Skip to main content
Praxikon
All obligations
Upcomingv1.0.0

Article 21: cooperation with competent authorities

Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.

Paragraph 1 provides that providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned.

Praxikon tracks Article 21: cooperation with competent authorities under the EU AI Act, checked against the official source on 14 August 2026, citing the source for every statement.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
14 August 2026

Review status: placed against the official source (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Upcoming · 2 December 2027

For whom

  • Authorised representative
  • Deployer
  • Provider of an AI system

What you do

Make your conformity file deliverable on request

What you record

Response file for a request from a competent authority

Official source

Article 21(1)-(3)

Who this is relevant to

When this applies

  • Authorised representative

    The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act.
  2. 2For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case.
  3. 3What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side.

What the official source establishes

The surroundings of Article 21, verbatim. Article 22(3), point (c), requires the authorised representative to provide a competent authority, upon a reasoned request, with all the information and documentation necessary to demonstrate conformity with the requirements set out in Section 2, including access to the logs referred to in Article 12(1) to the extent such logs are under the control of the provider; the final subparagraph of that paragraph provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities. Article 19(1) provides that the provider keeps the logs under its control for a period appropriate to the intended purpose, of at least six months. Article 26(6) imposes the same period of at least six months on the deployer for the logs under its control. Article 99(5) subjects the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of total worldwide annual turnover for the preceding financial year, whichever is higher.

The surroundings as Regulation (EU) 2026/1744 left them. Article 1, point (34), amends Article 77. The heading now reads "Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities". Paragraph 1 now provides that national public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, have the power to request and access any information or documentation created or maintained pursuant to this Regulation from the relevant market surveillance authority, in accessible language and machine-readable format by electronic means, where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction, and that the Article is without prejudice to the competences, tasks, powers and independence of those authorities or bodies. The restriction to the systems listed in Annex III, the requirement of an accessible format and the after-the-fact notification of the market surveillance authority are gone. Inserted paragraph 1a provides that the market surveillance authority grants that access, including by requesting the information or documentation from the provider or the deployer where necessary and without undue delay. Inserted paragraph 1b requires market surveillance authorities and those authorities or bodies to cooperate closely and to provide each other with mutual assistance, including exchange of information. Article 99(4) still does not list Article 21 after the amendment: Article 1, point (38)(b), only inserts a point (da) there on the obligations of providers and operators pursuant to Article 25(2) and (4).

The timeline this object rests on is stated in so many words in the amended Regulation. Article 1, point (40)(b), replaces Article 113, third paragraph, point (c), so that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Article 1, point (39)(a), replaces Article 111(2), so that the grace period is tied to the date of application of Chapter III referred to in Article 113 and no longer to 2 August 2026, while retaining 2 August 2030 for systems intended to be used by public authorities. Article 1, point (2)(a), replaces Article 2(2), so that for systems classified as high-risk under Article 6(1) related to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 apply; Article 21 is not on that list. Article 1, point (41), deletes point 1 of Annex I, Section A, and adds Regulation (EU) 2023/1230 on machinery to Annex I, Section B.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

Most of what is requested here already exists under the Regulation: the technical documentation of Article 11, the logs of Articles 12 and 19, the quality management system of Article 17, the conformity file of Article 43. Two things are genuinely additional. Article 19 requires you to keep the logs; Article 21(2) requires you to give an authority access to them, which is a different act. And the language rule of paragraph 1 is additional, because you deliver in an official language of the institutions of the Union chosen by the Member State concerned, not in the language you find most convenient. There is nothing to agree there; find out which language the Member State concerned has indicated and budget translation capacity for a technical file. Three further things go wrong in practice. Your documentation exists but is spread across teams and systems, so assembling it takes weeks. Your documentation belongs to a different system version than the one the question is about, in which case you demonstrate the conformity of something else. And the logs are gone: Article 19(1) and Article 26(6) ask for at least six months, so a request arriving later can meet an empty drawer. A provider established in a third country should also expect the request to land with its authorised representative: Article 22(3), point (c), imposes nearly the same delivery on him and the mandate empowers him to be addressed in addition to or instead of the provider. Article 21 is not the only channel either, but that second channel now runs differently. Under amended Article 77(1) a fundamental rights body requests information or documentation from the relevant market surveillance authority rather than directly from you, in accessible language and machine-readable format, and the restriction to Annex III systems has gone. Under inserted paragraph 1a that market surveillance authority may then request the material from you or from the deployer without undue delay. So expect a fundamental rights question to reach you as a request from the market surveillance authority, in a format a machine can read, and with its own route to testing under Article 77(3). On paragraph 3, finally, no comfortable story: Article 78 protects what you hand over only in accordance with Union or national law, carves out the cases of Article 5 of Directive (EU) 2016/943 for trade secrets and source code, and in paragraph 4 leaves the exchange of information, the dissemination of warnings and information duties under national criminal law unaffected. It is a rule on handling, not a shield.

What you can do now

Treat this as a delivery exercise rather than a documentation question. Record per high-risk system where each part of the conformity file sits, which system version it belongs to and who can assemble it within an agreed period. Find out which official language of the institutions of the Union the Member State concerned has indicated, and plan translation capacity instead of a language agreement. Determine per customer contract whether the automatically generated logs are under your control or with the deployer, and check that your retention period reaches the six months of Article 19(1), because otherwise the question can no longer be answered after half a year. If you are established outside the Union, record that your authorised representative can deliver the same file, since under Article 22(3), point (c), he is addressed in addition to or instead of you. And let nobody improvise in the answer: supplying incorrect, incomplete or misleading information in reply to a request is a separate ground for a fine under Article 99(5), in a different band from the obligations that Article 99(4) does list.

  1. 01

    Make your conformity file deliverable on request

    Map per high-risk system where each part of the file sits, which system version it belongs to, who assembles it, how long the logs are kept and in which language indicated by the Member State concerned you can supply it, so that a reasoned request becomes a delivery task rather than a search.

What to retain

Response file for a request from a competent authority

Per request: which authority made it and on what legal basis, on what date, on what grounds the request was reasoned, which documents and which logs were supplied, which system version they belong to, in what language and when. This file shows you delivered fully and in time, also years later when the staff involved have left.

Control and reassessment

  • Intake and deadline tracking of a request from an authority

    The control that ensures an incoming request from a competent authority reaches an identifiable owner the same day, that the documents requested are matched to the right system version, and that delivery is complete within the period set by the authority.

Public tools

Conditions and exceptions

  • Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies "as applicable", and it applies "to the extent such logs are under their control". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6).

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 21(1)-(3)

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (39)(a), replacing Article 111(2)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 21: cooperation with competent authorities",
praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z,
sha256 559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3,
https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-21-cooperation-with-authorities&effective_at=2026-08-08&known_at=2026-08-14&lang=en, accessed 2026-09-15)

Short form

praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities@1.0.0 (sha256 55925009)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-21-cooperation-with-authorities-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 21: cooperation with competent authorities},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3},
  url          = {https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities},
  urldate      = {2026-09-15},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities@1.0.0",
    "type": "dataset",
    "title": "Article 21: cooperation with competent authorities",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          14
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          15
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-21-cooperation-with-authorities&effective_at=2026-08-08&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    8 August 2026

    Article 21: cooperation with competent authorities

    Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist

Help with implementation

Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.

View AI governance at Embed AI

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.