Skip to content
Topic Contested in court

AI Act Formal Non-Compliance

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is needed to specifically address formal non-compliance under the AI Act, covering the determination, notification, and enforcement procedures specific to AI regulation compliance failures.

11 linked items 4 Laws2 Guidance4 Enforcement1 Literature

Overview

15 sources · Sep 25, 2026

Legal Framework

Formal non-compliance under the AI Act triggers a layered set of obligations across the supply chain. Article 20 imposes the primary corrective duty on providers of high-risk AI systems. When a provider has reason to believe a placed or deployed system does not conform, it must immediately take necessary corrective measures, including bringing it into compliance, withdrawal, deactivation, or recall:

"in overeenstemming te brengen, uit de handel te nemen, te deactiveren of terug te roepen"
— AI Act Art. 20(1)

Under Article 20(2), where the system poses a risk within the meaning of Article 79(1), the provider must investigate causes in cooperation with the deploying user who reported the risk and inform the competent market surveillance authority and any notified body that issued a certificate under Article 44.

Article 24 extends compliance duties to distributors. Before placing a high-risk system on the market, distributors must verify CE marking, the EU declaration of conformity under Article 47, and whether the provider and importer have met their obligations under Article 16(b)–(c) and Article 23(3). If a distributor has reason to believe a system it has already placed is non-compliant, it must take necessary corrective measures.

Article 85 establishes a complaint mechanism:

"any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority"
— AI Act Art. 85

Key Developments

The EDPB has clarified that supervisory authorities possess competence to intervene in processing related to anonymisation of AI models and during development, including by imposing corrective measures on that initial processing. This signals that DPA enforcement tools may operate in parallel with AI Act market surveillance powers.

The EDPB further notes that DPAs' role has already materialised through:

"investigations, corrective measures and (sometimes) sanctions. Furthermore, DPAs are also participating in various regulatory sandboxes."
— EDPB Statement 3/2024 §4

The Italian Garante's enforcement against Luka Inc. (Replika), resulting in a €5 million fine, illustrates how DPA powers may be exercised in practice — though grounded in GDPR rather than AI Act provisions, given the AI Act's phased application timeline.

Status of the Debate

This topic is developing: no dominant doctrinal pattern has yet emerged. The interplay between DPA corrective powers under the GDPR and market surveillance authority powers under the AI Act remains unsettled. The doctrinal question is whether the independence guarantee for supervisory authorities — established under Article 16(2) TFEU and Article 39 TEU, and reaffirmed by the Court of Justice — translates into a unified enforcement model or whether parallel regimes will operate with overlapping but distinct corrective tools. What would resolve the open question is a Court of Justice ruling clarifying the jurisdictional boundary between DPAs acting under GDPR and national market surveillance authorities acting under the AI Act, particularly for high-risk systems processing personal data.

Practical Guidance

  • Provider monitoring obligation: Under Article 20(1), implement continuous post-market monitoring systems that trigger immediate assessment upon any indication of non-conformity, ensuring you can demonstrate timely corrective action.

  • Distributor pre-market verification: Before placing any high-risk AI system on the market, verify CE marking, EU conformity declarations, and that provider and importer obligations under Article 16 and Article 23(3) have been met.

  • Risk escalation protocol: When a high-risk system poses a risk under Article 79(1), establish a procedure to investigate causes collaboratively with affected users and notify the competent market surveillance authority and relevant notified body without delay.

  • Complaint handling readiness: Prepare internal channels to handle complaints submitted under Article 85, since any natural or legal person may report suspected infringements to market surveillance authorities.

  • Dual-regime awareness: For high-risk systems processing personal data, maintain compliance documentation that addresses both AI Act conformity requirements and GDPR obligations, as both DPA and market surveillance enforcement may apply concurrently.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section