# National-Level Risk Procedures for AI Systems — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/national-risk-procedure-ai-systems
> Sources are cited per item. Verify against the official texts before relying on them.

This specific topic addresses the national-level procedural framework for identifying, assessing, and responding to AI systems presenting risks, which is distinct from general market surveillance and authority powers, and represents a key procedural mechanism in the AI Act.

## Overview

## National-Level Risk Procedures for AI Systems

## Legal Framework

The national-level risk procedure for AI systems is primarily governed by Articles 79 and 80 of the EU AI Act, read together with Article 75 on the national market surveillance framework. Article 79 establishes the core procedural mechanism: where a national market surveillance authority has sufficient reason to consider that a high-risk AI system presents a risk to health, safety, or fundamental rights despite being in conformity with the Act, it must conduct an evaluation of the system and require the relevant provider to take all appropriate corrective action within a reasonable period. The provider bears the burden of demonstrating compliance or implementing remediation. If the authority finds non-compliance, it must restrict or prohibit the system's availability on the market, withdraw or recall it, and notify the Commission and other Member States without delay.

Article 80 supplements this with the Union safeguard procedure, triggered when a Member State takes measures against a non-compliant system. The Commission must consult the provider and, where relevant, the importer or distributor, then issue a binding decision determining whether the national measure is justified. This creates a two-tier structure: national authorities act as first responders, while the Commission ensures uniformity across the internal market.

Article 81 further empowers natural or legal persons to submit complaints to competent authorities regarding suspected breaches, feeding the risk-identification pipeline.

## Key Developments

The AI Act entered into force in August 2024, with enforcement phased through 2026 and 2027. No enforcement decisions under Articles 79 or 80 have yet issued, as the procedural framework becomes applicable only from August 2026 for most provisions. However, preparatory regulatory activity is already shaping expectations. The European AI Office has begun coordinating with national authorities to establish operational protocols, and several Member States are designating their market surveillance authorities under Article 75. The parallel development of GDPR enforcement by DPAs on AI-adjacent systems offers a practical preview: authorities have consistently demanded documented risk assessments, demonstrable mitigation measures, and timely cooperation as baseline expectations.

## Practical Guidance

- **Establish a documented internal risk-monitoring system** that can trigger corrective action procedures on demand, satisfying Article 79's expectation that providers respond to authority inquiries within a reasonable period.
- **Maintain real-time post-market monitoring infrastructure** under Article 72, as the data generated feeds directly into the Article 79 procedure and determines whether authorities initiate formal evaluations.
- **Designate a regulatory liaison function** with authority to coordinate responses across multiple Member States, since Article 79 notifications propagate EU-wide and require synchronized corrective action.
- **Prepare template corrective-action plans** in advance, including product modification, withdrawal, and recall scenarios, so that responses to Article 79 demands can be issued immediately rather than drafted under pressure.
- **Track complaints submitted under Article 81** as an early-warning indicator, since public complaints frequently precede formal authority interventions under Article 79.

## Recent developments

### The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/52095*

While the EU's AI legislation aims to regulate high-risk AI systems, it is undermined by significant exceptions that allow for their uncontrolled application in the context of national security and law enforcement. These exceptions risk, among other things, enabling mass surveillance of protests and discriminatory migration practices. To prevent this, the EDRi partner Danes je nov has published recommendations for Slovenia to implement stricter national safeguards and transparent oversight mechanisms. The post "The AI legislation is not..."

### The AI Act isn&#8217;t enough: closing the dangerous loopholes that enable rights violations

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49203 — original: https://edri.org/our-work/the-ai-act-isnt-enough-closing-the-dangerous-loopholes-that-enable-rights-violations/*

While the EU's AI Act aims to regulate high-risk AI systems, it is undermined by major loopholes that allow their unchecked use in the context of national security and law enforcement. These exemptions risk enabling, among others, mass surveillance of protests and discriminatory migration practices. To prevent this, EDRi affiliate Danes je nov dan has published recommendations for Slovenia to adopt stricter national safeguards and transparent oversight mechanisms. The post The AI Act isn&#8217;t

### De AI-wet is niet voldoende: we moeten de gevaarlijke hiaten dichten die misbruik mogelijk maken en de rechten van mensen schenden.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/51727*

Hoewel de AI-wetgeving van de EU tot doel heeft om AI-systemen met een hoog risico te reguleren, wordt deze ondermijnd door belangrijke uitzonderingen die hun ongecontroleerde toepassing mogelijk maken in de context van nationale veiligheid en handhaving van de wet. Deze uitzonderingen riskeren onder meer het mogelijk maken van grootschalige surveillance van protesten en discriminerende migratiepraktijken. Om dit te voorkomen, heeft de EDRi-partner Danes je nov dan aanbevelingen gepubliceerd voor Slovenië om strengere nationale beschermingsmaatregelen en transparante toezichtsmechanismen in te voeren. De post "De AI-wetgeving is niet..."

### CJEU: PNR Directive Valid if Limited to the “Strictly Necessary”

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/6292 — original: https://eucrim.eu/news/cjeu-pnr-directive-valid-if-limited-to-the-strictly-necessary/#entry-388*

> In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line with the EU’s fundamental rights. In addition, indiscriminate processing of the data in cases of flights carried out only within the EU is banned unless there is a threat of terrorism. In general, the passengers’ data must also be deleted after six months at the latest.

### HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is.

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/51841*

Op 21 juni 2022 heeft het Gerechtshof van de Europese Unie (Groot Beschouwingscollege) een baanbrekende uitspraak gedaan waarin het het EU-regime voor het verzamelen en gebruiken van gegevens van reizigers bevestigde, mits dit strikt wordt geïnterpreteerd in overeenstemming met de fundamentele rechten van de EU. Bovendien is het zonder onderscheid verwerken van deze gegevens bij vluchten die uitsluitend binnen de EU plaatsvinden verboden, tenzij er een dreiging van terrorisme bestaat. Over het algemeen moeten de gegevens van de passagiers ook binnen zes maanden worden verwijderd.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **AI Risk Mitigation** — https://overview.legal/topics/risk-mitigation-measures-ai
  Risk management systems include specific measures to mitigate identified risks. This concept deserves dedicated coverage as it encompasses the practical impleme
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data

---
Generated by overview.legal · https://overview.legal/topics/national-risk-procedure-ai-systems · 2026-08-22
