Notified Body Information Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This specific topic is needed to comprehensively cover the distinct information obligations that notified bodies must fulfill under the AI Act, including their duties to disclose assessment findings, report non-compliance, notify authorities of incidents, and provide transparent information to stakeholders.
Overview
14 sources · Sep 8, 2026Legal Framework
The AI Act establishes a structured notification regime for conformity assessment bodies through Article 28, Article 29, and Article 30. Together, these provisions define the information obligations that notified bodies and notifying authorities must satisfy throughout the designation, notification, and ongoing monitoring lifecycle.
Article 29 requires conformity assessment bodies seeking notification to submit detailed applications to their national notifying authority, including descriptions of assessment activities, modules, AI system types, and accreditation certificates. Where no accreditation certificate exists, the body must supply documentary evidence sufficient for verification and regular monitoring. Crucially, the obligation is not static:
"The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31."
— AI Act Art. 29(4)
Article 30 governs the notification procedure itself. Once a notifying authority is satisfied that a body meets the requirements of Article 31, it must notify the Commission and other Member States through an electronic tool. The notification must be comprehensive:
"The notification referred to in paragraph 2 of this Article shall include full details of the conformity assessment activities, the conformity assessment module or modules, the types of AI systems concerned, and the relevant attestation of competence."
— AI Act Art. 30(3)
Article 28 imposes confidentiality obligations on notifying authorities, requiring them to protect information obtained during the assessment and monitoring process in accordance with Article 78 of the AI Act.
Key Developments
The EDPB-EDPS Joint Opinion on the AI Act proposal flagged early concerns about the clarity of competent authority roles and independence guarantees. The joint opinion noted that:
This uncertainty directly affects the information architecture: if the boundary between notifying authorities, market surveillance authorities, and supervisory authorities remains ambiguous, the channels through which notified bodies must report non-compliance and incidents are correspondingly unsettled. The Rechtbank Amsterdam's 2021 ruling, while addressing GDPR jurisdiction rather than AI Act notification, underscores that direct applicability of EU regulations means procedural obligations on designated bodies will be enforced without implementing national legislation.
Status of the Debate
This topic is contested and actively taking shape. The AI Act's notification framework borrows heavily from established Union harmonisation legislation (e.g., Regulation 765/2008), but the specific information duties of notified bodies for AI systems—particularly around reporting assessment findings and incident notification—lack settled interpretive precedent. No court has yet ruled on the scope or boundaries of these obligations. The debate will likely be resolved through the first wave of designations, where notifying authorities and the Commission will set practical thresholds through their objection and consultation decisions under Article 30(4)–(5). Until then, the precise content and timing of information obligations remains regulator-defined rather than court-tested.
Practical Guidance
Maintain a living documentation file. Under Article 29(4), notified bodies must proactively update their application documentation whenever relevant changes occur—not merely at annual review intervals. Establish internal triggers for identifying "relevant changes" in assessment scope, personnel, or methodology.
Prepare comprehensive notification packages. Article 30(3) requires full details of conformity assessment activities, modules, AI system types, and competence attestations. Incomplete notifications risk objection from the Commission or Member States within the two-week or two-month windows.
Implement confidentiality controls aligned with Article 78. Notifying authorities are bound by Article 28(6) to safeguard information obtained. Notified bodies should mirror these standards internally, particularly when handling proprietary AI system documentation received during assessment.
Leverage existing designations. Article 29(4) allows bodies already designated under other Union harmonisation legislation to reuse documents and certificates. Map existing accreditations to AI Act requirements to streamline the notification process.
Establish incident reporting channels early. While the AI Act's specific incident-reporting timelines for notified bodies will be further defined by implementing acts, bodies should build reporting workflows now that connect to both notifying authorities and market surveillance authorities, given the unresolved institutional boundary concerns flagged by the EDPB-EDPS.
Nothing of this type on this topic.