Source: OJ L, 2025/454, 10.3.2025

Current language: EN

Article 17 Conditions for granting access to the received documentation or information


Summary What does Article 17 of the Scientific panel of independent experts say?

This article governs how the AI Office actually delivers information to the scientific panel once a request for assistance has been approved under the preceding articles.

It sets out the practical conditions under which the rapporteur gains access to documentation or information obtained from a general-purpose AI model provider, establishing a controlled and secure framework for that access.

The article places clear obligations on both the AI Office and the rapporteur before any information changes hands.

Important points:

  • The AI Office is required to provide secure means for transmitting requested documentation or information exclusively to the appointed rapporteur and contributors, with access restricted in time.
  • Before granting access, the AI Office must obtain from the rapporteur a self-declaration of purpose and a description of safeguards for confidential handling of the information.
  • The AI Office may refuse access where it identifies reasonably foreseeable risks related to data security or confidentiality based on the rapporteur's submissions.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The AI Office shall provide secure means through which it can make available the received documentation or information, which the Commission has requested following a request for assistance, to the requesting rapporteur of the scientific panel.

    1. Access to the requested information shall be restricted to the appointed rapporteur and contributors and shall be limited in time, with the possibility for extension upon duly justified request.

    1. Before granting access to the received documentation or information, the AI Office shall require that the rapporteur submits:

      1. a self-declaration to use the information solely for the stated purposes referred to in Article 15(3) of this Regulation;

      2. a description of modalities and safeguards to ensure confidential handling of the received information.

    1. The AI Office shall be able to refuse access to the requested data, where on the basis of the information submitted pursuant to paragraph 3, it has grounds to assume that there are reasonably foreseeable risks related to data security or confidentiality.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod