Notified Body Competence Challenges and Dispute Resolution
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses challenges to the competence of notified bodies, which is a distinct regulatory mechanism not adequately covered by existing topics. It encompasses dispute resolution procedures, grounds for challenges, and remedial actions related to notified body competence.
Overview
16 sources · Jul 23, 2026Legal Framework
Article 37 of the EU AI Act establishes the procedural mechanism through which the competence of notified bodies can be formally challenged. Notified bodies are designated national organizations responsible for assessing the conformity of high-risk AI systems before they are placed on the Union market. The challenge mechanism serves as a critical accountability safeguard, ensuring that only qualified entities perform conformity assessments and that their decisions are subject to scrutiny.
The provision operates within the broader accountability-based framework that characterizes modern EU regulatory architecture. Just as the GDPR imposes structural obligations through designated officers and supervisory authority membership requirements—demanding transparent appointment procedures, defined qualifications, and clear terms of office—the AI Act similarly requires that notified bodies meet stringent competence criteria. Article 37 provides recourse where those criteria are arguably not met, allowing challenges to be raised on grounds relating to technical capability, impartiality, or procedural irregularity in the body's designation or operation.
The rationale is straightforward: conformity assessments determine whether high-risk AI systems may lawfully enter the market. If the body performing that assessment lacks competence, the integrity of the entire regulatory gatekeeping function is compromised.
Key Developments
The Data Protection Commissioner v. Schrems and Facebook ruling underscores a principle directly relevant to competence challenges: regulatory decisions must withstand scrutiny not only on substance but on the institutional capacity and legal authority of the decision-maker. The CJEU's analysis of whether US oversight mechanisms provided effective legal protection parallels the inquiry Article 37 invites—whether a notified body possesses the requisite qualifications and independence to render reliable conformity decisions.
Enforcement actions by the Irish DPC, including the EUR 1.2 billion fine against Meta Platforms and the EUR 5.5 million fine against WhatsApp Ireland, illustrate how supervisory authorities assess institutional compliance failures. These decisions demonstrate that regulators examine whether organizations have maintained proper governance structures—directly informing how competence challenges against notified bodies may be evaluated.
The EDPB Guidelines 06/2022 on amicable settlements between supervisory authorities provide a practical dispute resolution template. While developed in the GDPR context, the principles of structured negotiation, documentation, and escalation pathways inform how disputes involving notified body competence may be resolved before formal challenge proceedings are initiated.
Practical Guidance
Document the factual basis for any competence challenge with specificity: Article 37 challenges must identify concrete deficiencies—whether in technical expertise, impartiality safeguards, or procedural compliance—rather than asserting generalized dissatisfaction with a notified body's decision.
Engage the DPO or equivalent governance officer before initiating a challenge: Internal assessment of whether grounds exist should incorporate data protection and AI governance expertise, particularly where the challenge intersects with GDPR obligations.
Exhaust informal dispute resolution mechanisms first: Following the structured settlement approach reflected in EDPB Guidance 06/2022, pursue direct engagement with the notified body to resolve competence concerns before escalating to the notifying authority or the Commission.
Preserve evidence of the notified body's qualifications and appointment transparency: Challenges under Article 37 are strengthened by demonstrating that the body's appointment did not meet the transparent procedure and qualification standards required under the regulatory framework.
Monitor parallel supervisory authority positions: Where a DPA has taken enforcement action related to the AI system under assessment, coordinate the competence challenge strategy with ongoing data protection proceedings to avoid contradictory positions.