Art.78
EU AI Act Guide › Chapter IX — Post-Market Monitoring › Article 78

Article 78 – Confidentiality

Governance SME Relevant ~2 min read · 471 words

Article 78 protects confidential business information shared with authorities during AI Act compliance and enforcement activities. When providers share technical documentation, source code, training data or trade secrets with market surveillance authorities, notified bodies or the AI Office, those recipients are bound by strict confidentiality obligations. This is the provision that makes it safe to cooperate with authorities.

⚠ Medium compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Protection of business secrets shared during enforcement

Article 78 establishes confidentiality obligations for all parties who receive confidential information in the course of AI Act activities — including national authorities, the AI Office, notified bodies, and the AI Board. It ensures that the sensitive technical and commercial information businesses share during compliance assessments and investigations is protected from disclosure.

WHAT IT SAYS

Binding confidentiality obligations on all recipients of sensitive information

  • All parties receiving information in the course of AI Act activities — authorities, notified bodies, the AI Office, the AI Board, the Advisory Forum and the Scientific Panel — must treat it as confidential
  • Confidential information includes business secrets, personal data, source code, training data, technical documentation, and any other commercially sensitive material
  • Confidentiality obligations apply even after the person’s employment or other relationship with the receiving body ends
  • Information that is confidential may not be disclosed to third parties without the consent of the party that provided it — with limited exceptions for public interest
  • The confidentiality obligation does not prevent information sharing between competent authorities within the EU where necessary for enforcement
  • Market surveillance reports and decisions that are communicated to operators must not include confidential information unless disclosure is necessary
  • Violations of confidentiality obligations may result in liability

WHO IS AFFECTED

All parties who receive information in AI Act proceedings

  • National competent authorities — market surveillance authorities and notifying authorities
  • The AI Office and the AI Board
  • Notified bodies who receive technical documentation and source code during conformity assessments
  • Members of the Advisory Forum and Scientific Panel
  • Providers and deployers who receive information through inter-authority cooperation
  • Any third parties who receive information through official AI Act processes

WHAT IT MEANS FOR SMES

You can share sensitive information with authorities safely

  • This article removes a significant practical barrier to cooperation: providers can share source code, training data, proprietary algorithms and business-sensitive technical documentation with authorities without fear that it will be disclosed to competitors or the public
  • The confidentiality protection applies to notified bodies too — your technical documentation shared during conformity assessment is protected
  • If an authority requests your documentation under Article 21 or Article 74, complying fully is both legally required and legally safe from a confidentiality perspective
  • Keep a record of what confidential information you have shared with which authorities and when — if confidentiality is ever breached, this documentation supports any claim
  • Note that confidentiality does not prevent information sharing between EU authorities for enforcement purposes — information you share with one national authority may be shared with another in the context of a cross-border investigation

Related Articles

← Previous Art. 77 — Powers of Authorities Protecting Fundamental Rights Next → Art. 79 — Procedure at National Level for Dealing with AI Systems Presenting a Risk