Notifying Authorities
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to specifically address the procedures, requirements, timelines, and mechanisms for notifying authorities about AI systems, incidents, and compliance matters under the AI Act, which is a distinct regulatory obligation not fully captured by existing topics.
Overview
Legal Framework
The AI Act establishes specific notification obligations to national competent authorities, with key procedures detailed in Articles 16(3), 17(5), 19(2), 20(4), 26(3), 28(4), 50, and 73. These articles mandate that providers of high-risk AI systems notify the relevant market surveillance authority before placing such systems on the market or putting them into service. The notification must include detailed technical documentation and a declaration of conformity. Furthermore, providers are required to report any serious incident or any malfunction constituting a significant risk to Article 73 authorities without undue delay, and in any event, not later than 15 days after becoming aware of the incident.
Practical Application
The notification framework under the AI Act creates a proactive supervisory mechanism. While the authoritative T&C commentary on the GDPR outlines the general tasks and powers of supervisory authorities, the AI Act provisions are more prescriptive and sector-specific. The requirement to notify before placing a system on the market is a key distinction, shifting compliance from a reactive to a pre-emptive model. The technical documentation submitted must be sufficiently detailed to allow the authority to assess compliance with the Act's requirements. The incident reporting obligation under Article 73 is interpreted broadly; any malfunction that could lead to a serious risk to health, safety, or fundamental rights triggers the duty to notify, irrespective of whether the incident has already materialized into harm. The 15-day timeline is strict and begins from the moment the provider becomes aware of a potential issue.
Key Considerations
- Pre-Market Notification is Mandatory: For high-risk AI systems, you cannot launch your product or service without first notifying the competent authority and submitting the complete technical documentation and conformity declaration. Build this step into your product development and launch timeline.
- Incident Reporting is Time-Sensitive and Broad: Establish an internal rapid-response protocol to identify and assess "serious incidents" or "malfunctions." The 15-day reporting clock starts upon internal awareness, not upon full internal investigation. Err on the side of reporting if a significant risk is plausible.
- Identify the Correct National Authority: Notification obligations are to the "market surveillance authority" designated by each Member State. Before any market entry, you must confirm the exact identity and contact procedures for the competent authority in each country where you intend to operate.