Authority Cooperation
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authorities that are distinct from general compliance obligations and warrant dedicated coverage.
Overview
15 sources · Jul 23, 2026Legal Framework
Authority cooperation under the AI Act is governed primarily by Article 21 and Article 76. Article 21 imposes a direct obligation on providers and deployers of AI systems to cooperate with competent authorities, national supervisory authorities, and the Commission in the performance of their tasks under the regulation. This includes providing access to relevant documentation, technical data, and logs upon request. The obligation applies irrespective of whether the provider is established in the Union, provided the AI system is placed on the market or put into service within the EU — a principle consistent with the established case law on territorial scope under Article 4(1)(a) of Directive 95/46/EC, as confirmed by the Court of Justice in Google Spain v. AEPD, where even a subsidiary's promotional and sales activities sufficed to constitute an "establishment" through which processing occurs.
Article 76 specifically addresses the supervision of testing in real world conditions, requiring that market surveillance authorities be notified and granted supervisory access during such testing phases. The rationale is to ensure that authorities can verify compliance with risk management, data governance, and transparency obligations before systems are fully deployed, while also ensuring that the concept of "competent authority" extends beyond traditional government bodies to encompass any entity authorized under national law to exercise public authority — a formulation drawn from the parallel framework of Directive (EU) 2016/680.
Key Developments
The EDPB's February 2026 statement on AI-generated imagery and privacy protection, issued jointly through the Global Privacy Assembly, signals growing convergence between data protection authorities and AI sectoral regulators. The statement underscores that cooperation obligations extend not only to AI-specific competent authorities but also to data protection authorities exercising concurrent jurisdiction, particularly where AI systems process personal data during training, testing, or inference.
The Google Spain ruling remains the operative benchmark for establishment-based jurisdiction, confirming that even minimal but stable commercial activity through a subsidiary triggers regulatory authority. For AI providers, this means that cooperation obligations cannot be evaded by structuring operations to avoid a formal EU presence where effective and actual activity exists through durable arrangements, including through commercial agents collecting payments for AI-related services.
Practical Guidance
Maintain ready-accessible documentation packages: Article 21 requires cooperation upon request. Providers must ensure that technical documentation, logs, quality management records, and conformity assessments can be produced to competent authorities without delay — establish internal retrieval protocols with defined turnaround times.
Map all potentially competent authorities: Given that "competent authority" includes any entity authorized under national law to exercise public powers, providers should conduct jurisdictional mapping across each Member State where their AI system operates, identifying both AI-specific regulators and sectoral authorities with concurrent mandates.
Establish real-world testing notification protocols: Article 76 requires notification to and supervision by market surveillance authorities during real-world testing. Implement pre-testing workflows that identify the relevant authority, submit required notifications, and facilitate on-site or remote supervisory access.
Coordinate cross-authority data access: Where multiple authorities (AI regulators, DPAs, sectoral supervisors) assert concurrent jurisdiction, designate a single internal liaison to manage information requests, prevent inconsistent disclosures, and ensure that cooperation with one authority does not compromise obligations owed to another.
Verify establishment triggers: Apply the Google Spain standard to assess whether your operational footprint — including through agents, subsidiaries, or payment-collection arrangements — creates cooperation obligations in EU jurisdictions where you may not have considered yourselves subject to enforcement.