# Authority Cooperation — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/cooperation-with-authorities-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authorities that are distinct from general compliance obligations and warrant dedicated coverage.

## Overview

## Legal Framework

Authority cooperation under the AI Act is governed primarily by **Article 21** and **Article 76**. Article 21 imposes a direct obligation on providers and deployers of AI systems to cooperate with competent authorities, national supervisory authorities, and the Commission in the performance of their tasks under the regulation. This includes providing access to relevant documentation, technical data, and logs upon request. The obligation applies irrespective of whether the provider is established in the Union, provided the AI system is placed on the market or put into service within the EU — a principle consistent with the established case law on territorial scope under **Article 4(1)(a) of Directive 95/46/EC**, as confirmed by the Court of Justice in *Google Spain v. AEPD*, where even a subsidiary's promotional and sales activities sufficed to constitute an "establishment" through which processing occurs.

Article 76 specifically addresses the supervision of testing in real world conditions, requiring that market surveillance authorities be notified and granted supervisory access during such testing phases. The rationale is to ensure that authorities can verify compliance with risk management, data governance, and transparency obligations before systems are fully deployed, while also ensuring that the concept of "competent authority" extends beyond traditional government bodies to encompass any entity authorized under national law to exercise public authority — a formulation drawn from the parallel framework of **Directive (EU) 2016/680**.

## Key Developments

The EDPB's February 2026 statement on AI-generated imagery and privacy protection, issued jointly through the Global Privacy Assembly, signals growing convergence between data protection authorities and AI sectoral regulators. The statement underscores that cooperation obligations extend not only to AI-specific competent authorities but also to data protection authorities exercising concurrent jurisdiction, particularly where AI systems process personal data during training, testing, or inference.

The *Google Spain* ruling remains the operative benchmark for establishment-based jurisdiction, confirming that even minimal but stable commercial activity through a subsidiary triggers regulatory authority. For AI providers, this means that cooperation obligations cannot be evaded by structuring operations to avoid a formal EU presence where effective and actual activity exists through durable arrangements, including through commercial agents collecting payments for AI-related services.

## Practical Guidance

- **Maintain ready-accessible documentation packages**: Article 21 requires cooperation upon request. Providers must ensure that technical documentation, logs, quality management records, and conformity assessments can be produced to competent authorities without delay — establish internal retrieval protocols with defined turnaround times.

- **Map all potentially competent authorities**: Given that "competent authority" includes any entity authorized under national law to exercise public powers, providers should conduct jurisdictional mapping across each Member State where their AI system operates, identifying both AI-specific regulators and sectoral authorities with concurrent mandates.

- **Establish real-world testing notification protocols**: Article 76 requires notification to and supervision by market surveillance authorities during real-world testing. Implement pre-testing workflows that identify the relevant authority, submit required notifications, and facilitate on-site or remote supervisory access.

- **Coordinate cross-authority data access**: Where multiple authorities (AI regulators, DPAs, sectoral supervisors) assert concurrent jurisdiction, designate a single internal liaison to manage information requests, prevent inconsistent disclosures, and ensure that cooperation with one authority does not compromise obligations owed to another.

- **Verify establishment triggers**: Apply the *Google Spain* standard to assess whether your operational footprint — including through agents, subsidiaries, or payment-collection arrangements — creates cooperation obligations in EU jurisdictions where you may not have considered yourselves subject to enforcement.

## Legislation (full text of key provisions)

### Designation of national competent authorities and single points of contact

*Source: AI Act, aiact-art-70-en, 2024-06-12 — https://overview.legal/posts/93141*

### Cooperation with competent authorities

*Source: AI Act, aiact-art-21-en, 2024-06-12 — https://overview.legal/posts/92304*

### Supervision of testing in real world conditions by market surveillance authorities

*Source: AI Act, aiact-art-76-en, 2024-06-12 — https://overview.legal/posts/93261*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Recital 85 — general purpose AI provider cooperation obligations

*Source: AI Act, aiact-rec-85-en, 2024-06-12 — https://overview.legal/posts/93852*

General-purpose AI systems may be used as high-risk AI systems by themselves or be components of other high-risk AI systems. Therefore, due to their particular nature and in order to ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems should, irrespective of whether they may be used as high-risk AI systems as such by other providers or as components of high-risk AI systems and unless provided otherwise under this Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable their compliance with the relevant obligations under this Regulation and with the competent authorities established under this Regulation.

### Recital 154 — independent impartial national competent authorities

*Source: AI Act, aiact-rec-154-en, 2024-06-12 — https://overview.legal/posts/93990*

The national competent authorities should exercise their powers independently, impartially and without bias, so as to safeguard the principles of objectivity of their activities and tasks and to ensure the application and implementation of this Regulation. The members of these authorities should refrain from any action incompatible with their duties and should be subject to confidentiality rules under this Regulation.

### Recital 167 — confidentiality of information by competent authorities

*Source: AI Act, aiact-rec-167-en, 2024-06-12 — https://overview.legal/posts/94016*

In order to ensure trustful and constructive cooperation of competent authorities on Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks, in accordance with Union or national law. They should carry out their tasks and activities in such a manner as to protect, in particular, intellectual property rights, confidential business information and trade secrets, the effective implementation of this Regulation, public and national security interests, the integrity of criminal and administrative proceedings, and the integrity of classified information.

### Recital 153 — national competent authorities designation

*Source: AI Act, aiact-rec-153-en, 2024-06-12 — https://overview.legal/posts/93988*

Member States hold a key role in the application and enforcement of this Regulation. In that respect, each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities for the purpose of supervising the application and implementation of this Regulation. Member States may decide to appoint any kind of public entity to perform the tasks of the national competent authorities within the meaning of this Regulation, in accordance with their specific national organisational characteristics and needs. In order to increase organisation efficiency on the side of Member States and to set a single point of contact vis-à-vis the public and other counterparts at Member State and Union levels, each Member State should designate a market surveillance authority to act as a single point of contact.

### Recital 149 — AI Board establishment and advisory tasks

*Source: AI Act, aiact-rec-149-en, 2024-06-12 — https://overview.legal/posts/93980*

In order to facilitate a smooth, effective and harmonised implementation of this Regulation a Board should be established. The Board should reflect the various interests of the AI eco-system and be composed of representatives of the Member States. The Board should be responsible for a number of advisory tasks, including issuing opinions, recommendations, advice or contributing to guidance on matters related to the implementation of this Regulation, including on enforcement matters, technical specifications or existing standards regarding the requirements established in this Regulation and providing advice to the Commission and the Member States and their national competent authorities on specific questions related to AI. In order to give some flexibility to Member States in the designation of their representatives in the Board, such representatives may be any persons belonging to public entities who should have the relevant competences and powers to facilitate coordination at national level and contribute to the achievement of the Board’s tasks. The Board should establish two standing sub-groups to provide a platform for cooperation and exchange among market surveillance authorities and notifying authorities on issues related, respectively, to market surveillance and notified bodies. The standing subgroup for market surveillance should act as the administrative cooperation group (ADCO) for this Regulation within the meaning of Article 30 of Regulation (EU) 2019/1020. In accordance with Article 33 of that Regulation, the Commission should support the activities of the standing subgroup for market surveillance by undertaking market evaluations or studies, in particular with a view to identifying aspects of this Regulation requiring specific and urgent coordination among market surveillance authorities. The Board may establish other standing or temporary sub-groups as appropriate for the purpose of examining specific issues. The Board should also cooperate, as appropriate, with relevant Union bodies, experts groups and networks active in the context of relevant Union law, including in particular those active under relevant Union law on data, digital products and services.

### Recital 158 — financial services authorities for AI oversight

*Source: AI Act, aiact-rec-158-en, 2024-06-12 — https://overview.legal/posts/93998*

Union financial services law includes internal governance and risk-management rules and requirements which are applicable to regulated financial institutions in the course of provision of those services, including when they make use of AI systems. In order to ensure coherent application and enforcement of the obligations under this Regulation and relevant rules and requirements of the Union financial services legal acts, the competent authorities for the supervision and enforcement of those legal acts, in particular competent authorities as defined in Regulation (EU) No 575/2013 of the European Parliament and of the Council (46) and Directives 2008/48/EC (47), 2009/138/EC (48), 2013/36/EU (49), 2014/17/EU (50) and (EU) 2016/97 (51) of the European Parliament and of the Council, should be designated, within their respective competences, as competent authorities for the purpose of supervising the implementation of this Regulation, including for market surveillance activities, as regards AI systems provided or used by regulated and supervised financial institutions unless Member States decide to designate another authority to fulfil these market surveillance tasks. Those competent authorities should have all powers under this Regulation and Regulation (EU) 2019/1020 to enforce the requirements and obligations of this Regulation, including powers to carry our ex post market surveillance activities that can be integrated, as appropriate, into their existing supervisory mechanisms and procedures under the relevant Union financial services law. It is appropriate to envisage that, when acting as market surveillance authorities under this Regulation, the national authorities responsible for the supervision of credit institutions regulated under Directive 2013/36/EU, which are participating in the Single Supervisory Mechanism established by Council Regulation (EU) No 1024/2013 (52), should report, without delay, to the European Central Bank any information identified in the course of their market surveillance activities that may be of potential interest for the European Central Bank’s prudential supervisory tasks as specified in that Regulation. To further enhance the consistency between this Regulation and the rules applicable to credit institutions regulated under Directive 2013/36/EU, it is also appropriate to integrate some of the providers’ procedural obligations in relation to risk management, post marketing monitoring and documentation into the existing obligations and procedures under Directive 2013/36/EU. In order to avoid overlaps, limited derogations should also be envisaged in relation to the quality management system of providers and the monitoring obligation placed on deployers of high-risk AI systems to the extent that these apply to credit institutions regulated by Directive 2013/36/EU. The same regime should apply to insurance and re-insurance undertakings and insurance holding companies under Directive 2009/138/EC and the insurance intermediaries under Directive (EU) 2016/97 and other types of financial institutions subject to requirements regarding internal governance, arrangements or processes established pursuant to the relevant Union financial services law to ensure consistency and equal treatment in the financial sector.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Report on the use of SPE external experts in 2024

*Source: EDPB, edpb-report-20250313-support-pool-experts-programme-2024-en, 2025-03-18 — https://overview.legal/posts/50659 — original: https://www.edpb.europa.eu/documents/support-pool-of-experts/report-on-the-use-of-spe-external-experts-in-2024_en*

European Data Protection Board, Report on the use of SPE external experts in 2024, 2025.

### Statement 6/2024 on the Second Report on the Application of the General Data Protection Regulation - Fostering Cross-Regulatory Consistency and Cooperation

*Source: EDPB, statement-62024-on-the-second-report-on-the-application-of-en, 2024-12-03 — https://overview.legal/posts/125698 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-62024-on-the-second-report-on-the-application-of_en*

1 Statement 6/2024 on the Second Report on the Application of the General Data Protection Regulation - Fostering Cross - Regulatory Consistency and Cooperation Adopted on 3 December 2024 Executive summary The European Data Protection Board welcomes the reports from the European Commission and the Fundamental Rights Agency and takes this opportunity to confirm several ongoing initiatives which would help address some recommendations on cooperation under the GDPR, the future R egulation laying…

### EDPB Strategy 2024-2027

*Source: EDPB, edpb-strategy-2024-2027-en, 2024-04-18 — https://overview.legal/posts/125760 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2024-2027_en*

The mission and legal task of the European Data Protection Board (EDPB) is to ensure the consistent application of EU data protection rules and to promote effective cooperation among data protection authorities throughout the European Economic Area (EEA). Since their entries into application in 2018, the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED) have strengthened, modernised and harmonised data protection across the European Economic Area (EEA). Awareness…

### Statement on enforcement cooperation

*Source: EDPB, statement-on-enforcement-cooperation-en, 2022-04-28 — https://overview.legal/posts/125948 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-enforcement-cooperation_en*

Adopted 1 Statement on enforcement cooperation Adopted on 28 April 2022 The European Data Protection Board has adopted the following statement: At a two - day high level meeting in Vienna, EDPB members have agreed to further enhance cooperation on strategic cases, and to diversify the range of cooperation methods used. More than ever, strong and swift enforcement is crucial for ensuring a consistent interpretation of the GDPR. The EDPB stre sses its duty to ensure that the GDPR is enforced…

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

### EDPB Strategy 2021-2023

*Source: EDPB, edpb-strategy-2021-2023-en, 2020-12-15 — https://overview.legal/posts/126089 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2021-2023_en*

Adopted EDPB Strategy 2021 - 2023 Adopted on 15 December 2020 Adopted Adopted 1 INTRODUCTION 1. The mission of the European Data Protection Board (EDPB) is to ensure the consistent application of European data protection rules and to promote effective cooperation among supervisory authorities throughout the European Economic Area (EEA). 2. On 25 May 2018, the EDPB began putting into practice a new institutiona l and legal framework. This framework comprises both the General Data Protection…

## Recent developments

### Stakeholder event on guidelines on the interplay between data protection and competition law: express your interest

*Source: European Data Protection Board, 2026-07-30 — https://overview.legal/posts/184677 — original: https://www.edpb.europa.eu/news/stakeholder-event-on-guidelines-on-the-interplay-between-data-protection-and-competition-law-0_en*

Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic.The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB

### Stakeholder event on guidelines on the interplay between data protection and competition law: save the date

*Source: European Data Protection Board, 2026-07-23 — https://overview.legal/posts/156359 — original: https://www.edpb.europa.eu/news/stakeholder-event-on-guidelines-on-the-interplay-between-data-protection-and-competition-law_en*

Brussels, 23 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic.The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB

### AI-generated imagery and protection of privacy: EDPB supports joint Global Privacy Assembly’s statement

*Source: European Data Protection Board, 2026-02-23 — https://overview.legal/posts/52723 — original: https://www.edpb.europa.eu/news/news/2026/ai-generated-imagery-and-protection-privacy-edpb-supports-joint-global-privacy_en*

Brussels, 23 February - EDPB Chair Anu Talus has signed a Joint Statement on AI-Generated Imagery and the Protection of Privacy on behalf of the EDPB. The statement, coordinated by the Global Privacy Assembly's (GPA) International Enforcement Cooperation Working Group (IEWG), represents the united position of 61 authorities across the world. This reflects the Board’s commitment to contributing to the global dialogue on data protection as outlined in the fourth pillar of its work programme 2026-2

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings

*Source: International Journal of Law and Societal Studies, 2025-09-26 — https://overview.legal/posts/53859 — original: https://doi.org/10.61424/ijlss.v2i1.445*

This research examines the complex balance between privacy and law enforcement in EU digital surveillance laws during criminal proceedings. It analyzes how these laws protect individual rights while ensuring security through case studies and legal analysis. Landmark cases like Digital Rights Ireland, Schrems decisions, and Tele2 Sverige illustrate the European courts' preference for targeted surveillance over mass data collection, highlighting tensions between privacy and security. Although thes

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Market Surveillance and Control of AI Systems** — https://overview.legal/topics/market-surveillance-control-ai
  This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems
- **AI Act Territorial Scope** — https://overview.legal/topics/ai-act-territorial-scope
  The scope section of the AI Act includes specific provisions on territorial applicability and which providers are subject to the regulation regardless of their 
- **Market Surveillance Corrective Actions and Enforcement** — https://overview.legal/topics/market-surveillance-corrective-actions
  This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and 
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their

---
Generated by overview.legal · https://overview.legal/topics/cooperation-with-authorities-ai · 2026-08-22
