WHAT THE ARTICLE IS ABOUT
Whistleblower protections and infringement reporting channels
Article 87 establishes the framework for reporting AI Act violations and protecting those who report them. It extends the protections of the EU Whistleblower Protection Directive (Directive (EU) 2019/1937) to AI Act infringement reporting, ensuring that employees, contractors, and others who report suspected violations are protected from dismissal, demotion and other forms of retaliation.
WHAT IT SAYS
Protected reporting channels and retaliation protection
- Member states must ensure that there are effective mechanisms for persons to report potential or actual infringements of the AI Act to competent authorities
- Persons who report infringements in good faith must be protected from retaliation in accordance with the EU Whistleblower Protection Directive
- The protection applies to employees, self-employed persons, shareholders, members of administrative and supervisory bodies, volunteers, paid or unpaid trainees, and contractors — anyone in a work-related context who becomes aware of an infringement
- Protected persons must not face dismissal, demotion, salary reduction, change of duties, negative performance assessment, or any other detriment as a result of reporting
- Reports may be made to competent national authorities or directly to the AI Office for GPAI-related matters
- Anonymous reporting must be facilitated where national law permits it
- False reports made in bad faith are not protected — the good faith requirement is a meaningful condition
WHO IS AFFECTED
Employees, contractors and others in work-related contexts
- Employees of AI providers and deployers who become aware of AI Act violations
- Contractors, consultants and third-party workers with access to AI systems
- Members of management and supervisory boards who discover violations
- Regulators and market surveillance authorities who receive reports
- Providers and deployers who must ensure they do not retaliate against reporters
WHAT IT MEANS FOR SMES
Both a risk and an obligation — create a safe internal reporting culture
- As an employer: establish internal reporting channels so that employees who have concerns about AI Act compliance can raise them internally before going to authorities — this gives you the opportunity to correct issues voluntarily
- Never retaliate against an employee who raises AI compliance concerns — the Whistleblower Directive protections apply and retaliation creates separate legal liability
- As a smaller business, informal cultures can create implicit pressure not to raise concerns — be explicit that AI compliance reporting is welcome and protected
- From a risk perspective: an employee or contractor who observes a compliance issue and is not able to raise it internally is more likely to go directly to a market surveillance authority — effective internal reporting channels reduce external enforcement risk
- If you become aware that a vendor or partner is violating the AI Act, you may report this without retaliation — this applies to B2B relationships as well as employment relationships
Related Articles
- Article 85 — Right to lodge a complaint (the formal complaint right — distinct from whistleblowing)
- Article 74 — Market surveillance (the authority that receives infringement reports)
- Article 88 — GPAI enforcement (the AI Office receives GPAI infringement reports)
- Article 99 — Penalties (the consequences for the violations that whistleblowers may report)
