Skip to content
Topic Regulator-defined

Confidentiality Obligations and Requirements

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is needed to comprehensively address confidentiality as a distinct data protection principle in the AI Act and GDPR, covering obligations, requirements, and implementation measures specific to maintaining confidentiality of personal and sensitive data.

8 linked items 3 Guidance4 News1 Literature

Overview

8 sources · Sep 8, 2026

Legal Framework

Confidentiality obligations under the AI Act are distributed across several articles, each targeting a different actor in the AI lifecycle. Article 21(3) imposes a direct duty on competent authorities to handle information obtained during conformity assessments under the confidentiality regime of Article 78. This creates a closed-loop confidentiality architecture: providers must disclose information to authorities, but authorities are bound to protect it.

For providers of general-purpose AI models, Article 53(1)(b) introduces a dual obligation — to document and make available information to downstream providers — while explicitly preserving confidentiality of business information:

"Without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, the information and documentation shall:"
— AI Act Art. 53(1)(b)

Article 31 reinforces confidentiality through structural independence requirements for notified bodies, ensuring that conformity assessors do not have economic interests that could compromise the handling of proprietary and confidential information encountered during assessment.

Article 10's data governance framework implicitly requires confidentiality safeguards during data preparation operations — annotation, labelling, cleaning — where personal data is processed across potentially distributed environments.

Key Developments

No case law has yet tested the AI Act's confidentiality provisions, as the regulation is in early implementation. The EDPB's Guidelines 02/2021 on virtual voice assistants addressed confidentiality in the context of voice data processing, establishing that confidentiality must be embedded in the design of systems handling potentially sensitive voice inputs — a principle that carries forward into AI Act compliance.

The practical threshold emerging from the interplay between Articles 21, 31, and 53 is that confidentiality is not a standalone obligation but a structural constraint: it must be preserved across information flows between providers, authorities, and notified bodies, balanced against transparency duties.

Status of the Debate

This topic is regulator-defined. The AI Act establishes clear textual obligations but leaves significant operational detail to implementing acts and secondary guidance. No enforcement decisions or court rulings have interpreted the scope of "confidentiality obligations set out in Article 78" or the boundary between mandated transparency and protected trade secrets under Article 53. The tension between disclosure obligations and confidentiality protection remains unresolved and will likely be tested when providers challenge authority information requests or when downstream providers demand documentation that upstream providers claim is confidential. Resolution will come through the AI Office's templates for Article 53(1)(d) summaries and early enforcement decisions defining the proportionality threshold for confidentiality claims.

Practical Guidance

  • Map information flows before disclosure: Identify which categories of technical documentation, logs, and training data are subject to Article 21 disclosure obligations and which qualify for trade secret protection under Article 53(1)(b). Document the legal basis for each classification.
  • Implement access controls for notified body interactions: Ensure that personnel involved in conformity assessments under Article 31 operate under binding confidentiality agreements, and that documentation shared with notified bodies is marked and restricted to what is necessary for assessment.
  • Establish a confidentiality-by-design protocol for data governance: Under Article 10(2), data preparation operations involving personal data must incorporate confidentiality safeguards — limit access to annotated datasets and log all data handling.
  • Prepare Article 78-compliant handling procedures: Since authorities receiving information under Article 21 are bound by Article 78, providers should proactively specify confidentiality markings and expected handling standards when responding to authority requests.
  • Balance transparency and trade secret protection in downstream documentation: When preparing information packages under Article 53(1)(b) for downstream AI system providers, apply a structured redaction framework that preserves confidential business information while meeting the statutory disclosure minimum.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section