Authority Powers for Fundamental Rights Protection
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the powers and authorities granted to competent authorities to protect fundamental rights in AI systems, including inspection, intervention, and corrective action powers that are not adequately covered by existing topics.
Overview
28 sources · Aug 27, 2026Legal Framework
Authority powers for fundamental rights protection in AI systems draw on two intersecting legal instruments: the AI Act and the GDPR. Under the AI Act, Article 5 prohibits specified AI practices outright — including subliminal manipulation, vulnerability exploitation, social scoring, and certain predictive criminal risk assessments — establishing a hard boundary that competent authorities must enforce.
Article 27 imposes a forward-looking obligation on public-law deployers and certain private entities to conduct a fundamental rights impact assessment before first use of a high-risk system. That assessment must identify affected categories of persons, specific risks of harm, human oversight measures, and internal complaint mechanisms. Article 57 requires Member States to establish at least one AI regulatory sandbox by August 2026, allocating sufficient resources and mandating inter-authority cooperation. Article 66 tasks the AI Board with advising and assisting the Commission and Member States to ensure consistent application.
The GDPR's enforcement architecture supplies the operational toolkit. Article 58 GDPR grants supervisory authorities investigative, corrective, and judicial-referral powers — the same mechanisms that underpin fundamental rights protection in data-driven AI contexts.
Key Developments
The CJEU in Meta Platforms v noyb confirmed the tripartite structure of supervisory authority powers under Article 58 GDPR:
"Article 58 of the GDPR confers on those supervisory authorities, in paragraph 1, investigative powers, in paragraph 2, corrective powers, and in paragraph 5, the power to bring infringements"
— Meta Platforms v noyb ¶39
Dutch courts have clarified that corrective measures under Article 58(2) GDPR constitute a competence, not a duty. The Rechtbank held that Recital 148 GDPR does not obligate authorities to sanction every infringement, however minor, and that the choice to impose fines rests primarily with the authority. This principle — established under the Wbp and carried forward into the GDPR — means authorities retain discretion in calibrating enforcement to the severity of fundamental rights harm.
The Irish DPC's Permanent TSB decision illustrates corrective powers in practice:
"This Decision contains corrective powers under section 115 of the 2018 Act and Article 58(2) GDPR arising from the infringements that have been identified herein."
— Permanent TSB §13
That decision exercised the full range of corrective measures — reprimand, compliance orders, and processing restrictions — demonstrating how authorities translate investigative findings into binding remedial action.
Status of the Debate
This topic is contested in court. The boundary between discretionary corrective powers and mandatory enforcement obligations remains actively litigated, particularly where fundamental rights are at stake. Dutch courts have upheld the principle-based duty to enforce for remedial sanctions while distinguishing it from the discretionary imposition of fines, but the precise threshold at which an authority must act — versus may act — when AI systems threaten fundamental rights has not been definitively resolved. The interaction between AI Act enforcement mechanisms and GDPR Article 58 powers will generate further litigation as competent authorities begin exercising AI-specific mandates. A CJEU reference on the scope of mandatory corrective intervention in high-risk AI deployments would resolve the open question.
Practical Guidance
- Conduct a fundamental rights impact assessment before deploying any high-risk AI system covered by Article 27, documenting affected categories, identified risks, human oversight arrangements, and internal complaint mechanisms.
- Treat prohibited practices as a bright-line exclusion: systems falling within Article 5 cannot be placed on the market or deployed — no risk assessment cures this.
- Prepare for multi-authority engagement: AI regulatory sandboxes under Article 57 require cooperation between data protection authorities and AI competent authorities; establish clear points of contact for both.
- Anticipate the full range of corrective measures: authorities may impose processing restrictions, compliance orders, reprimands, or refer matters to judicial authorities — compliance programs should address each potential intervention.
- Maintain records sufficient for inspection: authorities' investigative powers under Article 58(1) GDPR extend to AI processing activities; ensure documentation supports both fundamental rights assessments and data protection accountability obligations.
why this is here
Article 58(1) of the GDPR confers extensive investigative powers on each supervisory authority.
The document directly outlines the powers of supervisory authorities to investigate and correct inadequacies in data transfers, central to protecting fundamental rights.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The SA has the corrective power to withdraw a certification or order to withdraw a certification issued pursuant to Articles 42 and 43 GDPR
It mentions the SA's corrective powers regarding certification, reflecting authority powers within the GDPR framework, though not specifically about fundamental rights in AI systems.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 27 Guidance · all 32 Enforcement