Skip to content
Topic Contested in court

Provider Obligations for AI Systems

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that deserves its own dedicated topic for better organization and searchability.

55 linked items 44 Laws1 Guidance1 News9 Literature

Overview

15 sources · Jul 23, 2026

Legal Framework

Provider obligations for high-risk AI systems are primarily governed by the AI Act, with critical intersections with GDPR requirements. Under AI Act Article 11, providers must maintain comprehensive technical documentation demonstrating their system's compliance with substantive requirements before market placement and throughout its lifecycle. This documentation must enable conformity assessment and post-market monitoring.

AI Act Article 43 establishes the conformity assessment framework, requiring providers to demonstrate compliance through either internal control procedures or notified body assessment, depending on the system's classification. For systems involving biometric data or other high-risk categories, third-party conformity assessment via notified bodies is mandatory. Article 39 extends this framework to third-country conformity assessment bodies, permitting their authorization provided they meet Article 31 requirements or demonstrate equivalent compliance levels.

The GDPR overlay is significant where AI systems process personal data. Article 28 GDPR imposes detailed processor agreement requirements that exceed the prior Directive 95/46 regime, demanding specific technical and organizational measures be contractually mandated. Article 11 GDPR provides that controllers who cannot identify data subjects from processed data are not obligated to collect additional identifying information solely for GDPR compliance—though they must accept supplementary data voluntarily provided by data subjects seeking to exercise access or rectification rights. This principle directly affects AI system design: providers building systems that operate on pseudonymized or non-identifying data should not be compelled to re-identify individuals merely to satisfy regulatory obligations.

Key Developments

The interplay between AI Act conformity requirements and GDPR processor obligations creates a layered compliance architecture. The GDPR's coherence mechanism under Articles 64-67 ensures supervisory authorities apply data protection rules consistently—a principle now extending to AI system oversight. Enforcement experience under Article 28 GDPR demonstrates that controllers must select processors offering sufficient guarantees regarding expertise, reliability, and resources, with Recital 81 specifically framing these guarantees beyond mere security measures. This standard directly informs AI provider due diligence when engaging subprocessors for training data or model hosting.

The rectification right under Article 17 GDPR has been judicially circumscribed: it does not extend to correcting impressions, opinions, research findings, or conclusions with which a data subject disagrees. This boundary is critical for AI system outputs—providers are not obligated to alter model-generated assessments merely because subjects contest them, provided the underlying data is accurate.

Practical Guidance

  • Maintain living technical documentation per AI Act Article 11 that covers system architecture, training data provenance, risk mitigation measures, and post-market monitoring protocols—this must exist before market placement and remain current throughout deployment.

  • Determine your conformity assessment pathway early under Article 43: map your system's risk classification to identify whether internal control suffices or notified body involvement is required, and if engaging third-country assessment bodies under Article 39, verify they satisfy Article 31 equivalence standards.

  • Structure processor agreements to satisfy both AI Act Article 11 documentation requirements and GDPR Article 28(3) contractual mandates, ensuring subprocessor guarantees address expertise and reliability—not solely security controls.

  • Design data minimization into training pipelines leveraging Article 11 GDPR principles: avoid re-identifying individuals solely for compliance purposes, while building mechanisms to accept voluntary supplementary data from data subjects exercising their rights.

  • Distinguish factual data correction from opinion contestation in handling rectification requests: update inaccurate underlying personal data but do not modify model outputs or assessments that represent opinions or conclusions, directing disputes to appropriate procedural channels.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 44
Art. 112(12) Any amendment to this Regulation pursuant to paragraph 10, or relevant delegated or implementing acts, which concerns sectoral Union harmonisation leg… AI Act Art. 3(12) ‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specifie… AI Act Art. 3(19) ‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designatio… AI Act Art. 3(20) ‘conformity assessment’ means the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI syste… AI Act rec 81 Recital 81 — provider quality management system AI Act Jun 2024 art 47 EU declaration of conformity AI Act Jun 2024 rec 71 Recital 71 — high-risk AI technical documentation and logs AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 art 46 Derogation from conformity assessment procedure AI Act Jun 2024 art 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems AI Act Jun 2024 rec 123 Recital 123 — conformity assessment for high-risk AI systems AI Act Jun 2024 rec 65 Recital 65 — high-risk AI risk management system AI Act Jun 2024 art 29 Application of a conformity assessment body for notification AI Act Jun 2024 art 43 Conformity assessment AI Act Jun 2024 rec 128 Recital 128 — substantial modification triggering new conformity assessment AI Act Jun 2024 rec 125 Recital 125 — High-risk AI systems conformity assessment procedure AI Act Jun 2024 rec 124 Recital 124 — conformity assessment integration with existing harmonisation legislation AI Act Jun 2024 rec 87 Recital 87 — high-risk AI system product manufacturer obligations AI Act Jun 2024 rec 129 Recital 129 — CE marking for high-risk AI systems AI Act Jun 2024 rec 78 Recital 78 — conformity assessment cybersecurity high-risk AI AI Act Jun 2024 art 9 Risk management system AI Act Jun 2024 art 48 CE marking AI Act Jun 2024 rec 127 Recital 127 — Mutual recognition of conformity assessment results AI Act Jun 2024 art 39 Conformity assessment bodies of third countries AI Act Jun 2024 Show 24 more →
Guidance 1
edps joint opinion 52021 on the proposal for a regulation of the EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) EDPB Jun 2021
News 1
Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023
Literature 9
AFMN Biomedicine REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT AFMN Biomedicine Jul 2026 SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Accounting and Auditing From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence Accounting and Auditing Jul 2026 Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 AI and Ethics Eu regulatory ecosystem for ethical AI AI and Ethics Jun 2025 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 Computer Law Review International Technical Documentation Obligations in Data Protection, Technology, and Cybersecurity Law Computer Law Review International Mar 2026 Journal of European Competition Law & Practice Training national judges for digital competition law: the DMA, private enforcement, and the infrastructure of judicial capacity Journal of European Competition Law & Practice May 2026 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026