{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":236,"filters":{"id":null,"type":null,"role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:action:annex-iii-classify","legacy_id":"raip:action:annex-iii-classify","type":"action","slug":"annex-iii-classify","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"45e9f9a5d90d79db8c90f170ae677cbdcf3189bb6e00ce819a3d88bc2a88d521","label":"Classify the use case and document the outcome","summary":"Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:appoint-gpai-authorised-representative","legacy_id":"raip:action:appoint-gpai-authorised-representative","type":"action","slug":"appoint-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f5a3eafa324e8ae8618656496fa8bd7c323e3a6f36d5993f3ab92493fe6d2c10","label":"Appoint an authorised representative and record the mandate","summary":"Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"appoint-gpai-authorised-representative-scope","operator":"all","description":"To be carried out before the model is placed on the Union market, and to be revisited on every change to the model, to the provider establishment or to the licence under which the model is released. For models placed on the market before 2 August 2025, the Article 111(3) period runs until 2 August 2027."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-10-data-governance-act","legacy_id":"raip:action:article-10-data-governance-act","type":"action","slug":"article-10-data-governance-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"07e6caa997eb341b80bd70dbe72375bbb20b6c2e8244781b1a78e5aa78bd5f99","label":"Set up data governance per dataset","summary":"Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-11-technical-documentation-act","legacy_id":"raip:action:article-11-technical-documentation-act","type":"action","slug":"article-11-technical-documentation-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"aac68683836ab7438b276e37db525147120ee1c8b17504deb8afdf463775028e","label":"Build the technical file per Annex IV","summary":"Document system description, development process, data, oversight measures, performance and risk management before market placement.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-12-logging-act","legacy_id":"raip:action:article-12-logging-act","type":"action","slug":"article-12-logging-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bc72111cd908749f45f4505a27037916f84201afd262d163734cd1e1cd1570d6","label":"Design logging into the system","summary":"Ensure the system automatically records events relevant to risk identification and post-market monitoring.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-13-instructions-act","legacy_id":"raip:action:article-13-instructions-act","type":"action","slug":"article-13-instructions-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2c933d039adc24eb26671c5b345f5af373daf4d22eb3eb65ae4cc0613e8d13fd","label":"Provide complete instructions for use","summary":"Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-14-human-oversight-act","legacy_id":"raip:action:article-14-human-oversight-act","type":"action","slug":"article-14-human-oversight-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3db8554f83cb279256051eba2cac4037890fa7aa612a9bec06cdd1419d865da9","label":"Design and assign effective human oversight","summary":"Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-15-accuracy-robustness-act","legacy_id":"raip:action:article-15-accuracy-robustness-act","type":"action","slug":"article-15-accuracy-robustness-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"308f37fc79ba9447a16e936a2d5cd3489b9c5c81080082781cbf3bf9ef6ba128","label":"Set and test performance and security levels","summary":"Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-17-quality-management-act","legacy_id":"raip:action:article-17-quality-management-act","type":"action","slug":"article-17-quality-management-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"353c4c34130f1911c4fc303b0b612f64dc2bf858c7f1ed3188fa121bdc142c2c","label":"Set up an AI quality management system","summary":"Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-4-measures","legacy_id":"raip:action:article-4-measures","type":"action","slug":"article-4-measures","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f3699a4a50d321f929398b3e22a09717b41cb61219099a76c50c7fe3e847bba","label":"Take role- and context-specific AI literacy measures","summary":"Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-5-screen","legacy_id":"raip:action:article-5-screen","type":"action","slug":"article-5-screen","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"04909810be70c58c1d7e803ba7db9de2f0b2097bfaeb94e6b843cfb674568843","label":"Screen every use case against Article 5 first","summary":"Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.","topics":["prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-50-disclosure","legacy_id":"raip:action:article-50-disclosure","type":"action","slug":"article-50-disclosure","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"99fae5953121e6ee0cea8f3714e4532267ff91f1f18cdb816068d17f3aab51f0","label":"Implement the applicable disclosure, marking or label","summary":"First determine which paragraph of Article 50 applies, then implement the specific transparency measure.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act","legacy_id":"raip:action:article-55-gpai-systemic-risk-act","type":"action","slug":"article-55-gpai-systemic-risk-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"22f1e83c282484613e9a5c0fd38afcaa111825c884177c792a1adfa24c94fa94","label":"Perform model evaluations and risk mitigation","summary":"Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-72-post-market-monitoring-act","legacy_id":"raip:action:article-72-post-market-monitoring-act","type":"action","slug":"article-72-post-market-monitoring-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b793dbcac4abe75f52fcb6314e88415f7a052a563c89542abc977881133dd82c","label":"Draw up a post-market monitoring plan","summary":"Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-73-incident-reporting-act","legacy_id":"raip:action:article-73-incident-reporting-act","type":"action","slug":"article-73-incident-reporting-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d21aa0f06e500097b8a63b4ce005a9181eb7330b407cef9d604f6cd6c58109a2","label":"Set up an incident process with reporting routes","summary":"Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline","legacy_id":"raip:action:article-8-state-of-the-art-baseline","type":"action","slug":"article-8-state-of-the-art-baseline","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ab16d4d4fad46ece0ef096efbab0877108130fefed5e739411793b55bc1d6983","label":"Record the state of the art and the intended purpose per system","summary":"Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.","topics":["conformity","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-8-state-of-the-art-baseline-scope","operator":"all","description":"Arises for every system that is high-risk under Article 6, and again on every change of intended purpose, on every release and on every revision of an applied standard or specification."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-9-risk-management-act","legacy_id":"raip:action:article-9-risk-management-act","type":"action","slug":"article-9-risk-management-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9fb9c4c7f569fdd776e6d5beebdde1935651c90f8c6bf6112103703100b69c0a","label":"Set up an iterative risk management process","summary":"Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:assess-safety-component-role","legacy_id":"raip:action:assess-safety-component-role","type":"action","slug":"assess-safety-component-role","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b97e18ebfc6b192d56b5cded8f3b3727de730dad73e5d36b3ecc82cb4580c289","label":"Determine and record whether your AI component is a safety component","summary":"Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"assess-safety-component-role-scope","operator":"all","description":"To be carried out during the design of a product covered by the Union harmonisation legislation listed in Annex I, Section A, and again on every change to the intended purpose or to the function of the AI component."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:assess-significant-design-change","legacy_id":"raip:action:assess-significant-design-change","type":"action","slug":"assess-significant-design-change","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b0fe6ddf25d93b669d1a7aa23de9ab4ee265e0e1ef885cabfb34362eca5c9b3d","label":"Assess for every design change whether it is significant","summary":"Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"assess-significant-design-change-scope","operator":"all","description":"Applies to every high-risk system relying on the transitional rule, from the cut off date for its route: 2 December 2027 for Annex III, 2 August 2028 for Annex I. Continuous, per change, without a deadline of its own. The assessment belongs before the change, because once it is live the switching moment has already passed."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:conformity-ce-registration-act","legacy_id":"raip:action:conformity-ce-registration-act","type":"action","slug":"conformity-ce-registration-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bfb9c4d6c2d511bcb65fe05b5604bbdcf9e4cecdeba886278f79ea41639c38bb","label":"Complete the conformity route before market placement","summary":"Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence","legacy_id":"raip:action:decide-and-record-gpai-code-adherence","type":"action","slug":"decide-and-record-gpai-code-adherence","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15c06567511f04bb7ed8af6b5ef082cca034e6b7c8e7c14048abe48bde7b2b36","label":"Take and record the decision whether you adhere to a code of practice","summary":"Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.","topics":["governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"decide-and-record-gpai-code-adherence-scope","operator":"all","description":"Arises when you place a general-purpose AI model on the Union market, and again whenever a code of practice is reviewed or adapted."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data","legacy_id":"raip:action:enter-and-maintain-eu-database-data","type":"action","slug":"enter-and-maintain-eu-database-data","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"435357e8801ee6d70b189145b8996f90aef44fa99a38559845927d9ab82c6af8","label":"Enter your data in the EU database and keep it up to date","summary":"Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date"],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"enter-and-maintain-eu-database-data-scope","operator":"all","description":"To be carried out before the system is placed on the market, put into service or used, and again on every change that touches one of the entered fields."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:establish-annex-i-product-route","legacy_id":"raip:action:establish-annex-i-product-route","type":"action","slug":"establish-annex-i-product-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1dbf0d3dff28ef691b411a542031d05ce0f9e65ce753b91c2474eaebc7e71fb6","label":"Establish the product route per product","summary":"Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"establish-annex-i-product-route-scope","operator":"all","description":"To be carried out before the product or the AI system is placed on the market or put into service, and again on every change to the product, to the AI function, to the assessment procedure chosen or to the list in Annex I."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:fria-assess","legacy_id":"raip:action:fria-assess","type":"action","slug":"fria-assess","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"060d2e1bc287118ccbb10293b2e58d6beb41edbc3a258713f507550ef6ba6a7e","label":"Perform a FRIA before deployment","summary":"Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:gpai-document","legacy_id":"raip:action:gpai-document","type":"action","slug":"gpai-document","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f7df0039880787783fe41ffab2efdb643b7f698288791536bfb338b5b5bde3f1","label":"Maintain GPAI documentation and transparency information","summary":"Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:keep-high-risk-documentation-available","legacy_id":"raip:action:keep-high-risk-documentation-available","type":"action","slug":"keep-high-risk-documentation-available","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5aa5a6db591797b50c67f1d26168112be16bbf14a3474fec066b623bdba6d2ef","label":"Set up the ten year retention of the system documentation","summary":"Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"keep-high-risk-documentation-available-scope","operator":"all","description":"To be set up before the system is placed on the market or put into service, and to be revisited on every change that leads to new technical documentation or a new declaration of conformity."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:map-system-to-annex-iii-area","legacy_id":"raip:action:map-system-to-annex-iii-area","type":"action","slug":"map-system-to-annex-iii-area","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ec43a226df935b1465f0ea61fd40197b8d386269327ef2574d0a84bb81c6835","label":"Map every system to a point of Annex III","summary":"Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"map-system-to-annex-iii-area-scope","operator":"all","description":"To be carried out before a system is placed on the market or put into service, and again on every change to the intended purpose. Well before 2 December 2027, because the answer determines how much work follows."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:mark-confidential-material-on-submission","legacy_id":"raip:action:mark-confidential-material-on-submission","type":"action","slug":"mark-confidential-material-on-submission","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1a1c83bf26c7b8cc95f52cc0350a637355d9b59e0da7bf6f9156788e1ccd37f8","label":"Mark and register what you submit to an authority or body","summary":"State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"mark-confidential-material-on-submission-scope","operator":"all","description":"Arises on every submission to a market surveillance authority, a notified body, the Commission or the AI Office, and on every registration part of which lands in the secure non-public section of the EU database."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:notify-systemic-risk-threshold","legacy_id":"raip:action:notify-systemic-risk-threshold","type":"action","slug":"notify-systemic-risk-threshold","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"65a8b063463c2dc75b5dc4818d987c332a94fbaca9284ee52d4ac412ac01f266","label":"Notify the Commission within two weeks","summary":"Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"notify-systemic-risk-threshold-scope","operator":"all","description":"To be carried out within two weeks after the requirement in Article 51(1), point (a), is met or after it becomes known that it will be met, and to be revisited for every new model version that touches the threshold. For models placed on the market before 2 August 2025 the date in Article 111(3) applies."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:plan-legacy-public-system-compliance","legacy_id":"raip:action:plan-legacy-public-system-compliance","type":"action","slug":"plan-legacy-public-system-compliance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1664bab006c5a034f299bad5cdd9f511aef0b1803a44e0b72fd9e299d964b701","label":"Plan compliance for legacy public sector systems by 2 August 2030","summary":"Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"plan-legacy-public-system-compliance-scope","operator":"all","description":"Applies once it is established that a high-risk system is intended to be used by public authorities. The 2 August 2030 deadline applies to that group regardless of when the system reached the market and regardless of whether the design changes. To be revisited when the system is replaced, phased out or supplied to a different customer group."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:record-bias-testing-legal-basis","legacy_id":"raip:action:record-bias-testing-legal-basis","type":"action","slug":"record-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b55a1476df5655c40a73f8fa334e80c3ed68ee44e4e178678829be3142ba58fc","label":"Justify and record your reliance on Article 4a","summary":"Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"record-bias-testing-legal-basis-scope","operator":"all","description":"Relevant only where you actually rely on Article 4a. In that case to be recorded before the processing starts, together with the data protection impact assessment, and to be revisited on every change to the purpose, the dataset or the set of people with access."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:request-systemic-risk-reassessment","legacy_id":"raip:action:request-systemic-risk-reassessment","type":"action","slug":"request-systemic-risk-reassessment","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d1f2f468a39d4cd72a817e9481564f17aa5263907196b6cdd5443130244b5145","label":"Request reassessment after a designation","summary":"If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"request-systemic-risk-reassessment-scope","operator":"all","description":"Only available to the provider of a model designated by the Commission under Article 52(4), and only once six months have passed since the designation decision or since a decision to maintain the designation."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:value-chain-representative-act","legacy_id":"raip:action:value-chain-representative-act","type":"action","slug":"value-chain-representative-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2ad75cc7b673736332e11a5f078c439bcc4d6de61a8566c335a9be3e7c4d08f2","label":"Assess the value-chain role per system and change","summary":"On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:verify-notified-body-standing","legacy_id":"raip:action:verify-notified-body-standing","type":"action","slug":"verify-notified-body-standing","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e52601467ef15090bb9a580857cc94205aa84cbc961989f3b5bfc5d601395a87","label":"Check the standing and independence of your notified body","summary":"At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.","topics":["conformity","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"verify-notified-body-standing-scope","operator":"all","description":"Arises as soon as you select or contract a notified body, on every renewal of the assignment, and on every notice of a change to its designation."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:ai-office","legacy_id":"raip:actor:ai-office","type":"actor","slug":"ai-office","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"22316f4ef249535428bf3fda894f06947441411820e6d05de779e863d0e37c3d","label":"AI Office","summary":"The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.","topics":["enforcement","governance","gpai"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:credit-or-insurance-deployer","legacy_id":"raip:actor:credit-or-insurance-deployer","type":"actor","slug":"credit-or-insurance-deployer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"708f7cf67870d5dee4af13b996f46aa5bf169cc0c6dbb59da14d300ee15052e0","label":"Credit or insurance deployer","summary":"A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:deployer","legacy_id":"raip:actor:deployer","type":"actor","slug":"deployer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2e95bd4a7cf24e69e0c77d9a006d5af3d3776312d2232a739e103e8f77cad2fc","label":"Deployer","summary":"An organisation using an AI system under its authority, excluding personal non-professional use.","topics":["governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:gpai-model-provider","legacy_id":"raip:actor:gpai-model-provider","type":"actor","slug":"gpai-model-provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b7d30d797a24d785ce56151a6038c71211a66a2894277e0a39faab35f93f488b","label":"Provider of a GPAI model","summary":"A party that places a general-purpose AI model on the Union market.","topics":["gpai"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:market-surveillance-authority","legacy_id":"raip:actor:market-surveillance-authority","type":"actor","slug":"market-surveillance-authority","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d01741f6ddf8930eff8d0ebfb001c233e657813742eca2a1fb8b7a2dd4428145","label":"Market surveillance authority","summary":"The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.","topics":["enforcement","governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:provider","legacy_id":"raip:actor:provider","type":"actor","slug":"provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d616e5233519c6adf01f00c1f5a3c8f16d7d861ad75579fefad24cd8ebbc2f81","label":"Provider of an AI system","summary":"A party that develops or has an AI system developed and places it on the market under its own name.","topics":["governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:public-law-body","legacy_id":"raip:actor:public-law-body","type":"actor","slug":"public-law-body","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c81c5d001bbe6e2594205af22045d18188224495448db00b5cb56b9d2162e78b","label":"Body governed by public law","summary":"A deployer that is a body governed by public law.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:public-service-provider","legacy_id":"raip:actor:public-service-provider","type":"actor","slug":"public-service-provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd2eae26e231ad222695741b498b82c7e75f3bfb42c035741598964764b9378d","label":"Private provider of public services","summary":"A private deployer providing public services.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2024-08-01-entry-into-force","legacy_id":"raip:change:2024-08-01-entry-into-force","type":"change","slug":"2024-08-01-entry-into-force","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3005c4a62c53f5c6606f6537159ec01ea6aaf834bfdc68728e4d8d8dece75259","label":"The AI Act enters into force","summary":"The regulation entered into force on 1 August 2024, after which the obligations followed in phases.","topics":["timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy","praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2024/1689 appeared in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. Article 113 sets out that most provisions only become applicable later.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable","legacy_id":"raip:change:2025-02-02-prohibitions-and-literacy-applicable","type":"change","slug":"2025-02-02-prohibitions-and-literacy-applicable","version":"1.0.0","effective_at":"2025-02-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"209c8ebc73f368351e91ff2dad213b0429b7cfc89381fafea6e337ed35d7828f","label":"Prohibited practices and AI literacy apply","summary":"Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.","topics":["ai-literacy","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy","praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Chapter I and Chapter II became applicable on 2 February 2025. That makes the prohibited practices the first category with enforceable duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice","legacy_id":"raip:change:2025-07-10-gpai-code-of-practice","type":"change","slug":"2025-07-10-gpai-code-of-practice","version":"1.0.0","effective_at":"2025-07-10T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"524909094d7534dcd6df4dbe2cf53d3f6fc0c5d0be57e07463d0cd313d96040c","label":"General-Purpose AI Code of Practice published","summary":"The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission published the General-Purpose AI Code of Practice on 10 July 2025. Signing is voluntary; signatories can rely on it to demonstrate compliance with the GPAI obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-10T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines","legacy_id":"raip:change:2025-07-18-gpai-guidelines","type":"change","slug":"2025-07-18-gpai-guidelines","version":"1.0.0","effective_at":"2025-07-18T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"951b241022b8676b3140c22c06c12657cb1c5f8930553cd333732ff615d36a91","label":"Guidelines on the scope of the GPAI obligations","summary":"The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5045 final of 18 July 2025 describe the scope of the obligations for providers of GPAI models, including when a party modifying a model becomes a provider itself.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-18T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines","legacy_id":"raip:change:2025-07-29-ai-system-definition-guidelines","type":"change","slug":"2025-07-29-ai-system-definition-guidelines","version":"1.0.0","effective_at":"2025-07-29T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f50ff3430cd1811fa195bea40d12ca839169924ffcb0d8d6aa72772c7838fc62","label":"Guidelines on the definition of an AI system","summary":"The Commission draws the line between software that does and does not fall under the regulation.","topics":["scope"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5053 final of 29 July 2025 explain Article 3(1) through borderline cases, such as classical optimisation, statistical estimation and expert systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-29T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines","legacy_id":"raip:change:2025-07-29-prohibited-practices-guidelines","type":"change","slug":"2025-07-29-prohibited-practices-guidelines","version":"1.0.0","effective_at":"2025-07-29T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c853a0b561615bdd7c5af45302f539140684f35b1fa46f5b21f090e66a821c84","label":"Guidelines on prohibited AI practices","summary":"Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.","topics":["prohibited"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5052 final of 29 July 2025 work out each Article 5 prohibition with examples. The guidelines are non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-29T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable","legacy_id":"raip:change:2025-08-02-gpai-obligations-applicable","type":"change","slug":"2025-08-02-gpai-obligations-applicable","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"029478e4015cda1adb2addf8614ca5fb51f7c72781d5b13d247911ffb5fa99ad","label":"GPAI model obligations apply","summary":"Since 2 August 2025 the obligations for providers of general-purpose AI models apply.","topics":["gpai","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Chapter V became applicable on 2 August 2025. Models placed on the market before that date must comply by 2 August 2027 at the latest.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 53 to 55 and Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines","legacy_id":"raip:change:2026-05-19-draft-high-risk-guidelines","type":"change","slug":"2026-05-19-draft-high-risk-guidelines","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f8996eb1bc4fd2bb4496f27f0be4b686f56122564b91e488e733ad0a50128c31","label":"Draft guidelines on high-risk classification","summary":"The Commission explains in consultation when a system falls under Annex I or Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"On 19 May 2026 the Commission published draft guidelines on the classification of high-risk AI systems for stakeholder consultation, with separate annexes on Annex I and Annex III. The text is non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines of 19 May 2026, annexes on Annex I and Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-05-19T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice","legacy_id":"raip:change:2026-06-10-transparency-code-of-practice","type":"change","slug":"2026-06-10-transparency-code-of-practice","version":"1.0.0","effective_at":"2026-06-10T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ac921e9a99752dc8855683b007914f8b886141207a92b0f2e496a5a28b05c06b","label":"Transparency Code of Practice published","summary":"A voluntary route to comply with parts of Article 50, in two separately signable sections.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Code of Practice on transparency of AI-generated content appeared on 10 June 2026. After a positive adequacy assessment, signatories can rely on it for Article 50(2), (3) and (5). Section 1 addresses providers, section 2 deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:transparency-code-of-practice","source_locator":"Code of Practice on Transparency of AI-generated Content, 10 June 2026","source_url":"https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-06-10T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-12-en-18286-approved","legacy_id":"raip:change:2026-07-12-en-18286-approved","type":"change","slug":"2026-07-12-en-18286-approved","version":"1.0.0","effective_at":"2026-07-12T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f0e540984fe6c775513d06b2c738b5d64f1539828da45102159106383747671","label":"First European AI Act standard approved","summary":"EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"CEN-CENELEC approved EN 18286:2026 on 12 July 2026. It is the first JTC 21 deliverable under standardisation request M/613 to reach the publication stage.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-07-12T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines","legacy_id":"raip:change:2026-07-20-article-50-guidelines","type":"change","slug":"2026-07-20-article-50-guidelines","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"acb754d01dded0d0bbcfe4cc0a6f8a09b3284fd4f485c6bbb8c6c9464ecad1bc","label":"Final guidelines on Article 50","summary":"The Commission works out the transparency duties and confirms they apply from 2 August 2026.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2026) 5054 final of 20 July 2026 work out the notification and marking duties of Article 50, with worked examples for chatbots, deep fakes and AI texts of public interest.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-07-20T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","legacy_id":"raip:change:2026-07-27-annex-iii-date","type":"change","slug":"2026-07-27-annex-iii-date","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a252b9b5dba99234038ed5eb5d01255eee1c9c4c65fb2c6492eabc36135e3c7e","label":"Annex III core rules moved to 2 December 2027","summary":"The amended application date has been binding law since 27 July 2026.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 sets application for Article 6(2) and Annex III on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation","legacy_id":"raip:change:2026-07-27-article-2-13-limitation","type":"change","slug":"2026-07-27-article-2-13-limitation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c71ee2e8cff0bad78dce3f027b001a9787257d56b09f2599217e809efc5ad7d3","label":"New Article 2(13): requirements for Annex I systems may be limited","summary":"Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (3), of Regulation (EU) 2026/1744 adds a paragraph 13 to Article 2. Its final subparagraph provides: by 2 August 2027, the Commission shall adopt delegated acts in accordance with Article 97 in order to supplement this Regulation by specifying the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (3), inserting Article 2(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-4-amended","legacy_id":"raip:change:2026-07-27-article-4-amended","type":"change","slug":"2026-07-27-article-4-amended","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e99fb271a9edefa0ca93ceff84fd425c82bcc7a037c931c0c2b97e3de4b79bb","label":"Article 4 amended to a duty to take measures","summary":"Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-4-measures"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-4-measures-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 amended Article 4 with effect from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 4 amendment and entry into force","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted","legacy_id":"raip:change:2026-07-27-article-4a-inserted","type":"change","slug":"2026-07-27-article-4a-inserted","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8b9ea80c30b7b1348135ff14cda588fe1e19db2dabe15d5bb6e6fd38a836bd7b","label":"Article 4a inserted, Article 10(5) deleted","summary":"Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserted Article 4a and deleted Article 10(5) with effect from 27 July 2026. Anyone justifying a processing operation by reference to Article 10(5) has since been referring to a deleted provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link","legacy_id":"raip:change:2026-07-27-fria-date-and-dpia-link","type":"change","slug":"2026-07-27-fria-date-and-dpia-link","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d67a5efb08ce495fa109c2de2ea7698deb5cb7bfb5a2c791dfa090e582b011e","label":"FRIA follows new date and may cross-reference a DPIA","summary":"The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:fria-assess"],"evidence_ids":["praxikon:eu:ai-act:evidence:fria-report"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The amending regulation links the relevant FRIA route to the new application calendar and expressly enables reuse through a DPIA.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment and amended Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b","legacy_id":"raip:change:2026-07-27-machinery-moved-to-annex-i-b","type":"change","slug":"2026-07-27-machinery-moved-to-annex-i-b","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bc334b0f3c19fbd7ead1a4fcaf1eeb0f0276303ab2afdeeba541bf3e38d55e2","label":"Machinery moves from Annex I, Section A, to Section B","summary":"Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.","topics":["conformity","high-risk","scope"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (41), of Regulation (EU) 2026/1744 provides: Annex I is amended as follows: (a) in Section A, point 1 is deleted; (b) in Section B, the following point is added: 21. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed","legacy_id":"raip:change:2026-07-27-safety-component-narrowed","type":"change","slug":"2026-07-27-safety-component-narrowed","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ed963204383921369662bfcb49af43ff2f3753b60af5fc3b43d495874f12af12","label":"Article 6 gains paragraphs 1a to 1c on safety components","summary":"Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).","topics":["high-risk","scope"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (8), of Regulation (EU) 2026/1744 inserts the following paragraphs into Article 6: 1a. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components. 1b. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards","legacy_id":"raip:change:2026-12-02-new-prohibitions-technical-safeguards","type":"change","slug":"2026-12-02-new-prohibitions-technical-safeguards","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2202ac53e7a1afdb40dd7686939d2e1610f0c1620dab4c72d8c80f8a1e6f6e0b","label":"New prohibitions require technical safeguards","summary":"The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.","topics":["prohibited","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 adds a prohibition on AI intended to generate child sexual abuse material or non-consensual intimate imagery. The required technical safeguards must be in place by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, amendment of Article 5","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2026-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply","legacy_id":"raip:change:2027-08-02-legacy-gpai-models-comply","type":"change","slug":"2027-08-02-legacy-gpai-models-comply","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"17e4e2305767d130376a05e7217cad919dea24364451dfefb06df5708baea73a","label":"Legacy GPAI models must comply","summary":"Models placed on the market before 2 August 2025 have until 2 August 2027.","topics":["gpai","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 111(3) gives providers of GPAI models placed on the market before 2 August 2025 until 2 August 2027 to comply with Chapter V.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational","legacy_id":"raip:change:2027-08-02-sandboxes-operational","type":"change","slug":"2027-08-02-sandboxes-operational","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"56ce8fd9cbe0fcc04361c424890f6bc019291a646e0d5a67e93f4f50fdb07c97","label":"National AI regulatory sandboxes operational on 2 August 2027","summary":"The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (22)(a), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 57(1) with: Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (22)(a), replacing Article 57(1), first subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template","legacy_id":"raip:change:2027-09-02-post-market-monitoring-template","type":"change","slug":"2027-09-02-post-market-monitoring-template","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"df08ab4eea5c80fa9005e4ccfadbf7f19c3b695000c96ca764c1c5312810a1e5","label":"Template for the post-market monitoring plan becomes guidance, by 2 September 2027","summary":"Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.","topics":["high-risk","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (30), of Regulation (EU) 2026/1744 replaces Article 72(3) with: the post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (30), replacing Article 72(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-09-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable","legacy_id":"raip:change:2028-08-02-annex-i-high-risk-applicable","type":"change","slug":"2028-08-02-annex-i-high-risk-applicable","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"139fd5e6f94a689f8d05a09f4653fbe7cab49b5d6ca99447ab28a3373a68e89a","label":"High-risk AI embedded in regulated products","summary":"AI as a safety component of products under Annex I follows on 2 August 2028.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"For AI systems under Article 6(1) and Annex I, that is AI as a safety component of products already covered by EU product legislation, the high-risk requirements apply from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, amended application dates under Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-i-product-route-change-gate","legacy_id":"raip:control:annex-i-product-route-change-gate","type":"control","slug":"annex-i-product-route-change-gate","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"41147ad53e75659681724c69c680f6ff2bfb2f77c57493b2b88f304dd539c613","label":"Reassessment on a change of product or assessment route","summary":"The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.","topics":["control","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger","legacy_id":"raip:control:annex-iii-area-rescan-trigger","type":"control","slug":"annex-iii-area-rescan-trigger","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"65d9b6c9abea4895f3b114bde6ccbbf75e8a218f6ddff7347857f09f72f539ce","label":"Reassessment on a change of intended purpose","summary":"The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-iii-change-trigger","legacy_id":"raip:control:annex-iii-change-trigger","type":"control","slug":"annex-iii-change-trigger","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5e147cd22d5207a8d1912771c7f88764d646fedc6ec79ed6fa684842469257e","label":"Reclassification on purpose or context change","summary":"Reopen classification when intended purpose, use context or system functionality changes materially.","topics":["control","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-10-data-governance-control","legacy_id":"raip:control:article-10-data-governance-control","type":"control","slug":"article-10-data-governance-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a1197480eeb259121cc853f384382755339627047a5fedee4e958dc1be5b3d36","label":"Data check before retraining","summary":"Repeat the data quality assessment before every retraining or dataset change.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-11-technical-documentation-control","legacy_id":"raip:control:article-11-technical-documentation-control","type":"control","slug":"article-11-technical-documentation-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f41fa75300653fe8cf65da2dc464a21a6fe9f1bdce68ba2f0e7bdb2b9d44108","label":"Documentation update on every release","summary":"Update the file before every release and retain earlier versions traceably.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-12-logging-control","legacy_id":"raip:control:article-12-logging-control","type":"control","slug":"article-12-logging-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef6bb673f232b91ca9a7ccc999eaced167d75fe7d5b6c8697976b68841abd1ca","label":"Periodic log review","summary":"Periodically verify that logging works, is complete and is retained according to the regime.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-13-instructions-control","legacy_id":"raip:control:article-13-instructions-control","type":"control","slug":"article-13-instructions-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d5e946dff0be31c1f71ccb47aefb643d221bb4f4509cc213c2072ea7737681a1","label":"Instructions check at deployment","summary":"At every deployment and update, verify instructions are present, current and internally translated.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-14-human-oversight-control","legacy_id":"raip:control:article-14-human-oversight-control","type":"control","slug":"article-14-human-oversight-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55eb68e6c4e828adf673c2be5ab291024de40807686a85097372ca99d2e1e00e","label":"Oversight test before go-live","summary":"Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-15-accuracy-robustness-control","legacy_id":"raip:control:article-15-accuracy-robustness-control","type":"control","slug":"article-15-accuracy-robustness-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"41b67105a6c49d112c6e9d4a83e3863d34c6c2402fa104568390e7e2636e1dfa","label":"Performance monitoring in use","summary":"Monitor whether the system stays within declared levels in production and escalate on deviation.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-17-quality-management-control","legacy_id":"raip:control:article-17-quality-management-control","type":"control","slug":"article-17-quality-management-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e20819d7fa6ff1eec67706612fa84dd4cce163c8ee5ac03b35072f1874fd2328","label":"Internal audit cycle","summary":"Periodically audit whether practice follows the described system and record deviations and improvements.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-18-retention-review","legacy_id":"raip:control:article-18-retention-review","type":"control","slug":"article-18-retention-review","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2f76214c0b47f1f672820a54caf7fca4d6ccdabfc2538b98f066b1829aab06ca","label":"Periodic check on completeness and retrievability of the retention file","summary":"The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-4-periodic-review","legacy_id":"raip:control:article-4-periodic-review","type":"control","slug":"article-4-periodic-review","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0e4f286e8ab077ec312e5c3b2a491e5dd74beae4cce63bcbd8e69d290b511fdd","label":"Periodic role and context review","summary":"Check when systems, roles or risks change whether the selected measures remain appropriate.","topics":["ai-literacy","control"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-5-intake-gate","legacy_id":"raip:control:article-5-intake-gate","type":"control","slug":"article-5-intake-gate","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"37d45153584850ac2fb2b45e6d3da2c33f991d45251f12314162e56611cf0403","label":"Article 5 gate at intake and change","summary":"Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.","topics":["control","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-50-release-check","legacy_id":"raip:control:article-50-release-check","type":"control","slug":"article-50-release-check","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef03e3c5735fc9e8bcd12090e90c9f547541fcc4af4e171bad16fa1b156b6c59","label":"Pre-release transparency check","summary":"Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.","topics":["control","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control","legacy_id":"raip:control:article-55-gpai-systemic-risk-control","type":"control","slug":"article-55-gpai-systemic-risk-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4120e7c4ab88a0b1a21183363aad47c10324fb4199bb46e9966088927a83235c","label":"Compute threshold monitoring","summary":"Monitor cumulative training compute and notify the Commission when the threshold is reached.","topics":["control","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-56-code-commitment-review","legacy_id":"raip:control:article-56-code-commitment-review","type":"control","slug":"article-56-code-commitment-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bef812ac71a549672a98de87ed6db504ebe93e9b284d502b8a9681ed0b3f0ad","label":"Review moment on your reliance on a code of practice","summary":"The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.","topics":["control","governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-72-post-market-monitoring-control","legacy_id":"raip:control:article-72-post-market-monitoring-control","type":"control","slug":"article-72-post-market-monitoring-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c706acb5c18b681ab35cb71fe040a9cfd6ae019bffcaf84a122cb58536095ec0","label":"Signal-to-action loop","summary":"Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.","topics":["control","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-73-incident-reporting-control","legacy_id":"raip:control:article-73-incident-reporting-control","type":"control","slug":"article-73-incident-reporting-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fea3dc4bdbe0c4e36abad77a33369cd226656d4f52f9dde1d0f736f2afb04fb8","label":"Incident drill and deadline watch","summary":"Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.","topics":["control","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-78-disclosure-review","legacy_id":"raip:control:article-78-disclosure-review","type":"control","slug":"article-78-disclosure-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8ecf8b9fd5f0aece19a1cbd0a0187a2921d194f04caa372275204598627b2f92","label":"Review before handing over source code or trade secrets","summary":"The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.","topics":["control","enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-8-integrated-documentation-review","legacy_id":"raip:control:article-8-integrated-documentation-review","type":"control","slug":"article-8-integrated-documentation-review","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f68b5943d7a3ff8db427de0bebec8ef281d9786a4198f8cec879e03f120d7b3d","label":"Review of the overlap with sectoral product documentation","summary":"The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.","topics":["conformity","control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-9-risk-management-control","legacy_id":"raip:control:article-9-risk-management-control","type":"control","slug":"article-9-risk-management-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c3f5ab2befc762f6e21c1f2c74f24043d104c9e229c5edf7b4525254f7f630f","label":"Reassessment on every material change","summary":"Reopen the risk management process on changes in purpose, data, model or use context and before every release.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:bias-testing-data-deletion","legacy_id":"raip:control:bias-testing-data-deletion","type":"control","slug":"bias-testing-data-deletion","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9c6c357526a089a9dcbe2b8d6ba4367e77f55bb6f20e41101cf91993024d9e01","label":"Access and deletion control for bias testing","summary":"The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:conformity-ce-registration-control","legacy_id":"raip:control:conformity-ce-registration-control","type":"control","slug":"conformity-ce-registration-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f3f1746fc31ee9566dd0b6d950a65fe3fbad3185781fbbb10adc10669075ec6b","label":"Reassessment on substantial modification","summary":"Rerun the conformity route whenever the system is substantially modified.","topics":["conformity","control"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:design-change-review-gate","legacy_id":"raip:control:design-change-review-gate","type":"control","slug":"design-change-review-gate","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"717dd89458fe469f5033af10a567225e56493704d9c91fc274fe7be26c3f4f97","label":"Review gate on a design change","summary":"The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:eu-database-entry-currency","legacy_id":"raip:control:eu-database-entry-currency","type":"control","slug":"eu-database-entry-currency","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a76323e94795cd8600b3d4232a3871c6ffb670db39c3cfa01d1dc41b1000a3af","label":"Currency check on the database entry","summary":"The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.","topics":["conformity","control"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:fria-pre-deployment-gate","legacy_id":"raip:control:fria-pre-deployment-gate","type":"control","slug":"fria-pre-deployment-gate","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f26a0d2d91a4c059b5ce23eca62fc6a093d05de3b5ecb275c5c00961f5030af2","label":"Pre-deployment FRIA go/no-go","summary":"Block deployment until applicability, assessment, mitigation and notification have been completed.","topics":["control","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:gpai-documentation-change-control","legacy_id":"raip:control:gpai-documentation-change-control","type":"control","slug":"gpai-documentation-change-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4187977f383ac562ce20b445c452c5c7f1522ebe928ce37cb7ba6ca1e69dc4ab","label":"GPAI documentation change control","summary":"Update documentation and downstream information when the model, capabilities or risks change.","topics":["control","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:gpai-mandate-review","legacy_id":"raip:control:gpai-mandate-review","type":"control","slug":"gpai-mandate-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"abdb7a014ca38dc4812c42694c4c21a0ae8a1ff18298f325e121fb93b02efb17","label":"Periodic review and termination of the mandate","summary":"The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.","topics":["control","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:notified-body-continuity-review","legacy_id":"raip:control:notified-body-continuity-review","type":"control","slug":"notified-body-continuity-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fabcb8697be43cd7e7a5afb718c6e33c634899dffe4109ec6bbea8a2332dd293","label":"Control on the continuity of your conformity assessment","summary":"The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).","topics":["conformity","control","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:safety-component-reassessment-trigger","legacy_id":"raip:control:safety-component-reassessment-trigger","type":"control","slug":"safety-component-reassessment-trigger","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b7a06f34c9bf60a67bc1c01bc2cc893fae70b7505eb55a44f53ab7f338be88f","label":"Reassessment on a change of function or purpose","summary":"The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:systemic-risk-notification-deadline","legacy_id":"raip:control:systemic-risk-notification-deadline","type":"control","slug":"systemic-risk-notification-deadline","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a1360f831fc363afa31b7d27ce19e2052508240de43a2a817385d5e384640dea","label":"Deadline tracking of the notification","summary":"The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:value-chain-representative-control","legacy_id":"raip:control:value-chain-representative-control","type":"control","slug":"value-chain-representative-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"092d622c30e9a7df25f8f59e6f5734fb380006a1e183c6f0e3009f8fe684988a","label":"Role reassessment on every change","summary":"Repeat the role assessment on every rebranding, modification or new use of an existing system.","topics":["control","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-1-biometrics","legacy_id":"raip:definition:annex-iii-area-1-biometrics","type":"definition","slug":"annex-iii-area-1-biometrics","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"06d2c055970a09dc388a0c89907336f3aeb31ab93d97a70346acf440d068bc97","label":"Annex III, point 1: biometrics","summary":"Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Biometrics, in so far as their use is permitted under relevant Union or national law: (a) remote biometric identification systems. This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be; (b) AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics; (c) AI systems intended to be used for emotion recognition.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 1","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area where order matters most: many biometric applications first engage a prohibition under Article 5 and only then the question whether they are high-risk. Note subpoint (b) too: the text covers not only categorisation on sensitive characteristics themselves but also categorisation based on the inference of those characteristics, and that inference element is exactly where this subpoint bites.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 1","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Rules that were not postponed already apply in this area. Article 5(1)(f) has prohibited, since 2 February 2025, AI systems inferring emotions of a natural person in the workplace and in education, except where the system is put into service or placed on the market for medical or safety reasons, and Article 5(1)(g) prohibits biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with the carve-out attached to it that the prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data, or categorising of biometric data in the area of law enforcement. Article 50(3) has required deployers of emotion recognition and biometric categorisation systems, since 2 August 2026, to inform the persons exposed. The date of 2 December 2027 applies to the high-risk rules, not to those prohibitions and that transparency duty.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f) and (g), Article 50(3), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/biometrie","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-2-critical-infrastructure","legacy_id":"raip:definition:annex-iii-area-2-critical-infrastructure","type":"definition","slug":"annex-iii-area-2-critical-infrastructure","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"66333c35ee0160d73cb5ce61d1610c52db447d25b29983457b79cc555e23b11f","label":"Annex III, point 2: critical infrastructure","summary":"Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 2","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The only area without lettered subpoints, and the only one excluded by Article 86 and Article 27: point 2 carries no right to an explanation and no fundamental rights impact assessment. The test sits in the words safety component and management and operation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 2","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/kritieke-infrastructuur","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-3-education-and-vocational-training","legacy_id":"raip:definition:annex-iii-area-3-education-and-vocational-training","type":"definition","slug":"annex-iii-area-3-education-and-vocational-training","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"57245084664bd933a726eef3777437e56c1ef5f6c96e9b9429cb5fd24568f428","label":"Annex III, point 3: education and vocational training","summary":"Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Education and vocational training: (a) AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels; (b) AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels; (c) AI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels; (d) AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 3","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Not limited to schools: every vendor of assessment, placement or proctoring software sits here. Note the context clause in subpoints (c) and (d), which ties them to the context of or within an educational or vocational training institution; proctoring outside that context does not fall under subpoint (d) on the text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 3","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/onderwijs-beroepsopleiding","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-4-employment-and-workers-management","legacy_id":"raip:definition:annex-iii-area-4-employment-and-workers-management","type":"definition","slug":"annex-iii-area-4-employment-and-workers-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ac2c2682bf8940bebd5ad702b407ec6516a260eade226c66defed523d4ac055","label":"Annex III, point 4: employment and workers management","summary":"Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Employment, workers’ management and access to self-employment: (a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates; (b) AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 4","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area touching almost every employer, and where the line between administrative help and evaluating people is crossed fastest without anyone noticing. An employer that is a body governed by public law or provides public services also reaches Article 27 here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 4","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/werkgelegenheid-personeelsbeheer","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-5-essential-private-and-public-services","legacy_id":"raip:definition:annex-iii-area-5-essential-private-and-public-services","type":"definition","slug":"annex-iii-area-5-essential-private-and-public-services","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f02c2c4969764ca9c0b91e14aa9e8d6ab2f968214fc51fc44be7171318ba6e17","label":"Annex III, point 5: essential private and public services","summary":"Annex III, point 5, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Access to and enjoyment of essential private services and essential public services and benefits: (a) AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services; (b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud; (c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance; (d) AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 5","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The broadest area: benefits, healthcare, credit, insurance and emergency services in one point. Subpoint (a) is tied to use by or on behalf of public authorities; subpoints (b) and (c) are not, and they are the only subpoints of Annex III that extend the Article 27 fundamental rights impact assessment to private deployers as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 5","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/essentiele-diensten-voordelen","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-6-law-enforcement","legacy_id":"raip:definition:annex-iii-area-6-law-enforcement","type":"definition","slug":"annex-iii-area-6-law-enforcement","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"baf7a4d2ca4edaa3e113103e3f8dbe2014f50da7f8d4d032da2b27d568c08491","label":"Annex III, point 6: law enforcement","summary":"Annex III, point 6, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Law enforcement, in so far as their use is permitted under relevant Union or national law: (a) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences; (b) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools; (c) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences; (d) AI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups; (e) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 6","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Each of the five subpoints is tied to use by or on behalf of law enforcement authorities or by Union institutions in support of them. A recidivism risk model or profiling system outside that circle therefore does not enter through point 6, however closely it resembles the description; you then have to look at another point or at Article 5.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 6","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/rechtshandhaving","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-7-migration-asylum-and-border-control","legacy_id":"raip:definition:annex-iii-area-7-migration-asylum-and-border-control","type":"definition","slug":"annex-iii-area-7-migration-asylum-and-border-control","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3356e73db9f1924b55062ac32d12d5de26108cbb13ed199789d0628abc4eac4c","label":"Annex III, point 7: migration, asylum and border control","summary":"Annex III, point 7, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law: (a) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools; (b) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State; (c) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence; (d) AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 7","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"All four subpoints are tied to use by or on behalf of competent public authorities or Union bodies; a vendor builds the system, but the point is engaged by the intended use inside that circle. The exception for verification of travel documents in subpoint (d) is narrow and covers only that verification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 7","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/migratie-asiel-grenscontrole","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-8-justice-and-democratic-processes","legacy_id":"raip:definition:annex-iii-area-8-justice-and-democratic-processes","type":"definition","slug":"annex-iii-area-8-justice-and-democratic-processes","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f8c0153462a12cf70cb67280d79ac23299f6a968dc86474650f7fe27ec697bb","label":"Annex III, point 8: administration of justice and democratic processes","summary":"Annex III, point 8, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Administration of justice and democratic processes: (a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution; (b) AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area reaching beyond the courts themselves: alternative dispute resolution and campaign tools that reach voters directly fall under it too. Subpoint (a) is tied to use by or on behalf of a judicial authority; a legal research tool at a law firm does not fall under it on the text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Duties that were not postponed already apply here as well. The transparency obligations of Article 50 apply since 2 August 2026: a provider of a system generating or manipulating synthetic content must mark that output in a machine readable format, and whoever publishes deepfake content must disclose that the content has been artificially generated or manipulated. That stands apart from the question whether the system is high-risk through point 8.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(2) and (4), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/rechtspleging-democratische-processen","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-i-product-route-record","legacy_id":"raip:evidence:annex-i-product-route-record","type":"evidence","slug":"annex-i-product-route-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6eac0d6037a3d5ce9f190875bb97e869dacbcd30d5147a98b1b9035b46eff115","label":"Product route record","summary":"Per product: the Annex I legal act, the section it falls under after 27 July 2026, the conformity assessment procedure chosen and whether a third party is involved, the harmonised standards any opt-out relies on, the AI functions identified as safety components together with the failure analysis, and the role you carry as a result. This is the file that shows why your system is or is not high risk through Article 6(1).","topics":["evidence","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record","legacy_id":"raip:evidence:annex-iii-area-mapping-record","type":"evidence","slug":"annex-iii-area-mapping-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b4d0c04bcf0db0393cf6bc1c95fbb74c71ef9aa68dca43830d11e05dea625f84","label":"Record of the mapping to a point of Annex III","summary":"Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-classification-record","legacy_id":"raip:evidence:annex-iii-classification-record","type":"evidence","slug":"annex-iii-classification-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4d68ecf14476cac0fc4d5138f0be0dcc68e0abf1ac4cd44ce0aa8e994cb8a7fa","label":"Article 6 and Annex III classification record","summary":"Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.","topics":["evidence","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-10-data-governance-record","legacy_id":"raip:evidence:article-10-data-governance-record","type":"evidence","slug":"article-10-data-governance-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"32f2b963bf38be0fb7c35f6b9c324675a8d24747dacf56cb1b4b161b90f4224b","label":"Data governance file","summary":"Record per dataset of origin, choices, assumptions, bias examination and mitigations.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-11-technical-documentation-record","legacy_id":"raip:evidence:article-11-technical-documentation-record","type":"evidence","slug":"article-11-technical-documentation-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b689bbd5807454d5cdcf7df2eeb1b4551149bd8145913635ee43b8d5960c61c3","label":"Technical file (Annex IV)","summary":"Technical documentation kept current per system version, ready for a supervisor’s request.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-12-logging-record","legacy_id":"raip:evidence:article-12-logging-record","type":"evidence","slug":"article-12-logging-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"36b14e51199191933a3881aae2888e665d8dab5f41d1dd8b64dfee4f9aef7c13","label":"Logs and retention regime","summary":"Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-13-instructions-record","legacy_id":"raip:evidence:article-13-instructions-record","type":"evidence","slug":"article-13-instructions-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9cf5a9282978ba5dcc5f638ecf130b839b7d1013200e9a5ae552edd3ea76a669","label":"Instructions and interpretation file","summary":"The received instructions for use plus their internal translation into work instructions per role.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-14-human-oversight-record","legacy_id":"raip:evidence:article-14-human-oversight-record","type":"evidence","slug":"article-14-human-oversight-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bc9a6564b37a39095b93cffd0ac26e457b39138da1e5b215f988afd2f3b11550","label":"Oversight file per system","summary":"Record of oversight measures, appointed persons, their training and the moments of intervention.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record","legacy_id":"raip:evidence:article-15-accuracy-robustness-record","type":"evidence","slug":"article-15-accuracy-robustness-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"46b259071d6f973b30588fc7952ae2529db2f278e9ee17c2d0cc70c29efee49b","label":"Performance and security file","summary":"Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-17-quality-management-record","legacy_id":"raip:evidence:article-17-quality-management-record","type":"evidence","slug":"article-17-quality-management-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dd98fef1830c5aad4dbb123f0544d3056d5f2910af30df1e36a749e525839a69","label":"QMS documentation","summary":"The documented quality system with procedures, role assignment and references to the underlying files.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-18-retention-dossier","legacy_id":"raip:evidence:article-18-retention-dossier","type":"evidence","slug":"article-18-retention-dossier","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"487d604645cda8cc98d8021b49da2c699b1d45ec3ea95e6eb22362c04ac04d42","label":"Retention file per high-risk system","summary":"Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-4-measures-record","legacy_id":"raip:evidence:article-4-measures-record","type":"evidence","slug":"article-4-measures-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e6a4c07cb2d763eadd2b346ceb4000aaf4341d5c1f7acf66daf5abce9102bb1","label":"AI literacy measures record","summary":"Versioned record of roles, context, measures, participation or instruction and review moments.","topics":["ai-literacy","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-5-screening-record","legacy_id":"raip:evidence:article-5-screening-record","type":"evidence","slug":"article-5-screening-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1c2ae4225779328f997e6a1d522a439d885728d71cf3045eda9abbe2dc24f5b7","label":"Article 5 screening record","summary":"A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion \"no prohibited practice\" is evidence too.","topics":["evidence","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-50-implementation-record","legacy_id":"raip:evidence:article-50-implementation-record","type":"evidence","slug":"article-50-implementation-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f27b10e694ea2bb90ee95fc8f15d1bd35f10975665a57bdc35b4f22a0b1f255f","label":"Transparency implementation record","summary":"Record of scenario, actor, disclosure or marking, technical implementation, test and owner.","topics":["evidence","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record","legacy_id":"raip:evidence:article-55-gpai-systemic-risk-record","type":"evidence","slug":"article-55-gpai-systemic-risk-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"80aec0d15f08b43419b7c3db7adf403eae6ff153b6de6d569741ac2f73e7ec7a","label":"Systemic-risk file","summary":"Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.","topics":["evidence","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record","legacy_id":"raip:evidence:article-56-code-adherence-decision-record","type":"evidence","slug":"article-56-code-adherence-decision-record","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7b7dd0817eeaba14597f377f266eeda19e018e03219c541bfe6bc9f028370ef6","label":"Record of the decision on a code of practice","summary":"Per model: the decision whether or not to adhere to a code of practice, the version and chapter it relates to, the date and the authorised signatory, whether adherence was limited under paragraph 7 to the obligations in Article 53, and, where the decision is negative, the elaboration of your own for the issues in paragraph 2.","topics":["evidence","governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record","legacy_id":"raip:evidence:article-72-post-market-monitoring-record","type":"evidence","slug":"article-72-post-market-monitoring-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a18ec7e58d627144f8421441a9201ab887912716bcd16766e589d779216eef36","label":"Monitoring plan and reports","summary":"The plan as part of the technical documentation plus the periodic analyses and follow-up actions.","topics":["evidence","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-73-incident-reporting-record","legacy_id":"raip:evidence:article-73-incident-reporting-record","type":"evidence","slug":"article-73-incident-reporting-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fb0ba99f9bdac6eefd1c88a6bf50aa6400d1c69556f236bca616a9eb0c2b515f","label":"Incident register and reports","summary":"Record of incidents, analyses, reports to supervisors and corrective measures.","topics":["evidence","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-78-submission-register","legacy_id":"raip:evidence:article-78-submission-register","type":"evidence","slug":"article-78-submission-register","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f0b4c2661b1eff2583e0610b30ab07aff9916ba1ec11d1e0ffcb1379c03fba5","label":"Register of submissions to authorities","summary":"Per submission: which system, which document, which version, to which recipient, on what date, which part was marked confidential, and which purpose the recipient stated.","topics":["enforcement","evidence","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification","legacy_id":"raip:evidence:article-8-state-of-the-art-justification","type":"evidence","slug":"article-8-state-of-the-art-justification","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"176cee8830401ce1f875026a5c8b547a06ec90b0f3764045749971944b8ea2f9","label":"Justification of the state of the art","summary":"Per system and per version: which intended purpose was taken, which standards, specifications, evaluation methods and test sets were treated as the state of the art, which were deliberately not applied and why, who established that, and on what date the record was reviewed again.","topics":["conformity","evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-9-risk-management-record","legacy_id":"raip:evidence:article-9-risk-management-record","type":"evidence","slug":"article-9-risk-management-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"20554dec6405ccab0e623e6efb0f1bdecfb6a777ca09760e48b3981ff0aa3e56","label":"Risk management file","summary":"Versioned record of risk analyses, chosen measures, residual risks and test results per system version.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:bias-testing-necessity-record","legacy_id":"raip:evidence:bias-testing-necessity-record","type":"evidence","slug":"bias-testing-necessity-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eaa43374278cdd83d1669e545e106c809a21f4eddf225586fe7e7ac9f553651c","label":"Necessity file for bias testing","summary":"Per processing operation: the system or model, the paragraph of Article 4a relied on, the justification why synthetic or anonymised data do not suffice, the technical and organisational safeguards applied, the access list, the confirmation that no other party can reach the data, and the deletion date. This is also the text that paragraph 1, point (f), requires in the record of processing activities.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:conformity-ce-registration-record","legacy_id":"raip:evidence:conformity-ce-registration-record","type":"evidence","slug":"conformity-ce-registration-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"abb03c902019896fde8cba3a0acad7168ed37188298d59f9ae7d6916a3271be9","label":"Conformity file","summary":"The assessment, EU declaration of conformity, CE marking and registration proof, per system version.","topics":["conformity","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:eu-database-entry-record","legacy_id":"raip:evidence:eu-database-entry-record","type":"evidence","slug":"eu-database-entry-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"747c0a6a89a43d904575e42fa3906bb5d79d282308d08ef4c0eb964f4fe4a5a0","label":"EU database registration file","summary":"Per system: which Annex VIII data was entered, by which natural person with the legal authority to do so, on what date, in which version, when the entry was last checked against reality, and for a public deployer the URL of the entry made by the provider. This is also the file that shows the public entry and your internal documents say the same thing.","topics":["conformity","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:fria-report","legacy_id":"raip:evidence:fria-report","type":"evidence","slug":"fria-report","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e1a8981a104a700cd8e8138d96d56c30865ee1c30ba8e7757002d59e9dc51a94","label":"FRIA report and notification","summary":"Dated impact assessment, measures, residual risks and, where required, notification to the market surveillance authority.","topics":["evidence","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-compliance-file","legacy_id":"raip:evidence:gpai-compliance-file","type":"evidence","slug":"gpai-compliance-file","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7262c79821f4a681772adcd2c0841fa9bfbb6e4c59124704064543d75cd6d2dc","label":"GPAI compliance file","summary":"Current technical documentation, downstream information, copyright policy and public training summary.","topics":["evidence","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-representative-mandate-file","legacy_id":"raip:evidence:gpai-representative-mandate-file","type":"evidence","slug":"gpai-representative-mandate-file","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c48344fa977400be55c1d5713e695114d36fd9a1af8343301b43ea121cd8eb7b","label":"Mandate file of the authorised representative","summary":"The written mandate itself, in an official language of the institutions of the Union, together with the copy of the Annex XI technical documentation, the contact details of the provider, and the record of the verification under paragraph 3(a). The provider grants the mandate and supplies the documentation; the ten year retention after the placing on the market rests under paragraph 3(b) with the representative, which keeps the file at the disposal of the AI Office and national competent authorities.","topics":["evidence","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:legacy-system-transition-register","legacy_id":"raip:evidence:legacy-system-transition-register","type":"evidence","slug":"legacy-system-transition-register","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a0d73b1e9e6d0a528df9b419472895124c96876c96c0da71e972719d4fa96471","label":"Transition register of legacy high-risk systems","summary":"Per type and model: the date the first unit was placed on the market or put into service, the route and therefore the cut off date, whether it is intended to be used by public authorities, which design changes have been made since that cut off, and per change the judgement whether it was significant with the reasoning and the date. This is the file that shows which track a system was on and why.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:notified-body-standing-record","legacy_id":"raip:evidence:notified-body-standing-record","type":"evidence","slug":"notified-body-standing-record","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"56f9eda5647bd23dbf43d538f9e3e670bb286785ece80df1ce6d64f4aa52eabe","label":"File on the chosen notified body","summary":"Per body: identification number, Member State of establishment, the conformity assessment activities and system types for which it is notified, the date of each check against the public list, the outcome of the independence test, the subcontracted tasks with your written agreement, and every notice of a change to its designation.","topics":["conformity","evidence","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:safety-component-assessment-record","legacy_id":"raip:evidence:safety-component-assessment-record","type":"evidence","slug":"safety-component-assessment-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7eb7584bed3094c35599cf257fb614f7c4d6e40f3d5de6380792ceca8654f80d","label":"Record of the safety component assessment","summary":"Per AI component: the intended purpose, the function inside the product, the failure analysis with its consequence for health and safety, the basis of the third-party conformity assessment, and which of paragraphs 1a, 1b and 1c was applied and why. This is a self-maintained file; the Regulation does not prescribe it, and for products under Annex I, Section B, the technical documentation of Article 11 and Annex IV does not apply at all.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:systemic-risk-notification-file","legacy_id":"raip:evidence:systemic-risk-notification-file","type":"evidence","slug":"systemic-risk-notification-file","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"905f723bedbd08a93711a9b87bff0a323bc966b6062131c4f19119025d149bc0","label":"Systemic-risk notification file","summary":"Per model version: the measured and planned training compute with the scope of recital 111, so including pre-training, synthetic data generation and fine-tuning, the moment the threshold was reached or foreseen, the notification sent with its supporting information, any arguments under paragraph 2, any reassessment request under paragraph 5, and the response or designation decision of the Commission.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:value-chain-representative-record","legacy_id":"raip:evidence:value-chain-representative-record","type":"evidence","slug":"value-chain-representative-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8a1a79ce12646a7074a1a5732b7048064013029c563b9f5c1601a324b774ad09","label":"Value-chain file","summary":"Record per system of role, contractual arrangements on information and cooperation, and the appointment of a representative where required.","topics":["evidence","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-gezichtsherkenning-toegangscontrole","legacy_id":"raip:example:example-artikel-4-gezichtsherkenning-toegangscontrole","type":"example","slug":"example-artikel-4-gezichtsherkenning-toegangscontrole","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"595c5cc236618a40fa4882c79603f0febc9762b4165cdf0ac60b70bdbbe5c457","label":"Facial recognition at access control: the guard behind the camera counts too","summary":"An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) provides that providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. In doing so they must take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, and consider the persons or groups of persons on whom the AI systems are to be used. The same provision states that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read the phrase about the persons on whom the system is used as the centre of gravity for biometrics: whoever stands in front of the camera is subject to the outcome and has little to set against it. That argues for equipping the officer who decides for himself when no match comes back more substantively than the colleague who merely switches the system on and off. The article itself names no sufficient level and expressly states that you need not guarantee one, so where the floor lies for each role stays open. In our assessment a record kept per role, stating the choice made and the reason for it, is easier to defend than one organisation-wide session backed only by an attendance list.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-politie-opsporingsanalyse","legacy_id":"raip:example:example-artikel-4-politie-opsporingsanalyse","type":"example","slug":"example-artikel-4-politie-opsporingsanalyse","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"60ac6751cd1959be17d92f129f223cca3fae064e4dfa4eed6759a8d2f88b5297","label":"Police using AI in investigations: context sets how deep the training goes","summary":"A police force uses AI to search large volumes of investigation files and surface connections a detective would otherwise miss. The outputs feed into the choice of which suspect is pursued further and end up in documents that enter the criminal process. The question is whether one and the same basic instruction is enough for the analyst operating the model and for the detective who acts on its output.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) requires providers and deployers of AI systems to take measures supporting the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The provision prescribes that they take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It also states that this obligation does not require any specific level of AI literacy of any individual to be guaranteed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 4 requires you to weigh the context of use and the people the system is applied to, and in law enforcement both factors run high on our reading. Whether a general introduction to what AI can do is then enough for someone carrying an output into a file that affects a person's position as a suspect, we doubt, but the provision expressly names no level you must guarantee, so that floor is yours to justify. We would record for each role what someone must be able to recognise, for instance that a discovered connection is not yet evidence, and revisit that choice periodically.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-redactie-generatieve-content","legacy_id":"raip:example:example-artikel-4-redactie-generatieve-content","type":"example","slug":"example-artikel-4-redactie-generatieve-content","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c17ece0eea8b5b5b7f25d80eb389c31dbc5e18c57449d3e19d41d7ba2b0a8658","label":"Newsroom with generative AI: do freelancers count within your measures?","summary":"A newsroom uses generative AI to prepare summaries, headlines and imagery, after which an editor finishes the piece and the desk decides to publish. Part of that work sits with freelancers, and an outside agency produces marketing content with the same tools. The question is whether your AI literacy measures must reach those freelancers and that agency, or only the people on the payroll.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) is addressed to providers and deployers of AI systems and requires them to take measures supporting the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The provision requires them to take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It does not require any specific level of AI literacy of any individual to be guaranteed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Alongside staff, the text expressly names other persons dealing with the operation and use of AI systems on your behalf, and we read that as a functional boundary rather than a contractual one. On that reading a freelance editor using your tool inside your workflow and on your instruction sits within your measures, employment contract or not. The outside agency is a harder case: if it works in your environment and on your instruction, the argument that it acts on your behalf holds up, but if it runs its own tools on its own account it is a deployer in its own right, and Article 4 does not say your measures must cover that work. In practice, in our assessment, that means recording in your agreements who works in which role and what instruction you give, rather than trusting the other side to arrange it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-ai-chat-sollicitanten","legacy_id":"raip:example:example-artikel-50-ai-chat-sollicitanten","type":"example","slug":"example-artikel-50-ai-chat-sollicitanten","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bbf1f3c5c8847982509ad7a4d086b513a5e0742db0e4415b178f1cdd5cfe1bc2","label":"AI chat in recruitment and selection: what the applicant must be told","summary":"A recruiter deploys an AI chat that puts candidates through a first screening conversation after they respond to a job posting, and adds their answers to their CV. The chat introduces itself with a first name and writes in a casual conversational tone. The question is whether these applicants reasonably realise that they are talking to an AI system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50(1) requires providers to ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. Article 50(5) provides that this information must be given to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction, and must conform to the applicable accessibility requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read the obviousness test as a question about the audience the system actually meets, and in recruitment and selection that audience is not a trained professional group but a broad set of applicants under pressure who do not yet know the organisation. A human first name and a casual tone push that assessment the wrong way in our view, however well they convert. If you buy the chat rather than build it, Article 50(1) is by its wording addressed to the provider, while you are the one choosing the persona and the entry point; whether putting your own name on such a chat moves you into the provider role is a question Article 50 does not answer. So make the disclosure in the first message a procurement requirement and verify at delivery that it is genuinely there.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-camera-toegangscontrole-categorisatie","legacy_id":"raip:example:example-artikel-50-camera-toegangscontrole-categorisatie","type":"example","slug":"example-artikel-50-camera-toegangscontrole-categorisatie","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"160b7164fde8818b8b2563f5a2e755e5669228072717a49f653bf2ca4c75bee6","label":"Camera at the entrance: access control versus biometric categorisation","summary":"An organisation admits staff through facial recognition at its access control gate and additionally runs a camera in the visitor area that sorts faces into age groups. Both applications run on the same biometric infrastructure and the same images. The question is which of the two requires the people involved to be actively informed.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 count automated facial-recognition access controls among the systems that merely collect data passively and are not capable of an exchange with natural persons, and therefore do not interact within the meaning of Article 50(1). For Article 50(3) they state that, unless the use is prohibited under Article 5(1)(g), the information duty applies to any biometric categorisation system, including outside the high-risk scope, and they give classification by age or gender on the basis of biometric data as an example. Article 50(3) itself carries a further exception for systems permitted by law to detect, prevent or investigate criminal offences. As a way of informing people the guidelines describe a visible notice at each possible entrance to an exhibition room stating that facial images are captured to assign visitors to an age group, provided at the latest at the moment of first exposure.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (30) and points (104) to (108)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that you should map this per processing purpose rather than per camera: the same lens that stays outside Article 50(1) at the access control gate moves inside Article 50(3) as soon as those images place people in a category. Record for each setup what happens to the capture and who the deployer is, because that decides whether a notice belongs at the entrance. The guidelines prescribe no fixed form, but they do fix the moment: the notice has to be there before someone walks into frame, and a line in the privacy statement rarely makes that moment, in our reading.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (30) and points (104) to (108)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-code-assistent","legacy_id":"raip:example:example-artikel-50-code-assistent","type":"example","slug":"example-artikel-50-code-assistent","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fe318cc5831d962473121e1af68d1c399dd3a01e1b3bd89e04d554385ee6a460","label":"Code assistant for developers: an exception, until it faces outward","summary":"A software company uses an AI assistant for code suggestions and code review, available only to professional developers. The same company also runs a helpdesk chatbot for customers.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list code assistance and code review chatbots available only to professional developers as an example where the obviousness exception applies. Chatbots embedded in online platforms or helpdesks, where users may perceive outputs as human-generated, they list as an example where the disclosure duty does apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two AI assistants at the same company, two outcomes. Assess per application who the user is and what they reasonably expect, rather than taking one organisation-wide position on chatbots.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-fraudemeldportaal-bank","legacy_id":"raip:example:example-artikel-50-fraudemeldportaal-bank","type":"example","slug":"example-artikel-50-fraudemeldportaal-bank","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"582aea2e3144049ca4f842c782162a26e0e60300ad221f75347d55f99d05a125","label":"Fraud reporting portal at a bank: why the law enforcement exception drops out","summary":"A bank opens an AI-driven reporting portal where customers can flag suspected fraud around their payment account or loan. The system asks follow-up questions, categorises the report and routes it to fraud detection and, where money laundering signals appear, to the internal reporting team. Because the portal concerns criminal offences, the bank assumes the disclosure duty for direct AI interaction does not apply.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 expressly list AI-assisted fraud reporting hotlines and digital portals operated by financial institutions or public authorities, where users can report suspected financial crimes, as an example that is not exempted and falls within the scope of Article 50(1). They explain that the exception does not apply where the system is available to the public and offers individuals the functionality to report a criminal offence. The fact that the system only gathers details, categorises and prioritises the report while human investigators validate the information before any action is taken does not change that in the guidelines.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, points (48) and (49), list of examples under the law enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In our reading this is where banks most often take the wrong turn: the reporting portal sits organisationally under fraud and compliance, which makes the law enforcement exception feel natural, while it is precisely the public reporting channel that is carved out of that exception. On top of that, the exception is written for use authorised by law for law enforcement purposes, and the guidelines stretch it no further than to other public authorities holding such a legal basis, so in our reading a private bank rarely stands in it at all, before the public reporting channel even comes up. Treat the portal as an ordinary public-facing chat and put the disclosure in the first screen of the conversation. A line in the terms and conditions or a product leaflet is a weak choice for this channel, because by then the person is already telling their story.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, points (48) and (49), list of examples under the law enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-gemeentelijke-ai-tekst","legacy_id":"raip:example:example-artikel-50-gemeentelijke-ai-tekst","type":"example","slug":"example-artikel-50-gemeentelijke-ai-tekst","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"607ccc8ecea80ab82aa178e5832f9ad99914406b4a757935b3aabb504f27a676","label":"AI text from a municipality: when a final check counts as editorial control","summary":"A municipality has an AI system write the web pages about a changed scheme for social assistance and allowances, meant to explain to citizens what they are entitled to. A communications officer reads the text for style and spelling and publishes it. The question is whether this public service thereby falls under the exception to the labelling duty.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 count public administration and public services among the matters of public interest covered by the disclosure duty for published AI text in Article 50(4). For the exception, the guidelines require two cumulative conditions: the AI-generated or manipulated text has undergone human review or editorial control, and a natural or legal person holds editorial responsibility for the publication. They add that human review means a deliberate examination of the substance with fact-checking as a minimum requirement, and that superficial, purely formal or procedural checks such as spell-checking or grammatical correction do not meet it. For the second condition they expect the identity or the function carrying editorial responsibility to be publicly available in an easily findable place.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (131), points (133) to (136) and point (138)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that many municipalities do have a publication process but no identifiable person carrying substantive final responsibility, and that is exactly the hinge of this exception. Assign that role explicitly, make it findable who holds it, and record per page who checked the facts, or otherwise take the simpler route and label the text. Watch the order of steps in your workflow, because an AI tool that substantively rewrites the text after human sign-off removes the ground from under that sign-off.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (131), points (133) to (136) and point (138)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-interne-medewerkersassistent","legacy_id":"raip:example:example-artikel-50-interne-medewerkersassistent","type":"example","slug":"example-artikel-50-interne-medewerkersassistent","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fa7779195063a2d6c102ecd9efa1d0962397eab18f9e9a1016737e97d85efc17","label":"Internal assistant for HR and compliance: an exception with a condition","summary":"An organisation gives staff an internal AI assistant for HR, legal, procurement, compliance and IT questions. Must that assistant disclose at every turn that it is AI?","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list an internal employee-facing assistant for properly trained, AI-literate staff who are aware they are using AI systems for internal organisational purposes as an example where the obviousness exception in Article 50(1) applies.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The guidelines tie this exception explicitly to properly trained, AI-literate staff. Relying on it therefore stands or falls with what you have arranged and can demonstrate on literacy under Article 4: without that record you are leaning on an assumption about your own people.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-klinisch-beslissysteem","legacy_id":"raip:example:example-artikel-50-klinisch-beslissysteem","type":"example","slug":"example-artikel-50-klinisch-beslissysteem","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"373ac7240ce91407219c0e1aa4125e839d59caee1738579bab6fc375dfa28564","label":"Diagnostic support for clinicians: no disclosure duty, still due care","summary":"A hospital deploys an interactive AI system used exclusively by properly trained health professionals to support medical diagnosis and suggest treatments. The question is whether the patient or the clinician must be told it is AI.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list interactive AI systems intended only for properly trained health professionals to support medical diagnosis and suggest treatments as an example where the obviousness exception in Article 50(1) applies: for that user the AI nature is clear.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception attaches to the user, not to the system. The moment the same model also speaks to patients, that ground falls away and the disclosure duty applies as normal. And an exception to Article 50 says nothing about the rest: where it is a medical device or a high-risk application, those regimes continue to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-opsporing-uitzondering","legacy_id":"raip:example:example-artikel-50-opsporing-uitzondering","type":"example","slug":"example-artikel-50-opsporing-uitzondering","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f22913de6679b4a1f4549e5f0135681758c39a74b7ce0d57e99aab9ee6bb2603","label":"Law enforcement: exempt from the disclosure duty, with safeguards","summary":"An authority empowered by law to detect criminal offences wants to deploy an interactive AI system without telling those involved that they are communicating with AI.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50(1) exempts providers of interactive AI systems from the disclosure duty where they are authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties. The Commission guidelines of 20 July 2026 elaborate that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (46), law-enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception is narrow and conditional: it requires a legal basis for the law-enforcement task and appropriate safeguards for third parties. A public task by itself is not enough, and the safeguards are not a footnote but part of the ground you are relying on.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (46), law-enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-beoordelingssysteem-personeel-incidentmelding","legacy_id":"raip:example:example-beoordelingssysteem-personeel-incidentmelding","type":"example","slug":"example-beoordelingssysteem-personeel-incidentmelding","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"10323fa9be53a342a148727da06c2c2e2326f11f0d1102e4586b4686a08f6df9","label":"Performance scoring for staff goes wrong: report or not","summary":"An employer uses an AI system that scores employee performance and lets that score weigh in promotion and dismissal. After a change to the model it turns out that a group of staff was scored too low for months, and decisions have already been taken on those scores. HR wonders whether this is a serious incident and who would have to report it.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) places the duty to report serious incidents on the provider of the high-risk AI system placed on the Union market, towards the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident, with the period taking account of the severity of the incident. Article 73(6) obliges the provider, after reporting, to perform the necessary investigations without delay in relation to the serious incident and the AI system concerned, including a risk assessment and corrective action, cooperating with the competent authorities and, where relevant, with the notified body concerned. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In the workplace the hard part is the awareness trigger in Article 73(2): harm spread thinly across many employees does not arrive as an alarm but trickles in through complaints, a performance review or the works council. Whether systematically low scores that feed into promotion and dismissal amount to a serious incident depends, on our reading, on whether obligations protecting fundamental rights have thereby been infringed within the meaning of Article 3, point (49)(c); Article 73 does not make that assessment for you. Decide in advance which HR signal counts as an incident signal and who puts it in front of the provider that same week, rather than reconstructing that afterwards; Article 26(5) also requires you as deployer, once you have identified a serious incident, to inform the provider immediately and then the importer or distributor and the market surveillance authority. Note finally that the corrective action in Article 73(6) concerns the system; what should happen to promotion or dismissal decisions already taken is, on our reading, not answered by this article and runs through other rules, employment law among them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-biometrische-verificatie-grenspoort","legacy_id":"raip:example:example-biometrische-verificatie-grenspoort","type":"example","slug":"example-biometrische-verificatie-grenspoort","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2f0da23dce88ea57a597d35e2ab6c9bbf07dbbf6bbc17182bbb2203a51e218c","label":"Face comparison at the border gate: verification or identification","summary":"An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that biometric verification falls outside the high-risk classification: one-to-one comparison of presented biometrics with previously stored biometrics, for the sole purpose of confirming that a person is who they claim to be. Where the same capture is additionally compared against a law-enforcement database, it does become remote biometric identification. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Test your biometric application on purpose rather than technology: the same camera and the same model stay outside the high-risk route as long as the comparison is one-to-one and only confirms identity, and fall inside it as soon as that same capture is also held against a database. Record per application what the comparison runs against, because that single design choice moves the entire regime.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ernstig-incident-productielijn-meldtermijn","legacy_id":"raip:example:example-ernstig-incident-productielijn-meldtermijn","type":"example","slug":"example-ernstig-incident-productielijn-meldtermijn","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ebe7b7020fc00e471f22844f0b97ed3e30f6702e78b04c376cd86720ec3d51bd","label":"Serious incident on the production line: who reports and within what deadline","summary":"A manufacturer supplies an AI system that runs as a safety component in a machine on the production line and at the same time drives quality control. At a customer's factory an operator is seriously injured after the machine failed to stop on an anomaly. The question is who reports, to whom, and which clock is already running at that moment.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 73(1) places the reporting of serious incidents on the provider of the high-risk AI system placed on the Union market, addressed to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires that report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the incident, with the reporting period taking account of the severity of the incident. Article 73(4) shortens that to no later than 10 days in the event of the death of a person. Article 73(6) obliges the provider, following the report, to perform the necessary investigations without delay, including a risk assessment and corrective action, and not to perform any investigation involving alteration of the AI system in a way that may affect the subsequent evaluation of the causes of the incident without first informing the competent authorities. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities, and makes Article 73 apply mutatis mutandis where the deployer cannot reach the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1), (2), (4) and (6), and Article 26(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 73(2) as meaning that the clock can already start at the deployer on the factory floor, while the report under Article 73(1) sits with you as the provider of the AI system. That does not leave your customer free to sit still: Article 26(5) gives the deployer a notification route of its own, running past you, the importer or distributor and the market surveillance authority, and makes Article 73 apply mutatis mutandis if you cannot be reached. Fix that route in the contract and in the service line before anything happens. Where an operator is seriously injured but does not die, we read the outer limit of Article 73(2) as the one in play rather than the 10 days of Article 73(4); how much sooner than that outer limit you must report is left open by the text and turns on severity. Bear in mind as well that the reflex to repair the machine immediately and resume production can collide with Article 73(6), because an investigation that alters the system first requires notice to the competent authority. Working that out only during the incident costs days that these deadlines do not allow.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1), (2), (4) and (6), and Article 26(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-bijstandsuitkering-gemeente","legacy_id":"raip:example:example-fria-bijstandsuitkering-gemeente","type":"example","slug":"example-fria-bijstandsuitkering-gemeente","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"563700f6a56bbda6f2fd701e38b2eeb9df22a2523f7612fe1109c68a791ffe42","label":"Awarding social assistance in a municipality: the FRIA and the notification","summary":"A municipality wants to deploy an AI system that sorts applications for social assistance benefits and indicates which files merit extra scrutiny before a case worker decides. The application is already listed in the public algorithm register. The question is what has to be in place before the first citizen passes through this system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) requires deployers which are bodies governed by public law, or private entities providing public services, to perform an assessment of the impact on fundamental rights that the use of a high-risk AI system referred to in Article 6(2) may produce, prior to deploying it, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment covers, among other elements, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the implementation of human oversight measures, and the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(3) provides that once the assessment has been performed, the deployer shall notify the market surveillance authority of its results and submit the filled-out template referred to in paragraph 5 as part of that notification, and that in the case referred to in Article 46(1) deployers may be exempt from that obligation to notify. Article 27(5) provides that the AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (3) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as making the municipality the most obvious deployer here, and as requiring the assessment to be complete before the first application runs through the system, not as an account rendered afterwards. That duty does depend first on whether this system is high-risk at all: does it help decide entitlement to social assistance, or does it stay within a preparatory or narrowly procedural task under Article 6(3), which closes its own exception again once the system profiles citizens? Answer that question before you start on paragraph 1. An entry in the public algorithm register is on our reading something different from the assessment under paragraph 1, and it does not replace notifying the market surveillance authority of the results. In practice it pays to record the citizen's complaint route and the case worker's room to depart from the signal in the same file, because paragraph 1 asks for precisely those two elements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (3) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-recidiverisico-politie","legacy_id":"raip:example:example-fria-recidiverisico-politie","type":"example","slug":"example-fria-recidiverisico-politie","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3136fdfa784bcee684810eafa3fc784e9ff1905adf38d86767b1e6daed7c37da","label":"Recidivism scoring in police work: when the assessment must be redone","summary":"A police service deploys an AI system that estimates the recidivism risk of a suspect, as an aid to the judgements later made by the prosecution service and the court. The model is subsequently retrained on newer investigative data and use is extended to a second region. The question is whether the assessment made for first use remains adequate.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) requires deployers which are bodies governed by public law to perform, prior to deploying a high-risk AI system referred to in Article 6(2), an assessment of the impact on fundamental rights that its use may produce, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the processes in which the system will be used, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm taking into account the information given by the provider pursuant to Article 13, of the implementation of human oversight measures according to the instructions for use, and of the measures to be taken if those risks materialise. Article 27(2) provides that the obligation applies to the first use, that previously conducted impact assessments or existing assessments carried out by the provider may be relied on in similar cases, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(3) provides that the results are notified to the market surveillance authority together with the filled-out template, and that in the case referred to in Article 46(1) an exemption from that notification duty may apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as covering a police service as a body governed by public law under paragraph 1, and as an assessment that does not stop at first use: retraining on newer investigative data or extending use to a second region touches the elements of paragraph 1 and, on our reading, calls for updating the record. That retraining also raises a question Article 27 itself does not answer, namely whether the change goes far enough to count as a substantial modification, which would make you a provider in your own right under Article 25. Bear in mind as well that the exception in paragraph 3 concerns, on our reading, the notification and not the assessment itself. Finally, start that assessment only after establishing that the deployment as such is permitted, because Article 5 rules out certain predictive applications in criminal investigation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-selectie-inschrijving-hogeschool","legacy_id":"raip:example:example-fria-selectie-inschrijving-hogeschool","type":"example","slug":"example-fria-selectie-inschrijving-hogeschool","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81f378ec11bfd5271d13fa170d8d63f220e78317143a657af062421c1512c069","label":"Selection at student admission: a DPIA is not yet a FRIA","summary":"A university of applied sciences has an AI system rank applications for a vocational programme, using the exam results of earlier students to calibrate that ranking. A data protection impact assessment already exists for this processing. The question the school asks is whether that also covers the fundamental rights side of admission.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) provides that deployers which are bodies governed by public law, or private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the deployer's processes in which the system will be used in line with its intended purpose, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm to those categories, of the implementation of human oversight measures, and of the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(2) provides that the obligation applies to the first use, that the deployer may in similar cases rely on previously conducted impact assessments or existing assessments carried out by the provider, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(4) provides that where an obligation under this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the assessment under paragraph 1 complements that data protection impact assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as placing the education institution that runs this selection itself in the deployer role, but that alone does not settle the duty. Paragraph 1 names bodies governed by public law and private entities providing public services, and whether a state-funded or a private university of applied sciences answers to either description is the question you have to settle first. If it does, an existing data protection impact assessment is on our reading the starting point rather than the last word: paragraph 4 has the fundamental rights assessment sit alongside it, and since Regulation (EU) 2026/1744 that assessment may incorporate or cross-refer to relevant parts of it, so the real question is which elements of paragraph 1 are still missing. For you that means recording which groups of students may be affected, how the admissions committee or the teacher can correct an outcome, and where a rejected applicant can lodge a complaint. If the selection rule or the assessment component underpinning the ranking changes, that is on our reading the moment to update the record, rather than the start of the next academic year.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-zorgverzekeraar-risicobeoordeling","legacy_id":"raip:example:example-fria-zorgverzekeraar-risicobeoordeling","type":"example","slug":"example-fria-zorgverzekeraar-risicobeoordeling","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da4c33f856bb8621e0a1ecad5647b97f9511b86d1c9cc729d555166238398e7e","label":"Health insurer using AI for risk assessment: public or private makes no difference","summary":"A health insurer uses AI for risk assessment and pricing of health and life insurance. The question is whether this falls under point 5(c) of Annex III, and with that whether the Article 27 FRIA duty comes into play.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that the health and life insurance in point 5(c) may be offered on a private or a public basis: a health insurer governed by public law also falls within it, so long as the system is intended for risk assessment or pricing with regard to natural persons. Privately serviced health insurance counts as an essential private service, even in a Member State with a public healthcare system. Unlike point 5(b), point 5(c) provides no exception for fraud detection. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For the FRIA question point 5(c) counts twice: it makes the system high-risk and it makes you, as deployer, one of the parties Article 27 names. A public-law form or a public healthcare system in your Member State changes nothing there. Do not count on the fraud-detection exception from point 5(b) either: it does not apply here, and a fraud feature alongside risk assessment does not take the system out.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-hogeschool-aanmelding-toetsing","legacy_id":"raip:example:example-logging-hogeschool-aanmelding-toetsing","type":"example","slug":"example-logging-hogeschool-aanmelding-toetsing","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"87cc04e5994d67a08654e7bda8c7ea6eb508508cf029630e0faf71818cbd70bb","label":"Logging in admission and assessment: what the institution keeps in its own hands","summary":"A university of applied sciences uses a purchased AI system that ranks student admissions and also raises flags during digital assessment. The logs sit in the supplier environment, which hands them over on request. The teaching organisation wonders whether that settles the matter or whether the school retains a duty of its own.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires a high-risk AI system to technically allow for the automatic recording of events (logs) over the lifetime of the system, and Article 12(2) ties that recording to a level of traceability appropriate to the intended purpose of the system. Article 26(6) provides that deployers keep the automatically generated logs to the extent those logs are under their control, for a period appropriate to the intended purpose, of at least six months, unless applicable Union or national law provides otherwise, in particular Union law on the protection of personal data. Article 19(1) places a corresponding retention duty on providers for the logs generated by their systems that are under their control, likewise for at least six months.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"On our reading, the fact that the supplier hosts the logs does not by itself place the school outside Article 26(6): what matters is whether the logs are under its control. The Regulation does not define that notion, and on our reading server location is not decisive in itself; the question is whether you can actually and contractually dispose of those logs, and it has to be answered for each procurement. So agree at procurement that the institution can request, export and itself retain the logs for the chosen period, and record which admission and assessment events that covers. Take data protection into account at the same time, because the same provision allows other Union or national law to cap the retention period.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-productielijn-veiligheidscomponent","legacy_id":"raip:example:example-logging-productielijn-veiligheidscomponent","type":"example","slug":"example-logging-productielijn-veiligheidscomponent","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"624d417df4b70bdd1072de6b663f188dd48de9556bd5866eabfc9f1da5fe3d3a","label":"Logging on the production line: which logs the manufacturer keeps and which the factory keeps","summary":"A manufacturer supplies an AI system that runs as a safety component inside the machinery of a production line and also drives quality control. The factory operating the line keeps only the alerts visible in the local controller; the rest of the recording flows to the supplier environment. The question is who has to keep which logs when it later has to be reconstructed why the line was halted.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the lifetime of the system. Under Article 12(2), those logging capabilities must enable the recording of events relevant for identifying situations that may result in the system presenting a risk within the meaning of Article 79(1) or in a substantial modification, for facilitating the post-market monitoring referred to in Article 72, and for monitoring the operation of the high-risk AI systems referred to in Article 26(5). Article 19(1) obliges providers to keep those automatically generated logs to the extent they are under their control, for a period appropriate to the intended purpose of the system, of at least six months, unless applicable Union or national law provides otherwise. Article 26(6) places a corresponding retention duty on deployers for the logs under their control, with the same six-month floor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 19 together with Article 26(6) as leaving the manufacturer, acting here as the provider, and the factory, acting as the deployer, each with a retention duty of its own for the logs under its control. The Regulation does not say when logs count as being under your control, and on our reading the place where the recording physically lands does not settle that by itself; the question has to be answered system by system. For a production line that means recording which events stay in the machinery controller and which travel to the supplier, and securing access to that second set contractually before you need it. Leave that unarranged and you risk being unable to trace a line stoppage or a quality control rejection back to the behaviour of the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-taakverdeling-werkvloer","legacy_id":"raip:example:example-logging-taakverdeling-werkvloer","type":"example","slug":"example-logging-taakverdeling-werkvloer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"be80038e3b50070a20f07e501c8a3a9c35fff975654135c454e9a4c5a9b96545","label":"Logging in task allocation at work: evidence about the system or a file on the employee","summary":"An employer deploys an AI system that handles task allocation among staff and summarises their performance for the performance review. HR wants to know what record of those outcomes has to be retained when an employee objects months later to a promotion decision.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the lifetime of the system. Article 12(2)(c) names, as one of the purposes of those logging capabilities, monitoring the operation of the systems referred to in Article 26(5), and that paragraph obliges deployers to monitor operation on the basis of the instructions for use and, where relevant, to inform the provider in accordance with Article 72. Article 26(6) obliges deployers to keep the automatically generated logs to the extent they are under their control, for a period appropriate to the intended purpose, of at least six months, unless applicable Union or national law provides otherwise. Article 19(1) sets out a corresponding retention duty for providers, with the same six-month floor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2)(c), Article 19(1) and Article 26(5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 12(2) as putting the logging capabilities there first of all to follow risks, substantial modifications and the operation of the system, not to sharpen judgements about individual staff. Whether that statement of purpose also limits what the retained logs may later be used for is something Article 12 does not say: on our reading that limit has to come from data protection law, to which Article 26(6) itself refers. For HR a practical line follows: keep what is needed to trace an outcome and to carry out the monitoring under Article 26(5), and settle in writing beforehand whether those same files may double as a performance record. Bear in mind that the six-month floor can be shorter than the period within which an employee challenges a promotion decision; the Regulation does not govern that evidential position.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2)(c), Article 19(1) and Article 26(5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-politie-model-bijtrainen-opsporing","legacy_id":"raip:example:example-politie-model-bijtrainen-opsporing","type":"example","slug":"example-politie-model-bijtrainen-opsporing","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f76e99119daefd7c5cfc07f8db92500ea93ce6a13b3e86aff47818a0a15cb89a","label":"Police fine-tuning a model for investigations: settle the role question first","summary":"A police service fine-tunes an open general-purpose model on its own files from ongoing criminal investigations, so that detectives can see links between suspects and cases sooner. The fine-tuned model stays inside the service and is not made available to anyone else. The question is whether the service thereby becomes a provider of a general-purpose AI model itself, and so falls under Article 53.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 53(1) requires providers of general-purpose AI models to do four things: draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at a minimum the information set out in Annex XI so that it can be provided on request to the AI Office and the national competent authorities; draw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the model, containing at a minimum the elements set out in Annex XII; put in place a policy to comply with Union law on copyright and related rights; and draw up and make publicly available a sufficiently detailed summary about the content used for training, according to a template provided by the AI Office. Article 53(2) provides that the obligations under points (a) and (b) do not apply to providers of models released under a free and open-source licence that allows for the access, usage, modification and distribution of the model, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available, and that this exception does not apply to general-purpose AI models with systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Start with your role, because merely using someone else's model does not by itself make you a model provider; Article 53 does not say at what point a service that fine-tunes crosses that line, and the point deserves an explicit answer rather than an assumption. A further question comes before Article 53: whether your fine-tuned investigation model has been placed on the market within the meaning of the Regulation. That it never leaves the service does not settle this on its own, since the Commission's guidelines on the scope of the obligations for providers of general-purpose AI models also treat internal use affecting the rights of natural persons as placing on the market. We read paragraph 2 as attaching the open-source exception to your own model rather than carrying it over automatically from the model you started out with: if you do not publish the weights and architecture of the fine-tuned model, which is the obvious course in criminal matters, then on that reading the exception is not open to you, and the duties under points (c) and (d) remain in place in any event, since paragraph 2 lifts only points (a) and (b). So record, version by version, exactly what you changed, on which data and to what end, because that record is what decides whether you stand here as a user or as a provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-hr-beoordelingssysteem","legacy_id":"raip:example:example-post-market-monitoring-hr-beoordelingssysteem","type":"example","slug":"example-post-market-monitoring-hr-beoordelingssysteem","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"834c3d7f217e8710ac5698e4b555f10d6b66e59eddbb6facca765496ad4b791d","label":"Assessing staff: signals from the workplace flowing back to the provider","summary":"A provider supplies a system that summarises employee performance data and supports HR in promotion decisions. After a year in use, departments turn out to apply it differently than intended, and managers factor the outputs into the performance review. The question is what the provider is supposed to know about that.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system in a manner proportionate to the nature of the AI technologies and the risks of the high-risk AI system. Article 72(2) requires that system to actively and systematically collect, document and analyse relevant data, which may be provided by deployers or collected through other sources, on performance throughout the system's lifetime, allowing the provider to evaluate continuous compliance with the requirements set out in Chapter III, Section 2. Article 72(3) provides that the system is based on a plan forming part of the technical documentation referred to in Annex IV, and instructs the Commission to adopt an implementing act laying down detailed provisions establishing a template for that plan and the list of elements to be included in it; the Regulation sets 2 February 2026 as the date for that act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that use which departs from what was intended is exactly the kind of real-world data paragraph 2 has in mind, because it bears on the human oversight and the intended purpose laid down in Section 2. Paragraph 3 points to a Commission template for which the Regulation sets 2 February 2026 as the date; check whether that template has since been adopted and align with it if so, since paragraph 4 refers to it as well. In the meantime we would not put the design of your monitoring on hold for it: which data you need already follows from the requirements the system must continue to meet. Agree with the organisations using the system on the route by which employee complaints and deviations in assessments reach you.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-proctoring-tentamens","legacy_id":"raip:example:example-post-market-monitoring-proctoring-tentamens","type":"example","slug":"example-post-market-monitoring-proctoring-tentamens","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"683c18d4fac97ff4db4363416589f34e9615625ed4323784e0b292b8d25ad231","label":"Proctoring during exams: which real-world data the institution reports back","summary":"A vendor offers proctoring software that flags possible cheating during exams. Several universities of applied sciences use the system, each with its own assessment formats and its own student populations. The vendor wants to know which real-world data it must keep collecting after roll-out, and from whom.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system, proportionate to the nature of the AI technologies and the risks of the system. Article 72(2) provides that this system actively and systematically collects, documents and analyses relevant data which may be provided by deployers or collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of those systems with the requirements set out in Chapter III, Section 2. Where relevant, monitoring includes an analysis of the interaction with other AI systems. Article 72(3) provides that the system is based on a plan forming part of the technical documentation referred to in Annex IV.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The duty sits with the provider, but the useful signals arise in education itself: unfounded suspicions, student complaints, differences between programmes and assessment formats. Our reading is that paragraph 2 allows deployers to supply that data while leaving the duty to collect and analyse it with the provider. What the article does not settle is the route by which the data reaches you, or whether the institutions are bound to supply it; that is something you have to arrange with them and cannot read out of Article 72. We would therefore fix that route before the system goes live, and would also set out in the plan how you break performance down by assessment format and by group, since an average across all schools hides precisely the pattern you are looking for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-veiligheidscomponent-productielijn","legacy_id":"raip:example:example-post-market-monitoring-veiligheidscomponent-productielijn","type":"example","slug":"example-post-market-monitoring-veiligheidscomponent-productielijn","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1ed8bb9e9486b8528de2cce401e4f0ce0bed59bd284ede4a90ac5703f85dc09","label":"Safety component on the production line: the manufacturer keeps watching after delivery","summary":"A manufacturer supplies an AI safety component that halts machinery on a production line as soon as someone comes too close to the robot. The component already falls under product legislation for machinery, and the manufacturer runs quality control and incident follow-up for it. The question is what Article 72 adds on top of that.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system in a manner proportionate to the nature of the AI technologies and the risks of the high-risk AI system. Article 72(3) provides that this system is based on a post-market monitoring plan, and that the plan forms part of the technical documentation referred to in Annex IV. Article 72(4) gives providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, the choice of integrating the necessary elements described in paragraphs 1, 2 and 3 into those systems and plans, using the template referred to in paragraph 3, provided this achieves an equivalent level of protection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1), (3) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that Article 72 does not force a second, separate monitoring structure here: paragraph 4 gives you the choice of housing the elements in the system and plan you already run under product legislation, using the template from paragraph 3 and as long as the level of protection remains equivalent. That route stands or falls on a question the article does not answer for you: does the applicable product legislation genuinely have an established post-market monitoring system and plan, or do you run quality control and incident follow-up that were never established as such. Beyond that, you need to be able to show that the signals coming off the factory floor genuinely speak to continued compliance with the high-risk AI requirements, and not only to the mechanical safety of the machine. We would therefore record, for each production signal, which requirement it touches, so that integration does not become dilution.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1), (3) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-proctoring-tentamen-incidentmelding","legacy_id":"raip:example:example-proctoring-tentamen-incidentmelding","type":"example","slug":"example-proctoring-tentamen-incidentmelding","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9acab6c994b68ac7110c3307f8907ee18580a895ef51f8ed17588a3e03b73504","label":"Proctoring during an exam overshoots: from signal to reporting duty","summary":"A university of applied sciences uses proctoring software during an online exam and finds that a group of students is systematically and wrongly flagged as suspicious, after which grades were withdrawn. Teaching staff and the examination board want to know whether this pattern is a serious incident and, if so, who has to report it and within what time.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) obliges the provider of a high-risk AI system placed on the Union market to report serious incidents to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established the causal link or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident. Article 73(5) allows an initial, incomplete report followed by a complete report where this is necessary to ensure timely reporting. Article 73(7) provides that upon receiving a report concerning a serious incident as referred to in Article 3, point (49)(c), the market surveillance authority informs the national public authorities or bodies referred to in Article 77(1). Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2), (5) and (7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 73 as meaning that an incident in education is rarely a single dramatic moment: the signal sits in the pattern in exam results, and the institution sees that pattern before the software supplier does. Whether that pattern amounts to a serious incident is a separate question: it turns on whether the wrongful flagging and the withdrawal of grades count as an infringement of obligations protecting fundamental rights within the meaning of Article 3, point (49)(c), and Article 73 does not make that assessment for you. Leaving the question open until your own investigation is finished carries a risk, because the Article 73(2) period runs from awareness. Set up your examination and complaints process so that such a pattern reaches the provider within days; Article 26(5) also puts a notification duty on the institution itself as deployer, towards the provider, the importer or distributor and the market surveillance authority. The initial, incomplete report of Article 73(5) is the pressure valve here; waiting for a finished investigation report is not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2), (5) and (7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur","legacy_id":"raip:example:example-securitymonitoring-kritieke-digitale-infrastructuur","type":"example","slug":"example-securitymonitoring-kritieke-digitale-infrastructuur","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115","label":"Security monitoring by a SaaS company: cybersecurity alone is not a safety component","summary":"A software company supplies a SaaS platform that monitors network traffic at an operator of critical digital infrastructure and reports anomalous patterns to that customer's security team. Its developers see that use at such an operator may fall under point 2 of Annex III and wonder whether their own product therefore becomes a high-risk AI system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that point 2 of Annex III lists AI systems intended to be used as safety components in the management and operation of, among other things, critical digital infrastructure, and that Recital 55 draws a clear distinction between a safety component and a cybersecurity component. To fall within point 2, an AI system must not be used solely for cybersecurity purposes; without a direct safety role it cannot be a safety component in critical infrastructure and therefore cannot be classified as high-risk under Article 6(2). As examples of systems used solely for cybersecurity and thus falling outside point 2, they list an AI honeypot that identifies and neutralises cyber threats in real time, technology that actively engages with potential attackers to learn new attack patterns, a system supporting the detection of unauthorised access, and a system that detects suspicious email addresses and identifies stolen data. They add that an AI system is classified as a safety component in critical infrastructure only where it is used by an entity identified as a critical entity by a Member State under the CER Directive, and that this interpretation does not require that status to be disclosed to a third-party provider. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read this passage as a line drawn function by function rather than customer by customer: the fact that your client operates critical digital infrastructure does not by itself turn your monitoring product into a safety component. What we cannot settle from the text is where mere flagging ends and a safety function begins, because the same guidelines also count monitoring and detecting situations that may directly lead to physical harm among the safety functions. The open question is therefore whether your SaaS platform stands apart from the systems that drive physical control, or in practice becomes part of them. So record, per product function, what the system performs and what it expressly leaves to the operator, because that distinction carries your entire classification and is hard to reconstruct after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-toelating-hogeschool-registratie-eu-databank","legacy_id":"raip:example:example-toelating-hogeschool-registratie-eu-databank","type":"example","slug":"example-toelating-hogeschool-registratie-eu-databank","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3d53527e1fe64875c7712e50282816d365b64c9b924e3a6965b22cf6c50a7dff","label":"Admission system at a higher education institution: who registers in the EU database","summary":"A higher education institution procures an AI system that organises student applications and enrolment and produces an admission recommendation for each candidate in its vocational programmes. The supplier says it handles the conformity assessment itself and affixes the CE marking. What is left unresolved is whether the institution still has a step of its own to take before the system goes into use in its teaching.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 43(2) provides that for high-risk AI systems referred to in points 2 to 8 of Annex III, providers follow the conformity assessment procedure based on internal control set out in Annex VI, which does not provide for the involvement of a notified body. Article 47(1) requires the provider to draw up, for each high-risk AI system, a written machine-readable, physical or electronically signed EU declaration of conformity and to keep it at the disposal of the national competent authorities for ten years after the system has been placed on the market or put into service. Article 49(1) requires the provider or, where applicable, the authorised representative to register themselves and their system in the EU database referred to in Article 71 before an Annex III high-risk system is placed on the market or put into service, with the exception of the systems listed in point 2 of Annex III. Article 49(3) provides that deployers that are public authorities or Union institutions, bodies, offices or agencies, or persons acting on their behalf, register themselves, select the system and register its use in that same database before putting such a system into service or using it, again with the exception of the systems listed in point 2 of Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(2), Article 47(1) and Article 49(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 49 as two separate registrations: paragraph 1 covers the provider and its system, paragraph 3 covers your own use, and on that reading the first does not relieve you of the second. The hinge question for the institution is therefore not whether the supplier does its job, but whether it is a public authority within the meaning of paragraph 3. The Regulation does not define that term, and until that is settled it remains open whether the institution must itself appear in the EU database. In practice we would move the request for the EU declaration of conformity and the registration number into the procurement stage, so that the question does not turn into a blocker just before an application period opens.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(2), Article 47(1) and Article 49(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-triage-spoedeisende-hulp","legacy_id":"raip:example:example-triage-spoedeisende-hulp","type":"example","slug":"example-triage-spoedeisende-hulp","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"62d16510c753780018aa9840884d802dfdc1b68e969a525fc0d205fdd486c3f3","label":"Emergency triage system: two routes to high risk","summary":"A hospital uses AI to prioritise incoming patients at the emergency department. The question is not whether the system is high-risk but by which route: as a medical device under product legislation, or directly under Annex III.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that an emergency healthcare patient triage system may qualify as a medical device; where it then meets Article 6(1), it is high-risk via Annex I and sectoral rules apply. A triage system that is not a medical device is high-risk via Article 6(2) and point 5(d) of Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (334) and (335)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"First establish whether your triage system is a medical device, because that question decides the whole route: via Annex I the assessment travels with the medical conformity assessment and its date, via Annex III the separate timeline of Article 6(2) applies. Either way the outcome is high-risk, so postponing that determination only creates uncertainty about which regime to set up.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (334) and (335)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-webshop-kredietcheck-technisch-dossier","legacy_id":"raip:example:example-webshop-kredietcheck-technisch-dossier","type":"example","slug":"example-webshop-kredietcheck-technisch-dossier","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d78a5fb746a80b877e3392af6e2f5baa03e844e1777db2c3b305ccb327eb0704","label":"Webshop builds its own consumer credit check: what belongs in the file","summary":"A non-food retail chain lets customers pay later in its webshop and decides at checkout whether a consumer qualifies. The team builds that assessment system in house, on top of a pre-trained model supplied by a vendor. The question is what has to be on record before the feature goes live, and who has to put it there.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 11(1) requires the technical documentation of a high-risk AI system to be drawn up before that system is placed on the market or put into service, and to be kept up to date. It must be drawn up so as to demonstrate compliance with the requirements of that Section and to give national competent authorities and notified bodies the necessary information, in a clear and comprehensive form, to assess that compliance; it contains at a minimum the elements set out in Annex IV. Annex IV lists those elements as applicable to the AI system concerned, and asks among other things for the methods and steps performed for development, including, where relevant, recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified by the provider, for the validation and testing procedures used, and for a description of relevant changes made by the provider to the system through its lifecycle. SMEs, including start-ups, may supply those elements in a simplified manner; where they take that route, they must use the simplified form the Commission is to establish for that purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 11 puts the documentation duty on the provider, so the first open question here is who that provider is. If the creditworthiness assessment of consumers counts as high-risk in your situation, then in our reading there is a strong case that a webshop assembling the system itself and putting it into service under its own name is no longer merely a deployer but ends up on the provider side, carrying the documentation duty that comes with it. Article 11 does not settle that allocation of roles, so test it against the definitions and against Article 25 before assuming the file is your vendor's problem. In our reading the hard part in retail is not the first version of the file but the pace afterwards, because a webshop often ships changes per release while the file stays frozen at the state it had when the feature went into service. So contract for the provenance, training and testing information that Annex IV expects from you when you buy the pre-trained model, and assign per release who updates the file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:annex-iii-eight-areas","legacy_id":"raip:obligation:annex-iii-eight-areas","type":"obligation","slug":"annex-iii-eight-areas","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6","label":"Annex III: the eight areas separately","summary":"Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open here is not the text but the boundary and the form. The eight points are reproduced verbatim, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Publishing the points as separate objects is also our choice; the Regulation gives a list and not eight self-standing norms. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own. It also remains unclear how Article 6(3) works out per area: the exception is drafted in general terms, but the profiling proviso bites in almost every case in one area and rarely in another. Finally, we have checked that Regulation (EU) 2026/1744 inserts Article 6(1a) to (1c) without renumbering or amending paragraphs 2 and 3; if that changes, the route in this object changes with it.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:map-system-to-annex-iii-area"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text"],"conditions":[{"id":"annex-iii-eight-areas-intended-purpose","operator":"any","description":"Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes."},{"id":"annex-iii-eight-areas-route","operator":"all","description":"Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order."},{"id":"annex-iii-eight-areas-article-25-role-shift","operator":"any","description":"The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself."}],"exceptions":[{"id":"annex-iii-eight-areas-article-6-3-derogation","operator":"not","description":"Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk."},{"id":"annex-iii-eight-areas-article-6-4-documentation","operator":"all","description":"The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request."}],"statements":[{"kind":"official_fact","text":"The introductory sentence of Annex III reads: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas. Eight numbered areas follow. 1. Biometrics, in so far as their use is permitted under relevant Union or national law. 2. Critical infrastructure. 3. Education and vocational training. 4. Employment, workers’ management and access to self-employment. 5. Access to and enjoyment of essential private services and essential public services and benefits. 6. Law enforcement, in so far as their use is permitted under relevant Union or national law. 7. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law. 8. Administration of justice and democratic processes. The full text of each point, with its lettered subpoints, sits on the object for that area.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex III is not fixed. Article 7(1) empowers the Commission to add or amend use cases in Annex III by delegated act, and Article 7(3) to remove them. Article 7(1)(a) requires the system to be intended for use in one of the areas listed in Annex III. The eight areas are therefore the stable layer; the lettered subpoints inside them can change without the Regulation itself being revised.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 7(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Seven of the eight areas are subdivided into lettered subpoints in the text: point 1 into (a) to (c), point 3 into (a) to (d), point 4 into (a) and (b), point 5 into (a) to (d), point 6 into (a) to (e), point 7 into (a) to (d) and point 8 into (a) and (b). Point 2 has no lettered subpoints. We therefore count twenty-four lettered subpoints across seven areas. That number appears nowhere in the Regulation: it is our count of the text as it stands at our knowledge date, and a delegated act under Article 7 can silently make it stale.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Reading Annex III as one block leads to the wrong question. The question is not whether your organisation works in one of the eight areas, because nearly everyone does: a hospital touches point 5, a school point 3, and every employer point 4. The question is whether the intended purpose of this one system coincides with the description of a lettered subpoint. A CV parser that only deduplicates repeat applications does something other than a system that evaluates candidates, and yet both get filed under recruitment in practice. Note the order too. Points 1, 6 and 7 carry the condition that the use must be permitted, and that is where Article 5 comes first. Emotion recognition in the workplace and in education is prohibited under Article 5(1)(f), except where the system is placed on the market or put into service for medical or safety reasons; whoever reverses that builds a conformity file for something that is not allowed. Finally, the area also determines which duties then weigh heavily. Article 86 gives a right to an explanation for decisions based on any system listed in Annex III other than point 2, and Article 27 requires bodies governed by public law and private providers of public services to carry out a fundamental rights impact assessment on every Annex III route other than point 2, with point 5(b) and (c) extending that duty to any deployer. For systems already on the market before the application date, the separate transitional rule of Article 111(2) applies as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system, record in your register not that it falls under Annex III but which point and which lettered subpoint it touches, with the intended purpose in your own words alongside. The eight area objects sit in the graph under the slugs annex-iii-area-1-biometrics through annex-iii-area-8-justice-and-democratic-processes; refer to those rather than to Annex III as a whole. Add four fields: is the use permitted, and if not, why is Article 5 not engaged; has the Article 6(3) test been carried out, which of the four conditions was met, and has the assessment been documented and the system registered under Article 6(4) and Article 49(2); does the system perform profiling, because the exception then falls away; and who carries the provider role after Article 25. Repeat that record on every change to the intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"related","href":"https://www.praxikon.com/nl/annex-iii","label":"The eight areas on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:annex-iii-high-risk","legacy_id":"raip:obligation:annex-iii-high-risk","type":"obligation","slug":"annex-iii-high-risk","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c0afd1789ed393ba3f9ce04205bd74b4831ff0fd58146108fdd8dd08d2f4f6c9","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-change-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-classifier"],"conditions":[{"id":"annex-iii-listed-purpose","operator":"all","description":"The intended purpose falls within a use case listed in Annex III."},{"id":"article-6-2-route","operator":"all","description":"Classification follows Article 6(2)."}],"exceptions":[{"id":"article-6-3-exception","operator":"not","description":"A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented."}],"statements":[{"kind":"official_fact","text":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-10-data-governance","legacy_id":"raip:obligation:article-10-data-governance","type":"obligation","slug":"article-10-data-governance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b6992c5a6d684dd828c8b00a7239e768eee9d4a5cb4fdbc4fbaee3dbf561d91","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-10-data-governance-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-10-data-governance-record"],"control_ids":["praxikon:eu:ai-act:control:article-10-data-governance-control"],"template_ids":["praxikon:eu:ai-act:template:article-10-data-governance-legal-text"],"conditions":[{"id":"article-10-data-governance-scope","operator":"all","description":"The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data."}],"exceptions":[{"id":"article-10-data-governance-exception","operator":"not","description":"For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions)."}],"statements":[{"kind":"official_fact","text":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-11-technical-documentation","legacy_id":"raip:obligation:article-11-technical-documentation","type":"obligation","slug":"article-11-technical-documentation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15571dc37c23ef11a79a3b7b9b7d5674ee4fc7161cc4a9bb8f62321f66294a2c","label":"Article 11: technical documentation","summary":"The technical file demonstrating before market placement that a high-risk system meets the requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-11-technical-documentation-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-11-technical-documentation-record"],"control_ids":["praxikon:eu:ai-act:control:article-11-technical-documentation-control"],"template_ids":["praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text"],"conditions":[{"id":"article-11-technical-documentation-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-11-technical-documentation-exception","operator":"not","description":"Small providers (SMEs) may provide the documentation in the simplified form established by the Commission."}],"statements":[{"kind":"official_fact","text":"Article 11 requires technical documentation drawn up before market placement, kept up to date and containing the Annex IV elements, so that compliance with Section 2 is demonstrable to supervisors.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buying organisations, Annex IV is the checklist of what you must be able to request contractually from your supplier; without that file you cannot meet your own Article 26 duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the right to access the technical documentation in AI procurement and supplier contracts now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-11-technical-documentation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 11 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-111-legacy-public-systems","legacy_id":"raip:obligation:article-111-legacy-public-systems","type":"obligation","slug":"article-111-legacy-public-systems","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4","label":"Article 111(2): legacy high-risk systems and the 2 August 2030 date","summary":"High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The text above is the consolidated text and has been checked against the Official Journal; what is preliminary is our reading of it. First, the cut off date. The amended paragraph 2 refers not to a date but to the date of application of Chapter III referred to in Article 113, and since the Digital Omnibus Article 113, third paragraph, point (c) gives two: 2 December 2027 for Annex III and 2 August 2028 for Annex I. We therefore read the cut off as route dependent. A defensible alternative reading is that the reference points at the general application date of Chapter III as a whole, that is 2 August 2026, because Sections 4 and 5 of that Chapter were not deferred; on that reading the cut off would effectively still be 2 August 2026. We follow the route dependent reading because point (c) expressly names Sections 1, 2 and 3, and those are the Sections carrying the requirements the grace period exists for. Second, the notion of a significant change in the design. That is not the same wording as the defined substantial modification used elsewhere in the Regulation, and there is no guidance or case law saying whether a model update, a retraining run or a new data source counts. We read it as a change that touches the intended purpose, the functioning or the risk profile, and not as every release. Third, the reach of intended to be used by public authorities. It is unclear whether a system supplied to both public and private customers falls under it in full, and whether a private party carrying out a public task is a public authority. We read the intention as following from the market the system is offered for and not from the legal form of the individual customer.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends","praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable"],"action_ids":["praxikon:eu:ai-act:action:assess-significant-design-change","praxikon:eu:ai-act:action:plan-legacy-public-system-compliance"],"evidence_ids":["praxikon:eu:ai-act:evidence:legacy-system-transition-register"],"control_ids":["praxikon:eu:ai-act:control:design-change-review-gate"],"template_ids":["praxikon:eu:ai-act:template:article-111-legal-text"],"conditions":[{"id":"article-111-2-scope-article-5-unaffected","operator":"all","description":"The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed."},{"id":"article-111-2-scope-limited-to-chapter-iii","operator":"all","description":"The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them."},{"id":"article-111-2-legacy-scope","operator":"all","description":"Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date."},{"id":"article-111-2-type-and-model","operator":"all","description":"The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union."},{"id":"article-111-2-public-authority-deadline","operator":"all","description":"Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged."}],"exceptions":[{"id":"article-111-2-exception-annex-x-systems","operator":"not","description":"Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030."}],"statements":[{"kind":"official_fact","text":"Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The grace period in paragraph 2 applies where the type and model of an AI system has already been placed on the market. If at least one individual unit was lawfully placed on the market or put into service before the cut off date, the grace period also covers other units of the same type and model, which may be offered without additional obligations, requirements or mandatory additional certification, as long as the design remains unchanged. On a significant change to the design after the cut off date the provider must fully comply with all relevant provisions applicable to high-risk AI systems, including the conformity assessment requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this provision is read exactly the wrong way round. Executives hear that existing systems are left alone and conclude that nothing is needed until well into the 2030s. That is wrong in two ways. For a public sector organisation the second sentence gives no escape but a deadline, and it applies whether or not you change anything about the system. And for everyone the transitional rule concerns only the high-risk requirements: Article 4 has been running since February 2025 and Article 50 since August 2026, with legacy generative systems having only until 2 December 2026 to get the machine-readable marking of Article 50(2) in order. The first sentence, moreover, is not a resting place but a switch. As soon as the design is significantly changed you must comply fully with what applies to high-risk systems, the conformity assessment first of all; those duties do follow the shifted calendar of 2 December 2027 and 2 August 2028. That switching moment rarely arises at a time you choose: it arises on a supplier update, a migration or a new data source. Two things therefore matter more than the date itself. You need to know when the first unit of each type and model reached the market, because that is the decisive date and without it you cannot later show which track a system was on. And you need a moment in your change process at which someone assesses whether a change is significant, before it goes live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per type and model of your high-risk AI systems when the first unit was placed on the market or put into service, and whether the system is intended to be used by public authorities. Record that determination with a date and a reasoning, and note which route applies, because that decides whether your cut off is 2 December 2027 or 2 August 2028. For the systems intended for public authority use, set a plan towards 2 August 2030 that counts back from the conformity assessment and the registration, not from the end date. Also build into your change and release process a review moment at which someone records whether an intended design change is significant, before the change goes into production. Separately, check whether Article 111(4) catches you: if so you have until 2 December 2026 for the marking under Article 50(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-12-logging","legacy_id":"raip:obligation:article-12-logging","type":"obligation","slug":"article-12-logging","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"92daf8448d3471e5014ea66a2dc2731909f2689e5e3bdb243f49a75572002f20","label":"Article 12: logging and traceability","summary":"Automatic recording of events over the lifetime of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-12-logging-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-12-logging-record"],"control_ids":["praxikon:eu:ai-act:control:article-12-logging-control"],"template_ids":["praxikon:eu:ai-act:template:article-12-logging-legal-text"],"conditions":[{"id":"article-12-logging-scope","operator":"all","description":"The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control."}],"exceptions":[{"id":"article-12-logging-exception","operator":"not","description":"The retention period may be limited by Union or national law, including data protection."}],"statements":[{"kind":"official_fact","text":"Article 12 requires high-risk AI systems to be technically capable of automatically recording events over their lifetime, for traceability, risk signalling and post-market monitoring; Article 19 and Article 26(6) govern log retention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Logging is the backbone of all other evidence: without logs an incident cannot be reconstructed and a monitoring duty cannot be fulfilled. Buyers should already test whether a system is technically capable of this.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include logging capability and log access as a requirement in every AI purchase and assign the retention regime (who, where, how long) per system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-12-logging","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 12 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-13-instructions","legacy_id":"raip:obligation:article-13-instructions","type":"obligation","slug":"article-13-instructions","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"818266e8912de0d2c95a38a4a16c67b1aad02d10359b3571710fd757c678819b","label":"Article 13: transparency towards deployers","summary":"Comprehensible instructions for use and system information so deployers can operate the system correctly.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-13-instructions-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-13-instructions-record"],"control_ids":["praxikon:eu:ai-act:control:article-13-instructions-control"],"template_ids":["praxikon:eu:ai-act:template:article-13-instructions-legal-text"],"conditions":[{"id":"article-13-instructions-scope","operator":"all","description":"The provider supplies a high-risk system; the deployer uses it according to the instructions."}],"exceptions":[{"id":"article-13-instructions-exception","operator":"not","description":"The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed."}],"statements":[{"kind":"official_fact","text":"Article 13 requires high-risk systems to be designed transparently enough for deployers to interpret and use the output, with instructions covering purpose, accuracy, limitations, human oversight and maintenance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The instructions are the hinge between provider and deployer duties: what the provider fails to supply here, the deployer cannot deliver under Article 26. Ask for it explicitly at procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Translate received instructions per system into internal work instructions per role and record who received them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-13-instructions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 13 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-14-human-oversight","legacy_id":"raip:obligation:article-14-human-oversight","type":"obligation","slug":"article-14-human-oversight","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"02da6ce26c5036d2cdea0842564e14a1227cd8f8e5fe5e67e15b52cd5332f98b","label":"Article 14: human oversight","summary":"High-risk AI must be designed so that humans can effectively oversee it and intervene.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-14-human-oversight-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-14-human-oversight-record"],"control_ids":["praxikon:eu:ai-act:control:article-14-human-oversight-control"],"template_ids":["praxikon:eu:ai-act:template:article-14-human-oversight-legal-text"],"conditions":[{"id":"article-14-human-oversight-scope","operator":"all","description":"The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons."}],"exceptions":[{"id":"article-14-human-oversight-exception","operator":"not","description":"For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there."}],"statements":[{"kind":"official_fact","text":"Article 14 requires high-risk systems to be effectively overseeable by natural persons, with measures enabling them to understand the system, correctly interpret output, remain aware of automation bias, and decide not to use, to disregard or to stop the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Oversight on paper is not oversight: the law names automation bias explicitly, so a human who may only click through does not count. Effective oversight requires understanding, time and mandate, which ties directly into the Article 4 literacy measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Appoint the overseeing persons per (upcoming) high-risk system now, train them specifically and record their mandate to intervene in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-14-human-oversight","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 14 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-15-accuracy-robustness","legacy_id":"raip:obligation:article-15-accuracy-robustness","type":"obligation","slug":"article-15-accuracy-robustness","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d","label":"Article 15: accuracy, robustness and cybersecurity","summary":"Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-15-accuracy-robustness-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record"],"control_ids":["praxikon:eu:ai-act:control:article-15-accuracy-robustness-control"],"template_ids":["praxikon:eu:ai-act:template:article-15-accuracy-robustness-legal-text"],"conditions":[{"id":"article-15-accuracy-robustness-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-15-accuracy-robustness-exception","operator":"not","description":"Systems that continue learning after deployment carry additional requirements to control feedback loops and drift."}],"statements":[{"kind":"official_fact","text":"Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 15 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-17-quality-management","legacy_id":"raip:obligation:article-17-quality-management","type":"obligation","slug":"article-17-quality-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d04f5f23729c5c48f26262f0e266c680dce5753d12543479b1ea672bbe1c6e9","label":"Article 17: quality management system","summary":"The documented quality system through which a high-risk AI provider structurally assures compliance.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-17-quality-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-17-quality-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-17-quality-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-17-quality-management-legal-text"],"conditions":[{"id":"article-17-quality-management-scope","operator":"all","description":"The provider places high-risk AI systems on the market or puts them into service."}],"exceptions":[{"id":"article-17-quality-management-exception","operator":"not","description":"Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form."}],"statements":[{"kind":"official_fact","text":"Article 17 requires a documented quality management system covering a compliance strategy, design and development procedures, data management, risk management, post-market monitoring, incident reporting and an accountability structure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The QMS is the umbrella over all other provider duties: those with the separate files but no system connecting them fail exactly this article in an audit.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build the QMS not as a separate document but as an index on top of the existing files (risk, data, documentation, monitoring) with owners per procedure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-17-quality-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 17 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-18-document-retention","legacy_id":"raip:obligation:article-18-document-retention","type":"obligation","slug":"article-18-document-retention","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb","label":"Article 18: documentation keeping","summary":"The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:keep-high-risk-documentation-available"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-18-retention-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-18-retention-review"],"template_ids":["praxikon:eu:ai-act:template:article-18-legal-text"],"conditions":[{"id":"article-18-scope","operator":"all","description":"Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service."},{"id":"article-18-financial-institutions-regime","operator":"all","description":"Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a) the technical documentation referred to in Article 11; (b) the documentation concerning the quality management system referred to in Article 17; (c) the documentation concerning the changes approved by notified bodies, where applicable; (d) the decisions and other documents issued by the notified bodies, where applicable; (e) the EU declaration of conformity referred to in Article 47. Paragraph 2 provides that each Member State shall determine conditions under which that documentation remains at the disposal of the national competent authorities for the period indicated for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period. Paragraph 3 provides that providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended application dates for Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), are 2 December 2027 for the standalone Annex III route and 2 August 2028 for high-risk AI in products covered by the Annex I harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Four things here are our reading and not the text. First the application date: Regulation (EU) 2026/1744 does not name Article 18 separately, so the fact that this duty moves with 2 December 2027 and 2 August 2028 follows from its placement in Chapter III, Section 3, and not from an explicit provision. Second the starting moment. Paragraph 1 names the placing on the market and the putting into service side by side without choosing, and for a system where both moments occur that is years of difference at the end of the period. Counting from the later moment is the only count that falls short under neither reading, and that is what we would advise a provider. The other reading is defensible: in Union product law the placing on the market is usually the moment that counts, and then the period ends earlier. Third a substantially modified version: the text is silent, and it is equally defensible that every version gets its own period as that the original one continues. Fourth the reach of paragraph 3: it names only the technical documentation, so we keep points (b) to (e) under the general regime until the contrary is settled. Paragraph 2, finally, is addressed to the Member State and not to you. The Netherlands has not yet determined those conditions, so what happens to your file on insolvency or cessation of activity currently follows from contract and not from law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Watch the boundaries of this duty, because they get crossed in both directions. The automatically generated logs are not among the five components: they fall under Article 19, with its own and much shorter period of at least six months, appropriate to the intended purpose, and with a clause for financial institutions that parallels paragraph 3. So do not stretch the ten years to your logs, and conversely do not settle for six months for your documentation. For a provider established in a third country the actual availability moreover sits with two parties at once: Article 22(3)(b) requires the authorised representative to keep, for ten years, the contact details of the provider, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body at the disposal of the competent authorities and of the bodies referred to in Article 74(10). Two files that drift apart are worse than one. Point (e) overlaps with Article 47(1), which gives the declaration of conformity its own ten year period, and under Article 23(5) the importer carries ten years again for the certificate, the instructions for use and the declaration of conformity. That overlap is no reason to drop one of the periods: they are independent duties of different parties. It is a reason to choose a place of retention where they coincide. On the GDPR, finally: a retention duty under Union law is itself a ground under Article 6(1)(c) GDPR, and the storage limitation of Article 5(1)(e) permits retention that the law requires. The question is therefore not whether it is allowed but how far it reaches. Ten years applies to what Article 18(1) names, and not to everything created along the way: separate test sets, log samples and raw data dumps from the documentation you must be able to produce.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"This is the duty that asks nothing at the moment you take it on and everything at the moment you have forgotten it. Ten years is longer than the average life of a supplier contract, a document management system and a product team. In the organisations where we encounter this, the five components rarely sit in one archive: the quality system sits with compliance, the notified body decisions with certification, the declaration of conformity with legal. That is not law, but it is common enough that it is worth checking before you assume your situation is different. Whoever first assembles the documents when an authority asks discovers that retention in fact depended on a person and not on a process. Note also the side that is not about you: paragraph 2 concerns the situation where the provider or its representative goes bankrupt, and that is exactly the risk you run as a customer of a small supplier. It is a contracting question before it becomes a compliance question.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Designate per high-risk system one place of retention where the five components of paragraph 1 come together. Record side by side when the system was placed on the market and when it was put into service, and calculate the end date from the later of those two moments, so that you do not fall short under either reading. Set that end date as a commitment in a system that survives a change of staff, and keep the Article 19 logs separately with their own period. If you work with an authorised representative, record who holds which copy, because Article 22(3)(b) places the same availability on them as well. When procuring a high-risk system, put in the contract what happens to the documentation if the supplier stops or goes bankrupt, because paragraph 2 leaves that arrangement to national law that does not yet exist in the Netherlands.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-18-document-retention","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-27-fria","legacy_id":"raip:obligation:article-27-fria","type":"obligation","slug":"article-27-fria","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:fria-assess"],"evidence_ids":["praxikon:eu:ai-act:evidence:fria-report"],"control_ids":["praxikon:eu:ai-act:control:fria-pre-deployment-gate"],"template_ids":["praxikon:eu:ai-act:template:fria-questionnaire"],"conditions":[{"id":"fria-annex-iii-high-risk","operator":"all","description":"The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2."},{"id":"fria-covered-deployer","operator":"any","description":"The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c)."}],"exceptions":[{"id":"fria-emergency-notification","operator":"not","description":"In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself."}],"statements":[{"kind":"official_fact","text":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-27-fria","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-28-39-notified-bodies","legacy_id":"raip:obligation:article-28-39-notified-bodies","type":"obligation","slug":"article-28-39-notified-bodies","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"244200659e300ee841c99c7ece25bf19795a8036b16b7faca26e35a05ecae3b1","label":"Articles 28 to 39: notifying authorities and notified bodies","summary":"Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.","topics":["conformity","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:verify-notified-body-standing"],"evidence_ids":["praxikon:eu:ai-act:evidence:notified-body-standing-record"],"control_ids":["praxikon:eu:ai-act:control:notified-body-continuity-review"],"template_ids":["praxikon:eu:ai-act:template:article-28-39-legal-text"],"conditions":[{"id":"article-28-39-scope","operator":"all","description":"Practically engaged as soon as a notified body comes into the picture for your system. Within Annex III that is, under Article 43(1), only for the biometrics of point 1, and then only along the Annex VII procedure. Within Annex I, Section A, it happens through the sectoral conformity assessment of Article 43(3). For the systems of points 2 to 8 of Annex III, which follow the internal control of Annex VI, no notified body is involved and this Section has no direct bearing on you. The Section itself has applied since 2 August 2025 and therefore well before the underlying high-risk obligations bite: the notification chain has to exist before there is anything to assess."},{"id":"article-28-39-subcontracting-consent","operator":"all","description":"Article 33(3) makes the agreement of the provider a condition for subcontracting: activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. That is a right you can exercise only if you ask about it, because the provision does not prescribe any active notice to you."}],"exceptions":[{"id":"article-28-39-third-country-bodies","operator":"not","description":"Article 39 rules out a free choice of a foreign body. Only conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies, and then only where they meet the requirements laid down in Article 31 or ensure an equivalent level of compliance."},{"id":"article-28-39-presumption-limited","operator":"not","description":"The presumption in Article 32 is narrow. A conformity assessment body is presumed to comply with the requirements of Article 31 in so far as the applicable harmonised standards cover those requirements and their references have been published in the Official Journal of the European Union. Without that publication the presumption does not operate, and it never reaches further than what the standard covers."}],"statements":[{"kind":"official_fact","text":"Article 28(1) provides: Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States. Paragraph 3 provides: Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded. Paragraph 5 provides: Notifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis. Article 29(1) provides: Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established. Paragraph 2 provides: The application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31. Article 30(1) provides: Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31. Paragraph 2, as replaced by Article 1, point (16), of Regulation (EU) 2026/1744, provides: Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1. The second subparagraph of that paragraph empowers the Commission to amend Annex XIV by delegated act. Until 27 July 2026 paragraph 2 carried no such list of codes; since then it sets the scope of the designation. Paragraph 4 provides: The conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 28(1), (3) and (5); Article 29(1) and (2); Article 30(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 28(8), as added by Article 1, point (14), of Regulation (EU) 2026/1744, provides: notifying authorities designated pursuant to this Regulation that are responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both pursuant to this Regulation and that legislation is provided with the possibility to submit a single application and undergoes a unified assessment procedure, where the relevant Union harmonisation legislation provides for such a procedure. A conformity assessment body designated pursuant to more than one piece of that legislation shall have to apply only once to be designated pursuant to this Regulation, and a designation pursuant to this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which it is designated. Paragraph 9 provides that a notifying authority designated pursuant to that legislation is also the notifying authority for the application of that procedure, unless the Member State designates another notifying authority for this Regulation. Article 29(4), as replaced by Article 1, point (15), provides that notified bodies undergoing the unified assessment procedure shall submit the single application to the notifying authority designated pursuant to that Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (14) to (16), amending Articles 28, 29 and 30","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 31(1) provides: A notified body shall be established under the national law of a Member State and shall have legal personality. Paragraph 4 provides: Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. Paragraph 5 provides: Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. Paragraph 6 provides: Notified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Paragraph 8 provides: Notified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned. Paragraph 11 provides: The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 32 provides: Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements. Article 33(1) provides: Where a notified body subcontracts specific tasks connected with the conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 31, and shall inform the notifying authority accordingly. Paragraph 2 provides: Notified bodies shall take full responsibility for the tasks performed by any subcontractors or subsidiaries. Paragraph 3 provides: Activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available. Paragraph 4 provides: The relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation shall be kept at the disposal of the notifying authority for a period of five years from the termination date of the subcontracting.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 34(1) provides: Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43. Paragraph 2 provides: Notified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation. Paragraph 3 provides: Notified bodies shall make available and submit upon request all relevant documentation, including the providers documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section. Article 35(1) provides: The Commission shall assign a single identification number to each notified body, even where a body is notified under more than one Union act. Paragraph 2 provides: The Commission shall make publicly available the list of the bodies notified under this Regulation, including their identification numbers and the activities for which they have been notified. The Commission shall ensure that the list is kept up to date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 36(3) provides: Where a notified body decides to cease its conformity assessment activities, it shall inform the notifying authority and the providers concerned as soon as possible and, in the case of a planned cessation, at least one year before ceasing its activities. The certificates of the notified body may remain valid for a period of nine months after cessation of the notified body activities, on condition that another notified body has confirmed in writing that it will assume responsibilities for the high-risk AI systems covered by those certificates. The latter notified body shall complete a full assessment of the high-risk AI systems affected by the end of that nine-month-period before issuing new certificates for those systems. Where the notified body has ceased its activity, the notifying authority shall withdraw the designation. Paragraph 5 provides: Where its designation has been suspended, restricted, or fully or partially withdrawn, the notified body shall inform the providers concerned within 10 days. Paragraph 6 provides: In the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall take appropriate steps to ensure that the files of the notified body concerned are kept, and to make them available to notifying authorities in other Member States and to market surveillance authorities at their request. Paragraph 9 provides: With the exception of certificates unduly issued, and where a designation has been withdrawn, the certificates shall remain valid for a period of nine months under the following circumstances: (a) the national competent authority of the Member State in which the provider of the high-risk AI system covered by the certificate has its registered place of business has confirmed that there is no risk to health, safety or fundamental rights associated with the high-risk AI systems concerned; and (b) another notified body has confirmed in writing that it will assume immediate responsibility for those AI systems and completes its assessment within 12 months of the withdrawal of the designation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 37(1) provides: The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the requirements laid down in Article 31 and of its applicable responsibilities. Paragraph 2 provides: The notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned. Paragraph 4 provides: Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including the suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. Article 38(1) provides: The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies. Paragraph 2 provides: Each notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives. Paragraph 3 provides: The Commission shall provide for the exchange of knowledge and best practices between notifying authorities. Article 39 provides: Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 37(1), (2) and (4); Article 38(1) to (3); Article 39","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this Section as the supplier terms of your conformity assessor, because that is exactly what it is. Three points in it go wrong in practice. The first is the independence requirement of Article 31(4) and (5). It prohibits not only the obvious double role but rules out consultancy services in particular. Anyone who has his high-risk file built by the advisory firm that later performs the assessment buys a certificate that can be challenged on that ground. Separate those two purchases at the outset, not halfway through. The second is Article 31(1) read alongside Article 39. The body must be established under the national law of a Member State and have legal personality; a body from a third country comes into the picture only where the Union has concluded an agreement with that country. For a group that places its worldwide certification with a single house, that is a hard limit: the European assessment must sit with a European notified legal person, and the group brand name says nothing about that. The third is Article 33. Subcontracting is allowed, but only with your agreement, and the body retains full responsibility for what the subcontractor does. The provision does not oblige it to tell you of its own motion; it only makes its subsidiaries publicly available. So ask, and record the answer, because without the question the agreement never comes up.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two provisions in this Section work in your favour and are rarely used. Article 34(2) is the first. It requires the body to avoid unnecessary burdens for providers and to take due account of your size, your sector, your structure and the complexity of the system, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises. That is not a policy aspiration but an operational obligation of the body, and it sits alongside Article 31(8), which demands the same proportionality in its procedures. The second sentence of paragraph 2 immediately bounds it: the degree of rigour and the level of protection stand. The practical reading is therefore not that a small provider has to demonstrate less, but that the road there must be proportionate. If you are handed a standard package plainly designed for a different kind of organisation, this is the provision on which you raise it. Article 36 is the second. It holds the scenario that hits a provider hardest and appears in no project plan: your body ceases or loses its designation. Your certificates then remain valid for at most nine months, and only where another notified body has confirmed in writing that it will assume responsibility. You hear about it within ten days, and that is the only deadline in this Section that runs directly to you. The follow-on steps for the certificate itself sit in the object on Article 44; what matters here is that the continuity of your market access depends on a party over which you have no control. So treat the notified body as a supplier with concentration risk, and not as a quality mark.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether this Section touches you at all: only where your system goes through a notified body via Annex VII or via the sectoral route of Article 43(3). If it does, check four things in the Commission public list at the moment of choice and annually thereafter: is the body still listed, what identification number does it carry, for which conformity assessment activities and which types of AI systems is it notified, and has its designation been restricted or suspended. Record for each choice that you tested the independence of Article 31(4) and (5), in particular whether the same group previously advised you on the same system. When placing the assignment, ask explicitly which tasks are subcontracted to a subcontractor or a subsidiary, give or withhold your agreement under Article 33(3) in writing, and provide in the contract that any change to it requires your agreement again. Add two clauses: a duty on the body to report any change to its designation, mirroring the ten days of Article 36(5), and a handover clause describing which files you get back within what period if it ceases. Finally, keep a second notified body in view that is notified for your type of system, so that the nine months of Article 36(3) and (9) become a handover rather than a search.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-28-39-notified-bodies","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4-ai-literacy","legacy_id":"raip:obligation:article-4-ai-literacy","type":"obligation","slug":"article-4-ai-literacy","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7a9516670dfca5dd7dcc96ae019e5714f843e20235abd3e9d92b71eb42445ff1","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-4-measures"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-4-measures-record"],"control_ids":["praxikon:eu:ai-act:control:article-4-periodic-review"],"template_ids":["praxikon:eu:ai-act:template:article-4-measures-plan"],"conditions":[{"id":"article-4-in-scope-ai","operator":"all","description":"The organisation is a provider or deployer of an AI system within scope."}],"exceptions":[{"id":"article-4-no-specific-level","operator":"not","description":"The provision does not require a specific individual level to be guaranteed."}],"statements":[{"kind":"official_fact","text":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Official amending regulation"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis","legacy_id":"raip:obligation:article-4a-bias-testing-legal-basis","type":"obligation","slug":"article-4a-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffee7eb28c48cc8a2586f097f3abec38cbe7590c73e15b9845f9295f8f095d4c","label":"Article 4a: legal basis for bias testing with special categories of personal data","summary":"Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are open here, and the risk runs the other way round than with a right such as Article 86: a broad reading here benefits the controller and not the data subject, because this concerns data on ethnicity, health, religion, trade union membership and sexual orientation. Where in doubt the narrow reading is therefore the safe one. First, the reach of \"other AI systems and models\" in paragraph 2, which on its face covers any AI system and any model and for which no delimitation exists. We read it on its face, but with the threshold in paragraph 2, point (a), as the real boundary: without a consequence for health and safety, fundamental rights or prohibited discrimination there is no basis. A defensible alternative reading is that paragraph 2 is confined to systems comparable to the examples in recital 9, such as scoring tools for permits and public services. Second, the relationship with Article 9 GDPR. Recital 9 states that the extension is subject to the same limitations, conditions and safeguards and thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, so we read Article 4a as the Union law measure that point requires, with the safeguards carried by the six conditions themselves. The counterargument stands against that and has not gone away, but it has narrowed since 27 July 2026: the anchoring sits in a recital and not in the article, and the article itself designates no ground from Article 9(2). What no longer supports that counterargument is Article 2(7). Until 27 July 2026 that paragraph left the GDPR unaffected without reservation, but it was replaced by Article 1, point 2(b), of Regulation (EU) 2026/1744 and now reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The Union legislature therefore carved the reservation out for Article 4a precisely, which points towards reading Article 4a as the Union law measure itself rather than a mere cross-reference to the GDPR. Anyone citing this object while quoting the former wording of Article 2(7) is quoting a replaced provision. A defensible alternative reading remains that a national or Union measure with specific safeguards is still needed alongside it, but it now rests only on the absence of an express designation in the article itself. On the date from which the basis operates, part is settled and part is not. What is settled is what recital 9 says, namely that the basis should apply from the date of entry into application of Regulation (EU) 2024/1689; that has been read and is not a house reading. What remains open is which date this object therefore carries. We hold to 27 July 2026, the day Article 4a entered the text, because a basis that was not yet there was in fact not available. The alternative reading follows recital 9 literally and lets the basis reach back to the date of application of the base Regulation. That difference is not academic for anyone who has to justify processing from that period. The editorial statement below marks that choice as our inference.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted"],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":["praxikon:eu:ai-act:control:bias-testing-data-deletion"],"template_ids":["praxikon:eu:ai-act:template:article-4a-legal-text"],"conditions":[{"id":"article-4a-paragraph-1-high-risk-provider-only","operator":"all","description":"Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2."},{"id":"article-4a-paragraph-2-wider-circle-with-harm-threshold","operator":"all","description":"Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it."},{"id":"article-4a-cumulative-conditions","operator":"all","description":"The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data."}],"exceptions":[{"id":"article-4a-no-duty-to-test","operator":"not","description":"Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, to the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur: (a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data; (b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation; (c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations; (d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties; (e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and (f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 2 provides that providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that: (a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and (b) all of the conditions and safeguards set out in paragraph 1 are applied. Paragraph 2 closes with a separate subparagraph: this paragraph does not create any obligation to conduct such bias detection and correction. Article 4a has no paragraph 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts Article 4a into Regulation (EU) 2024/1689 by Article 1, point 6, and deletes Article 10(5) by Article 1, point 9(b). The same point 9 replaces Article 10(1) and Article 10(6) so that they now refer to the quality criteria in Article 4a(1). The basis therefore no longer sits with the requirements for high-risk systems in Chapter III, but as a standalone article in Chapter I, immediately after Article 4, while Article 10 refers back to it from the outside. In the Dutch language version of the Official Journal the inserted article is numbered \"artikel 4 bis\"; \"Article 4a\" is the English numbering of the same provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same amending Regulation replaces Article 2(7) of Regulation (EU) 2024/1689 by Article 1, point 2(b). Since 27 July 2026 that paragraph reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The previous version of that paragraph carried no such reservation for Article 4a.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 9 of Regulation (EU) 2026/1744 states that bias detection and correction constitute a substantial public interest, that the extended legal basis is subject to the same limitations, conditions and safeguards as the existing Article 10(5), and that this thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, Article 10(2), point (g), of Regulation (EU) 2018/1725 and Article 10, point (a), of Directive (EU) 2016/680. The same recital states that the legal basis established by Article 4a should apply from the date of entry into application of Regulation (EU) 2024/1689, so as to enable providers of high-risk AI systems lawfully to undertake bias detection and correction activities in preparation for compliance with the requirements for high-risk AI systems. Article 4 of the amending Regulation governs only entry into force on the third day following publication and provides for no deferred application; the amended Article 113, third paragraph, point (a), provides that Chapters I and II apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026. Article 4a sits in Chapter I and falls outside that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Three things matter more in practice than the relocation itself. The first is that this article instructs you to do nothing. Paragraph 2 says so in as many words, and no date by which anything must be done belongs with it either. The second, and the more dangerous misreading, is that the move into Chapter I means you may now start collecting sensitive attributes because you want to run fairness measurements. What has widened is the set of parties, not the room inside the basis: recital 9 expressly states that the same limitations, conditions and safeguards apply as under the former Article 10(5). In practice it therefore starts with a written justification of why synthetic or anonymised data do not suffice, and not with assembling a dataset. The third is the condition that bites hardest and appears in no summary: point (d) provides that the data are not transmitted, transferred or otherwise accessed by other parties. That is in effect a ban on outsourcing. An external fairness vendor, a bias auditing firm, a research partner or a cloud party that can reach the data itself does not fit inside this basis, however good the contract. Anyone who intended to buy in their bias testing must run it in house here, or work with data that are not a special category. Finally, watch your own documentation: records of processing, data protection impact assessments and AI policy documents that refer to Article 10(5) have been referring to a deleted provision since 27 July 2026. The same holds for documents citing Article 2(7) to argue that the GDPR prevails without qualification: that paragraph too has been replaced and now expressly reserves Articles 4a and 59. Two dates to close on, and the second is our inference rather than source text. Article 4a sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025, but the provision only entered the text on 27 July 2026; we therefore treat 27 July 2026 as the day the basis actually became available, while recital 9 states that it should apply from the date of entry into application of Regulation (EU) 2024/1689. Finally, note that the requirements in Article 10(2), points (f) and (g), which paragraph 1 refers to, themselves only start to apply on 2 December 2027 for Annex III systems and on 2 August 2028 for Annex I systems. The basis therefore deliberately runs ahead of the duty you use it for, exactly as recital 9 intends.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Carry out the data protection impact assessment before you start. Processing special categories at scale for bias testing engages Article 35 GDPR in almost every case, and Article 4a does not remove that assessment: it supplies the legal basis, not the risk appraisal. Then record, per processing operation, which paragraph of Article 4a you rely on, for which system or model, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access and at what point the data are deleted. In the same pass, review your record of processing activities, your impact assessments and your AI policy documents for references to Article 10(5) and replace them with Article 4a. Set the deletion moment as a monitored deadline rather than an intention, verify that no external party can reach the data, and align the justification with your data protection officer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4a-bias-testing-legal-basis","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-5-prohibited-practices","legacy_id":"raip:obligation:article-5-prohibited-practices","type":"obligation","slug":"article-5-prohibited-practices","version":"1.0.0","effective_at":"2025-02-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"674c4b85d1cf177b2ab9256989e18b2d685fdb69388f02f22bcc8cebd4f5faf8","label":"Article 5: prohibited practices","summary":"The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.","topics":["prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-5-screen"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-5-screening-record"],"control_ids":["praxikon:eu:ai-act:control:article-5-intake-gate"],"template_ids":["praxikon:eu:ai-act:template:article-5-legal-text"],"conditions":[{"id":"article-5-listed-practice","operator":"any","description":"Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement."}],"exceptions":[{"id":"article-5-narrow-exceptions","operator":"not","description":"The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance."}],"statements":[{"kind":"official_fact","text":"The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5, Article 99(3) and Article 113(a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment to Article 5 and transition to 2 December 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(a)-(h)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5 read with Article 6 classification order","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-5-prohibited-practices","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 5 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification","legacy_id":"raip:obligation:article-52-systemic-risk-classification","type":"obligation","slug":"article-52-systemic-risk-classification","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fda72f0c021ed141ad0881c569a2e4d7e59aefdcec7c95a562b9f547352a974e","label":"Article 52: notification of a GPAI model with systemic risk","summary":"The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"settled","interpretation_note":null,"obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply"],"action_ids":["praxikon:eu:ai-act:action:notify-systemic-risk-threshold","praxikon:eu:ai-act:action:request-systemic-risk-reassessment"],"evidence_ids":["praxikon:eu:ai-act:evidence:systemic-risk-notification-file"],"control_ids":["praxikon:eu:ai-act:control:systemic-risk-notification-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-52-legal-text"],"conditions":[{"id":"article-52-notification-trigger","operator":"all","description":"Applies to the provider of a general-purpose AI model as soon as that model meets the condition in Article 51(1), point (a): high impact capabilities, which under Article 51(2) are presumed where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. The two-week period runs from the moment that requirement is met or it becomes known that it will be met. The second route to systemic risk, a Commission designation under Article 51(1), point (b), or Article 52(4), is not covered here: Article 52(1) refers only to point (a)."}],"exceptions":[{"id":"article-52-legacy-models-transitional","operator":"not","description":"For general-purpose AI models placed on the market before 2 August 2025, Article 111(3) provides that the provider shall take the necessary steps to comply with the obligations of this Regulation by 2 August 2027. For those models the governing date is therefore 2 August 2027 and not the two-week period."}],"statements":[{"kind":"official_fact","text":"Article 51(1), point (a), classifies a general-purpose AI model as a model with systemic risk where it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; Article 51(2) provides that a model is presumed to have such capabilities where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. Article 51(1), point (b), reads in full: based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. The requirement of equivalent capabilities or impact and the anchoring in Annex XIII are therefore part of the norm and not only of the procedure. Article 51(3) provides in addition: the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. The 10^25 threshold above is therefore movable; as long as that act does not exist, the threshold applies as it stands in paragraph 2. See data/ai-act/delegated-acts.json, key praxikon:eu:ai-act:delegated-act:article-51-3-thresholds. Article 52(1) refers only to point (a) and provides that the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met, and that the notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. Paragraph 2 allows the provider to present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although the model meets that requirement, it does not present systemic risks due to its specific characteristics and should therefore not be classified as a general-purpose AI model with systemic risk. Paragraph 3 provides that where the Commission concludes that those arguments are not sufficiently substantiated and the provider was not able to demonstrate that the model does not present systemic risks due to its specific characteristics, it shall reject those arguments and the model shall be considered to be a general-purpose AI model with systemic risk. Paragraph 4 empowers the Commission to designate a model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of the criteria set out in Annex XIII, and empowers it to adopt delegated acts in accordance with Article 97 to amend Annex XIII by specifying and updating the criteria set out in that Annex. Paragraph 5 provides that upon a reasoned request of a provider whose model has been designated pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII, that such a request shall contain objective, detailed and new reasons that have arisen since the designation decision, that providers may request reassessment at the earliest six months after the designation decision, and that where the Commission decides to maintain the designation a further six months must pass. Paragraph 6 provides that the Commission shall ensure that a list of general-purpose AI models with systemic risk is published and kept up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 111 states that the cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Recital 112 states that the provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a model will meet the requirements that lead to the presumption, and that this is especially relevant in relation to the threshold of floating point operations because training takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers are able to know if their model would meet the threshold before the training is completed. The same recital states that in the context of that notification the provider should be able to demonstrate that the model exceptionally does not present systemic risks, that the information allows the AI Office to anticipate the placing on the market of models with systemic risks, and that it is especially important for models planned to be released as open-source. Recital 113 states that the Commission should be empowered to designate a model where it becomes aware that the model meets the requirements which previously had either not been known or of which the provider failed to notify it, and that a system of qualified alerts from the scientific panel should exist in addition to the monitoring activities of the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(3) provides that providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) state in point (63) that a downstream modifier is considered to be the provider of the modified model where the training compute used for the modification is greater than a third of the training compute of the original model, and in point (64) that where the downstream modifier cannot know and cannot estimate the original value, that threshold is replaced by a third of 10^25 FLOP where the original model is a model with systemic risk and otherwise by a third of 10^23 FLOP. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1). The guidelines are not binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission enforcement powers for general-purpose AI models and the fine regime of Article 101 have been active since 2 August 2026. Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only duty in this chapter with a numbered deadline, and two weeks is short. Other duties are also tied to a clock, only without a figure: Article 55(1), point (c), requires serious incidents to be reported to the AI Office without undue delay. The question here is therefore not whether you can notify, but whether you see the threshold being crossed in time. Recital 112 leaves little room to push that back: the legislator expressly assumes that the upfront allocation of compute lets you know before training ends that you will meet the threshold. The remaining edge question is how firm that knowledge is for a run not yet allocated, and it is small next to the duty itself. Four things are missed in practice. The first is the transitional rule: if your model was already on the market before 2 August 2025, Article 111(3) gives you until 2 August 2027, and that is the difference between two weeks and two years. The second is the reach of the trigger: only the threshold route of Article 51(1), point (a), starts this clock. If your model is designated by the Commission under Article 51(1), point (b), or Article 52(4), Article 55 begins without Article 52 asking anything of you. The third is the reversal in the last sentence of paragraph 1: if the Commission becomes aware of a model it was not notified about, it may designate it, and you then hold the conversation from a designation rather than from your own file. Since 2 August 2026 the Article 101 fine regime stands behind that. The fourth is the rebuttal route in paragraph 2: those arguments belong with the notification and not after it, so they must already be ready at the moment you notify. Once designated, only paragraph 5 remains, and that route is slow: six months after the decision at the earliest, and only with objective, detailed and new reasons that have arisen since it. The text names the Commission as addressee; recital 112 and Article 55(1), point (c), name the AI Office, which performs this task within the Commission. For an organisation that merely uses an external model this article does not bite: it addresses the provider of the model. That does not put further development out of reach: under point (71) of guidelines C(2025) 5045 final, a party that becomes the provider of a systemic-risk model through a modification must notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model and not merely a user, and whether your model was already on the market before 2 August 2025, because the date in Article 111(3) then applies instead of the two-week period. If you are the provider of a new model, record the planned and the consumed training compute per training run, including pre-training, synthetic data generation and fine-tuning, because recital 111 counts all three. Agree who notifies once the threshold comes into view, so the two-week period is not spent finding an owner, and tie that to the moment compute is allocated rather than to the end of the run. Keep the reasoning with which you would argue that the model does not present systemic risks ready before you notify, because it belongs with the notification. If you have already been designated under paragraph 4, build deliberately towards objective, detailed and new reasons that have arisen since the designation decision, because only those get you to a reassessment after six months. Retain the notification, the substantiation sent with it, any reassessment request and the Commission response as a living file per model version.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-52-systemic-risk-classification","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines C(2025) 5045 final on the scope of the GPAI obligations"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-53-gpai","legacy_id":"raip:obligation:article-53-gpai","type":"obligation","slug":"article-53-gpai","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55f22a1c21f936ec956fc61f7db4f29defb4524294046799c13af57745cd8b36","label":"Article 53: GPAI model providers","summary":"Documentation, information, copyright and transparency duties for providers of general-purpose AI models.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:gpai-document"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-compliance-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-documentation-change-control"],"template_ids":["praxikon:eu:ai-act:template:gpai-guide"],"conditions":[{"id":"gpai-union-market","operator":"all","description":"The party is a provider of a GPAI model placed on the Union market."},{"id":"gpai-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the duties apply from that time. Models placed on the market before 2 August 2025 must comply by 2 August 2027."}],"exceptions":[{"id":"gpai-open-source-limited-exception","operator":"not","description":"The open-source exception is limited and retains, among other things, the copyright policy and public training-content summary. Additional duties apply to models with systemic risk."}],"statements":[{"kind":"official_fact","text":"Article 53 applies since 2 August 2025 to new GPAI models. Providers maintain technical documentation, provide information to downstream providers, operate a Union copyright policy and publish a sufficiently detailed summary of training content.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1), Annex XI and Annex XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable obligations by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An organisation merely using an external GPAI model does not thereby automatically become a GPAI model provider. First determine its role in the value chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Scope and provider qualification guidance","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record model versions, role qualification, documentation owners, downstream information, copyright policy and training summary in one change-controlled file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53 and Annexes XI-XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-53-gpai","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative","legacy_id":"raip:obligation:article-54-gpai-authorised-representative","type":"obligation","slug":"article-54-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c470c29e8f0c2ad222dc0517b6a9437615474bfc6429e9c37b90eb35572d5c5","label":"Article 54: authorised representative of a provider of a GPAI model","summary":"A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-gpai-authorised-representative"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-representative-mandate-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-mandate-review"],"template_ids":["praxikon:eu:ai-act:template:article-54-legal-text"],"conditions":[{"id":"article-54-scope","operator":"all","description":"Applies where the model qualifies as a general-purpose AI model within the meaning of Article 3(63), its provider is established in a third country, and that model is placed on the Union market. The appointment is made by written mandate within the meaning of Article 3(5), which is not only given but also accepted, and it is made before the model is placed on the market. The moment at which the latter occurs is fixed less sharply for a model than for a system; see the editorial interpretation."},{"id":"article-54-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the appointment duty applies from that moment. Providers of models placed on the market before 2 August 2025 shall, under Article 111(3), take the necessary steps to comply with the obligations of the Regulation by 2 August 2027."}],"exceptions":[{"id":"article-54-open-source-exception","operator":"not","description":"Paragraph 6 excludes the obligation for providers of AI models released under a free and open-source licence that allows access, usage, modification and distribution, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available. That exception falls away as soon as the model presents a systemic risk. Whether a given release qualifies is a factual test that has not been settled anywhere; we read it narrowly, so a partially public release does not qualify."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union. Paragraph 2 provides that the provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider. Paragraph 3 provides that the authorised representative shall perform the tasks specified in the mandate received from the provider, that it shall provide a copy of the mandate to the AI Office upon request in one of the official languages of the institutions of the Union, and that for the purposes of the Regulation the mandate shall empower the authorised representative to carry out the following tasks: (a) verify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider; (b) keep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative; (c) provide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in that Chapter; (d) cooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union. Paragraph 4 provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with the Regulation. Paragraph 5 provides that the authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to the Regulation, and that in such a case it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor. Paragraph 6 provides that the obligation set out in that Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 113(3)(b) provides that Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Article 54 sits in Chapter V and therefore applies from 2 August 2025.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. Article 101 is excluded by Article 113(3)(b) from the earlier application of Chapter XII and has therefore applied since 2 August 2026. The obligation in Article 54 has thus applied since 2 August 2025, while the Commission fining power behind it exists only since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in the Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article touches two parties that rarely see themselves that way. The first is the model provider outside the Union that assumes nothing is required until a European customer asks: paragraph 1 places the appointment before the placing on the market, so the representative should exist before the first user in the Union can access the model. The second is the European party that accepts the mandate. It is not stepping into a mailbox role, but note how paragraph 3 is built: the first sentence obliges it to perform the tasks the mandate assigns to it, and only then does the article list what the mandate empowers it to do. Points (a) to (d) are therefore mandate content and empowerment, and its duty runs through them. That is where this article leaves its sharpest question open: is a representative that accepts a mandate omitting task (a) or (b) itself in breach, or does the failure rest entirely with the provider that drew up the mandate. We read paragraph 3 as making the list mandatory minimum content, so that a mandate lacking it does not satisfy the article, which leaves the provider answerable under paragraph 1 and the representative answerable for what it did accept. A defensible alternative reading is that a representative signing without those powers takes on a task it cannot discharge and thereby falls short itself. So do not assume the ten year retention in point (b) rests on you automatically, or automatically does not; write it out. Paragraph 5 closes this off in a way that is often missed: a representative that considers, or has reason to consider, that the provider is breaching its obligations terminates the mandate and immediately informs the AI Office. That is a duty rather than a power, and it calls for access to the documentation agreed in advance and for a moment at which that access is tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Three things about the timeline and the scope. First, the difference between duty and enforcement: the duty has applied since 2 August 2025, but Article 101 is excluded from the earlier application, so the Commission can only fine since 2 August 2026. For a provider outside the Union discovering today that it has no representative, that means: in breach for well over a year, and now also exposed to a fine. Second, the relationship with Article 22. That article carries the same figure for high-risk AI systems, starting on 2 December 2027 and 2 August 2028; Article 54 is the separate route for general-purpose AI models and has applied since 2 August 2025. Anyone looking up the role of authorised representative finds both and needs to know which route applies. Third, the trigger in paragraph 1. The Regulation fixes the moment of placing on the market less sharply for a model than for a system, and for a model made available only through an interface from a third country there is no case law. We read the duty as starting once the model is made available to users in the Union in the course of a commercial activity, because paragraph 1 attaches to placing on the market and not to establishment in the Union. A defensible alternative reading is that making a model available through an interface is not placing the model itself on the market, so that the duty only arises on an actual supply of the model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model or only a user, because only the provider appoints. If you are established outside the Union, put the mandate in writing before the model becomes available here, and write the four tasks in paragraph 3 into it expressly, together with the access to the Annex XI documentation and the point of contact under paragraph 4. If your model was already on the market before 2 August 2025, work to 2 August 2027 rather than to today. If you are only now discovering that there is no representative, assume the duty has run since 2 August 2025 and that the Commission has been able to fine since 2 August 2026; remedy first and record when you did. If you accept a mandate, agree in advance how you carry out the verification in paragraph 3(a), who holds the copy for ten years, and at what moment you test whether termination under paragraph 5 is called for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-54-gpai-authorised-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/54","label":"Read Article 54 in the AI Act Explorer"},{"relation":"related","href":"/en/ai-act/artikel/53","label":"Article 53: the duties the representative verifies"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk","legacy_id":"raip:obligation:article-55-gpai-systemic-risk","type":"obligation","slug":"article-55-gpai-systemic-risk","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589","label":"Article 55: GPAI models with systemic risk","summary":"Additional duties for the most capable general-purpose AI models, on top of Article 53.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record"],"control_ids":["praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control"],"template_ids":["praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text"],"conditions":[{"id":"article-55-gpai-systemic-risk-scope","operator":"all","description":"The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission."}],"exceptions":[{"id":"article-55-gpai-systemic-risk-exception","operator":"not","description":"The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance."}],"statements":[{"kind":"official_fact","text":"Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 55 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice","legacy_id":"raip:obligation:article-56-gpai-codes-of-practice","type":"obligation","slug":"article-56-gpai-codes-of-practice","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6e6afc9742736b52408f8c38c9435fc8be751641392f5d0b5d57a34afee4c1c","label":"Article 56: codes of practice for general-purpose AI models","summary":"The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.","topics":["governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record"],"control_ids":["praxikon:eu:ai-act:control:article-56-code-commitment-review"],"template_ids":["praxikon:eu:ai-act:template:article-56-legal-text"],"conditions":[{"id":"article-56-scope-gpai-provider","operator":"any","description":"Arises for the provider of a general-purpose AI model: it may be invited under paragraph 3 to participate in the drawing up of a code of practice, and under paragraph 7 to adhere to a code of practice."},{"id":"article-56-scope-value-chain","operator":"any","description":"Arises for other stakeholders: paragraph 3 names civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, that may support the process."}],"exceptions":[{"id":"article-56-limited-adherence-without-systemic-risk","operator":"not","description":"Paragraph 7 provides that for providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code. A provider without a systemic-risk model therefore does not have to sign up to the systemic-risk part in order to rely on the code."},{"id":"article-56-voluntary-instrument","operator":"not","description":"Article 56 does not impose a separate obligation on the provider. Paragraphs 3 and 7 speak of inviting, not of requiring, and the obligations themselves remain those of Articles 53 and 55. Not signing is therefore not an infringement of Article 56."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches. Paragraph 2 provides that the AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues: (a) the means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments; (b) the adequate level of detail for the summary about the content used for training; (c) the identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate; (d) the measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain. Paragraph 3 provides that the AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that the AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level. Paragraph 5 provides that the AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants. Paragraph 6, as replaced by Article 1, point (21), of Regulation (EU) 2026/1744, provides that the Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice. The power to approve a code of practice by implementing act and give it general validity within the Union, which sat in the second subparagraph of paragraph 6 until 27 July 2026, lapsed with that replacement. Paragraph 7 provides that the AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (21), replacing Article 56(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 8 provides that the AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards. Paragraph 9 provides that codes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7. The second subparagraph of paragraph 9 provides that if, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A code of practice is a voluntary instrument, and that word does all the work here. Signing creates no new obligation: your obligations remain those of Articles 53 and 55, and Article 56 changes nothing about them. Not signing is not an infringement either, because paragraphs 3 and 7 speak of inviting and not of requiring. What does shift is the burden of proof. A provider adhering to a code can point to a shared elaboration, assessed by the AI Office and the Board, when a regulator asks how it keeps its documentation up to date, how detailed its summary about the training content is, or how it assesses and manages systemic risk. A provider that does not sign has to write that elaboration itself and defend it itself, up to and including the question why its own approach is at least as good. That is not a legal difference in the norm, but it is a large difference in what is on the table when something is asked. Two things that are often conflated here. First: paragraph 7 allows a provider without a systemic-risk model to limit itself to the obligations in Article 53, unless it explicitly declares its interest in the full code. Partial participation is therefore an expressly foreseen choice and not half-heartedness. Second: paragraph 9 puts a stick behind the door that does not rest on you but does reach you. If no code comes about, or if the AI Office deems it inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. Those rules, unlike a code, are not voluntary.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Precision is in order about the state of play, because this is where the market overstates the most. It is established that the General-Purpose AI Code of Practice was published on 10 July 2025; that code is archived in this repository as three chapter PDF files, on transparency, copyright and safety and security, and it is present as a source record in this knowledge base. Whether an approving implementing act followed was not established for the period up to 27 July 2026, and after that date it is no longer the right question: paragraph 6 no longer carries that power. Since then the question is whether the Commission has published its assessment of adequacy. That too is not established here, and for as long as that is the case you must not read anywhere that the code has been approved or has general validity within the Union. That distinction is not a formality: a published code is a text you can voluntarily adhere to, a code approved by implementing act is on top of that an instrument with general validity in the Union. Anyone mistaking the first for the second overestimates what a signature buys and underestimates what they still have to record themselves. The content of the three chapters was also not read in this build, so nothing in this object says anything about what exactly is in them. In practice that means the following. Check the approval status yourself and by date before you rely on the code in a conversation with a regulator or a customer, and record which version of the code and which chapter your adherence relates to. A code may be reviewed and adapted under paragraph 8, in particular in light of emerging standards, so a reliance on the code without a version reference ages on its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the question whether you adhere to a code of practice as a decision that is taken and recorded, not as something that happens by itself. Record per model: do you adhere to a code, to which version and to which chapter, and if not, which elaboration of your own you apply instead for the issues named in paragraph 2, namely keeping the information in Article 53(1), points (a) and (b), up to date, the level of detail of the summary about the training content, and, where you offer a systemic-risk model, the identification and management of systemic risk. Decide explicitly whether under paragraph 7 the obligations in Article 53 are enough for you or whether you join the full code, and note that choice with a date and an authorised signatory. Before you rely on a code externally, check whether the Commission has published its assessment of adequacy under the amended paragraph 6, and claim no more than you can point at that moment. Do not ask for an approving implementing act: that power has not existed since 27 July 2026, and asking for it is asking for a decision nobody can take any more. Finally, put a review moment in your own calendar: paragraph 8 provides for review and adaptation of codes in light of emerging standards, and paragraph 9 allows the Commission to lay down common rules where a code fails to appear or is deemed inadequate, and both change what you are relying on without anyone calling you.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-56-gpai-codes-of-practice","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route","legacy_id":"raip:obligation:article-6-1-annex-i-product-route","type":"obligation","slug":"article-6-1-annex-i-product-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"69936813db0c35758e25c435a583907437346b30c52f1b9943517c31b41f9369","label":"Article 6(1): the product route to high risk","summary":"An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is mainly open is what condition (b) requires. The text of paragraph 1, point (b), asks whether the product must undergo a third-party conformity assessment, which reads as a reference to the procedure actually prescribed. Article 43(3), third subparagraph, as replaced by Regulation (EU) 2026/1744, points the other way: it subjects the opt-out from third-party assessment to an additional condition under this Regulation and expressly provides that classification as a high-risk AI system does not affect the choice of procedure. That presupposes such systems are high risk. The Commission draft guidelines of 19 May 2026 say the same: the fact that a manufacturer may rely on internal control based on harmonised standards does not affect classification under Article 6(1). We follow that reading and therefore assume a module A route does not take your system out of high risk where the legislature prescribed enhanced scrutiny for that product type. A defensible alternative reading holds to the letter of point (b): only those actually required to involve a third party fall under this route, and Article 43(3) concerns the procedure for an already classified system rather than classification itself. While the guidelines remain draft and the Court has not ruled, that difference in outcome is real. Second open point: the dates diverge within this route. Chapter III, Sections 1 to 3, applies from 2 August 2028, but Articles 102 to 110 apply from 27 July 2026. That range overlaps with what remains for products under Section B of Annex I but does not coincide with it: for Section B the amended Article 2(2) makes Article 6(1), Article 60a and Articles 102 to 112 applicable, so two articles more than the new point (d) brings forward. The date on this object is the Chapter III date, not that of the sectoral amendments. Third open point: machinery moved from Section A to Section B by the same amending Regulation. How the requirements land there depends on delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028 and have not yet been adopted.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-annex-i-product-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-i-product-route-record"],"control_ids":["praxikon:eu:ai-act:control:annex-i-product-route-change-gate"],"template_ids":["praxikon:eu:ai-act:template:article-6-1-legal-text"],"conditions":[{"id":"article-6-1-covered-product","operator":"all","description":"The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I. Whether the system is placed on the market independently of that product is irrelevant."},{"id":"article-6-1-third-party-assessment","operator":"all","description":"That product, or the AI system as a product itself, is required under that same harmonisation legislation to undergo a third-party conformity assessment with a view to its placing on the market or putting into service. Both conditions must be fulfilled together."}],"exceptions":[{"id":"article-6-1bis-non-safety-function","operator":"not","description":"Article 6(1a), inserted by Regulation (EU) 2026/1744, provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back as soon as failure or malfunctioning would endanger health and safety."},{"id":"article-6-1quater-non-health-safety-assessment","operator":"not","description":"Article 6(1c), as inserted, provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 43(3) was replaced by Regulation (EU) 2026/1744. The third subparagraph of the new text reads: where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by that harmonisation legislation. The first subparagraph of the same paragraph provides that the requirements set out in Chapter III, Section 2, apply to those high-risk AI systems and form part of that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(2) was replaced by Regulation (EU) 2026/1744 and reads: for AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. Articles 57, 58 and 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation. The original text named only Article 6(1), Articles 102 to 109 and Article 112, and limited the effect of Article 57 in the same way.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends Annex I: in Section A point 1 is deleted and in Section B point 21 is added, Regulation (EU) 2023/1230 on machinery. Point 1 of Section A was Directive 2006/42/EC on machinery. Machinery therefore moves from Section A to Section B. Regulation (EU) 2023/1230 is amended at the same time so that the Commission adopts delegated acts supplementing Annex III to that Regulation with health and safety requirements for AI systems classified as high risk pursuant to Article 6(1) of Regulation (EU) 2024/1689, reflecting the requirements of Chapter III, Section 2, and Articles 17, 19, 72 and 73. Those delegated acts shall apply by 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(1), point (e), provides that this Regulation applies to product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark. Article 25(3) provides that in the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system and shall be subject to the obligations under Article 16 under either of the following circumstances: (a) the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer; (b) the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market. Article 25(3) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The text of Article 113, third paragraph, point (c), as published in the Official Journal provides that Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces point (c) of the third paragraph of Article 113 with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The same amendment adds a point (d) to that paragraph: Articles 102 to 110 shall apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(2) was replaced and reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The inserted Article 2(13) provides that for high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection, and such limitation does not reduce the overall level of protection provided for by this Regulation. By 2 August 2027 the Commission shall adopt delegated acts specifying the systems concerned, the requirements that may be limited, the conditions and the scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (3), inserting Article 2(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For most organisations the first question is not whether their system is AI, but what function their AI component performs and which section of Annex I their product falls under. What often goes wrong is the idea that the conformity route chosen determines the classification: we apply harmonised standards, therefore internal control, therefore no third party, therefore no high risk. That reasoning does not hold. The replaced Article 43(3) attaches an additional condition under this Regulation to the opt-out and states in the same subparagraph that classification as a high-risk AI system does not affect the choice of procedure, and the draft guidelines of 19 May 2026 read Article 6(1) the same way. Where you can genuinely fall outside this route is through the inserted paragraphs 1a and 1c: a model that solely supports throughput or quality control and whose failure does not endanger health and safety, and a product that needed a third party only because of radio spectrum or electromagnetic interference. Two further things go wrong in practice. The first is the date: whoever put 2 December 2027 in the plan because that was the date in the news is planning on the Annex III route and not their own, and whoever notes only 2 August 2028 misses that Articles 102 to 110 have applied since 27 July 2026. The second is the section: machinery has been in Section B since 27 July 2026, no longer in Section A. For a machine builder that means a different regime, with the requirements landing through delegated acts in Annex III to Regulation (EU) 2023/1230 rather than directly through Chapter III of this Regulation. What stands: if you do not build the AI system yourself but put it in your product under your own brand, Article 2(1), point (e), and Article 25(3) make you the provider, with the obligations of Article 16, and not merely a customer of your software supplier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"List per product which Annex I legal act it falls under and whether that is Section A or Section B after the amendment of 27 July 2026, which conformity assessment procedure applies there, and which AI functions are safety components within the meaning of Article 3, point (14). Test classification not against the module you actually use but against whether the legislature prescribed enhanced scrutiny for that product type. For Section A products the provider follows the procedure required under that legal act and the requirements of Chapter III, Section 2, form part of that assessment; if you use the opt-out in Article 43(3), record which harmonised standards cover all requirements of Section 2. Determine whether Article 2(1), point (e), or Article 25(3) makes you the provider yourself. Plan on 2 August 2028 for Chapter III, and track separately that Articles 102 to 110 have applied since 27 July 2026. For existing products check whether Article 111(2) spares you as long as the design is not significantly changed, and whether 2 August 2030 applies for systems intended for use by public authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1-annex-i-product-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route","legacy_id":"raip:obligation:article-6-1bis-1quater-route","type":"obligation","slug":"article-6-1bis-1quater-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1a3c8f90e9a6725cbe17956c5c8b7e1eef30c09b708afd4f0758b446f53b35f","label":"Article 6(1a) to (1c): the tightened classification route","summary":"The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The legal text below is settled; our reading of the route is not, which is why the whole object stands as preliminary. Three things. First, the sharpest textual tension, and it is not where you would look for it. In the adopted text of paragraph 1a the qualifier \"non-safety related aspects of\" governs the entire list, including user assistance and performance optimisation. In recital 7 that qualifier attaches to quality control alone: it says this does not in particular include AI systems intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or non-safety related aspects for quality control operations. We read the operative text, so with the qualifier across the whole list. A defensible alternative is the recital-conform, narrower reading in which only quality control is limited to non-safety related aspects and the rest is excluded unconditionally. Second, what paragraph 1a looks at. The text says \"are used\", while recital 7 is explicit: the safety function should be an intended purpose of the system, determined by the provider, and the mere fact that an AI system is integrated into or operates within a regulated product does not, in itself, mean that it fulfils a safety function. That second sentence and the amended definition in Article 3, point (14), make this question less open than it seems; we read it as the intended purpose. The alternative reading remains that actual use decides, so that a provider loses the exclusion as soon as a customer deploys the system differently. Third, from when. The amended definition sits in Chapter I and operates now, and the paragraphs have been binding law since 27 July 2026. They steer a live classification only once the route itself applies: 2 December 2027 for Annex III, point 2, and 2 August 2028 for the Annex I route. A defensible alternative reading is that the paragraphs, sitting in Chapter III, Section 1, do not operate at all before the later date. One point of candour: the published definition object on Article 3, point (14), still carries the unamended text and the reading that a component need not have an identifiable safety function. That is exactly what is qualified here, and while both objects stand side by side the text in this object governs.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:assess-safety-component-role"],"evidence_ids":["praxikon:eu:ai-act:evidence:safety-component-assessment-record"],"control_ids":["praxikon:eu:ai-act:control:safety-component-reassessment-trigger"],"template_ids":["praxikon:eu:ai-act:template:article-6-1bis-1quater-legal-text"],"conditions":[{"id":"article-6-1-annex-i-route","operator":"any","description":"Applies where it must be determined whether an AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and whether that product is required to undergo a third-party conformity assessment. Because paragraph 1a writes itself for the purposes of this Regulation, the delimitation also bears on Annex III, point 2, where the notion of safety component is used for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity."},{"id":"article-6-1-section-a-only","operator":"all","description":"For the consequences under Chapter III only Annex I, Section A, counts. For products under Section B, including machinery since Regulation (EU) 2023/1230 was moved there, the amended Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 apply."}],"exceptions":[{"id":"article-6-1bis-non-safety-functions","operator":"not","description":"Paragraph 1a provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back: AI systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components."},{"id":"article-6-1quater-non-safety-conformity-assessment","operator":"not","description":"Paragraph 1c provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered as fulfilling the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Article 6(1) provides: irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts three paragraphs into Article 6. Paragraph 1a: \"For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.\" Paragraph 1b: \"Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.\" Paragraph 1c: \"A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).\"","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends the definition in Article 3, point (14). As amended it reads: \"safety component\" means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. Article 3 sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025. This amended definition therefore operates from the entry into force of the amending Regulation on 27 July 2026 and not only from some later application date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended Article 113, third paragraph, point (c), provides that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The added point (d) provides that Articles 102 to 110 shall apply from 27 July 2026. Annex III, point 2, uses the notion of safety component for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; that route falls under the 2 December 2027 date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation moves machinery out of Chapter III. In Annex I, Section A, point 1 (the reference to Directive 2006/42/EC) is deleted and Section B gains point 21: Regulation (EU) 2023/1230 on machinery. The amended Article 2(2) reads that for AI systems classified as high-risk in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. The amended Article 43(3) adds that the classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to manufacturers of products covered by Annex I, Section A, and that those manufacturers are not required to choose a procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if the Section A legislation does not require it. The new Article 2(13) provides that specific requirements or obligations under Articles 9 to 15 and 17 to 25 may be limited where Section A legislation provides an equivalent or higher level of protection, and obliges the Commission to adopt delegated acts on this by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"What changes in practice is what the discussion is about. Until now it was about whether your product falls under Annex I and whether a third party is involved. Those two questions remain, but a third one belongs in front of them: what function does your AI component actually perform. A recommendation model that optimises when a machine is serviced, or a model that improves throughput on a line, sits in the list in paragraph 1a, and such functions often ended up classified as safety components simply because they ran inside a regulated product. Be careful with quality control as an example: paragraph 1a names only the non-safety related aspects of it, and in many regulated products a vision model that flags deviations is safety QC. Paragraph 1b draws the line: as soon as failure or malfunctioning would endanger health and safety, the exclusion does not count. The question therefore moves from your product file to your failure analysis, and at most providers that analysis is recorded nowhere. Paragraph 1c is narrower: anyone who needed a third party only because of radio spectrum or electromagnetic interference does not meet paragraph 1, point (b), by that route. That paragraph too requires a weighing, because it works only if the third party is mandatory solely on account of those other risks; where your product falls under several Annex I acts, a second act may still satisfy the condition on health and safety grounds. Two things finally that move the stakes. Machinery no longer runs through this route: Regulation (EU) 2023/1230 now sits in Annex I, Section B, and for those products the amended Article 2(2) means Chapter III does not apply at all. And for Section A products the same Regulation pushes the other way: the amended Article 43(3) says expressly that classification under Article 6(1) does not affect the choice of conformity assessment procedure and pushes nobody towards a notified body who was not already headed there. So build your failure analysis as your own file, not as something you will have to put in front of a notified body anyway.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"This is our recommendation and not a legal duty: paragraphs 1a to 1c are delimiting rules and impose no obligation on anyone. First establish whether your product falls under Annex I, Section A or Section B; for Section B, which now includes machinery, Chapter III stops here. For Section A, record per AI component which function it performs, whether that is a safety function within the meaning of the amended Article 3, point (14), and what happens on failure or malfunctioning. Note which of the three paragraphs you apply and why. Use that file to support your own classification, not because a notified body asks for it: the amended Article 43(3) points the other way. Keep two dates apart: 2 December 2027 for the route via Annex III, point 2, and 2 August 2028 for the route via Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1bis-1quater-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-71-eu-database","legacy_id":"raip:obligation:article-71-eu-database","type":"obligation","slug":"article-71-eu-database","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ceaa3da5b4cb893e068c9cbe5094b7934da65e8a20cc7cf57546945c0b877c06","label":"Article 71: EU database for high-risk AI systems listed in Annex III","summary":"The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things about the law itself are unsettled here. First, the date. Article 71 falls under the general application date of 2 August 2026, while the entry duties in paragraphs 2 and 3 hang on the registration in Article 49, whose Annex III route was shifted to 2 December 2027 by Regulation (EU) 2026/1744. We therefore read the practical deadline as 2 December 2027. Two alternative readings are defensible, and they point in opposite directions: the mild one is that the database exists from 2 August 2026 and only the entering follows the later date, so whoever registers earlier is not being early but on time; the hard one is that the amended Article 113, third paragraph, point (c), names only Chapter III, Sections 1, 2 and 3, while Article 49 sits in Section 5 of that same Chapter, so the registration duty may not have moved with it and you may already be late rather than early. Anyone planning against this deadline is planning against our reading and not against a settled fact. Second, the Article 60 route. Article 60 sits in Chapter VI and the provider or prospective provider testing in real world conditions today must register under Article 60(4), point (c), in accordance with Article 71(4). Whether that route moved with the Annex III deferral or already runs under the general date of 2 August 2026 is unsettled. The fact that 2026/1744 widened the scope of Article 60 to Annex I Section A and placed an Article 60a alongside it for Annex I Section B makes that question larger rather than smaller. This object does not carry that duty and the status here says nothing about it. Settled, and therefore no longer a ground for the preliminary status: the content of Section B of Annex VIII. Article 1, point (42), of Regulation (EU) 2026/1744 deletes points 7 and 9, and the reading above follows that text rather than the base regulation. One cross-reference does follow from it that the legislator did not chase down: Article 49(4) is unamended and still lists point 9 of Section B for the secure section, a point that no longer exists. Whoever works through that list literally is looking for a field that is not there. In addition, and this expressly does not carry the status because it is not an unsettled reading but a coverage gap of this dataset: paragraphs 1 and 6 address the Commission, which is not an actor here, so this object carries only the entry duties of paragraphs 2 and 3; and paragraph 3 also names whoever acts on behalf of a public authority, a role that does not exist separately alongside the body governed by public law, so a private party registering on behalf of a public authority has to assess for itself whether paragraph 3 rests on it.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date"],"action_ids":["praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data"],"evidence_ids":["praxikon:eu:ai-act:evidence:eu-database-entry-record"],"control_ids":["praxikon:eu:ai-act:control:eu-database-entry-currency"],"template_ids":["praxikon:eu:ai-act:template:article-71-legal-text"],"conditions":[{"id":"article-71-scope","operator":"any","description":"Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use."}],"exceptions":[{"id":"article-71-exception-annex-iii-point-2","operator":"not","description":"Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database."},{"id":"article-71-exception-secure-section","operator":"not","description":"Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there."},{"id":"article-71-exception-real-world-testing","operator":"not","description":"Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission shall, in collaboration with the Member States, set up and maintain an EU database containing the information referred to in paragraphs 2 and 3 concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60, and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications the Commission shall consult the relevant experts, and when updating them the Board. Paragraph 2 provides that the data listed in Sections A and B of Annex VIII shall be entered into the database by the provider or, where applicable, by the authorised representative. Paragraph 3 provides that the data listed in Section C of Annex VIII shall be entered by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4). Paragraph 4 provides that, with the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner, and that the information should be easily navigable and machine-readable. The same paragraph provides that the information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible to the public. Paragraph 5 provides that the database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation, and that such information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer. Paragraph 6 provides that the Commission shall be the controller of the database, shall make adequate technical and administrative support available to providers, prospective providers and deployers, and that the database shall comply with the applicable accessibility requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 71(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex VIII sets out which information is submitted upon registration and kept up to date thereafter. Section A, for providers registering in accordance with Article 49(1), lists thirteen points, including the name, address and contact details of the provider and of the authorised representative, the trade name and any additional unambiguous reference allowing identification and traceability of the system, a description of the intended purpose and of the components and functions supported, a basic and concise description of the information used and of the operating logic, the status of the system, the details and a scanned copy of the notified body certificate where applicable, the Member States where the system is available, a copy of the EU declaration of conformity referred to in Article 47 and the electronic instructions for use, which are not provided for the law enforcement, migration, asylum and border control management areas of points 1, 6 and 7 of Annex III. Section C, for deployers registering under Article 49(3), lists five points: the name, address and contact details of the deployer, the same details of the person submitting information on its behalf, the URL of the entry of the system in the database by its provider, a summary of the findings of the fundamental rights impact assessment carried out in accordance with Article 27, and where applicable a summary of the data protection impact assessment. Neither Section was amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Section B","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 22 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 49(4) lists exhaustively what goes into the secure non-public section, and that is less than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. The final subparagraph provides that only the Commission and the national authorities referred to in Article 74(8) have access to the respective restricted sections of the database. Annex IX carries the information provided upon registration of testing in real world conditions and kept up to date thereafter, and lists five points: a Union wide unique single identification number of the testing, the name and contact details of the provider or prospective provider and of the deployers involved, a short description of the AI system and its intended purpose together with the information needed to identify it, a summary of the main characteristics of the testing plan, and information on the suspension or termination of the testing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 60(4), point (c), provides that the provider or prospective provider has registered the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management that registration takes place in the secure non-public section in accordance with Article 49(4), point (d), and for the systems referred to in point 2 of Annex III in accordance with Article 49(5). Article 60 sits in Chapter VI of the Regulation, on measures in support of innovation. That point (c) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(4), point (c), Article 49(4) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The scope of Article 60 itself was amended. Article 1, point (24), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 60(1) and Article 60(2): testing in real world conditions outside AI regulatory sandboxes is now also open to providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, alongside the systems listed in Annex III. Article 1, point (25), inserts an Article 60a for high-risk AI systems covered by the harmonisation legislation listed in Section B of Annex I: Member States may adopt frameworks for real-world testing for those systems, must notify the Commission of any such framework before implementing it, and those frameworks must among other things ensure compliance with Article 60(2), (3), (4)(d)-(j) and (5)-(9). The registration duty in Article 60(4), point (c), which refers to Article 71(4), falls outside that enumeration.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 1, point (40), of Regulation (EU) 2026/1744 amends the THIRD paragraph of Article 113, which is where points (a) to (d) sit. Point (40)(b) replaces point (c) with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Two things belong with that and are often left out: the exception for Article 6(5) falls outside this deferral, and point (40)(c) adds a point (d) under which Articles 102 to 110 apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 131 explains why the database exists and how far the public availability reaches. It names as the aim facilitating the work of the Commission and the Member States and increasing transparency towards the public, states that this part of the database should be publicly accessible and free of charge and that the information should be easily searchable, understandable and machine-readable, and that the database should be user-friendly, for example by offering search functionalities including through keywords, so that the general public can find the registration information. It adds that any substantial modification of high-risk AI systems should also be registered in the database, that access to the secure non-public section should be strictly limited to the Commission and, as regards their national section, to market surveillance authorities, and that the database should comply with the requirements of Directive (EU) 2019/882.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the entry as a publication and not as a form. Designate per system the natural person who has the legal authority to register, because paragraph 5 provides that their name and contact details go into the database. Write the description of the intended purpose, of the operating logic and, for a public deployer, the summary of the fundamental rights impact assessment so that you can let them be read without explanation. Settle the sequence in your procurement contract: point 3 of Section C asks for the URL of the entry of the system in the database by its provider, so a municipality can only complete its Section C after its supplier has entered Section A. Record within what period the supplier delivers that URL and what happens if it does not. Also record when the entry was last checked against reality and tie that to your change and decommissioning process, so that status, Member States and declaration of conformity move with it. On procurement, check that the system is listed in the database before you put it into use: if it is not listed, a deployer may not use it under Article 26(8) and has to inform the provider or the distributor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-71-eu-database","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-72-post-market-monitoring","legacy_id":"raip:obligation:article-72-post-market-monitoring","type":"obligation","slug":"article-72-post-market-monitoring","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6fe04840ffe25ded5e84488a9486d4fa3f46720b9c66ce47d2244110d9e33098","label":"Article 72: post-market monitoring","summary":"Systematic monitoring of high-risk AI in real use, after market placement.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-72-post-market-monitoring-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record"],"control_ids":["praxikon:eu:ai-act:control:article-72-post-market-monitoring-control"],"template_ids":["praxikon:eu:ai-act:template:article-72-post-market-monitoring-legal-text"],"conditions":[{"id":"article-72-post-market-monitoring-scope","operator":"all","description":"The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals."}],"exceptions":[{"id":"article-72-post-market-monitoring-exception","operator":"not","description":"The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes."}],"statements":[{"kind":"official_fact","text":"Article 72 obliges providers to operate a post-market monitoring system with a plan forming part of the technical documentation, collecting relevant real-world data to evaluate continued compliance with Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Compliance does not stop at go-live: this article turns compliance into a continuous state. For deployers it is also the basis to force suppliers to act on deviations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Design the monitoring together with the Article 12 logging: the same data flows feed both duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-72-post-market-monitoring","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 72 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-73-incident-reporting","legacy_id":"raip:obligation:article-73-incident-reporting","type":"obligation","slug":"article-73-incident-reporting","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df","label":"Article 73: serious incident reporting","summary":"The duty to report serious incidents with high-risk AI, under strict deadlines.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-73-incident-reporting-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-73-incident-reporting-record"],"control_ids":["praxikon:eu:ai-act:control:article-73-incident-reporting-control"],"template_ids":["praxikon:eu:ai-act:template:article-73-incident-reporting-legal-text"],"conditions":[{"id":"article-73-incident-reporting-scope","operator":"all","description":"A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment."}],"exceptions":[{"id":"article-73-incident-reporting-exception","operator":"not","description":"For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication."}],"statements":[{"kind":"official_fact","text":"Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 73 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-78-confidentiality","legacy_id":"raip:obligation:article-78-confidentiality","type":"obligation","slug":"article-78-confidentiality","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fe3d73fa9cc874bc4fc12b0f664ff4e60e68de553dfc7bf0c64c38bc1350c8e3","label":"Article 78: confidentiality of what you submit to an authority","summary":"The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:mark-confidential-material-on-submission"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-78-submission-register"],"control_ids":["praxikon:eu:ai-act:control:article-78-disclosure-review"],"template_ids":["praxikon:eu:ai-act:template:article-78-legal-text"],"conditions":[{"id":"article-78-scope","operator":"all","description":"Applies to all information and data obtained by the Commission, the market surveillance authorities, the notified bodies and any other natural or legal person involved in the application of this Regulation in carrying out their tasks and activities. The protection operates in accordance with Union or national law and not on its own."},{"id":"article-78-strict-necessity","operator":"all","description":"Paragraph 2 limits what an authority may request: only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of its powers in accordance with this Regulation and with Regulation (EU) 2019/1020. Two follow-on duties attach to that: adequate and effective cybersecurity measures, and deletion as soon as the data is no longer needed for the purpose for which it was obtained."}],"exceptions":[{"id":"article-78-trade-secrets-directive-carve-out","operator":"not","description":"The protection of intellectual property, confidential business information and trade secrets, including source code, applies except in the cases referred to in Article 5 of Directive (EU) 2016/943. Point (a) of paragraph 1 says so in as many words."},{"id":"article-78-information-exchange-unaffected","operator":"not","description":"Paragraph 4 provides that paragraphs 1, 2 and 3 do not affect the rights or obligations of the Commission, the Member States and their relevant authorities, or those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor the obligations of the parties concerned to provide information under criminal law of the Member States. Confidentiality under this article is therefore not a duty of silence between authorities."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a) the intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943; (b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits; (c) public and national security interests; (d) the conduct of criminal or administrative proceedings; (e) information classified pursuant to Union or national law. Paragraph 2 provides that the authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020, that they shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and that they shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides that, without prejudice to paragraphs 1 and 2, information exchanged on a confidential basis between the national competent authorities or between national competent authorities and the Commission shall not be disclosed without prior consultation of the originating national competent authority and the deployer when high-risk AI systems referred to in point 1, 6 or 7 of Annex III are used by law enforcement, border control, immigration or asylum authorities and when such disclosure would jeopardise public and national security interests. This exchange of information shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities. The second subparagraph of paragraph 3 provides that when the law enforcement, immigration or asylum authorities are providers of high-risk AI systems referred to in point 1, 6 or 7 of Annex III, the technical documentation referred to in Annex IV shall remain within the premises of those authorities, that those authorities shall ensure that the market surveillance authorities referred to in Article 74(8) and (9), as applicable, can, upon request, immediately access the documentation or obtain a copy thereof, and that only staff of the market surveillance authority holding the appropriate level of security clearance shall be allowed to access that documentation or any copy thereof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that paragraphs 1, 2 and 3 shall not affect the rights or obligations of the Commission, Member States and their relevant authorities, as well as those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor shall they affect the obligations of the parties concerned to provide information under criminal law of the Member States. Paragraph 5 provides that the Commission and Member States may exchange, where necessary and in accordance with relevant provisions of international and trade agreements, confidential information with regulatory authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of confidentiality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article as the answer to the question your supplier asks and that you ask yourself as soon as you have to hand something over. The protection is real and it names source code expressly, which is unusually explicit in Union law. But it is a duty of the recipient and not a right of refusal for the party submitting. Article 21(1) requires the provider, upon a reasoned request, to give all the information and documentation necessary to demonstrate conformity; Article 78 does not say you may withhold anything, it says what the recipient must do afterwards. Anyone who inverts that and refuses on grounds of confidentiality is legally empty-handed. Two limits on top, because they get missed in practice. The first is Article 5 of Directive (EU) 2016/943: that exception sits verbatim in point (a) and it covers, among other things, exercising the right to freedom of expression and information and revealing misconduct in the general public interest. The second is paragraph 4: between authorities, and when disseminating warnings, confidentiality does not operate as a lock. Your file can therefore reach another Member State without that being a breach. What does work in your favour is paragraph 2. That is a strict necessity test on the request itself, with a retention limit attached: deletion as soon as the data is no longer needed for the purpose for which it was obtained. That is a question you can put to an authority and whose answer you can record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"There is an asymmetry in this article that is rarely noticed. Paragraph 3 gives one set of parties a heavy extra protection: where a high-risk system from point 1, 6 or 7 of Annex III is used by a law enforcement, border control, immigration or asylum authority, information exchanged on a confidential basis may not be disclosed without prior consultation of the originating authority and the deployer, and the technical documentation stays physically within the premises of that authority where it is itself the provider. For a commercial provider in exactly the same Annex III areas that arrangement does not apply. The practical conclusion is not that one is better protected than the other, but that you need to know which side you are on: if you supply such an authority, your documentation travels a different path from your own archive, and you settle that path in the contract rather than after the fact. Note also what this article does not govern. It says nothing about the public availability of the EU database in Article 71, whose public part is meant to be found, and nothing about what a deployer must explain to an affected person under Article 86. Confidentiality towards a regulator and transparency towards a citizen are two separate tracks in this Regulation, and it is a mistake to try to close one with the other.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Mark on every submission which part you regard as confidential business information, trade secret or source code, and why, and keep a register of what you handed to whom on what date. That register is your only starting point if you later want to know whether something left the circle. When asked for additional data, ask about the necessity within the meaning of paragraph 2 and about the purpose for which the data is obtained, and record the answer; that is not a refusal and it is the only way to be able to invoke the retention limit of paragraph 2 later. Put in supplier contracts who receives a request from an authority, who decides what is handed over, and that the other party is informed within an agreed period. If you supply a law enforcement, border control, immigration or asylum authority, record where the technical documentation stays physically and who has access to it. Finally, do not assume that confidentiality releases you from Article 21: the duty to deliver on request stands apart from the recipient’s duty to handle what is delivered with care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-78-confidentiality","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements","legacy_id":"raip:obligation:article-8-compliance-with-requirements","type":"obligation","slug":"article-8-compliance-with-requirements","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f","label":"Article 8: compliance with the requirements for high-risk AI systems","summary":"High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.","topics":["conformity","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What the provision asks of a provider is settled; when it asks it has been derived here. Article 8 sits in Chapter III, Section 2, and names no date of its own. The timeline canon dates the high-risk requirements per route and not per chapter: 2 December 2027 for the systems that are high-risk through Annex III, and 2 August 2028 for those that are high-risk through Annex I. Those two dates do not fit in a field that carries one. `deadline_at` therefore carries 2 December 2027, the earlier of the two and the same date already carried by the objects for Articles 9 to 15. A defensible alternative reading is that a chapeau provision should carry no date of its own and that the dating belongs with the seven requirements it sits above; on that reading this field reads as the earliest of the two routes and not as the date of Article 8. On either reading: for a system inside a regulated product under Annex I, 2 December 2027 is too early and 2 August 2028 is the date that counts. What also remains open is the content of the second measure in paragraph 1. The generally acknowledged state of the art is not a term the Regulation defines and not a synonym for a harmonised standard; anyone who equates it with the standard of Article 40 closes an open measure. On Regulation (EU) 2026/1744. That text was retrieved after all on 6 September 2026 from the Publications Office Cellar service and is archived in data/ai-act/review/sources/reg-eu-2026-1744-nl.txt and -en.txt. The amending regulation carries forty-three amendment points in its Article 1; which of those are reflected in the local legal texts is recorded per point in data/ai-act/review/consolidation-manifest.json. Where a point touches this Article, that is stated below with the statement concerned.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification"],"control_ids":["praxikon:eu:ai-act:control:article-8-integrated-documentation-review"],"template_ids":["praxikon:eu:ai-act:template:article-8-legal-text"],"conditions":[{"id":"article-8-scope","operator":"all","description":"Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision."},{"id":"article-8-two-measures","operator":"all","description":"Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing."},{"id":"article-8-annex-i-product","operator":"any","description":"Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing."}],"exceptions":[{"id":"article-8-integration-is-a-choice","operator":"not","description":"The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that high-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements. Paragraph 2 provides that, where a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 8(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read Article 8 not as an eighth requirement alongside the seven of Articles 9 to 15, but as the provision that says how those seven are to be read. It does two things none of the seven does itself. The first is that it brings in a measure from outside the Regulation. Article 8 is the only article in Section 2 that names the generally acknowledged state of the art, and that means the bar moves. A file that sufficed at the first conformity assessment does not necessarily still suffice some years later, without a single word of the Regulation changing: what was the state of the art then is no longer the state of the art later. The Regulation provides no re-certification rhythm for this beyond the substantial modification of Article 43(4), so anyone who does not set a rhythm of their own has none. Note also what the measure is not. The state of the art is not a synonym for a harmonised standard: Article 40 gives a presumption of conformity to whoever applies such a standard, but Article 8 sets an open measure alongside it that does not stop applying once the standard has been ticked off. The second is that paragraph 1 designates the risk management system of Article 9 as the instrument through which compliance with the other requirements is assessed. Article 9 is therefore not one requirement beside the other six but the file in which you show that you have met the other six at the right level. An organisation that keeps its risk analysis as a separate document beside the technical documentation misses exactly that connection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 is the anti-duplication provision, and in practice it is rarely used. It concerns the product that contains an AI system and falls both under this Regulation and under the Union harmonisation legislation of Section A of Annex I: that is precisely the route of Article 6(1). Two different things are stated. The first is an allocation: the provider is responsible for his product being fully compliant with everything the sectoral legislation requires. It does not say that the AI Act replaces or lightens the sectoral requirements, nor that the sectoral assessment swallows the requirements of Section 2; it says that both stacks apply at once and that the provider of the product covers both. The second is a choice, not a duty: he may integrate the testing and reporting processes, the information and the documentation on the product into the documentation and procedures the sectoral legislation already prescribes. We see two mistakes there. The first is that the AI Act file is built beside the existing technical file, with two versions of the same risk analysis that drift apart after two releases; that is exactly the duplication paragraph 2 seeks to avoid. The second is that the integration happens but cannot be found. Whoever enters the sectoral conformity assessment of Article 43(3) must be able to point, per requirement of Articles 9 to 15, to where in the existing file the answer sits. Integrating is therefore not merging into invisibility; it is a cross-reference per requirement, and that is the form in which the choice of paragraph 2 actually saves work.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record once, per high-risk system, what you regard as the generally acknowledged state of the art, with the sources: which harmonised standards or common specifications you apply, which of them you do not apply and why, and which evaluation method, benchmark or test set you use for this application area. Attach a fixed re-assessment moment to it, for instance annually and at every release, and hang that record on the risk management file of Article 9 rather than on a separate document; paragraph 1 designates that file as the instrument through which compliance is assessed. Note against which intended purpose each requirement of Articles 9 to 15 has been met, so that a change of intended purpose visibly touches the whole series. If your system sits in a product also covered by Section A of Annex I, make the choice of paragraph 2 explicit before you start and record who made it: one combined file or two files. If you combine, build a cross-reference table that points, per requirement of Section 2, to where in the existing technical file the answer sits, and let that table travel through the sectoral assessment. If you keep two files, record who keeps them in step and on which change both are updated.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-9-risk-management","legacy_id":"raip:obligation:article-9-risk-management","type":"obligation","slug":"article-9-risk-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53","label":"Article 9: risk management system","summary":"A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-9-risk-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-9-risk-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-9-risk-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-9-risk-management-legal-text"],"conditions":[{"id":"article-9-risk-management-scope","operator":"all","description":"The system is high-risk under Article 6 and the provider places it on the market or puts it into service."}],"exceptions":[{"id":"article-9-risk-management-exception","operator":"not","description":"Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope."}],"statements":[{"kind":"official_fact","text":"Article 9 requires a risk management system as a continuous, iterative process across the entire lifecycle, with identification, analysis, evaluation and mitigation of risks to health, safety and fundamental rights, and testing to determine the most appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is not a one-off risk analysis but a living process: most organisations have an assessment, but no cycle that reruns on every change. The cycle is what a supervisor will request.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start the risk management file now for systems that will become high-risk towards 2 December 2027: today’s design and procurement choices determine tomorrow’s residual risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-9-risk-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 9 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:conformity-ce-registration","legacy_id":"raip:obligation:conformity-ce-registration","type":"obligation","slug":"conformity-ce-registration","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2ba6e413ff6670e5896f31ee36839ff048b04b714b4c13decc1ed8e0d2f9186","label":"Articles 43-49: conformity assessment, CE and registration","summary":"The route from assessment to CE marking and EU database registration before market placement of high-risk AI.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:conformity-ce-registration-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:conformity-ce-registration-record"],"control_ids":["praxikon:eu:ai-act:control:conformity-ce-registration-control"],"template_ids":["praxikon:eu:ai-act:template:conformity-ce-registration-legal-text"],"conditions":[{"id":"conformity-ce-registration-scope","operator":"all","description":"The provider places a high-risk system on the market; public deployers also register their use."}],"exceptions":[{"id":"conformity-ce-registration-exception","operator":"not","description":"For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking."}],"statements":[{"kind":"official_fact","text":"Article 43 governs the conformity assessment, Article 47 the EU declaration of conformity, Article 48 the CE marking and Article 49 the registration in the EU database before market placement or putting into service, including registration of the Article 6(3) assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buyers this is the simplest supplier check there is: ask for the declaration of conformity and the registration number. No declaration means the system may not be there by 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Plan the conformity route backwards from 2 December 2027: standards selection, assessment, declaration and registration together take months, not weeks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/conformity-ce-registration","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 43-49 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:value-chain-representative","legacy_id":"raip:obligation:value-chain-representative","type":"obligation","slug":"value-chain-representative","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38342a3db27dd0959f29e10415d9217331e2056d163b17a95fef284213092d52","label":"Articles 22-25: value chain and authorised representative","summary":"Role shifts in the AI value chain and the mandatory representative for non-EU providers.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:value-chain-representative-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:value-chain-representative-record"],"control_ids":["praxikon:eu:ai-act:control:value-chain-representative-control"],"template_ids":["praxikon:eu:ai-act:template:value-chain-representative-legal-text"],"conditions":[{"id":"value-chain-representative-scope","operator":"all","description":"A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU."}],"exceptions":[{"id":"value-chain-representative-exception","operator":"not","description":"Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties."}],"statements":[{"kind":"official_fact","text":"Article 25 provides that a distributor, importer, deployer or third party becomes the provider when it puts its name on a high-risk system, substantially modifies it or changes its intended purpose so it becomes high-risk; Article 22 obliges third-country providers to appoint a written authorised representative in the Union.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The most dangerous role switch is the unintended one: your own layer on top of a procured model, your own brand on a tool, and you suddenly carry the full provider duties. This belongs as a standing question in every AI project.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the role question in the AI register and in project gates, and contractually define who supplies which information and cooperation on changes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/value-chain-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 22-25 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:annex-iii-classifier","legacy_id":"raip:template:annex-iii-classifier","type":"template","slug":"annex-iii-classifier","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dae4e0cfcd90846c10fa8ab1777f21308410df28876ab6df9e201a05ea6f9155","label":"Annex III classification route","summary":"Public classifier for the high-risk use cases in Annex III.","topics":["high-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/annex-iii","label":"Open the eight public classification routes"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text","legacy_id":"raip:template:annex-iii-eight-areas-legal-text","type":"template","slug":"annex-iii-eight-areas-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5ef654d7cb162b35619676f49abb8eb27afe33e30747965ffcca11cd78f8e1b","label":"Full text of Annex III","summary":"The full text of Annex III, with all eight areas and their lettered subpoints, in the public AI Act Explorer and on EUR-Lex.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-10-data-governance-legal-text","legacy_id":"raip:template:article-10-data-governance-legal-text","type":"template","slug":"article-10-data-governance-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c4525b47886b0b8562a281f37b58eb8c859ae33c2f6ab6398220d1bf7b9936d3","label":"Full text of Article 10","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/10","label":"Read Article 10 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text","legacy_id":"raip:template:article-11-technical-documentation-legal-text","type":"template","slug":"article-11-technical-documentation-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b4a8665dde718cd9f5128ee43bae41a35bb1e93957f80397aea2c0d6ce9f675","label":"Full text of Article 11","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/11","label":"Read Article 11 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-111-legal-text","legacy_id":"raip:template:article-111-legal-text","type":"template","slug":"article-111-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38dd22cf8878f0f09dbd8e27001f8de7d6cbe4017cb5495e1203f560fc43c032","label":"Full text of Article 111","summary":"The legal text on EUR-Lex: the base text in Regulation (EU) 2024/1689 and the replacement of paragraph 2 and the addition of paragraph 4 in Regulation (EU) 2026/1744. Reading only the base text means reading the 2024 version.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-12-logging-legal-text","legacy_id":"raip:template:article-12-logging-legal-text","type":"template","slug":"article-12-logging-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0b388455f428f11dfb5468f87917aefff00ef5a2a79a9e13bafe13ef4285badf","label":"Full text of Article 12","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/12","label":"Read Article 12 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-13-instructions-legal-text","legacy_id":"raip:template:article-13-instructions-legal-text","type":"template","slug":"article-13-instructions-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"417dfd58e9c213b4628e05547f8ba669a5b1a1055dcc9d8168c4800c87ea4620","label":"Full text of Article 13","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/13","label":"Read Article 13 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-14-human-oversight-legal-text","legacy_id":"raip:template:article-14-human-oversight-legal-text","type":"template","slug":"article-14-human-oversight-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"503e54076c77a49f21f87deeb88184e6553063cb2cab5f172eb9cbea96c9c4b1","label":"Full text of Article 14","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/14","label":"Read Article 14 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-15-accuracy-robustness-legal-text","legacy_id":"raip:template:article-15-accuracy-robustness-legal-text","type":"template","slug":"article-15-accuracy-robustness-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"79ee3412f8d237f653302e9cf55ba8b88316d39bb0ad16e64b2e9e990e55f56c","label":"Full text of Article 15","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/15","label":"Read Article 15 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-16-provider-obligations-legal-text","legacy_id":"raip:template:article-16-provider-obligations-legal-text","type":"template","slug":"article-16-provider-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"838d057e1bea1f6bdaa626ad24caaca47eb7c7c9e7f2b79df5f2c2ed388b0cc1","label":"Full text of Article 16","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-16-provider-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/16","label":"Read Article 16 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-17-quality-management-legal-text","legacy_id":"raip:template:article-17-quality-management-legal-text","type":"template","slug":"article-17-quality-management-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2ae55f99f1425e8cb858449719be7600a688e08cbc12fdb3d587349e6ee5fdde","label":"Full text of Article 17","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/17","label":"Read Article 17 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-18-legal-text","legacy_id":"raip:template:article-18-legal-text","type":"template","slug":"article-18-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5b19503bf7f4e44688a2cb2d46d0b3fd964c943e51457f098e6fe67621b617b6","label":"Full text of Article 18","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-23-importer-obligations-legal-text","legacy_id":"raip:template:article-23-importer-obligations-legal-text","type":"template","slug":"article-23-importer-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a496206177b88595c0276aede65fe7f0033c3c4c9816f5f7a1f2ac1dbdba380b","label":"Full text of Article 23","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-23-importer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/23","label":"Read Article 23 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-24-distributor-obligations-legal-text","legacy_id":"raip:template:article-24-distributor-obligations-legal-text","type":"template","slug":"article-24-distributor-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"db0d18d585624e430c992f65eb6f1af0b9bb5164e61ac183727a4af1c8a34d13","label":"Full text of Article 24","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-24-distributor-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/24","label":"Read Article 24 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-26-deployer-obligations-legal-text","legacy_id":"raip:template:article-26-deployer-obligations-legal-text","type":"template","slug":"article-26-deployer-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d5675ff568eed50bfad51b263032a2053826fa1ea99c99abe9bb592f92be72c2","label":"Full text of Article 26","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-26-deployer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/26","label":"Read Article 26 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-28-39-legal-text","legacy_id":"raip:template:article-28-39-legal-text","type":"template","slug":"article-28-39-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2edf393dfa2fe74bf11228eb660a7444be2bfb03743c383af94184e0cb25b7e1","label":"Full text of Articles 28 to 39","summary":"The full legal text of Chapter III, Section 4, in the public AI Act Explorer.","topics":["conformity","governance","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-4-measures-plan","legacy_id":"raip:template:article-4-measures-plan","type":"template","slug":"article-4-measures-plan","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"857b4bd32f2868a918b0191bcbd624dcb65accca8e079afc2b3bbe0b3841a101","label":"AI literacy measures plan","summary":"Public route for structuring measures by role and context.","topics":["ai-literacy","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/article-4-evidence-dossier-checklist","label":"Open public evidence checklist"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-4a-legal-text","legacy_id":"raip:template:article-4a-legal-text","type":"template","slug":"article-4a-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ed6adebe93cb3f7dc0c2e75c30d886e16819253dd953317fafbd656e6480fac8","label":"Full text of Article 4a","summary":"The full text of Article 4a as inserted and published in the Official Journal of 24 July 2026.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-5-legal-text","legacy_id":"raip:template:article-5-legal-text","type":"template","slug":"article-5-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"035492482a5c481e790573a6949745f1da8b49792bfb28bb377c4bba7c92d48f","label":"Full text of Article 5","summary":"The full legal text of the prohibited practices with all categories and exceptions, in the public AI Act Explorer.","topics":["prohibited-practices","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/5","label":"Read Article 5 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-50-checklist","legacy_id":"raip:template:article-50-checklist","type":"template","slug":"article-50-checklist","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"165eaabca3372655df0955fa11ee94e3125d67b5adfa1a7f26157df5f031b26f","label":"Article 50 checklist","summary":"Public decision route for the distinct transparency obligations.","topics":["template","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/ai-transparency-notice","label":"Open public transparency template"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-52-legal-text","legacy_id":"raip:template:article-52-legal-text","type":"template","slug":"article-52-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0d6085f7e5a1c6077dfe6516ca71e7c72924b01b8c61674bdc18d18b2d740bcf","label":"Full text of Article 52","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-54-legal-text","legacy_id":"raip:template:article-54-legal-text","type":"template","slug":"article-54-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"20ea620fe652fa973a8cdfb0a2f0be479c107896b90803a79ebe529a3eb5d896","label":"Full text of Article 54","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text","legacy_id":"raip:template:article-55-gpai-systemic-risk-legal-text","type":"template","slug":"article-55-gpai-systemic-risk-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a78c5debbb73f96dc47f83d6dfb91f50e9ed69d412126deaa23afb74bbe8e31e","label":"Full text of Article 55","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai-systemic-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/55","label":"Read Article 55 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-56-legal-text","legacy_id":"raip:template:article-56-legal-text","type":"template","slug":"article-56-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a88041020566d088c724fed811dea3f8f4b46e002abf1ea84943798a7d3c12b1","label":"Full text of Article 56","summary":"The full legal text in the public AI Act Explorer.","topics":["governance","gpai","gpai-systemic-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-57-regulatory-sandboxes-legal-text","legacy_id":"raip:template:article-57-regulatory-sandboxes-legal-text","type":"template","slug":"article-57-regulatory-sandboxes-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a450df3b7e1b9407df652959c71ba0c2406714c0fe9b00512d3ffa3953d78b14","label":"Full text of Article 57","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/57","label":"Read Article 57 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-6-1-legal-text","legacy_id":"raip:template:article-6-1-legal-text","type":"template","slug":"article-6-1-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"94d919e36dac16c0d666fc5ab294ed86dd101260cb47a68805a41c8ed62d41b9","label":"Full text of Article 6 and Annex I","summary":"The full legal text in the public AI Act Explorer, alongside the amending Regulation.","topics":["high-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-6-1bis-1quater-legal-text","legacy_id":"raip:template:article-6-1bis-1quater-legal-text","type":"template","slug":"article-6-1bis-1quater-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f96e5ef70dd116756fb84b8177f61c2216721b42a51448d8f846fcc907ad885c","label":"Full text of the inserted paragraphs","summary":"The full text of the amendment to Article 6 as published in the Official Journal of 24 July 2026, inserted by Article 1, point (8), of Regulation (EU) 2026/1744.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"in_force","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-60-real-world-testing-legal-text","legacy_id":"raip:template:article-60-real-world-testing-legal-text","type":"template","slug":"article-60-real-world-testing-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3cb72c16ed3875f5a3a60a7863584dc3d266458e6321dfd3147f848e8117e94d","label":"Full text of Article 60","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-60-real-world-testing"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/60","label":"Read Article 60 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-71-legal-text","legacy_id":"raip:template:article-71-legal-text","type":"template","slug":"article-71-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8a1119c835b0c193ee9babdb1c971fe94175cc6d036c84cce14d5b06733f1e29","label":"Full text of Article 71","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-72-post-market-monitoring-legal-text","legacy_id":"raip:template:article-72-post-market-monitoring-legal-text","type":"template","slug":"article-72-post-market-monitoring-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1efe1f458525f1f6e47913d9ae599436bbc52f3279073f80478f74c1fe6e7880","label":"Full text of Article 72","summary":"The full legal text in the public AI Act Explorer.","topics":["post-market","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/72","label":"Read Article 72 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-73-incident-reporting-legal-text","legacy_id":"raip:template:article-73-incident-reporting-legal-text","type":"template","slug":"article-73-incident-reporting-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f22615858521d40a4f31851f27377f587e2f8cbdccb351ee2e6756d4d23706be","label":"Full text of Article 73","summary":"The full legal text in the public AI Act Explorer.","topics":["post-market","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/73","label":"Read Article 73 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-78-legal-text","legacy_id":"raip:template:article-78-legal-text","type":"template","slug":"article-78-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38acb4e27d0f5910d94c017f7ac296770ef0755c26c294021c73fcb24c6b0a4b","label":"Full text of Article 78","summary":"The full legal text in the public AI Act Explorer.","topics":["enforcement","governance","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-8-legal-text","legacy_id":"raip:template:article-8-legal-text","type":"template","slug":"article-8-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d31f2f1852cfa24ffc8c354279e254efad2e321cdc7593aa0f8276abb6273173","label":"Full text of Article 8","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-9-risk-management-legal-text","legacy_id":"raip:template:article-9-risk-management-legal-text","type":"template","slug":"article-9-risk-management-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a9514f57564fd4a3e11a591c10c252f43e0e34c72665cb90781ba7e689bb0f69","label":"Full text of Article 9","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/9","label":"Read Article 9 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:conformity-ce-registration-legal-text","legacy_id":"raip:template:conformity-ce-registration-legal-text","type":"template","slug":"conformity-ce-registration-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da4e79a386e5b81a43a23d49b7934181d9a557f404f917b7cbbdb9f6b0986cfa","label":"Full text of Article 43","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/43","label":"Read Article 43 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:fria-questionnaire","legacy_id":"raip:template:fria-questionnaire","type":"template","slug":"fria-questionnaire","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"12fdf535a33a65f7bf33ab56dbdc41763fd6bca2a7906eded6a46083b829990b","label":"FRIA questionnaire","summary":"Public generator for structuring a fundamental rights impact assessment.","topics":["fundamental-rights","template"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/fria","label":"Open public FRIA template"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:gpai-guide","legacy_id":"raip:template:gpai-guide","type":"template","slug":"gpai-guide","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a2469dd7c21ddf62f3b35aa0078b856acda090edba8b66b46aef18f7a3abfd3c","label":"GPAI obligations route","summary":"Public guide to GPAI model obligations and exceptions.","topics":["gpai","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/gpai-gids","label":"Open GPAI guide"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:value-chain-representative-legal-text","legacy_id":"raip:template:value-chain-representative-legal-text","type":"template","slug":"value-chain-representative-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd85b9ea413e52e72f7df326246c40517c3d873c63035c874a97911ff4d7797e","label":"Full text of Article 25","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/25","label":"Read Article 25 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":{"nl":"CEN-CENELEC JTC 21: Europese normen onder normalisatieverzoek M/613","en":"CEN-CENELEC JTC 21: European standards under standardisation request M/613"},"publisher":{"nl":"CEN-CENELEC JTC 21","en":"CEN-CENELEC JTC 21"},"canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"952a677040f5a8facb59fc7e89676b9127e1c9e4a36e191112c7f7c1dcd45a94","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:cen-cenelec-jtc21"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":{"nl":"Vragen en antwoorden over AI-geletterdheid","en":"AI literacy questions and answers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"a07599c1c5af5cb25fbe1a72caecc7f0093326202cea7949a43d7a89c6c7f038","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-literacy-qa"},{"id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","title":{"nl":"Richtsnoeren over de definitie van een AI-systeem, C(2025) 5053 final","en":"Guidelines on the definition of an AI system, C(2025) 5053 final"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null,"source_version":"c-2025-5053-final-2025-07-29","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"51b321c2804bc3c4deb4c0d3b19d039a9b8eecaf06c56a4bb3ade3f7d36128b8","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-system-definition-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":{"nl":"Richtsnoeren over Artikel 50","en":"Guidelines on Article 50"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"3c3d066f0294692b398f096861adb89198f3d6062939237a97b35fa9ced4d39d","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-article-50-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":{"nl":"Ontwerprichtsnoeren over de classificatie van hoog-risico AI-systemen","en":"Draft guidelines on the classification of high-risk AI systems"},"publisher":{"nl":"Europese Commissie (AI Office)","en":"European Commission (AI Office)"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"1560a59f57f0d9c0c6fe9d1a370772d43e93c21c6686db6ab198f44712dcb8d3","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-draft-high-risk-classification-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","title":{"nl":"Richtsnoeren over verboden AI-praktijken, C(2025) 5052 final","en":"Guidelines on prohibited AI practices, C(2025) 5052 final"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null,"source_version":"c-2025-5052-final-2025-07-29","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"5abfc9ac7322566cc0c6f47865437049be46dd0c2a12f282f247e123667329ca","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-prohibited-practices-guidelines"},{"id":"praxikon:eu:ai-act:source:gpai-code-of-practice","title":{"nl":"Praktijkcode voor AI voor algemene doeleinden","en":"General-Purpose AI Code of Practice"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null,"source_version":"published-2025-07-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"c5c59097f402c229249c30efeda4e895ca79c2617adcdf954c890c5456cd4123","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:gpai-code-of-practice"},{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"},{"id":"praxikon:eu:ai-act:source:transparency-code-of-practice","title":{"nl":"Praktijkcode over transparantie van door AI gegenereerde inhoud","en":"Code of Practice on transparency of AI-generated content"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content","eli":null,"source_version":"published-2026-06-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"81a4a50dce1b7f73e526f865ce726eaf7678774c869a0b54ace6c2c4f9fd4a28","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:transparency-code-of-practice"}]},"links":{"self":"https://www.praxikon.com/api/v1/entities?effective_at=2026-07-27T00%3A00%3A00.000Z&lang=en","alternate":"https://www.praxikon.com/api/v1/entities?effective_at=2026-07-27T00%3A00%3A00.000Z&lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}