When people talk about what an authority can ask of you, the article that almost always gets cited is Article 21, "Cooperation with competent authorities." It's a name that invites the assumption.
And it isn't yours.
What Article 21 says, and to whom
"Providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2…"
Providers. The entire article — all three paragraphs — is addressed to whoever builds the system and places it on the market. Its purpose is to demonstrate the conformity of the system, which is precisely what a deployer cannot do: it doesn't hold the technical documentation, because it doesn't produce it.
Two consequences worth keeping straight.
It doesn't bind you. If someone tells you that Article 21 requires you to hand over conformity documentation, they're making the attribution error that runs through half the Regulation.
And it sets no deadline. Neither Article 21 nor its paragraphs mention a number of days. It speaks of a "reasoned request," not response deadlines. Any figure cited as "the Article 21 deadline" isn't in the article.
The one that does reach you
At the end of Article 26, among the deployer's obligations:
"12. Deployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system…"
It's a general duty of cooperation, with no closed list of documents and no deadline of its own. What the authority can ask of you is determined, in practice, by what the other obligations in Article 26 require you to have.
And there the list does exist, even if it isn't called that:
- That you use the system in accordance with its instructions for use, with the technical and organisational measures you've adopted — 26(1).
- Who has been assigned human oversight, with the necessary competence, training and authority — 26(2).
- What input data you use, to the extent you control it — 26(4).
- How you monitor the system's operation and what you've reported to the provider — 26(5).
- The logs the system generates, to the extent they're under your control — 26(6).
- What you've told the workers affected, if you're an employer — 26(7).
Read the list backwards and you see what can actually be asked of you: not the conformity of the system, but the diligence of your use of it. They're two different things, and only one of them is yours.
The specific national procedure isn't published
This is where it's worth being explicit, because it's where most of the improvising happens.
The Regulation places market surveillance in its own chapter and gives national authorities the powers of verification, request and corrective measures. That's the framework.
What doesn't exist today is a published Spanish procedure that spells out step by step how an action is conducted: who gives notice, in what form, with what deadlines for submissions, with what remedies. That procedure is a matter of national law, and this article neither describes nor anticipates it: any detailed "step by step" description circulating today is a forecast, not a procedure.
And it's worth saying it that way rather than filling the gap: describing a procedure that isn't published is exactly the kind of claim no one can later verify. For who AESIA is and how it fits into the map of authorities, there's already an article that covers it; what this one adds is whose obligation each item is once the request arrives.
And the date, which puts all of this in order
None of Article 26 — including paragraph 12 — is enforceable today. The Annex III high-risk regime begins on 2 December 2027, and the date circulating in many guides is a different one.
What an authority can ask you today has to do with what's already binding: Article 4 on literacy and Article 5 on prohibited practices, in force since 2 February 2025, and — through a completely separate route, with its own authority — everything the GDPR has required for years.
What's worth having, and it isn't conformity documentation
Three things, and all three are yours by definition.
What systems you use, and for what. Without that, no question has a possible answer.
Who's accountable for each one. Not the provider — someone inside your own organisation.
And what you decided, when, and on what basis. Because the question an authority asks you isn't about the system — that one goes to the provider — it's about you: "what did you do before you used it?"
Content in accordance with Articles 4, 5, 21 and 26 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).
This article is for informational purposes only and does not constitute legal advice.