SkarpSkarp

Chapter 21 of 25

Risk Procedures, Remedies and General-Purpose AI Enforcement

The enforcement chapters address systems that are risky, misclassified, formally defective or compliant on paper but dangerous in practice. They also give the Commission and AI Office specialised powers over general-purpose AI models while preserving complaint, explanation and whistleblower channels.

20 min readen

Article 79: When an AI System Presents a Risk

The legal meaning of risk

Article 79 links risky AI to EU product-safety law: "AI systems presenting a risk shall be understood as a ‘product presenting a risk’ as defined in Article 3, point 19 of Regulation (EU) 2019/1020".

Evaluation trigger

Where a market surveillance authority has sufficient reason to consider a risk exists, it shall evaluate compliance with all Regulation requirements. It must give particular attention to vulnerable groups.

Fundamental-rights risks

Where risks to fundamental rights are identified, the authority must inform and fully cooperate with the national bodies in Article 77(1). Relevant operators must cooperate as necessary.

Corrective-action deadline

Following non-compliance, the authority can require compliance, withdrawal, or recall: "in any event within the shorter of 15 working days, or as provided for in the relevant Union harmonisation legislation".

Trace the Article 79 Enforcement Path

Thought Exercise: What Must the Authority Do Next?

A national market surveillance authority receives credible evidence that a high-risk AI recruitment system systematically excludes applicants with disabilities. It has sufficient reason to consider that the system presents a risk to fundamental rights.

Put the following actions in the order required by Article 79:

  1. Evaluate compliance with all requirements and obligations under the Regulation.
  2. Inform and fully cooperate with the relevant national public authorities or bodies under Article 77(1).
  3. Require appropriate corrective action if the evaluation identifies non-compliance.
  4. Ensure the operator's deadline is no longer than the shorter of 15 working days or the applicable Union-harmonisation-law period.
  5. Notify the relevant notified body.

Self-check

The logical sequence begins with the authority's sufficient reason to suspect risk. It then performs the evaluation. Because this scenario identifies a fundamental-rights risk, cooperation with the Article 77(1) bodies is also required. If non-compliance is found, the authority requires compliance, withdrawal, or recall within the specified period, and informs the notified body.

Do not assume Article 79 allows the authority to wait for a private complaint before acting. The trigger in paragraph 2 is that the authority has sufficient reason to consider that the system presents the defined risk.

Article 79 Across Borders and Article 80 Misclassification

Beyond the initiating state

If non-compliance is not restricted to one national territory, the initiating authority shall inform the Commission and other Member States without undue delay. Corrective action must cover all affected systems on the Union market.

When the operator does not act

If adequate correction is not taken in time, Article 79 requires provisional measures: restriction, prohibition, withdrawal, or recall, followed by notification to the Commission and other Member States.

Non-high-risk is not final

Under Article 80, an Annex III system classified as non-high-risk can be reassessed where the authority has sufficient reason to consider it is actually high-risk under Article 6(3).

Circumvention matters

If the authority establishes "the AI system was misclassified by the provider as non-high-risk in order to circumvent the application of requirements in Chapter III, Section 2", Article 99 fines apply.

Quiz: Risk, Correction, and Classification

Choose the most accurate answer under Articles 79 and 80.

A provider labels an Annex III system non-high-risk. The authority establishes that the label was used to evade Chapter III, Section 2 requirements. What does Article 80(7) say?

  1. The provider shall be subject to fines in accordance with Article 99.
  2. The authority may only issue informal guidance because classification is the provider's exclusive decision.
  3. The provider automatically receives a three-month period before any enforcement step is possible.
  4. The Commission must first declare every Annex III system high-risk.
Show Answer

Answer: A) The provider shall be subject to fines in accordance with Article 99.

Article 80(7) addresses deliberate circumvention. Its exact trigger is that **"the AI system was misclassified by the provider as non-high-risk in order to circumvent the application of requirements in Chapter III, Section 2"**. In that event, the provider shall be subject to Article 99 fines.

Articles 79-83: Review, Union Safeguards, and Formal Defects

Provisional-measure review

A notified national provisional measure is deemed justified where "within three months of receipt of the notification referred to in paragraph 5 of this Article, no objection has been raised".

Article 5 acceleration

For non-compliance with Article 5 prohibitions, the ordinary three-month review period is reduced to 30 days. Article 81 also shortens the Commission decision period to 60 days.

Risk despite compliance

Article 82 applies even where a high-risk system complies on paper but still risks health, safety, fundamental rights, or another aspect of public-interest protection.

Formal non-compliance

Article 83 includes missing EU-database registration, CE-marking defects, missing declarations, absent representatives where applicable, and unavailable technical documentation. Persistent defects trigger proportionate restriction, prohibition, recall, or withdrawal.

Articles 84-87: Support Structures and Individual Remedies

Testing support

"The Commission shall designate one or more Union AI testing support structures". They perform specified market-surveillance support tasks and also provide independent technical or scientific advice when requested.

Complaint right

Any natural or legal person with grounds to consider an infringement may complain to the relevant market surveillance authority. Complaints must be taken into account for surveillance activities and handled through dedicated procedures.

Explanation: a conditional right

Article 86 applies to specific Annex III high-risk-system decisions with legal or similarly significant adverse effects. It excludes Annex III point 2 systems and remains subject to lawful Union or national exceptions.

Reporting persons

Article 87 applies Directive (EU) 2019/1937 to reporting infringements of this Regulation and protecting the people who make those reports.

Articles 88-90: General-Purpose AI Model Oversight

Who enforces Chapter V?

Article 88 states: "The Commission shall have exclusive powers to supervise and enforce Chapter V". The Commission entrusts implementation to the AI Office, subject to Article 94 procedural guarantees.

Monitoring and complaints

The AI Office may monitor compliance, including adherence to approved codes of practice. "Downstream providers shall have the right to lodge a complaint alleging an infringement of this Regulation."

What a downstream complaint needs

A complaint must be duly reasoned and state the provider contact point, facts, relevant provisions, reasons for the alleged infringement, and other information the downstream provider considers relevant.

Qualified alerts

"The scientific panel may provide a qualified alert to the AI Office" for a concrete identifiable Union-level risk or where a model may meet Article 51 conditions.

Flashcards: Enforcement Vocabulary

Flip each card and test whether you can state the trigger, actor, and consequence precisely.

Article 79 risk definition
AI systems presenting a risk are understood as a product presenting a risk under Article 3(19) of Regulation (EU) 2019/1020, insofar as they risk health, safety, or fundamental rights.
Article 79 corrective-action limit
The authority may prescribe the period, but action is required in any event within the shorter of 15 working days, or the period under relevant Union harmonisation legislation.
Article 80 misclassification consequence
If a provider misclassified a system as non-high-risk to circumvent Chapter III, Section 2, the provider is subject to Article 99 fines.
Article 82 key insight
A high-risk AI system may require corrective measures even though it complies with the Regulation, if it nevertheless presents a specified risk.
Article 85 complaint holder
Any natural or legal person with grounds to consider an infringement may submit a complaint to the relevant market surveillance authority.
Article 88 enforcement allocation
The Commission has exclusive powers to supervise and enforce Chapter V and entrusts implementation tasks to the AI Office.
Article 92 model access
The Commission may request access through APIs or other appropriate technical means and tools, including source code.

Articles 91-94: Information, Evaluation, Remedies, and Due Process

Information requests

The Commission may request Articles 53 and 55 documentation and additional necessary information. The request must state its legal basis, purpose, required information, deadline, and applicable Article 101 fines.

When evaluation is available

After consulting the Board, the AI Office may evaluate where Article 91 information is insufficient or to investigate Union-level systemic risks, particularly following a qualified scientific-panel alert.

Access to the model

"The Commission may request access to the general-purpose AI model concerned through APIs or further appropriate technical means and tools, including source code."

Measures and procedural rights

Where necessary and appropriate, the Commission may require compliance, mitigation, or "restrict the making available on the market, withdraw or recall the model". Article 94 preserves applicable procedural rights.

Final Quiz: Which Power Fits the Situation?

Apply the exact structure of Articles 91 to 94.

The AI Office has consulted the Board and finds that information obtained under Article 91 is insufficient to assess a general-purpose AI model provider's compliance. Which statement is correct?

  1. The AI Office may conduct an evaluation under Article 92, and the Commission may request model access through APIs or other appropriate technical means, including source code.
  2. The AI Office must immediately recall the model without consulting the provider or using any further assessment.
  3. Only a national market surveillance authority may request information from a general-purpose AI model provider.
  4. The scientific panel must itself issue a binding withdrawal order.
Show Answer

Answer: A) The AI Office may conduct an evaluation under Article 92, and the Commission may request model access through APIs or other appropriate technical means, including source code.

Article 92(1)(a) permits an evaluation where Article 91 information is insufficient to assess compliance. Article 92(3) states that the Commission may request access through APIs or further appropriate technical means and tools, including source code. A recall is instead one possible Article 93 measure where necessary and appropriate.

Key Terms

deployer
The actor using an AI system. Under Article 86, the deployer may owe clear and meaningful explanations to an affected person when all specified conditions are met.
qualified alert
A duly reasoned alert that the scientific panel may provide to the AI Office under Article 90 when it suspects a concrete identifiable Union-level risk or that Article 51 conditions are met.
mutatis mutandis
Applied with the modifications needed for the different context. Article 94 applies Article 18 of Regulation (EU) 2019/1020 this way to providers of general-purpose AI models.
relevant operator
The operator addressed by enforcement action under the applicable provision, such as a provider or another operator in the supply chain.
downstream provider
A provider entitled under Article 89 to lodge a duly reasoned complaint alleging an infringement of the Regulation.
high-risk AI system
An AI system falling within the Regulation's high-risk framework. In this module, the term is especially relevant to Articles 80, 82, 83, and Article 86.
provisional measure
A national restriction, prohibition, withdrawal, or recall measure taken under Article 79(5) when an operator does not take adequate corrective action within the required period.
structured dialogue
A dialogue that the AI Office may initiate before an information request, model-access request, or requested measure under Articles 91 to 93.
formal non-compliance
A defect listed in Article 83, such as CE-marking failures, missing or incorrect declarations of conformity, absent EU-database registration, no authorised representative where applicable, or unavailable technical documentation.
general-purpose AI model
The subject of Chapter V supervision and enforcement in Articles 88 to 94.
Union safeguard procedure
The Article 81 process through which the Commission evaluates contested national measures or measures considered contrary to Union law.
market surveillance authority
A Member State authority that carries out market-surveillance functions, including evaluating AI systems and imposing or initiating corrective and restrictive measures under the Articles taught here.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself