Skip to content
Topic Developing

Market Surveillance Corrective Actions and Enforcement

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and remedial measures, which are distinct from general corrective action procedures.

23 linked items 12 Laws2 Guidance8 News1 Literature

Overview

10 sources · Jul 23, 2026

Legal Framework

Market surveillance under the AI Act is anchored in Article 76, which empowers market surveillance authorities to supervise testing of AI systems in real-world conditions. This provision ensures that authorities can intervene when testing deviates from regulatory requirements, enabling corrective measures before systems reach broader deployment. Article 85 establishes a complementary mechanism: any natural or legal person may lodge a complaint with the relevant market surveillance authority when they believe an infringement has occurred. These complaints must be processed under the dedicated procedures established by authorities pursuant to Regulation (EU) 2019/1020, creating a formal channel for third-party signals to trigger surveillance activity. Recital 36 adds a sector-specific layer, requiring notification to both the market surveillance authority and the national data protection authority for each use of real-time biometric identification systems, with annual reporting obligations to the Commission.

Key Developments

The interplay between the AI Act and Regulation (EU) 2019/1020 establishes the procedural backbone for corrective actions. Authorities may order withdrawal, suspension, or remedial measures when non-compliance is identified during surveillance. The DSA Human Rights Alliance's 2026 guidelines signal growing pressure to embed human-rights-based standards into digital enforcement, which will likely shape how market surveillance authorities exercise discretion in ordering corrective actions—particularly for high-risk AI systems interfacing with fundamental rights. The EDPB's guidance on controller and processor concepts remains relevant where AI systems process personal data during testing, as market surveillance authorities must coordinate with data protection authorities when corrective actions implicate processing activities.

Practical Guidance

  • Establish internal procedures to respond rapidly to market surveillance authority inquiries under Article 76, including designated contacts and documentation retrieval protocols for real-world testing phases.
  • Implement a complaint-handling mechanism that mirrors the Article 85 threshold—any third-party complaint forwarded by authorities must be triaged and addressed within the authority's procedural timelines.
  • For real-time biometric identification systems, build dual-notification workflows targeting both the market surveillance authority and the national DPA, and maintain annual reporting records for Commission submission per Recital 36.
  • Conduct pre-deployment compliance audits to identify potential triggers for withdrawal or suspension orders, focusing on high-risk system categories where corrective action is most likely.
  • Map data protection obligations alongside AI Act requirements so that corrective actions ordered by market surveillance authorities do not conflict with GDPR processing constraints, particularly where remedial measures require altering data flows.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 12
Art. 3(48) ‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union… AI Act Art. 5(6) National market surveillance authorities and the national data protection authorities of Member States that have been notified of the use of ‘real-tim… AI Act Art. 20(2) Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately in… AI Act Art. 22(3) The authorised representative shall perform the tasks specified in the mandate received from the provider. It shall provide a copy of the mandate to t… AI Act art 76 Supervision of testing in real world conditions by market surveillance authorities AI Act Jun 2024 rec 36 Recital 36 — biometric system use notification and reporting AI Act Jun 2024 rec 149 Recital 149 — AI Board establishment and advisory tasks AI Act Jun 2024 rec 131 Recital 131 — EU database for high-risk AI registration AI Act Jun 2024 rec 162 Recital 162 — Commission AI Office general-purpose model supervision AI Act Jun 2024 rec 161 Recital 161 — Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 160 Recital 160 — joint market surveillance and investigation activities AI Act Jun 2024 rec 158 Recital 158 — financial services authorities for AI oversight AI Act Jun 2024 rec 159 Recital 159 — biometric AI surveillance authority powers AI Act Jun 2024 rec 156 Recital 156 — market surveillance and compliance enforcement framework AI Act Jun 2024 art 85 Right to lodge a complaint with a market surveillance authority AI Act Jun 2024 rec 130 Recital 130 — rapid deployment of innovative AI systems AI Act Jun 2024
Guidance 2
§45 However, the EDPB and the EDPS underline that some provisions of the P roposal defining the tasks and powers of the different competent authorities un… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on transparency Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) EDPB Nov 2025
News 8
European Digital Rights Ensuring human rights-based, global perspectives in the DSA enforcement: the DSA Human Rights Alliance’s guidelines European Digital Rights Feb 2026 Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Hunton Andrews Kurth De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen. Hunton Andrews Kurth Sep 2022 NL Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022 IAPP TikTok staat mogelijk een boete van 27 miljoen Britse pond te wachten van de ICO (Information Commissioner's Office). IAPP Sep 2022 NL
Literature 1
Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026