What individuals get: complaints, explanations, and whistleblowers

Lesson 3 of 6 in Governance, Enforcement, Penalties, and Sandboxes.

For most of its length the AI Act talks to companies and regulators. Articles 85–87 are where it finally talks to people — and the rights are narrower than the headlines suggested, so precision pays.

Article 85 — the complaint. Any natural or legal person with grounds to consider the Act infringed may lodge a complaint with the relevant market surveillance authority. No standing requirements, no need to be personally affected — a complaint is an enforcement trigger, feeding the Article 79 machinery you just walked. What Article 85 does not create is a private right to damages; for compensation, individuals must look to national law and the product-liability regime you will meet in the final lesson.

Article 87 — the whistleblower. Reporting infringements of the AI Act falls under Directive (EU) 2019/1937, the EU whistleblower directive: protected channels, prohibition of retaliation, and identity protection for the engineer who reports that the Annex IV file describes tests that never ran. For governance teams the operational takeaway is blunt — your internal reporting channels must cover AI Act infringements, and your incident-response plan should assume regulators may already know.

Unpack the conditions, because each one excludes real cases: the system must be Annex III high-risk (limited-risk chatbots and minimal-risk tools grant nothing); point 2 — critical infrastructure — is carved out; there must be a decision with legal or similarly significant adverse effects (a score that no human ever acts on does not qualify); the duty sits on the deployer, not the provider; and Article 86 applies only to the extent the right is not already provided under other Union law — it is a gap-filler behind GDPR Article 22 and its Article 15(1)(h) access right, which already cover solely automated decisions on personal data. Article 86’s marginal value is precisely the cases GDPR misses: decisions with meaningful human involvement based on high-risk AI output, and affected persons whose complaint is not about personal-data processing.

Note also what the explanation must contain: the role of the AI system in the procedure and the main elements of the decision — not the model’s weights, not a mathematical proof. It is a procedural-transparency right, engineered to be satisfiable.

Does Article 86 give this person an explanation right?

Interactive decision tree — outcomes:

  • Article 86 applies

    The deployer owes a clear and meaningful explanation of the AI system’s role in the decision-making procedure and the main elements of the decision. This is exactly the gap Art 86 was built for: consequential decisions with human involvement that GDPR Art 22 does not reach.

  • Use the GDPR lane

    Art 86 yields where other Union law already grants the right. A solely automated decision on personal data runs through GDPR Arts 22 and 15(1)(h) — with the DPA, not the market surveillance authority, as the natural forum.

  • Carved out: Annex III point 2

    Critical-infrastructure systems are expressly excepted from Art 86 — grid-management decisions do not generate individual explanation rights. Other remedies (Art 85 complaints, sectoral law) may still be available.

  • No qualifying decision effect

    Without legal or similarly significant adverse effects there is no Art 86 right. An internal risk score nobody acts on, or a recommendation the human decision-maker independently re-derives, does not qualify.

  • Outside Article 86 entirely

    Art 86 attaches only to decisions based on Annex III high-risk system output. Chatbot interactions, minimal-risk tools, and Annex I product systems sit outside it — look to Art 85 complaints, GDPR, consumer law, or sectoral regimes instead.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.