Chapter 10 of 25
Supervision, Remedies and the Recitals’ Closing Framework
The final recitals allocate supervision among financial, biometric, national and Union authorities before turning to remedies, penalties, review and staged application. They reveal how the Act intends to move from legislative design to phased, revisable enforcement.
Recital (158): Financial-Sector Supervision
Use existing financial supervisors
Recital (158) generally assigns oversight of AI used or provided by regulated financial institutions to the competent authorities for the supervision and enforcement of those legal acts.
Market surveillance is included
Those authorities should conduct enforcement and market surveillance, including ex post activities, unless a Member State designates another authority for the market-surveillance role.
Banking coordination
Single Supervisory Mechanism participants should report without delay to the ECB information from AI market surveillance that may matter to the ECB's prudential tasks.
Avoid duplication
The recital envisages integrating risk management, post-market monitoring, and documentation into existing financial-law procedures, with limited derogations to prevent overlapping duties.
Recitals (159)-(160): Biometrics and Cross-Border Action
High-risk biometrics
Recital (159) concerns biometric high-risk AI used in law enforcement, migration, asylum, border management, justice, and democratic processes.
A minimum access power
The authority should have powers including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks.
Independence and safeguards
Authorities should act with complete independence. Limits involving sensitive operational data should not reduce powers under Directive (EU) 2016/680.
Joint investigations
Under Recital (160), authorities and the Commission should be able to propose joint action for serious risks across two or more Member States; the AI Office should coordinate investigations.
Recitals (161)-(164): Who Supervises General-Purpose AI?
The same-provider rule
If the same provider supplies both a general-purpose model and the AI system built on it, Recital (161) says supervision should occur at Union level through the AI Office.
The default elsewhere
In all other cases, national market-surveillance authorities remain responsible. They should cooperate with the AI Office where directly deployable general-purpose systems can serve a high-risk purpose.
Commission competence
Recital (162) says the powers of supervision and enforcement of the obligations on providers of general-purpose AI models should be a competence of the Commission.
How enforcement works
The AI Office should monitor, request information, evaluate models, involve independent experts, request mitigation, and potentially restrict, withdraw, or recall a model.
Recitals (165)-(167): Voluntary Codes, Product Safety, and Confidentiality
Voluntary, not compulsory
Recital (165) says Providers of AI systems that are not high-risk should be encouraged to create codes of conduct. It frames this as encouragement, not a mandatory high-risk classification.
What a code can cover
Codes may adapt high-risk-style practices to lower risk and address sustainability, AI literacy, inclusion, accessibility, stakeholder participation, and team diversity.
Make codes measurable
Effective voluntary codes should use clear objectives and key performance indicators. They should be developed inclusively, as appropriate, with relevant stakeholders.
Safety and secrecy
Recital (166) identifies Regulation (EU) 2023/988 as a safety net. Recital (167) calls for confidentiality that protects trade secrets, security, proceedings, and classified information.
Recitals (168)-(172): Penalties, Complaints, Explanations, and Whistleblowing
Penalties
Recital (168) says Member States should ensure implementation through effective, proportionate and dissuasive penalties, while respecting the ne bis in idem principle.
Individualised fines
Fine-setting should consider the nature, gravity, duration, and consequences of an infringement, plus provider size, including whether the provider is an SME or start-up.
Complaint route
A natural or legal person with grounds to think the Regulation was infringed should be entitled to complain to the relevant market-surveillance authority.
Explanation and whistleblowers
For certain high-risk-system decisions mainly based on AI output, affected persons should receive a clear, meaningful explanation. Directive (EU) 2019/1937 should protect reporting persons.
Recitals (173)-(176): Updating and Justifying the Framework
Delegated acts
Recital (173) lists specific areas in which Article 290 TFEU delegated acts may amend the framework, including high-risk classification, documentation, conformity assessment, and systemic-risk criteria.
Consultation matters
The Commission should consult appropriately. Parliament and Council should receive documents at the same time as Member State experts and have access to relevant expert-group meetings.
A repeated review cycle
the Commission should evaluate and review this Regulation by 2 August 2029 and every four years thereafter, alongside annual and separate three-year and four-year assessments.
Why Union action?
Recital (176) relies on subsidiarity and proportionality: Union-level action is presented as better suited to the objective and no broader than necessary.
Recitals (177)-(180): Legacy Systems and Staged Application
Legacy high-risk systems
Recital (177) generally links pre-existing high-risk systems to the Regulation only when they undergo significant design or intended-purpose changes after the general application date.
Public-sector exceptions
Large-scale IT-system components have an end-of-2030 compliance point; high-risk systems intended for public authorities have a 2 August 2030 compliance point.
The staged dates in Recital (179)
General application should begin 2 August 2026. Prohibitions and general provisions should already apply from 2 February 2025; governance, penalties, and general-purpose-model obligations should apply from 2 August 2025.
External currency note
PE-CONS 30/26, dated 8 July 2026, is signed pending publication, not in force. It proposes later Chapter III application dates, but the original source dates remain operative on 22 July 2026.
Authority Allocation Lab
Classify each situation before revealing the answer
For each scenario, identify the principal supervisory path described by Recitals (158)-(164). Then state one reason grounded in the recital language.
- A bank uses a high-risk creditworthiness AI system. Its ordinary banking supervisor is already competent under Union financial-services law.
- A national authority investigates a biometric high-risk system used at a border crossing and needs the personal data being processed to assess compliance.
- One company supplies both a general-purpose AI model and a recruitment system built on that model.
- A national authority cannot finish investigating a high-risk system because the provider will not provide necessary information about the underlying general-purpose model.
- A general-purpose model provider allegedly ignores a Commission-requested risk-mitigation measure.
Suggested answers
- Recital (158): the existing financial competent authority should generally be designated within its competence, unless the Member State designates another market-surveillance authority.
- Recital (159): the relevant market-surveillance authority should have effective investigative and corrective powers, including access to all personal data being processed and all necessary information; it should act independently.
- Recital (161): supervision should take place at Union level through the AI Office because the same provider supplies both model and system.
- Recital (161): the authority should be able to request AI Office assistance; the Chapter VI mutual-assistance procedure of Regulation (EU) 2019/1020 should apply mutatis mutandis.
- Recitals (162), (164), and (169): the Commission has supervisory and enforcement competence for general-purpose-model provider obligations; compliance may be pursued through requested measures and fines.
Quiz 1: Same Provider, Which Level?
Choose the answer that most closely follows Recital (161).
A provider offers both a general-purpose AI model and an AI system based on that model. According to Recital (161), where should supervision take place?
- At Union level through the AI Office
- Only through the provider's voluntary code of conduct
- Only through the European Data Protection Supervisor
- Automatically through the relevant national authority, with no AI Office role
Show Answer
Answer: A) At Union level through the AI Office
Recital (161) states that where the model and the AI system are provided by the same provider, supervision should take place at Union level through the AI Office. National authorities remain responsible in all other cases, subject to the cooperation arrangements described there.
Quiz 2: Reading the Staged Dates
Test your ability to distinguish the source text's different application points.
Under Recital (179) as written, which item should have been ready by 2 May 2025?
- Codes of practice
- The Regulation's general application for all provisions
- Public-authority compliance with legacy high-risk systems
- The Commission's first general review
Show Answer
Answer: A) Codes of practice
Recital (179) says: "Codes of practice should be ready by 2 May 2025." It separately identifies 2 August 2026 as the general application date, 2 August 2030 for certain public-authority high-risk systems in Recital (177), and 2 August 2029 for the first general review in Recital (174).
Flashcards: Closing Framework Recall
Flip each card and recall the recital, rule, and date before checking the answer.
- Financial-sector oversight
- Recital (158): existing financial competent authorities should generally supervise AI systems of regulated financial institutions within their competences, unless a Member State designates another market-surveillance authority.
- Biometric authority access
- Recital (159): authorities should have effective investigative and corrective powers, including access to all personal data being processed and all information necessary for their tasks.
- Same provider: model plus system
- Recital (161): supervision should take place at Union level through the AI Office.
- General-purpose model provider enforcement
- Recital (162): supervision and enforcement powers over provider obligations should be a competence of the Commission.
- Complaint route
- Recital (170): a natural or legal person with grounds to consider that the Regulation was infringed should be entitled to complain to the relevant market-surveillance authority.
- First general review
- Recital (174): the Commission should evaluate and review the Regulation by 2 August 2029 and every four years thereafter.
- Core application timetable
- Recital (179): prohibitions and general provisions from 2 February 2025; governance, penalties, and general-purpose-model obligations from 2 August 2025; general application from 2 August 2026.
Key Terms
- AI Office
- The Union-level body described in the recitals as supervising certain same-provider model-and-system cases and supporting or conducting specified general-purpose-AI oversight tasks.
- Delegated act
- An act adopted under the delegated-power mechanism of Article 290 TFEU; Recital (173) identifies the AI Act areas that may be amended through this mechanism.
- Ne bis in idem
- The principle Recital (168) says Member States should respect when implementing penalties.
- Qualified alert
- An alert the scientific panel may provide to the AI Office where it has reason to suspect a concrete and identifiable Union-level risk or systemic-risk classification criteria.
- Codes of conduct
- Voluntary codes that non-high-risk AI providers should be encouraged to create under Recital (165), potentially adapting some high-risk requirements to lower-risk systems.
- Significant change
- For Recital (177), a change in design or intended purpose understood as equivalent in substance to substantial modification for high-risk AI systems.
- Implementing powers
- Powers conferred on the Commission to ensure uniform conditions for implementation, exercised under Regulation (EU) No 182/2011 according to Recital (175).
- General-purpose AI model
- The model category addressed in Recitals (161)-(164), for which the Commission and AI Office have specified supervisory and enforcement roles.
- Ex post market surveillance
- Surveillance performed after a system has been placed on the market or put into service.
- Market surveillance authority
- An authority responsible for supervising compliance and enforcing relevant requirements in the market-surveillance framework discussed in the recitals.