Provider Obligations for AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that deserves its own dedicated topic for better organization and searchability.
Overview
15 sources · Jul 23, 2026Legal Framework
Provider obligations for high-risk AI systems are primarily governed by the AI Act, with critical intersections with GDPR requirements. Under AI Act Article 11, providers must maintain comprehensive technical documentation demonstrating their system's compliance with substantive requirements before market placement and throughout its lifecycle. This documentation must enable conformity assessment and post-market monitoring.
AI Act Article 43 establishes the conformity assessment framework, requiring providers to demonstrate compliance through either internal control procedures or notified body assessment, depending on the system's classification. For systems involving biometric data or other high-risk categories, third-party conformity assessment via notified bodies is mandatory. Article 39 extends this framework to third-country conformity assessment bodies, permitting their authorization provided they meet Article 31 requirements or demonstrate equivalent compliance levels.
The GDPR overlay is significant where AI systems process personal data. Article 28 GDPR imposes detailed processor agreement requirements that exceed the prior Directive 95/46 regime, demanding specific technical and organizational measures be contractually mandated. Article 11 GDPR provides that controllers who cannot identify data subjects from processed data are not obligated to collect additional identifying information solely for GDPR compliance—though they must accept supplementary data voluntarily provided by data subjects seeking to exercise access or rectification rights. This principle directly affects AI system design: providers building systems that operate on pseudonymized or non-identifying data should not be compelled to re-identify individuals merely to satisfy regulatory obligations.
Key Developments
The interplay between AI Act conformity requirements and GDPR processor obligations creates a layered compliance architecture. The GDPR's coherence mechanism under Articles 64-67 ensures supervisory authorities apply data protection rules consistently—a principle now extending to AI system oversight. Enforcement experience under Article 28 GDPR demonstrates that controllers must select processors offering sufficient guarantees regarding expertise, reliability, and resources, with Recital 81 specifically framing these guarantees beyond mere security measures. This standard directly informs AI provider due diligence when engaging subprocessors for training data or model hosting.
The rectification right under Article 17 GDPR has been judicially circumscribed: it does not extend to correcting impressions, opinions, research findings, or conclusions with which a data subject disagrees. This boundary is critical for AI system outputs—providers are not obligated to alter model-generated assessments merely because subjects contest them, provided the underlying data is accurate.
Practical Guidance
Maintain living technical documentation per AI Act Article 11 that covers system architecture, training data provenance, risk mitigation measures, and post-market monitoring protocols—this must exist before market placement and remain current throughout deployment.
Determine your conformity assessment pathway early under Article 43: map your system's risk classification to identify whether internal control suffices or notified body involvement is required, and if engaging third-country assessment bodies under Article 39, verify they satisfy Article 31 equivalence standards.
Structure processor agreements to satisfy both AI Act Article 11 documentation requirements and GDPR Article 28(3) contractual mandates, ensuring subprocessor guarantees address expertise and reliability—not solely security controls.
Design data minimization into training pipelines leveraging Article 11 GDPR principles: avoid re-identifying individuals solely for compliance purposes, while building mechanisms to accept voluntary supplementary data from data subjects exercising their rights.
Distinguish factual data correction from opinion contestation in handling rectification requests: update inaccurate underlying personal data but do not modify model outputs or assessments that represent opinions or conclusions, directing disputes to appropriate procedural channels.