{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":1,"filters":{"id":"praxikon:eu:ai-act:obligation:article-20-corrective-actions","type":"obligation","role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":"praxikon:eu:ai-act:obligation:article-20-corrective-actions","role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:obligation:article-20-corrective-actions","legacy_id":"raip:obligation:article-20-corrective-actions","type":"obligation","slug":"article-20-corrective-actions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3da4413e7f76d6cd26cf52cc894dc8b6637916ab4ed1d39776d4446a96c5232c","label":"Article 20: corrective actions and duty of information","summary":"A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.","topics":["high-risk-requirements","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-corrective-action-procedure"],"evidence_ids":["praxikon:eu:ai-act:evidence:corrective-action-record"],"control_ids":["praxikon:eu:ai-act:control:non-conformity-escalation-gate"],"template_ids":["praxikon:eu:ai-act:template:article-20-legal-text"],"conditions":[{"id":"article-20-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as they consider, or have reason to consider, that a system they have placed on the market or put into service is not in conformity with this Regulation. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028."},{"id":"article-20-risk-trigger","operator":"any","description":"The second layer in paragraph 2 is added only where the system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk. The investigation of causes and the duty to inform the market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44, then come on top of the corrective actions under paragraph 1."},{"id":"article-20-article-25-1-becoming-provider","operator":"any","description":"The distributor, the importer and the deployer appear here as affected parties, but that is not their only possible position. Anyone who puts their name or trade mark on a high-risk system already placed on the market, who substantially modifies such a system, or who changes the intended purpose of a system not classified as high-risk so that it becomes high-risk, is considered a provider under Article 25(1) and is subject to the obligations of Article 16. Point (j) of that Article routes straight to Article 20, so this provision then becomes a duty of their own rather than a notification arriving from someone else. In the trade mark case this applies without prejudice to contractual arrangements allocating the obligations otherwise."}],"exceptions":[{"id":"article-20-legacy-systems-article-111-2","operator":"not","description":"Article 20 is by definition about systems already placed on the market or put into service, and that is exactly the group covered by the transitional rule of Article 111(2). That provision was replaced by Article 1, point (39)(a), of Regulation (EU) 2026/1744 and now reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation applies to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The cut-off is therefore no longer a fixed date in paragraph 2: the date of 2 August 2026 that stood there until that amendment has been removed, and the amended paragraph names no date of its own. The carve-out in paragraph 1 covers systems that are components of the large-scale IT systems listed in Annex X; paragraph 1 was not amended and keeps a cut-off of its own. For systems intended to be used by public authorities the reprieve in paragraph 2 does not hold: there, compliance with the requirements and obligations is due by 2 August 2030 in any event. Which date of application of Chapter III is the cut-off is an open point: the object on Article 111 reads it as route dependent, so 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route, and marks that reading expressly as preliminary. That question is carried there, not here."}],"statements":[{"kind":"official_fact","text":"Paragraph 1. Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly. Paragraph 2. Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), of Regulation (EU) 2026/1744, replacing Article 113, third paragraph, point (c), of Regulation (EU) 2024/1689","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This provision is rarely read as a procedure, and that is exactly where it goes wrong. Article 20 places four measures side by side that differ sharply in practice, and those four are not legally equivalent. Recall and withdrawal are defined in Article 3(16) and (17), and the knowledge base carries those terms separately; the difference between them is the point in the chain. Bringing a system into conformity is the patch. Disabling is the odd one out: it is practically the heaviest switch, because it stops a customer who is running the system, and it is at the same time the only one of the four the Regulation nowhere defines. Anyone who copies that word into a contract or procedure without deciding for themselves what it means leaves the heaviest measure the vaguest. The second half is the notification, and in practice that is what fails most often. Paragraph 1 asks you to reach your distributors and, where applicable, your deployers, authorised representatives and importers, which is only possible if you hold a current list of who runs the system in which version and through which contact you reach them. That list is not a by-product of your CRM: resale, white labelling and integration mean you have customers you do not know.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 and Article 73 are often built as a single reporting channel, and that goes wrong in two ways. The trigger differs: Article 73 concerns a serious incident that has occurred, Article 20(2) a risk within the meaning of Article 79(1), that is, a risk to the health, safety or fundamental rights of persons. That is not a tidy split between past and future: a serious incident that has occurred usually also means the system presents a risk, so in practice both provisions often fire at the same time. Nor do the recipients differ entirely, because both routes run to market surveillance authorities. The difference sits in the detail: Article 73(1) points to the authorities of the Member States where the incident occurred, Article 20(2) to the authorities competent for the system concerned, and only Article 20(2) adds the notified body that issued a certificate under Article 44. Only Article 73, moreover, sets hard deadlines. So build one internal process with two exits, not two separate channels and not one channel that forgets the notified body.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two things within this duty are unsettled. First, what \"immediately\" requires: Article 20 sets no period. The closest anchor in the Regulation is Article 73(2), which ties \"immediately\" to the moment the provider has established a causal link between the system and the incident, or the reasonable likelihood of such a link, with an outer limit of fifteen days after becoming aware. We read Article 20 in that light: act once the signal is confirmed, and not only after a full internal investigation has been completed, because paragraph 2 places the investigation of causes alongside the measures rather than before them. A defensible alternative reading is that a provider first has reasonable time to verify and that \"immediately\" only starts running once the non-conformity is established. Second, the threshold \"reason to consider\": it is nowhere settled whether a complaint from a deployer, a deviating test result or a signal from the post-market monitoring of Article 72 already meets it. Whoever records that themselves can later demonstrate the moment of becoming aware; whoever does not has to reconstruct it after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Write out the four measures in paragraph 1 as four concrete scenarios with an owner, a decision maker and a lead time, and decide for yourself what disabling means in your system, because the Regulation does not define that term. Test at least once whether you can actually disable or recall a system without needing a fresh decision to do so. Also keep a record, per system version, of who runs it and through which contact you reach that party, and record which signal meets the \"reason to consider\" threshold in your organisation, so that the moment of becoming aware is demonstrable rather than something reconstructed after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-20-corrective-actions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"}]},"links":{"self":"https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-20-corrective-actions&lang=en","alternate":"https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-20-corrective-actions&lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}