Skip to content
Topic Contested in court

Notified Body Information Obligations

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This specific topic is needed to comprehensively cover the distinct information obligations that notified bodies must fulfill under the AI Act, including their duties to disclose assessment findings, report non-compliance, notify authorities of incidents, and provide transparent information to stakeholders.

7 linked items 1 Laws2 Guidance1 News3 Literature

Overview

24 sources · Jul 23, 2026

Legal Framework

Notified bodies operating under the AI Act are subject to layered information obligations that extend beyond mere conformity assessment. Article 13 of the AI Act establishes the core transparency and information-sharing duties owed to deployers, requiring that high-risk AI systems be accompanied by instructions for use, documentation, and information that enables meaningful oversight. Notified bodies must communicate assessment findings to providers, flag non-conformities, and where an AI system fails to meet requirements, refuse or withdraw the EU technical documentation assessment.

Beyond provider-facing duties, notified bodies must inform the notifying authority and the AI Office of significant changes affecting their competence, suspensions or withdrawals of certificates, and any circumstances that may cast doubt on a provider's compliance. These obligations mirror the structured transparency reporting seen in the Digital Services Act under Articles 15 and 42, where providers of intermediary services must publish periodic reports on content moderation and algorithmic decisions — establishing a regulatory pattern of mandatory, documented disclosure to supervisory authorities.

The GDPR framework reinforces these duties where notified bodies process personal data during assessments. Article 13 GDPR requires transparent information to data subjects, and Article 15 GDPR grants access rights that intersect with notified body activities — particularly when assessment findings touch on individuals' data. Member States may impose professional secrecy obligations under Article 15(2) that qualify how broadly assessment findings can be disseminated, creating a tension between transparency and confidentiality that notified bodies must navigate.

Key Developments

Dutch administrative case law illustrates the practical thresholds for adequate information provision. In one ruling, the court upheld a controller's right to request specification when a data subject sought access to a large volume of records — establishing that information obligations are not unlimited where the scope is genuinely broad. In another matter, the court found information provision deficient because the controller failed to disclose specific intelligence indicators, did not provide copies of referenced decisions, and omitted personal data handling information — demonstrating that partial or incomplete disclosure constitutes a violation.

The Malta Data Protection Commissioner's enforcement actions reinforce these standards. A €20,000 fine was imposed where a controller's data protection policy failed to meet transparency requirements alongside a failure to inform a data subject. A separate €4,000 fine addressed both unsolicited messaging and a non-compliant privacy policy. These decisions establish that transparency obligations are enforced independently — a deficient policy alone triggers liability even absent other violations.

The February 2026 AI Omnibus proposals seeking to weaken AI Act transparency provisions signal ongoing political pressure that notified bodies should monitor, as any dilution of reporting standards would directly affect their compliance burden.

Practical Guidance

  • Document every assessment finding with a clear communication chain: Notified bodies must maintain auditable records of what was communicated to providers, authorities, and the AI Office, tracing each disclosure to the specific legal basis under Article 13 AI Act and related provisions.

  • Establish escalation protocols for non-conformity: When assessment reveals non-compliance, notified bodies must have predefined procedures for refusing or withdrawing certification and simultaneously notifying the notifying authority — delays or omissions create enforcement exposure.

  • Reconcile transparency with professional secrecy: Where Member State law imposes confidentiality obligations under Article 15(2) GDPR-equivalent provisions, notified bodies must classify information into tiers — fully disclosable, restricted, and legally protected — and apply access controls accordingly.

  • Ensure information provided to deployers is operationally sufficient: Following the Dutch court standard, information must be complete enough to enable meaningful human oversight; partial disclosure that omits material findings fails the legal threshold.

  • Monitor legislative amendments actively: The AI Omnibus proposals demonstrate that information obligations remain politically contested; notified bodies should build compliance systems that are modular enough to accommodate tightened or relaxed reporting requirements without structural redesign.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 1
Art. 3(19) ‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designatio… AI Act Art. 3(48) ‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union… AI Act Art. 28(1) Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures f… AI Act Art. 29(1) Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established… AI Act rec 153 Recital 153 — national competent authorities designation AI Act Jun 2024
Guidance 2
§45 However, the EDPB and the EDPS underline that some provisions of the P roposal defining the tasks and powers of the different competent authorities un… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021
News 1
European Digital Rights AI Omnibus: Reject the proposals to undermine transparency in the AI Act European Digital Rights Feb 2026
Literature 3
SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 International Journal of Computer Applications A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance International Journal of Computer Applications Sep 2024