Market Surveillance Corrective Actions and Enforcement
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and remedial measures, which are distinct from general corrective action procedures.
Overview
12 sources · Sep 8, 2026Legal Framework
The primary provision governing market surveillance corrective actions is Article 20 AI Act, which imposes immediate obligations on providers of high-risk AI systems upon discovering non-conformity. The article operates on two tiers: a general non-conformity duty under paragraph 1 and a risk-specific duty under paragraph 2, the latter triggered when a system "presents a risk within the meaning of Article 79(1)."
Under Article 20(1), providers must take corrective action the moment they "consider or have reason to consider" that a placed or put-into-service system is non-compliant. The available measures are cumulative and graduated:
"shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate"
— AI Act Art. 20(1)
When the non-conformity rises to the level of a risk under Article 79(1), paragraph 2 adds an investigative and notification duty: the provider must investigate causes in collaboration with the reporting deployer and inform both the competent market surveillance authority and, where applicable, the notified body that issued the certificate.
Article 22 complements this framework for third-country providers by requiring appointment of an EU-based authorised representative whose mandate must include providing competent authorities with all relevant documentation upon reasoned request — ensuring there is an accountable addressee within the Union for market surveillance enforcement.
Key Developments
The AI Act designates data protection authorities — or alternative bodies meeting equivalent independence requirements — as Market Surveillance Authorities for certain high-risk AI systems. The EDPB confirmed this allocation:
"The AI Act designates DPAs (or other authorities with the same requirements on independence) as Market Surveillance Authorities (MSA) for certain high-risk AI systems, reinforcing their central role in protecting data protection rights."
— EDPB Annual Report 2024 §21
However, the institutional architecture remains unsettled. The EDPB and EDPS jointly flagged that the relationships between MSAs, fundamental rights authorities, and the Commission lack clarity, particularly regarding independence guarantees and reporting lines. Their 2021 opinion noted that the framework "does not require Supervisory authorities to be independent, and even requires them to report to the Commission on certain tasks carried out by market surveillance authorities." A subsequent 2026 joint opinion reinforced the call for clarifying MSA roles as administrative points of contact for executing enforcement requests directed at providers and deployers.
No case law directly interpreting Article 20 has yet emerged. The Dutch administrative rulings in the record address unrelated governance disputes and do not touch AI Act corrective action procedures.
Status of the Debate
This topic is actively contested at the institutional level rather than in court. The doctrinal friction centres on two open questions: first, whether MSAs designated under the AI Act meet the independence standards required under Regulation 2019/1020; and second, how enforcement cooperation between MSAs and fundamental rights authorities will function in practice. The EDPB has consistently pushed for clearer enacting terms. Resolution will likely require either a legislative amendment simplifying the cooperation framework or the first wave of enforcement decisions that establish de facto operational thresholds — whichever arrives first.
Practical Guidance
- Trigger assessment protocol: Establish internal procedures that activate the moment any staff member "considers or has reason to consider" non-conformity, as the Article 20(1) threshold is subjective and does not require confirmed non-compliance before action is mandated.
- Graduated response matrix: Map each corrective option — conformity correction, withdrawal, disabling, recall — to specific risk scenarios in advance, so that the "as appropriate" determination can be documented and justified to MSAs.
- Risk-threshold escalation: When non-conformity may constitute a risk under Article 79(1), immediately extend the response to include root-cause investigation and parallel notification of both the competent MSA and the relevant notified body.
- Authorised representative readiness: For third-country providers, ensure the mandated representative's powers expressly cover providing documentation to MSAs upon reasoned request, as required by Article 22(3), to avoid enforcement gaps.
- Deployer collaboration channel: Maintain a structured reporting interface with deployers, since Article 20(2) explicitly requires collaboration with the reporting deployer during risk investigations.
Nothing of this type on this topic.