# AI Investigative Powers — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/authority-investigative-powers-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address the investigative and information-gathering powers of competent authorities under the AI Act, which is distinct from general cooperation obligations and encompasses the procedural mechanisms for requesting and obtaining documentation.

## Overview

## Legal Framework
The investigative powers of competent authorities are governed by **AI Act Recital 159** and supported by the principle of cooperation in **DSA Recital 127**. Recital 159 mandates that market surveillance authorities for high-risk AI systems in specified sensitive areas (e.g., law enforcement, migration) must possess effective investigative and corrective powers. This includes, at a minimum, the power to access all personal data processed by these AI systems. Recital 127 DSA underscores the necessity for a high level of cross-border cooperation and information exchange to enable consistent enforcement.

## Practical Application
These recitals establish a framework where authorities have broad access powers for monitoring compliance. The case law, such as *Weltimmo*, clarifies the territorial scope of an authority's investigative powers: a national authority may initiate an investigation based on a complaint within its own territory, even before determining the applicable national law. This principle supports the AI Act's approach, allowing authorities to investigate potential non-compliance with AI system requirements proactively. The powers are designed to be effective, meaning authorities can request and obtain necessary documentation and data to assess an AI system's conformity.

## Key Considerations
*   **Documentation Access:** Deployers and providers of high-risk AI systems in the sensitive areas listed must be prepared to provide authorities with access to all relevant documentation, training data, and logs upon request, as part of a compliance investigation.
*   **Cross-Border Cooperation:** Organizations operating across multiple EU Member States should anticipate that an investigation initiated by one national authority may involve coordinated information sharing with other competent authorities under the DSA and AI Act cooperation frameworks.
*   **Proactive Compliance:** Given the authority's power to investigate based on a complaint within its territory (as seen in *Weltimmo*), maintaining transparent and readily available technical documentation is critical for a swift and cooperative response to any inquiry.

## Legislation (full text of key provisions)

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

## Guidance

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62

*Source: EDPB, contribution-of-the-edpb-to-the-european-commissions-en, 2021-12-14 — https://overview.legal/posts/125973 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-european-commissions_en*

Adopted Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive ( LED ) under Article 62 Adopted on 14 December 2021 2 3 The European Data Protection Board Having regard to Articles 51(1)(a)(b) and (h) of the Directive ( EU ) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal da ta by competent authorities for the purposes of the…

### EDPB Work Programme 2021-2022

*Source: EDPB, edpb-work-programme-2021-2022-en, 2021-03-16 — https://overview.legal/posts/126048 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2021-2022_en*

EDPB Work Programme 2021/2022 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: To issue opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); To advise the European Commission on any issue related to the protection of personal data in the Union; To…

### EDPB Strategy 2021-2023

*Source: EDPB, edpb-strategy-2021-2023-en, 2020-12-15 — https://overview.legal/posts/126089 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2021-2023_en*

Adopted EDPB Strategy 2021 - 2023 Adopted on 15 December 2020 Adopted Adopted 1 INTRODUCTION 1. The mission of the European Data Protection Board (EDPB) is to ensure the consistent application of European data protection rules and to promote effective cooperation among supervisory authorities throughout the European Economic Area (EEA). 2. On 25 May 2018, the EDPB began putting into practice a new institutiona l and legal framework. This framework comprises both the General Data Protection…

## Literature

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Marketing** — https://overview.legal/topics/marketing
  Use of personal data for marketing and advertising purposes
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Biometric Data** — https://overview.legal/topics/biometric-data
  Processing of biometric data for identification

---
Generated by overview.legal · https://overview.legal/topics/authority-investigative-powers-ai · 2026-08-22
