{"answer_id":"praxikon:eu:ai-act:answer:wanneer-publieke-organisatie-ai-act","canonical_page":"https://www.praxikon.com/en/antwoord/wanneer-publieke-organisatie-ai-act","query":"When do the AI Act obligations start to apply to a public-law body?","lang":"en","view":"full","mode":"form","question":"When do the AI Act obligations start to apply to a public-law body?","situation":"The obligations for a public-law body do not all start on the same day. They spread over 2 groups, from 2 August 2026 to 2 December 2027. Below is when each provision starts to apply.","likely_role":"public-law body","note":null,"matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-26-deployer-obligations","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-27-fria","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-27-fria","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}]},{"slug":"article-49-registration","label":"Article 49: registration in the EU database before the system reaches the market","summary":"The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":"2027-12-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/article-49-registration","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"editorial_interpretation","statement":"Two readings existed of the date on this object, and Chef chose between them on 6 September 2026. Article 49 sits in Section 5 of Chapter III, and the third paragraph of Article 113 names a Section of Chapter III twice: point (b) names Section 4 and sets it at 2 August 2025, and point (c) names Sections 1, 2 and 3, with the exception of Article 6(5). Section 5 appears in neither point, nor in point (a) or point (d). Article 49 therefore falls under the general date in the second paragraph, and that is the date this object carries: 2 August 2026. Whoever places an Annex III system on the market today without registering is late, not early. The practical reading is not written away but sits alongside it: the duty only acquires an object once a high-risk AI system exists, and that status arises through Article 6(2) and Annex III on 2 December 2027, the date named in point (c) of the third paragraph as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744. That date sits in high_risk_regime_from and the ground of the chosen date in timing_basis. The decision is recorded in data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"Two readings existed of the date on this object, and Chef chose between them on 6 September 2026. Article 49 sits in Section 5 of Chapter III, and the third paragraph of Article 113 names a Section of Chapter III twice: point (b) names Section 4 and sets it at 2 August 2025, and point (c) names Sections 1, 2 and 3, with the exception of Article 6(5). Section 5 appears in neither point, nor in point (a) or point (d). Article 49 therefore falls under the general date in the second paragraph, and that is the date this object carries: 2 August 2026. Whoever places an Annex III system on the market today without registering is late, not early. The practical reading is not written away but sits alongside it: the duty only acquires an object once a high-risk AI system exists, and that status arises through Article 6(2) and Annex III on 2 December 2027, the date named in point (c) of the third paragraph as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744. That date sits in high_risk_regime_from and the ground of the chosen date in timing_basis. The decision is recorded in data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"official_fact","statement":"Paragraph 1 provides that, before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71. Paragraph 2 provides that, before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71. Paragraph 3 provides that, before putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"Paragraph 2 is the most expensive sentence in this article and it is missed systematically. Anyone invoking the Article 6(3) exception for an Annex III system believes they have stepped out of the high-risk regime. That is true for the requirements on the system, but not for the registration: it is precisely that provider that registers itself and that system in the EU database, and does so before it is placed on the market or put into service. The exception is therefore not free. It is paid for in visibility: your name, your system and the Article 6(3) condition you rely on end up in a publicly searchable register, exactly where you thought you would stay out of sight. The mistake that follows is predictable and expensive. An organisation carries out the Article 6(3) assessment properly, documents it, and skips the registration because in its mind that belongs to the high-risk regime. The result is that the database holds no trace of a choice it did in fact make deliberately, and that a regulator meets it as a party that simply failed to register the system. The matching piece of evidence already exists in this knowledge base as the registration record for the Article 6(3) route and hangs off the Annex III obligation; the object below covers registration under paragraphs 1, 3, 4 and 5. Note the sequence, finally. Registration is a precondition, not a notification afterwards. Delivering first and registering later repairs nothing: the moment the duty is breached is the placing on the market itself.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"Read Article 49 together with Article 71 and with Article 26(8), because those three form a chain that in practice stalls at its weakest point. Article 71 describes the database and says who fills in which fields; Article 49 says when that must happen and by whom; Article 26(8) turns the result into a procurement condition. That last one is the sharpest: a deployer with the status of a public authority that establishes that the system it intends to use is not registered in the EU database shall not use that system and shall inform the provider or the distributor. For a supplier that means a missing registration is not an administrative backlog but a block on the public market, and the party raising it with you is your own customer. For a public sector organisation it means the check belongs in the procurement process and not at the moment of deployment. Two routes deviate and are forgotten for exactly that reason. The first is paragraph 4: for the areas of law enforcement, migration, asylum and border control management the registration moves into a secure non-public section with a shorter list of fields, and only the Commission and the national authorities referred to in Article 74(8) can look into it. That is not an exemption but a different counter, and whoever reads it as an exemption registers nothing. The second is paragraph 5: the systems in point 2 of Annex III, critical infrastructure, are registered at national level. The Regulation does not say which national register that is, so you answer that question in national law and not here. For a grid operator or a water utility that is the difference between an existing counter and a search that only starts once the system is already running.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Make registration a hard gate in the release process, before the moment of placing on the market or putting into service, not after. Work through three questions per system. First: does the intended purpose fall under a point of Annex III, and if so, under which point. Second: are you relying on Article 6(3). If you are, the registration in paragraph 2 is your duty and not your choice, and you register yourself and that system, together with the condition you rely on. Third: if it concerns point 2 of Annex III, the registration does not go to the EU database but to national level, and you locate that counter before you need the system. If you are a public sector organisation, do not only register yourself but also select the system and register its use, and build the Article 26(8) check into your procurement process: no deployment as long as the provider entry is not in the database, with a written notification to the provider or the distributor where it is missing. If you supply into the areas of law enforcement, migration, asylum or border control management, record that your registration runs through the secure non-public section and which limited fields go into it. Keep, per system, the registration number, the date of registration and the name of the person who submitted it, together with the system version the entry relates to, and update that entry as soon as the intended purpose, the status or the conformity documentation changes.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Make registration a hard gate in the release process, before the moment of placing on the market or putting into service, not after. Work through three questions per system. First: does the intended purpose fall under a point of Annex III, and if so, under which point. Second: are you relying on Article 6(3). If you are, the registration in paragraph 2 is your duty and not your choice, and you register yourself and that system, together with the condition you rely on. Third: if it concerns point 2 of Annex III, the registration does not go to the EU database but to national level, and you locate that counter before you need the system. If you are a public sector organisation, do not only register yourself but also select the system and register its use, and build the Article 26(8) check into your procurement process: no deployment as long as the provider entry is not in the database, with a written notification to the provider or the distributor where it is missing. If you supply into the areas of law enforcement, migration, asylum or border control management, record that your registration runs through the secure non-public section and which limited fields go into it. Keep, per system, the registration number, the date of registration and the name of the person who submitted it, together with the system version the entry relates to, and update that entry as soon as the intended purpose, the status or the conformity documentation changes.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-71-eu-database","label":"Article 71: EU database for high-risk AI systems listed in Annex III","summary":"The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-71-eu-database","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Paragraph 1 provides that the Commission shall, in collaboration with the Member States, set up and maintain an EU database containing the information referred to in paragraphs 2 and 3 concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60, and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications the Commission shall consult the relevant experts, and when updating them the Board. Paragraph 2 provides that the data listed in Sections A and B of Annex VIII shall be entered into the database by the provider or, where applicable, by the authorised representative. Paragraph 3 provides that the data listed in Section C of Annex VIII shall be entered by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4). Paragraph 4 provides that, with the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner, and that the information should be easily navigable and machine-readable. The same paragraph provides that the information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible to the public. Paragraph 5 provides that the database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation, and that such information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer. Paragraph 6 provides that the Commission shall be the controller of the database, shall make adequate technical and administrative support available to providers, prospective providers and deployers, and that the database shall comply with the applicable accessibility requirements.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 71(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"Annex VIII sets out which information is submitted upon registration and kept up to date thereafter. Section A, for providers registering in accordance with Article 49(1), lists thirteen points, including the name, address and contact details of the provider and of the authorised representative, the trade name and any additional unambiguous reference allowing identification and traceability of the system, a description of the intended purpose and of the components and functions supported, a basic and concise description of the information used and of the operating logic, the status of the system, the details and a scanned copy of the notified body certificate where applicable, the Member States where the system is available, a copy of the EU declaration of conformity referred to in Article 47 and the electronic instructions for use, which are not provided for the law enforcement, migration, asylum and border control management areas of points 1, 6 and 7 of Annex III. Section C, for deployers registering under Article 49(3), lists five points: the name, address and contact details of the deployer, the same details of the person submitting information on its behalf, the URL of the entry of the system in the database by its provider, a summary of the findings of the fundamental rights impact assessment carried out in accordance with Article 27, and where applicable a summary of the data protection impact assessment. Neither Section was amended by Regulation (EU) 2026/1744.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Section B","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"official_fact","statement":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 22 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"official_fact","statement":"Article 49(4) lists exhaustively what goes into the secure non-public section, and that is less than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. The final subparagraph provides that only the Commission and the national authorities referred to in Article 74(8) have access to the respective restricted sections of the database. Annex IX carries the information provided upon registration of testing in real world conditions and kept up to date thereafter, and lists five points: a Union wide unique single identification number of the testing, the name and contact details of the provider or prospective provider and of the deployers involved, a short description of the AI system and its intended purpose together with the information needed to identify it, a summary of the main characteristics of the testing plan, and information on the suspension or termination of the testing.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"Article 60(4), point (c), provides that the provider or prospective provider has registered the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management that registration takes place in the secure non-public section in accordance with Article 49(4), point (d), and for the systems referred to in point 2 of Annex III in accordance with Article 49(5). Article 60 sits in Chapter VI of the Regulation, on measures in support of innovation. That point (c) was not amended by Regulation (EU) 2026/1744.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(4), point (c), Article 49(4) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"The scope of Article 60 itself was amended. Article 1, point (24), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 60(1) and Article 60(2): testing in real world conditions outside AI regulatory sandboxes is now also open to providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, alongside the systems listed in Annex III. Article 1, point (25), inserts an Article 60a for high-risk AI systems covered by the harmonisation legislation listed in Section B of Annex I: Member States may adopt frameworks for real-world testing for those systems, must notify the Commission of any such framework before implementing it, and those frameworks must among other things ensure compliance with Article 60(2), (3), (4)(d)-(j) and (5)-(9). The registration duty in Article 60(4), point (c), which refers to Article 71(4), falls outside that enumeration.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"official_fact","statement":"Article 1, point (40), of Regulation (EU) 2026/1744 amends the THIRD paragraph of Article 113, which is where points (a) to (d) sit. Point (40)(b) replaces point (c) with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Two things belong with that and are often left out: the exception for Article 6(5) falls outside this deferral, and point (40)(c) adds a point (d) under which Articles 102 to 110 apply from 27 July 2026.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"official_fact","statement":"Recital 131 explains why the database exists and how far the public availability reaches. It names as the aim facilitating the work of the Commission and the Member States and increasing transparency towards the public, states that this part of the database should be publicly accessible and free of charge and that the information should be easily searchable, understandable and machine-readable, and that the database should be user-friendly, for example by offering search functionalities including through keywords, so that the general public can find the registration information. It adds that any substantial modification of high-risk AI systems should also be registered in the database, that access to the secure non-public section should be strictly limited to the Commission and, as regards their national section, to market surveillance authorities, and that the database should comply with the requirements of Directive (EU) 2019/882.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Treat the entry as a publication and not as a form. Designate per system the natural person who has the legal authority to register, because paragraph 5 provides that their name and contact details go into the database. Write the description of the intended purpose, of the operating logic and, for a public deployer, the summary of the fundamental rights impact assessment so that you can let them be read without explanation. Settle the sequence in your procurement contract: point 3 of Section C asks for the URL of the entry of the system in the database by its provider, so a municipality can only complete its Section C after its supplier has entered Section A. Record within what period the supplier delivers that URL and what happens if it does not. Also record when the entry was last checked against reality and tie that to your change and decommissioning process, so that status, Member States and declaration of conformity move with it. On procurement, check that the system is listed in the database before you put it into use: if it is not listed, a deployer may not use it under Article 26(8) and has to inform the provider or the distributor.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Treat the entry as a publication and not as a form. Designate per system the natural person who has the legal authority to register, because paragraph 5 provides that their name and contact details go into the database. Write the description of the intended purpose, of the operating logic and, for a public deployer, the summary of the fundamental rights impact assessment so that you can let them be read without explanation. Settle the sequence in your procurement contract: point 3 of Section C asks for the URL of the entry of the system in the database by its provider, so a municipality can only complete its Section C after its supplier has entered Section A. Record within what period the supplier delivers that URL and what happens if it does not. Also record when the entry was last checked against reality and tie that to your change and decommissioning process, so that status, Member States and declaration of conformity move with it. On procurement, check that the system is listed in the database before you put it into use: if it is not listed, a deployer may not use it under Article 26(8) and has to inform the provider or the distributor.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"conformity-ce-registration","label":"Articles 43-49: conformity assessment, CE and registration","summary":"The route from assessment to CE marking and EU database registration before market placement of high-risk AI.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":"2027-12-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/conformity-ce-registration","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 43 governs the conformity assessment, Article 47 the EU declaration of conformity, Article 48 the CE marking and Article 49 the registration in the EU database before market placement or putting into service, including registration of the Article 6(3) assessment.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"For buyers this is the simplest supplier check there is: ask for the declaration of conformity and the registration number. No declaration means the system may not be there by 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Plan the conformity route backwards from 2 December 2027: standards selection, assessment, declaration and registration together take months, not weeks.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]}],"conditional":[],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":"Draft guidelines on the classification of high-risk AI systems","publisher":"European Commission (AI Office)","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":"CEN-CENELEC JTC 21: European standards under standardisation request M/613","publisher":"CEN-CENELEC JTC 21","canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Assign human oversight and give those people a mandate","summary":"Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside."},{"label":"Map the affected groups and their specific risks of harm","summary":"Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13."},{"label":"Register yourself and the system before it reaches the market or is put into service","summary":"Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used."}],"evidence":[{"label":"Deployment dossier: logs, worker information and information to affected persons","summary":"The dossier that shows you retain the logs, that you informed workers and their representatives in time, and that the people about whom decisions are made are aware of it.","url":null},{"label":"Notification to the market surveillance authority with the completed template","summary":"The sent notification through which you report the assessment results to the market surveillance authority, with the completed template attached, plus date of dispatch and acknowledgement of receipt.","url":null},{"label":"Article 49 registration dossier","summary":"Per system: which Article 49 route was followed, the registration number, the date of registration, the name of the person who submitted it, the system version the entry relates to, and, for the secure section, a statement of which limited fields from Annex VIII and Annex IX were completed.","url":"https://www.praxikon.com/en/ai-act/artikel/49"}],"guidance":[{"label":"Annex I lists legislation, not products","statement":"The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.","source_locator":"Draft guidelines Annex I, points (23) to (26)"},{"label":"Section A and Section B of Annex I trigger different requirement sets","statement":"The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act"},{"label":"Two cumulative conditions for high-risk under Annex I","statement":"The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.","source_locator":"Draft guidelines Annex I, points (27) and (21)"},{"label":"The Article 6(3) filter: four exhaustive grounds, to be read narrowly","statement":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, Article 6(3) sets out four grounds on which a provider may exempt a system from high-risk classification: performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment absent proper human review, and performing a preparatory task. Paragraph (88) of this draft states these grounds are exhaustive but alternative, that there is no separate independent risk test, and that they must be interpreted narrowly because Article 6(3) is an exception to rules that among other things protect fundamental rights. Paragraph (87) states the filter applies only to systems under Article 6(2) and not to systems under Article 6(1). Paragraph (89) states a system always remains high-risk where it performs profiling. Paragraph (90) adds that the filter does not apply where the system forms part of a complex system whose combined intended purpose or joint outputs materially influence an individual decision, including agentic AI. Paragraphs (113) to (116) of this draft describe that this is a self-assessment by the provider, that Article 6(4) requires documenting the assessment before placing on the market and registering in the Article 71 EU database, and that the assessment must contain at least the intended purpose, why the system falls under Article 6(2), which Article 6(3) condition applies and why, and why the system does not perform profiling. Paragraph (117) of these draft guidelines points to Articles 80 and 99 where an authority finds a system was misclassified as non high-risk to circumvent the rules.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)"}],"examples":[{"label":"Awarding social assistance in a municipality: the FRIA and the notification","situation":"A municipality wants to deploy an AI system that sorts applications for social assistance benefits and indicates which files merit extra scrutiny before a case worker decides. The application is already listed in the public algorithm register. The question is what has to be in place before the first citizen passes through this system.","outcome":"Article 27(1) requires deployers which are bodies governed by public law, or private entities providing public services, to perform an assessment of the impact on fundamental rights that the use of a high-risk AI system referred to in Article 6(2) may produce, prior to deploying it, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment covers, among other elements, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the implementation of human oversight measures, and the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(3) provides that once the assessment has been performed, the deployer shall notify the market surveillance authority of its results and submit the filled-out template referred to in paragraph 5 as part of that notification, and that in the case referred to in Article 46(1) deployers may be exempt from that obligation to notify. Article 27(5) provides that the AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.","lesson":"We read Article 27 as making the municipality the most obvious deployer here, and as requiring the assessment to be complete before the first application runs through the system, not as an account rendered afterwards. That duty does depend first on whether this system is high-risk at all: does it help decide entitlement to social assistance, or does it stay within a preparatory or narrowly procedural task under Article 6(3), which closes its own exception again once the system profiles citizens? Answer that question before you start on paragraph 1. An entry in the public algorithm register is on our reading something different from the assessment under paragraph 1, and it does not replace notifying the market surveillance authority of the results. In practice it pays to record the citizen's complaint route and the case worker's room to depart from the signal in the same file, because paragraph 1 asks for precisely those two elements.","source_locator":"Article 27(1), (3) and (5)","provenance":"editorial"},{"label":"Recidivism scoring in police work: when the assessment must be redone","situation":"A police service deploys an AI system that estimates the recidivism risk of a suspect, as an aid to the judgements later made by the prosecution service and the court. The model is subsequently retrained on newer investigative data and use is extended to a second region. The question is whether the assessment made for first use remains adequate.","outcome":"Article 27(1) requires deployers which are bodies governed by public law to perform, prior to deploying a high-risk AI system referred to in Article 6(2), an assessment of the impact on fundamental rights that its use may produce, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the processes in which the system will be used, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm taking into account the information given by the provider pursuant to Article 13, of the implementation of human oversight measures according to the instructions for use, and of the measures to be taken if those risks materialise. Article 27(2) provides that the obligation applies to the first use, that previously conducted impact assessments or existing assessments carried out by the provider may be relied on in similar cases, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(3) provides that the results are notified to the market surveillance authority together with the filled-out template, and that in the case referred to in Article 46(1) an exemption from that notification duty may apply.","lesson":"We read Article 27 as covering a police service as a body governed by public law under paragraph 1, and as an assessment that does not stop at first use: retraining on newer investigative data or extending use to a second region touches the elements of paragraph 1 and, on our reading, calls for updating the record. That retraining also raises a question Article 27 itself does not answer, namely whether the change goes far enough to count as a substantial modification, which would make you a provider in your own right under Article 25. Bear in mind as well that the exception in paragraph 3 concerns, on our reading, the notification and not the assessment itself. Finally, start that assessment only after establishing that the deployment as such is permitted, because Article 5 rules out certain predictive applications in criminal investigation.","source_locator":"Article 27(1)-(3)","provenance":"editorial"},{"label":"Selection at student admission: a DPIA is not yet a FRIA","situation":"A university of applied sciences has an AI system rank applications for a vocational programme, using the exam results of earlier students to calibrate that ranking. A data protection impact assessment already exists for this processing. The question the school asks is whether that also covers the fundamental rights side of admission.","outcome":"Article 27(1) provides that deployers which are bodies governed by public law, or private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the deployer's processes in which the system will be used in line with its intended purpose, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm to those categories, of the implementation of human oversight measures, and of the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(2) provides that the obligation applies to the first use, that the deployer may in similar cases rely on previously conducted impact assessments or existing assessments carried out by the provider, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(4) provides that where an obligation under this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the assessment under paragraph 1 complements that data protection impact assessment.","lesson":"We read Article 27 as placing the education institution that runs this selection itself in the deployer role, but that alone does not settle the duty. Paragraph 1 names bodies governed by public law and private entities providing public services, and whether a state-funded or a private university of applied sciences answers to either description is the question you have to settle first. If it does, an existing data protection impact assessment is on our reading the starting point rather than the last word: paragraph 4 has the fundamental rights assessment sit alongside it, and since Regulation (EU) 2026/1744 that assessment may incorporate or cross-refer to relevant parts of it, so the real question is which elements of paragraph 1 are still missing. For you that means recording which groups of students may be affected, how the admissions committee or the teacher can correct an outcome, and where a rejected applicant can lodge a complaint. If the selection rule or the assessment component underpinning the ranking changes, that is on our reading the moment to update the record, rather than the start of the next academic year.","source_locator":"Article 27(1), (2) and (4)","provenance":"editorial"},{"label":"Health insurer using AI for risk assessment: public or private makes no difference","situation":"A health insurer uses AI for risk assessment and pricing of health and life insurance. The question is whether this falls under point 5(c) of Annex III, and with that whether the Article 27 FRIA duty comes into play.","outcome":"The Commission draft guidelines of 19 May 2026 state that the health and life insurance in point 5(c) may be offered on a private or a public basis: a health insurer governed by public law also falls within it, so long as the system is intended for risk assessment or pricing with regard to natural persons. Privately serviced health insurance counts as an essential private service, even in a Member State with a public healthcare system. Unlike point 5(b), point 5(c) provides no exception for fraud detection. The document is a consultation version: non-binding and not yet final.","lesson":"For the FRIA question point 5(c) counts twice: it makes the system high-risk and it makes you, as deployer, one of the parties Article 27 names. A public-law form or a public healthcare system in your Member State changes nothing there. Do not count on the fraud-detection exception from point 5(b) either: it does not apply here, and a fraud feature alongside risk assessment does not take the system out.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","provenance":"official"}],"standards":[{"label":"prEN 18285: conformity assessment framework for AI systems","summary":"The draft European standard operationalising the conformity assessment procedure of Article 43 and Annex VII.","statement":"prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027."}],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/wanneer-publieke-organisatie-ai-act","follow_up_questions":[{"question":"We use AI to monitor or evaluate employees. What applies?","url":"https://www.praxikon.com/en/antwoord/werknemers-monitoren"},{"question":"We use AI in healthcare. Which AI Act rules apply there?","url":"https://www.praxikon.com/en/antwoord/zorg-medische-ai"},{"question":"What are a deployer’s obligations under Article 26?","url":"https://www.praxikon.com/en/antwoord/artikel-26-deployer-plichten"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}