Skip to content
Topic Developing

AI Corrective Actions

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because corrective actions are a specific and distinct obligation under the AI Act that encompasses systematic procedures for addressing identified risks, defects, and incidents in AI systems, requiring dedicated coverage separate from general risk management.

7 linked items 2 Laws1 Guidance1 Enforcement1 News2 Literature

Overview

Legal Framework

The obligation to implement corrective actions for AI systems is governed by Article 21 of the AI Act, which mandates a post-market monitoring system, and Article 73 of the AI Act, which specifically details the requirements for taking corrective actions. These provisions require providers of high-risk AI systems to establish and document procedures for taking corrective action. This includes actions to bring a non-compliant system into compliance, to prevent its further use, or to withdraw or recall it from the market. The legal text requires these actions to be taken immediately when a provider has reason to believe that a system presents a risk or is not in conformity with the AI Act, and to be proportionate to the nature of the risk.

Practical Application

Corrective actions are a distinct and systematic obligation that goes beyond general risk management. As highlighted in Recital 155, the purpose of post-market monitoring is to allow providers to learn from real-world use to improve systems and to take timely corrective measures. This creates a closed-loop feedback system where monitoring directly informs corrective action. The obligation is triggered not only by a confirmed incident but also when a provider has reason to believe a risk exists, establishing a proactive duty to investigate potential non-conformities. For general-purpose AI models with systemic risk under Recital 115, a similar but heightened obligation exists, requiring immediate action to mitigate a serious incident. The process is formalized: providers must document the corrective actions taken and, for high-risk AI systems, notify their relevant authorities and, in some cases, the AI Office.

Key Considerations

  • Establish Formal Procedures: Organizations must develop and integrate documented procedures for initiating, executing, and documenting corrective actions into their quality management and post-market monitoring systems. This is not an ad-hoc process.
  • Define Clear Triggers: Internal protocols must define what constitutes "reason to believe" a system presents a risk, using data from post-market monitoring, user feedback, and incident reports to activate the corrective action process promptly.
  • Coordinate Notifications: The corrective action process must be linked to incident reporting obligations under Article 73. Taking corrective action may trigger a mandatory report to authorities, and the two processes must be coordinated to ensure timely and compliant communication.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 2
Art. 16(j) take the necessary corrective actions and provide information as required in Article 20; AI Act Art. 20(1) Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into… AI Act Art. 24(4) A distributor that considers or has reason to consider, on the basis of the information in its possession, a high-risk AI system which it has made ava… AI Act Art. 37(4) Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notif… AI Act art 20 Corrective actions and duty of information AI Act Jun 2024 rec 115 Recital 115 — systemic risk management for general-purpose AI AI Act Jun 2024
Guidance 1
32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024
Enforcement 1
EDPS EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft EDPS Mar 2024
News 1
European Data Protection Board One-Stop-Shop case digest on right to object and right to erasure updated European Data Protection Board Jun 2026
Literature 2
Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 International Journal of Social Sciences and Public Administration Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection International Journal of Social Sciences and Public Administration Jan 2025