WHAT THE ARTICLE IS ABOUT
The legal duty to work with regulators
Article 21 formalises the relationship between providers of high-risk AI systems and the national competent authorities responsible for enforcing the AI Act. It establishes that cooperation is not optional — providers have a legal duty to provide information, grant access, and assist authorities in any action they take in relation to the provider’s AI system.
WHAT IT SAYS
Provide information, grant access, assist investigations
- Providers of high-risk AI systems must cooperate with the national competent authorities in any action those authorities take in relation to the high-risk AI system
- Upon a reasoned request from a national competent authority, providers must provide all information and documentation necessary to demonstrate the conformity of the AI system with the Act’s requirements
- The information must be provided in a language that is easily understood by the authority making the request — typically the language of the member state concerned
- Providers must also grant access to the automatically generated logs referred to in Article 12, where relevant to the authority’s investigation
- Where a provider has appointed an authorised representative, the representative may fulfil these cooperation obligations on the provider’s behalf
WHO IS AFFECTED
All high-risk AI providers — including those based outside the EU
- All providers of high-risk AI systems operating in the EU — regardless of where they are established
- Non-EU providers must either cooperate directly with EU authorities or through their appointed authorised representative under Article 22
- Authorised representatives acting on behalf of non-EU providers — they carry the cooperation obligations on behalf of the provider
- Legal and compliance teams responsible for regulatory affairs and authority liaison
WHAT IT MEANS FOR SMES
Be prepared — and be transparent
- A request from a competent authority is not the beginning of a problem — it is a normal part of market surveillance and does not automatically mean you are suspected of non-compliance
- The best preparation is having your documentation in order before any request arrives — a provider who can immediately produce well-organised technical documentation and QMS records signals competence and good faith to regulators
- Designate a person within your organisation as the regulatory liaison responsible for handling authority requests — do not leave this to chance
- If you are a non-EU provider: appoint an authorised representative under Article 22 before you place your system on the EU market — attempting to cooperate with EU authorities from outside the EU without a representative creates significant practical and legal difficulties
- Non-cooperation or obstruction is treated as a compliance failure in its own right and can trigger sanctions under Article 99 — transparency is always the right strategy
Download your free AI Act Compliance Tracker for SMEs.
See the AI Act Compliance Tracker for SMEs here to learn what it does.
Related Articles
- Article 16 — Provider obligations (cooperation is one of the twelve listed duties)
- Article 22 — Authorised representatives (the mechanism for non-EU provider cooperation)
- Article 74 — Market surveillance (the framework within which authority requests are made)
- Article 78 — Confidentiality (protects commercially sensitive information disclosed to authorities)
- Article 99 — Penalties (sanctions for non-cooperation)
