Skip to main content
Member States Are Misreading the AI Act's Notification BurdenCompliance & Audit
6 min readFor AI Governance Leaders

Member States Are Misreading the AI Act's Notification Burden

EU Member States face 28 distinct notification and assessment responsibilities under the AI Act. Many national authorities mistakenly treat this as a simple documentation task. They're wrong.

These responsibilities require active management. Each notification triggers an assessment workflow, decision timeline, and cross-border coordination. The difference between merely receiving notifications and managing a notification system will determine whether your national framework can handle the volume effectively or collapses under pressure.

Here's why governance teams keep making the same preparation mistakes and how to fix them before the August 2025 deadline.

Why These Mistakes Keep Happening

Member States often view the AI Act through a compliance lens instead of an operational one. The regulation outlines what must happen, such as receiving risk notifications (Article 20(2)) and assessing conformity bodies (Articles 29-31), but doesn't specify the infrastructure needed to handle multiple notifications or how to staff cross-functional assessments.

Many national authorities underestimate the coordination required. For example, Article 36 mandates notifying the Commission and other Member States about changes to a notified body's status. This isn't a one-time email. It's a documented decision with evidence, shared through a centralized electronic tool, allowing other states to object under Article 30(4/5).

The result: teams build notification portals without assessment workflows, hire conformity assessors without cross-border protocols, and schedule sandbox programs without the authority to suspend testing under Article 57(11).

Mistake 1: Treating All 28 Responsibilities as Equal Priority

Why it happens: The AI Act lists responsibilities chronologically, not by complexity. Teams create implementation roadmaps that mirror the article sequence rather than the resource intensity of each duty.

The consequence: Your team allocates equal effort to receiving a provider's EU declaration of conformity (Article 47(1), a registration task) and assessing a conformity assessment body's qualifications (Articles 29-31, a multi-month evaluation). When conformity body applications arrive in Q3 2025, you don't have assessors ready.

The fix: Tier your 28 responsibilities by assessment depth, not article number. Create three categories:

  • Registration-only: Receive and log (e.g., Article 47 declarations, Article 22 mandate copies). Build a secure portal with validation checks.
  • Assessment-required: Evaluate documentation and make approval decisions (e.g., Articles 29-31 conformity bodies, Article 46 exceptional authorizations). Staff with technical reviewers and legal counsel.
  • Ongoing supervision: Monitor and potentially intervene (e.g., Article 36 notified body changes, Article 57(11) sandbox risk escalations). Establish surveillance protocols and escalation thresholds.

Allocate 60% of your 2025 budget to the assessment-required category. That's where bottlenecks will form.

Mistake 2: Building Notification Systems Without Cross-Border Workflows

Why it happens: National authorities focus on inbound notifications from providers within their jurisdiction, forgetting that 11 of the 28 responsibilities require informing the Commission or other Member States.

The consequence: You receive a notification under Article 20(2) about a high-risk system. Your team evaluates it internally, documents the findings, and closes the case. Three months later, the Commission asks why you never submitted the required cross-border notification. You now have a compliance gap and no audit trail showing you intended to notify.

The fix: Map every responsibility to its notification counterparty. For each Article requiring Commission or Member State notification:

  • Identify the electronic tool specified (Article 30(2) references a centralized notification tool for conformity bodies).
  • Define the information package required (supporting documentation, assessment rationale, timeline).
  • Set internal deadlines allowing 10 business days for translation and legal review before the external submission deadline.

Build your workflow software to generate the outbound notification automatically when you close an assessment. If your system can receive but not transmit, you're only halfway compliant.

Mistake 3: Staffing Sandboxes Without Suspension Authority

Why it happens: Article 57 describes AI regulatory sandboxes as innovation support mechanisms. Teams staff them with business development professionals and technical advisors, not enforcement personnel.

The consequence: A sandbox participant's testing reveals significant risks. Article 57(11) requires you to request mitigation and, if that fails, suspend the testing. Your sandbox team lacks legal training, suspension criteria, and an escalation path to an authority with enforcement powers. The testing continues while you scramble to involve your legal department.

The fix: Structure your sandbox with three distinct roles:

  • Innovation advisors: Provide guidance on regulatory expectations and technical practices (Article 57(6)).
  • Risk monitors: Continuously assess for fundamental rights, health, and safety risks during testing.
  • Enforcement liaisons: Maintain direct authority to initiate suspension under Article 57(11), with pre-approved criteria and escalation protocols.

Your sandbox participation agreement must state that risk monitors can halt testing immediately, with formal suspension following within 48 hours. If you position the sandbox purely as a support service, you lose the ability to act when risks materialize.

Mistake 4: Underestimating Conformity Assessment Body Volume

Why it happens: Member States assume they'll designate a few notified bodies domestically and occasionally review their performance. The AI Act's scope makes this assumption obsolete.

The consequence: High-risk AI systems span sectors from medical devices to critical infrastructure. Each sector needs specialized conformity assessment expertise. You receive 12 applications from bodies seeking notification under Articles 29-31, each requiring assessment of technical competence, independence, and quality management systems. Your team planned for 3 assessments, not 12. Application reviews stretch from 3 months to 9 months, delaying market access for compliant providers.

The fix: Conduct a sector-based demand forecast now. Identify every high-risk AI system category in Annex III that applies to your national economy. For each category, estimate:

  • How many providers will need conformity assessment (based on current AI system deployments and planned launches).
  • Whether existing notified bodies from adjacent regulations (e.g., medical device bodies under MDR) can extend their scope.
  • The technical competence gap for categories without existing assessment infrastructure.

If your forecast shows demand for 8+ notified bodies across sectors, establish a rolling assessment process with quarterly application windows rather than ad-hoc review. This prevents bottlenecks and sets clear timeline expectations under Articles 29-31.

Mistake 5: Ignoring the August 2025 vs. August 2026 Split

Why it happens: Teams see "AI Act implementation" as a single 2026 deadline and backload their preparation accordingly.

The consequence: Thirteen responsibilities apply from 02 August 2025 under Article 113(b). These include assessing and notifying conformity bodies (Articles 29-31), receiving General-Purpose AI Model documentation (Article 53(1a)), and handling systemic risk incident notifications (Article 55(1c)). If you're not operationally ready by August 2025, you're non-compliant for 12 months before the main regulation takes effect.

The fix: Build two implementation tracks with separate readiness dates:

Track 1 (August 2025 deadline): Focus on conformity body assessment infrastructure, General-Purpose AI Model oversight capabilities, and serious incident reporting systems. These require technical expertise you may not have in-house, so procurement and hiring must start now.

Track 2 (August 2026 deadline): Address provider notification systems, deployer fundamental rights impact assessments (Article 27(3)), and sandbox operational protocols.

Your Track 1 budget should be at least 40% of your total AI Act implementation spend. Treat August 2025 as your real launch date, not a soft opening.

Prevention Checklist

Before finalizing your national compliance framework:

  • Tiered all 28 responsibilities by assessment complexity, not article order.
  • Mapped cross-border notification requirements to specific electronic tools and counterparties.
  • Staffed AI regulatory sandboxes with personnel who have legal authority to suspend testing under Article 57(11).
  • Forecasted conformity assessment body demand by high-risk AI sector, not as a single national total.
  • Separated August 2025 and August 2026 implementation tracks with independent budgets and readiness milestones.
  • Established assessment capacity for Article 29-31 conformity body applications (target: 90-day review cycle).
  • Built notification workflows that generate outbound Commission/Member State alerts automatically.
  • Defined escalation protocols for significant risks identified in sandboxes, with documented suspension criteria.
  • Identified technical expertise gaps for General-Purpose AI Model oversight and initiated hiring or procurement.
  • Created a quarterly review process to assess notification volume against capacity, with scaling triggers.

Member States that treat this as an operational infrastructure build, not a policy drafting exercise, will be ready when notifications start arriving in August 2025. The rest will be managing a backlog while providers wait for decisions that should take weeks, not months.

You Might Also Like