Skip to main content
Praxikon
Back to the explorer
ControlEditorialv1.0.0

Protection of the person reporting

The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.

The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map

Address and citation

This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.

Identifier
praxikon:eu:ai-act:control:reporting-person-protection
Payload hash (sha256)
0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2

Citation line

Praxikon, "Protection of the person reporting", praxikon:eu:ai-act:control:reporting-person-protection@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z, sha256 0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2
Version
1.0.0
Legal time (effective_at)
2 August 2026
Knowledge time (known_at)
14 August 2026
Closed on
Not closed
Topics
control, fundamental-rights

Review status: Editorially reviewed (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

What this object links to

Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.

The obligation this hangs off

1 of 1 shown

The object belongs to this obligation. The source line it hangs off sits there.

  1. Source

    This object carries no official fact of its own. The source line below sits on the obligation it hangs off; the link itself is recorded editorially.

    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 87

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What this object is about

2 of 2 shown

The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.

  1. Source

    This object carries no official fact of its own. The source line below sits on the obligation it hangs off; the link itself is recorded editorially.

    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 87

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    No condition or exception recorded on this object.

    Consequence

What points at this object

Where this control comes from

1 of 1 shown

This is what keeps compliance in place over time, periodic or event-driven.

  1. Source

    Official fact on this object, with its locator.

    • EU Artificial Intelligence Act 2024/1689

      Locator: Article 87

      praxikon:eu:ai-act:source:reg-eu-2024-1689

      Open official source

    Via

    • Condition | allThe trigger is a report of an infringement of this Regulation, whatever the risk class of the system: a report about an AI system outside the high-risk category is covered just as much. The protection itself is not unconditional. It comes from Directive (EU) 2019/1937, which in Article 4 requires the person reporting to have obtained the information in a work-related context, and in Article 6(1)(a) requires reasonable grounds to believe that what was reported was true and fell within the scope of that Directive.
    • ExceptionArticle 87 creates no channel requirement. That requirement comes from Article 8 of Directive (EU) 2019/1937. Paragraph 1 places it on legal entities in the private and the public sector; paragraph 3 limits paragraph 1 in the private sector to entities with 50 or more workers. That threshold is not general, however. Paragraph 4 provides that the threshold in paragraph 3 shall not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, following a risk assessment, to require entities with fewer than 50 workers as well. Paragraph 9 applies paragraph 1 to all legal entities in the public sector, with the option for a Member State to exempt municipalities under 10 000 inhabitants and other small public entities. Below fifty workers there is therefore not simply no channel requirement: it depends on the sector you fall in and on what your Member State has decided. The right to report and the protection of the person reporting exist in any event, through the external route of Article 10 of that Directive.
    • ExceptionThe material scope of Directive (EU) 2019/1937 runs through Article 2(1)(a), which refers to the Union acts listed in the Annex to that Directive. Regulation (EU) 2024/1689 was not added to that Annex: it makes the Directive applicable directly, in Article 87. National transposition law that ties its own scope to that same Annex, such as the Dutch Wet bescherming klokkenluiders, may therefore lag behind the Regulation. Whether a report about an AI system falls under national law as a result is not settled.

    As long as this exception is not ruled out, the outcome stays conditional and you have to establish it yourself.

    Relation recorded on: Article 87: reporting of infringements and protection of reporting persons

    Consequence

When this applies

No condition recorded on this object.

When this does not apply

No exception recorded on this object.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Protection of the person reporting",
praxikon:eu:ai-act:control:reporting-person-protection@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-08-02T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z,
sha256 0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2,
https://www.praxikon.com/en/verkenner/control/reporting-person-protection
(https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Acontrol%3Areporting-person-protection&effective_at=2026-08-02&known_at=2026-08-14&lang=en, accessed 2026-09-21)

Short form

praxikon:eu:ai-act:control:reporting-person-protection@1.0.0 (sha256 0a6eda3b)

BibTeX

@misc{praxikon-eu-ai-act-control-reporting-person-protection-1-0-0,
  author       = {{Praxikon}},
  title        = {Protection of the person reporting},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:control:reporting-person-protection},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-08-02T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2},
  url          = {https://www.praxikon.com/en/verkenner/control/reporting-person-protection},
  urldate      = {2026-09-21},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:control:reporting-person-protection@1.0.0",
    "type": "dataset",
    "title": "Protection of the person reporting",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:control:reporting-person-protection",
    "URL": "https://www.praxikon.com/en/verkenner/control/reporting-person-protection",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          14
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          21
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-02T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Acontrol%3Areporting-person-protection&effective_at=2026-08-02&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

For agents and integrations

This page and the machine output come from the same object and the same two time axes.