AI Act Formal Non-Compliance
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to specifically address formal non-compliance under the AI Act, covering the determination, notification, and enforcement procedures specific to AI regulation compliance failures.
Overview
14 sources · Jul 23, 2026Legal Framework
Formal non-compliance under the AI Act is governed primarily by Article 83, which establishes a graduated enforcement mechanism for failures to meet procedural and documentation obligations rather than substantive safety or fundamental rights requirements. The provision empowers market surveillance authorities to require providers or deployers to bring non-compliant AI systems into conformity with the regulation, accompanied by a deadline and, where necessary, interim corrective measures.
Article 20 complements this framework by imposing corrective and notification obligations: when an AI system presents a risk or fails to meet formal requirements, the provider must inform the competent national authority, take remedial action, and where appropriate, withdraw or recall the system. Member states must vest supervisory authorities with the power to refer infringements to judicial authorities and initiate court proceedings—a requirement the Court of Justice of the EU has long recognized as essential to effective oversight, as established in Schrems (C-362/14) in the data protection context and now extended to AI regulation.
Article 85 grants any natural or legal person the right to lodge complaints with the relevant market surveillance authority where they believe the AI Act has been infringed. Complaints are processed under the market surveillance procedures established pursuant to Regulation (EU) 2019/1020, integrating AI Act enforcement into the broader EU product safety compliance architecture.
The independence of supervisory authorities—rooted in Article 16(2) TFEU and Article 39 TEU—ensures that enforcement of formal compliance requirements is shielded from external influence. The CJEU has consistently held that this independence guarantee secures the effectiveness and reliability of regulatory oversight.
Key Developments
Enforcement activity remains in its early stages, but the Italian Data Protection Authority's action against Luka Inc. illustrates the convergence of data protection and AI regulatory enforcement. The Garante imposed a €5,000,000 fine on the developer of the Replika chatbot, addressing failures spanning both GDPR and AI-relevant obligations. The decision signals that authorities will leverage existing data protection powers while AI Act enforcement infrastructure matures, and that chatbot and conversational AI systems face heightened scrutiny.
The Schrems precedent remains instructive: national authorities must possess—and exercise—judicial referral powers when formal non-compliance is identified. Member states that fail to equip their AI supervisory authorities with such powers risk infringement proceedings, as the Court has already established in the parallel data protection context.
Practical Guidance
Establish internal conformity monitoring: Article 83 enforcement begins with a market surveillance authority finding of non-compliance; providers should maintain continuous documentation demonstrating conformity with all formal requirements, including technical documentation, logging, and transparency obligations, to preempt regulatory intervention.
Prepare notification protocols: Under Article 20, providers must be ready to notify competent authorities upon identifying formal non-compliance, with defined internal escalation procedures specifying who notifies, when, and what corrective measures will be taken.
Designate regulatory liaison for complaint handling: Article 85 allows any person to file complaints with market surveillance authorities; organizations should implement intake and response processes to address complaints before they escalate to formal enforcement.
Verify national implementation status: Member states must designate competent authorities and vest them with judicial referral powers; providers operating across multiple jurisdictions should map each state's designated authority and applicable national enforcement procedures.
Integrate AI Act compliance with existing data protection governance: The Luka/Replika enforcement demonstrates that DPAs will act on AI systems using existing powers; organizations should align AI Act formal compliance with GDPR accountability frameworks to avoid parallel enforcement actions.