AI Information Duties
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the AI Act imposes specific duties on providers to inform relevant parties (users, authorities, affected persons) about corrective actions, incidents, and system modifications, which represents a distinct compliance obligation that warrants separate topical coverage.
Overview
23 sources · Feb 17, 2026Legal Framework
The AI Act establishes specific disclosure duties requiring providers to inform users, authorities, and affected persons regarding corrective actions, incidents, and material system modifications affecting high-risk AI systems. Recital 157 mandates that national public authorities supervising fundamental rights—including data protection authorities and equality bodies—must access documentation created under the Regulation where necessary for their mandate, particularly when enforcing against systems presenting risks to health, safety, or fundamental rights. Recital 104 subjects general-purpose AI models to transparency requirements, with exceptions for open-source releases lacking systemic risk. These AI-specific obligations operate within the broader framework of Article 13 GDPR, which requires controllers to furnish information relating strictly to processing operations where they actually determine purposes and means. The doctrinal analysis clarifies that such provision must occur immediately upon data collection, with content strictly scoped to the controller's determined operational sphere.
Key Developments
The CJEU in FASHION ID GmbH & Co. KG v. VERBRAUCHERZENTRALE NRW eV established that information duties attach exclusively to processing operations where an operator actually determines purposes and means, and must be discharged immediately when data collection occurs. This precedent prevents diffusion of responsibility across AI supply chains involving multiple stakeholders. The Spanish Data Protection Authority demonstrated strict enforcement by imposing a €300 fine on a driving school for failing to adequately inform data subjects regarding video surveillance, confirming that notification deficiencies trigger sanctions regardless of organizational context. The EDPB Guidelines 3/2022 further operationalize these standards by prohibiting deceptive design patterns that obscure or delay mandatory disclosures, requiring interface architectures that actively facilitate user comprehension rather than manipulating attention away from material information.
Practical Guidance
• Delineate operational control: Document specific AI processing operations where your organization exclusively determines purposes and means, restricting information duty scope to these operations per FASHION ID.
• Configure immediate disclosure: Implement technical measures to deliver mandatory notifications contemporaneously with data collection or AI system interaction, satisfying Article 13 GDPR immediacy requirements.
• Maintain incident documentation: Establish accessible repositories detailing corrective actions, system modifications, and risk assessments for supervisory authority inspection under AI Act Recital 157.
• Audit interface transparency: Review AI system interfaces against EDPB Guidelines 3/2022 to eliminate deceptive patterns that might obscure information duties or manipulate user consent mechanisms.
• Establish authority response protocols: Create standardized procedures for providing documentation to national supervisory bodies upon request, ensuring compliance with Recital 157 access obligations.