Skip to content
Topic Contested in court

Authority Cooperation

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authorities that are distinct from general compliance obligations and warrant dedicated coverage.

45 linked items 29 Laws12 Guidance4 Literature

Overview

15 sources · Sep 25, 2026

Legal Framework

The AI Act establishes a multi-layered supervisory architecture in which national competent authorities — comprising at least one notifying authority and one market surveillance authority per Member State — serve as the primary enforcement interface. Article 70 sets the structural baseline: Member States must designate these authorities, ensure their independence, and guarantee adequate resources. Crucially, each Member State must also designate a single market surveillance authority to act as the single point of contact for the Regulation, ensuring a streamlined communication channel with the Commission and the public.

"Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and tasks"
— AI Act Art. 70(1)

Recital 153 reinforces that Member States may appoint any kind of public entity to perform these tasks, reflecting national organizational preferences. Recital 154 further specifies that authority members must refrain from actions incompatible with their duties and are subject to confidentiality rules.

Article 76 supplements this framework by granting market surveillance authorities specific competences over testing in real world conditions — including the power to suspend, terminate, or require modification of testing where conditions under Articles 60 and 61 are not met.

Key Developments

The EDPB and EDPS have consistently flagged ambiguities in the division of competences between the AI Office and national authorities. In their Joint Opinion 5/2021, they observed that the relationship between competent authorities — particularly whether supervisory authorities must be independent — was insufficiently clarified:

Their subsequent Joint Opinion 1/2026 sharpened this critique, warning that active cooperation provisions may prove insufficient if the AI Office retains exclusive authority and national bodies cannot act independently:

"this active cooperation provision may not be sufficient to guarantee the ability of national competent authorities to initiate actions if the AI Office has not already acted or does not want to"
— EDPB-EDPS Joint Opinion 1/2026 §30

The same opinion recommended expressly excluding from the AI Office's competence the supervision of AI systems developed or used by Union institutions, to preserve legal certainty and the independent character of supervision — a call reflected in the tension between Recital 14 and the operative text.

Status of the Debate

This area is contested and actively shaped by regulator-driven interpretation rather than settled case law. No court has yet ruled on the boundary between AI Office competences and national authority autonomy under the AI Act. The EDPB-EDPS opinions reveal a structural fault line: whether the AI Office's exclusivity in certain domains effectively sidelines national competent authorities, particularly DPAs acting as market surveillance authorities for high-risk AI systems touching data protection rights. What would resolve the open question is either a legislative amendment expressly delimiting AI Office competences — as the EDPB and EDPS recommend — or a preliminary reference clarifying whether Article 70's independence requirement is satisfied where national authorities must defer to an EU-level body before initiating enforcement. Until then, the practical balance depends on inter-authority memoranda and the Commission's implementing acts.

Practical Guidance

  • Identify your supervisory contact early: Each Member State must designate a single point of contact by 2 August 2025; confirm which national market surveillance authority governs your deployment and maintain a direct communication channel.
  • Map competence boundaries: Where an AI system implicates data protection risks, anticipate dual oversight by the market surveillance authority and the competent DPA under Article 70 and Article 2(7) AIA — prepare separate compliance dossiers for each.
  • Prepare for real-world testing interventions: Under Article 76(3), market surveillance authorities can suspend or terminate testing unilaterally; build incident response protocols that account for authority-directed modifications.
  • Monitor AI Office exclusivity: Track implementing acts and any amendments arising from the simplification proposals, as the AI Office's exclusive competence scope directly affects whether national authorities can independently engage your organization.
  • Document authority cooperation touchpoints: When multiple authorities are involved, maintain records of which authority initiated contact, under which legal basis, and what information was shared — this supports proportionality challenges under administrative law if competences overlap.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section