Providers must supply conformity evidence and log access to authorities on request
Context fileUnder EU AI Act, Article 21
What does it require?
On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show that the system meets the Section 2 requirements, in a language the authority can readily understand, and must give the authority access to the automatically generated logs it holds. Authorities must treat what they receive as confidential under Article 78.
Practical action
Keep an authority-request playbook with a named contact, the documentation index and a pre-agreed export format for logs.
Who does it apply to?
Providers of high-risk AI systems; requests may come from any national competent authority.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
supportsPolicyExecutive sponsor for AI · annualAI governance policy and accountability structure
Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes
Names the regulator liaison and escalation path.
-
supportsTechnical measureEngineering lead · continuousAutomatic event logging and record retention
Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check
Logs must be retrievable in a usable format.
-
supportsProcessProduct or model owner · at launch and on material changeTechnical documentation, model cards and instructions for use
Serves 13 recorded duties · evidence: Technical documentation file, Model card or deployer information pack, Instructions for use
The documentation set that is handed over.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Regulator request handling procedure | document | |
| Log of authority requests and responses | register |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 7.5; Annex A.8.3 | Documented information available for external reporting. | medium |
| NIST AI RMF 1.0 | GOVERN 1.4, GOVERN 4.2 | Transparency and accountability records. | medium |
Cite this record
AIPolicyTracker (2026). “Providers must supply conformity evidence and log access to authorities on request (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.