Skip to main content
Praxikon
All obligations
Applicablev1.0.0

Article 87: reporting of infringements and protection of reporting persons

The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.

Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.

Praxikon tracks Article 87: reporting of infringements and protection of reporting persons under the EU AI Act, checked against the official source on 14 August 2026, citing the source for every statement.

Status
Applicable
Application date
2 August 2026
Version
1.0.0
Last reviewed
14 August 2026

Review status: placed against the official source (14 August 2026). Next check due by 10 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Applicable · 2 August 2026

For whom

  • Deployer
  • Provider of an AI system

What you do

Make sure a report about an AI system reaches your reporting channel

What you record

File of reports about AI systems

Official source

Article 87

Who this is relevant to

When this applies

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1The trigger is a report of an infringement of this Regulation, whatever the risk class of the system: a report about an AI system outside the high-risk category is covered just as much. The protection itself is not unconditional. It comes from Directive (EU) 2019/1937, which in Article 4 requires the person reporting to have obtained the information in a work-related context, and in Article 6(1)(a) requires reasonable grounds to believe that what was reported was true and fell within the scope of that Directive.

What the official source establishes

Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

This article is short because the work was done elsewhere, and that is exactly why it gets overlooked. Its practical meaning lies in the direction of travel: Articles 85 and 86 concern who knocks on your door from outside, Article 87 concerns who steps out from within. That is almost always the first person to notice something. The developer who knows the logging has not run for months, the recruiter who sees the selection model filtering out candidates on something that should never have been in it: they hold the facts a regulator only obtains after an investigation. Three things follow. If you must already have a reporting channel, that channel must be able to receive such a report and recognise it as touching the AI Regulation, because a report handled as a general complaint disappears into a different process. Whether you must have that channel is not a matter of a single number. Article 8(3) of Directive (EU) 2019/1937 imposes the channel requirement in the private sector at fifty or more workers, but paragraph 4 sets that threshold aside for entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, after a risk assessment, to require smaller entities as well, and paragraph 9 imposes the requirement on all legal entities in the public sector, with an optional exemption a Member State may make for municipalities with fewer than ten thousand inhabitants or fewer than fifty workers, and for other public entities with fewer than fifty workers. Below fifty workers the question is therefore which sector you are in and what your Member State has decided, not whether you clear the threshold. If you are genuinely outside each of those cases the channel need not exist, and even then the person reporting has somewhere to go: Article 10 of that Directive gives them an external route to the competent authority without having to report internally first, and Article 15 permits public disclosure under conditions. And the protection is not a formality, but it is not enforced through this Regulation: Article 19 of the Directive prohibits retaliation and Article 21 sets out the protective measures, and enforcement runs through national whistleblower law, in the Netherlands through the Huis voor Klokkenluiders and the civil courts. Article 99 of this Regulation does not list Article 87 among the fineable infringements; there is therefore no AI Act fine for disadvantaging a person who reported. Note too that the report here does not depend on a decision or on harm, whereas the right to an explanation in Article 86 does.

What you can do now

First determine whether Directive (EU) 2019/1937 and national transposition law apply to you at all: below fifty workers there is in principle no channel requirement, in which case this object is not a set-up question for you. If you are covered, check whether your existing reporting channel recognises a report about an AI system and whether whoever receives it knows the AI Regulation may be engaged. Record per report what was reported, about which system, what was done with it and when feedback was given, and measure that against the deadlines in Article 9(1) of that Directive: acknowledgement of receipt within seven days under point (b), feedback within three months under point (f). Keep the identity of the person reporting out of what goes to line managers (Article 16), retain no longer than necessary and proportionate (Article 18(1)), and record an oral report only with consent (Article 18(2) to (4)). Also decide whether you will handle anonymous reports: Article 6(2) leaves that choice to the Member State, so check what your national law says. Finally, put to your lawyer the question whether your national whistleblower act already covers AI Act infringements, because such an act usually ties its scope to the Annex to the Directive and Regulation (EU) 2024/1689 is not listed there.

  1. 01

    Make sure a report about an AI system reaches your reporting channel

    Only for organisations that must already have a reporting arrangement. Make visible in it that an infringement of the AI Regulation is a reportable infringement, designate who receives such a report, agree how the identity of the person reporting stays out of the rest of the process, and record whether you handle anonymous reports.

What to retain

File of reports about AI systems

Per report: what was reported, about which system and which version, what was done with it, when feedback was given and who handled it. The deadlines against which that is measured sit in Article 9(1) of Directive (EU) 2019/1937: acknowledgement of receipt within seven days (point (b)) and feedback within three months (point (f)). This file has limits that are as hard as the record keeping itself: the identity of the person reporting stays shielded and does not travel with the substantive follow-up (Article 16), nothing is retained longer than necessary and proportionate (Article 18(1)), and an oral report is recorded only with the consent of the person reporting (Article 18(2) to (4)). Without those limits the file is itself a risk, including under the GDPR.

Control and reassessment

  • Protection of the person reporting

    The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.

Public tools

  • Full text of Article 87

    The full legal text in the public AI Act Explorer.

Conditions and exceptions

  • Article 87 creates no channel requirement. That requirement comes from Article 8 of Directive (EU) 2019/1937. Paragraph 1 places it on legal entities in the private and the public sector; paragraph 3 limits paragraph 1 in the private sector to entities with 50 or more workers. That threshold is not general, however. Paragraph 4 provides that the threshold in paragraph 3 shall not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, following a risk assessment, to require entities with fewer than 50 workers as well. Paragraph 9 applies paragraph 1 to all legal entities in the public sector, with the option for a Member State to exempt municipalities under 10 000 inhabitants and other small public entities. Below fifty workers there is therefore not simply no channel requirement: it depends on the sector you fall in and on what your Member State has decided. The right to report and the protection of the person reporting exist in any event, through the external route of Article 10 of that Directive.
  • The material scope of Directive (EU) 2019/1937 runs through Article 2(1)(a), which refers to the Union acts listed in the Annex to that Directive. Regulation (EU) 2024/1689 was not added to that Annex: it makes the Directive applicable directly, in Article 87. National transposition law that ties its own scope to that same Annex, such as the Dutch Wet bescherming klokkenluiders, may therefore lag behind the Regulation. Whether a report about an AI system falls under national law as a result is not settled.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 87

  • Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law

    European Parliament and Council | original-oj-2019-11-26

    Source locator: Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)

  • Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law

    European Parliament and Council | original-oj-2019-11-26

    Source locator: Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 87: reporting of infringements and protection of reporting persons",
praxikon:eu:ai-act:obligation:article-87-reporting-infringements@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-08-02T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z,
sha256 57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6,
https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-87-reporting-infringements&effective_at=2026-08-02&known_at=2026-08-14&lang=en, accessed 2026-09-15)

Short form

praxikon:eu:ai-act:obligation:article-87-reporting-infringements@1.0.0 (sha256 57d296c3)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-87-reporting-infringements-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 87: reporting of infringements and protection of reporting persons},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-87-reporting-infringements},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-08-02T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6},
  url          = {https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements},
  urldate      = {2026-09-15},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-87-reporting-infringements@1.0.0",
    "type": "dataset",
    "title": "Article 87: reporting of infringements and protection of reporting persons",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-87-reporting-infringements",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          14
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          15
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-02T00:00:00.000Z; known_at 2026-08-14T00:00:00.000Z; sha256 57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-87-reporting-infringements&effective_at=2026-08-02&known_at=2026-08-14&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    2 August 2026

    Article 87: reporting of infringements and protection of reporting persons

    The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist

Help with implementation

Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.

View AI governance at Embed AI

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.