Corrective Actions and Duty of Information Framework
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic combines two interconnected AI Act obligations: the requirement for providers to take corrective actions when systems fail to comply, and the corresponding duty to inform authorities and stakeholders about these actions and any identified issues. This integrated framework is essential for understanding post-market compliance mechanisms.
Overview
14 sources · Sep 8, 2026Legal Framework
The corrective actions and duty of information framework for high-risk AI systems is anchored in two interconnected provisions of the AI Act. Article 16(j) imposes a general obligation on providers to "take the necessary corrective actions and provide information as required in Article 20." This cross-reference makes Article 20 the operational core of the post-market compliance mechanism.
Article 20(1) establishes a two-pronged duty: when a provider "considers or has reason to consider" that a placed or put-into-service system is non-conformant, it must immediately take corrective actions—bringing the system into conformity, withdrawing it, disabling it, or recalling it—and must inform distributors, deployers, authorised representatives, and importers. The trigger is deliberately broad, capturing both actual knowledge and constructive awareness.
"Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate."
— AI Act Art. 20(1)
Article 20(2) adds a second layer: where the system "presents a risk within the meaning of Article 79(1)," the provider must immediately investigate causes—collaborating with the reporting deployer—and inform market surveillance authorities and the relevant notified body. Article 79(1) defines "risk" by reference to Regulation (EU) 2019/1020, covering risks to health, safety, or fundamental rights. Distributors face parallel obligations under Article 24, including a duty to inform providers or importers when they identify non-conformity.
Key Developments
The AI Act's corrective action framework borrows directly from the EU product safety acquis, particularly Regulation (EU) 2019/1020, meaning that established case law on "product presenting a risk" under that regulation will shape interpretation. Article 79(2) requires market surveillance authorities to evaluate compliance when they have "sufficient reason to consider" a system presents a risk, with particular attention to vulnerable groups and mandatory cooperation with national public authorities on fundamental rights risks.
The EDPB has signalled that transparency obligations in the AI context must be "accessible, understandable and user-friendly," reinforcing that the duty to inform under Article 20 extends beyond authorities to affected deployers and, indirectly, data subjects. Italian DPA enforcement against AI-driven services (Garante decisions on Character.AI and AgID) illustrates that supervisory authorities are already exercising powers over AI systems that present risks to fundamental rights, even under existing GDPR powers—foreshadowing how Article 79(2) cooperation between market surveillance and data protection authorities will function in practice.
Status of the Debate
This topic is actively contested. The AI Act's corrective action provisions are novel in their specific application to AI, and several interpretive questions remain unresolved. The threshold for "reason to consider" non-conformity—whether it requires concrete evidence or extends to general risk indicators—will likely be the first flashpoint. The interaction between Article 20 duties and GDPR breach notification obligations creates overlapping regimes that no court has yet reconciled. The doctrinal analysis suggests that courts have diverged on analogous obligations under data protection law, particularly regarding the scope of supervisory authority powers and the duty to inform judicial bodies. Resolution will likely come through CJEU preliminary references on the meaning of "immediately" and the boundary between corrective actions under the AI Act and remediation under the GDPR. Until then, providers must adopt a conservative reading.
Practical Guidance
Establish internal trigger mechanisms: Implement monitoring systems capable of detecting non-conformity signals, since Article 20(1) activates on both actual knowledge and constructive awareness ("reason to consider"). Document the basis for every determination, whether or not corrective action follows.
Map your notification chain in advance: Article 20(1) requires informing distributors, deployers, authorised representatives, and importers; Article 20(2) adds market surveillance authorities and notified bodies. Pre-build contact registers and notification templates to satisfy the "immediately" standard.
Define "risk" broadly: Article 79(1) incorporates the Regulation (EU) 2019/1020 definition, covering health, safety, and fundamental rights. Do not limit risk assessments to physical safety—fundamental rights impacts, particularly on vulnerable groups, trigger the full Article 20(2) investigation and reporting cascade.
Coordinate with deployers: Article 20(2) explicitly requires collaboration with the "reporting deployer" during cause investigation. Contractual arrangements should mandate deployer cooperation and information sharing to avoid delays that could breach the immediacy requirement.
Align with GDPR breach notification: Where corrective actions involve personal data issues, the Article 20 duty to inform authorities may run parallel to GDPR Article 33 breach notification. Assess both regimes simultaneously to avoid inconsistent communications to supervisory authorities.
Nothing of this type on this topic.