The Week in One Line
Last week we covered who supervises you. This week: what they can ask for, what they cannot, and why the answer to a request for information is mostly a document you were already supposed to have.
What the Act Actually Says
A request has to be reasoned, and it has to tell you things. Article 21 obliges providers of high-risk AI systems to respond to a reasoned request — not to any informal enquiry. For general-purpose AI models, Article 91(4) goes further: the request must state its legal basis and purpose, specify what is required, set a period for providing it, and state the fines for supplying incorrect, incomplete or misleading information. Article 91(2) also lets the AI Office open a structured dialogue first.
What they can ask for comes in three tiers, and they are not equally easy to reach.
- Documentation and data — easiest. Article 74(12) grants market surveillance authorities full access to your documentation and to the training, validation and testing data sets used to develop a high-risk system, limited to what is necessary. The Act expressly contemplates this happening through an API or other remote access.
- Logs — bounded by control. Article 21(2) gives access to the automatically generated logs under Article 12(1), but only to the extent those logs are under your control.
- Source code — hardest. Article 74(13) requires a reasoned request and both conditions together: access must be necessary to assess conformity, and testing based on the data and documentation you already provided must have been exhausted or proved insufficient.
There are real protections, worth knowing by number. Article 78(1)(a) names intellectual property, confidential business information and trade secrets — including source code — as protected. Article 78(2) says authorities shall request only data that is strictly necessary, must secure it, and must delete it once no longer needed.
The language rule nobody plans for. Article 21(1) requires the information in a language easily understood by the authority, in one of the official EU languages as indicated by the Member State concerned. If your architecture documentation exists only in English and your supervisor has nominated its own language, that is a translation project sitting inside a deadline.
One thing the Act does not give you. No general fixed response deadline for high-risk documentation requests is written into the Regulation. Article 91(4) requires the Commission to set a period in its GPAI requests; otherwise the timeframe comes from the request itself and national procedure. Anyone quoting a standard number of days is going beyond the text.
Your lawyer can send it. You still own it. Article 91(5) is blunt: duly authorised lawyers may supply information for clients, and the clients nevertheless remain fully responsible if it is incomplete, incorrect or misleading.
A scope note, because most commentary blurs it. Articles 21 and 74(12)–(13) are written for high-risk systems, so if you run a chatbot under Article 50 that documentation duty does not apply to you. But Article 74(1) applies Regulation (EU) 2019/1020 to all AI systems in scope, so general market surveillance powers still reach you.
Sources: AI Act Article 21, 74, 78, 91, 12 and Annex IV, via the Commission's AI Act Service Desk.
What This Means for Your Business
The documentation is the answer. Annex IV is, in practice, the question list: intended purpose and versions, system architecture, design choices and what the system optimises for, data provenance and labelling, human oversight, validation and testing with dated and signed test logs, cybersecurity measures, known limitations, and the post-market monitoring plan. If that exists and is current, an information request is an export. If not, the request becomes the deadline by which you write it.
Logs you do not control are a contract problem, not a technical one. Article 21(2) limits the duty to logs under your control — which quietly means that if your model runs on someone else's infrastructure, your ability to answer depends on a clause somebody negotiated. Worth checking before it matters.
Article 78(2) is yours to invoke. Strictly necessary, secured, deleted when no longer needed. That is not licence to be obstructive — pushing back badly is worse than answering. But a proportionate reply that cites the limits is a stronger position than either silence or handing over everything.
One point in your favour: Article 11(1) lets SMEs and start-ups provide Annex IV documentation in simplified form, and notified bodies must accept it.
This Week's Action Point
Run a dry run. Pick your most exposed AI system, give one named person three working days, and ask for a single response pack containing:
- What the system does, which versions are live, and where it runs
- The architecture description and the design choices behind it
- Data sources, provenance and labelling procedures
- Validation and test results, dated and attributable
- Human oversight measures and known limitations
- Logs for a defined period, and confirmation of who controls them
Then look at what is missing, what is stale, and what only one person knew. That gap list is the real output, and cheaper to find now than under someone else's deadline.
I have turned the Annex IV headings into a one-page template — The Information Request Response Pack — with the confidentiality provisions you can point to and the three access tiers in plain language. Linked in the comments of today's post. Free, no sign-up.
Further Reading
- Article 21 — cooperation, including the language rule
- Article 74 — market surveillance, source code in 74(13)
- Article 78 — confidentiality and data minimisation
- Annex IV — full technical documentation contents
- Enforcement framework — European Commission
One question I would like your answer to: if a reasoned request landed on your desk on Monday, which of those six items would you struggle with most? My guess is the dated test results, but I would rather know than guess. Reply or leave it in the comments. I read every one.
Next Tuesday
Annex IV in practice: what "a detailed description of the system architecture" means when the honest answer is a diagram nobody updated since the pilot.
Matúš Paško — I design enterprise AI systems that have to run in production under real compliance and reliability constraints. If the dry run turns up more gaps than you expected, my calendar link is in my profile, and a short call is usually enough to tell you whether it is an afternoon of tidying or a real project.
#EUAIAct #AIGovernance #AICompliance #AnnexIV #EnterpriseAI