{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":6,"filters":{"id":null,"type":null,"role":null,"duty_holder":"gpai-model-provider","topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications","legacy_id":"raip:obligation:article-40-42-standards-and-specifications","type":"obligation","slug":"article-40-42-standards-and-specifications","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c","label":"Articles 40 to 42: standards, common specifications and presumption of conformity","summary":"A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.","topics":["conformity","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open is the anchoring of the duty holder. Of the three Articles only Article 41(5) contains a rule of conduct addressed to a role this graph knows: providers of high-risk AI systems or general-purpose AI models must duly justify that they have adopted at least equivalent technical solutions where they do not apply a common specification. The object is anchored on that paragraph. A defensible alternative reading treats Articles 40 to 42 as entirely institutional, with an empty duty holder and `out_of_scope`, and hangs the justification on Article 11 and Annex IV, where the technical documentation is described. On that reading the recommended action and the file below move to the object on Article 11; the substance does not change, the basis does. Also open is where the justification must be recorded. Article 41(5) prescribes no form, no place and no recipient. We read it as belonging in the technical documentation, because that is the only file a market surveillance authority can request under Article 21; that is an inference and not text. Not open is the dating: Articles 40, 41 and 42 sit in Chapter III, Section 5, and that Section is not excepted in the third paragraph of Article 113, so the general application date of the second paragraph governs, 2 August 2026.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:justify-standards-and-specification-choices"],"evidence_ids":["praxikon:eu:ai-act:evidence:standards-conformity-justification-file"],"control_ids":["praxikon:eu:ai-act:control:official-journal-citation-watch"],"template_ids":["praxikon:eu:ai-act:template:article-40-42-legal-text"],"conditions":[{"id":"article-40-42-publication-condition","operator":"all","description":"The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal."},{"id":"article-40-42-justification-condition","operator":"all","description":"The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route."}],"exceptions":[{"id":"article-40-42-presumption-is-rebuttable","operator":"not","description":"A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements."},{"id":"article-40-42-specification-withdrawn","operator":"not","description":"Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis."}],"statements":[{"kind":"official_fact","text":"The final subparagraph of Article 40(2), as added by Article 1, point (17), of Regulation (EU) 2026/1744, provides: the Commission shall request, in accordance with Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation. Article 42(3), added by Article 1, point (18), provides: where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (17) and (18), amending Article 40(2) and Article 42","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 40(1) provides: High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations. Paragraph 2 provides: In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum. When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation. Paragraph 3 provides: The participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(1) provides: The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and: (i) the request has not been accepted by any of the European standardisation organisations; or (ii) the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or (iii) the relevant harmonised standards insufficiently address fundamental rights concerns; or (iv) the harmonised standards do not comply with the request; and (b) no reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period. When drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67. Paragraph 2 provides: Before preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled. Paragraph 3 provides: High-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(4) provides: Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V. Paragraph 5 provides: Where providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto. Paragraph 6 provides: Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 42(1) provides: High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4). Paragraph 2 provides: High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The word everything turns on is presumed. A presumption of conformity is not proof of compliance and it is rebuttable: it shifts who has to demonstrate what, and nothing more. If a market surveillance authority shows that your system in fact does not meet a requirement of Section 2, the standard you applied does not stop that. Two limits set out in the text itself come on top. The first is the coverage limit: the presumption operates only in so far as the standard or the specification covers the requirements or obligations concerned. EN 18286 shows exactly what that means, because the coverage statement accompanying that standard expressly excludes Article 17(2) to (4) and Article 72; whatever falls outside the coverage you substantiate yourself. The second is the publication limit: without a reference in the Official Journal of the European Union no presumption arises, however complete the standard may be. That is why all twelve standard objects in data/ai-act/graph/standards.ts carry guidance and not applicable. So anyone hearing a supplier say that his product meets the European standard and is therefore AI Act compliant is hearing two leaps at once: from coverage to completeness, and from standard to legal effect.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Article 41 is often dismissed as an emergency valve that will never be used, and that is the wrong call. The European standards under standardisation request M/613 are not all available yet: the standards layer in data/ai-act/graph/standards.ts shows one completed EN and six deliverables still at drafting or enquiry stage. That is precisely the state described by the conditions of Article 41(1), point (a)(ii), and point (b), and so the common specification route remains practically relevant. For you that means two things. First, an implementing act may appear for a requirement of Section 2 that you did not see coming and that touches your design choices; those acts are adopted under the examination procedure of Article 98(2) and not in consultation with individual providers. Second, there is then a paragraph that asks something of you directly: paragraph 5. If you do not apply the common specification, you must duly justify that your technical solution is at least equivalent. That is the only place in these three Articles where you have to write something yourself, and the text does not say where. In practice that justification belongs in the technical documentation, because that is the file that has to be handed over upon a reasoned request. Article 42 is narrower than it looks and is overrated for that reason. Paragraph 1 touches only Article 10(4) and not the rest of the data governance of Article 10; paragraph 2 touches only the cybersecurity requirements of Article 15 and only where the references of the scheme under Regulation (EU) 2019/881 have been published in the Official Journal. A certificate under a scheme not yet published yields no presumption, and a presumption on Article 15 says nothing about your Article 9, 11, 12, 13 or 14.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build a coverage matrix per high-risk system and per general-purpose AI model: put every requirement of Section 2 that applies to you in the left column, and next to it which harmonised standard, which common specification or which document of your own covers that requirement. Note per row whether the reference of that standard has been published in the Official Journal of the European Union, because only those rows carry a presumption; the remaining rows call for evidence of your own. For every requirement where a common specification exists that you do not apply, write a justification under Article 41(5): which technical solution you adopted, why it is at least equivalent to what the specification demands, and which test shows it. Include that justification in the technical documentation so that it can travel immediately upon a reasoned request. Set up a standing check on publications in the Official Journal as well: a new reference switches a presumption on, and under Article 41(4) repeals an existing common specification, which can remove the basis under a row of your matrix. If you want to rely on Article 42, record why your training and testing data reflect the geographical, behavioural, contextual or functional setting within which the system is intended to be used, and confine the conclusion to Article 10(4). For the cybersecurity route, first check whether the references of the scheme under Regulation (EU) 2019/881 appear in the Official Journal; without that publication the certificate is a good document with no legal effect under Article 15.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(4); Article 15; Article 43(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis","legacy_id":"raip:obligation:article-4a-bias-testing-legal-basis","type":"obligation","slug":"article-4a-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffee7eb28c48cc8a2586f097f3abec38cbe7590c73e15b9845f9295f8f095d4c","label":"Article 4a: legal basis for bias testing with special categories of personal data","summary":"Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are open here, and the risk runs the other way round than with a right such as Article 86: a broad reading here benefits the controller and not the data subject, because this concerns data on ethnicity, health, religion, trade union membership and sexual orientation. Where in doubt the narrow reading is therefore the safe one. First, the reach of \"other AI systems and models\" in paragraph 2, which on its face covers any AI system and any model and for which no delimitation exists. We read it on its face, but with the threshold in paragraph 2, point (a), as the real boundary: without a consequence for health and safety, fundamental rights or prohibited discrimination there is no basis. A defensible alternative reading is that paragraph 2 is confined to systems comparable to the examples in recital 9, such as scoring tools for permits and public services. Second, the relationship with Article 9 GDPR. Recital 9 states that the extension is subject to the same limitations, conditions and safeguards and thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, so we read Article 4a as the Union law measure that point requires, with the safeguards carried by the six conditions themselves. The counterargument stands against that and has not gone away, but it has narrowed since 27 July 2026: the anchoring sits in a recital and not in the article, and the article itself designates no ground from Article 9(2). What no longer supports that counterargument is Article 2(7). Until 27 July 2026 that paragraph left the GDPR unaffected without reservation, but it was replaced by Article 1, point 2(b), of Regulation (EU) 2026/1744 and now reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The Union legislature therefore carved the reservation out for Article 4a precisely, which points towards reading Article 4a as the Union law measure itself rather than a mere cross-reference to the GDPR. Anyone citing this object while quoting the former wording of Article 2(7) is quoting a replaced provision. A defensible alternative reading remains that a national or Union measure with specific safeguards is still needed alongside it, but it now rests only on the absence of an express designation in the article itself. On the date from which the basis operates, part is settled and part is not. What is settled is what recital 9 says, namely that the basis should apply from the date of entry into application of Regulation (EU) 2024/1689; that has been read and is not a house reading. What remains open is which date this object therefore carries. We hold to 27 July 2026, the day Article 4a entered the text, because a basis that was not yet there was in fact not available. The alternative reading follows recital 9 literally and lets the basis reach back to the date of application of the base Regulation. That difference is not academic for anyone who has to justify processing from that period. The editorial statement below marks that choice as our inference.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted"],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":["praxikon:eu:ai-act:control:bias-testing-data-deletion"],"template_ids":["praxikon:eu:ai-act:template:article-4a-legal-text"],"conditions":[{"id":"article-4a-paragraph-1-high-risk-provider-only","operator":"all","description":"Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2."},{"id":"article-4a-paragraph-2-wider-circle-with-harm-threshold","operator":"all","description":"Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it."},{"id":"article-4a-cumulative-conditions","operator":"all","description":"The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data."}],"exceptions":[{"id":"article-4a-no-duty-to-test","operator":"not","description":"Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, to the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur: (a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data; (b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation; (c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations; (d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties; (e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and (f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 2 provides that providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that: (a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and (b) all of the conditions and safeguards set out in paragraph 1 are applied. Paragraph 2 closes with a separate subparagraph: this paragraph does not create any obligation to conduct such bias detection and correction. Article 4a has no paragraph 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts Article 4a into Regulation (EU) 2024/1689 by Article 1, point 6, and deletes Article 10(5) by Article 1, point 9(b). The same point 9 replaces Article 10(1) and Article 10(6) so that they now refer to the quality criteria in Article 4a(1). The basis therefore no longer sits with the requirements for high-risk systems in Chapter III, but as a standalone article in Chapter I, immediately after Article 4, while Article 10 refers back to it from the outside. In the Dutch language version of the Official Journal the inserted article is numbered \"artikel 4 bis\"; \"Article 4a\" is the English numbering of the same provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same amending Regulation replaces Article 2(7) of Regulation (EU) 2024/1689 by Article 1, point 2(b). Since 27 July 2026 that paragraph reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The previous version of that paragraph carried no such reservation for Article 4a.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 9 of Regulation (EU) 2026/1744 states that bias detection and correction constitute a substantial public interest, that the extended legal basis is subject to the same limitations, conditions and safeguards as the existing Article 10(5), and that this thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, Article 10(2), point (g), of Regulation (EU) 2018/1725 and Article 10, point (a), of Directive (EU) 2016/680. The same recital states that the legal basis established by Article 4a should apply from the date of entry into application of Regulation (EU) 2024/1689, so as to enable providers of high-risk AI systems lawfully to undertake bias detection and correction activities in preparation for compliance with the requirements for high-risk AI systems. Article 4 of the amending Regulation governs only entry into force on the third day following publication and provides for no deferred application; the amended Article 113, third paragraph, point (a), provides that Chapters I and II apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026. Article 4a sits in Chapter I and falls outside that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Three things matter more in practice than the relocation itself. The first is that this article instructs you to do nothing. Paragraph 2 says so in as many words, and no date by which anything must be done belongs with it either. The second, and the more dangerous misreading, is that the move into Chapter I means you may now start collecting sensitive attributes because you want to run fairness measurements. What has widened is the set of parties, not the room inside the basis: recital 9 expressly states that the same limitations, conditions and safeguards apply as under the former Article 10(5). In practice it therefore starts with a written justification of why synthetic or anonymised data do not suffice, and not with assembling a dataset. The third is the condition that bites hardest and appears in no summary: point (d) provides that the data are not transmitted, transferred or otherwise accessed by other parties. That is in effect a ban on outsourcing. An external fairness vendor, a bias auditing firm, a research partner or a cloud party that can reach the data itself does not fit inside this basis, however good the contract. Anyone who intended to buy in their bias testing must run it in house here, or work with data that are not a special category. Finally, watch your own documentation: records of processing, data protection impact assessments and AI policy documents that refer to Article 10(5) have been referring to a deleted provision since 27 July 2026. The same holds for documents citing Article 2(7) to argue that the GDPR prevails without qualification: that paragraph too has been replaced and now expressly reserves Articles 4a and 59. Two dates to close on, and the second is our inference rather than source text. Article 4a sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025, but the provision only entered the text on 27 July 2026; we therefore treat 27 July 2026 as the day the basis actually became available, while recital 9 states that it should apply from the date of entry into application of Regulation (EU) 2024/1689. Finally, note that the requirements in Article 10(2), points (f) and (g), which paragraph 1 refers to, themselves only start to apply on 2 December 2027 for Annex III systems and on 2 August 2028 for Annex I systems. The basis therefore deliberately runs ahead of the duty you use it for, exactly as recital 9 intends.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Carry out the data protection impact assessment before you start. Processing special categories at scale for bias testing engages Article 35 GDPR in almost every case, and Article 4a does not remove that assessment: it supplies the legal basis, not the risk appraisal. Then record, per processing operation, which paragraph of Article 4a you rely on, for which system or model, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access and at what point the data are deleted. In the same pass, review your record of processing activities, your impact assessments and your AI policy documents for references to Article 10(5) and replace them with Article 4a. Set the deletion moment as a monitored deadline rather than an intention, verify that no external party can reach the data, and align the justification with your data protection officer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4a-bias-testing-legal-basis","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification","legacy_id":"raip:obligation:article-52-systemic-risk-classification","type":"obligation","slug":"article-52-systemic-risk-classification","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fda72f0c021ed141ad0881c569a2e4d7e59aefdcec7c95a562b9f547352a974e","label":"Article 52: notification of a GPAI model with systemic risk","summary":"The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"settled","interpretation_note":null,"obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply"],"action_ids":["praxikon:eu:ai-act:action:notify-systemic-risk-threshold","praxikon:eu:ai-act:action:request-systemic-risk-reassessment"],"evidence_ids":["praxikon:eu:ai-act:evidence:systemic-risk-notification-file"],"control_ids":["praxikon:eu:ai-act:control:systemic-risk-notification-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-52-legal-text"],"conditions":[{"id":"article-52-notification-trigger","operator":"all","description":"Applies to the provider of a general-purpose AI model as soon as that model meets the condition in Article 51(1), point (a): high impact capabilities, which under Article 51(2) are presumed where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. The two-week period runs from the moment that requirement is met or it becomes known that it will be met. The second route to systemic risk, a Commission designation under Article 51(1), point (b), or Article 52(4), is not covered here: Article 52(1) refers only to point (a)."}],"exceptions":[{"id":"article-52-legacy-models-transitional","operator":"not","description":"For general-purpose AI models placed on the market before 2 August 2025, Article 111(3) provides that the provider shall take the necessary steps to comply with the obligations of this Regulation by 2 August 2027. For those models the governing date is therefore 2 August 2027 and not the two-week period."}],"statements":[{"kind":"official_fact","text":"Article 51(1), point (a), classifies a general-purpose AI model as a model with systemic risk where it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; Article 51(2) provides that a model is presumed to have such capabilities where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. Article 51(1), point (b), reads in full: based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. The requirement of equivalent capabilities or impact and the anchoring in Annex XIII are therefore part of the norm and not only of the procedure. Article 51(3) provides in addition: the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. The 10^25 threshold above is therefore movable; as long as that act does not exist, the threshold applies as it stands in paragraph 2. See data/ai-act/delegated-acts.json, key praxikon:eu:ai-act:delegated-act:article-51-3-thresholds. Article 52(1) refers only to point (a) and provides that the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met, and that the notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. Paragraph 2 allows the provider to present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although the model meets that requirement, it does not present systemic risks due to its specific characteristics and should therefore not be classified as a general-purpose AI model with systemic risk. Paragraph 3 provides that where the Commission concludes that those arguments are not sufficiently substantiated and the provider was not able to demonstrate that the model does not present systemic risks due to its specific characteristics, it shall reject those arguments and the model shall be considered to be a general-purpose AI model with systemic risk. Paragraph 4 empowers the Commission to designate a model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of the criteria set out in Annex XIII, and empowers it to adopt delegated acts in accordance with Article 97 to amend Annex XIII by specifying and updating the criteria set out in that Annex. Paragraph 5 provides that upon a reasoned request of a provider whose model has been designated pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII, that such a request shall contain objective, detailed and new reasons that have arisen since the designation decision, that providers may request reassessment at the earliest six months after the designation decision, and that where the Commission decides to maintain the designation a further six months must pass. Paragraph 6 provides that the Commission shall ensure that a list of general-purpose AI models with systemic risk is published and kept up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 111 states that the cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Recital 112 states that the provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a model will meet the requirements that lead to the presumption, and that this is especially relevant in relation to the threshold of floating point operations because training takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers are able to know if their model would meet the threshold before the training is completed. The same recital states that in the context of that notification the provider should be able to demonstrate that the model exceptionally does not present systemic risks, that the information allows the AI Office to anticipate the placing on the market of models with systemic risks, and that it is especially important for models planned to be released as open-source. Recital 113 states that the Commission should be empowered to designate a model where it becomes aware that the model meets the requirements which previously had either not been known or of which the provider failed to notify it, and that a system of qualified alerts from the scientific panel should exist in addition to the monitoring activities of the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(3) provides that providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) state in point (63) that a downstream modifier is considered to be the provider of the modified model where the training compute used for the modification is greater than a third of the training compute of the original model, and in point (64) that where the downstream modifier cannot know and cannot estimate the original value, that threshold is replaced by a third of 10^25 FLOP where the original model is a model with systemic risk and otherwise by a third of 10^23 FLOP. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1). The guidelines are not binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission enforcement powers for general-purpose AI models and the fine regime of Article 101 have been active since 2 August 2026. Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only duty in this chapter with a numbered deadline, and two weeks is short. Other duties are also tied to a clock, only without a figure: Article 55(1), point (c), requires serious incidents to be reported to the AI Office without undue delay. The question here is therefore not whether you can notify, but whether you see the threshold being crossed in time. Recital 112 leaves little room to push that back: the legislator expressly assumes that the upfront allocation of compute lets you know before training ends that you will meet the threshold. The remaining edge question is how firm that knowledge is for a run not yet allocated, and it is small next to the duty itself. Four things are missed in practice. The first is the transitional rule: if your model was already on the market before 2 August 2025, Article 111(3) gives you until 2 August 2027, and that is the difference between two weeks and two years. The second is the reach of the trigger: only the threshold route of Article 51(1), point (a), starts this clock. If your model is designated by the Commission under Article 51(1), point (b), or Article 52(4), Article 55 begins without Article 52 asking anything of you. The third is the reversal in the last sentence of paragraph 1: if the Commission becomes aware of a model it was not notified about, it may designate it, and you then hold the conversation from a designation rather than from your own file. Since 2 August 2026 the Article 101 fine regime stands behind that. The fourth is the rebuttal route in paragraph 2: those arguments belong with the notification and not after it, so they must already be ready at the moment you notify. Once designated, only paragraph 5 remains, and that route is slow: six months after the decision at the earliest, and only with objective, detailed and new reasons that have arisen since it. The text names the Commission as addressee; recital 112 and Article 55(1), point (c), name the AI Office, which performs this task within the Commission. For an organisation that merely uses an external model this article does not bite: it addresses the provider of the model. That does not put further development out of reach: under point (71) of guidelines C(2025) 5045 final, a party that becomes the provider of a systemic-risk model through a modification must notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model and not merely a user, and whether your model was already on the market before 2 August 2025, because the date in Article 111(3) then applies instead of the two-week period. If you are the provider of a new model, record the planned and the consumed training compute per training run, including pre-training, synthetic data generation and fine-tuning, because recital 111 counts all three. Agree who notifies once the threshold comes into view, so the two-week period is not spent finding an owner, and tie that to the moment compute is allocated rather than to the end of the run. Keep the reasoning with which you would argue that the model does not present systemic risks ready before you notify, because it belongs with the notification. If you have already been designated under paragraph 4, build deliberately towards objective, detailed and new reasons that have arisen since the designation decision, because only those get you to a reassessment after six months. Retain the notification, the substantiation sent with it, any reassessment request and the Commission response as a living file per model version.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-52-systemic-risk-classification","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines C(2025) 5045 final on the scope of the GPAI obligations"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-53-gpai","legacy_id":"raip:obligation:article-53-gpai","type":"obligation","slug":"article-53-gpai","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55f22a1c21f936ec956fc61f7db4f29defb4524294046799c13af57745cd8b36","label":"Article 53: GPAI model providers","summary":"Documentation, information, copyright and transparency duties for providers of general-purpose AI models.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:gpai-document"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-compliance-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-documentation-change-control"],"template_ids":["praxikon:eu:ai-act:template:gpai-guide"],"conditions":[{"id":"gpai-union-market","operator":"all","description":"The party is a provider of a GPAI model placed on the Union market."},{"id":"gpai-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the duties apply from that time. Models placed on the market before 2 August 2025 must comply by 2 August 2027."}],"exceptions":[{"id":"gpai-open-source-limited-exception","operator":"not","description":"The open-source exception is limited and retains, among other things, the copyright policy and public training-content summary. Additional duties apply to models with systemic risk."}],"statements":[{"kind":"official_fact","text":"Article 53 applies since 2 August 2025 to new GPAI models. Providers maintain technical documentation, provide information to downstream providers, operate a Union copyright policy and publish a sufficiently detailed summary of training content.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1), Annex XI and Annex XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable obligations by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An organisation merely using an external GPAI model does not thereby automatically become a GPAI model provider. First determine its role in the value chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Scope and provider qualification guidance","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record model versions, role qualification, documentation owners, downstream information, copyright policy and training summary in one change-controlled file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53 and Annexes XI-XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-53-gpai","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative","legacy_id":"raip:obligation:article-54-gpai-authorised-representative","type":"obligation","slug":"article-54-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c470c29e8f0c2ad222dc0517b6a9437615474bfc6429e9c37b90eb35572d5c5","label":"Article 54: authorised representative of a provider of a GPAI model","summary":"A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-gpai-authorised-representative"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-representative-mandate-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-mandate-review"],"template_ids":["praxikon:eu:ai-act:template:article-54-legal-text"],"conditions":[{"id":"article-54-scope","operator":"all","description":"Applies where the model qualifies as a general-purpose AI model within the meaning of Article 3(63), its provider is established in a third country, and that model is placed on the Union market. The appointment is made by written mandate within the meaning of Article 3(5), which is not only given but also accepted, and it is made before the model is placed on the market. The moment at which the latter occurs is fixed less sharply for a model than for a system; see the editorial interpretation."},{"id":"article-54-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the appointment duty applies from that moment. Providers of models placed on the market before 2 August 2025 shall, under Article 111(3), take the necessary steps to comply with the obligations of the Regulation by 2 August 2027."}],"exceptions":[{"id":"article-54-open-source-exception","operator":"not","description":"Paragraph 6 excludes the obligation for providers of AI models released under a free and open-source licence that allows access, usage, modification and distribution, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available. That exception falls away as soon as the model presents a systemic risk. Whether a given release qualifies is a factual test that has not been settled anywhere; we read it narrowly, so a partially public release does not qualify."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union. Paragraph 2 provides that the provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider. Paragraph 3 provides that the authorised representative shall perform the tasks specified in the mandate received from the provider, that it shall provide a copy of the mandate to the AI Office upon request in one of the official languages of the institutions of the Union, and that for the purposes of the Regulation the mandate shall empower the authorised representative to carry out the following tasks: (a) verify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider; (b) keep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative; (c) provide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in that Chapter; (d) cooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union. Paragraph 4 provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with the Regulation. Paragraph 5 provides that the authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to the Regulation, and that in such a case it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor. Paragraph 6 provides that the obligation set out in that Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 113(3)(b) provides that Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Article 54 sits in Chapter V and therefore applies from 2 August 2025.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. Article 101 is excluded by Article 113(3)(b) from the earlier application of Chapter XII and has therefore applied since 2 August 2026. The obligation in Article 54 has thus applied since 2 August 2025, while the Commission fining power behind it exists only since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in the Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article touches two parties that rarely see themselves that way. The first is the model provider outside the Union that assumes nothing is required until a European customer asks: paragraph 1 places the appointment before the placing on the market, so the representative should exist before the first user in the Union can access the model. The second is the European party that accepts the mandate. It is not stepping into a mailbox role, but note how paragraph 3 is built: the first sentence obliges it to perform the tasks the mandate assigns to it, and only then does the article list what the mandate empowers it to do. Points (a) to (d) are therefore mandate content and empowerment, and its duty runs through them. That is where this article leaves its sharpest question open: is a representative that accepts a mandate omitting task (a) or (b) itself in breach, or does the failure rest entirely with the provider that drew up the mandate. We read paragraph 3 as making the list mandatory minimum content, so that a mandate lacking it does not satisfy the article, which leaves the provider answerable under paragraph 1 and the representative answerable for what it did accept. A defensible alternative reading is that a representative signing without those powers takes on a task it cannot discharge and thereby falls short itself. So do not assume the ten year retention in point (b) rests on you automatically, or automatically does not; write it out. Paragraph 5 closes this off in a way that is often missed: a representative that considers, or has reason to consider, that the provider is breaching its obligations terminates the mandate and immediately informs the AI Office. That is a duty rather than a power, and it calls for access to the documentation agreed in advance and for a moment at which that access is tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Three things about the timeline and the scope. First, the difference between duty and enforcement: the duty has applied since 2 August 2025, but Article 101 is excluded from the earlier application, so the Commission can only fine since 2 August 2026. For a provider outside the Union discovering today that it has no representative, that means: in breach for well over a year, and now also exposed to a fine. Second, the relationship with Article 22. That article carries the same figure for high-risk AI systems, starting on 2 December 2027 and 2 August 2028; Article 54 is the separate route for general-purpose AI models and has applied since 2 August 2025. Anyone looking up the role of authorised representative finds both and needs to know which route applies. Third, the trigger in paragraph 1. The Regulation fixes the moment of placing on the market less sharply for a model than for a system, and for a model made available only through an interface from a third country there is no case law. We read the duty as starting once the model is made available to users in the Union in the course of a commercial activity, because paragraph 1 attaches to placing on the market and not to establishment in the Union. A defensible alternative reading is that making a model available through an interface is not placing the model itself on the market, so that the duty only arises on an actual supply of the model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model or only a user, because only the provider appoints. If you are established outside the Union, put the mandate in writing before the model becomes available here, and write the four tasks in paragraph 3 into it expressly, together with the access to the Annex XI documentation and the point of contact under paragraph 4. If your model was already on the market before 2 August 2025, work to 2 August 2027 rather than to today. If you are only now discovering that there is no representative, assume the duty has run since 2 August 2025 and that the Commission has been able to fine since 2 August 2026; remedy first and record when you did. If you accept a mandate, agree in advance how you carry out the verification in paragraph 3(a), who holds the copy for ten years, and at what moment you test whether termination under paragraph 5 is called for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-54-gpai-authorised-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/54","label":"Read Article 54 in the AI Act Explorer"},{"relation":"related","href":"/en/ai-act/artikel/53","label":"Article 53: the duties the representative verifies"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk","legacy_id":"raip:obligation:article-55-gpai-systemic-risk","type":"obligation","slug":"article-55-gpai-systemic-risk","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589","label":"Article 55: GPAI models with systemic risk","summary":"Additional duties for the most capable general-purpose AI models, on top of Article 53.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record"],"control_ids":["praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control"],"template_ids":["praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text"],"conditions":[{"id":"article-55-gpai-systemic-risk-scope","operator":"all","description":"The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission."}],"exceptions":[{"id":"article-55-gpai-systemic-risk-exception","operator":"not","description":"The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance."}],"statements":[{"kind":"official_fact","text":"Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 55 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":{"nl":"CEN-CENELEC JTC 21: Europese normen onder normalisatieverzoek M/613","en":"CEN-CENELEC JTC 21: European standards under standardisation request M/613"},"publisher":{"nl":"CEN-CENELEC JTC 21","en":"CEN-CENELEC JTC 21"},"canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"952a677040f5a8facb59fc7e89676b9127e1c9e4a36e191112c7f7c1dcd45a94","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:cen-cenelec-jtc21"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"},{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"}]},"links":{"self":"https://www.praxikon.com/api/v1/entities?duty_holder=gpai-model-provider&lang=en","alternate":"https://www.praxikon.com/api/v1/entities?duty_holder=gpai-model-provider&lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}