{"answer_id":"praxikon:eu:ai-act:answer:data-eisen-hoog-risico","canonical_page":"https://www.praxikon.com/en/antwoord/data-eisen-hoog-risico","query":"What data requirements does the AI Act set for high-risk AI (Article 10)?","lang":"en","view":"full","mode":"scenario","question":"What data requirements does the AI Act set for high-risk AI (Article 10)?","situation":"You want to know which requirements apply to training, validation and test data and what you must be able to demonstrate about them.","likely_role":"Mainly the provider; the deployer controls relevant input data","note":"Article 10 requires data governance across the lifecycle: datasets appropriate for the intended purpose, attention to representativeness, errors and completeness, and examination of possible bias with appropriate mitigation. The requirement follows the high-risk timeline to 2 December 2027, but the datasets you build or procure now determine whether you can comply then.","matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-10-data-governance","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"annex-iii-high-risk","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-4-ai-literacy","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null},{"kind":"recommended_action","statement":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}]},{"slug":"article-15-accuracy-robustness","label":"Article 15: accuracy, robustness and cybersecurity","summary":"Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-17-quality-management","label":"Article 17: quality management system","summary":"The documented quality system through which a high-risk AI provider structurally assures compliance.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-17-quality-management","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 17 requires a documented quality management system covering a compliance strategy, design and development procedures, data management, risk management, post-market monitoring, incident reporting and an accountability structure.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The QMS is the umbrella over all other provider duties: those with the separate files but no system connecting them fail exactly this article in an audit.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Build the QMS not as a separate document but as an index on top of the existing files (risk, data, documentation, monitoring) with owners per procedure.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]}],"conditional":[{"slug":"article-61-informed-consent","id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","label":"Article 61: informed consent of test subjects for testing in real world conditions","status":"possibly_applies","source_locator":"Article 60(4), point (i), with Article 61(1)","addressee":"reader","human_page":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent"}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":"AI literacy questions and answers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":"Draft guidelines on the classification of high-risk AI systems","publisher":"European Commission (AI Office)","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":"CEN-CENELEC JTC 21: European standards under standardisation request M/613","publisher":"CEN-CENELEC JTC 21","canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","title":"ISO/IEC JTC 1/SC 42: international standards for artificial intelligence","publisher":"ISO/IEC JTC 1/SC 42","canonical_url":"https://www.iso.org/committee/6794475.html","eli":null,"source_version":"catalogue-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Set up data governance per dataset","summary":"Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation."},{"label":"Justify the Article 6(3) exception against each individual condition","summary":"Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making."},{"label":"Take role- and context-specific AI literacy measures","summary":"Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate."}],"evidence":[{"label":"Data governance file","summary":"Record per dataset of origin, choices, assumptions, bias examination and mitigations.","url":null},{"label":"Article 49(2) registration record for the system assessed as not high-risk","summary":"Proof that the system for which you invoke the Article 6(3) exception is registered as Article 49(2) requires, with the registration number linked to the underlying assessment.","url":null},{"label":"AI literacy measures record","summary":"Versioned record of roles, context, measures, participation or instruction and review moments.","url":null}],"guidance":[{"label":"No mandatory course format, no certificate, no exam and no AI officer","statement":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)"},{"label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","statement":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)"},{"label":"Article 6 has two separate routes to high-risk","statement":"The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)"},{"label":"Broadly positioned and general purpose AI systems: a disclaimer is not enough","statement":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)"}],"examples":[{"label":"Candidate recommendation that automatically becomes a decision","situation":"An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.","outcome":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","lesson":"Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","provenance":"official"},{"label":"Facial recognition at access control: the guard behind the camera counts too","situation":"An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.","outcome":"Article 4(1) provides that providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. In doing so they must take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, and consider the persons or groups of persons on whom the AI systems are to be used. The same provision states that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.","lesson":"We read the phrase about the persons on whom the system is used as the centre of gravity for biometrics: whoever stands in front of the camera is subject to the outcome and has little to set against it. That argues for equipping the officer who decides for himself when no match comes back more substantively than the colleague who merely switches the system on and off. The article itself names no sufficient level and expressly states that you need not guarantee one, so where the floor lies for each role stays open. In our assessment a record kept per role, stating the choice made and the reason for it, is easier to defend than one organisation-wide session backed only by an attendance list.","source_locator":"Article 4(1)","provenance":"editorial"},{"label":"Police using AI in investigations: context sets how deep the training goes","situation":"A police force uses AI to search large volumes of investigation files and surface connections a detective would otherwise miss. The outputs feed into the choice of which suspect is pursued further and end up in documents that enter the criminal process. The question is whether one and the same basic instruction is enough for the analyst operating the model and for the detective who acts on its output.","outcome":"Article 4(1) requires providers and deployers of AI systems to take measures supporting the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The provision prescribes that they take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It also states that this obligation does not require any specific level of AI literacy of any individual to be guaranteed.","lesson":"Article 4 requires you to weigh the context of use and the people the system is applied to, and in law enforcement both factors run high on our reading. Whether a general introduction to what AI can do is then enough for someone carrying an output into a file that affects a person's position as a suspect, we doubt, but the provision expressly names no level you must guarantee, so that floor is yours to justify. We would record for each role what someone must be able to recognise, for instance that a discovered connection is not yet evidence, and revisit that choice periodically.","source_locator":"Article 4(1)","provenance":"editorial"},{"label":"Newsroom with generative AI: do freelancers count within your measures?","situation":"A newsroom uses generative AI to prepare summaries, headlines and imagery, after which an editor finishes the piece and the desk decides to publish. Part of that work sits with freelancers, and an outside agency produces marketing content with the same tools. The question is whether your AI literacy measures must reach those freelancers and that agency, or only the people on the payroll.","outcome":"Article 4(1) is addressed to providers and deployers of AI systems and requires them to take measures supporting the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The provision requires them to take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It does not require any specific level of AI literacy of any individual to be guaranteed.","lesson":"Alongside staff, the text expressly names other persons dealing with the operation and use of AI systems on your behalf, and we read that as a functional boundary rather than a contractual one. On that reading a freelance editor using your tool inside your workflow and on your instruction sits within your measures, employment contract or not. The outside agency is a harder case: if it works in your environment and on your instruction, the argument that it acts on your behalf holds up, but if it runs its own tools on its own account it is a deployer in its own right, and Article 4 does not say your measures must cover that work. In practice, in our assessment, that means recording in your agreements who works in which role and what instruction you give, rather than trusting the other side to arrange it.","source_locator":"Article 4(1)","provenance":"editorial"}],"standards":[{"label":"ISO/IEC 5259 series: data quality for analytics and machine learning","summary":"The five-part international series on data quality, in practice the most usable structure for the Article 10 data governance dossier.","statement":"The ISO/IEC 5259 series (Artificial intelligence: Data quality for analytics and machine learning) comprises five parts: part 1 (overview, terminology and examples), part 2 (data quality measures), part 3 (data quality management requirements and guidelines) and part 4 (data quality process framework), all published in 2024, plus part 5 (data quality governance framework), published in February 2025. CEN-CENELEC has adopted parts as European standards, including EN ISO/IEC 5259-4:2025 and EN ISO/IEC 5259-3:2025. No part is cited in the Official Journal, so no presumption of conformity under Article 40 arises. The deliverable intended to do so for Article 10 is prEN 18284."},{"label":"prEN 18284: quality and governance of datasets in AI","summary":"The draft European standard operationalising the Article 10 data governance requirements for training, validation and testing data.","statement":"prEN 18284 (Artificial intelligence: Quality and governance of datasets in AI) is the JTC 21 deliverable under M/613 for Article 10 of the AI Act, which sets requirements for the training, validation and testing datasets of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal."},{"label":"EN 18286:2026: quality management system for EU AI Act regulatory purposes","summary":"The first completed European standard under the AI Act standardisation request: the quality management system that Article 17 requires from providers of high-risk AI systems.","statement":"EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation."},{"label":"EN ISO/IEC 42001: artificial intelligence management system","summary":"The certifiable organisation-level AI management system, a European standard since 2026, but not a harmonised standard under the AI Act.","statement":"ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal."}],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/data-eisen-hoog-risico","follow_up_questions":[{"question":"Does our system fall under the definition of an AI system (Article 3)?","url":"https://www.praxikon.com/en/antwoord/valt-ons-systeem-onder-de-ai-act"},{"question":"What is automation bias and what should our organisation do about it?","url":"https://www.praxikon.com/en/antwoord/automation-bias"},{"question":"Do we need to appoint an AI officer or AI compliance officer?","url":"https://www.praxikon.com/en/antwoord/ai-compliance-officer"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}