WHAT THE ARTICLE IS ABOUT
Connecting AI enforcement to fundamental rights protection bodies
Article 77 creates a coordination bridge between market surveillance authorities and the broader network of public bodies responsible for protecting fundamental rights in each member state. It recognises that high-risk AI systems — particularly in areas like employment, credit, education and law enforcement — can affect rights that are overseen by specialised authorities beyond the product safety regulator.
WHAT IT SAYS
MSAs must inform and cooperate with fundamental rights bodies
- Market surveillance authorities must cooperate with national public authorities and bodies responsible for the supervision and enforcement of fundamental rights law — including data protection authorities, equality bodies, consumer protection authorities and others
- Where a market surveillance authority finds that an AI system may infringe fundamental rights, it must notify the relevant national body and share relevant information
- National public authorities responsible for fundamental rights must have the power to request information from market surveillance authorities on AI systems relevant to their mandate
- The cooperation obligation is mutual — fundamental rights bodies may alert market surveillance authorities to potential AI Act violations they discover in the course of their own work
- The GDPR supervisory authorities (data protection authorities) are explicitly part of this network
- Member states must designate which national bodies fall within the scope of this cooperation obligation
WHO IS AFFECTED
Market surveillance authorities, data protection bodies, and equality authorities
- Market surveillance authorities — must cooperate and share information
- Data protection authorities — have both a cooperation obligation and rights to request AI information
- Equality bodies and anti-discrimination authorities — relevant for AI systems in employment, credit and education
- Consumer protection authorities — relevant for AI systems in essential services
- Providers whose systems may be subject to scrutiny by multiple types of authority simultaneously
WHAT IT MEANS FOR SMES
AI Act compliance is not separate from data protection and equality law
- The most practical implication: if your AI system is being investigated by a data protection authority for GDPR issues, that authority may share information with the market surveillance authority investigating AI Act compliance — and vice versa
- Non-compliance in one regulatory domain can trigger scrutiny in another — treat GDPR, equality law and AI Act compliance as an integrated package rather than separate issues
- Employment AI systems are particularly exposed: they sit at the intersection of AI Act obligations, GDPR, equality law and labour law — all of which can converge on the same system
- Document how your AI system addresses fundamental rights impacts — this documentation serves both the AI Act (Article 27 FRIA for deployers) and the various authorities that may request it under this article
Related Articles
- Article 27 — Fundamental rights impact assessment (the deployer-side obligation that complements this article)
- Article 74 — Market surveillance (the framework within which this cooperation operates)
- Article 10 — Data governance (data protection issues relevant to this cooperation)
- Article 70 — National competent authorities (the bodies involved in this cooperation network)
