# Interim Measures under AI Act — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/interim-measures-ai-act
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address interim measures provisions in the AI Act, which allow authorities to take temporary protective actions against high-risk AI systems that pose immediate risks to fundamental rights, safety, or public security, pending full compliance assessment or corrective actions.

## Overview

## Legal Framework

Interim measures under the AI Act are grounded in the market surveillance architecture established by Regulation (EU) 2019/1020, as incorporated into the AI Act's enforcement regime. Article 85 of the AI Act provides that any natural or legal person may lodge a complaint with the relevant market surveillance authority where there are grounds to believe an infringement has occurred. These complaints feed directly into market surveillance activities and must be handled under the dedicated procedures established by national authorities.

The competence to take interim protective action rests primarily with national market surveillance authorities, except where an AI system is based on a general-purpose AI model provided by the same provider—in which case the AI Office acts as the market surveillance authority at Union level, as clarified by Recital 161. Recital 170 confirms that the complaint mechanism operates without prejudice to existing judicial and administrative remedies under Union and national law, ensuring that interim measures form one layer within a broader enforcement ecosystem.

The substantive basis for interim measures arises where a high-risk AI system presents an immediate and substantiated risk to fundamental rights, safety, or public security. Authorities may restrict or prohibit the system's availability on the market, require its withdrawal, or impose conditions on its use pending the provider's corrective action or a full compliance assessment.

## Key Developments

The AI Act entered into force on 1 August 2024, with enforcement staged through 2026 and 2027. No case law or enforcement decisions on interim measures have yet emerged, as the relevant provisions are not yet fully applicable. However, the framework draws directly on the established practice under Regulation (EU) 2019/1020, where market surveillance authorities have exercised analogous powers to recall products, impose sales bans, and require corrective action for non-compliant goods posing immediate risks. Member States are currently designating their national market surveillance authorities and establishing the procedural infrastructure to receive and act on complaints under Article 85.

## Practical Guidance

- **Map your market surveillance authority**: Identify the competent national authority for each Member State where your high-risk AI system is placed on the market, and the AI Office's role where general-purpose AI models are involved under Recital 161.

- **Establish a complaint intake protocol**: Article 85 allows any natural or legal person to lodge complaints. Maintain internal procedures to monitor and respond to complaints escalated by authorities, as these trigger market surveillance activity.

- **Prepare for provisional restrictions**: Develop contingency plans for scenarios where authorities impose interim measures—product withdrawal, market restrictions, or use conditions—pending compliance verification.

- **Document risk mitigation measures**: Maintain real-time evidence of safety controls, conformity assessments, and corrective action capacity to demonstrate readiness if an authority initiates interim proceedings.

- **Coordinate across remedies**: Recital 170 preserves existing judicial and administrative remedies. Ensure legal strategy accounts for parallel proceedings before national courts, data protection authorities, and AI-specific market surveillance bodies.

## Legislation (full text of key provisions)

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Recital 170 — complaint rights for AI regulation infringement

*Source: AI Act, aiact-rec-170-en, 2024-06-12 — https://overview.legal/posts/94022*

Union and national law already provide effective remedies to natural and legal persons whose rights and freedoms are adversely affected by the use of AI systems. Without prejudice to those remedies, any natural or legal person that has grounds to consider that there has been an infringement of this Regulation should be entitled to lodge a complaint to the relevant market surveillance authority.

### Recital 130 — rapid deployment of innovative AI systems

*Source: AI Act, aiact-rec-130-en, 2024-06-12 — https://overview.legal/posts/93942*

Under certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons, the protection of the environment and climate change and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons, environmental protection and the protection of key industrial and infrastructural assets, market surveillance authorities could authorise the placing on the market or the putting into service of AI systems which have not undergone a conformity assessment. In duly justified situations, as provided for in this Regulation, law enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation of the market surveillance authority, provided that such authorisation is requested during or after the use without undue delay.

### Recital 141 — real world testing conditions without sandbox

*Source: AI Act, aiact-rec-141-en, 2024-06-12 — https://overview.legal/posts/93964*

In order to accelerate the process of development and the placing on the market of the high-risk AI systems listed in an annex to this Regulation, it is important that providers or prospective providers of such systems may also benefit from a specific regime for testing those systems in real world conditions, without participating in an AI regulatory sandbox. However, in such cases, taking into account the possible consequences of such testing on individuals, it should be ensured that appropriate and sufficient guarantees and conditions are introduced by this Regulation for providers or prospective providers. Such guarantees should include, inter alia, requesting informed consent of natural persons to participate in testing in real world conditions, with the exception of law enforcement where the seeking of informed consent would prevent the AI system from being tested. Consent of subjects to participate in such testing under this Regulation is distinct from, and without prejudice to, consent of data subjects for the processing of their personal data under the relevant data protection law. It is also important to minimise the risks and enable oversight by competent authorities and therefore require prospective providers to have a real-world testing plan submitted to competent market surveillance authority, register the testing in dedicated sections in the EU database subject to some limited exceptions, set limitations on the period for which the testing can be done and require additional safeguards for persons belonging to certain vulnerable groups, as well as a written agreement defining the roles and responsibilities of prospective providers and deployers and effective oversight by competent personnel involved in the real world testing. Furthermore, it is appropriate to envisage additional safeguards to ensure that the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded and that personal data is protected and is deleted when the subjects have withdrawn their consent to participate in the testing without prejudice to their rights as data subjects under the Union data protection law. As regards transfer of data, it is also appropriate to envisage that data collected and processed for the purpose of testing in real-world conditions should be transferred to third countries only where appropriate and applicable safeguards under Union law are implemented, in particular in accordance with bases for transfer of personal data under Union law on data protection, while for non-personal data appropriate safeguards are put in place in accordance with Union law, such as Regulations (EU) 2022/868 (42) and (EU) 2023/2854 (43) of the European Parliament and of the Council.

### Recital 156 — market surveillance and compliance enforcement framework

*Source: AI Act, aiact-rec-156-en, 2024-06-12 — https://overview.legal/posts/93994*

In order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 153 — national competent authorities designation

*Source: AI Act, aiact-rec-153-en, 2024-06-12 — https://overview.legal/posts/93988*

Member States hold a key role in the application and enforcement of this Regulation. In that respect, each Member State should designate at least one notifying authority and at least one market surveillance authority as national competent authorities for the purpose of supervising the application and implementation of this Regulation. Member States may decide to appoint any kind of public entity to perform the tasks of the national competent authorities within the meaning of this Regulation, in accordance with their specific national organisational characteristics and needs. In order to increase organisation efficiency on the side of Member States and to set a single point of contact vis-à-vis the public and other counterparts at Member State and Union levels, each Member State should designate a market surveillance authority to act as a single point of contact.

### Recital 161 — Union and national supervision responsibilities for general-purpose AI

*Source: AI Act, aiact-rec-161-en, 2024-06-12 — https://overview.legal/posts/94004*

It is necessary to clarify the responsibilities and competences at Union and national level as regards AI systems that are built on general-purpose AI models. To avoid overlapping competences, where an AI system is based on a general-purpose AI model and the model and system are provided by the same provider, the supervision should take place at Union level through the AI Office, which should have the powers of a market surveillance authority within the meaning of Regulation (EU) 2019/1020 for this purpose. In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems. However, for general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk, market surveillance authorities should cooperate with the AI Office to carry out evaluations of compliance and inform the Board and other market surveillance authorities accordingly. Furthermore, market surveillance authorities should be able to request assistance from the AI Office where the market surveillance authority is unable to conclude an investigation on a high-risk AI system because of its inability to access certain information related to the general-purpose AI model on which the high-risk AI system is built. In such cases, the procedure regarding mutual assistance in cross-border cases in Chapter VI of Regulation (EU) 2019/1020 should apply mutatis mutandis.

### Recital 36 — biometric system use notification and reporting

*Source: AI Act, aiact-rec-36-en, 2024-06-12 — https://overview.legal/posts/93754*

In order to carry out their tasks in accordance with the requirements set out in this Regulation as well as in national rules, the relevant market surveillance authority and the national data protection authority should be notified of each use of the real-time biometric identification system. Market surveillance authorities and the national data protection authorities that have been notified should submit to the Commission an annual report on the use of real-time biometric identification systems.

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

## Literature

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act

*Source: Studies in Law and Justice, 2023-09-01 — https://overview.legal/posts/132567 — original: https://doi.org/10.56397/slj.2023.09.09*

The European Commission released the proposed Regulation on Artificial Intelligence (the EU AI Act) on 21 April 2021, which reflects the EU’s leadership orientation in establishing norms and standards in emerging fields, and also reflects the urgent need for legal unity of the EU as a unified market entity. The Act sets out harmonized rules for the development, placing on the market, and use of AI in the European Union. The ideas of a risk-based approach and experimental governance are of great

### Training national judges for digital competition law: the DMA, private enforcement, and the infrastructure of judicial capacity

*Source: Journal of European Competition Law & Practice, 2026-05-27 — https://overview.legal/posts/53835 — original: https://doi.org/10.1093/jeclap/lpag040*

The EU has adopted a dense digitalization ‘acquis’, including the Digital Markets Act (DMA), the Digital Services Act (DSA), Data Act, and Artificial Intelligence (AI) Act. Yet these regimes also create a ‘judicial’ order.1 National courts review National Competition Authorities' (NCAs) decisions, hear injunction and damages actions, manage disclosure and confidentiality, apply the principles of equivalence and effectiveness, and decide whether to refer questions to the Court of Justice. In digi

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Market Surveillance and Control of AI Systems** — https://overview.legal/topics/market-surveillance-control-ai
  This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems
- **AI Incident Notification** — https://overview.legal/topics/serious-incident-notification-ai
  The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated cov
- **Authority Access Rights to AI Systems and Documentation** — https://overview.legal/topics/authority-access-rights-ai-systems
  This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during o
- **Post-Market Monitoring for AI Systems** — https://overview.legal/topics/post-market-monitoring-ai
  Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and
- **Conformity Body Notification** — https://overview.legal/topics/conformity-assessment-body-notification
  This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/interim-measures-ai-act · 2026-08-22
