lacked explicit statutory powers to bring cases before the courts, a deficiency that required legislative correction following the Schrems decision. This evolution demonstrates that EU law demands authorities be fully empowered to act decisively. Consequently, when AI systems pose systemic risks to fundamental rights, authorities can bypass standard administrative procedures and directly implement restrictive measures or seek immediate judicial intervention to halt harmful processing.
Practical Guidance
- Maintain comprehensive logs of all personal data processed by AI systems and ensure immediate accessibility for authorities, fulfilling the access requirements mandated by Recital 159 of the AI Act.
- Develop internal protocols for rapid compliance with emergency suspension orders, as market surveillance authorities can impose immediate restrictions on system deployment without prior negotiation.
- Conduct periodic risk assessments specifically targeting high-risk AI applications, such as biometric identification and law enforcement tools, to mitigate the likelihood of forced corrective interventions.
- Designate a legal liaison to manage communications with market surveillance authorities, ensuring timely responses to information requests and facilitating any necessary judicial proceedings initiated by the authority.
- Ensure that AI system architecture includes built-in suspension mechanisms or kill switches to comply with potential authority-mandated shutdowns and market withdrawals.