Mutual Assistance Between Member States for AI Oversight
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is essential as the provision specifically addresses mutual assistance mechanisms between member states and the AI Office for coordinating market surveillance and control activities for AI systems.
Overview
10 sources · Sep 25, 2026Legal Framework
Article 75 of the AI Act establishes the mutual assistance architecture between national market surveillance authorities and the AI Office for general-purpose AI systems. The provision creates three distinct supervisory pathways. First, where the model and system share the same provider, the AI Office exercises full market surveillance authority at Union level, inheriting all powers under Regulation (EU) 2019/1020. Second, where deployers can directly use a general-purpose AI system for at least one high-risk purpose, national authorities must cooperate with the AI Office for compliance evaluations and notify the Board. Third, where a national authority cannot complete an investigation due to information inaccessibility, it may request AI Office enforcement of access.
Recital 161 confirms the rationale: avoiding overlapping competences between Union and national levels. As the recital states:
"In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems."
— AI Act Recital 161
The cross-border mutual assistance procedure from Chapter VI of Regulation (EU) 2019/1020 applies mutatis mutandis when a national authority requests the AI Office to enforce information access.
Key Developments
No case law or enforcement decisions have yet tested Article 75. The provision is newly enacted, and its operational mechanics remain unlitigated. The EDPB has flagged the broader regulatory interplay, noting:
The EDPB's 2026–2027 work programme reinforces this trajectory, committing to facilitate cooperation tools and update guidance on cross-regulatory consistency. The 30-day deadline in Article 75(3) for the AI Office to supply information to a requesting authority is the only hard temporal benchmark in the provision, and it will likely become the first practical compliance metric tested in practice.
Status of the Debate
This topic is regulator-defined. Article 75's framework is legislatively settled, but its operational contours—particularly the boundary between national competence and AI Office primacy when model and system providers diverge—remain untested. No court has interpreted the "sufficient reason" threshold in paragraph 2 or the "all appropriate efforts" standard in paragraph 3. The first enforcement action involving a national authority's reasoned request to the AI Office under paragraph 3 will establish whether 30 days is workable and what "relevant information" means in practice. Until then, the EDPB's planned guidance on AI Act–GDPR interplay will shape expectations.
Practical Guidance
- Map provider identity early: Determine whether your general-purpose AI model and downstream AI system share the same provider—if so, the AI Office holds exclusive supervisory competence under Article 75(1).
- Prepare for dual-track oversight: Where deployers can use your system directly for high-risk purposes, expect coordinated compliance evaluations involving both national authorities and the AI Office under paragraph 2.
- Document information accessibility: If a national authority requests model-level information you control, ensure you can demonstrate that "all appropriate efforts" to provide access have been exhausted before the matter escalates to the AI Office.
- Build a 30-day response capability: The AI Office must relay relevant information to requesting authorities within 30 days; providers should maintain internal processes to support this timeline when the Office seeks underlying documentation.
- Monitor EDPB cross-regulatory guidance: Track forthcoming EDPB guidelines on GDPR–AI Act enforcement interplay, as these will define how data protection authorities and market surveillance authorities coordinate under parallel mandates.
Nothing of this type on this topic.