Art.21
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 21

Article 21 — Cooperation with Competent Authorities

High-Risk Systems SME Relevant ~2 min read · 498 words

Article 21 establishes the provider’s duty to cooperate with national competent authorities. It is short and direct: when a regulator asks for information or requests access to your AI system, you must comply. Obstruction or non-cooperation is itself a compliance failure under the Act.

⚠ Medium compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

The legal duty to work with regulators

Article 21 formalises the relationship between providers of high-risk AI systems and the national competent authorities responsible for enforcing the AI Act. It establishes that cooperation is not optional — providers have a legal duty to provide information, grant access, and assist authorities in any action they take in relation to the provider’s AI system.

WHAT IT SAYS

Provide information, grant access, assist investigations

  • Providers of high-risk AI systems must cooperate with the national competent authorities in any action those authorities take in relation to the high-risk AI system
  • Upon a reasoned request from a national competent authority, providers must provide all information and documentation necessary to demonstrate the conformity of the AI system with the Act’s requirements
  • The information must be provided in a language that is easily understood by the authority making the request — typically the language of the member state concerned
  • Providers must also grant access to the automatically generated logs referred to in Article 12, where relevant to the authority’s investigation
  • Where a provider has appointed an authorised representative, the representative may fulfil these cooperation obligations on the provider’s behalf

WHO IS AFFECTED

All high-risk AI providers — including those based outside the EU

  • All providers of high-risk AI systems operating in the EU — regardless of where they are established
  • Non-EU providers must either cooperate directly with EU authorities or through their appointed authorised representative under Article 22
  • Authorised representatives acting on behalf of non-EU providers — they carry the cooperation obligations on behalf of the provider
  • Legal and compliance teams responsible for regulatory affairs and authority liaison

WHAT IT MEANS FOR SMES

Be prepared — and be transparent

  • A request from a competent authority is not the beginning of a problem — it is a normal part of market surveillance and does not automatically mean you are suspected of non-compliance
  • The best preparation is having your documentation in order before any request arrives — a provider who can immediately produce well-organised technical documentation and QMS records signals competence and good faith to regulators
  • Designate a person within your organisation as the regulatory liaison responsible for handling authority requests — do not leave this to chance
  • If you are a non-EU provider: appoint an authorised representative under Article 22 before you place your system on the EU market — attempting to cooperate with EU authorities from outside the EU without a representative creates significant practical and legal difficulties
  • Non-cooperation or obstruction is treated as a compliance failure in its own right and can trigger sanctions under Article 99 — transparency is always the right strategy

Download your free AI Act Compliance Tracker for SMEs.
See the AI Act Compliance Tracker for SMEs here to learn what it does.

Related Articles

← Previous Art. 20 — Corrective Actions and Duty of Information Next → Art. 22 — Authorised Representatives of Providers of High-Risk AI Systems