AI Corrective Actions
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because corrective actions are a specific and distinct obligation under the AI Act that encompasses systematic procedures for addressing identified risks, defects, and incidents in AI systems, requiring dedicated coverage separate from general risk management.
Overview
12 sources · Sep 25, 2026Legal Framework
Corrective actions under the AI Act are primarily governed by Article 20, which imposes obligations on providers of high-risk AI systems to address non-conformity once identified — whether discovered internally or flagged by deployers or other operators. The provision establishes two tiers of obligation. First, upon determining that a placed or put-into-service system is non-compliant, the provider must act immediately. Second, where the system presents a risk under Article 79(1), a separate duty to investigate and notify market surveillance authorities is triggered.
"shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate"
— AI Act Art. 20
The corrective arsenal is explicitly enumerated: conformity restoration, withdrawal, disabling, or recall. Providers must also inform distributors and, where applicable, deployers, authorised representatives, and importers. Where a risk under Article 79(1) materialises, the provider must investigate causes collaboratively with the reporting deployer and notify both the competent market surveillance authority and the notified body that issued the certificate.
"shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities"
— AI Act Art. 20
Article 24(4) extends a parallel corrective obligation to distributors who become aware that a high-risk AI system they have made available does not conform with Section 2 requirements. Distributors must either take corrective action themselves or ensure it is taken:
"shall take the corrective actions necessary to bring that system into conformity with those requirements, to withdraw it or recall it"
— AI Act Art. 24
Article 79 governs the downstream enforcement dimension: where a market surveillance authority evaluates a system and finds non-compliance, it must require the relevant operator to take corrective measures without undue delay, and the notified body must be informed.
Key Developments
The EDPB's Opinion 28/2024 confirms that supervisory authorities may impose corrective measures on AI model developers during both the development and anonymisation phases, grounding this power in the intersection of Article 5(2) GDPR, Article 24 GDPR, and AI Act provisions. The EDPB's Statement 3/2024 further signals that data protection authorities view corrective measures — including investigations and sanctions — as part of their toolkit within the AI Act framework, particularly where fundamental rights are implicated. No court has yet ruled on the scope or adequacy of corrective actions under Article 20 specifically, leaving the practical thresholds for what constitutes "immediate" action and what level of investigation satisfies the Article 20(2) duty to be defined through enforcement practice.
Status of the Debate
This topic is developing. The AI Act's corrective action regime is newly codified, and no dominant doctrinal pattern has emerged from courts or enforcement bodies regarding its interpretation. The interplay between provider obligations under Article 20, distributor obligations under Article 24(4), and market surveillance authority powers under Article 79 creates a multi-layered enforcement architecture whose practical operation will be shaped by the first wave of regulatory interventions. The critical open question is what evidentiary and temporal thresholds regulators will demand to satisfy the "immediately" standard in Article 20(1) and (2), and how the collaborative investigation duty between providers and deployers will be operationalised. Clarification will likely come through initial market surveillance authority decisions and subsequent judicial review.
Practical Guidance
- Establish a rapid-response protocol: Article 20(1) requires "immediate" corrective action upon identifying non-conformity. Build internal escalation procedures that trigger conformity assessment, withdrawal, disabling, or recall within defined timeframes — not awaiting external notification.
- Map your notification chain: Under Article 20(1), providers must inform distributors, deployers, authorised representatives, and importers. Under Article 20(2), notification extends to market surveillance authorities and the notified body when a risk materialises. Maintain up-to-date contact registers for all these actors.
- Document investigation procedures: Article 20(2) requires providers to "immediately investigate the causes" in collaboration with the reporting deployer. Establish joint investigation frameworks with deployers before incidents occur, including data-sharing and root-cause analysis protocols.
- Align distributor corrective duties: Ensure distributors understand their independent Article 24(4) obligation to take corrective action or escalate, and that supply-chain contracts allocate responsibilities clearly between providers and distributors.
- Coordinate with GDPR accountability mechanisms: Where the AI system processes personal data, corrective actions may overlap with GDPR obligations; ensure that remediation under the AI Act is consistent with Article 5(2) GDPR accountability and Article 24 GDPR risk mitigation requirements.
Nothing of this type on this topic.