Skip to content
Topic Developing

AI Act Formal Non-Compliance

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is needed to specifically address formal non-compliance under the AI Act, covering the determination, notification, and enforcement procedures specific to AI regulation compliance failures.

16 linked items 4 Laws1 Guidance3 Enforcement7 News1 Literature

Overview

14 sources · Jul 23, 2026

Legal Framework

Formal non-compliance under the AI Act is governed primarily by Article 83, which establishes a graduated enforcement mechanism for failures to meet procedural and documentation obligations rather than substantive safety or fundamental rights requirements. The provision empowers market surveillance authorities to require providers or deployers to bring non-compliant AI systems into conformity with the regulation, accompanied by a deadline and, where necessary, interim corrective measures.

Article 20 complements this framework by imposing corrective and notification obligations: when an AI system presents a risk or fails to meet formal requirements, the provider must inform the competent national authority, take remedial action, and where appropriate, withdraw or recall the system. Member states must vest supervisory authorities with the power to refer infringements to judicial authorities and initiate court proceedings—a requirement the Court of Justice of the EU has long recognized as essential to effective oversight, as established in Schrems (C-362/14) in the data protection context and now extended to AI regulation.

Article 85 grants any natural or legal person the right to lodge complaints with the relevant market surveillance authority where they believe the AI Act has been infringed. Complaints are processed under the market surveillance procedures established pursuant to Regulation (EU) 2019/1020, integrating AI Act enforcement into the broader EU product safety compliance architecture.

The independence of supervisory authorities—rooted in Article 16(2) TFEU and Article 39 TEU—ensures that enforcement of formal compliance requirements is shielded from external influence. The CJEU has consistently held that this independence guarantee secures the effectiveness and reliability of regulatory oversight.

Key Developments

Enforcement activity remains in its early stages, but the Italian Data Protection Authority's action against Luka Inc. illustrates the convergence of data protection and AI regulatory enforcement. The Garante imposed a €5,000,000 fine on the developer of the Replika chatbot, addressing failures spanning both GDPR and AI-relevant obligations. The decision signals that authorities will leverage existing data protection powers while AI Act enforcement infrastructure matures, and that chatbot and conversational AI systems face heightened scrutiny.

The Schrems precedent remains instructive: national authorities must possess—and exercise—judicial referral powers when formal non-compliance is identified. Member states that fail to equip their AI supervisory authorities with such powers risk infringement proceedings, as the Court has already established in the parallel data protection context.

Practical Guidance

  • Establish internal conformity monitoring: Article 83 enforcement begins with a market surveillance authority finding of non-compliance; providers should maintain continuous documentation demonstrating conformity with all formal requirements, including technical documentation, logging, and transparency obligations, to preempt regulatory intervention.

  • Prepare notification protocols: Under Article 20, providers must be ready to notify competent authorities upon identifying formal non-compliance, with defined internal escalation procedures specifying who notifies, when, and what corrective measures will be taken.

  • Designate regulatory liaison for complaint handling: Article 85 allows any person to file complaints with market surveillance authorities; organizations should implement intake and response processes to address complaints before they escalate to formal enforcement.

  • Verify national implementation status: Member states must designate competent authorities and vest them with judicial referral powers; providers operating across multiple jurisdictions should map each state's designated authority and applicable national enforcement procedures.

  • Integrate AI Act compliance with existing data protection governance: The Luka/Replika enforcement demonstrates that DPAs will act on AI systems using existing powers; organizations should align AI Act formal compliance with GDPR accountability frameworks to avoid parallel enforcement actions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 4
Art. 37(4) Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notif… AI Act Art. 55(1)(c) keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant informatio… AI Act Art. 79(9) The market surveillance authorities shall ensure that appropriate restrictive measures are taken in respect of the product or the AI system concerned,… AI Act Art. 81(2) Where the Commission considers the measure taken by the relevant Member State to be justified, all Member States shall ensure that they take appropria… AI Act art 85 Right to lodge a complaint with a market surveillance authority AI Act Jun 2024 art 83 Formal non-compliance AI Act Jun 2024 rec 115 Recital 115 — systemic risk management for general-purpose AI AI Act Jun 2024 rec 66 Recital 66 — risk management requirements for high-risk AI AI Act Jun 2024
Guidance 1
32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024
Enforcement 3
Italian Data Protection Authority (Garante) Luka Inc.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2025 Italian Data Protection Authority (Garante) Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking. Italian Data Protection Authority (Garante) Apr 2025 NL EDPS EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft EDPS Mar 2024
News 7
European Data Protection Board One-Stop-Shop case digest on right to object and right to erasure updated European Data Protection Board Jun 2026 Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022 Hunton Andrews Kurth De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen. Hunton Andrews Kurth Sep 2022 NL
Literature 1
Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023