Chapter VII, GovernanceArticle 89

Article 89: Monitoring actions

Applies from 2 Dec 20276 min readEUR-Lex verified Aug 2026

Article 89 empowers the AI Office to take all necessary actions to monitor the effective implementation and compliance with the Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice. It also gives downstream providers the right to lodge duly reasoned complaints alleging infringements.

Who does this apply to?

  • -EU institutions, bodies, offices and agencies acting as AI providers or deployers
  • -The European Data Protection Supervisor (EDPS) as the enforcement authority for Union bodies under the AI Act
  • -Compliance teams within EU agencies responsible for ensuring their AI systems meet AI Act requirements

Scenarios

Frontex deploys an AI-based risk analysis system to support border management operations. As an EU agency acting as a deployer of a high-risk AI system (border control falls under Annex III), Frontex must comply with deployer obligations under Article 26. The EDPS is the competent supervisory authority for Frontex's AI Act compliance.

The EDPS reviews Frontex's fundamental rights impact assessment, human oversight arrangements, and logging practices. If the EDPS identifies non-compliance, such as insufficient human oversight, it may require corrective measures and, if Frontex fails to comply, impose administrative fines under Article 98.
Ref. Art. 89(1), (2)

The European Commission develops an internal AI tool to assist in processing state aid notifications. The Commission acts as both provider and deployer of this AI system. A staff member raises concerns that the system's outputs may be used in decisions affecting third parties without adequate transparency disclosures.

The EDPS investigates whether the Commission has met its transparency obligations under Article 50 and deployer obligations under Article 26. The EDPS exercises the same enforcement powers that a national market surveillance authority would exercise over a national entity, including the power to order corrective measures.
Ref. Art. 89(1)

What Article 89 does (in plain terms)

Article 89 gives the AI Office an operational mandate for monitoring actions over GPAI model providers. It is not about supervision of Union institutions.

1. Monitoring implementation. The AI Office may take the necessary actions to monitor effective implementation of and compliance with the Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice (Article 56, not to be confused with the codes of conduct in Article 95). 2. Downstream provider complaint. Downstream providers may lodge a complaint alleging an infringement. It must be duly reasoned and state at least: the contact point of the model provider, the facts, the provisions concerned and the reasons, and any other relevant information.

How Article 89 connects to the rest of the Act

  • Article 88: the exclusive Commission and AI Office powers over Chapter V.
  • Article 56: the GPAI codes of practice whose adherence may be monitored.
  • Article 53: the baseline GPAI provider obligations that downstream complaints usually concern.
  • Article 101: the GPAI-specific fine regime.
  • Article 113: dates of application.

Practical guidance

For downstream providers: build the complaint file with a contact point, the facts, the articles engaged and the evidence. A vague complaint does not meet Article 89(2).

For GPAI providers: document adherence to the code of practice and prepare for AI Office monitoring actions, which are distinct from national investigations into systems.

Official wording: Article 89

Article 89

Monitoring actions

1. For the purpose of carrying out the tasks assigned to it under this Section, the AI Office may take the necessary actions to monitor the effective implementation and compliance with this Regulation by providers of general-purpose AI models, including their adherence to approved codes of practice.
2. Downstream providers shall have the right to lodge a complaint alleging an infringement of this Regulation. A complaint shall be duly reasoned and indicate at least:

(a) the point of contact of the provider of the general-purpose AI model concerned;

(b) a description of the relevant facts, the provisions of this Regulation concerned, and the reason why the downstream provider considers that the provider of the general-purpose AI model concerned infringed this Regulation;
(c) any other information that the downstream provider that sent the request considers relevant, including, where appropriate, information gathered on its own initiative.

Compliance checklist

  • Conduct a comprehensive AI system inventory across your EU institution, classifying each system by AI Act risk category.
  • Designate an internal AI compliance function with clear responsibility for AI Act obligations, coordinating with the Data Protection Officer.
  • Prepare technical documentation and conformity assessment records for all high-risk AI systems in a format suitable for EDPS inspection.
  • Complete fundamental rights impact assessments for high-risk AI systems deployed by your institution, particularly in areas affecting natural persons.
  • Register all high-risk AI systems in the EU database under Article 49.
  • Establish a direct communication channel with the EDPS for AI Act supervisory matters, separate from data protection supervision.
  • Monitor EDPS guidance and enforcement priorities specific to Union institutions' use of AI.

Assess your EU institution's AI Act readiness, start the free assessment.

Start free assessment

Frequently asked questions

Why is the EDPS the supervisory authority rather than a new AI-specific body?

The EDPS already supervises EU institutions for data protection compliance under Regulation (EU) 2018/1725. Assigning AI Act supervision to the EDPS leverages existing institutional relationships, expertise in fundamental rights, and enforcement infrastructure. The EDPS is also already familiar with the technical operations of EU institutions, making it a natural choice.

Can the EDPS actually fine EU institutions?

Yes. Article 89 in combination with Article 98 gives the EDPS the power to impose administrative fines on Union institutions, bodies, offices and agencies. This ensures that EU institutions face real financial consequences for non-compliance, mirroring the penalty regime that applies to private-sector operators under national enforcement.

Does Article 89 apply to EU agencies that outsource AI development to private contractors?

Yes. When an EU agency acts as a deployer of an AI system, even one developed by a private contractor, the agency remains subject to deployer obligations and EDPS supervision under Article 89. The private contractor, as provider, would separately be subject to national market surveillance authority oversight. Both the agency and the contractor must comply with their respective obligations.