Market Surveillance Corrective Actions and Enforcement
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic addresses the specific enforcement and corrective actions available to authorities during market surveillance, including withdrawal, suspension, and remedial measures, which are distinct from general corrective action procedures.
Overview
10 sources · Jul 23, 2026Legal Framework
Market surveillance under the AI Act is anchored in Article 76, which empowers market surveillance authorities to supervise testing of AI systems in real-world conditions. This provision ensures that authorities can intervene when testing deviates from regulatory requirements, enabling corrective measures before systems reach broader deployment. Article 85 establishes a complementary mechanism: any natural or legal person may lodge a complaint with the relevant market surveillance authority when they believe an infringement has occurred. These complaints must be processed under the dedicated procedures established by authorities pursuant to Regulation (EU) 2019/1020, creating a formal channel for third-party signals to trigger surveillance activity. Recital 36 adds a sector-specific layer, requiring notification to both the market surveillance authority and the national data protection authority for each use of real-time biometric identification systems, with annual reporting obligations to the Commission.
Key Developments
The interplay between the AI Act and Regulation (EU) 2019/1020 establishes the procedural backbone for corrective actions. Authorities may order withdrawal, suspension, or remedial measures when non-compliance is identified during surveillance. The DSA Human Rights Alliance's 2026 guidelines signal growing pressure to embed human-rights-based standards into digital enforcement, which will likely shape how market surveillance authorities exercise discretion in ordering corrective actions—particularly for high-risk AI systems interfacing with fundamental rights. The EDPB's guidance on controller and processor concepts remains relevant where AI systems process personal data during testing, as market surveillance authorities must coordinate with data protection authorities when corrective actions implicate processing activities.
Practical Guidance
- Establish internal procedures to respond rapidly to market surveillance authority inquiries under Article 76, including designated contacts and documentation retrieval protocols for real-world testing phases.
- Implement a complaint-handling mechanism that mirrors the Article 85 threshold—any third-party complaint forwarded by authorities must be triaged and addressed within the authority's procedural timelines.
- For real-time biometric identification systems, build dual-notification workflows targeting both the market surveillance authority and the national DPA, and maintain annual reporting records for Commission submission per Recital 36.
- Conduct pre-deployment compliance audits to identify potential triggers for withdrawal or suspension orders, focusing on high-risk system categories where corrective action is most likely.
- Map data protection obligations alongside AI Act requirements so that corrective actions ordered by market surveillance authorities do not conflict with GDPR processing constraints, particularly where remedial measures require altering data flows.