Regulation Tracker / EU AI Act / Chapter IX · Section 3
Article 74
Market surveillance and control of AI systems in the Union market
Chapter IX — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems, Section 3 — Market surveillance and control of AI systems in the Union market. 15 distinct duties, powers or definitions are coded from this article, applying from 2026-08-02. 5 reach legal practice directly.
Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 114 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex.
official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub
The text
1. Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation. For the purposes of the effective enforcement of this Regulation:
- (a)any reference to an economic operator under Regulation (EU) 2019/1020 shall be understood as including all operators identified in Article 2(1) of this Regulation;
- (b)any reference to a product under Regulation (EU) 2019/1020 shall be understood as including all AI systems falling within the scope of this Regulation.
2. As part of their reporting obligations under Article 34(4) of Regulation (EU) 2019/1020, the market surveillance authorities shall report annually to the Commission and relevant national competition authorities any information identified in the course of market surveillance activities that may be of potential interest for the application of Union law on competition rules. They shall also annually report to the Commission about the use of prohibited practices that occurred during that year and about the measures taken.
3. For high-risk AI systems related to products covered by the Union harmonisation legislation listed in Section A of Annex I, the market surveillance authority for the purposes of this Regulation shall be the authority responsible for market surveillance activities designated under those legal acts.
4. The procedures referred to in Articles 79 to 83 of this Regulation shall not apply to AI systems related to products covered by the Union harmonisation legislation listed in section A of Annex I, where such legal acts already provide for procedures ensuring an equivalent level of protection and having the same objective. In such cases, the relevant sectoral procedures shall apply instead.
5. Without prejudice to the powers of market surveillance authorities under Article 14 of Regulation (EU) 2019/1020, for the purpose of ensuring the effective enforcement of this Regulation, market surveillance authorities may exercise the powers referred to in Article 14(4), points (d) and (j), of that Regulation remotely, as appropriate.
6. For high-risk AI systems placed on the market, put into service, or used by financial institutions regulated by Union financial services law, the market surveillance authority for the purposes of this Regulation shall be the relevant national authority responsible for the financial supervision of those institutions under that legislation in so far as the placing on the market, putting into service, or the use of the AI system is in direct connection with the provision of those financial services.
7. By way of derogation from paragraph 6, in appropriate circumstances, and provided that coordination is ensured, another relevant authority may be identified by the Member State as market surveillance authority for the purposes of this Regulation.
8. For high-risk AI systems listed in point 1 of Annex III to this Regulation, in so far as the systems are used for law enforcement purposes, border management and justice and democracy, and for high-risk AI systems listed in points 6, 7 and 8 of Annex III to this Regulation, Member States shall designate as market surveillance authorities for the purposes of this Regulation either the competent data protection supervisory authorities under Regulation (EU) 2016/679 or Directive (EU) 2016/680, or any other authority designated pursuant to the same conditions laid down in Articles 41 to 44 of Directive (EU) 2016/680. Market surveillance activities shall in no way affect the independence of judicial authorities, or otherwise interfere with their activities when acting in their judicial capacity.
9. Where Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as their market surveillance authority, except in relation to the Court of Justice of the European Union acting in its judicial capacity.
10. Member States shall facilitate coordination between market surveillance authorities designated under this Regulation and other relevant national authorities or bodies which supervise the application of Union harmonisation legislation listed in Annex I, or in other Union law, that might be relevant for the high-risk AI systems referred to in Annex III.
11. Market surveillance authorities and the Commission shall be able to propose joint activities, including joint investigations, to be conducted by either market surveillance authorities or market surveillance authorities jointly with the Commission, that have the aim of promoting compliance, identifying non-compliance, raising awareness or providing guidance in relation to this Regulation with respect to specific categories of high-risk AI systems that are found to present a serious risk across two or more Member States in accordance with Article 9 of Regulation (EU) 2019/1020. The AI Office shall provide coordination support for joint investigations.
12. Without prejudice to the powers provided for under Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks, the market surveillance authorities shall be granted full access by providers to the documentation as well as the training, validation and testing data sets used for the development of high-risk AI systems, including, where appropriate and subject to security safeguards, through application programming interfaces (API) or other relevant technical means and tools enabling remote access.
13. Market surveillance authorities shall be granted access to the source code of the high-risk AI system upon a reasoned request and only when both of the following conditions are fulfilled:
- (a)access to source code is necessary to assess the conformity of a high-risk AI system with the requirements set out in Chapter III, Section 2; and
- (b)testing or auditing procedures and verifications based on the data and documentation provided by the provider have been exhausted or proved insufficient.
14. Any information or documentation obtained by market surveillance authorities shall be treated in accordance with the confidentiality obligations set out in Article 78.
What it requires, coded
SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.
Art. 74(1)Enforcement powerAll AI systems
Regulation 2019/1020 applies to AI systems covered by the AI Act, with references to economic operators and products read as operators and AI systems.
"Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation."
- Who
- Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal-AI vendors or public bodies — Market-surveillance powers can reach legal-sector AI operators when their systems fall within the Act.
- See
- Regulation (EU) 2019/1020 · Art. 2(1)
Art. 74(2)Cooperation with authoritiesNot tier-specific
Market surveillance authorities must annually report competition-relevant information, prohibited-practice use and measures taken to the Commission and relevant competition authorities.
"They shall also annually report to the Commission about the use of prohibited practices that occurred during that year and about the measures taken."
- Who
- Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal-AI vendors or public bodies — Reports on prohibited practices can include legal-sector AI uses if discovered during market surveillance.
- See
- Regulation (EU) 2019/1020 Article 34(4) · Art. 5
Art. 74(4)Derogation or exemptionHigh-risk
Articles 79 to 83 procedures do not apply to Annex I Section A product-related AI where equivalent sectoral procedures with the same objective already apply.
"the relevant sectoral procedures shall apply instead."
Art. 74(5)Enforcement powerNot tier-specific
Market surveillance authorities may exercise specified Regulation 2019/1020 powers remotely where appropriate to enforce the AI Act effectively.
"market surveillance authorities may exercise the powers referred to in Article 14(4), points (d) and (j), of that Regulation remotely, as appropriate."
- Who
- Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal-AI vendors or public bodies — Remote investigative or enforcement powers may affect legal-AI providers and deployers subject to market surveillance.
- See
- Regulation (EU) 2019/1020 Article 14(4)(d) · Regulation (EU) 2019/1020 Article 14(4)(j)
Art. 74(8)RequirementHigh-risklegal practice
Market surveillance activities must not affect judicial independence or interfere with judicial authorities when they act in their judicial capacity.
"Market surveillance activities shall in no way affect the independence of judicial authorities, or otherwise interfere with their activities when acting in their judicial capacity."
- Who
- Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal practice directly — This is directly relevant to courts deploying or overseeing AI in judicial work.
- See
- Annex III point 8
Art. 74(10)Cooperation with authoritiesNot tier-specific
Member States must facilitate coordination between AI Act market surveillance authorities and other relevant national or Union-law supervisory authorities.
"Member States shall facilitate coordination between market surveillance authorities designated under this Regulation and other relevant national authorities or bodies"
- Who
- Member State
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal-AI vendors or public bodies — Coordinated supervision may involve justice, data-protection or sectoral bodies relevant to legal-sector AI.
- See
- Annex I · Annex III
Art. 74(11)Enforcement powerHigh-risk
Market surveillance authorities and the Commission may propose joint compliance, investigation, awareness or guidance activities for high-risk AI presenting serious risk in multiple Member States; the AI Office supports coordination.
"Market surveillance authorities and the Commission shall be able to propose joint activities, including joint investigations"
- Who
- Market surveillance authority, Commission, AI Office
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal-AI vendors or public bodies — Cross-border investigations may affect high-risk legal-AI systems deployed in multiple Member States.
- See
- Regulation (EU) 2019/1020 Article 9
Art. 74(12)Cooperation with authoritiesHigh-risklegal practice
Providers must grant market surveillance authorities full access to documentation and training, validation and testing data sets where relevant and necessary for their tasks.
"the market surveillance authorities shall be granted full access by providers to the documentation as well as the training, validation and testing data sets used for the development of high-risk AI systems"
- Who
- Provider, Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Fine tier
- Art. 99(4)
- Legal practice
- Reaches legal practice directly — High-risk legal-AI providers may have to provide documentation and datasets to regulators.
- See
- Art. 78
Art. 74(13)Enforcement powerHigh-risklegal practice
Market surveillance authorities may access high-risk AI source code on reasoned request only when source access is necessary and other data, documentation and audit methods are exhausted or insufficient.
"Market surveillance authorities shall be granted access to the source code of the high-risk AI system upon a reasoned request and only when both of the following conditions are fulfilled:"
- Who
- Provider, Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal practice directly — Legal-AI providers of high-risk systems may face source-code access requests in narrow circumstances.
- See
- Chapter III Section 2 · Art. 78
Art. 74(14)Cooperation with authoritiesNot tier-specificlegal practice
Information and documentation obtained by market surveillance authorities under Article 74 must be treated under Article 78 confidentiality obligations.
"Any information or documentation obtained by market surveillance authorities shall be treated in accordance with the confidentiality obligations set out in Article 78."
- Who
- Market surveillance authority
- From
- (Art. 113 second subparagraph (general application))
- Legal practice
- Reaches legal practice directly — Confidentiality is important for legal-AI vendors providing sensitive documentation, data or source code.
- See
- Art. 78
Cite
Regulation (EU) 2024/1689, Article 74 (Market surveillance and control of AI systems in the Union market), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_74 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-74, accessed 2026-09-08, CC BY 4.0.