WHAT THE ARTICLE IS ABOUT
When a technically compliant AI system is still too risky
Article 82 deals with situations where an AI system meets all its applicable technical and procedural requirements under the Act but nonetheless presents a risk that justifies regulatory intervention. This is sometimes called the ‘safety override’ provision — it prevents the Act’s detailed compliance framework from becoming a shield against intervention where genuine risks exist.
WHAT IT SAYS
Compliance is not a complete defence against risk-based intervention
- Where a market surveillance authority finds that an AI system is in compliance with all applicable requirements but nonetheless presents a risk to health, safety, fundamental rights or other public interests, it may require the operator to take appropriate measures
- Measures may include ensuring the AI system no longer presents the risk, withdrawing it from the market, recalling it, or restricting its use
- The authority must notify the Commission and other member states of its measures and the reasons for them
- Other member states may object to the measures within three months — triggering Commission review under the Union Safeguard Procedure
- This provision applies even where the AI system complies with harmonised standards — technical compliance with standards does not override a genuine risk finding
- The authority must justify why the risk is not adequately addressed by compliance with applicable requirements
WHO IS AFFECTED
Providers of high-risk AI systems with compliant but potentially risky systems
- Providers whose systems are fully compliant but may present unforeseen risks in deployment
- Market surveillance authorities that identify risks in compliant systems
- The Commission and other member states who review notifications under this article
- Deployers using systems that may be subject to restrictions despite compliance
WHAT IT MEANS FOR SMES
Compliance is necessary but not sufficient — real-world safety matters
- This article is a reminder that compliance is a minimum standard, not a guarantee of regulatory safety — if your system causes real harm in deployment despite meeting all requirements, intervention remains possible
- Post-market monitoring under Article 72 is your early warning system: monitoring data that reveals your system is causing unexpected harms should prompt voluntary corrective action before an authority acts
- The requirement that authorities justify why risks are not adequately addressed by compliance creates a meaningful barrier to arbitrary intervention — this is not a blank cheque for regulators
- In practice this provision is likely to be used sparingly — the compliance framework is designed to address the foreseeable risks; Article 82 catches truly unforeseen ones
- If you receive an Article 82 measure despite full compliance, the objection mechanism and Union Safeguard Procedure under Article 81 provide avenues to challenge it
Related Articles
- Article 79 — National enforcement procedure (the broader framework within which Article 82 operates)
- Article 81 — Union safeguard procedure (applies to contested Article 82 measures)
- Article 72 — Post-market monitoring (the mechanism that would typically reveal the risks Article 82 addresses)
- Article 83 — Formal non-compliance (the parallel provision for systems that are actually non-compliant)
