Article 92: Power to conduct evaluations
Article 92 empowers the AI Office (after consulting the Board) to conduct evaluations of general-purpose AI models to assess provider compliance or to investigate systemic risks at Union level. The Commission may appoint independent experts and may request access to the model through APIs or other technical means, including source code. Providers must supply the information requested. The Commission shall adopt implementing acts setting out detailed arrangements for evaluations.
Who does this apply to?
- -Market surveillance authorities requesting access to data and documentation from AI system providers
- -Providers of high-risk AI systems required to share training data, validation data, and technical documentation with authorities upon reasoned request
- -The AI Office accessing data and documentation from providers of general-purpose AI models for enforcement purposes
Scenarios
A national market surveillance authority investigates a high-risk AI medical diagnostic system following serious incident reports. The authority issues a reasoned request under Article 92 to the provider, demanding access to the training dataset to assess whether the system was trained on sufficiently representative data across patient demographics.
The AI Office investigates a provider of a general-purpose AI model following concerns about systemic risk. The AI Office issues a reasoned request for access to the model's training data documentation, evaluation results, and red-teaming outputs to verify compliance with Article 55 obligations for GPAI models with systemic risk.
What Article 92 does (in plain terms)
Article 92 is the power to evaluate GPAI models, not a general power for national authorities to access the training sets of high-risk systems, which sits with market surveillance and Article 74.
1. Two purposes. Either (a) to assess provider compliance where the information gathered under Article 91 is insufficient, or (b) to investigate systemic risks at Union level, in particular following an alert under Article 90(1)(a). 2. Independent experts. The Commission may appoint them, including from the scientific panel in Article 68, subject to the criteria in Article 68(2). 3. Technical access. The Commission may request access to the model through an API or other technical means, including source code.
How Article 92 connects to the rest of the Act
- Article 91: documentation requests whose insufficiency can trigger an evaluation.
- Article 90: scientific panel alerts, in particular under paragraph 1(a).
- Article 93: the power to request measures after an evaluation.
- Article 101: fines where access is refused.
- Article 98: the committee procedure for implementing acts.
- Article 113: dates of application.
Practical guidance
For GPAI providers: prepare access arrangements, an API or a controlled environment, sufficient for an evaluation without unnecessary transfer of trade secrets. Refusing access exposes you to Article 101. The structured dialogue in paragraph 7 is an opportunity to document internal testing before formal access.
Official wording: Article 92
Article 92
Power to conduct evaluations
1. The AI Office, after consulting the Board, may conduct evaluations of the general-purpose AI model concerned:
(a) to assess compliance of the provider with obligations under this Regulation, where the information gathered pursuant to Article 91 is insufficient; or
(b) to investigate systemic risks at Union level of general-purpose AI models with systemic risk, in particular following a qualified alert from the scientific panel in accordance with Article 90(1), point (a).
2. The Commission may decide to appoint independent experts to carry out evaluations on its behalf, including from the scientific panel established pursuant to Article 68. Independent experts appointed for this task shall meet the criteria outlined in Article 68(2).
3. For the purposes of paragraph 1, the Commission may request access to the general-purpose AI model concerned through APIs or further appropriate technical means and tools, including source code.
4. The request for access shall state the legal basis, the purpose and reasons of the request and set the period within which the access is to be provided, and the fines provided for in Article 101 for failure to provide access.
5. The providers of the general-purpose AI model concerned or its representative shall supply the information requested. In the case of legal persons, companies or firms, or where the provider has no legal personality, the persons authorised to represent them by law or by their statutes, shall provide the access requested on behalf of the provider of the general-purpose AI model concerned.
6. The Commission shall adopt implementing acts setting out the detailed arrangements and the conditions for the evaluations, including the detailed arrangements for involving independent experts, and the procedure for the selection thereof. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).
7. Prior to requesting access to the general-purpose AI model concerned, the AI Office may initiate a structured dialogue with the provider of the general-purpose AI model to gather more information on the internal testing of the model, internal safeguards for preventing systemic risks, and other internal procedures and measures the provider has taken to mitigate such risks.
Compliance checklist
- Maintain structured and accessible records of training, validation, and testing datasets for all high-risk AI systems, including data provenance and pre-processing documentation.
- Pre-classify all trade secrets and proprietary information within your datasets and documentation so confidentiality can be asserted promptly upon receiving an access request.
- Establish an internal response protocol for Article 92 data access requests, including designated contacts, review procedures, and response timelines.
- Implement technical infrastructure (APIs, secure data rooms, or access-controlled environments) that can facilitate authority access without full data transfer.
- Train legal and compliance teams on the 'reasoned request' standard so they can evaluate whether authority requests are properly scoped.
- Coordinate with your Data Protection Officer on requests that may involve personal data within training datasets, ensuring GDPR compliance during authority access.
Ensure your data is audit-ready for enforcement access, start the free assessment.
Start free assessmentRelated articles
Frequently asked questions
Can authorities demand a full copy of training data, or only access to inspect it?
Article 92 refers to granting 'access' to data, including through APIs or other technical means. This does not necessarily require handing over a full copy. Providers may propose access modalities, such as on-premises inspection, secure data rooms, or API-based querying, that allow the authority to verify compliance without full data transfer. The key is that the access must be sufficient for the authority's enforcement purposes.
What happens if training data contains personal data subject to GDPR?
Article 92 access requests do not override GDPR obligations. When training data contains personal data, the authority's access must comply with applicable data protection law. Authorities themselves are bound by GDPR when processing personal data for enforcement purposes. Providers should coordinate with their DPO and the authority to ensure appropriate data protection safeguards are in place during access.
Can a provider refuse an Article 92 request on trade secret grounds?
Not outright. Article 92 requires authorities to ensure confidentiality of trade secrets, but it does not allow providers to refuse access on trade secret grounds alone. The authority is entitled to access the data; the safeguard is that it must treat the information confidentially. If a provider believes a request is unreasonably broad, it can challenge the scope of the request, but not the principle of access itself.