WHAT THE ARTICLE IS ABOUT
Protection of business secrets shared during enforcement
Article 78 establishes confidentiality obligations for all parties who receive confidential information in the course of AI Act activities — including national authorities, the AI Office, notified bodies, and the AI Board. It ensures that the sensitive technical and commercial information businesses share during compliance assessments and investigations is protected from disclosure.
WHAT IT SAYS
Binding confidentiality obligations on all recipients of sensitive information
- All parties receiving information in the course of AI Act activities — authorities, notified bodies, the AI Office, the AI Board, the Advisory Forum and the Scientific Panel — must treat it as confidential
- Confidential information includes business secrets, personal data, source code, training data, technical documentation, and any other commercially sensitive material
- Confidentiality obligations apply even after the person’s employment or other relationship with the receiving body ends
- Information that is confidential may not be disclosed to third parties without the consent of the party that provided it — with limited exceptions for public interest
- The confidentiality obligation does not prevent information sharing between competent authorities within the EU where necessary for enforcement
- Market surveillance reports and decisions that are communicated to operators must not include confidential information unless disclosure is necessary
- Violations of confidentiality obligations may result in liability
WHO IS AFFECTED
All parties who receive information in AI Act proceedings
- National competent authorities — market surveillance authorities and notifying authorities
- The AI Office and the AI Board
- Notified bodies who receive technical documentation and source code during conformity assessments
- Members of the Advisory Forum and Scientific Panel
- Providers and deployers who receive information through inter-authority cooperation
- Any third parties who receive information through official AI Act processes
WHAT IT MEANS FOR SMES
You can share sensitive information with authorities safely
- This article removes a significant practical barrier to cooperation: providers can share source code, training data, proprietary algorithms and business-sensitive technical documentation with authorities without fear that it will be disclosed to competitors or the public
- The confidentiality protection applies to notified bodies too — your technical documentation shared during conformity assessment is protected
- If an authority requests your documentation under Article 21 or Article 74, complying fully is both legally required and legally safe from a confidentiality perspective
- Keep a record of what confidential information you have shared with which authorities and when — if confidentiality is ever breached, this documentation supports any claim
- Note that confidentiality does not prevent information sharing between EU authorities for enforcement purposes — information you share with one national authority may be shared with another in the context of a cross-border investigation
Related Articles
- Article 21 — Cooperation with competent authorities (the obligation to share information that this article protects)
- Article 74 — Market surveillance (authorities receive confidential information in investigations)
- Article 44 — Certificates (notified bodies receive confidential technical documentation)
- Article 45 — Information obligations of notified bodies (subject to this confidentiality framework)
