Direct answer
What does Article 78 of the AI Act say about confidentiality of what you submit to an authority?
Your question is about Article 78: confidentiality of what you submit to an authority. That obligation applies today. Whether your system actually falls under it depends on conditions you assess yourself.
You determine this yourself
- Applies to all information and data obtained by the Commission, the market surveillance authorities, the notified bodies and any other natural or legal person involved in the application of this Regulation in carrying out their tasks and activities. The protection operates in accordance with Union or national law and not on its own.
- Paragraph 2 limits what an authority may request: only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of its powers in accordance with this Regulation and with Regulation (EU) 2019/1020. Two follow-on duties attach to that: adequate and effective cybersecurity measures, and deletion as soon as the data is no longer needed for the purpose for which it was obtained.
- The protection of intellectual property, confidential business information and trade secrets, including source code, applies except in the cases referred to in Article 5 of Directive (EU) 2016/943. Point (a) of paragraph 1 says so in as many words.
- Paragraph 4 provides that paragraphs 1, 2 and 3 do not affect the rights or obligations of the Commission, the Member States and their relevant authorities, or those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor the obligations of the parties concerned to provide information under criminal law of the Member States. Confidentiality under this article is therefore not a duty of silence between authorities.
First step: Mark and register what you submit to an authority or body.
Article 78 of the AI Act covers confidentiality of what you submit to an authority. The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched. This provision concerns the deployer, the provider of a GPAI model and the provider of an AI system. This provision applies today.
This applies now
Your first actions
- Mark and register what you submit to an authority or body. State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).
Record this
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation