Notified Body Information Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This specific topic is needed to comprehensively cover the distinct information obligations that notified bodies must fulfill under the AI Act, including their duties to disclose assessment findings, report non-compliance, notify authorities of incidents, and provide transparent information to stakeholders.
Overview
24 sources · Jul 23, 2026Legal Framework
Notified bodies operating under the AI Act are subject to layered information obligations that extend beyond mere conformity assessment. Article 13 of the AI Act establishes the core transparency and information-sharing duties owed to deployers, requiring that high-risk AI systems be accompanied by instructions for use, documentation, and information that enables meaningful oversight. Notified bodies must communicate assessment findings to providers, flag non-conformities, and where an AI system fails to meet requirements, refuse or withdraw the EU technical documentation assessment.
Beyond provider-facing duties, notified bodies must inform the notifying authority and the AI Office of significant changes affecting their competence, suspensions or withdrawals of certificates, and any circumstances that may cast doubt on a provider's compliance. These obligations mirror the structured transparency reporting seen in the Digital Services Act under Articles 15 and 42, where providers of intermediary services must publish periodic reports on content moderation and algorithmic decisions — establishing a regulatory pattern of mandatory, documented disclosure to supervisory authorities.
The GDPR framework reinforces these duties where notified bodies process personal data during assessments. Article 13 GDPR requires transparent information to data subjects, and Article 15 GDPR grants access rights that intersect with notified body activities — particularly when assessment findings touch on individuals' data. Member States may impose professional secrecy obligations under Article 15(2) that qualify how broadly assessment findings can be disseminated, creating a tension between transparency and confidentiality that notified bodies must navigate.
Key Developments
Dutch administrative case law illustrates the practical thresholds for adequate information provision. In one ruling, the court upheld a controller's right to request specification when a data subject sought access to a large volume of records — establishing that information obligations are not unlimited where the scope is genuinely broad. In another matter, the court found information provision deficient because the controller failed to disclose specific intelligence indicators, did not provide copies of referenced decisions, and omitted personal data handling information — demonstrating that partial or incomplete disclosure constitutes a violation.
The Malta Data Protection Commissioner's enforcement actions reinforce these standards. A €20,000 fine was imposed where a controller's data protection policy failed to meet transparency requirements alongside a failure to inform a data subject. A separate €4,000 fine addressed both unsolicited messaging and a non-compliant privacy policy. These decisions establish that transparency obligations are enforced independently — a deficient policy alone triggers liability even absent other violations.
The February 2026 AI Omnibus proposals seeking to weaken AI Act transparency provisions signal ongoing political pressure that notified bodies should monitor, as any dilution of reporting standards would directly affect their compliance burden.
Practical Guidance
Document every assessment finding with a clear communication chain: Notified bodies must maintain auditable records of what was communicated to providers, authorities, and the AI Office, tracing each disclosure to the specific legal basis under Article 13 AI Act and related provisions.
Establish escalation protocols for non-conformity: When assessment reveals non-compliance, notified bodies must have predefined procedures for refusing or withdrawing certification and simultaneously notifying the notifying authority — delays or omissions create enforcement exposure.
Reconcile transparency with professional secrecy: Where Member State law imposes confidentiality obligations under Article 15(2) GDPR-equivalent provisions, notified bodies must classify information into tiers — fully disclosable, restricted, and legally protected — and apply access controls accordingly.
Ensure information provided to deployers is operationally sufficient: Following the Dutch court standard, information must be complete enough to enable meaningful human oversight; partial disclosure that omits material findings fails the legal threshold.
Monitor legislative amendments actively: The AI Omnibus proposals demonstrate that information obligations remain politically contested; notified bodies should build compliance systems that are modular enough to accommodate tightened or relaxed reporting requirements without structural redesign.