Articles 74-79 establish the market surveillance framework for the EU AI Act, largely building on Regulation 2019/1020 on market surveillance and compliance of products. NCAs are empowered to access systems, request documentation, and take corrective actions.
- NCAs may request AI system documentation, source code, and training data from providers
- NCAs may conduct on-site inspections of provider premises and infrastructure
- If a serious risk is identified, NCAs may require withdrawal or recall of an AI system
- The RAPEX (rapid alert system) mechanism applies to high-risk AI systems presenting serious risks
- Market surveillance findings must be reported to the Commission and other Member States