Complaint handling is now an operational capability

The European Commission's AI Act Complaint Tool allows individuals and organisations to submit complaints about alleged infringements involving AI systems within the AI Office's remit. A submission can identify the country where an incident occurred, describe the alleged infringement and include supporting documents.

A complaint is an allegation, not a finding. The organisation's first task is therefore to preserve the record, establish scope and assemble verifiable facts. A rushed defensive answer can create more risk than a measured response that distinguishes confirmed evidence from assumptions.

The playbook below is an operating model for internal readiness. It does not replace legal advice, a regulator's directions or incident-reporting duties that may apply under the AI Act or other law.

Day one: log, preserve and contain

Create a complaint record with the time received, source, allegations, affected country, named system or feature and any supporting material. Assign a response owner and restrict access to the people needed for triage.

Preserve relevant system versions, prompts, configuration, model and supplier identifiers, input and output records, user notices, approvals, monitoring alerts and communications. Do not alter the system or overwrite logs before the evidence-preservation decision is documented.

Where continuing operation could cause harm, use the organisation's existing incident and safety procedures to consider proportionate containment. Record what was changed, by whom, when and why.

Days two and three: identify the system, role and route

Connect the allegation to the AI inventory. Confirm the intended purpose, actual use, product owner, deployment version, provider and deployer roles, users, affected people, geography and upstream model or service providers.

Map the allegation to the potentially relevant obligation without assuming the outcome. The AI Office supervises defined categories of AI providers and systems, while national competent authorities and the European Data Protection Supervisor have other responsibilities. The Commission may also refer a complaint with the complainant's consent where appropriate.

Legal and compliance teams should decide which authority or reporting route may apply. Operational teams should provide the evidence for that decision, not make unsupported legal classifications.

Days four to six: reconstruct what happened

Build a timeline from deployment and change records, system logs, user interactions, human reviews, alerts and escalation decisions. Separate observed events from interpretations and identify gaps explicitly.

Compare actual operation with intended purpose, user instructions, transparency notices, risk controls and approved limitations. Check whether a model, prompt, retrieval source, data flow, safeguard or subprocessor changed after the original approval.

Interview relevant owners using a consistent question set. Keep notes attributable and versioned so the organisation can show how its understanding developed.

Days seven to ten: decide, remediate and assemble the response pack

Document the evidence reviewed, factual findings, unresolved questions, impact assessment, applicable internal policies and any legal analysis obtained. Record corrective actions, owners, deadlines and verification criteria.

A response pack should include the complaint intake, system record, role and scope assessment, preserved evidence index, chronology, risk assessment, relevant control evidence, decision log, remediation plan and approved communications.

Use a two-person review for material factual claims. The pack should enable a regulator, customer or board reviewer to trace each conclusion to evidence without exposing unrelated personal, confidential or privileged material.

Turn each complaint into a control improvement

After closure, capture lessons in the risk register, control catalogue, training plan and supplier governance process. Review whether the inventory, logging, user notices, escalation path or evidence retention made the response faster or harder.

Test the playbook with a tabletop exercise before a real complaint arrives. For the wider enforcement context, read our guide to AI Act complaints and whistleblower channels. AI Act Ready helps teams turn system, risk and control records into a response-ready evidence pack.