Skip to content
Topic Contested in court

Corrective Actions and Duty of Information Framework

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic combines two interconnected AI Act obligations: the requirement for providers to take corrective actions when systems fail to comply, and the corresponding duty to inform authorities and stakeholders about these actions and any identified issues. This integrated framework is essential for understanding post-market compliance mechanisms.

8 linked items 3 Laws2 Guidance2 Enforcement1 Literature

Overview

24 sources · Jul 23, 2026

Legal Framework

The corrective actions and duty of information framework operates at the intersection of two distinct but related obligations under the AI Act and GDPR. AI Act Article 20 establishes the core requirement for providers to take corrective actions when AI systems fail to comply with regulatory requirements, coupled with a duty to inform competent authorities and affected parties. AI Act Article 45 imposes parallel information obligations on notified bodies, ensuring transparency in the conformity assessment ecosystem. Under the GDPR, Article 58(2) grants supervisory authorities the power to impose corrective measures, while Article 20 of the GDPR (as interpreted through national implementing legislation) requires member states to equip supervisory authorities with the capacity to refer infringements to judicial authorities. The CJEU confirmed in Schrems (C-362/14, ECLI:EU:C:2015:650) that this judicial referral capability is an essential component of effective oversight. The independence requirement under Article 16 GDPR, reinforced by Article 16(2) TFEU and Article 39 TEU, ensures that supervisory authorities can exercise these corrective powers without external interference, safeguarding the reliability of post-market compliance mechanisms.

Key Developments

The Dutch Council of State (ECLI:NL:RVS:2021:1407) clarified that the imposition of corrective measures by supervisory authorities constitutes a discretionary power rather than a mandatory obligation for every infringement, aligning with CJEU jurisprudence (ECLI:EU:C:2023:949). This means authorities may calibrate enforcement responses proportionally rather than issuing reprimands for every minor violation. In practice, information duty violations have attracted direct enforcement: the Italian Garante fined a barber shop €800 (March 2026) and a sole trader €1,000 (February 2026) for insufficient fulfilment of information obligations, demonstrating that even small-scale operators face financial penalties for transparency failures. The ICS credit card case established that where automated profiling forms part of a decision-making process, the extended information obligations under GDPR apply, but the presence of human review can mitigate the characterization of purely automated decision-making. The UWV administrative fine case illustrates that information duty breaches—specifically failure to report income changes—trigger both corrective measures and punitive sanctions, with courts requiring authorities to account for individual circumstances when calibrating penalties.

Practical Guidance

  • Establish internal escalation triggers: Providers must define specific compliance failure scenarios that activate corrective action obligations under AI Act Article 20, including timelines for notifying competent authorities once a non-conformity is identified.

  • Implement layered information protocols: Distinct notification duties apply to authorities, affected individuals, and notified bodies; each requires tailored content and timing, as enforcement authorities have penalized incomplete or delayed information provision even for minor commercial actors.

  • Document the human oversight element: Where automated profiling is involved, maintain records demonstrating meaningful human intervention in decision-making processes, as this affects the scope of information obligations and can distinguish partially automated from fully automated decisions.

  • Calibrate corrective measures proportionally: While authorities possess discretion in imposing corrective measures, providers should not assume minor violations will go unenforced; the Italian Garante fines demonstrate that information failures attract penalties regardless of organizational size.

  • Maintain audit trails for supervisory authority engagement: When complaints are filed requesting corrective measures, supervisory authorities must process them within their discretionary framework; providers should preserve all correspondence and compliance documentation to support their position during investigations.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 3
Art. 16(j) take the necessary corrective actions and provide information as required in Article 20; AI Act Art. 20(1) Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into… AI Act Art. 24(4) A distributor that considers or has reason to consider, on the basis of the information in its possession, a high-risk AI system which it has made ava… AI Act Art. 79(2)(cont)(1) Where, in the course of that evaluation, the market surveillance authority or, where applicable the market surveillance authority in cooperation with … AI Act art 20 Corrective actions and duty of information AI Act Jun 2024 art 45 Information obligations of notified bodies AI Act Jun 2024 rec 88 Recital 88 — AI value chain supplier cooperation AI Act Jun 2024
Guidance 2
of the work undertaken by the chatgpt taskforce Report of the work undertaken by the ChatGPT Taskforce EDPB May 2024 edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022
Enforcement 2
Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026
Literature 1
International Journal of Social Sciences and Public Administration Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection International Journal of Social Sciences and Public Administration Jan 2025