AIPolicyTracker
Legal requirement Incident reporting and handling European Union Partially applicable

Providers must take corrective action and inform the supply chain about non-conforming high-risk AI

Context fileUnder EU AI Act, Article 20

Source-linked Open official source

What does it require?

A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, withdraw it, disable it or recall it as appropriate, and inform the distributors, deployers, authorised representative and importers. Where the system presents a risk to health, safety or fundamental rights and the provider becomes aware of that risk, it must immediately investigate the causes together with the reporting deployer and inform the market surveillance authorities and, where relevant, the notified body.

Practical action

Add a non-conformity and recall procedure for AI products with a supply-chain notification list and an authority-notification step.

Who does it apply to?

Providers of high-risk AI systems already on the market or in service.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessIncident coordinator · continuous
    AI incident management and regulatory reporting

    Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority

    Investigation, corrective action and notification of authorities and the supply chain.

  • supportsProcessRelease manager · at launch and on material change
    Model release and change-management gate

    Serves 5 recorded duties · evidence: Release or change approval record, Release and change-classification procedure

    Withdrawal, disabling and re-release pass through the gate.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Corrective action and recall procedure for AI systemsdocument
Non-conformity investigation recordrecordRoot cause, action taken, parties notified and dates.

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 10.2; Annex A.8.4Nonconformity and corrective action; communication of incidents.high
NIST AI RMF 1.0MANAGE 2.4, MANAGE 4.3Mechanisms to deactivate or supersede systems and respond to incidents.high

Cite this record

AIPolicyTracker (2026). “Providers must take corrective action and inform the supply chain about non-conforming high-risk AI (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.