! High compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
What providers must do when non-compliance is discovered
Article 20 sets out the corrective action obligations for providers of high-risk AI systems. It covers two scenarios: non-compliance with the Act’s requirements, and the discovery of a risk within the meaning of the market surveillance provisions. In both cases the obligation is immediate action, transparent communication, and full cooperation with regulators.
WHAT IT SAYS
Immediate action, immediate disclosure
- Providers who know or have reason to believe their high-risk AI system is not in conformity with the Act must immediately take corrective action — bringing the system into compliance, withdrawing it, disabling it, or recalling it as appropriate
- Providers must inform distributors, deployers, authorised representatives and importers of the non-compliance and the corrective actions taken
- Where the system presents a risk within the meaning of Article 79 — a risk to health, safety or fundamental rights — the provider must immediately investigate the causes in collaboration with the deployer where applicable
- The provider must then inform the relevant market surveillance authorities and any notified body that issued a certificate for the system, providing details of the non-compliance and the corrective actions taken
- Providers must cooperate fully with competent authorities in any investigation and must provide all requested information
WHO IS AFFECTED
Providers — but deployers are brought into the process
- Providers of high-risk AI systems — this is primarily their obligation
- Deployers who are required to cooperate with providers in investigating causes of risk
- Distributors and importers who must be notified of non-compliance and corrective actions
- National market surveillance authorities who receive notifications under this article
- Notified bodies that issued conformity certificates — they must be informed of material non-compliance
WHAT IT MEANS FOR SMES
Have an incident response plan before you need one
- The obligation is triggered by knowledge or reasonable suspicion — you do not need to wait for a regulator to identify the problem before acting; if your own monitoring picks up a non-conformity, the clock starts immediately
- Speed is legally required — the word ‘immediately’ appears multiple times in this article; delayed action is not a defence
- Have a pre-defined incident response procedure in your quality management system that maps directly to this article — who is responsible, what the escalation path is, and which authorities to notify
- Your deployers are your partners in this process — maintain open communication channels with them so that issues can be identified and investigated quickly
- Document every step of your corrective action process — what you discovered, when you discovered it, what you did, and what you communicated to whom; this documentation is your protection in any regulatory investigation
Related Articles
- Article 16 — Provider obligations (corrective action is one of the twelve listed duties)
- Article 17 — Quality management system (incident response must be built into the QMS)
- Article 72 — Post-market monitoring (the mechanism through which non-compliance is typically discovered)
- Article 73 — Reporting of serious incidents (closely related notification obligation)
- Article 79 — Procedure for dealing with AI systems presenting a risk (the market surveillance framework this article feeds into)
