Summary: From 2 August 2026 the EU Whistleblowing Directive explicitly covers AI Act violations. Protection extends well beyond employees, and free legal, psychological and technical support exists.
Sources: raw/Laws/Whistleblowing and the EU AI Act _ EU Artificial Intelligence Act.md
Last updated: 2026-07-28
Compiled by Santeri Koivula (EU Fellow, Future of Life Institute) and Karl Koch (founder, AI Whistleblower Initiative) (source: Whistleblowing and the EU AI Act…md).
The core facts
- The EU Whistleblowing Directive (2019/1937) “protects whistleblowers who report violations of EU law by requiring clear reporting channels and protecting whistleblowers from retaliation.”
- Protection applies to “a wide range of people in a professional context, including employees, contractors, suppliers, job applicants, and former workers.”
- Reports may be made “internally within an organisation, externally to national authorities, or publicly in certain situations where urgent public interest or risk of retaliation exists.”
- “From 2nd August 2026, whistleblowing protections explicitly cover violations of the EU AI Act, though some AI-related issues may already fall under existing protections.”
- “Various institutions and organisations offer free legal, psychological, and technical support to whistleblowers. Reaching out early can help ensure the best possible protection.”
The personal scope is the detail most people get wrong. Contractors, suppliers and former workers are covered — which matters in a field where a large share of frontier model evaluation and red teaming is done by contractors and external researchers.
Why this exists in an AI-security corpus
The source’s rationale: “insiders in companies are uniquely positioned to detect issues that are not readily observable externally. In a recent study, whistleblower protections were listed as one of the most effective interventions for mitigating AI risks” (source: Whistleblowing and the EU AI Act…md, citing SSRN 5021463).
The comparison offered is the SEC Whistleblower Program, which “has enabled the recovery of over US$6.3 billion in monetary sanctions since its launch in 2010.”
This is a governance control that operates on the information asymmetry problem — the same problem the Scientific Panel addresses from the outside. Regulators cannot evaluate what they cannot see; the Act’s answer is a technical expert panel with alert powers and protected internal reporters.
The public-disclosure caveat
Direct reporting to media or the public “has been transposed differently in each Member State, often with restrictions that make it an option of last resort” (source: Whistleblowing and the EU AI Act…md).
Anyone considering that route needs Member-State-specific advice, not the Directive text.
Practical guidance from the source
The source sets out sections on:
- Documenting evidence
- Secure communication
- Before you report
- Protection against retaliation
- Reporting channels and procedures
Support infrastructure is listed for international bodies and for Belgium, France, Germany and Ireland specifically.
The secure-communication and evidence-documentation sections are operational security guidance. Anyone in this position should read the source directly rather than a wiki summary of it.
The Code of Practice angle
Independently of the Directive, the Code of Practice Commitment 8 requires signatories to ensure “a strong risk culture, and protections for whistleblowers” as part of systemic risk responsibility allocation (Measure 8.3, “Promotion of a healthy risk culture”) (source: raw/Laws/Overview of the Code of Practice...md).
So a GPAI systemic-risk provider adhering to the Code has committed to whistleblower protection independently of, and ahead of, the August 2026 statutory coverage.