Art.20
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 20

Article 20 — Corrective Actions and Duty of Information

High-Risk Systems SME Relevant ~2 min read · 494 words

Article 20 deals with what happens when something goes wrong. It establishes the provider’s obligation to act immediately when they discover — or even suspect — that their high-risk AI system is not compliant. Speed, transparency, and cooperation with authorities are the three pillars of this article.

! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

What providers must do when non-compliance is discovered

Article 20 sets out the corrective action obligations for providers of high-risk AI systems. It covers two scenarios: non-compliance with the Act’s requirements, and the discovery of a risk within the meaning of the market surveillance provisions. In both cases the obligation is immediate action, transparent communication, and full cooperation with regulators.

WHAT IT SAYS

Immediate action, immediate disclosure

  • Providers who know or have reason to believe their high-risk AI system is not in conformity with the Act must immediately take corrective action — bringing the system into compliance, withdrawing it, disabling it, or recalling it as appropriate
  • Providers must inform distributors, deployers, authorised representatives and importers of the non-compliance and the corrective actions taken
  • Where the system presents a risk within the meaning of Article 79 — a risk to health, safety or fundamental rights — the provider must immediately investigate the causes in collaboration with the deployer where applicable
  • The provider must then inform the relevant market surveillance authorities and any notified body that issued a certificate for the system, providing details of the non-compliance and the corrective actions taken
  • Providers must cooperate fully with competent authorities in any investigation and must provide all requested information

WHO IS AFFECTED

Providers — but deployers are brought into the process

  • Providers of high-risk AI systems — this is primarily their obligation
  • Deployers who are required to cooperate with providers in investigating causes of risk
  • Distributors and importers who must be notified of non-compliance and corrective actions
  • National market surveillance authorities who receive notifications under this article
  • Notified bodies that issued conformity certificates — they must be informed of material non-compliance

WHAT IT MEANS FOR SMES

Have an incident response plan before you need one

  • The obligation is triggered by knowledge or reasonable suspicion — you do not need to wait for a regulator to identify the problem before acting; if your own monitoring picks up a non-conformity, the clock starts immediately
  • Speed is legally required — the word ‘immediately’ appears multiple times in this article; delayed action is not a defence
  • Have a pre-defined incident response procedure in your quality management system that maps directly to this article — who is responsible, what the escalation path is, and which authorities to notify
  • Your deployers are your partners in this process — maintain open communication channels with them so that issues can be identified and investigated quickly
  • Document every step of your corrective action process — what you discovered, when you discovered it, what you did, and what you communicated to whom; this documentation is your protection in any regulatory investigation

Related Articles

← Previous Art. 19 — Automatically Generated Logs Next → Art. 21 — Cooperation with Competent Authorities