{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":573,"filters":{"id":null,"type":null,"role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:action:annex-iii-article-6-3-justification","legacy_id":"raip:action:annex-iii-article-6-3-justification","type":"action","slug":"annex-iii-article-6-3-justification","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1da584826886a188a62f3c82c7f18ffc5eaf923ee2d7292ff096fd7ebb68ac9","label":"Justify the Article 6(3) exception against each individual condition","summary":"Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"annex-iii-article-6-3-justification-scope","operator":"all","description":"The intended purpose of the system falls within a use case listed in Annex III."}],"exceptions":[{"id":"annex-iii-article-6-3-justification-exception","operator":"not","description":"Notwithstanding the first subparagraph of Article 6(3), an AI system referred to in Annex III shall always be considered high-risk where it performs profiling of natural persons."}],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:annex-iii-classify","legacy_id":"raip:action:annex-iii-classify","type":"action","slug":"annex-iii-classify","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"45e9f9a5d90d79db8c90f170ae677cbdcf3189bb6e00ce819a3d88bc2a88d521","label":"Classify the use case and document the outcome","summary":"Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:annex-iii-profiling-test","legacy_id":"raip:action:annex-iii-profiling-test","type":"action","slug":"annex-iii-profiling-test","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"63c6b8df950a34f7be05999029d00cd5df74caceb857ce715a7401f3bc1e8f0e","label":"Run the profiling test before invoking the Article 6(3) exception","summary":"Establish as the first question whether the system performs profiling of natural persons; if yes, the Article 6(3) route falls away and the system remains high-risk, regardless of the four conditions.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"annex-iii-profiling-test-scope","operator":"all","description":"You are considering relying on Article 6(3) for a system falling under Annex III."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:appoint-and-empower-human-oversight","legacy_id":"raip:action:appoint-and-empower-human-oversight","type":"action","slug":"appoint-and-empower-human-oversight","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eec7cdecf192030cea45cc3409140b902d19749b8b04eae460632c92a7a764c7","label":"Assign human oversight and give those people a mandate","summary":"Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-26-deployer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"appoint-and-empower-human-oversight-scope","operator":"all","description":"To be carried out before putting into service and again on every change to the intended purpose or to the provider's instructions for use."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:appoint-gpai-authorised-representative","legacy_id":"raip:action:appoint-gpai-authorised-representative","type":"action","slug":"appoint-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f5a3eafa324e8ae8618656496fa8bd7c323e3a6f36d5993f3ab92493fe6d2c10","label":"Appoint an authorised representative and record the mandate","summary":"Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"appoint-gpai-authorised-representative-scope","operator":"all","description":"To be carried out before the model is placed on the Union market, and to be revisited on every change to the model, to the provider establishment or to the licence under which the model is released. For models placed on the market before 2 August 2025, the Article 111(3) period runs until 2 August 2027."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-10-data-governance-act","legacy_id":"raip:action:article-10-data-governance-act","type":"action","slug":"article-10-data-governance-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"07e6caa997eb341b80bd70dbe72375bbb20b6c2e8244781b1a78e5aa78bd5f99","label":"Set up data governance per dataset","summary":"Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-11-technical-documentation-act","legacy_id":"raip:action:article-11-technical-documentation-act","type":"action","slug":"article-11-technical-documentation-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"aac68683836ab7438b276e37db525147120ee1c8b17504deb8afdf463775028e","label":"Build the technical file per Annex IV","summary":"Document system description, development process, data, oversight measures, performance and risk management before market placement.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-12-logging-act","legacy_id":"raip:action:article-12-logging-act","type":"action","slug":"article-12-logging-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bc72111cd908749f45f4505a27037916f84201afd262d163734cd1e1cd1570d6","label":"Design logging into the system","summary":"Ensure the system automatically records events relevant to risk identification and post-market monitoring.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-13-instructions-act","legacy_id":"raip:action:article-13-instructions-act","type":"action","slug":"article-13-instructions-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2c933d039adc24eb26671c5b345f5af373daf4d22eb3eb65ae4cc0613e8d13fd","label":"Provide complete instructions for use","summary":"Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-14-human-oversight-act","legacy_id":"raip:action:article-14-human-oversight-act","type":"action","slug":"article-14-human-oversight-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3db8554f83cb279256051eba2cac4037890fa7aa612a9bec06cdd1419d865da9","label":"Design and assign effective human oversight","summary":"Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-15-accuracy-robustness-act","legacy_id":"raip:action:article-15-accuracy-robustness-act","type":"action","slug":"article-15-accuracy-robustness-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"308f37fc79ba9447a16e936a2d5cd3489b9c5c81080082781cbf3bf9ef6ba128","label":"Set and test performance and security levels","summary":"Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-17-quality-management-act","legacy_id":"raip:action:article-17-quality-management-act","type":"action","slug":"article-17-quality-management-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"353c4c34130f1911c4fc303b0b612f64dc2bf858c7f1ed3188fa121bdc142c2c","label":"Set up an AI quality management system","summary":"Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-4-measures","legacy_id":"raip:action:article-4-measures","type":"action","slug":"article-4-measures","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f3699a4a50d321f929398b3e22a09717b41cb61219099a76c50c7fe3e847bba","label":"Take role- and context-specific AI literacy measures","summary":"Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-4-role-needs-matrix","legacy_id":"raip:action:article-4-role-needs-matrix","type":"action","slug":"article-4-role-needs-matrix","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a94c4cdce929acd7ae41627b37fa94d983d6f3718258367de9b97331d98db928","label":"Determine per role which knowledge is needed to use the specific system responsibly","summary":"Map roles against the AI systems they use and record per combination what a person must be able to judge: what the system does, where it fails, who it is applied to, and when to intervene or escalate.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-4-role-needs-matrix-scope","operator":"all","description":"Your organisation is a provider or deployer of at least one AI system within scope."}],"exceptions":[{"id":"article-4-role-needs-matrix-exception","operator":"not","description":"Article 4 prescribes no specific course format, exam or certificate and does not require a guaranteed individual level."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-4-tool-and-onboarding-instruction","legacy_id":"raip:action:article-4-tool-and-onboarding-instruction","type":"action","slug":"article-4-tool-and-onboarding-instruction","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7a3565a8f233a829e5047045e496a834aa78f9b9961363183761263ea86eeb47","label":"Deliver instruction at the moment a new tool or a new employee arrives","summary":"Attach the literacy measure to two fixed moments in existing processes: the rollout of a new AI tool and the onboarding of anyone gaining access to an existing tool.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-4-tool-and-onboarding-instruction-scope","operator":"all","description":"A new AI tool is put into use or a person gains access to an existing AI tool."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-5-screen","legacy_id":"raip:action:article-5-screen","type":"action","slug":"article-5-screen","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"04909810be70c58c1d7e803ba7db9de2f0b2097bfaeb94e6b843cfb674568843","label":"Screen every use case against Article 5 first","summary":"Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.","topics":["prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-50-disclosure","legacy_id":"raip:action:article-50-disclosure","type":"action","slug":"article-50-disclosure","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"99fae5953121e6ee0cea8f3714e4532267ff91f1f18cdb816068d17f3aab51f0","label":"Implement the applicable disclosure, marking or label","summary":"First determine which paragraph of Article 50 applies, then implement the specific transparency measure.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-50-editorial-labelling-policy","legacy_id":"raip:action:article-50-editorial-labelling-policy","type":"action","slug":"article-50-editorial-labelling-policy","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1410894d5506c9cdc098126a0f01f524d239c97a7f54b5b3bf76382a5359f920","label":"Record per publication channel when AI text carries a disclosure and who holds editorial responsibility","summary":"Determine per channel whether the text is published to inform the public on matters of public interest, who performs the human review, who holds editorial responsibility, and which standard wording you use when the disclosure is required.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-editorial-labelling-policy-scope","operator":"all","description":"You are a deployer and publish content generated or manipulated, wholly or partly, by an AI system."}],"exceptions":[{"id":"article-50-editorial-labelling-policy-exception","operator":"not","description":"The Article 50(4) duty does not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-50-scenario-triage","legacy_id":"raip:action:article-50-scenario-triage","type":"action","slug":"article-50-scenario-triage","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dc033c20583465aae87a1bf8e67231cd4e90dd38804a7d491fea62bf5382f1dc","label":"Test every system in your AI register against the five Article 50 scenarios","summary":"For each AI system, walk through the distinct Article 50 scenarios (direct interaction, synthetic output, emotion recognition or biometric categorisation, deep fake, published text on matters of public interest) and record per paragraph whether it applies, does not apply or falls under an exception, with the reason.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-scenario-triage-scope","operator":"all","description":"The system is in your AI register and is placed on the market, put into service or used in the Union."}],"exceptions":[{"id":"article-50-scenario-triage-exception","operator":"not","description":"Article 50(1) does not apply where it is obvious, from the point of view of a reasonably well-informed, observant and circumspect natural person and taking into account the circumstances and the context of use, that the person is interacting with an AI system. In addition, paragraphs 1 to 4 each contain an exception for AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties. In paragraph 1 that latter exception does not apply to systems available for the public to report a criminal offence."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act","legacy_id":"raip:action:article-55-gpai-systemic-risk-act","type":"action","slug":"article-55-gpai-systemic-risk-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"22f1e83c282484613e9a5c0fd38afcaa111825c884177c792a1adfa24c94fa94","label":"Perform model evaluations and risk mitigation","summary":"Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-57-sandbox-application-and-plan","legacy_id":"raip:action:article-57-sandbox-application-and-plan","type":"action","slug":"article-57-sandbox-application-and-plan","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"456e8aa52101442982f9a45b07093d8092ed0537717d810f14faa9184dffd3f5","label":"Apply to a sandbox and agree the sandbox plan","summary":"Apply to the competent authority, agree a specific sandbox plan, and record which uncertainty about the Regulation you want resolved inside the sandbox.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-57-sandbox-application-and-plan-scope","operator":"all","description":"Applies as soon as you decide to enter an AI regulatory sandbox as a provider or prospective provider, possibly in partnership with a deployer or another third party."}],"exceptions":[{"id":"article-57-sandbox-application-and-plan-exception","operator":"not","description":"Article 58(2), point (d), requires the implementing acts to ensure access free of charge for SMEs and start-ups, subject to exceptional costs that the authority may recover in a fair and proportionate manner. The Regulation does not extend that free access to larger undertakings. Check with the authority concerned which cost regime it applies for as long as the implementing acts have not been adopted."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 58 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-60-testing-plan-and-authorisation","legacy_id":"raip:action:article-60-testing-plan-and-authorisation","type":"action","slug":"article-60-testing-plan-and-authorisation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1217f5cd26f004ac01e83945ae53d4bceba7a23b98c26504248857c1446f8f04","label":"Submit the testing plan, obtain approval and register the test","summary":"Draw up a real-world testing plan, submit it to the market surveillance authority, obtain approval, register the test with a Union-wide unique single identification number, and record the division of roles with your deployer.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-60-real-world-testing"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-60-testing-plan-and-authorisation-scope","operator":"all","description":"Applies before you start testing in real world conditions outside a sandbox. All conditions in Article 60(4) must be met cumulatively; it is not a menu."}],"exceptions":[{"id":"article-60-testing-plan-and-authorisation-exception","operator":"not","description":"Tacit approval after 30 days applies only where national law provides for it. Where national law does not, express authorisation remains required. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, critical infrastructure, a different route applies: Article 49(5) requires registration at national level."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 60 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent","legacy_id":"raip:action:article-61-inform-and-obtain-consent","type":"action","slug":"article-61-inform-and-obtain-consent","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f165fe13b1466a099d82c952bc1b6f82a49eb480fbbccf2fa6ba036922f812a3","label":"Inform the test subject and obtain consent to participate","summary":"Give every test subject concise, clear, relevant and understandable information beforehand on the five points of Article 61(1), then obtain freely-given informed consent, date and document that consent, and give a copy to the subject or the legal representative.","topics":["fundamental-rights","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-61-informed-consent"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-61-inform-and-obtain-consent-scope","operator":"all","description":"Arises prior to the participation of every natural person who is a subject of testing in real world conditions under Article 60, and again where the nature, objectives, conditions or expected duration of the test change."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-62-claim-sme-facilities","legacy_id":"raip:action:article-62-claim-sme-facilities","type":"action","slug":"article-62-claim-sme-facilities","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9673a606e0e422b439844d7f1546cbbca55448942f864cef4a79c45587c4df54","label":"Make use of the SME facilities in Article 62","summary":"Apply for priority access to the AI regulatory sandbox, use the national communication channel for questions about implementation, sign up for the standardisation process, and on a conformity assessment under Article 43 ask how the fee reduction has been applied.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-62-sme-support-measures"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-62-claim-sme-facilities-scope","operator":"all","description":"Arises where your organisation is an SME or a start-up with a registered office or a branch in the Union, and whenever you consider a sandbox, a conformity assessment or a standardisation track. This action is our construction: Article 62 addresses the Member States and the AI Office and imposes no literal duty on the organisation itself."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management","legacy_id":"raip:action:article-63-scope-simplified-quality-management","type":"action","slug":"article-63-scope-simplified-quality-management","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"64ba2f1ec918638f12ebd8e70d57d6162e4a07a205c05757c576a4b3418cd267","label":"Determine and bound the simplification of your quality management system","summary":"Test whether you are a microenterprise with no partner or linked enterprises, build the Article 17 system, mark which elements you would want to simplify once the Commission guidelines exist, and keep the nine articles of Article 63(2) expressly outside that simplification.","topics":["high-risk-requirements","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-63-sme-derogations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-63-scope-simplified-quality-management-scope","operator":"all","description":"Arises where you are the provider of a high-risk AI system and want to rely on Article 63, and again at every change in the shareholding structure. This action is our construction: Article 63 grants a possibility and places the only literal duty on the Commission."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-72-post-market-monitoring-act","legacy_id":"raip:action:article-72-post-market-monitoring-act","type":"action","slug":"article-72-post-market-monitoring-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b793dbcac4abe75f52fcb6314e88415f7a052a563c89542abc977881133dd82c","label":"Draw up a post-market monitoring plan","summary":"Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-73-incident-reporting-act","legacy_id":"raip:action:article-73-incident-reporting-act","type":"action","slug":"article-73-incident-reporting-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d21aa0f06e500097b8a63b4ce005a9181eb7330b407cef9d604f6cd6c58109a2","label":"Set up an incident process with reporting routes","summary":"Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline","legacy_id":"raip:action:article-8-state-of-the-art-baseline","type":"action","slug":"article-8-state-of-the-art-baseline","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ab16d4d4fad46ece0ef096efbab0877108130fefed5e739411793b55bc1d6983","label":"Record the state of the art and the intended purpose per system","summary":"Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.","topics":["conformity","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-8-state-of-the-art-baseline-scope","operator":"all","description":"Arises for every system that is high-risk under Article 6, and again on every change of intended purpose, on every release and on every revision of an applied standard or specification."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-9-risk-management-act","legacy_id":"raip:action:article-9-risk-management-act","type":"action","slug":"article-9-risk-management-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9fb9c4c7f569fdd776e6d5beebdde1935651c90f8c6bf6112103703100b69c0a","label":"Set up an iterative risk management process","summary":"Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code","legacy_id":"raip:action:article-95-scope-a-voluntary-code","type":"action","slug":"article-95-scope-a-voluntary-code","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0007e66736ec2968d6824189c8731dc744b45b3021f1aa92d35b85023fbc488d","label":"Scope a voluntary code of conduct and separate it from your duties","summary":"Choose the paragraph 1 or the paragraph 2 route, name which requirements you apply voluntarily and which you do not, give the code clear objectives and key performance indicators, and keep the voluntary commitments administratively separate from the obligations that continue to apply in full.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-95-scope-a-voluntary-code-scope","operator":"all","description":"Arises where you draw up or sign a code of conduct, an ethical framework or a voluntary commitment on AI, and where you reassess an existing promise. This action is our construction: Article 95 addresses the AI Office and the Member States and imposes no literal duty on the organisation."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers","legacy_id":"raip:action:article-99-101-map-penalty-tiers","type":"action","slug":"article-99-101-map-penalty-tiers","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"677f2bc0d2eedcb7da9a1b25be4939926b1fcb7cc4d93b6e0d718954a6506d58","label":"Assign to each obligation the penalty ceiling that belongs to it","summary":"Walk through your obligations register and mark per line which ceiling applies: Article 99(3) for Article 5, Article 99(4) for the role duties enumerated there, Article 25(2) and (4) and Article 50, Article 99(5) for answering information requests, and otherwise the national penalty regime under Article 99(1). Add the Article 101 regime wherever you provide a general-purpose AI model yourself, and the Article 75c regime wherever the AI Office is competent.","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-99-101-penalties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-99-101-map-penalty-tiers-scope","operator":"all","description":"To be done as soon as your obligations register exists, and to be revisited on every amendment of the Regulation and on every change to the national penalty regime of a Member State in which you operate. No deadline attaches to it: this is an editorial recommendation."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:assess-safety-component-role","legacy_id":"raip:action:assess-safety-component-role","type":"action","slug":"assess-safety-component-role","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b97e18ebfc6b192d56b5cded8f3b3727de730dad73e5d36b3ecc82cb4580c289","label":"Determine and record whether your AI component is a safety component","summary":"Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"assess-safety-component-role-scope","operator":"all","description":"To be carried out during the design of a product covered by the Union harmonisation legislation listed in Annex I, Section A, and again on every change to the intended purpose or to the function of the AI component."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:assess-significant-design-change","legacy_id":"raip:action:assess-significant-design-change","type":"action","slug":"assess-significant-design-change","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b0fe6ddf25d93b669d1a7aa23de9ab4ee265e0e1ef885cabfb34362eca5c9b3d","label":"Assess for every design change whether it is significant","summary":"Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"assess-significant-design-change-scope","operator":"all","description":"Applies to every high-risk system relying on the transitional rule, from the cut off date for its route: 2 December 2027 for Annex III, 2 August 2028 for Annex I. Continuous, per change, without a deadline of its own. The assessment belongs before the change, because once it is live the switching moment has already passed."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:assign-article-16-provider-duties","legacy_id":"raip:action:assign-article-16-provider-duties","type":"action","slug":"assign-article-16-provider-duties","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"afa914b0f02e49a720106d0b7aa4c968e20e8107858cb55aa5d3d993b7d10c40","label":"Assign an internal owner and a date to each point of Article 16","summary":"Translate the twelve points (a) to (l) into twelve named owners with a start date, so that no point falls between product management, quality and legal.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-16-provider-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"assign-article-16-provider-duties-scope","operator":"all","description":"To be carried out as soon as it is established that you are the provider of a system classified as high-risk under Article 6, well before the intended date of placing on the market."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 16 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:conformity-ce-registration-act","legacy_id":"raip:action:conformity-ce-registration-act","type":"action","slug":"conformity-ce-registration-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bfb9c4d6c2d511bcb65fe05b5604bbdcf9e4cecdeba886278f79ea41639c38bb","label":"Complete the conformity route before market placement","summary":"Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence","legacy_id":"raip:action:decide-and-record-gpai-code-adherence","type":"action","slug":"decide-and-record-gpai-code-adherence","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15c06567511f04bb7ed8af6b5ef082cca034e6b7c8e7c14048abe48bde7b2b36","label":"Take and record the decision whether you adhere to a code of practice","summary":"Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.","topics":["governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"decide-and-record-gpai-code-adherence-scope","operator":"all","description":"Arises when you place a general-purpose AI model on the Union market, and again whenever a code of practice is reviewed or adapted."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data","legacy_id":"raip:action:enter-and-maintain-eu-database-data","type":"action","slug":"enter-and-maintain-eu-database-data","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"435357e8801ee6d70b189145b8996f90aef44fa99a38559845927d9ab82c6af8","label":"Enter your data in the EU database and keep it up to date","summary":"Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date"],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"enter-and-maintain-eu-database-data-scope","operator":"all","description":"To be carried out before the system is placed on the market, put into service or used, and again on every change that touches one of the entered fields."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:establish-annex-i-product-route","legacy_id":"raip:action:establish-annex-i-product-route","type":"action","slug":"establish-annex-i-product-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1dbf0d3dff28ef691b411a542031d05ce0f9e65ce753b91c2474eaebc7e71fb6","label":"Establish the product route per product","summary":"Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"establish-annex-i-product-route-scope","operator":"all","description":"To be carried out before the product or the AI system is placed on the market or put into service, and again on every change to the product, to the AI function, to the assessment procedure chosen or to the list in Annex I."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:establish-competent-supervisor","legacy_id":"raip:action:establish-competent-supervisor","type":"action","slug":"establish-competent-supervisor","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dd5a7012eac1fbe8ee2b5b195b73a6695f8a3fde68921789c242d8c61d85812c","label":"Establish per system who your supervisor is","summary":"Assess per AI system whether it falls under the exclusive competence of the AI Office or under a national authority, record the outcome with its reasoning, and determine which carve-out in paragraph 1 applies if any and which counter follows from it.","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"establish-competent-supervisor-scope","operator":"all","description":"To be carried out before a system is placed on the market or put into service, and again whenever the underlying model, the provider or the corporate structure changes."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:fria-affected-groups-analysis","legacy_id":"raip:action:fria-affected-groups-analysis","type":"action","slug":"fria-affected-groups-analysis","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9a0dd9e77990f8f5744f182daf0e100f827c0dad9e2196b2fb91e0e0e9dfc97d","label":"Map the affected groups and their specific risks of harm","summary":"Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"fria-affected-groups-analysis-scope","operator":"all","description":"You are a body governed by public law, a private entity providing public services, or a deployer of a system under Annex III point 5(b) or 5(c), and you deploy a high-risk system under Article 6(2)."}],"exceptions":[{"id":"fria-affected-groups-analysis-exception","operator":"not","description":"High-risk AI systems intended for the area listed in Annex III point 2 fall outside the Article 27(1) FRIA duty."}],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:fria-assess","legacy_id":"raip:action:fria-assess","type":"action","slug":"fria-assess","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"060d2e1bc287118ccbb10293b2e58d6beb41edbc3a258713f507550ef6ba6a7e","label":"Perform a FRIA before deployment","summary":"Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:fria-complaint-mechanism-setup","legacy_id":"raip:action:fria-complaint-mechanism-setup","type":"action","slug":"fria-complaint-mechanism-setup","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"546f52fe4a8ea8f8ee489a7f35df22a0f08054168eccb92cdb62ed2221b22da8","label":"Set up the complaint mechanism and internal governance before the system runs","summary":"Describe the measures taken if a risk materialises, who decides internally, through which route an affected person can complain, within which deadline you respond, and who is authorised to stop the use.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"fria-complaint-mechanism-setup-scope","operator":"all","description":"The Article 27(1) FRIA duty applies to the system."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:gpai-document","legacy_id":"raip:action:gpai-document","type":"action","slug":"gpai-document","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f7df0039880787783fe41ffab2efdb643b7f698288791536bfb338b5b5bde3f1","label":"Maintain GPAI documentation and transparency information","summary":"Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:gpai-downstream-information-package","legacy_id":"raip:action:gpai-downstream-information-package","type":"action","slug":"gpai-downstream-information-package","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b65e381ec5f0d043cb17fce9d73c05d61b5c1ae63b21dbfca7b0eab718c1d4a5","label":"Assemble the downstream information package under Annex XII","summary":"Build one package for providers integrating your model, covering the intended tasks and integration options, acceptable use policies, release date and distribution methods, interaction with external hardware or software, software versions, architecture and parameter count, modality and format of inputs and outputs including maximum size, licence, required technical means, and information on the training, testing and validation data used.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"gpai-downstream-information-package-scope","operator":"all","description":"You are a provider of a general-purpose AI model placed on the Union market."}],"exceptions":[{"id":"gpai-downstream-information-package-exception","operator":"not","description":"Article 53(2) exempts providers of models released under a free and open-source licence whose parameters and related information are publicly available from points (a) and (b) of paragraph 1. That exception does not apply to GPAI models with systemic risk."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:gpai-rights-reservation-detection","legacy_id":"raip:action:gpai-rights-reservation-detection","type":"action","slug":"gpai-rights-reservation-detection","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e40f6c25d3c14c91f43647cc1fbe7d836d3790a0aa1c0994cba5db28c401f1f0","label":"Implement rights-reservation detection inside your copyright policy","summary":"Record which techniques you use to identify a reservation of rights within the meaning of Article 4(3) of Directive (EU) 2019/790 when collecting training data, how often you recheck, and how you then comply with that reservation.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"gpai-rights-reservation-detection-scope","operator":"all","description":"You are a provider of a general-purpose AI model placed on the Union market."}],"exceptions":[{"id":"gpai-rights-reservation-detection-exception","operator":"not","description":"The open-source exemption in Article 53(2) covers only points (a) and (b) of paragraph 1 and therefore leaves the point (c) copyright policy intact."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:handle-explanation-requests","legacy_id":"raip:action:handle-explanation-requests","type":"action","slug":"handle-explanation-requests","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6d83a4b800363d3d8f968ea680b136c2f0c56a22919d0585434ecb16344783be","label":"Set up how you handle a request for an explanation","summary":"Ensure your complaints or objections desk recognises a request for an explanation of an AI-supported decision, that it can be traced per decision which system in which version contributed to it, and that someone is designated to give the explanation.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-86-right-to-explanation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"handle-explanation-requests-scope","operator":"all","description":"To be set up before an Annex III system contributes to decisions about natural persons, and to be revisited on every change to that decision process."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:justify-standards-and-specification-choices","legacy_id":"raip:action:justify-standards-and-specification-choices","type":"action","slug":"justify-standards-and-specification-choices","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3b915d934d7f43ad0b980e02bd948bad5edd178e34d14385dbdaae143ce453f3","label":"Record per requirement which standard or specification you rely on, and justify every departure","summary":"Keep a coverage matrix of the requirements of Section 2 against the harmonised standards, common specifications and own documents applied, noting per row the publication status in the Official Journal, and write out the Article 41(5) justification for every common specification you do not apply.","topics":["conformity","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"justify-standards-and-specification-choices-scope","operator":"all","description":"Arises when drawing up the technical documentation, on every substantial modification of the system or model, and whenever a reference is published in the Official Journal of the European Union or a common specification is established or repealed."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:keep-high-risk-documentation-available","legacy_id":"raip:action:keep-high-risk-documentation-available","type":"action","slug":"keep-high-risk-documentation-available","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5aa5a6db591797b50c67f1d26168112be16bbf14a3474fec066b623bdba6d2ef","label":"Set up the ten year retention of the system documentation","summary":"Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"keep-high-risk-documentation-available-scope","operator":"all","description":"To be set up before the system is placed on the market or put into service, and to be revisited on every change that leads to new technical documentation or a new declaration of conformity."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:manage-notified-body-certificate","legacy_id":"raip:action:manage-notified-body-certificate","type":"action","slug":"manage-notified-body-certificate","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"075b09946e72bb958b7df4d8f4186cc77ebbd2f37bc753878f235c35e079186c","label":"Manage the life of the certificate","summary":"A practical working out for whoever holds a certificate: watch the expiry date, ask in time for the re-assessment that carries the extension, test every change against the substantial modification of Article 43(4), and make sure a deadline set by the body for corrective action reaches an identifiable person. Also track the body itself, because on cessation or withdrawal of its designation the deadlines of Article 36 apply.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-44-notified-body-certificates"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"manage-notified-body-certificate-scope","operator":"all","description":"To be set up as soon as a notified body has issued a certificate, along Annex VII or along the sectoral procedure of Article 43(3), and to be revisited on every change that is substantial within the meaning of Article 43(4). Article 44 imposes no duty on the provider himself; this is the practical working out we read into it, see the note on the provision."}],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:map-system-to-annex-iii-area","legacy_id":"raip:action:map-system-to-annex-iii-area","type":"action","slug":"map-system-to-annex-iii-area","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ec43a226df935b1465f0ea61fd40197b8d386269327ef2574d0a84bb81c6835","label":"Map every system to a point of Annex III","summary":"Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"map-system-to-annex-iii-area-scope","operator":"all","description":"To be carried out before a system is placed on the market or put into service, and again on every change to the intended purpose. Well before 2 December 2027, because the answer determines how much work follows."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:mark-confidential-material-on-submission","legacy_id":"raip:action:mark-confidential-material-on-submission","type":"action","slug":"mark-confidential-material-on-submission","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1a1c83bf26c7b8cc95f52cc0350a637355d9b59e0da7bf6f9156788e1ccd37f8","label":"Mark and register what you submit to an authority or body","summary":"State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"mark-confidential-material-on-submission-scope","operator":"all","description":"Arises on every submission to a market surveillance authority, a notified body, the Commission or the AI Office, and on every registration part of which lands in the secure non-public section of the EU database."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:notify-systemic-risk-threshold","legacy_id":"raip:action:notify-systemic-risk-threshold","type":"action","slug":"notify-systemic-risk-threshold","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"65a8b063463c2dc75b5dc4818d987c332a94fbaca9284ee52d4ac412ac01f266","label":"Notify the Commission within two weeks","summary":"Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"notify-systemic-risk-threshold-scope","operator":"all","description":"To be carried out within two weeks after the requirement in Article 51(1), point (a), is met or after it becomes known that it will be met, and to be revisited for every new model version that touches the threshold. For models placed on the market before 2 August 2025 the date in Article 111(3) applies."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:open-a-protected-reporting-route","legacy_id":"raip:action:open-a-protected-reporting-route","type":"action","slug":"open-a-protected-reporting-route","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5c2f21f3f2103b26d48c110857c7bc3ce689178cc441e6d18d32749b39635df","label":"Make sure a report about an AI system reaches your reporting channel","summary":"Only for organisations that must already have a reporting arrangement. Make visible in it that an infringement of the AI Regulation is a reportable infringement, designate who receives such a report, agree how the identity of the person reporting stays out of the rest of the process, and record whether you handle anonymous reports.","topics":["fundamental-rights","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"This action does not follow from Article 87 but from Directive (EU) 2019/1937 and its national transposition, and it applies only to those already covered by it. Article 87 adds subject matter to that arrangement, not a duty to set one up: it brings infringements of the AI Regulation within reach of a report. A defensible alternative reading is that there is nothing for you to do because your reporting arrangement already accepts any breach of Union law and the AI Regulation falls under it without change. Below the threshold of fifty workers there is nothing to set up at all. The date on which an existing channel requirement started is 17 December 2021, or 17 December 2023 for entities with fifty to two hundred and forty-nine workers, and not 2 August 2026; that last date is only when Article 87 brings the extension of subject matter. That is why no deadline_at is set here.","obligation_ids":["praxikon:eu:ai-act:obligation:article-87-reporting-infringements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"open-a-protected-reporting-route-scope","operator":"all","description":"Applies where an internal reporting requirement already rests on you under the national transposition of Directive (EU) 2019/1937, in principle at fifty or more workers, and you develop or use AI systems covered by the Regulation. To be revisited whenever your reporting arrangement or that national law changes."}],"exceptions":[{"id":"open-a-protected-reporting-route-below-threshold","operator":"any","description":"Does not apply to organisations falling outside the channel requirement under Article 8(3) or Article 8(9) of Directive (EU) 2019/1937. For them there is nothing to set up; the person reporting retains the external route of Article 10 of that Directive."}],"statements":[{"kind":"editorial_interpretation","text":"What is asked of you here is not stated in Article 87. It sits in Directive (EU) 2019/1937 and in national transposition law, and it applies only if you are already covered by it. Article 87 does one thing: it makes an infringement of the AI Regulation something that can be reported through that channel. The set-up question is therefore narrow. Does the person receiving the report recognise that the AI Regulation may be engaged, does the identity of the person reporting stay out of the substantive follow-up, and have you recorded whether you handle anonymous reports, which Article 6(2) of that Directive leaves to the Member State.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:plan-legacy-public-system-compliance","legacy_id":"raip:action:plan-legacy-public-system-compliance","type":"action","slug":"plan-legacy-public-system-compliance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1664bab006c5a034f299bad5cdd9f511aef0b1803a44e0b72fd9e299d964b701","label":"Plan compliance for legacy public sector systems by 2 August 2030","summary":"Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"plan-legacy-public-system-compliance-scope","operator":"all","description":"Applies once it is established that a high-risk system is intended to be used by public authorities. The 2 August 2030 deadline applies to that group regardless of when the system reached the market and regardless of whether the design changes. To be revisited when the system is replaced, phased out or supplied to a different customer group."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:prepare-article-46-derogation-request","legacy_id":"raip:action:prepare-article-46-derogation-request","type":"action","slug":"prepare-article-46-derogation-request","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4a0a2703e7c513ee90b17ea72c10dd64c87785258a9fdda798b971ec3eac66f6","label":"Prepare a derogation request and the exit plan that goes with it","summary":"Write in advance the reasoning paragraph 1 calls for, with the exceptional reason invoked, the evidence that the system complies with the requirements of Section 2, the status of the ongoing conformity assessment, and an exit plan in case the authorisation is refused or withdrawn.","topics":["conformity","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"prepare-article-46-derogation-request-scope","operator":"all","description":"Arises as soon as a high-risk system is needed for one of the four exceptional reasons sooner than the conformity assessment allows, and on every deployment by a law-enforcement or civil protection authority that may start without prior authorisation under paragraph 2. Does not arise for systems in products under Section A of Annex I: paragraph 7 excludes them."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:prepare-authority-information-request","legacy_id":"raip:action:prepare-authority-information-request","type":"action","slug":"prepare-authority-information-request","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a9b903cd57dbf97bcee07bc8804068afd035cf36db986902d3479a5ac7e508f7","label":"Make your conformity file deliverable on request","summary":"Map per high-risk system where each part of the file sits, which system version it belongs to, who assembles it, how long the logs are kept and in which language indicated by the Member State concerned you can supply it, so that a reasoned request becomes a delivery task rather than a search.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"prepare-authority-information-request-scope","operator":"all","description":"To be set up before the system is placed on the market or put into service, and to be revisited on every change that produces a new system version or that alters where the logs are held. For a provider established outside the Union, the authorised representative of Article 22 belongs in the same arrangement, because the request may land with him."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:prepare-for-a-complaint","legacy_id":"raip:action:prepare-for-a-complaint","type":"action","slug":"prepare-for-a-complaint","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2bb240a6b4679450ecfb8da63f94ca2640a3be05ce90eafee89a446a4700747","label":"Make sure you can answer a complaint with documents","summary":"Record per AI system which assessment was carried out, by whom, on what date and against which system version, and agree who receives a question from the authority and within what period.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-85-right-to-complain"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 85 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:record-bias-testing-legal-basis","legacy_id":"raip:action:record-bias-testing-legal-basis","type":"action","slug":"record-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b55a1476df5655c40a73f8fa334e80c3ed68ee44e4e178678829be3142ba58fc","label":"Justify and record your reliance on Article 4a","summary":"Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"record-bias-testing-legal-basis-scope","operator":"all","description":"Relevant only where you actually rely on Article 4a. In that case to be recorded before the processing starts, together with the data protection impact assessment, and to be revisited on every change to the purpose, the dataset or the set of people with access."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry","legacy_id":"raip:action:register-in-eu-database-before-market-entry","type":"action","slug":"register-in-eu-database-before-market-entry","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"21e847a8cb1d3ff7aaed32612bc5fbc191f77659dcd03cd3108289f7579b51cd","label":"Register yourself and the system before it reaches the market or is put into service","summary":"Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-49-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"register-in-eu-database-before-market-entry-scope","operator":"all","description":"Arises on every release of an Annex III system, on every application of Article 6(3) to such a system, and on every putting into service by a public authority or by a party acting on its behalf."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:request-systemic-risk-reassessment","legacy_id":"raip:action:request-systemic-risk-reassessment","type":"action","slug":"request-systemic-risk-reassessment","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d1f2f468a39d4cd72a817e9481564f17aa5263907196b6cdd5443130244b5145","label":"Request reassessment after a designation","summary":"If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"request-systemic-risk-reassessment-scope","operator":"all","description":"Only available to the provider of a model designated by the Commission under Article 52(4), and only once six months have passed since the designation decision or since a decision to maintain the designation."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:route-high-risk-duties-to-ai-office","legacy_id":"raip:action:route-high-risk-duties-to-ai-office","type":"action","slug":"route-high-risk-duties-to-ai-office","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ad630335bb28914d94333a6a39d024ef78fbd1df94d69f0da275751972ed8f0e","label":"Route reporting and conformity assessment to the AI Office","summary":"Adjust your incident procedure so that a serious incident concerning a high-risk system under the competence of the AI Office reaches the Office, with the Article 73 deadlines intact, and establish whether your third-party conformity assessment now runs through the Commission, including the fees you pay directly to the notified body.","topics":["enforcement","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The date is a derivation and not a deadline that Article 75 states itself. Both paragraphs address the provider of a high-risk AI system, and that status only arises once Chapter III, Sections 1 to 3, becomes applicable. Point (c) of the third paragraph of Article 113, as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744, gives two dates for that: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I. That second route does not drop out here, because the four carve-outs in Article 75(1) sit inside point (a), while point (b) independently brings a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine under the competence of the AI Office. This object carries the earlier of the two in deadline_at; for a system entering through point (b) and Annex I the date is 2 August 2028.","obligation_ids":["praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"editorial_interpretation","text":"The date on this object is derived and not stated by Article 75 itself. Point (c) of the third paragraph of Article 113 gives two dates for the moment Chapter III, Sections 1 to 3, becomes applicable: 2 December 2027 through Article 6(2) and Annex III, and 2 August 2028 through Article 6(1) and Annex I. This object carries the earlier of the two. Which date applies to your system depends on the route by which it is high-risk, and that choice is not made here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:run-corrective-action-procedure","legacy_id":"raip:action:run-corrective-action-procedure","type":"action","slug":"run-corrective-action-procedure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"651c8087e7f64bc06fbf114b77ca06603f6dedd3da892c36d4004d9da3b5968c","label":"Set up the procedure for corrective actions and notification","summary":"Work out the four measures in paragraph 1 as scenarios with an owner and a lead time, keep a record per system version of who runs it and how you reach that party, and set out the route along which the investigation of causes, the notification to the market surveillance authorities and the message to the notified body run once paragraph 2 comes into play.","topics":["high-risk-requirements","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-20-corrective-actions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"run-corrective-action-procedure-scope","operator":"all","description":"To be set up before a high-risk AI system is placed on the market or put into service, and to be revisited on every change in the customer chain or in the way the system can be switched off remotely."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:run-distributor-market-check","legacy_id":"raip:action:run-distributor-market-check","type":"action","slug":"run-distributor-market-check","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2eaa5a8939fd62cdb11d01f7fc92d55c2aaa80dd337e6f50b3a8fe4b2742ee97","label":"Perform the Article 24(1) check before making available","summary":"Verify the CE marking, the presence of the EU declaration of conformity and the instructions for use, and whether the provider and importer complied with Article 16, points (b) and (c), and Article 23(3).","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-24-distributor-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"run-distributor-market-check-scope","operator":"all","description":"To be carried out before every making available on the market, including where you supply the system free of charge or as part of a service bundle (Article 3(10))."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:run-importer-verification-checklist","legacy_id":"raip:action:run-importer-verification-checklist","type":"action","slug":"run-importer-verification-checklist","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a7cf5ade9bd6806752e716aba249de5c4641439b438a7d749e53567cbc16d2eb","label":"Run the four verifications of Article 23(1) before importing","summary":"Check and record: the conformity assessment has been carried out, the technical documentation exists, the CE marking plus declaration and instructions for use are present, and an authorised representative has been appointed.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-23-importer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"run-importer-verification-checklist-scope","operator":"all","description":"To be carried out before every first placing on the market of a high-risk AI system from a third-country provider."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:value-chain-representative-act","legacy_id":"raip:action:value-chain-representative-act","type":"action","slug":"value-chain-representative-act","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2ad75cc7b673736332e11a5f078c439bcc4d6de61a8566c335a9be3e7c4d08f2","label":"Assess the value-chain role per system and change","summary":"On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:action:verify-notified-body-standing","legacy_id":"raip:action:verify-notified-body-standing","type":"action","slug":"verify-notified-body-standing","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e52601467ef15090bb9a580857cc94205aa84cbc961989f3b5bfc5d601395a87","label":"Check the standing and independence of your notified body","summary":"At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.","topics":["conformity","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"verify-notified-body-standing-scope","operator":"all","description":"Arises as soon as you select or contract a notified body, on every renewal of the assignment, and on every notice of a change to its designation."}],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:ai-office","legacy_id":"raip:actor:ai-office","type":"actor","slug":"ai-office","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"22316f4ef249535428bf3fda894f06947441411820e6d05de779e863d0e37c3d","label":"AI Office","summary":"The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.","topics":["enforcement","governance","gpai"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:authorised-representative","legacy_id":"raip:actor:authorised-representative","type":"actor","slug":"authorised-representative","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c8f9493a2a252f9499a0a6adb239067fe4501d52259612dff91b94f3d206866c","label":"Authorised representative","summary":"The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.","topics":["value-chain"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"authorised-representative-scope","operator":"all","description":"Mandatory for providers of high-risk AI systems established in a third country, before they place those systems on the Union market (Article 22(1)). This duty starts on 2 December 2027 for the standalone Annex III route (Article 6(2)) and on 2 August 2028 for the embedded Annex I route (Article 6(1)). The definition and role determination in Article 3(5) already apply today."}],"exceptions":[{"id":"authorised-representative-exception","operator":"not","description":"Article 22 covers the high-risk AI system route. The definition in Article 3(5) also mentions general-purpose AI models; that route has its own regime, which is not elaborated here."}],"statements":[],"legal_status":"in_force","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 22 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:credit-or-insurance-deployer","legacy_id":"raip:actor:credit-or-insurance-deployer","type":"actor","slug":"credit-or-insurance-deployer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"708f7cf67870d5dee4af13b996f46aa5bf169cc0c6dbb59da14d300ee15052e0","label":"Credit or insurance deployer","summary":"A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:deployer","legacy_id":"raip:actor:deployer","type":"actor","slug":"deployer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2e95bd4a7cf24e69e0c77d9a006d5af3d3776312d2232a739e103e8f77cad2fc","label":"Deployer","summary":"An organisation using an AI system under its authority, excluding personal non-professional use.","topics":["governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:distributor","legacy_id":"raip:actor:distributor","type":"actor","slug":"distributor","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"97290626e5767363549f1ebc5715e16eb0b1ca3764034542c5e2e79b5a24975a","label":"Distributor","summary":"You are a distributor if you make an AI system available on the Union market without being the provider or the importer. This catches resellers, systems integrators and managed service providers that pass on someone else's AI.","topics":["value-chain"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"distributor-scope","operator":"all","description":"Applies where you sit in the supply chain, are neither provider nor importer, and supply the system in the course of a commercial activity. Supply free of charge expressly counts."}],"exceptions":[{"id":"distributor-exception","operator":"not","description":"If you put your own name or trade mark on a high-risk system already placed on the market, or make a substantial modification, or change its intended purpose, Article 25(1) treats you as a provider. Point (a) applies without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated. The role switch can be determined today; the duties of Article 16 start to apply on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route."}],"statements":[],"legal_status":"in_force","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:gpai-model-provider","legacy_id":"raip:actor:gpai-model-provider","type":"actor","slug":"gpai-model-provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b7d30d797a24d785ce56151a6038c71211a66a2894277e0a39faab35f93f488b","label":"Provider of a GPAI model","summary":"A party that places a general-purpose AI model on the Union market.","topics":["gpai"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:importer","legacy_id":"raip:actor:importer","type":"actor","slug":"importer","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"152e324e4109e7ad2b10c910c623deef18e05cca1f165166aa94f4f3b3a58f89","label":"Importer","summary":"You are an importer as soon as you, from within the EU, first place an AI system on the Union market that bears the name or trade mark of a party established outside the EU. What counts is not your purchasing role but whose brand is on the system and who first brings it to market.","topics":["value-chain"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"importer-scope","operator":"all","description":"Applies where you are located or established in the Union and are the first to place an AI system from a third-country provider on the Union market under that provider's name or trade mark."}],"exceptions":[{"id":"importer-exception","operator":"not","description":"You are not an importer but a provider as soon as you put your own name or trade mark on the system, make a substantial modification, or change the intended purpose so that the system becomes high-risk (Article 25(1)(a), (b) and (c)). Point (a) expressly applies without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated. The role switch can be determined today; the twelve duties of Article 16 start to apply on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route."}],"statements":[],"legal_status":"in_force","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:market-surveillance-authority","legacy_id":"raip:actor:market-surveillance-authority","type":"actor","slug":"market-surveillance-authority","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d01741f6ddf8930eff8d0ebfb001c233e657813742eca2a1fb8b7a2dd4428145","label":"Market surveillance authority","summary":"The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.","topics":["enforcement","governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:provider","legacy_id":"raip:actor:provider","type":"actor","slug":"provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d616e5233519c6adf01f00c1f5a3c8f16d7d861ad75579fefad24cd8ebbc2f81","label":"Provider of an AI system","summary":"A party that develops or has an AI system developed and places it on the market under its own name.","topics":["governance"],"actor_ids":[],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:public-law-body","legacy_id":"raip:actor:public-law-body","type":"actor","slug":"public-law-body","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c81c5d001bbe6e2594205af22045d18188224495448db00b5cb56b9d2162e78b","label":"Body governed by public law","summary":"A deployer that is a body governed by public law.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:actor:public-service-provider","legacy_id":"raip:actor:public-service-provider","type":"actor","slug":"public-service-provider","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd2eae26e231ad222695741b498b82c7e75f3bfb42c035741598964764b9378d","label":"Private provider of public services","summary":"A private deployer providing public services.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2024-08-01-entry-into-force","legacy_id":"raip:change:2024-08-01-entry-into-force","type":"change","slug":"2024-08-01-entry-into-force","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3005c4a62c53f5c6606f6537159ec01ea6aaf834bfdc68728e4d8d8dece75259","label":"The AI Act enters into force","summary":"The regulation entered into force on 1 August 2024, after which the obligations followed in phases.","topics":["timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy","praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2024/1689 appeared in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. Article 113 sets out that most provisions only become applicable later.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable","legacy_id":"raip:change:2025-02-02-prohibitions-and-literacy-applicable","type":"change","slug":"2025-02-02-prohibitions-and-literacy-applicable","version":"1.0.0","effective_at":"2025-02-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"209c8ebc73f368351e91ff2dad213b0429b7cfc89381fafea6e337ed35d7828f","label":"Prohibited practices and AI literacy apply","summary":"Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.","topics":["ai-literacy","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy","praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Chapter I and Chapter II became applicable on 2 February 2025. That makes the prohibited practices the first category with enforceable duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice","legacy_id":"raip:change:2025-07-10-gpai-code-of-practice","type":"change","slug":"2025-07-10-gpai-code-of-practice","version":"1.0.0","effective_at":"2025-07-10T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"524909094d7534dcd6df4dbe2cf53d3f6fc0c5d0be57e07463d0cd313d96040c","label":"General-Purpose AI Code of Practice published","summary":"The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission published the General-Purpose AI Code of Practice on 10 July 2025. Signing is voluntary; signatories can rely on it to demonstrate compliance with the GPAI obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-10T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines","legacy_id":"raip:change:2025-07-18-gpai-guidelines","type":"change","slug":"2025-07-18-gpai-guidelines","version":"1.0.0","effective_at":"2025-07-18T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"951b241022b8676b3140c22c06c12657cb1c5f8930553cd333732ff615d36a91","label":"Guidelines on the scope of the GPAI obligations","summary":"The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5045 final of 18 July 2025 describe the scope of the obligations for providers of GPAI models, including when a party modifying a model becomes a provider itself.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-18T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines","legacy_id":"raip:change:2025-07-29-ai-system-definition-guidelines","type":"change","slug":"2025-07-29-ai-system-definition-guidelines","version":"1.0.0","effective_at":"2025-07-29T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f50ff3430cd1811fa195bea40d12ca839169924ffcb0d8d6aa72772c7838fc62","label":"Guidelines on the definition of an AI system","summary":"The Commission draws the line between software that does and does not fall under the regulation.","topics":["scope"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5053 final of 29 July 2025 explain Article 3(1) through borderline cases, such as classical optimisation, statistical estimation and expert systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-29T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines","legacy_id":"raip:change:2025-07-29-prohibited-practices-guidelines","type":"change","slug":"2025-07-29-prohibited-practices-guidelines","version":"1.0.0","effective_at":"2025-07-29T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c853a0b561615bdd7c5af45302f539140684f35b1fa46f5b21f090e66a821c84","label":"Guidelines on prohibited AI practices","summary":"Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.","topics":["prohibited"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2025) 5052 final of 29 July 2025 work out each Article 5 prohibition with examples. The guidelines are non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2025-07-29T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable","legacy_id":"raip:change:2025-08-02-gpai-obligations-applicable","type":"change","slug":"2025-08-02-gpai-obligations-applicable","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"029478e4015cda1adb2addf8614ca5fb51f7c72781d5b13d247911ffb5fa99ad","label":"GPAI model obligations apply","summary":"Since 2 August 2025 the obligations for providers of general-purpose AI models apply.","topics":["gpai","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Chapter V became applicable on 2 August 2025. Models placed on the market before that date must comply by 2 August 2027 at the latest.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 53 to 55 and Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines","legacy_id":"raip:change:2026-05-19-draft-high-risk-guidelines","type":"change","slug":"2026-05-19-draft-high-risk-guidelines","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f8996eb1bc4fd2bb4496f27f0be4b686f56122564b91e488e733ad0a50128c31","label":"Draft guidelines on high-risk classification","summary":"The Commission explains in consultation when a system falls under Annex I or Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"On 19 May 2026 the Commission published draft guidelines on the classification of high-risk AI systems for stakeholder consultation, with separate annexes on Annex I and Annex III. The text is non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines of 19 May 2026, annexes on Annex I and Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-05-19T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice","legacy_id":"raip:change:2026-06-10-transparency-code-of-practice","type":"change","slug":"2026-06-10-transparency-code-of-practice","version":"1.0.0","effective_at":"2026-06-10T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ac921e9a99752dc8855683b007914f8b886141207a92b0f2e496a5a28b05c06b","label":"Transparency Code of Practice published","summary":"A voluntary route to comply with parts of Article 50, in two separately signable sections.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Code of Practice on transparency of AI-generated content appeared on 10 June 2026. After a positive adequacy assessment, signatories can rely on it for Article 50(2), (3) and (5). Section 1 addresses providers, section 2 deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:transparency-code-of-practice","source_locator":"Code of Practice on Transparency of AI-generated Content, 10 June 2026","source_url":"https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-06-10T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-12-en-18286-approved","legacy_id":"raip:change:2026-07-12-en-18286-approved","type":"change","slug":"2026-07-12-en-18286-approved","version":"1.0.0","effective_at":"2026-07-12T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f0e540984fe6c775513d06b2c738b5d64f1539828da45102159106383747671","label":"First European AI Act standard approved","summary":"EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"CEN-CENELEC approved EN 18286:2026 on 12 July 2026. It is the first JTC 21 deliverable under standardisation request M/613 to reach the publication stage.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-07-12T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines","legacy_id":"raip:change:2026-07-20-article-50-guidelines","type":"change","slug":"2026-07-20-article-50-guidelines","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"acb754d01dded0d0bbcfe4cc0a6f8a09b3284fd4f485c6bbb8c6c9464ecad1bc","label":"Final guidelines on Article 50","summary":"The Commission works out the transparency duties and confirms they apply from 2 August 2026.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2026) 5054 final of 20 July 2026 work out the notification and marking duties of Article 50, with worked examples for chatbots, deep fakes and AI texts of public interest.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-07-20T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","legacy_id":"raip:change:2026-07-27-annex-iii-date","type":"change","slug":"2026-07-27-annex-iii-date","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a252b9b5dba99234038ed5eb5d01255eee1c9c4c65fb2c6492eabc36135e3c7e","label":"Annex III core rules moved to 2 December 2027","summary":"The amended application date has been binding law since 27 July 2026.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 sets application for Article 6(2) and Annex III on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation","legacy_id":"raip:change:2026-07-27-article-2-13-limitation","type":"change","slug":"2026-07-27-article-2-13-limitation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c71ee2e8cff0bad78dce3f027b001a9787257d56b09f2599217e809efc5ad7d3","label":"New Article 2(13): requirements for Annex I systems may be limited","summary":"Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (3), of Regulation (EU) 2026/1744 adds a paragraph 13 to Article 2. Its final subparagraph provides: by 2 August 2027, the Commission shall adopt delegated acts in accordance with Article 97 in order to supplement this Regulation by specifying the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (3), inserting Article 2(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-4-amended","legacy_id":"raip:change:2026-07-27-article-4-amended","type":"change","slug":"2026-07-27-article-4-amended","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e99fb271a9edefa0ca93ceff84fd425c82bcc7a037c931c0c2b97e3de4b79bb","label":"Article 4 amended to a duty to take measures","summary":"Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-4-measures"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-4-measures-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 amended Article 4 with effect from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 4 amendment and entry into force","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted","legacy_id":"raip:change:2026-07-27-article-4a-inserted","type":"change","slug":"2026-07-27-article-4a-inserted","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8b9ea80c30b7b1348135ff14cda588fe1e19db2dabe15d5bb6e6fd38a836bd7b","label":"Article 4a inserted, Article 10(5) deleted","summary":"Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserted Article 4a and deleted Article 10(5) with effect from 27 July 2026. Anyone justifying a processing operation by reference to Article 10(5) has since been referring to a deleted provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link","legacy_id":"raip:change:2026-07-27-fria-date-and-dpia-link","type":"change","slug":"2026-07-27-fria-date-and-dpia-link","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d67a5efb08ce495fa109c2de2ea7698deb5cb7bfb5a2c791dfa090e582b011e","label":"FRIA follows new date and may cross-reference a DPIA","summary":"The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:fria-assess"],"evidence_ids":["praxikon:eu:ai-act:evidence:fria-report"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The amending regulation links the relevant FRIA route to the new application calendar and expressly enables reuse through a DPIA.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment and amended Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b","legacy_id":"raip:change:2026-07-27-machinery-moved-to-annex-i-b","type":"change","slug":"2026-07-27-machinery-moved-to-annex-i-b","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bc334b0f3c19fbd7ead1a4fcaf1eeb0f0276303ab2afdeeba541bf3e38d55e2","label":"Machinery moves from Annex I, Section A, to Section B","summary":"Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.","topics":["conformity","high-risk","scope"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (41), of Regulation (EU) 2026/1744 provides: Annex I is amended as follows: (a) in Section A, point 1 is deleted; (b) in Section B, the following point is added: 21. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed","legacy_id":"raip:change:2026-07-27-safety-component-narrowed","type":"change","slug":"2026-07-27-safety-component-narrowed","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ed963204383921369662bfcb49af43ff2f3753b60af5fc3b43d495874f12af12","label":"Article 6 gains paragraphs 1a to 1c on safety components","summary":"Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).","topics":["high-risk","scope"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (8), of Regulation (EU) 2026/1744 inserts the following paragraphs into Article 6: 1a. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components. 1b. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"in_force","deadline_at":"2026-07-27T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-08-02-article-50-applicable","legacy_id":"raip:change:2026-08-02-article-50-applicable","type":"change","slug":"2026-08-02-article-50-applicable","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd4cbaa1807f88e6c089eaac6e8f8cb22f0633c0711f8cc99597801a6e4a5d84","label":"Article 50 is applicable","summary":"The transparency duties apply since 2 August 2026.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-50-disclosure"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-50-implementation-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50 became applicable on 2 August 2026 and was not postponed by the Digital Omnibus.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50 and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","legacy_id":"raip:change:2026-08-02-gpai-enforcement","type":"change","slug":"2026-08-02-gpai-enforcement","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"769966b9e97bd68ec12b1c323d9aeb41f84eb4f7b6583b9768bd8bcec8806706","label":"GPAI enforcement powers active","summary":"Since 2 August 2026 the Commission can request GPAI information, conduct evaluations and require measures.","topics":["enforcement","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:gpai-document"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-compliance-file"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Commission enforcement powers for GPAI and the Article 101 fine regime have been active since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends","legacy_id":"raip:change:2026-12-02-article-50-marking-grace-ends","type":"change","slug":"2026-12-02-article-50-marking-grace-ends","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"58b7a8c79ca67e84d974e615732162e2d9ca692976e1ec9423ccae3fa650e115","label":"Grace period for machine-readable marking ends","summary":"Systems placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.","topics":["timeline","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50 has applied to all systems in scope since 2 August 2026. For the machine-readable marking and detectability of paragraph 2 a transition period runs to 2 December 2026, and only for systems placed on the market before 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, transitional regime under Article 50(2)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2026-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards","legacy_id":"raip:change:2026-12-02-new-prohibitions-technical-safeguards","type":"change","slug":"2026-12-02-new-prohibitions-technical-safeguards","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2202ac53e7a1afdb40dd7686939d2e1610f0c1620dab4c72d8c80f8a1e6f6e0b","label":"New prohibitions require technical safeguards","summary":"The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.","topics":["prohibited","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Regulation (EU) 2026/1744 adds a prohibition on AI intended to generate child sexual abuse material or non-consensual intimate imagery. The required technical safeguards must be in place by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, amendment of Article 5","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2026-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply","legacy_id":"raip:change:2027-08-02-legacy-gpai-models-comply","type":"change","slug":"2027-08-02-legacy-gpai-models-comply","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"17e4e2305767d130376a05e7217cad919dea24364451dfefb06df5708baea73a","label":"Legacy GPAI models must comply","summary":"Models placed on the market before 2 August 2025 have until 2 August 2027.","topics":["gpai","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 111(3) gives providers of GPAI models placed on the market before 2 August 2025 until 2 August 2027 to comply with Chapter V.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational","legacy_id":"raip:change:2027-08-02-sandboxes-operational","type":"change","slug":"2027-08-02-sandboxes-operational","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"56ce8fd9cbe0fcc04361c424890f6bc019291a646e0d5a67e93f4f50fdb07c97","label":"National AI regulatory sandboxes operational on 2 August 2027","summary":"The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (22)(a), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 57(1) with: Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (22)(a), replacing Article 57(1), first subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template","legacy_id":"raip:change:2027-09-02-post-market-monitoring-template","type":"change","slug":"2027-09-02-post-market-monitoring-template","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"df08ab4eea5c80fa9005e4ccfadbf7f19c3b695000c96ca764c1c5312810a1e5","label":"Template for the post-market monitoring plan becomes guidance, by 2 September 2027","summary":"Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.","topics":["high-risk","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 1, point (30), of Regulation (EU) 2026/1744 replaces Article 72(3) with: the post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (30), replacing Article 72(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-09-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable","legacy_id":"raip:change:2028-08-02-annex-i-high-risk-applicable","type":"change","slug":"2028-08-02-annex-i-high-risk-applicable","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"139fd5e6f94a689f8d05a09f4653fbe7cab49b5d6ca99447ab28a3373a68e89a","label":"High-risk AI embedded in regulated products","summary":"AI as a safety component of products under Annex I follows on 2 August 2028.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk","praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"For AI systems under Article 6(1) and Annex I, that is AI as a safety component of products already covered by EU product legislation, the high-risk requirements apply from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, amended application dates under Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:ai-office-proceeding-response","legacy_id":"raip:control:ai-office-proceeding-response","type":"control","slug":"ai-office-proceeding-response","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2a14d942690776abc57ebe1894061fb661d761a1be59c4d37f67ce71a63a0fcf","label":"Intake and deadline tracking for a demand or an inspection","summary":"The control that ensures an information request, a notice of investigation or an announced inspection from the AI Office reaches an identifiable person, that it is first established whether it is a simple request or a decision, that the period set is tracked, and that what was supplied is recorded. The substance is sanctioned too: a periodic penalty payment can be imposed where you fail to give correct or complete answers during an ordered inspection, and incorrect, incomplete or misleading information supplied to the Office falls under the fines of Article 99(5). A retention order under Article 75a(6) belongs in this control, because it overrides your deletion routines.","topics":["control","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties","praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-i-product-route-change-gate","legacy_id":"raip:control:annex-i-product-route-change-gate","type":"control","slug":"annex-i-product-route-change-gate","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"41147ad53e75659681724c69c680f6ff2bfb2f77c57493b2b88f304dd539c613","label":"Reassessment on a change of product or assessment route","summary":"The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.","topics":["control","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger","legacy_id":"raip:control:annex-iii-area-rescan-trigger","type":"control","slug":"annex-iii-area-rescan-trigger","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"65d9b6c9abea4895f3b114bde6ccbbf75e8a218f6ddff7347857f09f72f539ce","label":"Reassessment on a change of intended purpose","summary":"The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-iii-change-trigger","legacy_id":"raip:control:annex-iii-change-trigger","type":"control","slug":"annex-iii-change-trigger","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5e147cd22d5207a8d1912771c7f88764d646fedc6ec79ed6fa684842469257e","label":"Reclassification on purpose or context change","summary":"Reopen classification when intended purpose, use context or system functionality changes materially.","topics":["control","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:annex-iii-procurement-gate","legacy_id":"raip:control:annex-iii-procurement-gate","type":"control","slug":"annex-iii-procurement-gate","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9597e1a01dcda6e280b756880b38c7ae4b81369832866e493537d92888058c7e","label":"Procurement gate: no signature without a completed classification answer","summary":"Block signature of an AI contract until the supplier has answered in writing which Annex III point the intended purpose falls under, whether it relies on Article 6(3), and whether the system profiles natural persons.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"annex-iii-procurement-gate-scope","operator":"all","description":"You purchase, renew or extend a contract for an AI system or an AI component."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-10-data-governance-control","legacy_id":"raip:control:article-10-data-governance-control","type":"control","slug":"article-10-data-governance-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a1197480eeb259121cc853f384382755339627047a5fedee4e958dc1be5b3d36","label":"Data check before retraining","summary":"Repeat the data quality assessment before every retraining or dataset change.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-11-technical-documentation-control","legacy_id":"raip:control:article-11-technical-documentation-control","type":"control","slug":"article-11-technical-documentation-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f41fa75300653fe8cf65da2dc464a21a6fe9f1bdce68ba2f0e7bdb2b9d44108","label":"Documentation update on every release","summary":"Update the file before every release and retain earlier versions traceably.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-12-logging-control","legacy_id":"raip:control:article-12-logging-control","type":"control","slug":"article-12-logging-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef6bb673f232b91ca9a7ccc999eaced167d75fe7d5b6c8697976b68841abd1ca","label":"Periodic log review","summary":"Periodically verify that logging works, is complete and is retained according to the regime.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-13-instructions-control","legacy_id":"raip:control:article-13-instructions-control","type":"control","slug":"article-13-instructions-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d5e946dff0be31c1f71ccb47aefb643d221bb4f4509cc213c2072ea7737681a1","label":"Instructions check at deployment","summary":"At every deployment and update, verify instructions are present, current and internally translated.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-14-human-oversight-control","legacy_id":"raip:control:article-14-human-oversight-control","type":"control","slug":"article-14-human-oversight-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55eb68e6c4e828adf673c2be5ab291024de40807686a85097372ca99d2e1e00e","label":"Oversight test before go-live","summary":"Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-15-accuracy-robustness-control","legacy_id":"raip:control:article-15-accuracy-robustness-control","type":"control","slug":"article-15-accuracy-robustness-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"41b67105a6c49d112c6e9d4a83e3863d34c6c2402fa104568390e7e2636e1dfa","label":"Performance monitoring in use","summary":"Monitor whether the system stays within declared levels in production and escalate on deviation.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-16-pre-market-release-gate","legacy_id":"raip:control:article-16-pre-market-release-gate","type":"control","slug":"article-16-pre-market-release-gate","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"00da9a8e2003346475d96e042a7b628e03b1be93c39995ec7ccb606303ea787a","label":"Release gate before placing on the market","summary":"A hard block in your release or delivery process: no delivery without a completed conformity assessment, a signed EU declaration of conformity, an affixed CE marking and a completed registration.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-16-provider-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-16-pre-market-release-gate-scope","operator":"all","description":"Applies at every first supply to the market and again after a substantial modification within the meaning of Article 3(23), that is, a change after placing on the market or putting into service which was not foreseen in the initial conformity assessment and which affects compliance with Chapter III, Section 2, or results in a modification of the assessed intended purpose. Article 43(4) requires a new conformity assessment procedure in that case."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 16 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-17-quality-management-control","legacy_id":"raip:control:article-17-quality-management-control","type":"control","slug":"article-17-quality-management-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e20819d7fa6ff1eec67706612fa84dd4cce163c8ee5ac03b35072f1874fd2328","label":"Internal audit cycle","summary":"Periodically audit whether practice follows the described system and record deviations and improvements.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-18-retention-review","legacy_id":"raip:control:article-18-retention-review","type":"control","slug":"article-18-retention-review","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2f76214c0b47f1f672820a54caf7fca4d6ccdabfc2538b98f066b1829aab06ca","label":"Periodic check on completeness and retrievability of the retention file","summary":"The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-4-coverage-reconciliation","legacy_id":"raip:control:article-4-coverage-reconciliation","type":"control","slug":"article-4-coverage-reconciliation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f7592ade984067485bce8db9c3464ccc81ff55f07c1e8a50e0d801f34f3123e0","label":"Coverage reconciliation: every person with AI access appears in the register","summary":"Periodically reconcile the list of accounts and licences with access to AI systems against the participation and instruction register, and clear the gap list with an owner and a deadline.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-4-coverage-reconciliation-scope","operator":"all","description":"There are persons outside the standing payroll dealing with AI systems on your behalf."}],"exceptions":[{"id":"article-4-coverage-reconciliation-exception","operator":"not","description":"Article 4 prescribes no coverage percentage, record format or frequency. The reconciliation is a means of showing that the measures reach the persons referred to in Article 4(1); it is not itself a legal obligation."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-4-periodic-review","legacy_id":"raip:control:article-4-periodic-review","type":"control","slug":"article-4-periodic-review","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0e4f286e8ab077ec312e5c3b2a491e5dd74beae4cce63bcbd8e69d290b511fdd","label":"Periodic role and context review","summary":"Check when systems, roles or risks change whether the selected measures remain appropriate.","topics":["ai-literacy","control"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-46-derogation-exit-review","legacy_id":"raip:control:article-46-derogation-exit-review","type":"control","slug":"article-46-derogation-exit-review","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bc6a9018ac2b0b4202242567b07f12e4cd9c9aadbbd2ca8b104626a2831acacc","label":"Review of an authorisation expiring, being refused or withdrawn","summary":"The control that keeps a system running under Article 46 under watch: the ongoing conformity assessment has an owner and an end date, the fifteen calendar days of paragraph 4 are in the calendar, and a rehearsed plan is in place to stop use with immediate effect and discard all results and outputs if the authorisation is refused or withdrawn.","topics":["conformity","control","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-49-pre-market-registration-gate","legacy_id":"raip:control:article-49-pre-market-registration-gate","type":"control","slug":"article-49-pre-market-registration-gate","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c00322d9a521e62f60033115b1fdc2c26ea9847bd8687d7d0e3e1b7d3decf2c7","label":"Release gate: no market entry without registration","summary":"The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.","topics":["conformity","control","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-49-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-5-intake-gate","legacy_id":"raip:control:article-5-intake-gate","type":"control","slug":"article-5-intake-gate","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"37d45153584850ac2fb2b45e6d3da2c33f991d45251f12314162e56611cf0403","label":"Article 5 gate at intake and change","summary":"Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.","topics":["control","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-50-production-sampling","legacy_id":"raip:control:article-50-production-sampling","type":"control","slug":"article-50-production-sampling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"adb26ffb069fc9b9658401ebcdfd0f3213236d440010cd902c02a2a81cf9d518","label":"Quarterly sampling of live disclosures and markings in production","summary":"Each quarter, sample the systems carrying an Article 50 scenario and verify in the production environment that the disclosure still appears and the marking is still present in the actual output, recording finding, owner and remediation deadline.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-production-sampling-scope","operator":"all","description":"Your AI register contains at least one system to which an Article 50 scenario applies."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-50-release-check","legacy_id":"raip:control:article-50-release-check","type":"control","slug":"article-50-release-check","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef03e3c5735fc9e8bcd12090e90c9f547541fcc4af4e171bad16fa1b156b6c59","label":"Pre-release transparency check","summary":"Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.","topics":["control","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control","legacy_id":"raip:control:article-55-gpai-systemic-risk-control","type":"control","slug":"article-55-gpai-systemic-risk-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4120e7c4ab88a0b1a21183363aad47c10324fb4199bb46e9966088927a83235c","label":"Compute threshold monitoring","summary":"Monitor cumulative training compute and notify the Commission when the threshold is reached.","topics":["control","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-56-code-commitment-review","legacy_id":"raip:control:article-56-code-commitment-review","type":"control","slug":"article-56-code-commitment-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bef812ac71a549672a98de87ed6db504ebe93e9b284d502b8a9681ed0b3f0ad","label":"Review moment on your reliance on a code of practice","summary":"The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.","topics":["control","governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield","legacy_id":"raip:control:article-57-sandbox-supervision-and-fine-shield","type":"control","slug":"article-57-sandbox-supervision-and-fine-shield","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7df37a81273b8f3d3b41c34604e74866fe6ad2090d791363b4a8145d52ad1c47","label":"Supervision inside the sandbox and the conditional fine shield","summary":"The authority retains its supervisory and corrective powers and can suspend your testing or participation. If you stay within the plan and follow the guidance in good faith, authorities impose no administrative fines for infringements of this Regulation.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-57-sandbox-supervision-and-fine-shield-scope","operator":"all","description":"Applies throughout your participation in an AI regulatory sandbox, from entry to exit or termination."}],"exceptions":[{"id":"article-57-sandbox-supervision-and-fine-shield-exception","operator":"not","description":"The fine shield is conditional and lapses as soon as you depart from the specific plan or from the terms and conditions of participation, or fail to follow the guidance in good faith. For other Union or national law it applies only where the authorities responsible for that law were actively involved in supervision inside the sandbox and provided guidance. Article 57(12) refers only to participating providers and prospective providers. If you take part as a deployer in partnership under Article 58(2), point (b), do not assume the protection automatically covers your own obligations."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 57 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-60-oversight-and-incident-response","legacy_id":"raip:control:article-60-oversight-and-incident-response","type":"control","slug":"article-60-oversight-and-incident-response","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2d0f4824005cd8bf8954ca788130a98e43e23a7466fef11bc5926012b07d9d63","label":"Oversight during the test, incident reporting and recall procedure","summary":"The market surveillance authority may inspect unannounced. On a serious incident you report, take immediate mitigation or suspend, and you must have a procedure in place in advance for prompt recall of the system.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-60-real-world-testing"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-60-oversight-and-incident-response-scope","operator":"all","description":"Applies throughout the entire duration of the testing in real world conditions, and on its completion, suspension or termination."}],"exceptions":[{"id":"article-60-oversight-and-incident-response-exception","operator":"not","description":"The Regulation provides no exception to the duty to report a serious incident or to the inspection powers. The reporting route itself runs through Article 73, which governs the deadlines and the manner of reporting."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 60 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review","legacy_id":"raip:control:article-61-consent-and-withdrawal-review","type":"control","slug":"article-61-consent-and-withdrawal-review","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6f3955535f72a4be6f5f77876b14ac1e46e3f08e5ab1132c427f2a3d76ee61d2","label":"Consent and withdrawal review before a test in real world conditions starts","summary":"The control that no subject participates before the information pack is complete, the consent record is dated and a copy has been given, and that the withdrawal route with its recipient, period and deletion step works and has been rehearsed once.","topics":["control","fundamental-rights","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-61-informed-consent"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-62-fee-and-access-review","legacy_id":"raip:control:article-62-fee-and-access-review","type":"control","slug":"article-62-fee-and-access-review","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3b06a4753527d858f9a2d174af10076ff9039ce2d5732ffe02537ec8250db515","label":"Fee and access review on a conformity assessment","summary":"The control that on every application for a conformity assessment under Article 43 and on every sandbox application it is checked whether the SME facilities have been invoked and whether the proportionate fee reduction has been made visible, and that the answer reaches the procurement file.","topics":["control","governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-62-sme-support-measures"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-63-simplification-boundary-review","legacy_id":"raip:control:article-63-simplification-boundary-review","type":"control","slug":"article-63-simplification-boundary-review","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6db7cb37c1383a6ab87de859086e4b86beb7188a9cb05c9fd9d79c38482919f2","label":"Review of the boundary of the simplification","summary":"The control that every simplification you make under Article 63 is tested against paragraph 2, so that no item from Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73 falls away, and that the shareholding structure test is redone at every change.","topics":["control","high-risk-requirements","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-63-sme-derogations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-72-post-market-monitoring-control","legacy_id":"raip:control:article-72-post-market-monitoring-control","type":"control","slug":"article-72-post-market-monitoring-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c706acb5c18b681ab35cb71fe040a9cfd6ae019bffcaf84a122cb58536095ec0","label":"Signal-to-action loop","summary":"Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.","topics":["control","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-73-incident-reporting-control","legacy_id":"raip:control:article-73-incident-reporting-control","type":"control","slug":"article-73-incident-reporting-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fea3dc4bdbe0c4e36abad77a33369cd226656d4f52f9dde1d0f736f2afb04fb8","label":"Incident drill and deadline watch","summary":"Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.","topics":["control","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-78-disclosure-review","legacy_id":"raip:control:article-78-disclosure-review","type":"control","slug":"article-78-disclosure-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8ecf8b9fd5f0aece19a1cbd0a0187a2921d194f04caa372275204598627b2f92","label":"Review before handing over source code or trade secrets","summary":"The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.","topics":["control","enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-8-integrated-documentation-review","legacy_id":"raip:control:article-8-integrated-documentation-review","type":"control","slug":"article-8-integrated-documentation-review","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f68b5943d7a3ff8db427de0bebec8ef281d9786a4198f8cec879e03f120d7b3d","label":"Review of the overlap with sectoral product documentation","summary":"The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.","topics":["conformity","control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-9-risk-management-control","legacy_id":"raip:control:article-9-risk-management-control","type":"control","slug":"article-9-risk-management-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c3f5ab2befc762f6e21c1f2c74f24043d104c9e229c5edf7b4525254f7f630f","label":"Reassessment on every material change","summary":"Reopen the risk management process on changes in purpose, data, model or use context and before every release.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review","legacy_id":"raip:control:article-95-voluntary-versus-mandatory-review","type":"control","slug":"article-95-voluntary-versus-mandatory-review","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6e2bc0243e41f5b890eb12f58efdb8e37e01fa7834e0b91f8f08c9db66bd9526","label":"Review that keeps voluntary and mandatory apart","summary":"The control that no external statement, quotation, tender response or annual report presents a code of conduct as cover for an obligation under the Regulation, and that every voluntary commitment has an owner, an indicator and a moment of measurement before it goes out.","topics":["control","governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record","legacy_id":"raip:control:article-99-101-mitigating-factor-record","type":"control","slug":"article-99-101-mitigating-factor-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ecc7f911bd2521b65e45e24c8c4e5cc569b08ec97ee3cfd82a231e4acecaf993","label":"Recording of the factors in Article 99(7)","summary":"The control that ensures the factors which determine the amount of a fine are recorded at the time and not reconstructed afterwards: which technical and organisational measures were in place, when you notified an infringement yourself, how you responded to requests from the authority, and what you did to mitigate the harm suffered by affected persons. Those factors cut both ways, so the same record can also count against you; that is a reason to keep it properly rather than not at all.","topics":["control","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-99-101-penalties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:authority-request-intake-and-deadline","legacy_id":"raip:control:authority-request-intake-and-deadline","type":"control","slug":"authority-request-intake-and-deadline","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"54923ab0282bc2921673140d98f227b014225d5be4c7737040fa16f3cf19870c","label":"Intake and deadline tracking of a request from an authority","summary":"The control that ensures an incoming request from a competent authority reaches an identifiable owner the same day, that the documents requested are matched to the right system version, and that delivery is complete within the period set by the authority.","topics":["control","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"authority-request-intake-and-deadline-scope","operator":"all","description":"Article 21 itself sets no period, but the clock is not yours. Article 74(1) makes Regulation (EU) 2019/1020 applicable to AI systems covered by this Regulation, and the market surveillance authority sets a period in its own request. Design the internal turnaround around the period the authority imposes, not the other way round; an internally chosen period is a planning aid only."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:bias-testing-data-deletion","legacy_id":"raip:control:bias-testing-data-deletion","type":"control","slug":"bias-testing-data-deletion","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9c6c357526a089a9dcbe2b8d6ba4367e77f55bb6f20e41101cf91993024d9e01","label":"Access and deletion control for bias testing","summary":"The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:certificate-expiry-monitoring","legacy_id":"raip:control:certificate-expiry-monitoring","type":"control","slug":"certificate-expiry-monitoring","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b9da8d0c98b52bcc6529ee38406c59bfda726ee044c559b1691d0101150d3447","label":"Monitoring of certificate, modification and body","summary":"The control that ensures three signals reach an identifiable person in time instead of surfacing only once the certificate has already lapsed or been suspended: an approaching expiry date, a change that may be substantial within the meaning of Article 43(4), and a notice from or about the notified body itself, including the notification within ten days on suspension, restriction or withdrawal of its designation and the confirmation that Article 36(8), point (b), requires from the provider within three months.","topics":["conformity","control"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-44-notified-body-certificates"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:conformity-ce-registration-control","legacy_id":"raip:control:conformity-ce-registration-control","type":"control","slug":"conformity-ce-registration-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f3f1746fc31ee9566dd0b6d950a65fe3fbad3185781fbbb10adc10669075ec6b","label":"Reassessment on substantial modification","summary":"Rerun the conformity route whenever the system is substantially modified.","topics":["conformity","control"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:deployer-suspension-and-incident-control","legacy_id":"raip:control:deployer-suspension-and-incident-control","type":"control","slug":"deployer-suspension-and-incident-control","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f5a7cc3c88ecad6503c2407d70fab85c028743e16d170d6648114d6df005b82a","label":"Suspension and incident notification control","summary":"A fixed rule that suspends use and notifies in the correct order as soon as you have reason to consider the system presents a risk or as soon as you identify a serious incident.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-26-deployer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"deployer-suspension-and-incident-control-scope","operator":"all","description":"Triggered at the threshold of having reason to consider that use may result in a risk, and separately upon identifying a serious incident. For financial institutions the monitoring obligation is deemed fulfilled through the internal governance rules under Union financial services law."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:design-change-review-gate","legacy_id":"raip:control:design-change-review-gate","type":"control","slug":"design-change-review-gate","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"717dd89458fe469f5033af10a567225e56493704d9c91fc274fe7be26c3f4f97","label":"Review gate on a design change","summary":"The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:distributor-corrective-action-control","legacy_id":"raip:control:distributor-corrective-action-control","type":"control","slug":"distributor-corrective-action-control","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"00ef178a329a33eb3fc18c36b50301634f02505e28c9613c61ee6d4185ee0b42","label":"Distributor corrective action, withdrawal and recall control","summary":"A pre-arranged capability to bring an already supplied system into conformity, withdraw it or recall it, and to immediately notify the provider or importer and the competent authorities.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-24-distributor-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"distributor-corrective-action-control-scope","operator":"all","description":"Triggered as soon as, on the basis of the information in your possession, you have reason to consider that the system does not comply with Section 2, including where that information comes from a customer rather than the provider."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:eu-database-entry-currency","legacy_id":"raip:control:eu-database-entry-currency","type":"control","slug":"eu-database-entry-currency","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a76323e94795cd8600b3d4232a3871c6ffb670db39c3cfa01d1dc41b1000a3af","label":"Currency check on the database entry","summary":"The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.","topics":["conformity","control"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:explanation-request-routing","legacy_id":"raip:control:explanation-request-routing","type":"control","slug":"explanation-request-routing","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7bde6d0cb69f7b9121ff74f6ca0260e071e8823fb6f4d27f2f002e7181a25481","label":"Routing and deadline tracking of a request for an explanation","summary":"The control that ensures an incoming request reaches an identifiable person within a set period and is answered, instead of sitting in a general inbox.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-85-right-to-complain","praxikon:eu:ai-act:obligation:article-86-right-to-explanation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:fria-in-use-currency-check","legacy_id":"raip:control:fria-in-use-currency-check","type":"control","slug":"fria-in-use-currency-check","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cc980f8c064e4008236a420a100125d0fcc3be5947ea4f7f7c926bf490b397b4","label":"Currency check on the FRIA elements during use","summary":"Periodically and on every change in process, duration of use, affected groups, risks or oversight measures, check whether the recorded elements still hold, and update the information as soon as they do not.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"fria-in-use-currency-check-scope","operator":"all","description":"The system is in use and an assessment under Article 27(1) has been performed or relied upon."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:fria-pre-deployment-gate","legacy_id":"raip:control:fria-pre-deployment-gate","type":"control","slug":"fria-pre-deployment-gate","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f26a0d2d91a4c059b5ce23eca62fc6a093d05de3b5ecb275c5c00961f5030af2","label":"Pre-deployment FRIA go/no-go","summary":"Block deployment until applicability, assessment, mitigation and notification have been completed.","topics":["control","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:gpai-compliance-route-review","legacy_id":"raip:control:gpai-compliance-route-review","type":"control","slug":"gpai-compliance-route-review","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"be5e5a46aa9e7774c40b5a5ca0c894e8165770aba77f2aec550744e78862728b","label":"Half-yearly review of whether your chosen compliance route still covers you","summary":"Establish every six months whether you demonstrate compliance through a code of practice, through a published harmonised standard, or through alternative adequate means, and whether the underlying file matches that choice.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"gpai-compliance-route-review-scope","operator":"all","description":"You are a provider of a general-purpose AI model placed on the Union market."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:gpai-documentation-change-control","legacy_id":"raip:control:gpai-documentation-change-control","type":"control","slug":"gpai-documentation-change-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4187977f383ac562ce20b445c452c5c7f1522ebe928ce37cb7ba6ca1e69dc4ab","label":"GPAI documentation change control","summary":"Update documentation and downstream information when the model, capabilities or risks change.","topics":["control","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:gpai-mandate-review","legacy_id":"raip:control:gpai-mandate-review","type":"control","slug":"gpai-mandate-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"abdb7a014ca38dc4812c42694c4c21a0ae8a1ff18298f325e121fb93b02efb17","label":"Periodic review and termination of the mandate","summary":"The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.","topics":["control","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:importer-stop-and-notify-control","legacy_id":"raip:control:importer-stop-and-notify-control","type":"control","slug":"importer-stop-and-notify-control","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6225754e4ace03b923e329cd3b4065f3429e9f882aee8fa912fa227f828df76f","label":"Stop rule and notification route on doubts about conformity","summary":"As soon as you have sufficient reason to consider a system non-conforming or falsified, it does not go to market, and where there is a risk you notify the provider, the authorised representative and the market surveillance authorities.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-23-importer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"importer-stop-and-notify-control-scope","operator":"all","description":"Triggered at the threshold of sufficient reason to consider, meaning on a well-founded signal and not only upon certainty or third-party confirmation."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:non-conformity-escalation-gate","legacy_id":"raip:control:non-conformity-escalation-gate","type":"control","slug":"non-conformity-escalation-gate","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"535a1aa616eff2148c75aa7fa2ede9d11c180414585aa8126d23e4f69814a1dd","label":"Escalation gate on a suspicion of non-conformity","summary":"The control that ensures a signal about possible non-conformity reaches an identifiable decision maker within a set period, that it is decided there whether paragraph 1 or also paragraph 2 comes into play and whether the reporting duty of Article 73 runs alongside it, and that the decision is recorded with a date instead of remaining in a support ticket.","topics":["control","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-20-corrective-actions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:notified-body-continuity-review","legacy_id":"raip:control:notified-body-continuity-review","type":"control","slug":"notified-body-continuity-review","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fabcb8697be43cd7e7a5afb718c6e33c634899dffe4109ec6bbea8a2332dd293","label":"Control on the continuity of your conformity assessment","summary":"The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).","topics":["conformity","control","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:official-journal-citation-watch","legacy_id":"raip:control:official-journal-citation-watch","type":"control","slug":"official-journal-citation-watch","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8365830680dcd843d1d8b713e68d3a55607a3c59f62b6ca07acdb6645f119944","label":"Watch on publications in the Official Journal","summary":"The control that keeps the coverage matrix current: a fixed check on new references of harmonised standards, on new or amended common specifications, and on the repeal that Article 41(4) prescribes once a standard is published, with a named owner who then updates the matrix.","topics":["conformity","control","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:reporting-person-protection","legacy_id":"raip:control:reporting-person-protection","type":"control","slug":"reporting-person-protection","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0a6eda3b73c4bd55be4c0ee50e72b0592b6bb9d23d62de1d2732f2e7f75096c2","label":"Protection of the person reporting","summary":"The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.","topics":["control","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-87-reporting-infringements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:safety-component-reassessment-trigger","legacy_id":"raip:control:safety-component-reassessment-trigger","type":"control","slug":"safety-component-reassessment-trigger","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b7a06f34c9bf60a67bc1c01bc2cc893fae70b7505eb55a44f53ab7f338be88f","label":"Reassessment on a change of function or purpose","summary":"The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:systemic-risk-notification-deadline","legacy_id":"raip:control:systemic-risk-notification-deadline","type":"control","slug":"systemic-risk-notification-deadline","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a1360f831fc363afa31b7d27ce19e2052508240de43a2a817385d5e384640dea","label":"Deadline tracking of the notification","summary":"The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:control:value-chain-representative-control","legacy_id":"raip:control:value-chain-representative-control","type":"control","slug":"value-chain-representative-control","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"092d622c30e9a7df25f8f59e6f5734fb380006a1e183c6f0e3009f8fe684988a","label":"Role reassessment on every change","summary":"Repeat the role assessment on every rebranding, modification or new use of an existing system.","topics":["control","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-1-biometrics","legacy_id":"raip:definition:annex-iii-area-1-biometrics","type":"definition","slug":"annex-iii-area-1-biometrics","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"06d2c055970a09dc388a0c89907336f3aeb31ab93d97a70346acf440d068bc97","label":"Annex III, point 1: biometrics","summary":"Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Biometrics, in so far as their use is permitted under relevant Union or national law: (a) remote biometric identification systems. This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be; (b) AI systems intended to be used for biometric categorisation, according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics; (c) AI systems intended to be used for emotion recognition.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 1","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area where order matters most: many biometric applications first engage a prohibition under Article 5 and only then the question whether they are high-risk. Note subpoint (b) too: the text covers not only categorisation on sensitive characteristics themselves but also categorisation based on the inference of those characteristics, and that inference element is exactly where this subpoint bites.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 1","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Rules that were not postponed already apply in this area. Article 5(1)(f) has prohibited, since 2 February 2025, AI systems inferring emotions of a natural person in the workplace and in education, except where the system is put into service or placed on the market for medical or safety reasons, and Article 5(1)(g) prohibits biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with the carve-out attached to it that the prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data, or categorising of biometric data in the area of law enforcement. Article 50(3) has required deployers of emotion recognition and biometric categorisation systems, since 2 August 2026, to inform the persons exposed. The date of 2 December 2027 applies to the high-risk rules, not to those prohibitions and that transparency duty.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f) and (g), Article 50(3), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/biometrie","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-2-critical-infrastructure","legacy_id":"raip:definition:annex-iii-area-2-critical-infrastructure","type":"definition","slug":"annex-iii-area-2-critical-infrastructure","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"66333c35ee0160d73cb5ce61d1610c52db447d25b29983457b79cc555e23b11f","label":"Annex III, point 2: critical infrastructure","summary":"Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 2","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The only area without lettered subpoints, and the only one excluded by Article 86 and Article 27: point 2 carries no right to an explanation and no fundamental rights impact assessment. The test sits in the words safety component and management and operation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 2","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/kritieke-infrastructuur","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-3-education-and-vocational-training","legacy_id":"raip:definition:annex-iii-area-3-education-and-vocational-training","type":"definition","slug":"annex-iii-area-3-education-and-vocational-training","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"57245084664bd933a726eef3777437e56c1ef5f6c96e9b9429cb5fd24568f428","label":"Annex III, point 3: education and vocational training","summary":"Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Education and vocational training: (a) AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels; (b) AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels; (c) AI systems intended to be used for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access, in the context of or within educational and vocational training institutions at all levels; (d) AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 3","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Not limited to schools: every vendor of assessment, placement or proctoring software sits here. Note the context clause in subpoints (c) and (d), which ties them to the context of or within an educational or vocational training institution; proctoring outside that context does not fall under subpoint (d) on the text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 3","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/onderwijs-beroepsopleiding","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-4-employment-and-workers-management","legacy_id":"raip:definition:annex-iii-area-4-employment-and-workers-management","type":"definition","slug":"annex-iii-area-4-employment-and-workers-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ac2c2682bf8940bebd5ad702b407ec6516a260eade226c66defed523d4ac055","label":"Annex III, point 4: employment and workers management","summary":"Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Employment, workers’ management and access to self-employment: (a) AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates; (b) AI systems intended to be used to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 4","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area touching almost every employer, and where the line between administrative help and evaluating people is crossed fastest without anyone noticing. An employer that is a body governed by public law or provides public services also reaches Article 27 here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 4","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/werkgelegenheid-personeelsbeheer","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-5-essential-private-and-public-services","legacy_id":"raip:definition:annex-iii-area-5-essential-private-and-public-services","type":"definition","slug":"annex-iii-area-5-essential-private-and-public-services","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f02c2c4969764ca9c0b91e14aa9e8d6ab2f968214fc51fc44be7171318ba6e17","label":"Annex III, point 5: essential private and public services","summary":"Annex III, point 5, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Access to and enjoyment of essential private services and essential public services and benefits: (a) AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services; (b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud; (c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance; (d) AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 5","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The broadest area: benefits, healthcare, credit, insurance and emergency services in one point. Subpoint (a) is tied to use by or on behalf of public authorities; subpoints (b) and (c) are not, and they are the only subpoints of Annex III that extend the Article 27 fundamental rights impact assessment to private deployers as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 5","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/essentiele-diensten-voordelen","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-6-law-enforcement","legacy_id":"raip:definition:annex-iii-area-6-law-enforcement","type":"definition","slug":"annex-iii-area-6-law-enforcement","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"baf7a4d2ca4edaa3e113103e3f8dbe2014f50da7f8d4d032da2b27d568c08491","label":"Annex III, point 6: law enforcement","summary":"Annex III, point 6, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Law enforcement, in so far as their use is permitted under relevant Union or national law: (a) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies in support of law enforcement authorities or on their behalf to assess the risk of a natural person becoming the victim of criminal offences; (b) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities as polygraphs or similar tools; (c) AI systems intended to be used by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices or agencies, in support of law enforcement authorities to evaluate the reliability of evidence in the course of the investigation or prosecution of criminal offences; (d) AI systems intended to be used by law enforcement authorities or on their behalf or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for assessing the risk of a natural person offending or re-offending not solely on the basis of the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality traits and characteristics or past criminal behaviour of natural persons or groups; (e) AI systems intended to be used by or on behalf of law enforcement authorities or by Union institutions, bodies, offices or agencies in support of law enforcement authorities for the profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course of the detection, investigation or prosecution of criminal offences.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 6","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Each of the five subpoints is tied to use by or on behalf of law enforcement authorities or by Union institutions in support of them. A recidivism risk model or profiling system outside that circle therefore does not enter through point 6, however closely it resembles the description; you then have to look at another point or at Article 5.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 6","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/rechtshandhaving","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-7-migration-asylum-and-border-control","legacy_id":"raip:definition:annex-iii-area-7-migration-asylum-and-border-control","type":"definition","slug":"annex-iii-area-7-migration-asylum-and-border-control","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3356e73db9f1924b55062ac32d12d5de26108cbb13ed199789d0628abc4eac4c","label":"Annex III, point 7: migration, asylum and border control","summary":"Annex III, point 7, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law: (a) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies as polygraphs or similar tools; (b) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of irregular migration, or a health risk, posed by a natural person who intends to enter or who has entered into the territory of a Member State; (c) AI systems intended to be used by or on behalf of competent public authorities or by Union institutions, bodies, offices or agencies to assist competent public authorities for the examination of applications for asylum, visa or residence permits and for associated complaints with regard to the eligibility of the natural persons applying for a status, including related assessments of the reliability of evidence; (d) AI systems intended to be used by or on behalf of competent public authorities, or by Union institutions, bodies, offices or agencies, in the context of migration, asylum or border control management, for the purpose of detecting, recognising or identifying natural persons, with the exception of the verification of travel documents.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 7","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"All four subpoints are tied to use by or on behalf of competent public authorities or Union bodies; a vendor builds the system, but the point is engaged by the intended use inside that circle. The exception for verification of travel documents in subpoint (d) is narrow and covers only that verification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 7","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/migratie-asiel-grenscontrole","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:annex-iii-area-8-justice-and-democratic-processes","legacy_id":"raip:definition:annex-iii-area-8-justice-and-democratic-processes","type":"definition","slug":"annex-iii-area-8-justice-and-democratic-processes","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f8c0153462a12cf70cb67280d79ac23299f6a968dc86474650f7fe27ec697bb","label":"Annex III, point 8: administration of justice and democratic processes","summary":"Annex III, point 8, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here. First, the boundary of this area. The text above is literally in the Regulation, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Where the text leaves room we name that room instead of closing it. Second, the weight of this split. The Regulation gives a list and not eight self-standing norms; publishing each point as its own object is our choice, because the practical question arrives per area. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own and that the points inside it are no more than parts of one norm. The summary and the commentary on this object are ours; only the text marked as official fact is the Regulation.","obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Administration of justice and democratic processes: (a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution; (b) AI systems intended to be used for influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda. This does not include AI systems to the output of which natural persons are not directly exposed, such as tools used to organise, optimise or structure political campaigns from an administrative or logistical point of view.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The core rules of Chapter III, Sections 1 to 3, apply from 2 December 2027 to systems classified as high-risk pursuant to Article 6(2) and Annex III. That date follows from Article 113 as amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The area reaching beyond the courts themselves: alternative dispute resolution and campaign tools that reach voters directly fall under it too. Subpoint (a) is tied to use by or on behalf of a judicial authority; a legal research tool at a law firm does not fall under it on the text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, point 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Duties that were not postponed already apply here as well. The transparency obligations of Article 50 apply since 2 August 2026: a provider of a system generating or manipulating synthetic content must mark that output in a machine readable format, and whoever publishes deepfake content must disclose that the content has been artificially generated or manipulated. That stands apart from the question whether the system is high-risk through point 8.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(2) and (4), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/annex-iii/rechtspleging-democratische-processen","label":"This area on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-aanbieder","legacy_id":"raip:definition:definitie-aanbieder","type":"definition","slug":"definitie-aanbieder","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b8efafa63e2c337eb9399702aedafa0893df6229ccce4aeaef40b78aa10ee6cc","label":"Provider","summary":"The role carrying the heaviest obligations, and the role organisations most often end up in by accident.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(3) defines a provider as a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Many organisations believe they are a provider because they use a model. Use alone is not the test: the dividing line is placing on the market or putting into service under your own name or trademark. Someone who modifies or fine-tunes a general-purpose AI model and places the result on the market does, however, become a provider of that modified model; recital 109 then limits the obligations to that modification or fine-tuning. Conversely, organisations wrongly assume they can never be a provider because they sell nothing: having a system developed counts, free of charge counts, and an internally built tool that you put into service under your own name for your own use makes you a provider alongside being a deployer. Article 25(1) also moves a distributor, importer, deployer or third party into the provider role for a high-risk system when it puts its name or trademark on it, makes a substantial modification, or changes the intended purpose so that the system becomes high risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess the role question per system, not per organisation, and record the answer with its reasoning. Include three fields in the register: under whose name or trademark the system is offered or put into service, who developed it or had it developed, and whether the intended purpose or configuration has changed since deployment. Reassess those fields on every substantial modification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-aangemelde-instantie","legacy_id":"raip:definition:definitie-aangemelde-instantie","type":"definition","slug":"definitie-aangemelde-instantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c69ff95d0f54baf97cf6f991713e65639055000d24cc73ec9b28ed7b02e585f0","label":"Notified body","summary":"A conformity assessment body notified in accordance with this regulation and other relevant Union harmonisation legislation. Only notified bodies may carry out the external assessments under the AI Act.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(22) defines a notified body as a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The biggest misconception is that every high-risk system must pass through a notified body. That is wrong: for most Annex III systems, internal control by the provider itself suffices. External involvement mainly arises for biometrics and for products already covered by the Annex I harmonisation legislation, where existing product certification absorbs the AI requirements. Anyone who routinely demands a notified body certificate in a tender is often demanding something that does not exist for that system, and thereby excludes suitable suppliers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each high-risk system, determine whether external assessment is legally required before writing that requirement into a contract or tender, and record the analysis. If you do require notified body involvement, note the body's identification number and scope and verify them in the official Union database.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-aanmeldende-autoriteit","legacy_id":"raip:definition:definitie-aanmeldende-autoriteit","type":"definition","slug":"definitie-aanmeldende-autoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1248a9564ca01fe98a65faaf82e2d18cc7b2f73d960ef2a4d8462d71e3223f49","label":"Notifying authority","summary":"The national authority responsible for setting up and carrying out the procedures for assessing, designating and notifying conformity assessment bodies, and for monitoring them.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(19) defines notifying authority as the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The notifying authority is not your point of contact and does not supervise you. It approves the assessors. That distinction is often missed in the market: companies approach the notifying authority when they should be dealing with the market surveillance authority. For most organisations the practical significance is indirect but real: as long as Member States have designated few bodies, capacity is limited for the systems that do require external assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in your dossier which national bodies are relevant for your sector and what role each has, so that a notification or question does not go to the wrong party. Explicitly distinguish the notifying authority, the market surveillance authority and any notified body used by your supplier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-bureau","legacy_id":"raip:definition:definitie-ai-bureau","type":"definition","slug":"definitie-ai-bureau","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9a2b7365580dacf63ba54252ec6f0f0829465fe648555e08b9d410a35ddd4c4c","label":"AI Office","summary":"Not a standalone authority but a function within the European Commission. For general-purpose AI models the AI Office is your supervisor; for ordinary AI systems it is not.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(47) defines the AI Office as the Commission's function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in the Commission Decision of 24 January 2024. References in the Regulation to the AI Office are to be construed as references to the Commission.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The final sentence matters most: in law the AI Office is the Commission. There is no separate agency to appeal to, and the powers are the Commission's powers. In practice, for providers of general-purpose AI models the AI Office is the enforcer. The Article 53 obligations have applied since 2 August 2025 and have been enforceable since 2 August 2026. For ordinary AI systems your contact is not the AI Office but the national market surveillance authority. Organisations routinely send questions to the wrong desk and lose time doing so.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Set out in your escalation and contact map who approaches whom: questions and notifications about general-purpose AI models go to the AI Office, questions about AI systems go to the national market surveillance authority. Assign one internal owner per route.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-geletterdheid","legacy_id":"raip:definition:definitie-ai-geletterdheid","type":"definition","slug":"definitie-ai-geletterdheid","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5c27e9360af4aea6af04b202ce93a0d4062298d0823734a74e169a1fdf743c26","label":"AI literacy","summary":"Skills, knowledge and understanding that enable providers, deployers and affected persons to deploy AI systems in an informed way and to become aware of the opportunities, risks and possible harm of AI.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(56) defines AI literacy as skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations under this Regulation, to make an informed deployment of AI systems and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition is role-bound: literacy must match the rights and obligations of the person concerned, so it means something different for a recruiter than for a developer or a compliance lead. That is where practice goes wrong. Organisations buy one generic e-learning for everyone and consider themselves done, whereas the definition asks for understanding that matches what a person actually does with AI. Article 4 has applied since 2 February 2025 and, following the Digital Omnibus, Regulation (EU) 2026/1744 which entered into force on 27 July 2026, has become an obligation to take measures without a guaranteed individual level. That lowers the bar for the outcome, not for the evidence: you must still show which measures you took and why they are appropriate.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record which roles in your organisation work with AI, what level of knowledge and understanding each role requires, which measure you put in place for it and when. Retain participation and dates per person, and repeat the measure when someone changes role or a new AI system is taken into use, so you can show at any moment who is demonstrably prepared.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-model-voor-algemene-doeleinden","legacy_id":"raip:definition:definitie-ai-model-voor-algemene-doeleinden","type":"definition","slug":"definitie-ai-model-voor-algemene-doeleinden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"795f4732b91cc2ce447293a5033eb5f17030d362ee7c05787c7f1c49ee8bc1de","label":"General-purpose AI model (GPAI model)","summary":"The model is not the system, and that distinction determines which chapter of obligations applies to you.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-ai-model-voor-algemene-doeleinden-exception","operator":"not","description":"AI models used for research, development or prototyping activities before they are placed on the market fall outside the definition."}],"statements":[{"kind":"official_fact","text":"Article 3(63) defines a general-purpose AI model as an AI model, including where such a model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models used for research, development or prototyping activities before they are placed on the market. Point 66 separately defines a general-purpose AI system as an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Model and system are used interchangeably in practice, and that is the heart of the confusion. Point 63 concerns the model, point 66 the system built on top of it. Obligations for GPAI models rest on the model provider; an organisation embedding that model in its own application is in principle dealing with the regime for AI systems. Two further things are missed. The definition expressly excludes models used for research, development or prototyping before they are placed on the market, so the exception lapses at the moment of placing on the market. And the phrase regardless of the way the model is placed on the market means that openly released models can fall within the definition too. On timing: Article 53 has applied since 2 August 2025, the enforcement powers of the Commission and the AI Office and the fines of Article 101 have been active since 2 August 2026, and for models placed on the market before 2 August 2025 the period runs until 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Distinguish the model layer and the system layer explicitly in your register, and record per application which underlying model is used, from which provider, and whether your organisation itself places that model on the market. When developing your own models, record the moment the research or prototyping stage ends, because that is where the regime begins.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-systeem","legacy_id":"raip:definition:definitie-ai-systeem","type":"definition","slug":"definitie-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f53a73dad1a5bd2972b6b81d011d5b96864dbc53a56c9ba55a34737f711c2a0f","label":"AI system","summary":"The gateway definition of the Regulation's system track: if your application falls outside it, the obligations for AI systems do not apply. General-purpose AI models run on a separate track under Article 3(63), with their own obligations in Article 53.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(1) defines an AI system as a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two mirror-image errors. First, treating only generative AI and language models as AI systems, which leaves classic scoring models, matching algorithms and predictive models out of the register even though they clearly infer how to generate outputs. Second, calling every piece of software AI, which makes the register useless. The hinge is the word infers: a system that merely executes a rule written by a human infers nothing. Note also the word may in may exhibit adaptiveness: adaptiveness after deployment is a possibility, not a condition. A model frozen after training is still an AI system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every application, record three answers in your AI register with a date and the name of the assessor: does it operate with some degree of autonomy, does it infer from input how to generate output, and what is that output. When the outcome is negative, keep the reasoning, because that is the document with which you later explain why the system is out of scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-testomgeving-voor-regelgeving","legacy_id":"raip:definition:definitie-ai-testomgeving-voor-regelgeving","type":"definition","slug":"definitie-ai-testomgeving-voor-regelgeving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5da6b3a335b4c33877c537f2df3ddeb3e74de36c2531ff6bb9dd33f60afb5fb6","label":"AI regulatory sandbox","summary":"A controlled framework set up by a competent authority in which you may temporarily develop, train, validate and test an innovative AI system under regulatory supervision, following a sandbox plan.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(55) defines an AI regulatory sandbox as a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The biggest misconception is that a sandbox grants an exemption from the Regulation. It does not. The framework is controlled and time-limited and operates under regulatory supervision; it does not suspend obligations. The definition also expressly names prospective providers, so parties that have not yet placed anything on the market can take part. Anyone using the term as marketing language without admission by a competent authority is using it incorrectly.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether your participation has been formally admitted by a competent authority, which period applies, which sandbox plan governs it and which obligations continue to apply during participation. Include the sandbox outcomes in your technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-beoogd-doel","legacy_id":"raip:definition:definitie-beoogd-doel","type":"definition","slug":"definitie-beoogd-doel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3fdd25e29c42777568dc8e8cac6eecbf53b2a1c6f8c092e9d09e9f6331010b1a","label":"Intended purpose","summary":"The use set by the provider on which the entire risk classification and assessment rest.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(12) defines intended purpose as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things are structurally missed. First, the intended purpose is set by the provider, not by what you as a deployer do with the system. Second, and this hits providers hard: the intended purpose is derived not only from the manual but also from promotional and sales materials and from statements. A marketing claim that the system is also suitable for recruitment or for creditworthiness assessment therefore widens the intended purpose and can shift the risk classification. For deployers the mirror-image warning applies: use outside the intended purpose is not free. It can amount to reasonably foreseeable misuse, and under Article 25(1)(c) it can amount to a change of intended purpose that makes you the provider yourself, but only where the system thereby becomes a high-risk AI system in accordance with Article 6.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Have marketing and product management align claims about application areas explicitly with the instructions for use and the technical documentation, and record that those three sources carry the same scope. As a deployer, record per system the intended purpose as described by the supplier alongside your actual use, and flag every difference as a decision point.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-bijzondere-categorieen-persoonsgegevens","legacy_id":"raip:definition:definitie-bijzondere-categorieen-persoonsgegevens","type":"definition","slug":"definitie-bijzondere-categorieen-persoonsgegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d064259aa75aae71e530774d78a8d3b15f97468076b11be82f686cde95fdf357","label":"Special categories of personal data","summary":"The sensitive data categories from the GDPR and related European rules, imported here because the AI Act attaches both a prohibition and a narrow exception to them.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(37) defines special categories of personal data as the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition cross-refers, but the AI Act gives it two independent consequences. First, it touches Article 5, enforceable since 2 February 2025: biometric categorisation that infers individually sensitive attributes such as race, political opinions, trade union membership, religion, sex life or sexual orientation is prohibited. Second, Article 10(5) contains an exception permitting processing of special category data where strictly necessary to detect and correct bias in high-risk systems. That exception is consistently read too broadly. It applies only to high-risk systems, only where other means demonstrably do not suffice, with technical limits on reuse and transmission, and with deletion once the bias has been addressed. It is not a general basis for starting to collect sensitive attributes because you want to run fairness measurements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether you rely on Article 10(5), for which high-risk system, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access, and at what point the data are deleted. Align this with your data protection officer and cross-reference from your AI dossier to the corresponding data protection impact assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-gegevens","legacy_id":"raip:definition:definitie-biometrische-gegevens","type":"definition","slug":"definitie-biometrische-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"de8709be1f53c0c58a6f7fb9f6ac1724dff49b2f4f2cde17fd9075fd50c95ce0","label":"Biometric data","summary":"The AI Act uses its own, broader wording than the GDPR, and that difference decides whether you land in Annex III or Article 5.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(34) defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Almost everyone reads the GDPR definition into this one. That goes wrong on a point that is legally decisive: Article 4(14) GDPR requires that the processing allows or confirms unique identification, and that requirement does not appear in point 34 of the AI Act. Data on behavioural characteristics such as keystroke rhythm, gait or voice features can therefore be biometric data under the AI Act even where identification is not the aim. Anyone basing their AI inventory on the GDPR qualification risks missing systems falling under Article 5 or Annex III. For the GDPR side of the same processing, that Regulation continues to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess biometrics in your AI register separately from the GDPR assessment and record both outcomes side by side. Include systems that process behavioural characteristics without an identification purpose, such as fraud detection on typing behaviour or voice analysis in the customer contact chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie","legacy_id":"raip:definition:definitie-biometrische-identificatie","type":"definition","slug":"definitie-biometrische-identificatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c3eeaee7409efa91d2f46e04aa682d173ed02d56c169d19b6bb7f7923710a33","label":"Biometric identification","summary":"A one-to-many comparison against a database, to be distinguished from the one-to-one verification of point 36.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(35) defines biometric identification as the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database. Point 36 separately defines biometric verification as the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Identification and verification are used interchangeably in conversations with suppliers, while the difference determines the regime. Identification is one-to-many: the system searches for who someone is by comparing against a database holding data on individuals. Verification is one-to-one: the system confirms whether someone is who they claim to be. Access control with a face scan against the employee's own badge record is verification; a camera running faces past a watchlist is identification. A detail that is rarely noticed: point 35 also mentions psychological features, while the definition of biometric data in point 34 does not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in writing for each biometric application whether the comparison is one-to-one or one-to-many, which database is compared against and who controls that database. Ask for this as a hard requirement during procurement, because vendor material rarely speaks in these terms and the answer determines whether you end up in Article 5 or in Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-achteraf","legacy_id":"raip:definition:definitie-biometrische-identificatie-op-afstand-achteraf","type":"definition","slug":"definitie-biometrische-identificatie-op-afstand-achteraf","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e23f14491485a8d0e49063f6f81943dcb8a627dbeeb0b2886b11154ffba28cce","label":"Post-remote biometric identification system","summary":"The residual category: any remote identification that is not real-time. Not prohibited, but high-risk, and subject to its own authorisation regime in law enforcement.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(43) defines this as a remote biometric identification system other than a real-time remote biometric identification system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A residual category is not a free zone. Searching recorded footage for individuals after the fact does not fall under the Article 5 prohibition, but it is high-risk under Annex III, point 1(a) from 2 December 2027. For law enforcement, Article 26(10) applies as well: use requires, in principle, prior authorisation, or authorisation requested without undue delay, from a judicial or independent administrative authority, tied to a specific criminal offence. Organisations that offer \"we only look back afterwards\" as reassurance are confusing the absence of a prohibition with the absence of obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each search, record who authorised it, which offence or legal basis it rests on, which period and which footage were searched, and what the outcome was.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-in-real-time","legacy_id":"raip:definition:definitie-biometrische-identificatie-op-afstand-in-real-time","type":"definition","slug":"definitie-biometrische-identificatie-op-afstand-in-real-time","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"17a55cf94f879698b7063eab7013f6ef08e4daa2a7edf45073ccdb9ab50c46bf","label":"Real-time remote biometric identification system","summary":"Remote identification where capture, comparison and identification happen without significant delay. The legislator explicitly closed the escape route of an artificial delay.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(42) defines this as a remote biometric identification system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification but also limited short delays, in order to avoid circumvention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The reference to limited short delays is deliberate. It shuts down the design in which a buffer of seconds or minutes is added so the operator can claim the system is not real-time. The distinction matters enormously: the use of real-time remote identification in publicly accessible spaces for law enforcement has been prohibited in principle since 2 February 2025 under Article 5(1)(h), with narrow exceptions requiring prior authorisation and a national legal basis.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document the processing architecture and the measured latency of the system, including test results. A statement that you \"buffer\" is not a defence if identification becomes actionable within seconds or minutes in practice.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ce-markering","legacy_id":"raip:definition:definitie-ce-markering","type":"definition","slug":"definitie-ce-markering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6f70390736fed31fbad7adf8fe20472b3acc91e453b8fa07a92578e6203f8df0","label":"CE marking","summary":"The marking by which a provider indicates that an AI system conforms to the requirements of Chapter III, Section 2 and to other applicable Union harmonisation legislation providing for its affixing.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(24) defines CE marking as a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The CE marking is a declaration by the provider itself, not a regulator's seal and not a quality label. It belongs solely to high-risk AI systems, so a supplier presenting CE marking as a selling point for an ordinary chatbot is telling you the wrong story. Conversely, the absence of CE marking is not a shortcoming for a system that is not high-risk. For high-risk systems this becomes relevant from 2 December 2027 for Annex III and 2 August 2028 for Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every high-risk AI system, request the EU declaration of conformity that must sit behind the CE marking and keep it in your dossier, together with the system version it relates to. Do not accept a reference to CE marking without the underlying declaration as evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordeling","legacy_id":"raip:definition:definitie-conformiteitsbeoordeling","type":"definition","slug":"definitie-conformiteitsbeoordeling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a4e48a70b8962f16e951ff6bcfbce1b42d2f5ae1e6be57c5e76ab98f73fa004b","label":"Conformity assessment","summary":"The process of demonstrating that a high-risk AI system meets the requirements of Chapter III, Section 2. It is the evidence step for high-risk systems, not for all AI.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(20) defines conformity assessment as the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two misconceptions dominate. The first is that every AI application needs a conformity assessment: the definition expressly limits it to high-risk systems. The second is that conformity assessment equals an external audit: for most Annex III systems the internal control route of Article 43 suffices, with the provider itself demonstrating that the requirements are met. If you conclude you are not high-risk, substantiate that conclusion in writing rather than assuming it silently. The obligations apply to Annex III systems from 2 December 2027 and to Annex I products from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record your risk classification in writing for each AI system, including the reasoning, even where the outcome is that it is not high-risk. Where it is high-risk, also record which route you follow, internal control or involvement of a notified body, and which evidence per requirement of Chapter III, Section 2 sits in the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordelingsinstantie","legacy_id":"raip:definition:definitie-conformiteitsbeoordelingsinstantie","type":"definition","slug":"definitie-conformiteitsbeoordelingsinstantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c6d3757fe90472979ef062df91c77f44600ee5a330a5b6998fa70ebcb58ce6bd","label":"Conformity assessment body","summary":"A body that performs third-party conformity assessment activities, including testing, certification and inspection.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(21) defines a conformity assessment body as a body that performs third-party conformity assessment activities, including testing, certification and inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The key phrase is third party. An internal audit function, a consultancy or your own quality team is not a conformity assessment body, however thorough the work. Note also the difference from a notified body in point 22: every notified body is a conformity assessment body, but not the reverse. Only after notification may a body carry out the statutory assessments under this regulation. Certificates from bodies that are not notified have commercial value but no legal status under the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Before purchasing an external assessment, verify that the body is in fact notified for the relevant scope and record the evidence in your dossier. For every external report, note the role the party had, adviser or notified body, so it never later appears that an advisory report was a statutory assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-deepfake","legacy_id":"raip:definition:definitie-deepfake","type":"definition","slug":"definitie-deepfake","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b0c2f8ddba451add6e0ecd11ee18e5941ab3e4527dc4b59200029d389c60e2eb","label":"Deep fake","summary":"Far broader than fake videos of famous people: objects, places, entities and events are covered too.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(60) defines a deep fake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The name pushes the reading in the wrong direction. Under this Regulation a deep fake is not limited to fake footage of famous people: the definition expressly also names objects, places, entities and events. An AI-generated photo of an existing building, a demonstration that never happened, or a product image that reads as a real photograph can therefore be a deep fake. Two boundaries matter. The definition names image, audio and video; pure text is not covered, although Article 50 has its own rule for certain publications. And content resembling a non-existent person falls outside point 60, while it may still fall under the marking duty for synthetic output. Article 50 has applied since 2 August 2026; the only transition concerns the machine-readable marking of Article 50(2) for systems already on the market before 2 August 2026, running until 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which departments publish AI-generated image, audio or video content, including marketing, communications, training and customer contact, and record per channel how the artificial origin is disclosed. Include generated images of existing locations and products, because those are precisely the ones rarely recognised as deep fakes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-distributeur","legacy_id":"raip:definition:definitie-distributeur","type":"definition","slug":"definitie-distributeur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8113722b7f4a5259c937696ebb6364c374c7ec0e0db2f09bc0cab4f8455d442f","label":"Distributor","summary":"Any link in the supply chain that makes an AI system available on the Union market and is neither provider nor importer.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"definitie-distributeur-scope","operator":"all","description":"Applies only to a party in the supply chain that is neither the provider nor the importer."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(7) defines a distributor as a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Resellers, systems integrators, marketplaces and staffing firms that ship software along with their service often assume they fall outside the Regulation because they build nothing. The definition is a residual category: if you are neither provider nor importer in the chain, and you make the system available on the Union market, you are a distributor. Note point 10: making available on the market means supply in the course of a commercial activity, whether for payment or free of charge. Passing something on free or offering a trial version is covered too. Put your own name or trademark on it and the role shifts to provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which AI systems your organisation passes on to third parties, including free of charge and as a by-product of a service, and record per system whose name or trademark it carries. Set out in your resale contracts who holds which role, so that it is not disputed later who the provider was.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-downstreamaanbieder","legacy_id":"raip:definition:definitie-downstreamaanbieder","type":"definition","slug":"definitie-downstreamaanbieder","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"64567f634b5d9591bc7e867174cd0cf0c7de78cd05d5943f26798df581a0927c","label":"Downstream provider","summary":"A provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether that model is provided by themselves and vertically integrated or obtained from another entity on a contractual basis.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(68) defines a downstream provider as a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the definition organisations most often get wrong about their own role. Anyone integrating a third party model into their own product or service and offering it under their own name is a downstream provider and therefore a provider, not merely a deployer. The words regardless of whether make clear that it does not matter whether you built the model yourself. Your position determines what information you must be able to obtain from the model provider: providers of general-purpose AI models must under Article 53 make documentation available to downstream providers, an obligation applying since 2 August 2025 and enforceable since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record which underlying model is integrated, from which party, and whether that makes you a downstream provider. Include in the contract with the model provider which Article 53 documentation you receive, and keep that documentation in your own file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-emotieherkenningssysteem","legacy_id":"raip:definition:definitie-emotieherkenningssysteem","type":"definition","slug":"definitie-emotieherkenningssysteem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5e7b6617eec86ff450259e231ea73b3b429437f6ffd36bf4a6ea689c94bd219d","label":"Emotion recognition system","summary":"Prohibited in the workplace and in education since 2 February 2025; elsewhere an information duty under Article 50 applies since 2 August 2026.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-emotieherkenningssysteem-exception","operator":"not","description":"The Article 5(1)(f) prohibition does not apply where the use of the AI system is intended to be put in place or into the market for medical or safety reasons."}],"statements":[{"kind":"official_fact","text":"Article 3(39) defines an emotion recognition system as an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. Article 5(1)(f) prohibits placing on the market, putting into service for this specific purpose, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two scoping errors. First, assuming that every form of sentiment analysis is covered. The definition requires the inference to be made on the basis of biometric data. Sentiment analysis on written text, without biometrics, falls outside point 39 even though it feels comparable. Second, thinking only of facial expressions, while voice analysis in a call centre and posture analysis from camera footage are equally covered. Note also the word intentions alongside emotions: systems predicting purchase readiness or aggression from biometrics fall within the definition. Outside the workplace and education, emotion recognition is not prohibited, but it is listed in Annex III, point 1(c) and therefore counts as a high-risk AI system there once Article 6(2) becomes applicable on 2 December 2027. In addition, since 2 August 2026 the deployer carries the Article 50(3) duty to inform the exposed persons, except for systems permitted by law to detect, prevent, investigate or prosecute criminal offences.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map where voice, facial or posture analysis runs in your organisation, including as part of a larger package such as quality monitoring in customer contact, access control or proctoring. Assess per application whether biometric data forms the basis and whether the context is workplace or education; record that assessment, because this is the category carrying a fine of up to EUR 35 million or 7 percent of worldwide turnover.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ernstig-incident","legacy_id":"raip:definition:definitie-ernstig-incident","type":"definition","slug":"definitie-ernstig-incident","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b2c183f2dea17656eef982882a75bbebec3dec2519ac961d86b33fdd86801fbf","label":"Serious incident","summary":"Four categories of consequence, one of which is an infringement of fundamental rights protection. No physical harm is needed before a notification duty arises.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to: (a) the death of a person or serious harm to a person's health, (b) a serious and irreversible disruption of the management or operation of critical infrastructure, (c) the infringement of obligations under Union law intended to protect fundamental rights, or (d) serious harm to property or the environment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Point (c) is the provision organisations miss most often. An infringement of Union law protecting fundamental rights counts as a serious incident, even with no one physically injured. Systematic discrimination in a candidate screening system, in credit scoring or in the allocation of benefits can therefore be notifiable. \"Indirectly\" counts too: what matters is not only the direct output but the consequence further down the process. Providers of high-risk systems report to the market surveillance authority under Article 73, on short deadlines: in principle within 15 days of becoming aware, 2 days for a widespread infringement or serious disruption of critical infrastructure and 10 days in the event of death. That duty bites from the high-risk dates, Annex III on 2 December 2027 and Annex I on 2 August 2028, but incident logging should start now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Set up an incident register now that captures the four categories of point 49 separately, with a timestamp at the moment of awareness. Run one drill to confirm you can file a complete notification within two days; that is the tightest deadline and an ad hoc process will not meet it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gebruiksinstructies","legacy_id":"raip:definition:definitie-gebruiksinstructies","type":"definition","slug":"definitie-gebruiksinstructies","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"36ea5a9c1adf2d4c04734855fb040c503286546625eeaacfec1e1e732f4bf78c","label":"Instructions for use","summary":"The information the provider supplies to inform the deployer about, in particular, the intended purpose and proper use of an AI system. It is the hinge between the provider's obligations and the deployer's.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(15) defines instructions for use as the information provided by the provider to inform the deployer of, in particular, an AI system's intended purpose and proper use.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this goes wrong in two directions. Providers deliver marketing material or a technical manual instead of instructions that state the intended purpose and the limits of correct use. And deployers file those instructions without reading them, even though Article 26 requires them to use the system in accordance with them. A deployer operating outside the instructions for use can be treated as a provider under Article 25 and thereby take on the full set of provider obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the current instructions for use for each AI system in your dossier, with version number and date of receipt. Also record who in your organisation has read them, which uses you derive as permitted, and which uses you have explicitly prohibited in your own internal work instruction.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gebruiksverantwoordelijke","legacy_id":"raip:definition:definitie-gebruiksverantwoordelijke","type":"definition","slug":"definitie-gebruiksverantwoordelijke","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0e873b1862c2479a06c94ff9d198956c2f1ad38bdcc68dc41fb3f573f8f25e81","label":"Deployer","summary":"The role that virtually every organisation buying and using AI ends up in.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-gebruiksverantwoordelijke-exception","operator":"not","description":"Use in the course of a personal non-professional activity falls outside the definition."}],"statements":[{"kind":"official_fact","text":"Article 3(4) defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The role is routinely reduced to user, and that is where it goes wrong. The individual employee operating the tool is not the deployer; the legal entity using the system under its authority is. The second trap is the exception: it covers only personal non-professional use. An employee who takes up an AI tool on their own initiative for work does not fall under that exception, and the organisation remains the deployer even without a procurement contract. Shadow AI is therefore not a grey area but simply an unregistered system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per system which legal entity uses it under its authority, including tools a department procured itself or switched on within an existing licence. Add a periodic inventory of AI features that vendors have activated inside existing software, because those rarely arrive through procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-geharmoniseerde-norm","legacy_id":"raip:definition:definitie-geharmoniseerde-norm","type":"definition","slug":"definitie-geharmoniseerde-norm","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"70a5ec3eac27ea95162009985906f76819f9368b8019430397847748a6f4fdb7","label":"Harmonised standard","summary":"A European standard published in the Official Journal which, if you apply it, produces a presumption of conformity. This is the fastest route to demonstrability, but the AI Act standards are not finished yet.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(27) defines a harmonised standard as a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Textually this is a cross-reference, but the practical weight sits in Article 40: if you apply a harmonised standard whose reference has been published in the Official Journal, you are presumed to comply with the corresponding requirement. That removes a great deal of evidentiary burden. The problem as of the reference date is that the standardisation work at CEN and CENELEC is not yet fully completed and published, so organisations cannot currently lean on a ready-made presumption of conformity. Waiting for the standards is not viable, because the Annex III obligations arrive on 2 December 2027 and the Annex I ones on 2 August 2028. You therefore have to build demonstrability yourself and align later.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Maintain a register recording, per requirement from Chapter III, which standard, framework or internal control you rely on and why that choice covers the requirement. Structure that register so you can replace a row once the harmonised standard is published, without having to rewrite your entire dossier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-geinformeerde-toestemming","legacy_id":"raip:definition:definitie-geinformeerde-toestemming","type":"definition","slug":"definitie-geinformeerde-toestemming","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ab248474c9e870bf5f61b6dc9b78cd334224361527ea7ef7012cf449b5261b7c","label":"Informed consent","summary":"A subject's freely given, specific, unambiguous and voluntary expression of willingness to take part in a particular real-world test, after having been informed of all aspects relevant to that decision.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(59) defines informed consent as a subject's freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject's decision to participate.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Note the word particular: consent applies to one specific test, not to your testing programme as a whole and not to a next version of the system. A general clause in terms of use or an employment contract does not meet this. It is also a concept of its own under the AI Act and not the same as consent as a legal basis under the GDPR, so you cannot cover both with a single form. If the design of the test changes materially, you need fresh consent.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Use a separate consent form for each test containing the information relevant to the decision, and record when and how consent was given and how it can be withdrawn. Document separately that consent was voluntary, particularly for employees.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gemachtigde","legacy_id":"raip:definition:definitie-gemachtigde","type":"definition","slug":"definitie-gemachtigde","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1793ad1268e6a72c62e9c52cbdd27c80e19e72172e7d9ecc775c0f350e6c0d2d","label":"Authorised representative","summary":"The European point of contact for a provider from outside the Union, valid only on the basis of a written mandate.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"definitie-gemachtigde-scope","operator":"all","description":"The authorised representative is located or established in the Union and has received and accepted a written mandate."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(5) defines an authorised representative as a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common error is that a European sales partner, reseller or subsidiary assumes it is automatically the authorised representative. That does not follow from the commercial relationship. The definition sets two cumulative requirements: the mandate is written, and it is not only given but also accepted. Without that document there is no authorised representative and the supervisory authority in the Union has no formal point of contact for that provider. A second misconception is that appointing an authorised representative transfers the provider role. It does not: the representative acts on behalf of the provider, and the provider remains the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Ask every supplier from outside the Union for the name, registered address and contact details of the authorised representative and for a copy or confirmation of the accepted written mandate. Store it with the system file, because it is the first thing you need once a supervisory authority requests information about a system you source from outside the Union.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gemeenschappelijke-specificatie","legacy_id":"raip:definition:definitie-gemeenschappelijke-specificatie","type":"definition","slug":"definitie-gemeenschappelijke-specificatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"421ebb1712528befa2715115a21d98edf0bf2e164e2351f776bfcbbfd3bf3489","label":"Common specification","summary":"Technical specifications the Commission can adopt itself when harmonised standards are missing or fall short. The fallback that prevents the AI Act from stalling because standardisation is delayed.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(28) defines a common specification as a set of technical specifications as defined in Article 2, point (4), of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition exists because the legislator anticipated that standardisation would not be ready in time. Article 41 allows the Commission to adopt common specifications through implementing acts, with the same effect: applying them creates a presumption of conformity. The misunderstanding is that a common specification would be optional in practice. It is not: anyone deviating must show that their own technical solution is at least equivalent to the intended level of protection, and that reasoning must sit in the technical documentation. Deviating is allowed, but it costs more documentation than following.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Track the Commission's implementing acts and record which common specifications apply to your system. If you choose your own solution, explicitly document which element you do not follow, which alternative measure you take, and on the basis of which analysis you conclude the level of protection is equivalent.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gevoelige-operationele-gegevens","legacy_id":"raip:definition:definitie-gevoelige-operationele-gegevens","type":"definition","slug":"definitie-gevoelige-operationele-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bc6d19db61ff6157ceb0a90fe6d02e2a0a935cff58b07e9ce125caca6ad9d71","label":"Sensitive operational data","summary":"Operational data around detection and prosecution whose disclosure could harm criminal proceedings. The concept on which the law enforcement exceptions to transparency rest.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(38) defines sensitive operational data as operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the key with which the AI Act softens transparency obligations for law enforcement without removing them. Registration of high-risk systems used by law enforcement authorities takes place in a secure, non-public section of the EU database, and certain information need not be made public where it concerns sensitive operational data. Where it goes wrong: the concept is sometimes stretched to cover anything a public body would rather not share. That does not hold, because the definition is doubly bounded, namely by the criminal law context and by a concrete risk to the integrity of criminal proceedings. Outside that context it is no basis for withholding documentation; commercially confidential information follows a separate route. Equally important: it limits publication, not the access of the competent market surveillance authority.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per system which parts of your registration and documentation you designate as sensitive operational data, on what concrete ground disclosure could harm the integrity of criminal proceedings, who makes that assessment and when it is reviewed. Keep a non-sensitive summary available, so you can still account for the system without touching ongoing proceedings.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-importeur","legacy_id":"raip:definition:definitie-importeur","type":"definition","slug":"definitie-importeur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5929cd13fabbde75a31e8c36d3c791127c89b1aa48d8441e74ef87a49f5fd62c","label":"Importer","summary":"Whoever places on the Union market a system bearing the name or trademark of a party established in a third country.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(6) defines an importer as a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical trap is the assumption that importer has to do with customs or with the invoice flow. The test is different: do you place on the Union market for the first time a system bearing the name or trademark of a party from a third country. Someone who only takes a US service for their own use is not an importer but a deployer. Someone who passes on that same system under their own name or trademark is not an importer but a provider. The importer role sits exactly in between: passing it on with the third party's mark still on it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record three data points per AI system in your supplier register: the country of establishment of the party whose name or trademark the system bears, whether your organisation is the first to make the system available on the Union market, and under which name that happens. Those three fields together determine whether you are an importer, a distributor or a provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-in-de-handel-brengen","legacy_id":"raip:definition:definitie-in-de-handel-brengen","type":"definition","slug":"definitie-in-de-handel-brengen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7609bd6024e0675b2a5d459b010ccc5fa73c1556181f65fb346395f733e85ea1","label":"Placing on the market","summary":"The first moment a system or model is made available on the Union market, and therefore the trigger for many obligations.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(9) defines placing on the market as the first making available of an AI system or a general-purpose AI model on the Union market. Point 10 adds that making available on the market means the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The most persistent error is assuming that a sale or a price must be involved. Point 10 explicitly says whether in return for payment or free of charge. A free trial, an openly available model or a no-cost pilot at a customer can amount to placing on the market. The second error is confusing this concept with putting into service. Placing on the market concerns the market; a system you build and use purely internally is not placed on the market, but it is put into service, and that is an independent trigger in its own right.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each system and model the date of first making available in the Union, together with its form: sale, free trial, open release or pilot. That date determines which regime and which transitional period apply, and it is the first thing a supervisory authority will put next to your file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-in-gebruik-stellen","legacy_id":"raip:definition:definitie-in-gebruik-stellen","type":"definition","slug":"definitie-in-gebruik-stellen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"40f1cd7abe7b92d00b279e86fa695c94699acacbd644f4125e347401d180dd79","label":"Putting into service","summary":"The concept that brings internally built systems which are never sold within the scope of the Regulation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(11) defines putting into service as the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the trap for organisations that build their own systems. The reasoning runs: we sell nothing, so we place nothing on the market, so provider obligations do not apply. The words or for own use close off that route. As soon as you start using a self-built system in the Union for its intended purpose, you have put it into service, and under point 3 you are a provider as well as a deployer. Note also for first use: a system still running in a test environment and not used for its intended purpose has not yet been put into service.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Register for every internally developed AI system the date on which it went into production for its intended purpose, and note explicitly that your organisation is both provider and deployer. Tie the start of your file-building to that date, and assess immediately whether the system is high risk, because the technical documentation of Article 11 and the logging of Article 12 then apply from that moment and the file need not be reconstructed after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-inputdata","legacy_id":"raip:definition:definitie-inputdata","type":"definition","slug":"definitie-inputdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f2f8b703dc2d81858c6766ab6f7ca4e844f569071af7e99d0de1749bbff9b5c1","label":"Input data","summary":"The data entering the system or acquired by it, on the basis of which it produces its output. This is the data definition that touches the deployer, not just the provider.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(33) defines input data as data provided to or directly acquired by an AI system on the basis of which the system produces an output.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is where responsibility moves to your side of the table. Article 26(4) requires the deployer to ensure that input data are relevant and sufficiently representative in view of the intended purpose, to the extent it exercises control over them. The most persistent misconception is that data quality is the supplier's problem. Prompts, uploaded CVs, sensor readings, customer files and connected source systems are all input data, and an excellently built system produces unusable outcomes when you feed it outdated or skewed data. Note the second half of the definition as well: data the system acquires itself, for instance through a camera or an API, are equally input data and therefore fall within your duty of care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which input data are used, which source systems they come from, who owns their quality and representativeness, how often that is checked, and how long the input is retained in the logs. Explicitly name the input sources you do not control, since that marks the boundary of your duty of care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-kritieke-infrastructuur","legacy_id":"raip:definition:definitie-kritieke-infrastructuur","type":"definition","slug":"definitie-kritieke-infrastructuur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2f9688d6fbfc93d1a18ed0b3009a83c9fa9ca70529193ef905e1438b53837445","label":"Critical infrastructure","summary":"Critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557, the CER Directive. The AI Act gives no definition of its own here but aligns with that framework.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(62) provides that critical infrastructure means critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This cross-reference looks like a formality but has direct consequences for the risk class. Annex III, point 2, classifies AI systems as high risk where they are intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. Anyone wanting to know whether they fall within that scope must consult the CER Directive and the national designation of critical entities rather than invent a definition of their own. Organisations get this wrong because designation differs per Member State.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether your organisation or your customer has been designated as a critical entity under the national transposition of Directive (EU) 2022/2557, and link that determination to your risk classification under Annex III, point 2, with date and source.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-markttoezichtautoriteit","legacy_id":"raip:definition:definitie-markttoezichtautoriteit","type":"definition","slug":"definitie-markttoezichtautoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"33d5e1ae9840557e2d286646345f725d31d173d29cd696b6c028efbc2ada46be","label":"Market surveillance authority","summary":"The national supervisor that enforces the AI Act on the market, with the powers from the general market surveillance regulation. This is the party that comes knocking and requests your documentation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(26) defines the market surveillance authority as the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The confusion lies in distinguishing it from two other players. The notifying authority designates notified bodies and does no enforcement towards you; the Commission's AI Office supervises general-purpose AI models under Article 53, which has applied since 2 August 2025 and has been enforceable since 2 August 2026. The market surveillance authority is your actual enforcement contact point for AI systems: it can request technical documentation and logs, demand access to training and testing data sets, and restrict, withdraw or recall a system. The reference to Regulation (EU) 2019/1020 is not a formality, because through it the supervisor inherits a substantial toolkit of powers that did not need restating in the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which market surveillance authority is competent (this differs per sector and per Member State where you offer it), who inside your organisation is the point of contact, and within how many working days you can supply the technical documentation, the logs and the data set descriptions. Rehearse that delivery once, because the deadline the supervisor sets is short.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-nationale-bevoegde-autoriteit","legacy_id":"raip:definition:definitie-nationale-bevoegde-autoriteit","type":"definition","slug":"definitie-nationale-bevoegde-autoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"68e66efba97d9301506986942cb0b5559676c13e74b683e6a04131755f934feb","label":"National competent authority","summary":"An umbrella term for two very different roles: the notifying authority and the market surveillance authority. For EU institutions the European Data Protection Supervisor takes their place.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(48) defines a national competent authority as a notifying authority or a market surveillance authority. As regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities are to be construed as references to the European Data Protection Supervisor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition bundles two roles that should not be confused. The notifying authority designates and supervises conformity assessment bodies; as a deploying organisation you will rarely deal with it. The market surveillance authority supervises you, requests documentation, receives serious incident reports and imposes measures. Member States were required to designate and publish these authorities by 2 August 2025. The fact that designation is not fully settled in some Member States changes nothing about your obligations: the duties rest on you, not on the supervisor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every market in which you operate, track which market surveillance authority is competent for your sector, who inside your organisation handles contact and who is authorised to file notifications. State that contact point in your technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-niet-persoonsgebonden-gegevens","legacy_id":"raip:definition:definitie-niet-persoonsgebonden-gegevens","type":"definition","slug":"definitie-niet-persoonsgebonden-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6030cd84e362fe78bf9921f4e12b6d6018095b99b973465833b9144135e6040","label":"Non-personal data","summary":"Everything that is not personal data. The category exists to make clear that the AI Act applies even when no personal data is involved.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(51) defines non-personal data as data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This residual category is the proof that the AI Act is not a privacy law. The data and data governance requirements in Article 10, the technical documentation in Article 11 and the logging in Article 12 apply equally where you work only with machine data, sensor data or synthetic data. \"There is no personal data in it\" is at most a GDPR argument and never an AI Act exemption. In practice, technical teams use this argument to avoid documentation duties in industrial and infrastructure applications, which are exactly the applications that can fall under Annex I and Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each dataset whether it contains personal data, but never let that answer determine whether you produce the AI Act documentation. Assess documentation duties on the system's risk classification, not on the nature of the data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-openbare-ruimte","legacy_id":"raip:definition:definitie-openbare-ruimte","type":"definition","slug":"definitie-openbare-ruimte","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"896ab14f18c3e7c26c51a80be2ec11c4cb7993d3ab0327d4e9335cd0b954d295","label":"Publicly accessible space","summary":"Any physical place, publicly or privately owned, accessible to an undetermined number of people. Access conditions and capacity limits are irrelevant.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(44) defines a publicly accessible space as any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply and regardless of potential capacity restrictions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The familiar argument \"it is our own premises, so not a public space\" does not hold. Shops, stations, airports, stadiums, cinemas, hospital waiting rooms and shopping centres are publicly accessible spaces, even where ticketing, house rules or a capacity cap apply. What matters is whether the circle of visitors is undetermined. An office floor open only to your own staff normally falls outside, because that circle is determined. This concept switches the Article 5 prohibition on real-time remote identification on or off, and feeds through into Annex III classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"In your camera and biometrics register, mark for each location whether it is a publicly accessible space within the meaning of point 44, with a short justification. Do this before you procure a system, not after.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-operator","legacy_id":"raip:definition:definitie-operator","type":"definition","slug":"definitie-operator","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9b6f7e5b05a7c4b4fb0ecd210e6a6d585a78ef0309b31a7358b91e81e90dcc6c","label":"Operator","summary":"The umbrella term for all six roles in the chain, and not the person operating the controls.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(8) defines an operator as a provider, product manufacturer, deployer, authorised representative, importer or distributor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Operator is read as the person who operates the system day to day. That is precisely what it does not mean. It is an umbrella term: where a provision addresses operators, it addresses all six listed roles at once. Anyone who skips operator obligations in a gap analysis because they believe they are only a deployer misses provisions that do apply to them. Note also that product manufacturer appears in this list as a role but is not separately defined in Article 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add an operator column to your compliance overview that spells out the six roles explicitly, so that for each provision it is visible which roles are affected. Record per AI system every role your organisation holds for that specific system, because there is usually more than one.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-persoonsgegevens","legacy_id":"raip:definition:definitie-persoonsgegevens","type":"definition","slug":"definitie-persoonsgegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5f531533c5f033ec83c79b8dbe127db1de6e7a95344d8a02855f2838f3d57b0e","label":"Personal data","summary":"The AI Act deliberately creates no separate concept here and refers to the GDPR. Your GDPR records and your AI Act file must therefore cover the same data.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(50) defines personal data as personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The cross-reference looks dull but has a practical effect: there is no room for a separate AI Act reading of what constitutes personal data. Where the AI Act does open space, such as Article 10(5) permitting processing of special categories to detect and correct bias in high-risk systems, GDPR safeguards apply in full and additional conditions attach. Organisations that keep AI governance and privacy in separate files end up with conflicting descriptions of the same processing, precisely when a supervisor asks for both.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Link every AI system in your AI register to the corresponding processing activity in your GDPR record, using one shared identifier, so that a single change updates both files.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-plan-voor-testen-onder-reele-omstandigheden","legacy_id":"raip:definition:definitie-plan-voor-testen-onder-reele-omstandigheden","type":"definition","slug":"definitie-plan-voor-testen-onder-reele-omstandigheden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9070268d8aca95a4a3f19619bce98e681a8e5e4a2b3b454824b10249b3b702e5","label":"Real-world testing plan","summary":"The document in which you set out in advance how you will test an AI system outside the lab: objective, methodology, scope, who takes part, for how long and how you monitor it. Without this plan, testing in real-world conditions is not permitted.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(53) defines a real-world testing plan as a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this goes wrong because organisations keep calling a pilot with real users a pilot and assume nothing applies. As soon as you trial an AI system with real people in a real environment, you fall under the regime of Article 57 or 60, and that requires a plan drawn up in advance that can be reviewed. A test plan written after the fact to fill a file does not meet the definition, because the essence of the concept is that the design is fixed beforehand.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every real-world test, record a single document containing the eight elements from the definition: objective, methodology, geographical scope, the population involved, duration, monitoring, organisation and conduct. Link that document to the registration of the test and retain it with the date of approval.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-prestaties-ai-systeem","legacy_id":"raip:definition:definitie-prestaties-ai-systeem","type":"definition","slug":"definitie-prestaties-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d5ba2214f5fc1d09014b5705fdf602a7d9569bfb5ecc37b8a9edb76ea2dcf91","label":"Performance of an AI system","summary":"The ability of an AI system to achieve its intended purpose. Performance is therefore measured against the intended purpose, not against a standalone technical score.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(18) defines performance of an AI system as the ability of an AI system to achieve its intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition ties performance firmly to the intended purpose in point 12. An accuracy of 94 percent is therefore no answer to whether the system performs, as long as it is not established what it is meant for and for which group of people that score holds. A model that scores well on average but performs structurally worse for a subgroup does not achieve the intended purpose for that group. That is exactly what Article 15 on accuracy and robustness and Article 10 on data quality target.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record which performance metrics you use, which threshold is acceptable for the intended purpose, and how those metrics break down per relevant subgroup. Repeat the measurement periodically and retain the results, so you can demonstrate performance drift before a supervisory authority asks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-proefpersoon","legacy_id":"raip:definition:definitie-proefpersoon","type":"definition","slug":"definitie-proefpersoon","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2a16ab809e3d8274195aecfa9c536f70c3b6014bd6eb681db9591735bdf484a0","label":"Subject","summary":"For the purpose of real-world testing, a subject is a natural person who participates in such a test. The term comes from the testing regime, not from data protection law.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(58) defines subject, for the purpose of real-world testing, as a natural person who participates in testing in real-world conditions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition looks trivial but determines who is protected. Whoever is a subject is entitled to informed consent under point 59 and to the safeguards of Articles 57 and 60. The misunderstanding lies in assuming that only external test participants are subjects. Employees who work with a test system during their job can also be subjects, and precisely for them the voluntariness of consent is a sensitive point given the hierarchical relationship.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each test, keep a record of the subjects or of the clearly delimited group they come from, with the date of their consent and how they were informed. Assess separately whether employees participate as subjects and how you safeguard voluntariness.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-profilering","legacy_id":"raip:definition:definitie-profilering","type":"definition","slug":"definitie-profilering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a93aa74cab4873b611f98e223294c400f8b1a82e9a410d48051d44b8ef4a8624","label":"Profiling","summary":"Taken from the GDPR, but decisive in the AI Act: an Annex III system that profiles always remains high-risk.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(52) defines profiling as profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most important of the three GDPR cross-references. Article 6(3) offers an exception under which an Annex III system is nonetheless not treated as high-risk, for instance because it performs a narrow procedural task or only preparatory work. That exception falls away entirely once the system profiles within the meaning of the GDPR: automated processing to evaluate personal aspects such as performance, reliability, behaviour, health or preferences. In practice most recruitment, credit scoring and fraud detection applications do profile, so the exception many organisations invoke rarely holds.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each Annex III system, record explicitly whether it profiles within the meaning of Article 4(4) GDPR, with the reasoning and the date. Keep that reasoning with your Article 6(3) assessment; it is the first document a supervisor will ask for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-rechtshandhaving","legacy_id":"raip:definition:definitie-rechtshandhaving","type":"definition","slug":"definitie-rechtshandhaving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b70b2d63ec22c2531647bfd7cc878332768a97516194ee3eb176298a54e2b8ca","label":"Law enforcement","summary":"The activity, not the authority. Work carried out on behalf of a law enforcement authority is covered as well, including where a private party performs it.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(46) defines law enforcement as activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The words \"on their behalf\" are decisive. A vendor, forensic analysis firm or contracted data specialist working for the police operates inside the law enforcement regime, with the corresponding safeguards and registration duties. Conversely, fraud investigation by an insurer, internal integrity investigations and private security are not law enforcement. Those organisations cannot use the exceptions and fall squarely under the ordinary regime, including the prohibition on real-time remote identification as it applies to them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each deployment, record whether it falls inside or outside law enforcement, naming the commissioning authority and the contractual documents. Put that qualification in the contract so vendor and client apply the same regime.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-rechtshandhavingsinstantie","legacy_id":"raip:definition:definitie-rechtshandhavingsinstantie","type":"definition","slug":"definitie-rechtshandhavingsinstantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0860e2540f9c082630db246bc258237fdef48cea528e516e89b08a015444f834","label":"Law enforcement authority","summary":"Not just the police and prosecution service. Also any other body entrusted under national law with public authority for detection, prosecution or public security.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(45) covers (a) any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security, and (b) any other body or entity entrusted by Member State law to exercise public authority and public powers for those same purposes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Point (b) draws the circle far wider than people expect. Special enforcement officers, specialised investigation services, parts of municipal enforcement and private bodies with a statutory public task can all fall within it. This is not a label without consequences: the status changes the regime. Law enforcement authorities may rely, under strict conditions, on exceptions in Article 5, register their high-risk use in a non-public section of the EU database under Article 49(4), and are subject to their own safeguards in Article 26. An organisation that wrongly treats itself as a law enforcement authority builds its compliance file on the wrong footing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each team and each AI system, record the statutory basis on which you enforce and whether that makes you a law enforcement authority. Have that qualification reviewed legally before you rely on any exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-redelijkerwijs-te-voorzien-misbruik","legacy_id":"raip:definition:definitie-redelijkerwijs-te-voorzien-misbruik","type":"definition","slug":"definitie-redelijkerwijs-te-voorzien-misbruik","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1d878f952a65193ba15fd9063f41f55c720ebde6a05151597fae5090dcedab7c","label":"Reasonably foreseeable misuse","summary":"Use outside the intended purpose that the provider could have seen coming, and must therefore anticipate.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(13) defines reasonably foreseeable misuse as the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The word misuse suggests bad intent, or a user error. That is the wrong reading. It concerns behaviour that is simply predictable: an employee who also uses a summarisation tool for decision-making, a chatbot receiving questions it was not built for, a model fed input by another system through an integration. The second error is the belief that excluding a use in the manual removes the risk. Not being mentioned in the manual is not the same as not being foreseeable. Note also the explicit mention of interaction with other systems, including other AI systems: chained and agentic set-ups fall squarely within it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep a short list per system of foreseeable deviating use, fed by incidents, helpdesk questions and end-user signals, and note for each entry which measure was taken. Include the integrations with other systems explicitly in that list, because that is where use nobody designed emerges.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-risico","legacy_id":"raip:definition:definitie-risico","type":"definition","slug":"definitie-risico","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"367cbb58e793aeabc5e16e675d752f5d1d4e20ec3f1a1e7f088983c7f5a9d467","label":"Risk","summary":"Risk is the combination of the probability of harm occurring and the severity of that harm. It is the unit of measurement underpinning the entire regulation, from prohibited practices to the Article 9 risk management system.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(2) defines risk as the combination of the probability of an occurrence of harm and the severity of that harm.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition looks trivial but decides who is right in a dispute. Many organisations assess AI risk as the chance of a technical failure, whereas the regulation looks at harm to people's health, safety and fundamental rights. A model that rarely fails but that, when it does, wrongly excludes someone from a job or a benefit scores high in AI Act terms, not low. Without separately substantiating probability and severity, you have an opinion rather than a risk assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI application, record in your register what harm you foresee, to whom, how likely you consider it, how severe the consequence is, and the source of that estimate. Use one fixed scale for probability and severity across all applications so scores are comparable and you can show the classification was not ad hoc.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-substantiele-wijziging","legacy_id":"raip:definition:definitie-substantiele-wijziging","type":"definition","slug":"definitie-substantiele-wijziging","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1695d1dc88c1730de688ee4975230bf449ed94ea90a06e6ce04434b17759537d","label":"Substantial modification","summary":"A change to an AI system after it has been placed on the market or put into service that the provider did not foresee in the initial conformity assessment, and that affects compliance with Chapter III, Section 2 or changes the intended purpose.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(23) defines substantial modification as a change to an AI system after its placing on the market or putting into service which was not foreseen or planned by the provider in the initial conformity assessment and as a result of which compliance with the requirements set out in Chapter III, Section 2 is affected, or which results in a modification of the intended purpose for which the AI system was assessed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition decides when you must reassess, and it contains an escape route that is often missed: changes the provider foresaw and planned in the conformity assessment are not substantial modifications. A system that keeps learning within predefined boundaries therefore falls outside it in principle, while a model you retrain on a new population or repurpose does not. Note also the link with Article 25: if you change the intended purpose, you as deployer can become the provider. The legal term is substantial modification, not material change.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep a change log per AI system with the date, nature of the change, the reason, and the assessment of whether it is a substantial modification, including who determined that. Agree with your provider in advance which changes were already foreseen in the conformity assessment, so you do not have to argue afterwards about whether reassessment was required.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-categorisering","legacy_id":"raip:definition:definitie-systeem-voor-biometrische-categorisering","type":"definition","slug":"definitie-systeem-voor-biometrische-categorisering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fbcbc185dd0893403d5dd704758abe9fa3be327d9869bfb1ee5af1f03e17eb86","label":"Biometric categorisation system","summary":"An AI system that assigns people to categories on the basis of their biometric data. The carve-out for functions ancillary to another commercial service is narrow and is routinely read far too broadly in practice.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(40) defines a biometric categorisation system as an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Categorising is not the same as identifying: you are not establishing who someone is, you are attaching a label. That does not make it harmless. Sorting people by sensitive attributes such as race, political opinion, trade union membership, religion or sexual orientation has been prohibited under Article 5 since 2 February 2025, and since 2 August 2026 Article 50(3) requires you to inform the people the system is applied to. The carve-out only applies where the categorisation is strictly necessary on technical grounds for another service, for example an image filter that has to locate facial features. Commercial convenience is not technical necessity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each system which categories it assigns, which biometric features it uses and for what purpose. If you rely on the carve-out, document the technical necessity in the system description, and build the Article 50(3) information duty into your user-facing notices.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-identificatie-op-afstand","legacy_id":"raip:definition:definitie-systeem-voor-biometrische-identificatie-op-afstand","type":"definition","slug":"definitie-systeem-voor-biometrische-identificatie-op-afstand","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7c72e1b3c6b064394fd0d86cfbe44bc02d19b83bb6de7e8bc5b790de3ed19eb7","label":"Remote biometric identification system","summary":"An AI system that identifies people without their active involvement, typically at a distance, by comparing them against a reference database. The decisive words are \"active involvement\".","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(41) defines a remote biometric identification system as an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance, through the comparison of a person's biometric data with the biometric data contained in a reference database.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The hinge is whether the person actively participates. An employee placing a finger on a reader or presenting their face to gain entry is actively involved: that is biometric verification within the meaning of point 36, not remote identification. A camera that silently matches passers-by against a database does fall within scope, and such systems are high-risk under Annex III, point 1 in any event, with all attendant obligations from 2 December 2027. Vendors often sell this as \"smart access control\", while the reference database and the absence of cooperation are what actually decide the classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every camera or biometric system, establish and document two things: is there a reference database behind it, and does the person actively cooperate. Those two answers determine whether you land in Annex III and whether the Article 5 prohibition comes into play.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-monitoring-na-in-de-handel-brengen","legacy_id":"raip:definition:definitie-systeem-voor-monitoring-na-in-de-handel-brengen","type":"definition","slug":"definitie-systeem-voor-monitoring-na-in-de-handel-brengen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"52b7a3c34b19d54d31fb01524d1d71983825954390b43016beb44963a8cad530","label":"Post-market monitoring system","summary":"The set of activities through which a provider keeps following how its AI system behaves in practice after launch, so it can intervene in time. Conformity is a starting point, not an end point.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(25) defines this as all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service, for the purpose of identifying any need to immediately apply necessary corrective or preventive actions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is where organisations consistently slip: they treat the conformity assessment as the finish line and organise nothing afterwards. The definition instead establishes a continuous obligation covering the entire lifetime of the system, elaborated in Article 72 into a mandatory monitoring plan. It is not about waiting passively for a complaint, but about actively collecting and reviewing. For high-risk systems this bites from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), but the monitoring system must be designed in from the start, since otherwise you have no historical data to demonstrate drift or degradation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which signals you collect (complaints, support tickets, anomalous outcomes, performance measurements over time), who reviews them, at what frequency, and which threshold triggers a corrective action or a serious incident report. Keep the review records with date and model version, so you can later show that you did not start measuring only after an incident.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeemrisico","legacy_id":"raip:definition:definitie-systeemrisico","type":"definition","slug":"definitie-systeemrisico","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c8c6caf33ae18fc4a6b0088d737650a27551b660acde096bddbd180a4584802f","label":"Systemic risk","summary":"A concept that applies exclusively to GPAI models, and that is unrelated to the high-risk classification of AI systems.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(65) defines systemic risk as a risk specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society as a whole, that can be propagated at scale across the value chain. Point 64 defines high-impact capabilities as capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. Article 51(2) provides that a model is presumed to have such capabilities when the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10 to the power of 25.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Systemic risk is often used in conversation as a synonym for high risk, and sometimes, borrowed from the financial sector, as a synonym for systemic importance. Both are wrong. Under this Regulation systemic risk is exclusively a qualification of a general-purpose AI model, never of an AI system and never of an organisation. A second misconception is that the threshold of 10 to the power of 25 floating point operations is the definition. It is not: that threshold sits in Article 51(2) and operates as a presumption, while under Article 51(1)(b) the Commission may also classify a model, on its own initiative or following a qualified alert from the scientific panel, where it has capabilities or an impact equivalent to those in point (a), having regard to the criteria in Annex XIII. For virtually every organisation this concept concerns their supplier rather than themselves; the relevant question is then which model you use and what the provider documents about it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI application which underlying GPAI model is used and whether the provider designates that model as one with systemic risk, and keep the documentation or model card on which you base that. Use this information in supplier conversations rather than as your own classification, because the qualification belongs to the model provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-terugroepen-ai-systeem","legacy_id":"raip:definition:definitie-terugroepen-ai-systeem","type":"definition","slug":"definitie-terugroepen-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f4d2c87792a00e0b1002f3ada4386e8240f9778baefb9b8461ef4e671bd0cd89","label":"Recall of an AI system","summary":"A measure aimed at returning an AI system to the provider, taking it out of service, or disabling its use, where that system has already been made available to deployers. A recall reaches systems already in use.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(16) defines recall of an AI system as any measure aiming to achieve the return to the provider, the taking out of service, or the disabling of the use of an AI system made available to deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The difference from withdrawal is the point in the chain. A recall reaches the customer already running the system, while withdrawal only stops what has not yet been delivered. For software a recall is rarely physical: it is a disabled feature, a revoked licence key or a blocked API. Organisations underestimate that a provider may be required under Article 20 to recall a system you depend on operationally, so you need to know today what you will do if a core system is switched off tomorrow.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record who at the provider can announce a recall, through which channel you will receive that notice, and what fallback you have if the system becomes unusable immediately. Put these arrangements in the contract and test at least annually that the notification channel works.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testdata","legacy_id":"raip:definition:definitie-testdata","type":"definition","slug":"definitie-testdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"391375ba99e7c076813061d93db1fcfa0ac49f2c5e52448359b0abf0830367e7","label":"Testing data","summary":"Data for an independent evaluation confirming expected performance, which must take place beforehand: before the system is placed on the market or put into service.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(32) defines testing data as data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two words carry this definition: independent and before. Independent means the testing data must not have been used in training or tuning; the moment you go back and adjust the model based on the test results, your test set is contaminated and you need a new one. Before means the confirmation happens in advance, not as a reconstruction after a supervisor asks. In practice this fails most often with continuously updated systems: every substantial modification calls for a fresh independent confirmation, not a reference to last year's measurement. For high-risk systems this bites from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the test set sealed off and separated from the development team, and record the measurement results per relevant subgroup, with date, model version and the metric used. Tie every substantial modification to a fresh testing round and note who performed the evaluation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testen-onder-reele-omstandigheden","legacy_id":"raip:definition:definitie-testen-onder-reele-omstandigheden","type":"definition","slug":"definitie-testen-onder-reele-omstandigheden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"462eb93f173779fad096bb2f06a0467b6764a8920030b4912a1c59c601205c7e","label":"Testing in real-world conditions","summary":"Temporarily testing an AI system for its intended purpose outside the lab, in order to gather reliable data and assess conformity. It does not count as placing on the market or putting into service, provided you meet all conditions of Article 57 or 60.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(57) defines testing in real-world conditions as the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation; it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception stands or falls on the word provided. If you do not meet all conditions of Article 57 or 60, your test is no longer a test but a putting into service, with all the obligations that entails and an enforcement exposure you did not see coming. In practice this shows up in pilots that quietly continue, tests that are extended to more users or sites, and systems that simply stay in production after the pilot period. Temporary means temporary.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each test, record the start and end dates, the intended purpose being tested, the legal basis in Article 57 or 60, and an explicit decision point at the end: stop, extend under the same conditions, or move to putting into service with the full set of obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testomgevingsplan","legacy_id":"raip:definition:definitie-testomgevingsplan","type":"definition","slug":"definitie-testomgevingsplan","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d58656e46ce10c410330e0fd13609d719fc0d554b8e33dcf30b9fd4096513081","label":"Sandbox plan","summary":"The agreement between you and the supervisory authority about what you will do in an AI regulatory sandbox: objectives, conditions, timeframe, methodology and requirements. It is a two-sided document, not an internal plan.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(54) defines a sandbox plan as a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The distinction from point 53 is often missed. The real-world testing plan is your own test design; the sandbox plan is a document agreed with the competent authority. That means you cannot change it unilaterally, and departing from the agreed conditions affects your participation in the sandbox. It is also the document with which you can later demonstrate that the supervisor knew what you were doing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the signed or confirmed sandbox plan under version control and record every change together with the competent authority's agreement. Record in your file which activities fell within the agreed scope and which were kept outside it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-trainingsdata","legacy_id":"raip:definition:definitie-trainingsdata","type":"definition","slug":"definitie-trainingsdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef859e4087e8a7ceaa231ae837f6477f14ad93fb7a3b9faf98497d7b8313abe9","label":"Training data","summary":"Data used to fit the learnable parameters of an AI system. Narrowly defined, and precisely for that reason decisive for who carries which data governance obligation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(29) defines training data as data used for training an AI system through fitting its learnable parameters.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition is deliberately technical: it covers only data that actually fit the learnable parameters. Data you pass in a prompt or place in a retrieval index are not training data, and that distinction determines whether Article 10 on data governance applies to you. Where it goes wrong: organisations that fine-tune an existing model with their own data assume they remain mere users, while they are fitting learnable parameters and quickly become a downstream provider with documentation obligations of their own. For general-purpose AI models there is additionally the public summary of training content under Article 53, applicable since 2 August 2025 and enforceable since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per data set its origin, the basis on which you may use it, the period over which it was collected, which processing steps were applied, and which known limitations or skews it contains. Keep training data administratively separate from validation and testing data, and explicitly log every occasion on which you fine-tune an external model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-uit-de-handel-nemen","legacy_id":"raip:definition:definitie-uit-de-handel-nemen","type":"definition","slug":"definitie-uit-de-handel-nemen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2482d5e315cec62e5648d6abd0385eecdee52a794798bc48f2f6a506ee223348","label":"Withdrawal of an AI system","summary":"A measure aimed at preventing an AI system that is in the supply chain from being made available on the market. It stops distribution, not use by existing customers.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(17) defines withdrawal of an AI system as any measure aiming to prevent an AI system in the supply chain being made available on the market.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the lighter counterpart to a recall and is frequently confused with it, including in contracts. Withdrawal only affects units still in the chain at importers and distributors. Anyone already using the system notices nothing until a recall follows. For your own procurement the practical question is whether a supplier that withdraws its product still delivers updates, patches and support, or whether you are left with a system that is commercially dead but operationally live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include in procurement contracts that the provider informs you as soon as it withdraws an AI system, even if you already use it, and record which maintenance and security updates you will still receive afterwards and for how long.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-validatiedata","legacy_id":"raip:definition:definitie-validatiedata","type":"definition","slug":"definitie-validatiedata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4771ce3b2faa0f52b26fd42f2d915c301b392c7f3d128ff560c4183e2a98868c","label":"Validation data","summary":"Data with which you evaluate and tune the trained system, including its non-learnable parameters, to prevent underfitting and overfitting. Meant for tuning, not for producing the final score.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(30) defines validation data as data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The legislator deliberately separated validation from testing, because the classic error is using the same data both for tuning hyperparameters and for reporting final performance. You then measure your own choices back and overstate accuracy, while Article 15 requires a realistic level of accuracy that is stated in the instructions for use. In supervisory conversations this is one of the first things that stands out: an impressive accuracy figure without a separate, untouched test set.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record which tuning decisions were made on validation data, how many evaluation rounds took place and which configuration was ultimately chosen. Ensure the validation data are never used for the figure you cite in the instructions for use and the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-validatiedataset","legacy_id":"raip:definition:definitie-validatiedataset","type":"definition","slug":"definitie-validatiedataset","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b7e609baae36b231e16a3fdde9d8681deb4529b66c942984c2c7793877d13b1b","label":"Validation data set","summary":"The form validation data may take: a separate data set or part of the training data set, as a fixed or variable split. The law leaves the method open, but not the explainability.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(31) defines a validation data set as a separate data set or part of the training data set, either as a fixed or variable split.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition looks redundant but settles a concrete argument: may you use cross-validation instead of a fixed holdout. The answer is yes, because a variable split is expressly allowed. The flip side is that the burden shifts to reproducibility. If your split changes per run and you do not record the splitting rule, you cannot afterwards show that your reported performance is not the result of a lucky split. For data sets with a time ordering or with heavily represented subgroups, a random split is moreover misleading, while Article 10 specifically demands representativeness.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in the technical documentation which split you use, whether it is fixed or variable, which splitting rule or seed applies, and why that split suits the nature of the data. Keep this per model version, so a later retest is reproducible.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-veiligheidscomponent","legacy_id":"raip:definition:definitie-veiligheidscomponent","type":"definition","slug":"definitie-veiligheidscomponent","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"82b2bd6ae24f5ede7ef37bd40b03e99e2024a962e24dd7cbb7f7676595fe8e63","label":"Safety component","summary":"One of the two routes into the high-risk classification of Article 6(1), and often overlooked outside manufacturing.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(14) defines a safety component as a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition contains two independent tests joined by an or, and the second is almost always forgotten. A component need not have an identifiable safety function: it is enough that its failure or malfunctioning endangers the health and safety of persons or property. Property counts too, not only injury. The second misconception is that this concept only matters for machinery and medical devices. It is the gateway to Article 6(1), and therefore to the high-risk route via Annex I, which becomes applicable on 2 August 2028 for AI embedded in regulated products. Being a safety component is not sufficient in itself. Article 6(1) sets two cumulative conditions: alongside point (a), point (b) requires that the product, or the AI system as a product, must undergo third-party conformity assessment under the Annex I Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run both tests separately for each AI system and record both answers: does it fulfil a safety function, and what happens on failure or malfunctioning. Involve the product safety specialist or the product manufacturer, because that assessment belongs alongside the existing product conformity assessment and not in a separate AI track.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-wijdverbreide-inbreuk","legacy_id":"raip:definition:definitie-wijdverbreide-inbreuk","type":"definition","slug":"definitie-wijdverbreide-inbreuk","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bb625a0755e50f4c81ec2042b0840b7bce5cdc560ecfb5dc8348f5234e15ac05","label":"Widespread infringement","summary":"An act or omission contrary to Union law protecting the interests of individuals that harms the collective interests of persons in at least two other Member States, or that, with common features, occurs concurrently and is committed by the same operator in at least three Member States.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(61) defines a widespread infringement as any act or omission contrary to Union law protecting the interest of individuals which: (a) has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which (i) the act or omission originated or took place, (ii) the provider concerned or, where applicable, its authorised representative is located or established, or (iii) the deployer is established, where the infringement is committed by the deployer; or (b) has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This concept does not determine what is prohibited but how supervision is organised. Once a shortcoming in your AI system plays out the same way in several Member States, it stops being a series of separate national files and becomes one coordinated enforcement track. That is exactly the exposure of standardised software: one setting, one model or one flaw in the logic hits everywhere at once and therefore almost automatically meets the common features criterion. Note that the second limb expressly refers to the same operator, which brings deployers into scope and not only providers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map the Member States in which the same AI system or configuration is used and track which incidents and complaints share the same root cause across borders. Ensure that a correction made in one country is demonstrably rolled out in the others as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-zwevendekommabewerking-flop","legacy_id":"raip:definition:definitie-zwevendekommabewerking-flop","type":"definition","slug":"definitie-zwevendekommabewerking-flop","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"19fb0acd8e5e74b53182b1168df1505c0d7447ea4958d578708685882580b049","label":"Floating-point operation (FLOP)","summary":"Any mathematical operation or assignment involving floating-point numbers. This is the unit of computation with which the Regulation measures the scale of training of a general-purpose AI model.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(67) defines a floating-point operation as any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A technical definition with legal bite: FLOP is the yardstick for determining whether a general-purpose AI model is presumed to have high-impact capabilities and therefore systemic risk, using the cumulative training compute threshold in Article 51. That turns an engineering number into a compliance fact. In practice the problem is record keeping: many organisations can no longer establish afterwards how much compute went into training, while that very figure determines which regime applies and whether notification to the Commission is required.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every model you train or significantly further train, record the cumulative amount of compute in FLOP, the measurement method and the hardware used, and keep that record with the model's technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:ai-office-incident-and-assessment-record","legacy_id":"raip:evidence:ai-office-incident-and-assessment-record","type":"evidence","slug":"ai-office-incident-and-assessment-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"aa513b2e5543e349e9ed73bff5fdb13116e863efd089a15b5afee3903f7a76f9","label":"File of reports and assessments with the AI Office","summary":"Per serious incident: when you established it, when and where you reported it, which system version it concerned and how you met the Article 73 deadlines. Per third-party conformity assessment: that the Office was responsible, which notified body acted on behalf of the Commission, which fees you paid directly and when the assessment was completed.","topics":["enforcement","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The date is a derivation and not a deadline that Article 75 states itself. Both paragraphs address the provider of a high-risk AI system, and that status only arises once Chapter III, Sections 1 to 3, becomes applicable. Point (c) of the third paragraph of Article 113, as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744, gives two dates for that: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I. That second route does not drop out here, because the four carve-outs in Article 75(1) sit inside point (a), while point (b) independently brings a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine under the competence of the AI Office. This object carries the earlier of the two in deadline_at; for a system entering through point (b) and Annex I the date is 2 August 2028.","obligation_ids":["praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"editorial_interpretation","text":"The date on this object is derived and not stated by Article 75 itself. Point (c) of the third paragraph of Article 113 gives two dates for the moment Chapter III, Sections 1 to 3, becomes applicable: 2 December 2027 through Article 6(2) and Annex III, and 2 August 2028 through Article 6(1) and Annex I. This object carries the earlier of the two. Which date applies to your system depends on the route by which it is high-risk, and that choice is not made here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-i-product-route-record","legacy_id":"raip:evidence:annex-i-product-route-record","type":"evidence","slug":"annex-i-product-route-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6eac0d6037a3d5ce9f190875bb97e869dacbcd30d5147a98b1b9035b46eff115","label":"Product route record","summary":"Per product: the Annex I legal act, the section it falls under after 27 July 2026, the conformity assessment procedure chosen and whether a third party is involved, the harmonised standards any opt-out relies on, the AI functions identified as safety components together with the failure analysis, and the role you carry as a result. This is the file that shows why your system is or is not high risk through Article 6(1).","topics":["evidence","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record","legacy_id":"raip:evidence:annex-iii-area-mapping-record","type":"evidence","slug":"annex-iii-area-mapping-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b4d0c04bcf0db0393cf6bc1c95fbb74c71ef9aa68dca43830d11e05dea625f84","label":"Record of the mapping to a point of Annex III","summary":"Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-article-49-2-registration-record","legacy_id":"raip:evidence:annex-iii-article-49-2-registration-record","type":"evidence","slug":"annex-iii-article-49-2-registration-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6b15d546edc41ffd88f61b5c03d4f1c57d60aac40411f5339e09eb7399081b1e","label":"Article 49(2) registration record for the system assessed as not high-risk","summary":"Proof that the system for which you invoke the Article 6(3) exception is registered as Article 49(2) requires, with the registration number linked to the underlying assessment.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"annex-iii-article-49-2-registration-record-scope","operator":"all","description":"You invoke the Article 6(3) exception for an Annex III system."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-article-6-3-dated-assessment","legacy_id":"raip:evidence:annex-iii-article-6-3-dated-assessment","type":"evidence","slug":"annex-iii-article-6-3-dated-assessment","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"86971a70880a7466e353f1fd01c4bc66558016f5da51f719fd7da7eab3899cf1","label":"Dated Article 6(3) assessment made before market placement","summary":"The written assessment with date, author and rationale, drawn up before the system is placed on the market or put into service, ready to be provided to the national competent authority on request.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"annex-iii-article-6-3-dated-assessment-scope","operator":"all","description":"You are the provider and conclude that an Annex III system is not high-risk via Article 6(3)."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:annex-iii-classification-record","legacy_id":"raip:evidence:annex-iii-classification-record","type":"evidence","slug":"annex-iii-classification-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4d68ecf14476cac0fc4d5138f0be0dcc68e0abf1ac4cd44ce0aa8e994cb8a7fa","label":"Article 6 and Annex III classification record","summary":"Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.","topics":["evidence","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-10-data-governance-record","legacy_id":"raip:evidence:article-10-data-governance-record","type":"evidence","slug":"article-10-data-governance-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"32f2b963bf38be0fb7c35f6b9c324675a8d24747dacf56cb1b4b161b90f4224b","label":"Data governance file","summary":"Record per dataset of origin, choices, assumptions, bias examination and mitigations.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-11-technical-documentation-record","legacy_id":"raip:evidence:article-11-technical-documentation-record","type":"evidence","slug":"article-11-technical-documentation-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b689bbd5807454d5cdcf7df2eeb1b4551149bd8145913635ee43b8d5960c61c3","label":"Technical file (Annex IV)","summary":"Technical documentation kept current per system version, ready for a supervisor’s request.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-12-logging-record","legacy_id":"raip:evidence:article-12-logging-record","type":"evidence","slug":"article-12-logging-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"36b14e51199191933a3881aae2888e665d8dab5f41d1dd8b64dfee4f9aef7c13","label":"Logs and retention regime","summary":"Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-13-instructions-record","legacy_id":"raip:evidence:article-13-instructions-record","type":"evidence","slug":"article-13-instructions-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9cf5a9282978ba5dcc5f638ecf130b839b7d1013200e9a5ae552edd3ea76a669","label":"Instructions and interpretation file","summary":"The received instructions for use plus their internal translation into work instructions per role.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-14-human-oversight-record","legacy_id":"raip:evidence:article-14-human-oversight-record","type":"evidence","slug":"article-14-human-oversight-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bc9a6564b37a39095b93cffd0ac26e457b39138da1e5b215f988afd2f3b11550","label":"Oversight file per system","summary":"Record of oversight measures, appointed persons, their training and the moments of intervention.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record","legacy_id":"raip:evidence:article-15-accuracy-robustness-record","type":"evidence","slug":"article-15-accuracy-robustness-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"46b259071d6f973b30588fc7952ae2529db2f278e9ee17c2d0cc70c29efee49b","label":"Performance and security file","summary":"Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-16-provider-dossier","legacy_id":"raip:evidence:article-16-provider-dossier","type":"evidence","slug":"article-16-provider-dossier","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1f7243b6da197bce688b7e80cc23b9d60e2468187450dce916807519f05131db","label":"Provider dossier per high-risk AI system","summary":"One dossier per system holding the documentation, the logs, the EU declaration of conformity and the registration record, in the version that applied at the moment of placing on the market.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-16-provider-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-16-provider-dossier-scope","operator":"all","description":"To be maintained per individual high-risk AI system, not per product line or per supplier."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 16 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-17-quality-management-record","legacy_id":"raip:evidence:article-17-quality-management-record","type":"evidence","slug":"article-17-quality-management-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dd98fef1830c5aad4dbb123f0544d3056d5f2910af30df1e36a749e525839a69","label":"QMS documentation","summary":"The documented quality system with procedures, role assignment and references to the underlying files.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-18-retention-dossier","legacy_id":"raip:evidence:article-18-retention-dossier","type":"evidence","slug":"article-18-retention-dossier","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"487d604645cda8cc98d8021b49da2c699b1d45ec3ea95e6eb22362c04ac04d42","label":"Retention file per high-risk system","summary":"Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-4-measures-record","legacy_id":"raip:evidence:article-4-measures-record","type":"evidence","slug":"article-4-measures-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e6a4c07cb2d763eadd2b346ceb4000aaf4341d5c1f7acf66daf5abce9102bb1","label":"AI literacy measures record","summary":"Versioned record of roles, context, measures, participation or instruction and review moments.","topics":["ai-literacy","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-4-participation-register","legacy_id":"raip:evidence:article-4-participation-register","type":"evidence","slug":"article-4-participation-register","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1d4c18b3112e89337cc59b1e6088461b98d04a5454deaba2ae2fe47102fb9403","label":"Register of participation and instruction per person, system and date","summary":"Internal register showing who received which instruction, working session, training or guidance, for which system, on which date and on what basis, including new joiners, contractors and external staff.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-4-participation-register-scope","operator":"all","description":"Measures have been carried out under Article 4(1)."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-4-role-system-matrix-record","legacy_id":"raip:evidence:article-4-role-system-matrix-record","type":"evidence","slug":"article-4-role-system-matrix-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c9efae3988e62982d6a8f82748103a60bd3b18a3cd0a5fd1c48441874c4b958c","label":"Role-system matrix with the established literacy need","summary":"The recorded matrix of roles against AI systems, with the context of use, affected persons, risk and selected measure per combination, dated and with an owner per row.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-4-role-system-matrix-record-scope","operator":"all","description":"Your organisation is a provider or deployer of at least one AI system within scope."}],"exceptions":[{"id":"article-4-role-system-matrix-record-exception","operator":"not","description":"There is no prescribed format and no mandatory AI officer; the form may match the size of the organisation."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-46-derogation-request-file","legacy_id":"raip:evidence:article-46-derogation-request-file","type":"evidence","slug":"article-46-derogation-request-file","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7a60ee7f6aab31c0e55ae153388ff5bed3d896afd90ed226eebffc7bdd6506e9","label":"File accompanying a request to derogate from the conformity assessment","summary":"Per request: which system and which version, which exceptional reason was invoked and on which facts, to which market surveillance authority and on what date the request was made, what the status of the conformity assessment was, which end date was agreed, when the notification of paragraph 3 was made, and what the outcome was.","topics":["conformity","enforcement","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-49-registration-dossier","legacy_id":"raip:evidence:article-49-registration-dossier","type":"evidence","slug":"article-49-registration-dossier","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"729dd580c1dc362d253e0421272c09b19c132718dd4a7135f9986f386e63b836","label":"Article 49 registration dossier","summary":"Per system: which Article 49 route was followed, the registration number, the date of registration, the name of the person who submitted it, the system version the entry relates to, and, for the secure section, a statement of which limited fields from Annex VIII and Annex IX were completed.","topics":["conformity","evidence","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-49-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-5-screening-record","legacy_id":"raip:evidence:article-5-screening-record","type":"evidence","slug":"article-5-screening-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1c2ae4225779328f997e6a1d522a439d885728d71cf3045eda9abbe2dc24f5b7","label":"Article 5 screening record","summary":"A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion \"no prohibited practice\" is evidence too.","topics":["evidence","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-50-disclosure-test-report","legacy_id":"raip:evidence:article-50-disclosure-test-report","type":"evidence","slug":"article-50-disclosure-test-report","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8bfb0999742246f8fbdada0c856a340b599caad11ea54a2e21810778ac220feb","label":"Test report per touchpoint: disclosure visible, timely and accessible","summary":"Dated record per interface and channel showing that the disclosure appears at the latest at first interaction or exposure, is clear and distinguishable, and passed the accessibility check, with screenshot, version number and tester identity.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-disclosure-test-report-scope","operator":"all","description":"One of the duties in Article 50(1) to (4) applies to the system."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-50-implementation-record","legacy_id":"raip:evidence:article-50-implementation-record","type":"evidence","slug":"article-50-implementation-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f27b10e694ea2bb90ee95fc8f15d1bd35f10975665a57bdc35b4f22a0b1f255f","label":"Transparency implementation record","summary":"Record of scenario, actor, disclosure or marking, technical implementation, test and owner.","topics":["evidence","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-50-supplier-marking-statement","legacy_id":"raip:evidence:article-50-supplier-marking-statement","type":"evidence","slug":"article-50-supplier-marking-statement","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5a855bbbf7836c1953cdffd63c43df4eefe2f9206bf1958914af1a9af419d6b","label":"Supplier statement on machine-readable marking of output","summary":"Written statement from the supplier describing which marking is applied to the output, in which machine-readable format, how robust and interoperable the solution is, and whether the marking survives editing or export.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-supplier-marking-statement-scope","operator":"all","description":"The system generates synthetic audio, image, video or text content."}],"exceptions":[{"id":"article-50-supplier-marking-statement-exception","operator":"not","description":"The duty does not apply to the extent the AI system performs an assistive function for standard editing or does not substantially alter the input data provided by the deployer or its semantics, or where authorised by law to detect, prevent, investigate or prosecute criminal offences. Under the amended application calendar in Regulation (EU) 2026/1744, systems placed on the market before 2 August 2026 have a transition until 2 December 2026 for this machine-readable marking."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record","legacy_id":"raip:evidence:article-55-gpai-systemic-risk-record","type":"evidence","slug":"article-55-gpai-systemic-risk-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"80aec0d15f08b43419b7c3db7adf403eae6ff153b6de6d569741ac2f73e7ec7a","label":"Systemic-risk file","summary":"Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.","topics":["evidence","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record","legacy_id":"raip:evidence:article-56-code-adherence-decision-record","type":"evidence","slug":"article-56-code-adherence-decision-record","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7b7dd0817eeaba14597f377f266eeda19e018e03219c541bfe6bc9f028370ef6","label":"Record of the decision on a code of practice","summary":"Per model: the decision whether or not to adhere to a code of practice, the version and chapter it relates to, the date and the authorised signatory, whether adherence was limited under paragraph 7 to the obligations in Article 53, and, where the decision is negative, the elaboration of your own for the issues in paragraph 2.","topics":["evidence","governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-57-written-proof-and-exit-report","legacy_id":"raip:evidence:article-57-written-proof-and-exit-report","type":"evidence","slug":"article-57-written-proof-and-exit-report","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9771b8700143bc4d15dfd3498c66ced14b19b86e08b6db20ef66ca9479ef8967","label":"Written proof of participation and the exit report","summary":"On request, the competent authority provides written proof of the activities successfully carried out, plus an exit report with results and learning outcomes. You can use that documentation in conformity assessment and in market surveillance.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-57-written-proof-and-exit-report-scope","operator":"all","description":"Applies where you participate in or exit an AI regulatory sandbox as a provider or prospective provider. The written proof is provided only upon request; the exit report is provided by the authority on its own initiative. If you participate as a deployer in partnership under Article 58(2), point (b), the written proof remains a right of the provider or prospective provider; agree contractually that you receive a copy."}],"exceptions":[{"id":"article-57-written-proof-and-exit-report-exception","operator":"not","description":"Publication of the exit report through the single information platform only occurs where you and the national competent authority both explicitly agree. Access by the Commission and the Board likewise requires your agreement and remains subject to the confidentiality provisions in Article 78."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 57 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-61-informed-consent-record","legacy_id":"raip:evidence:article-61-informed-consent-record","type":"evidence","slug":"article-61-informed-consent-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"83c5561586bc98fb077ea5fd1b38b139c7cc36ea6e0393d7d6c05ea8f99346df","label":"Dated and documented informed consent of test subjects","summary":"For every test subject you record freely given informed consent, covering five prescribed information elements, dated, documented, with a copy provided to the subject.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-60-real-world-testing"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-61-informed-consent-record-scope","operator":"all","description":"Applies to every natural person who is a subject of testing in real world conditions under Article 60, prior to their participation."}],"exceptions":[{"id":"article-61-informed-consent-record-exception","operator":"not","description":"Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the AI system from being tested, testing may proceed without consent, provided that the testing and its outcome have no negative effect on the subjects and that their personal data are deleted after the test is performed. Outside that specific context there is no exception to consent."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-61-subject-information-pack","legacy_id":"raip:evidence:article-61-subject-information-pack","type":"evidence","slug":"article-61-subject-information-pack","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c8ce308511cb063b102afd2ce37a253dc3e6db2e2004149528224f21bd2f79a9","label":"Information pack for subjects of testing in real world conditions","summary":"The document that precedes consent: per test the five points of Article 61(1) written out, with the Union-wide unique single identification number, the contact details from whom further information can be obtained, and the mechanism for requesting the reversal or the disregarding of an output. This is a different item from the dated consent record itself, which sits in article-61-informed-consent-record.","topics":["evidence","fundamental-rights","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-61-informed-consent"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-62-sme-status-record","legacy_id":"raip:evidence:article-62-sme-status-record","type":"evidence","slug":"article-62-sme-status-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ed5c5b665f36364124f30b00bc26ee0fb194eebbbda28aaf18f1b74da7be11d2","label":"File on SME status and facilities used","summary":"The substantiation of your status as an SME or start-up with the date, the evidence of a registered office or branch in the Union, and per facility what was applied for, with which body, on what date and with what outcome, including the answer to how the fee reduction was applied.","topics":["evidence","governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-62-sme-support-measures"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-63-sme-eligibility-record","legacy_id":"raip:evidence:article-63-sme-eligibility-record","type":"evidence","slug":"article-63-sme-eligibility-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f87cb291c675b354a46343133cd9c19172f8e7e9c9c1374a416da66d86a2c4f6","label":"File on microenterprise status","summary":"The record of the test against Recommendation 2003/361/EC with the date, the evidence that there are no partner enterprises or linked enterprises, and the list of the elements of the quality management system for which you want to invoke a simplification once the Commission guidelines exist.","topics":["evidence","high-risk-requirements","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-63-sme-derogations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record","legacy_id":"raip:evidence:article-72-post-market-monitoring-record","type":"evidence","slug":"article-72-post-market-monitoring-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a18ec7e58d627144f8421441a9201ab887912716bcd16766e589d779216eef36","label":"Monitoring plan and reports","summary":"The plan as part of the technical documentation plus the periodic analyses and follow-up actions.","topics":["evidence","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-73-incident-reporting-record","legacy_id":"raip:evidence:article-73-incident-reporting-record","type":"evidence","slug":"article-73-incident-reporting-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fb0ba99f9bdac6eefd1c88a6bf50aa6400d1c69556f236bca616a9eb0c2b515f","label":"Incident register and reports","summary":"Record of incidents, analyses, reports to supervisors and corrective measures.","topics":["evidence","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-78-submission-register","legacy_id":"raip:evidence:article-78-submission-register","type":"evidence","slug":"article-78-submission-register","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7f0b4c2661b1eff2583e0610b30ab07aff9916ba1ec11d1e0ffcb1379c03fba5","label":"Register of submissions to authorities","summary":"Per submission: which system, which document, which version, to which recipient, on what date, which part was marked confidential, and which purpose the recipient stated.","topics":["enforcement","evidence","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification","legacy_id":"raip:evidence:article-8-state-of-the-art-justification","type":"evidence","slug":"article-8-state-of-the-art-justification","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"176cee8830401ce1f875026a5c8b547a06ec90b0f3764045749971944b8ea2f9","label":"Justification of the state of the art","summary":"Per system and per version: which intended purpose was taken, which standards, specifications, evaluation methods and test sets were treated as the state of the art, which were deliberately not applied and why, who established that, and on what date the record was reviewed again.","topics":["conformity","evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-9-risk-management-record","legacy_id":"raip:evidence:article-9-risk-management-record","type":"evidence","slug":"article-9-risk-management-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"20554dec6405ccab0e623e6efb0f1bdecfb6a777ca09760e48b3981ff0aa3e56","label":"Risk management file","summary":"Versioned record of risk analyses, chosen measures, residual risks and test results per system version.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-95-voluntary-commitment-register","legacy_id":"raip:evidence:article-95-voluntary-commitment-register","type":"evidence","slug":"article-95-voluntary-commitment-register","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"10a5c6acb8fe1177b7c15862884d9f48b9b5bee6ef30bc125a603028bf9d595b","label":"Register of voluntary commitments alongside the obligations","summary":"Per system and per commitment: which requirements you apply voluntarily, under which paragraph of Article 95, with which objectives and key performance indicators, who owns it, when it is measured, and which obligation under the Regulation continues to apply in full alongside it.","topics":["evidence","governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:article-99-101-penalty-exposure-register","legacy_id":"raip:evidence:article-99-101-penalty-exposure-register","type":"evidence","slug":"article-99-101-penalty-exposure-register","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"26861e8785e9779404427f4167ee17b0f32121936562af6e3e6c27102fa2060a","label":"Register of penalty ceilings per obligation","summary":"Per obligation: which ceiling attaches to it and on which provision that rests, whether the level follows from national law and if so from which, and whether the Article 101 or Article 75c regime is added on top. This is the document that shows a board there is no single amount, and that substantiates where you make your controls heavier.","topics":["enforcement","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-99-101-penalties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:authority-request-response-file","legacy_id":"raip:evidence:authority-request-response-file","type":"evidence","slug":"authority-request-response-file","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6715926c5c37023452ddc7762b4e2681c4b7a59ebea79761561c2c9652b39487","label":"Response file for a request from a competent authority","summary":"Per request: which authority made it and on what legal basis, on what date, on what grounds the request was reasoned, which documents and which logs were supplied, which system version they belong to, in what language and when. This file shows you delivered fully and in time, also years later when the staff involved have left.","topics":["evidence","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"authority-request-response-file-scope","operator":"all","description":"To be maintained per individual request, and kept alongside the provider dossier of the system the request concerned. Also to be maintained where the market surveillance authority requests material from you in order to serve a fundamental rights body under amended Article 77(1) and (1a), because that channel does not rest on Article 21, has its own legal basis and calls for a machine-readable format."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:bias-testing-necessity-record","legacy_id":"raip:evidence:bias-testing-necessity-record","type":"evidence","slug":"bias-testing-necessity-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eaa43374278cdd83d1669e545e106c809a21f4eddf225586fe7e7ac9f553651c","label":"Necessity file for bias testing","summary":"Per processing operation: the system or model, the paragraph of Article 4a relied on, the justification why synthetic or anonymised data do not suffice, the technical and organisational safeguards applied, the access list, the confirmation that no other party can reach the data, and the deletion date. This is also the text that paragraph 1, point (f), requires in the record of processing activities.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:conformity-ce-registration-record","legacy_id":"raip:evidence:conformity-ce-registration-record","type":"evidence","slug":"conformity-ce-registration-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"abb03c902019896fde8cba3a0acad7168ed37188298d59f9ae7d6916a3271be9","label":"Conformity file","summary":"The assessment, EU declaration of conformity, CE marking and registration proof, per system version.","topics":["conformity","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:corrective-action-record","legacy_id":"raip:evidence:corrective-action-record","type":"evidence","slug":"corrective-action-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4ec5e103307ae94e7f6d02c44fa6d577fb5cf1eda020923d244db77032c62dbe","label":"Record of corrective actions","summary":"Per case: which signal came in and when, which system and which version it concerned, which measure was chosen and why, who decided on it, which parties were informed and when, and what the investigation of causes produced. This is the file that shows that \"immediately\" is a moment in your organisation rather than an estimate after the fact.","topics":["evidence","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-20-corrective-actions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:deployer-use-dossier","legacy_id":"raip:evidence:deployer-use-dossier","type":"evidence","slug":"deployer-use-dossier","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fdda7fb9e6de7ae1ae8e787e7d4330c149867bb1eed87d205e49829ffdf9c3ec","label":"Deployment dossier: logs, worker information and information to affected persons","summary":"The dossier that shows you retain the logs, that you informed workers and their representatives in time, and that the people about whom decisions are made are aware of it.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-26-deployer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"deployer-use-dossier-scope","operator":"all","description":"To be maintained per high-risk AI system. Log retention applies only to the extent the logs are under your control; the information under paragraph 7 applies only where you are an employer and the system is used at the workplace."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:distributor-check-and-action-log","legacy_id":"raip:evidence:distributor-check-and-action-log","type":"evidence","slug":"distributor-check-and-action-log","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"119665e2191b6c61010f189bc56bab3c964894cea3071e0ca643238c2bc12f38","label":"Distributor log of checks and corrective actions","summary":"A running record of what you checked, when, with what outcome and which action followed, because the supervisor asks about your conduct rather than about the system.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-24-distributor-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"distributor-check-and-action-log-scope","operator":"all","description":"To be maintained per system made available and per customer, for as long as the system is on the market through you and you may still have to take corrective action."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:eu-database-entry-record","legacy_id":"raip:evidence:eu-database-entry-record","type":"evidence","slug":"eu-database-entry-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"747c0a6a89a43d904575e42fa3906bb5d79d282308d08ef4c0eb964f4fe4a5a0","label":"EU database registration file","summary":"Per system: which Annex VIII data was entered, by which natural person with the legal authority to do so, on what date, in which version, when the entry was last checked against reality, and for a public deployer the URL of the entry made by the provider. This is also the file that shows the public entry and your internal documents say the same thing.","topics":["conformity","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:explanation-request-record","legacy_id":"raip:evidence:explanation-request-record","type":"evidence","slug":"explanation-request-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"622e8f0a6fa35e54594a786b8410cfb916b6338d31532161ace8e816c7a9943c","label":"Register of requests for an explanation","summary":"Per request: who made it, about which decision, which system and which version contributed to it, what explanation was given and when. This is also the file that shows you did not silently ignore the right.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-85-right-to-complain","praxikon:eu:ai-act:obligation:article-86-right-to-explanation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:fria-authority-notification","legacy_id":"raip:evidence:fria-authority-notification","type":"evidence","slug":"fria-authority-notification","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e3d8c8c4162f969eb33d703dffb99286df869c88c935824cf5b156758775e336","label":"Notification to the market surveillance authority with the completed template","summary":"The sent notification through which you report the assessment results to the market surveillance authority, with the completed template attached, plus date of dispatch and acknowledgement of receipt.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"fria-authority-notification-scope","operator":"all","description":"The assessment under Article 27(1) has been performed."}],"exceptions":[{"id":"fria-authority-notification-exception","operator":"not","description":"In the case referred to in Article 46(1), deployers may be exempt from the notification duty; the assessment itself does not fall away."}],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:fria-dpia-crosswalk","legacy_id":"raip:evidence:fria-dpia-crosswalk","type":"evidence","slug":"fria-dpia-crosswalk","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b4c078b39849d433b845408840eb67f2c313067f2f2275d22c3b15d21a0a9fd3","label":"Crosswalk showing the FRIA complements rather than repeats the DPIA","summary":"An overview indicating per Article 27(1) element whether it is already covered in the data protection impact assessment and where, so it is visible which elements exist only in the FRIA.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"fria-dpia-crosswalk-scope","operator":"all","description":"A data protection impact assessment has been carried out or is required for the same deployment."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:fria-report","legacy_id":"raip:evidence:fria-report","type":"evidence","slug":"fria-report","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e1a8981a104a700cd8e8138d96d56c30865ee1c30ba8e7757002d59e9dc51a94","label":"FRIA report and notification","summary":"Dated impact assessment, measures, residual risks and, where required, notification to the market surveillance authority.","topics":["evidence","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-compliance-file","legacy_id":"raip:evidence:gpai-compliance-file","type":"evidence","slug":"gpai-compliance-file","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7262c79821f4a681772adcd2c0841fa9bfbb6e4c59124704064543d75cd6d2dc","label":"GPAI compliance file","summary":"Current technical documentation, downstream information, copyright policy and public training summary.","topics":["evidence","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-model-version-register","legacy_id":"raip:evidence:gpai-model-version-register","type":"evidence","slug":"gpai-model-version-register","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fbe144a47934ee8420952d2b02bba307ed0d6fa00f731548657ecc03f28671f9","label":"Model version register listing the changed Annex XI and XII elements per version","summary":"A register with one row per model version: release date, distribution method, architecture and parameter count, compute used, and a note of which Annex XI and Annex XII elements changed relative to the previous version.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"gpai-model-version-register-scope","operator":"all","description":"You place or make available more than one version of the same GPAI model on the Union market."}],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-public-training-summary","legacy_id":"raip:evidence:gpai-public-training-summary","type":"evidence","slug":"gpai-public-training-summary","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a87c76bed567c86db130620e5f947f3c586cb00a6757261945fc99d18e6552e9","label":"Public summary of training content following the AI Office template","summary":"The published, sufficiently detailed summary of the content used to train the model, drawn up according to the template provided by the AI Office, with publication date and the corresponding model version.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"gpai-public-training-summary-scope","operator":"all","description":"You are a provider of a general-purpose AI model placed on the Union market."}],"exceptions":[{"id":"gpai-public-training-summary-exception","operator":"not","description":"The open-source exemption in Article 53(2) covers only points (a) and (b) of paragraph 1 and therefore leaves the public training summary intact."}],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:gpai-representative-mandate-file","legacy_id":"raip:evidence:gpai-representative-mandate-file","type":"evidence","slug":"gpai-representative-mandate-file","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c48344fa977400be55c1d5713e695114d36fd9a1af8343301b43ea121cd8eb7b","label":"Mandate file of the authorised representative","summary":"The written mandate itself, in an official language of the institutions of the Union, together with the copy of the Annex XI technical documentation, the contact details of the provider, and the record of the verification under paragraph 3(a). The provider grants the mandate and supplies the documentation; the ten year retention after the placing on the market rests under paragraph 3(b) with the representative, which keeps the file at the disposal of the AI Office and national competent authorities.","topics":["evidence","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:importer-verification-record","legacy_id":"raip:evidence:importer-verification-record","type":"evidence","slug":"importer-verification-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7086f44c16690148ca56d0ec81a420d3ecdd0b893e32a71c4bb58a4c54c68241","label":"Importer dossier with ten-year retention","summary":"Your own archive of the notified body certificate, the instructions for use and the EU declaration of conformity, available for ten years and in a language the authority easily understands.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-23-importer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"importer-verification-record-scope","operator":"all","description":"The ten-year term runs from placing on the market or putting into service, and therefore per system and per version, not per supplier relationship."}],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:infringement-report-record","legacy_id":"raip:evidence:infringement-report-record","type":"evidence","slug":"infringement-report-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"50a625473e949463b8ff0fdf84945f303496018e20ea087100884f23b190a777","label":"File of reports about AI systems","summary":"Per report: what was reported, about which system and which version, what was done with it, when feedback was given and who handled it. The deadlines against which that is measured sit in Article 9(1) of Directive (EU) 2019/1937: acknowledgement of receipt within seven days (point (b)) and feedback within three months (point (f)). This file has limits that are as hard as the record keeping itself: the identity of the person reporting stays shielded and does not travel with the substantive follow-up (Article 16), nothing is retained longer than necessary and proportionate (Article 18(1)), and an oral report is recorded only with the consent of the person reporting (Article 18(2) to (4)). Without those limits the file is itself a risk, including under the GDPR.","topics":["evidence","fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-87-reporting-infringements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:legacy-system-transition-register","legacy_id":"raip:evidence:legacy-system-transition-register","type":"evidence","slug":"legacy-system-transition-register","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a0d73b1e9e6d0a528df9b419472895124c96876c96c0da71e972719d4fa96471","label":"Transition register of legacy high-risk systems","summary":"Per type and model: the date the first unit was placed on the market or put into service, the route and therefore the cut off date, whether it is intended to be used by public authorities, which design changes have been made since that cut off, and per change the judgement whether it was significant with the reasoning and the date. This is the file that shows which track a system was on and why.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:notified-body-certificate-record","legacy_id":"raip:evidence:notified-body-certificate-record","type":"evidence","slug":"notified-body-certificate-record","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c345a9067412665954302500530413f4800d28e05a2d8ca20ef76fdf68d7c8c3","label":"Certificate file per system","summary":"Per high-risk system: the certificate itself and the route along which it was issued, the notified body that issued it, its validity period and expiry date, its supplements, the extension requests with the re-assessment underlying them, the assessment per change of whether it was substantial within the meaning of Article 43(4), every decision to suspend, withdraw or restrict together with the reasons the body gave for it, and the notices from the body on cessation or change of its designation with the confirmation that followed.","topics":["conformity","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-44-notified-body-certificates"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:notified-body-standing-record","legacy_id":"raip:evidence:notified-body-standing-record","type":"evidence","slug":"notified-body-standing-record","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"56f9eda5647bd23dbf43d538f9e3e670bb286785ece80df1ce6d64f4aa52eabe","label":"File on the chosen notified body","summary":"Per body: identification number, Member State of establishment, the conformity assessment activities and system types for which it is notified, the date of each check against the public list, the outcome of the independence test, the subcontracted tasks with your written agreement, and every notice of a change to its designation.","topics":["conformity","evidence","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:safety-component-assessment-record","legacy_id":"raip:evidence:safety-component-assessment-record","type":"evidence","slug":"safety-component-assessment-record","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7eb7584bed3094c35599cf257fb614f7c4d6e40f3d5de6380792ceca8654f80d","label":"Record of the safety component assessment","summary":"Per AI component: the intended purpose, the function inside the product, the failure analysis with its consequence for health and safety, the basis of the third-party conformity assessment, and which of paragraphs 1a, 1b and 1c was applied and why. This is a self-maintained file; the Regulation does not prescribe it, and for products under Annex I, Section B, the technical documentation of Article 11 and Annex IV does not apply at all.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:standards-conformity-justification-file","legacy_id":"raip:evidence:standards-conformity-justification-file","type":"evidence","slug":"standards-conformity-justification-file","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"509b7a86a787c973d0cc794e078db8ee608a13d2331d6927de09686dafe11e0d","label":"Coverage matrix and justification for standards and specifications","summary":"Per requirement of Section 2: the harmonised standard or common specification applied with its version, the publication status of the reference in the Official Journal, what the standard or specification does and does not cover, and on departure the Article 41(5) justification with the technical solution chosen and the test showing equivalence.","topics":["conformity","evidence","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:supervisor-mapping-record","legacy_id":"raip:evidence:supervisor-mapping-record","type":"evidence","slug":"supervisor-mapping-record","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"24a0af311c120633523bf2119ca557dd8c2b81b8b4dc8a65fb0733850ca509a4","label":"Record of the competent supervisor per system","summary":"Per AI system: which model underlies it, from which provider, whether model and system come from the same undertaking, whether the system constitutes or is integrated into a designated very large online platform or search engine, which carve-out in paragraph 1 applies if any and which authority follows from it. With a date and with the system version the assessment covers.","topics":["enforcement","evidence"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:systemic-risk-notification-file","legacy_id":"raip:evidence:systemic-risk-notification-file","type":"evidence","slug":"systemic-risk-notification-file","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"905f723bedbd08a93711a9b87bff0a323bc966b6062131c4f19119025d149bc0","label":"Systemic-risk notification file","summary":"Per model version: the measured and planned training compute with the scope of recital 111, so including pre-training, synthetic data generation and fine-tuning, the moment the threshold was reached or foreseen, the notification sent with its supporting information, any arguments under paragraph 2, any reassessment request under paragraph 5, and the response or designation decision of the Commission.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:evidence:value-chain-representative-record","legacy_id":"raip:evidence:value-chain-representative-record","type":"evidence","slug":"value-chain-representative-record","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8a1a79ce12646a7074a1a5732b7048064013029c563b9f5c1601a324b774ad09","label":"Value-chain file","summary":"Record per system of role, contractual arrangements on information and cooperation, and the appointment of a representative where required.","topics":["evidence","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-aanbeveling-wordt-besluit-werving","legacy_id":"raip:example:example-aanbeveling-wordt-besluit-werving","type":"example","slug":"example-aanbeveling-wordt-besluit-werving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"76c172193a9e1982ab1ca28e79c55cb576156277399ac190d1f71f31f91ae4a2","label":"Candidate recommendation that automatically becomes a decision","summary":"An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ai-artikelen-zonder-menselijke-toetsing","legacy_id":"raip:example:example-ai-artikelen-zonder-menselijke-toetsing","type":"example","slug":"example-ai-artikelen-zonder-menselijke-toetsing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d014e1cc526836650d83ff2fb5f9f45b0366948dbe0c220e0e01b0338f8d8679","label":"AI articles on EU policy without substantive review","summary":"A website automatically publishes AI-generated articles about European policy. There is an editorial charter on paper, but nobody reviews the substance. Before publication only a spell check runs, and a second AI model reviews the text.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An editorial charter on paper, a spell check and a second AI model do not count as human review, so without substantive fact checking by a person you must label the publication.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ai-samenvatting-onder-eindredactie","legacy_id":"raip:example:example-ai-samenvatting-onder-eindredactie","type":"example","slug":"example-ai-samenvatting-onder-eindredactie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"faf85ddf4da03b060b2a4a9c932e089f20ebf87c9aac928b0b957cd5e24388ec","label":"AI summary of a council decision under editorial control","summary":"A news site places an AI-generated summary beneath a journalist's article about a recent town council decision. The editor in chief reads the summary on substance, checks the facts and signs off for publication.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Do not rely on the editorial exception without substantive review by a competent person and a publicly identifiable holder of editorial responsibility, and note that any AI intervention after sign-off voids it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ai-speelgoed-riskante-challenges","legacy_id":"raip:example:example-ai-speelgoed-riskante-challenges","type":"example","slug":"example-ai-speelgoed-riskante-challenges","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"17417429ddcc4fb52f722b90b68f84cebbbc8e247fa59b374b35391409d5fabe","label":"AI toy rewards children for dangerous challenges","summary":"A manufacturer markets an AI-powered toy that keeps children engaged by encouraging increasingly risky challenges, such as climbing furniture, exploring high shelves or handling sharp objects, in exchange for digital rewards and virtual praise.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If children are among your users, assess every engagement and reward mechanism separately, because what counts as acceptable stimulation for adults can already be exploitation of children's curiosity and desire for rewards.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-gezichtsherkenning-toegangscontrole","legacy_id":"raip:example:example-artikel-4-gezichtsherkenning-toegangscontrole","type":"example","slug":"example-artikel-4-gezichtsherkenning-toegangscontrole","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"595c5cc236618a40fa4882c79603f0febc9762b4165cdf0ac60b70bdbbe5c457","label":"Facial recognition at access control: the guard behind the camera counts too","summary":"An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) provides that providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. In doing so they must take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, and consider the persons or groups of persons on whom the AI systems are to be used. The same provision states that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read the phrase about the persons on whom the system is used as the centre of gravity for biometrics: whoever stands in front of the camera is subject to the outcome and has little to set against it. That argues for equipping the officer who decides for himself when no match comes back more substantively than the colleague who merely switches the system on and off. The article itself names no sufficient level and expressly states that you need not guarantee one, so where the floor lies for each role stays open. In our assessment a record kept per role, stating the choice made and the reason for it, is easier to defend than one organisation-wide session backed only by an attendance list.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-politie-opsporingsanalyse","legacy_id":"raip:example:example-artikel-4-politie-opsporingsanalyse","type":"example","slug":"example-artikel-4-politie-opsporingsanalyse","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"60ac6751cd1959be17d92f129f223cca3fae064e4dfa4eed6759a8d2f88b5297","label":"Police using AI in investigations: context sets how deep the training goes","summary":"A police force uses AI to search large volumes of investigation files and surface connections a detective would otherwise miss. The outputs feed into the choice of which suspect is pursued further and end up in documents that enter the criminal process. The question is whether one and the same basic instruction is enough for the analyst operating the model and for the detective who acts on its output.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) requires providers and deployers of AI systems to take measures supporting the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The provision prescribes that they take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It also states that this obligation does not require any specific level of AI literacy of any individual to be guaranteed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 4 requires you to weigh the context of use and the people the system is applied to, and in law enforcement both factors run high on our reading. Whether a general introduction to what AI can do is then enough for someone carrying an output into a file that affects a person's position as a suspect, we doubt, but the provision expressly names no level you must guarantee, so that floor is yours to justify. We would record for each role what someone must be able to recognise, for instance that a discovered connection is not yet evidence, and revisit that choice periodically.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-4-redactie-generatieve-content","legacy_id":"raip:example:example-artikel-4-redactie-generatieve-content","type":"example","slug":"example-artikel-4-redactie-generatieve-content","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c17ece0eea8b5b5b7f25d80eb389c31dbc5e18c57449d3e19d41d7ba2b0a8658","label":"Newsroom with generative AI: do freelancers count within your measures?","summary":"A newsroom uses generative AI to prepare summaries, headlines and imagery, after which an editor finishes the piece and the desk decides to publish. Part of that work sits with freelancers, and an outside agency produces marketing content with the same tools. The question is whether your AI literacy measures must reach those freelancers and that agency, or only the people on the payroll.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 4(1) is addressed to providers and deployers of AI systems and requires them to take measures supporting the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The provision requires them to take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, as well as the persons or groups of persons on whom the AI systems are to be used. It does not require any specific level of AI literacy of any individual to be guaranteed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Alongside staff, the text expressly names other persons dealing with the operation and use of AI systems on your behalf, and we read that as a functional boundary rather than a contractual one. On that reading a freelance editor using your tool inside your workflow and on your instruction sits within your measures, employment contract or not. The outside agency is a harder case: if it works in your environment and on your instruction, the argument that it acts on your behalf holds up, but if it runs its own tools on its own account it is a deployer in its own right, and Article 4 does not say your measures must cover that work. In practice, in our assessment, that means recording in your agreements who works in which role and what instruction you give, rather than trusting the other side to arrange it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-ai-chat-sollicitanten","legacy_id":"raip:example:example-artikel-50-ai-chat-sollicitanten","type":"example","slug":"example-artikel-50-ai-chat-sollicitanten","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bbf1f3c5c8847982509ad7a4d086b513a5e0742db0e4415b178f1cdd5cfe1bc2","label":"AI chat in recruitment and selection: what the applicant must be told","summary":"A recruiter deploys an AI chat that puts candidates through a first screening conversation after they respond to a job posting, and adds their answers to their CV. The chat introduces itself with a first name and writes in a casual conversational tone. The question is whether these applicants reasonably realise that they are talking to an AI system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50(1) requires providers to ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. Article 50(5) provides that this information must be given to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction, and must conform to the applicable accessibility requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read the obviousness test as a question about the audience the system actually meets, and in recruitment and selection that audience is not a trained professional group but a broad set of applicants under pressure who do not yet know the organisation. A human first name and a casual tone push that assessment the wrong way in our view, however well they convert. If you buy the chat rather than build it, Article 50(1) is by its wording addressed to the provider, while you are the one choosing the persona and the entry point; whether putting your own name on such a chat moves you into the provider role is a question Article 50 does not answer. So make the disclosure in the first message a procurement requirement and verify at delivery that it is genuinely there.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-camera-toegangscontrole-categorisatie","legacy_id":"raip:example:example-artikel-50-camera-toegangscontrole-categorisatie","type":"example","slug":"example-artikel-50-camera-toegangscontrole-categorisatie","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"160b7164fde8818b8b2563f5a2e755e5669228072717a49f653bf2ca4c75bee6","label":"Camera at the entrance: access control versus biometric categorisation","summary":"An organisation admits staff through facial recognition at its access control gate and additionally runs a camera in the visitor area that sorts faces into age groups. Both applications run on the same biometric infrastructure and the same images. The question is which of the two requires the people involved to be actively informed.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 count automated facial-recognition access controls among the systems that merely collect data passively and are not capable of an exchange with natural persons, and therefore do not interact within the meaning of Article 50(1). For Article 50(3) they state that, unless the use is prohibited under Article 5(1)(g), the information duty applies to any biometric categorisation system, including outside the high-risk scope, and they give classification by age or gender on the basis of biometric data as an example. Article 50(3) itself carries a further exception for systems permitted by law to detect, prevent or investigate criminal offences. As a way of informing people the guidelines describe a visible notice at each possible entrance to an exhibition room stating that facial images are captured to assign visitors to an age group, provided at the latest at the moment of first exposure.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (30) and points (104) to (108)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that you should map this per processing purpose rather than per camera: the same lens that stays outside Article 50(1) at the access control gate moves inside Article 50(3) as soon as those images place people in a category. Record for each setup what happens to the capture and who the deployer is, because that decides whether a notice belongs at the entrance. The guidelines prescribe no fixed form, but they do fix the moment: the notice has to be there before someone walks into frame, and a line in the privacy statement rarely makes that moment, in our reading.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (30) and points (104) to (108)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-code-assistent","legacy_id":"raip:example:example-artikel-50-code-assistent","type":"example","slug":"example-artikel-50-code-assistent","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fe318cc5831d962473121e1af68d1c399dd3a01e1b3bd89e04d554385ee6a460","label":"Code assistant for developers: an exception, until it faces outward","summary":"A software company uses an AI assistant for code suggestions and code review, available only to professional developers. The same company also runs a helpdesk chatbot for customers.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list code assistance and code review chatbots available only to professional developers as an example where the obviousness exception applies. Chatbots embedded in online platforms or helpdesks, where users may perceive outputs as human-generated, they list as an example where the disclosure duty does apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two AI assistants at the same company, two outcomes. Assess per application who the user is and what they reasonably expect, rather than taking one organisation-wide position on chatbots.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-fraudemeldportaal-bank","legacy_id":"raip:example:example-artikel-50-fraudemeldportaal-bank","type":"example","slug":"example-artikel-50-fraudemeldportaal-bank","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"582aea2e3144049ca4f842c782162a26e0e60300ad221f75347d55f99d05a125","label":"Fraud reporting portal at a bank: why the law enforcement exception drops out","summary":"A bank opens an AI-driven reporting portal where customers can flag suspected fraud around their payment account or loan. The system asks follow-up questions, categorises the report and routes it to fraud detection and, where money laundering signals appear, to the internal reporting team. Because the portal concerns criminal offences, the bank assumes the disclosure duty for direct AI interaction does not apply.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 expressly list AI-assisted fraud reporting hotlines and digital portals operated by financial institutions or public authorities, where users can report suspected financial crimes, as an example that is not exempted and falls within the scope of Article 50(1). They explain that the exception does not apply where the system is available to the public and offers individuals the functionality to report a criminal offence. The fact that the system only gathers details, categorises and prioritises the report while human investigators validate the information before any action is taken does not change that in the guidelines.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, points (48) and (49), list of examples under the law enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In our reading this is where banks most often take the wrong turn: the reporting portal sits organisationally under fraud and compliance, which makes the law enforcement exception feel natural, while it is precisely the public reporting channel that is carved out of that exception. On top of that, the exception is written for use authorised by law for law enforcement purposes, and the guidelines stretch it no further than to other public authorities holding such a legal basis, so in our reading a private bank rarely stands in it at all, before the public reporting channel even comes up. Treat the portal as an ordinary public-facing chat and put the disclosure in the first screen of the conversation. A line in the terms and conditions or a product leaflet is a weak choice for this channel, because by then the person is already telling their story.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, points (48) and (49), list of examples under the law enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-gemeentelijke-ai-tekst","legacy_id":"raip:example:example-artikel-50-gemeentelijke-ai-tekst","type":"example","slug":"example-artikel-50-gemeentelijke-ai-tekst","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"607ccc8ecea80ab82aa178e5832f9ad99914406b4a757935b3aabb504f27a676","label":"AI text from a municipality: when a final check counts as editorial control","summary":"A municipality has an AI system write the web pages about a changed scheme for social assistance and allowances, meant to explain to citizens what they are entitled to. A communications officer reads the text for style and spelling and publishes it. The question is whether this public service thereby falls under the exception to the labelling duty.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 count public administration and public services among the matters of public interest covered by the disclosure duty for published AI text in Article 50(4). For the exception, the guidelines require two cumulative conditions: the AI-generated or manipulated text has undergone human review or editorial control, and a natural or legal person holds editorial responsibility for the publication. They add that human review means a deliberate examination of the substance with fact-checking as a minimum requirement, and that superficial, purely formal or procedural checks such as spell-checking or grammatical correction do not meet it. For the second condition they expect the identity or the function carrying editorial responsibility to be publicly available in an easily findable place.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (131), points (133) to (136) and point (138)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that many municipalities do have a publication process but no identifiable person carrying substantive final responsibility, and that is exactly the hinge of this exception. Assign that role explicitly, make it findable who holds it, and record per page who checked the facts, or otherwise take the simpler route and label the text. Watch the order of steps in your workflow, because an AI tool that substantively rewrites the text after human sign-off removes the ground from under that sign-off.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, point (131), points (133) to (136) and point (138)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-interne-medewerkersassistent","legacy_id":"raip:example:example-artikel-50-interne-medewerkersassistent","type":"example","slug":"example-artikel-50-interne-medewerkersassistent","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fa7779195063a2d6c102ecd9efa1d0962397eab18f9e9a1016737e97d85efc17","label":"Internal assistant for HR and compliance: an exception with a condition","summary":"An organisation gives staff an internal AI assistant for HR, legal, procurement, compliance and IT questions. Must that assistant disclose at every turn that it is AI?","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list an internal employee-facing assistant for properly trained, AI-literate staff who are aware they are using AI systems for internal organisational purposes as an example where the obviousness exception in Article 50(1) applies.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The guidelines tie this exception explicitly to properly trained, AI-literate staff. Relying on it therefore stands or falls with what you have arranged and can demonstrate on literacy under Article 4: without that record you are leaning on an assumption about your own people.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-klinisch-beslissysteem","legacy_id":"raip:example:example-artikel-50-klinisch-beslissysteem","type":"example","slug":"example-artikel-50-klinisch-beslissysteem","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"373ac7240ce91407219c0e1aa4125e839d59caee1738579bab6fc375dfa28564","label":"Diagnostic support for clinicians: no disclosure duty, still due care","summary":"A hospital deploys an interactive AI system used exclusively by properly trained health professionals to support medical diagnosis and suggest treatments. The question is whether the patient or the clinician must be told it is AI.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 list interactive AI systems intended only for properly trained health professionals to support medical diagnosis and suggest treatments as an example where the obviousness exception in Article 50(1) applies: for that user the AI nature is clear.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception attaches to the user, not to the system. The moment the same model also speaks to patients, that ground falls away and the disclosure duty applies as normal. And an exception to Article 50 says nothing about the rest: where it is a medical device or a high-risk application, those regimes continue to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-artikel-50-opsporing-uitzondering","legacy_id":"raip:example:example-artikel-50-opsporing-uitzondering","type":"example","slug":"example-artikel-50-opsporing-uitzondering","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f22913de6679b4a1f4549e5f0135681758c39a74b7ce0d57e99aab9ee6bb2603","label":"Law enforcement: exempt from the disclosure duty, with safeguards","summary":"An authority empowered by law to detect criminal offences wants to deploy an interactive AI system without telling those involved that they are communicating with AI.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50(1) exempts providers of interactive AI systems from the disclosure duty where they are authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties. The Commission guidelines of 20 July 2026 elaborate that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (46), law-enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception is narrow and conditional: it requires a legal basis for the law-enforcement task and appropriate safeguards for third parties. A public task by itself is not enough, and the safeguards are not a footnote but part of the ground you are relying on.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (46), law-enforcement exception","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-asimov-inductiecall-bij-klant","legacy_id":"raip:example:example-asimov-inductiecall-bij-klant","type":"example","slug":"example-asimov-inductiecall-bij-klant","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f286cb7f01499108c016b693b60666dcccbcc56e8e2d03b8d3dbe2f3213034c5","label":"An induction call with the customer at the moment of go-live","summary":"Asimov AI is a micro organisation of at most fifteen people that supplies AI services for legislative work to government institutions and companies. With every new contract it holds one or more induction calls with the team leads and officials who will use the platform, explaining how the platform and the underlying models work and how hallucinations arise in this domain and can be mitigated.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This practice puts literacy where the risk arises: with the people who will operate the system, at the moment they start. For a small provider that is also the only workable moment, because there is no training department to redo it later. Anyone adopting it should record who attended and what was explained, because otherwise the effort survives only in the participants memory a year on.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-beoordelingssysteem-personeel-incidentmelding","legacy_id":"raip:example:example-beoordelingssysteem-personeel-incidentmelding","type":"example","slug":"example-beoordelingssysteem-personeel-incidentmelding","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"10323fa9be53a342a148727da06c2c2e2326f11f0d1102e4586b4686a08f6df9","label":"Performance scoring for staff goes wrong: report or not","summary":"An employer uses an AI system that scores employee performance and lets that score weigh in promotion and dismissal. After a change to the model it turns out that a group of staff was scored too low for months, and decisions have already been taken on those scores. HR wonders whether this is a serious incident and who would have to report it.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) places the duty to report serious incidents on the provider of the high-risk AI system placed on the Union market, towards the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident, with the period taking account of the severity of the incident. Article 73(6) obliges the provider, after reporting, to perform the necessary investigations without delay in relation to the serious incident and the AI system concerned, including a risk assessment and corrective action, cooperating with the competent authorities and, where relevant, with the notified body concerned. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In the workplace the hard part is the awareness trigger in Article 73(2): harm spread thinly across many employees does not arrive as an alarm but trickles in through complaints, a performance review or the works council. Whether systematically low scores that feed into promotion and dismissal amount to a serious incident depends, on our reading, on whether obligations protecting fundamental rights have thereby been infringed within the meaning of Article 3, point (49)(c); Article 73 does not make that assessment for you. Decide in advance which HR signal counts as an incident signal and who puts it in front of the provider that same week, rather than reconstructing that afterwards; Article 26(5) also requires you as deployer, once you have identified a serious incident, to inform the provider immediately and then the importer or distributor and the market surveillance authority. Note finally that the corrective action in Article 73(6) concerns the system; what should happen to promotion or dismissal decisions already taken is, on our reading, not answered by this article and runs through other rules, employment law among them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-biometrische-categorisering-politieke-voorkeur","legacy_id":"raip:example:example-biometrische-categorisering-politieke-voorkeur","type":"example","slug":"example-biometrische-categorisering-politieke-voorkeur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9d8a700ae5aad549ff10ecf2a1cdbea0dfa44d026ea66f260dfd2de85b541041","label":"Inferring political opinions from uploaded photos","summary":"A platform analyses the biometric data in photos users have uploaded to infer their assumed political orientation and serve them targeted political messages. A comparable system infers assumed sexual orientation in order to serve advertisements.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Relying on the ancillary feature exception requires that the feature is also strictly necessary for objective technical reasons alongside the main service, since both conditions apply cumulatively and advertising purposes do not meet that bar.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-biometrische-verificatie-grenspoort","legacy_id":"raip:example:example-biometrische-verificatie-grenspoort","type":"example","slug":"example-biometrische-verificatie-grenspoort","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2f0da23dce88ea57a597d35e2ab6c9bbf07dbbf6bbc17182bbb2203a51e218c","label":"Face comparison at the border gate: verification or identification","summary":"An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that biometric verification falls outside the high-risk classification: one-to-one comparison of presented biometrics with previously stored biometrics, for the sole purpose of confirming that a person is who they claim to be. Where the same capture is additionally compared against a law-enforcement database, it does become remote biometric identification. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Test your biometric application on purpose rather than technology: the same camera and the same model stay outside the high-risk route as long as the comparison is one-to-one and only confirms identity, and fall inside it as soon as that same capture is also held against a database. Record per application what the comparison runs against, because that single design choice moves the entire regime.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-booking-training-voor-juristen","legacy_id":"raip:example:example-booking-training-voor-juristen","type":"example","slug":"example-booking-training-voor-juristen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"41c8d4bfbefc3c65e18a409d9db002667c9a06313ff1bea1d6ecc22c34120a4e","label":"A three-part training for legal and public affairs staff","summary":"Booking.com built a three-part training for its legal and public affairs teams: first basic terminology and the difference between classic machine learning and language models, then how AI works inside the company, then the regulatory landscape and where it meets the law they already practise. The material was also released as a video and podcast series with subtitles and written handouts.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The sequence is the interesting part: first the technology, then the organisation itself, and only then the law. Lawyers who reverse that order memorise the Regulation without being able to judge where their own systems land. That the training exists in several formats also helps to show it was genuinely reachable for everyone who needed it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-callcenter-emotieherkenning-medewerkers","legacy_id":"raip:example:example-callcenter-emotieherkenning-medewerkers","type":"example","slug":"example-callcenter-emotieherkenning-medewerkers","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bd45128b99b8e9d810b8fd9593c5607ee29625f2ab7ac72058009f78b0e435f","label":"Call centre measures employees' anger","summary":"A call centre uses webcams and voice recognition to track employees' emotions, such as anger. The same company also uses voice analysis to detect when a customer becomes irritated.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The prohibition follows the relationship of authority rather than the technique: the same voice analysis is prohibited on employees but not on customers, and workplace also covers applicants and probation periods.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-cv-filter-rangschikt-sollicitanten","legacy_id":"raip:example:example-cv-filter-rangschikt-sollicitanten","type":"example","slug":"example-cv-filter-rangschikt-sollicitanten","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"87a6edde2fbb05ea364a21df1cabd13ede28c3f040f86e881d341010e280fe76","label":"A CV filter that ranks applicants","summary":"An employer has an external recruitment system score and rank every incoming application, after which recruiters only review the top twenty percent by hand. The vendor puts the system on the market under its own name, and the employer uses it in its own selection process.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Recruiters keeping the final say does not help you, because once the system scores or ranks applicants and thereby shapes the shortlist it stays high-risk and no exemption applies.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-databasequery-en-standaard-spreadsheet","legacy_id":"raip:example:example-databasequery-en-standaard-spreadsheet","type":"example","slug":"example-databasequery-en-standaard-spreadsheet","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dd645d7a2f830db1183793533874510925d883c1e644a6116f5d9f9234b4a52e","label":"Database query and standard spreadsheet without AI features","summary":"A customer service department runs a database query to find all customers who purchased a specific product last month, and calculates the average from a satisfaction survey in a standard spreadsheet. Every step follows predefined instructions.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If you rely on the basic data processing category, look at the whole lifecycle rather than the use phase alone, because that category assumes no learning, reasoning or modelling at any stage.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-dedalus-gekruiste-training","legacy_id":"raip:example:example-dedalus-gekruiste-training","type":"example","slug":"example-dedalus-gekruiste-training","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1e2abda43783d7283bcef7fb1b20f9040362ecc96c1e659890af2ce1172acec3","label":"Lawyers learn the technology, developers learn the law","summary":"Dedalus Healthcare, which among other things supplies AI that predicts complications for hospital patients, trains its legal staff, data protection officer, compliance function and quality and regulatory affairs department on the technical side. Developers and engineers conversely receive training focused on the legal and compliance aspects of the AI Act. The executive committee received its own session tailored to its role.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Look for knowledge deliberately outside a single discipline, because the repository names collaboration between industry and academia as one of the ways organisations build AI literacy.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-deepfake-op-een-kerstkaart","legacy_id":"raip:example:example-deepfake-op-een-kerstkaart","type":"example","slug":"example-deepfake-op-een-kerstkaart","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e0d27a9440616cc90519896867e55940ffd8a6ef8df0f90dbaff02550d1c2a9","label":"Deep fake on a Christmas card: the provider marks, the private person does not","summary":"A private individual uses a generative AI service to create a deep fake of themselves and their household for their own Christmas card, purely personal and with no business purpose.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The personal-use exclusion touches only the user duties, so if you supply the generative service you still mark outputs machine-readably, and any professional purpose brings the labelling duty back.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-echt-product-tegen-ai-achtergrond","legacy_id":"raip:example:example-echt-product-tegen-ai-achtergrond","type":"example","slug":"example-echt-product-tegen-ai-achtergrond","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c3ce2a3a371aeae06bc60f3e5af245b03d50cc3a0991d0e464b5770649477776","label":"A real car against an AI background is not a deep fake","summary":"A car company photographs an existing model and places it in an advertisement against a fully AI-generated background with an invented landscape. The car itself is untouched.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The leeway hangs on the product itself, so an AI background is fine as long as appearance, characteristics and use stay unchanged, but once the editing touches the product, labelling returns.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-emotieherkenning-medische-uitzondering","legacy_id":"raip:example:example-emotieherkenning-medische-uitzondering","type":"example","slug":"example-emotieherkenning-medische-uitzondering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ccd6925b46bde2fbd643a40f0543e621533e20aa476621cf18ddbe4a8283361e","label":"Medical exception: accessibility yes, burnout detection no","summary":"An employer wants to deploy emotion recognition. In one scenario the system assists employees with autism and improves accessibility for blind and deaf colleagues. In the other it measures stress levels to flag burnout, boredom or loss of motivation.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The medical exception is narrow: supporting a specific impairment qualifies, general monitoring of wellbeing, stress or motivation does not, and data gathered under a permitted use may not be reused for other purposes.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ernstig-incident-productielijn-meldtermijn","legacy_id":"raip:example:example-ernstig-incident-productielijn-meldtermijn","type":"example","slug":"example-ernstig-incident-productielijn-meldtermijn","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ebe7b7020fc00e471f22844f0b97ed3e30f6702e78b04c376cd86720ec3d51bd","label":"Serious incident on the production line: who reports and within what deadline","summary":"A manufacturer supplies an AI system that runs as a safety component in a machine on the production line and at the same time drives quality control. At a customer's factory an operator is seriously injured after the machine failed to stop on an anomaly. The question is who reports, to whom, and which clock is already running at that moment.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 73(1) places the reporting of serious incidents on the provider of the high-risk AI system placed on the Union market, addressed to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires that report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the incident, with the reporting period taking account of the severity of the incident. Article 73(4) shortens that to no later than 10 days in the event of the death of a person. Article 73(6) obliges the provider, following the report, to perform the necessary investigations without delay, including a risk assessment and corrective action, and not to perform any investigation involving alteration of the AI system in a way that may affect the subsequent evaluation of the causes of the incident without first informing the competent authorities. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities, and makes Article 73 apply mutatis mutandis where the deployer cannot reach the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1), (2), (4) and (6), and Article 26(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 73(2) as meaning that the clock can already start at the deployer on the factory floor, while the report under Article 73(1) sits with you as the provider of the AI system. That does not leave your customer free to sit still: Article 26(5) gives the deployer a notification route of its own, running past you, the importer or distributor and the market surveillance authority, and makes Article 73 apply mutatis mutandis if you cannot be reached. Fix that route in the contract and in the service line before anything happens. Where an operator is seriously injured but does not die, we read the outer limit of Article 73(2) as the one in play rather than the 10 days of Article 73(4); how much sooner than that outer limit you must report is left open by the text and turns on severity. Bear in mind as well that the reflex to repair the machine immediately and resume production can collide with Article 73(6), because an investigation that alters the system first requires notice to the competent authority. Working that out only during the incident costs days that these deadlines do not allow.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1), (2), (4) and (6), and Article 26(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-expertsysteem-medische-diagnose","legacy_id":"raip:example:example-expertsysteem-medische-diagnose","type":"example","slug":"example-expertsysteem-medische-diagnose","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"11a57563ce0ce4036678d8a24528721e2ed2bdcb86387dfce6e86edbfbfd9d38","label":"Expert system that draws a conclusion from encoded knowledge","summary":"A hospital uses an older diagnostic support expert system in which physicians encoded knowledge, facts and rules. Based on the symptoms a doctor enters, the system independently draws a conclusion about possible conditions.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Machine learning is not a requirement, so you cannot argue that your system merely applies rules encoded by experts; logic and knowledge based systems that draw conclusions on their own are covered too.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fastweb-ai-spoc-per-afdeling","legacy_id":"raip:example:example-fastweb-ai-spoc-per-afdeling","type":"example","slug":"example-fastweb-ai-spoc-per-afdeling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"82d13410b61ae9a20785297bc71e236bd3444822d904f2131c50a00d2d69a71b","label":"A trained AI contact person in every department at a telecom company","summary":"Fastweb operates more than ninety AI systems and formally appoints an AI-SPOC in every department, a trained point of contact for AI questions from that team. These people receive separate instruction on prohibited practices and high-risk systems and are allowed to run their department's AI risk assessment themselves.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Do not copy a practice from this repository as is, since the Commission states that replication grants no automatic presumption of compliance; first test whether the setup fits your own systems and roles.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-finetunen-boven-de-compute-drempel","legacy_id":"raip:example:example-finetunen-boven-de-compute-drempel","type":"example","slug":"example-finetunen-boven-de-compute-drempel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"19885d3f717598c8a1aee1069d8562064fc5cf9be2478635082ec52171301dd6","label":"Heavy fine-tuning makes you the model provider","summary":"A European scale-up fine-tunes an existing general-purpose AI model for its own product, using more compute than one third of the compute used to train the original model.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Estimate your fine-tuning compute against the original model before you start, because exceeding one third of it makes you the provider, with documentation, copyright and training-content duties limited to your modification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fiscale-misdrijven-voorspellen-uit-profiel","legacy_id":"raip:example:example-fiscale-misdrijven-voorspellen-uit-profiel","type":"example","slug":"example-fiscale-misdrijven-voorspellen-uit-profiel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2641f027fba48853241130e6beec9799f7ca4a356031923e8a0613507d739cb2","label":"Screening tax returns for criminal offences on a profile alone","summary":"A tax authority runs a predictive AI tool over all tax returns to flag potential criminal tax offences. This is done solely on the profile built by the system, using personality traits such as dual nationality, place of birth and number of children, together with inferred variables that are hard to verify.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"To stay outside this prohibition a system must rest on real, verifiable facts directly linked to a specific criminal activity, since simply adding further variables to a profile is not enough.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fraudeprofilering-kinderopvangtoeslag","legacy_id":"raip:example:example-fraudeprofilering-kinderopvangtoeslag","type":"example","slug":"example-fraudeprofilering-kinderopvangtoeslag","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e14fd1327b3176580476a891b9220ebf561cddc3fe18cb8d536a516c383edb02","label":"Fraud profiling in childcare benefits","summary":"A tax authority uses an AI system to detect childcare benefit fraud by profiling beneficiaries and assigning them to categories such as deliberate intent or gross negligence, using criteria such as low income, dual nationality and social behaviour. Based on the risk score, files are inspected, benefits are stopped and repayment is demanded.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Fraud detection remains legitimate, but check for each variable whether it genuinely belongs to the purpose and whether the consequence is proportionate, since unrelated personal characteristics plus severe consequences turn a control into social scoring.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-bijstandsuitkering-gemeente","legacy_id":"raip:example:example-fria-bijstandsuitkering-gemeente","type":"example","slug":"example-fria-bijstandsuitkering-gemeente","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"563700f6a56bbda6f2fd701e38b2eeb9df22a2523f7612fe1109c68a791ffe42","label":"Awarding social assistance in a municipality: the FRIA and the notification","summary":"A municipality wants to deploy an AI system that sorts applications for social assistance benefits and indicates which files merit extra scrutiny before a case worker decides. The application is already listed in the public algorithm register. The question is what has to be in place before the first citizen passes through this system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) requires deployers which are bodies governed by public law, or private entities providing public services, to perform an assessment of the impact on fundamental rights that the use of a high-risk AI system referred to in Article 6(2) may produce, prior to deploying it, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment covers, among other elements, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the implementation of human oversight measures, and the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(3) provides that once the assessment has been performed, the deployer shall notify the market surveillance authority of its results and submit the filled-out template referred to in paragraph 5 as part of that notification, and that in the case referred to in Article 46(1) deployers may be exempt from that obligation to notify. Article 27(5) provides that the AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (3) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as making the municipality the most obvious deployer here, and as requiring the assessment to be complete before the first application runs through the system, not as an account rendered afterwards. That duty does depend first on whether this system is high-risk at all: does it help decide entitlement to social assistance, or does it stay within a preparatory or narrowly procedural task under Article 6(3), which closes its own exception again once the system profiles citizens? Answer that question before you start on paragraph 1. An entry in the public algorithm register is on our reading something different from the assessment under paragraph 1, and it does not replace notifying the market surveillance authority of the results. In practice it pays to record the citizen's complaint route and the case worker's room to depart from the signal in the same file, because paragraph 1 asks for precisely those two elements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (3) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-recidiverisico-politie","legacy_id":"raip:example:example-fria-recidiverisico-politie","type":"example","slug":"example-fria-recidiverisico-politie","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3136fdfa784bcee684810eafa3fc784e9ff1905adf38d86767b1e6daed7c37da","label":"Recidivism scoring in police work: when the assessment must be redone","summary":"A police service deploys an AI system that estimates the recidivism risk of a suspect, as an aid to the judgements later made by the prosecution service and the court. The model is subsequently retrained on newer investigative data and use is extended to a second region. The question is whether the assessment made for first use remains adequate.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) requires deployers which are bodies governed by public law to perform, prior to deploying a high-risk AI system referred to in Article 6(2), an assessment of the impact on fundamental rights that its use may produce, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the processes in which the system will be used, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm taking into account the information given by the provider pursuant to Article 13, of the implementation of human oversight measures according to the instructions for use, and of the measures to be taken if those risks materialise. Article 27(2) provides that the obligation applies to the first use, that previously conducted impact assessments or existing assessments carried out by the provider may be relied on in similar cases, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(3) provides that the results are notified to the market surveillance authority together with the filled-out template, and that in the case referred to in Article 46(1) an exemption from that notification duty may apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as covering a police service as a body governed by public law under paragraph 1, and as an assessment that does not stop at first use: retraining on newer investigative data or extending use to a second region touches the elements of paragraph 1 and, on our reading, calls for updating the record. That retraining also raises a question Article 27 itself does not answer, namely whether the change goes far enough to count as a substantial modification, which would make you a provider in your own right under Article 25. Bear in mind as well that the exception in paragraph 3 concerns, on our reading, the notification and not the assessment itself. Finally, start that assessment only after establishing that the deployment as such is permitted, because Article 5 rules out certain predictive applications in criminal investigation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-selectie-inschrijving-hogeschool","legacy_id":"raip:example:example-fria-selectie-inschrijving-hogeschool","type":"example","slug":"example-fria-selectie-inschrijving-hogeschool","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81f378ec11bfd5271d13fa170d8d63f220e78317143a657af062421c1512c069","label":"Selection at student admission: a DPIA is not yet a FRIA","summary":"A university of applied sciences has an AI system rank applications for a vocational programme, using the exam results of earlier students to calibrate that ranking. A data protection impact assessment already exists for this processing. The question the school asks is whether that also covers the fundamental rights side of admission.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 27(1) provides that deployers which are bodies governed by public law, or private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the deployer's processes in which the system will be used in line with its intended purpose, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm to those categories, of the implementation of human oversight measures, and of the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(2) provides that the obligation applies to the first use, that the deployer may in similar cases rely on previously conducted impact assessments or existing assessments carried out by the provider, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(4) provides that where an obligation under this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the assessment under paragraph 1 complements that data protection impact assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 27 as placing the education institution that runs this selection itself in the deployer role, but that alone does not settle the duty. Paragraph 1 names bodies governed by public law and private entities providing public services, and whether a state-funded or a private university of applied sciences answers to either description is the question you have to settle first. If it does, an existing data protection impact assessment is on our reading the starting point rather than the last word: paragraph 4 has the fundamental rights assessment sit alongside it, and since Regulation (EU) 2026/1744 that assessment may incorporate or cross-refer to relevant parts of it, so the real question is which elements of paragraph 1 are still missing. For you that means recording which groups of students may be affected, how the admissions committee or the teacher can correct an outcome, and where a rejected applicant can lodge a complaint. If the selection rule or the assessment component underpinning the ranking changes, that is on our reading the moment to update the record, rather than the start of the next academic year.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fria-zorgverzekeraar-risicobeoordeling","legacy_id":"raip:example:example-fria-zorgverzekeraar-risicobeoordeling","type":"example","slug":"example-fria-zorgverzekeraar-risicobeoordeling","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da4c33f856bb8621e0a1ecad5647b97f9511b86d1c9cc729d555166238398e7e","label":"Health insurer using AI for risk assessment: public or private makes no difference","summary":"A health insurer uses AI for risk assessment and pricing of health and life insurance. The question is whether this falls under point 5(c) of Annex III, and with that whether the Article 27 FRIA duty comes into play.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that the health and life insurance in point 5(c) may be offered on a private or a public basis: a health insurer governed by public law also falls within it, so long as the system is intended for risk assessment or pricing with regard to natural persons. Privately serviced health insurance counts as an essential private service, even in a Member State with a public healthcare system. Unlike point 5(b), point 5(c) provides no exception for fraud detection. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For the FRIA question point 5(c) counts twice: it makes the system high-risk and it makes you, as deployer, one of the parties Article 27 names. A public-law form or a public healthcare system in your Member State changes nothing there. Do not count on the fraud-detection exception from point 5(b) either: it does not apply here, and a fraud feature alongside risk assessment does not take the system out.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-fysicasimulatie-met-ml-versnelling","legacy_id":"raip:example:example-fysicasimulatie-met-ml-versnelling","type":"example","slug":"example-fysicasimulatie-met-ml-versnelling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fd65201978e0fb6b88a6604f62c5e0f0731358ce5fd8bcd66fa88bb26de4beb5","label":"Weather simulation where machine learning approximates physical processes","summary":"A meteorological institute runs physics based weather models and uses machine learning to approximate complex atmospheric processes such as cloud microphysics and turbulence. The estimated values are then fed into the established physics model, which produces the actual forecast.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"That your model can infer from input does not by itself bring it within the definition, since the guidelines justify excluding such accelerating systems precisely because they do not transcend basic data processing.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-gemiddelde-als-voorspelling-benchmark","legacy_id":"raip:example:example-gemiddelde-als-voorspelling-benchmark","type":"example","slug":"example-gemiddelde-als-voorspelling-benchmark","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"05e0f1687969ccded7daf22e1dacead75dc5b5c612cf355161b79738c6d7c6f2","label":"The historical average used as a prediction","summary":"An asset manager builds a simple baseline model that predicts future prices by always taking the historical average, in order to test whether a more advanced model genuinely adds value. A weather service does the same by predicting tomorrow's temperature using last week's average.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A simple baseline you place alongside a more advanced model falls outside the definition on its performance, but that verdict says nothing about the advanced model, which you must assess separately.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-generali-drie-kennisniveaus","legacy_id":"raip:example:example-generali-drie-kennisniveaus","type":"example","slug":"example-generali-drie-kennisniveaus","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fdbb4f9deed858006b652b2cdf7cbf02c6731d9abe4016d07cc6335d40415d5a","label":"Three knowledge levels and internal role academies at an insurer","summary":"Generali offers all staff basic courses on what AI is and how the group uses it, intermediate modules for people who use AI systems daily, and advanced sessions with external experts for those who build or maintain them. On top of that it runs internal role academies for data scientists, actuaries and accountants, set up with universities and research institutes.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Attach layered AI training to an existing upskilling programme and learning platform, so you can extend levels and audiences without having to build a new learning infrastructure first.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-gepersonaliseerde-reclame-geen-verboden-manipulatie","legacy_id":"raip:example:example-gepersonaliseerde-reclame-geen-verboden-manipulatie","type":"example","slug":"example-gepersonaliseerde-reclame-geen-verboden-manipulatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c7671bfcaeb60bffc15c6fce2ddaa53aedae358d58d540960dcf806a0a8f47dd","label":"Personalised advertising is not automatically prohibited manipulation","summary":"An advertiser uses AI to tailor ads to user preferences. The question is whether that touches the manipulation prohibition.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Personalisation stays outside the prohibition as long as it is transparent and respects free choice, so test your advertising technique against the GDPR, consumer law and the DSA rather than assuming advertising is always allowed.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-gezichtsdatabank-scrapen-sociale-media","legacy_id":"raip:example:example-gezichtsdatabank-scrapen-sociale-media","type":"example","slug":"example-gezichtsdatabank-scrapen-sociale-media","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8497b54890fab6eedf211f9cebfe1715a0a0d59604e7035b5bedd049ba180874","label":"Facial recognition company builds a database from social media","summary":"A software company runs an automated image scraper across the internet to detect images containing human faces on social media, stores them with source URL, geolocation and sometimes names, and converts the facial features into mathematical representations against which an uploaded photo can be matched.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Images published publicly on social media do not amount to consent, and the decisive point is targeting: untargeted collection for a database capable of matching faces stays prohibited even when done step by step.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-gjensidige-onboarding-en-werving","legacy_id":"raip:example:example-gjensidige-onboarding-en-werving","type":"example","slug":"example-gjensidige-onboarding-en-werving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"559b2c97a4ed1f6d1dc5c429a0059b1d856c6f66443c4d87dfa3367f6068066e","label":"AI literacy in recruitment and onboarding at an insurer","summary":"Gjensidige Forsikring gives all employees a mandatory e-learning as a baseline and builds role-based depth on top: analysts get model risk and data governance, claims handlers get training on the systems they operate themselves. Where relevant, AI literacy is checked during recruitment and training on AI systems is part of onboarding.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Decide whom you train using the wording the document quotes: Article 4 names your own staff as well as anyone using the systems on your behalf.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-helpdesk-chatbot-meldt-zichzelf","legacy_id":"raip:example:example-helpdesk-chatbot-meldt-zichzelf","type":"example","slug":"example-helpdesk-chatbot-meldt-zichzelf","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a6e0b0363b8a214845ebb212cc55ac10addd98da4630115b562bf06d1cf839a4","label":"A webshop helpdesk chatbot must announce itself","summary":"A webshop runs an AI chatbot for questions about orders, delivery and returns. The bot writes fluent prose, carries a staff profile picture, and nowhere does it say that no human is reading along.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Do not count on the obviousness exception, because the more human your customer-facing bot looks, the more you must disclose its artificial nature at the first turn rather than only in the terms.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-admission-file-handling","legacy_id":"raip:example:example-high-risk-admission-file-handling","type":"example","slug":"example-high-risk-admission-file-handling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d93ca41a9674f908ba4a52cb54514b06a83f6a49d7b488bc35837abc89e797d","label":"Application file handling at an educational institution","summary":"An educational institution uses AI for application file handling: indexing, searching, text and speech processing, translation of documents submitted with applications, and extracting, transforming and organising the collected data into a usable format.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Indexing, searching, translating and reorganising application files remains preparatory work, as long as the system leaves the substantive judgment on the application entirely to the institution.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-agriculture-chemical-spraying-targeting","legacy_id":"raip:example:example-high-risk-agriculture-chemical-spraying-targeting","type":"example","slug":"example-high-risk-agriculture-chemical-spraying-targeting","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b320365843ff4ea17b6d2ae82a6dad0a4b7659ed17e50087da6253379e488368","label":"Agriculture: AI system targeting land areas for chemical spraying","summary":"An AI system determines which areas of agricultural land are sprayed with chemicals. The intended purpose given to it by the provider is optimising the use of chemicals.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Do not limit your failure analysis to the product itself but include the environment in which it operates, because people nearby help determine whether a malfunction creates danger.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-agriculture-yield-forecasting-irrigation","legacy_id":"raip:example:example-high-risk-agriculture-yield-forecasting-irrigation","type":"example","slug":"example-high-risk-agriculture-yield-forecasting-irrigation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"34a7162c1636024787596e5ec40ba03597c03f35bc5158d4a5feea44c8d07fc3","label":"Agriculture: AI for yield forecasting and irrigation optimisation","summary":"An AI system is integrated into a drone or robot and used for agronomic purposes such as yield forecasting or irrigation optimisation.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Record per application why a malfunction in your setup creates no danger, because the same agronomic function can become a safety component in a different product design.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-ai-proposing-substantially-different-solution","legacy_id":"raip:example:example-high-risk-ai-proposing-substantially-different-solution","type":"example","slug":"example-high-risk-ai-proposing-substantially-different-solution","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7baae084acee37edf9d0aab85faa1df824d25499cf71e1697179d196be612e32","label":"System that checks a human decision or design and provides a substantially different solution","summary":"An AI system checks a decision, plan or construction made by a human and then provides a substantially different solution.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Ask whether your system refines or replaces the human work, because delivering a substantially different solution is not an improvement and rules out reliance on Article 6(3)(b).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-aml-detection-by-accounting-firm","legacy_id":"raip:example:example-high-risk-aml-detection-by-accounting-firm","type":"example","slug":"example-high-risk-aml-detection-by-accounting-firm","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b18929aa59e2a4f132780d5e97215ee0c7c9960204c7d54d7edce1cdc88081ee","label":"Money laundering detection by an accounting firm under its own legal duty","summary":"An accounting firm deploys an AI system that detects money laundering, in order to comply with its own obligations under EU anti-money laundering legislation.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Check whether you are meeting your own legal duty or taking over a task from a public authority, because only in the second case do you act on its behalf and enter the law enforcement regime.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-atex-gas-concentration-shutdown","legacy_id":"raip:example:example-high-risk-atex-gas-concentration-shutdown","type":"example","slug":"example-high-risk-atex-gas-concentration-shutdown","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e3a88a7adeee80d2900576b3e4c0a90691aeb886021b9f5ca6833b68df5d004a","label":"ATEX: AI system monitoring gas concentrations and commanding shutdown","summary":"Equipment for potentially explosive atmospheres contains an AI system intended to monitor gas concentrations and command shutdown when thresholds are exceeded.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Once you offer a system that monitors a dangerous value and itself commands an intervention, the safety function follows from your stated intended purpose, not from how reliably the system performs.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-benefits-chatbot-factual","legacy_id":"raip:example:example-high-risk-benefits-chatbot-factual","type":"example","slug":"example-high-risk-benefits-chatbot-factual","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ccd4592906b30dd15e8f2c82b781487573d638c6715c0b0b4593ee2316f7fac9","label":"Chatbot answering factual questions from a benefits case handler","summary":"A chatbot answers a case handler's factual questions relating to the evaluation of a natural person's application for healthcare benefits, for instance the applicant's age. The case handler can grant or deny the benefits based on those answers.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A chatbot that only returns existing facts in structured form falls under the exemption, but once it answers case-specific legal questions it steers the decision and is high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-company-creditworthiness","legacy_id":"raip:example:example-high-risk-company-creditworthiness","type":"example","slug":"example-high-risk-company-creditworthiness","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b59afcb1ffbf61bce9cf580117c6f27b06980a88a62ae4271124e1dd8bea3c94","label":"Company creditworthiness based on corporate financials","summary":"A provider develops a system assessing the creditworthiness of companies by evaluating their company data, balance sheets and financial statements. In a variant, the owner of a legal entity is assessed to back a company loan.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Decide in advance whether natural persons form part of your intended purpose, because a system that also evaluates their personal finances falls within point 5(b) as a whole, regardless of its corporate focus.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-company-creditworthiness-assessment","legacy_id":"raip:example:example-high-risk-company-creditworthiness-assessment","type":"example","slug":"example-high-risk-company-creditworthiness-assessment","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bec3e289c02900f85bdfedf9cdc0c17ecd3ab7203b9abb51f24acfea18516f8f","label":"Corporate creditworthiness based on balance sheets and financial statements","summary":"A provider develops an AI system that assesses the creditworthiness of companies using company data, balance sheets and financial statements. The situation where the owner of a legal entity is assessed as backing for a company loan is also addressed.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An assessment remains corporate as long as the credit accrues to the company, so even an owner backing a company loan does not turn your system into an evaluation of a natural person.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-credit-score-small-business-owner","legacy_id":"raip:example:example-high-risk-credit-score-small-business-owner","type":"example","slug":"example-high-risk-credit-score-small-business-owner","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2694e3a6f3e830d9aca6138171e67fa89f6d17cb9e02aa21d32454ad5b62607f","label":"Credit score of a business owner based solely on business data","summary":"A provider develops an AI system that establishes the credit score of the owner of a small business or of a company that is not a legal entity. The system uses only business or company data.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Limit your system demonstrably to business data if you want to stay outside point 5(b), because the moment it also draws on the owner personal finances you are evaluating a natural person.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-customs-risk-assessment-of-goods","legacy_id":"raip:example:example-high-risk-customs-risk-assessment-of-goods","type":"example","slug":"example-high-risk-customs-risk-assessment-of-goods","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a0b520a795203acf559db27ddf059b7a00fbe9a9b717ac498267c6ca120f1cd9","label":"Customs risk assessment of goods at the external border","summary":"An AI system is used by customs authorities to assess the risk that goods entering the EU do not comply with legislation applicable at the border, based on information about the economic operators concerned, such as container number, description of goods, routing, transport and payment method.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Determine what your risk model actually targets, because if it concerns consignments and goods flows rather than personal aspects of individuals, there is no profiling to block the exemption.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-cv-tailoring-for-candidates","legacy_id":"raip:example:example-high-risk-cv-tailoring-for-candidates","type":"example","slug":"example-high-risk-cv-tailoring-for-candidates","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"375afaabd02fa99caac9117722375a966333ac2c3dd09e4c488f53596fe8efe6","label":"AI helping candidates tailor their CV to a vacancy","summary":"The system analyses the candidate's CV together with the job description supplied by the candidate and recommends changes to increase the likelihood of being selected for an interview. Those recommendations are shared exclusively with the candidate.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Who initiates the tool decides the outcome here, because an aid started by the candidate whose results reach only the candidate falls outside the recruitment use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-flagging-incomplete-application-forms","legacy_id":"raip:example:example-high-risk-flagging-incomplete-application-forms","type":"example","slug":"example-high-risk-flagging-incomplete-application-forms","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b6a7aea77701a6ae42b6f0ca8613f5a55a08171a8bf688261f564629a7bd2989","label":"Flagging incomplete forms and returning them to the applicant","summary":"An AI system detects and flags incompletely filled-in forms so that they can be returned to the applicant to be completed correctly.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A flagging function that merely notes missing data and returns the form can be treated as a narrow procedural task, as long as it says nothing about the substance or quality of the application.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-gas-appliance-combustion-optimisation","legacy_id":"raip:example:example-high-risk-gas-appliance-combustion-optimisation","type":"example","slug":"example-high-risk-gas-appliance-combustion-optimisation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9a1ee52837873b5e4b715a9ff9c62f178a89f2995303301376f38f65c8caaa3f","label":"Gas appliances: AI optimising combustion efficiency","summary":"An AI system optimises combustion efficiency in a household gas appliance. The intended purpose is energy efficiency.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Whether an efficiency system is a safety component depends on the product design: if a malfunction can cause fire, explosion or carbon monoxide it counts, if it only raises the energy bill it does not.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-hiring-pattern-audit","legacy_id":"raip:example:example-high-risk-hiring-pattern-audit","type":"example","slug":"example-high-risk-hiring-pattern-audit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"020cb94fe6b56f5b6623461c6390b28248a2ae45c0ff42d6819554c16f799f02","label":"Retrospective audit of hiring patterns on anonymised data","summary":"A system audits completed hiring decisions by analysing anonymised recruitment data, including CV scores, interview notes and hiring outcomes, using statistical modelling to detect potential bias or inconsistencies. It plays no role in ongoing recruitment and does not assess identified or identifiable recruiters or applicants.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Anonymise the data and keep the analysis entirely retrospective, and you can examine hiring patterns for bias without the system being treated as high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-interview-scheduling-tool","legacy_id":"raip:example:example-high-risk-interview-scheduling-tool","type":"example","slug":"example-high-risk-interview-scheduling-tool","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"72722ab6bf1fdb72da91b94efde5c3c095b3f0b64b2dab61b9f1456c583c23e1","label":"AI scheduling job interviews","summary":"The system coordinates appointments with applicants by combining calendars and stated availability, proposes time slots based on logistical constraints such as time zones and maximum daily meetings, sends reminders, and processes accessibility needs such as sign language interpretation, extended interview duration or alternative communication formats.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Purely logistical support stays clear of the heavy obligations, provided your scheduling tool initiates or influences no assessment and merely processes accessibility needs in practical terms.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-legal-reference-support-for-benefits-decisions","legacy_id":"raip:example:example-high-risk-legal-reference-support-for-benefits-decisions","type":"example","slug":"example-high-risk-legal-reference-support-for-benefits-decisions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7483952e1ca7798728d8c79025c0e78521239c9336562657fb453923a7a4fe01","label":"System that surfaces legal provisions and internal guidance for benefits decisions","summary":"An AI system is used in assessing data relevant to a decision, for example on public benefits, and provides the human operator with references to the relevant legal provisions, information on jurisdiction and possibly existing internal guidelines relevant to the decision-making process.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"General references to legislation and internal guidance remain preparatory, but the moment your system analyses the concrete file or gives a case-specific recommendation you lose that qualification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-lift-door-timing-obstacle-detection","legacy_id":"raip:example:example-high-risk-lift-door-timing-obstacle-detection","type":"example","slug":"example-high-risk-lift-door-timing-obstacle-detection","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f507cc6b3030e353b222eafd7e08a7d5c34e40de988ee100500040053b4d9827","label":"Lifts: AI system managing door closing timing and obstacle detection","summary":"An AI system in a lift manages door closing timing and obstacle detection. The intended purpose given to it by the provider is efficient lift operation, not safety.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Naming efficiency as the purpose leaves the second route open: if a malfunction could injure someone, the system still qualifies as a safety component, so your stated purpose is not the final answer.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-machinery-robot-cell-human-detection","legacy_id":"raip:example:example-high-risk-machinery-robot-cell-human-detection","type":"example","slug":"example-high-risk-machinery-robot-cell-human-detection","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"82b297fbfa06a7e83990a28e6bda1e59e470aeb27ee456c7bc45837ee14ebc78","label":"Machinery: vision system detecting humans in a robot cell","summary":"An AI-based computer vision system detects human presence in a robot cell and triggers a safe stop or speed reduction. The intended purpose given to it by the provider is to prevent injury.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If your instructions for use, technical documentation or sales materials state that a system exists to prevent injury, you have yourself established that it performs a safety function.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-pattern-analysis-on-completed-eligibility-checks","legacy_id":"raip:example:example-high-risk-pattern-analysis-on-completed-eligibility-checks","type":"example","slug":"example-high-risk-pattern-analysis-on-completed-eligibility-checks","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fae3ce694a2854d266dc959a2c3cb92441e2e3db479f71c3834e8717aaedd21e","label":"Pattern analysis on completed eligibility checks in the public sector","summary":"An AI system analyses previously completed eligibility checks by public administrators to detect decision-making patterns or deviations, for quality assurance and reporting. It does not propose outcomes on live cases and does not evaluate the performance of staff members, for example in the annual appraisal.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Pattern analysis stays within the exemption as long as it runs afterwards, proposes no outcome in live cases and does not evaluate the performance of your own staff.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-pressure-equipment-runaway-pressure","legacy_id":"raip:example:example-high-risk-pressure-equipment-runaway-pressure","type":"example","slug":"example-high-risk-pressure-equipment-runaway-pressure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0cf747859996e0a614d986694766c45daa4ca41e0bd7e0f61ff4566dbead65e5","label":"Pressure equipment: AI system predicting runaway pressure and actuating protection","summary":"An AI system in pressure equipment is intended to predict runaway pressure and actuate protective measures, for instance by triggering a shutdown linked to safety accessories.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A model that merely predicts still performs a safety function once that prediction actuates a protective measure, so assess what happens with the output and not only what the model calculates.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-promotion-writing-assistant","legacy_id":"raip:example:example-high-risk-promotion-writing-assistant","type":"example","slug":"example-high-risk-promotion-writing-assistant","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b7fc60bfc307367b422425099b10e24d4e2135075f0f0124b0ee07b79e725cd","label":"Writing assistant refining completed promotion evaluations","summary":"A consultancy firm uses an AI writing assistant to refine managers' promotion reports after evaluations are fully completed. Managers have already recorded the recommendation, justification and ratings; the system improves clarity of language, ensures consistency with corporate style and flags potentially biased wording, after which the manager is required to double-check the revised text.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Have the manager fully record the recommendation, justification and ratings first and restrict the system to wording and consistency, and it remains an after-the-fact improvement.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-quality-assurance-on-finalised-human-work","legacy_id":"raip:example:example-high-risk-quality-assurance-on-finalised-human-work","type":"example","slug":"example-high-risk-quality-assurance-on-finalised-human-work","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c9018b8bc39e8bca7c59ecc317a5f4739ed6ac88cad1a8c0785d52eac369cac7","label":"Quality assurance on finalised human work without replacing the judgment","summary":"Three kinds of auxiliary systems: systems that flag errors or contradictions in finalised human work as a quality-assurance function, systems that map conclusions to evidentiary records to strengthen the traceability of a decision without substituting human judgment, and systems that convert human-validated content for interoperability or accessibility purposes.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Keep your auxiliary system strictly after the human decision and without a view of its own on the outcome, and it remains an improvement that leaves the rights and position of those affected untouched.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-rail-speed-monitoring-collision-prevention","legacy_id":"raip:example:example-high-risk-rail-speed-monitoring-collision-prevention","type":"example","slug":"example-high-risk-rail-speed-monitoring-collision-prevention","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5e311d8dad3d2643f79e306bfa20f9a3c0fbe5968780b717277acea82c296bb8","label":"Rail: AI system in a train monitoring speed limits","summary":"An AI system in a train is intended to monitor speed limits and to prevent collisions and derailments.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If you work in a sector with its own safety regime, note that only the definition in Article 3(14) of the AI Act counts, not the sectoral notion of safety component.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-recruiter-deviation-profiling","legacy_id":"raip:example:example-high-risk-recruiter-deviation-profiling","type":"example","slug":"example-high-risk-recruiter-deviation-profiling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"083a9a0b6a7fa69c7a835a451cd1c2308d0825c729f63acdf802153e07b842b1","label":"Deviation detection in recruitment that assesses the recruiters themselves","summary":"A system identifies deviations from previous recruitment decision-making patterns before recruitment is completed, to detect inconsistencies with corporate recruitment policy, while evaluating the personal characteristics of the recruiters conducting the interviews.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"To keep the exemption, aim the deviation analysis solely at the decisions themselves rather than at the people who made them, and run it only after recruitment has been completed.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-recruitment-background-checks","legacy_id":"raip:example:example-high-risk-recruitment-background-checks","type":"example","slug":"example-high-risk-recruitment-background-checks","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"247c5593dc308ad099695c84690317ae25607ecea26e6ef81e6b6e14917caba7","label":"AI background checks producing applicant risk scores","summary":"The system aggregates official records, employment history, social network history and, where legally permissible, financial data, plus open-source information, and returns composite risk scores or categories such as low, medium and high risk with alerts such as unexplained employment gaps. In high-volume hiring, candidates flagged as high risk are deprioritised before a caseworker reviews the file.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Background checking with composite risk scores is profiling, and that rules out every exemption, even where you have formally built a human review into the process.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-recruitment-deviation-detection-profiling-recruiters","legacy_id":"raip:example:example-high-risk-recruitment-deviation-detection-profiling-recruiters","type":"example","slug":"example-high-risk-recruitment-deviation-detection-profiling-recruiters","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a6d12e69d940a6cc94b67c89bb2098c4bc71af76715b56d3b54c400b58ff0610","label":"Deviation detection in recruitment that also evaluates the recruiters themselves","summary":"An AI system is used in the recruitment of employees. It identifies deviations from previous recruitment decision-making patterns to detect potential inconsistencies with corporate recruitment policies, and in doing so also evaluates the personal characteristics of the recruiters conducting the job interviews. The system runs before recruitment is completed.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A system detecting deviations in decision-making can fall under the exemption, but once it also weighs personal characteristics of your own staff there is profiling and that route closes.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-school-assignment-system","legacy_id":"raip:example:example-high-risk-school-assignment-system","type":"example","slug":"example-high-risk-school-assignment-system","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1ab5c33b5560078b2c4719ebe70a84e9fc2fec017277c87f8a318ab01a9df12e","label":"Automated school assignment by municipalities","summary":"Municipalities or regional authorities automatically assign pupils to public schools based on structured data such as home address, school catchment boundaries and available capacity, also factoring in sibling attendance and parental status to keep families together or minimise commuting distance.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Even an assignment on seemingly objective data such as address and capacity counts as profiling here, so as a public body you cannot rely on the Article 6(3) exemption.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-scoring-applicant-answers","legacy_id":"raip:example:example-high-risk-scoring-applicant-answers","type":"example","slug":"example-high-risk-scoring-applicant-answers","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3b333b0c6e9d12a88917fb9e1041b555aceab0fcbe9473b862f33dcbb489fb2a","label":"AI scoring and ranking applicant answers","summary":"A system evaluates written or oral responses given by job applicants in an online assessment, assigns a numerical score based on linguistic and substantive criteria, and generates a ranking used to determine who is invited to the interview stage.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Once your assessment turns answers into a score that decides who is invited to interview, the system performs a core evaluation and no exemption gets you out.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-smart-thermostat-comfort-optimisation","legacy_id":"raip:example:example-high-risk-smart-thermostat-comfort-optimisation","type":"example","slug":"example-high-risk-smart-thermostat-comfort-optimisation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cf4e8e4317baea81dff8c43da5cf22a19f57b94a6430f8f355b60550b7378eec","label":"Smart thermostat optimising comfort and energy use","summary":"A smart thermostat covered by the radio equipment rules learns household routines and optimises temperature settings. The intended purpose is greater comfort and lower energy use.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Being a consumer or household product excludes nothing; substantiate that a malfunction leads at most to discomfort or a higher energy bill, and pay particular attention to children and vulnerable users.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-sorting-school-admission-applications","legacy_id":"raip:example:example-high-risk-sorting-school-admission-applications","type":"example","slug":"example-high-risk-sorting-school-admission-applications","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b7d0c75c5242e306ea6f107d1f161fe799f8bb415a00d915296d4623900d9e8e","label":"Sorting school or university admission applications by level","summary":"An AI system sorts incoming applications for admission to a school or university by the grade or educational level applied for, placing them into predefined categories such as primary, secondary or specific grades, based on information supplied in the application.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Sorting on a datum the applicant supplied stays a narrow procedural task, provided your system passes no judgment on suitability and prepares no admission decision.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-toy-music-recommendation","legacy_id":"raip:example:example-high-risk-toy-music-recommendation","type":"example","slug":"example-high-risk-toy-music-recommendation","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d0c36ee8bea5ceb368fe3d22743f6a3df3bebf295d8237072e7c06e9c5e34d58","label":"Toys: AI recommending music in a connected toy","summary":"An AI system in a connected toy makes music recommendations to the child playing with it.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Not every AI component inside a regulated product counts; where both a safety purpose and a hazardous failure consequence are absent, the component falls outside the notion of safety component and outside Article 6(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-toys-harmonised-standards-module-opt-out","legacy_id":"raip:example:example-high-risk-toys-harmonised-standards-module-opt-out","type":"example","slug":"example-high-risk-toys-harmonised-standards-module-opt-out","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0b9ad63de716de07c6d1e477d3d06ba28a60975bfaf687ba02bbafc6b95feaa5","label":"Toys: manufacturer opts for internal control based on standards","summary":"A toy manufacturer whose product contains an AI system as a safety component applies harmonised standards and thereby opts for a conformity assessment procedure without third-party involvement.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Opting for internal control based on harmonised standards without a third party changes your procedure but not the classification: the system remains high-risk and the accompanying obligations still apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-vehicle-lane-assistance","legacy_id":"raip:example:example-high-risk-vehicle-lane-assistance","type":"example","slug":"example-high-risk-vehicle-lane-assistance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"729897c34abb1939cfd4f4f4621e628d1b20718510415ca539d8bd178e314f30","label":"Vehicles: AI system for lane assistance","summary":"An AI system for lane assistance in a vehicle. The intended purpose given to it by the provider is enhancement of the user experience.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"On the failure route your own stated purpose carries little weight; support the assessment with system architecture, failure modes and their effects, because that is what will be examined.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-visa-file-indexing","legacy_id":"raip:example:example-high-risk-visa-file-indexing","type":"example","slug":"example-high-risk-visa-file-indexing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b979e40e96d280599b2865d51a542f45b145453a20df39f30d9065e4daf84df4","label":"Scanning visa files, filing them and marking duplicate attachments","summary":"A system in migration and border management scans each submitted visa file, converts scanned documents into text for indexing, automatically files items into fixed, predefined folders such as identity documents, travel itinerary, supporting evidence and translations, and detects exact duplicate attachments and marks them as duplicates.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Even where your file processing qualifies for the exemption, you must document the assessment beforehand and register the system, so the supervisory authority can check your choice at any time.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-high-risk-visa-file-indexing-and-deduplication","legacy_id":"raip:example:example-high-risk-visa-file-indexing-and-deduplication","type":"example","slug":"example-high-risk-visa-file-indexing-and-deduplication","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7aa58637bcc05ae6d27a1b39ba18c36faa17becac39c203df9374f523e020b01","label":"Scanning, indexing visa files and marking duplicate attachments","summary":"An AI system in the migration and border management context scans each submitted visa file, converts scanned documents into text for indexing, automatically files items into fixed predefined folders such as identity documents, travel itinerary, supporting evidence and translations, and detects exact duplicate attachments and marks them as duplicates.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Fix the boundaries of your file processing tightly, because the exemption falls away as soon as the system ranks items, labels them useful or less useful, hides them or suggests a next step.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-ineco-bewustwording-leidt-tot-gedragsregel","legacy_id":"raip:example:example-ineco-bewustwording-leidt-tot-gedragsregel","type":"example","slug":"example-ineco-bewustwording-leidt-tot-gedragsregel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"178e6872cb246e444c56f5919d033f797df879970193c885884fe6fdd9dae344","label":"Awareness that turns into a hard usage rule","summary":"INECO, a large Spanish engineering firm working for public authorities on rail, airports and digitalisation, ran over twenty AI trainings with more than four hundred participants in 2024 and set up an AI Master Classroom on the intranet with short modules, audio and subtitles. After making staff aware of data leakage risk, the organisation limited the use of public language models and moved to a secured chatbot solution.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Combine short online modules with real sessions, because the Commission describes the collected initiatives as a mix of e-learning platforms and in person trainings rather than one fixed format.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-interne-ai-assistent-evidente-interactie","legacy_id":"raip:example:example-interne-ai-assistent-evidente-interactie","type":"example","slug":"example-interne-ai-assistent-evidente-interactie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"99b82321431c15da8264240496e89a3b0f37839ea71c08a92cd5c85c757ccc83","label":"Internal AI assistant for trained staff needs no notice","summary":"An organisation makes an internal AI assistant available for HR, procurement, IT and compliance questions. It sits behind the company login only, and staff have been trained in using AI.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception rests on a closed and trained audience, so record who has access and what AI training they received, because once the assistant reaches beyond that circle the exemption falls away.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-kredietreclame-lage-inkomens-postcode","legacy_id":"raip:example:example-kredietreclame-lage-inkomens-postcode","type":"example","slug":"example-kredietreclame-lage-inkomens-postcode","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffa93e0956769c74fc8e96a02d58648ed7d2254187a61356488f17c2486ac356","label":"Credit advertising targeted at low-income postcodes","summary":"A financial services provider uses a predictive AI model to target advertising for predatory financial products at people living in low-income postcodes who are in dire financial straits.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Deliberately targeting proxy variables such as postcodes that coincide with a vulnerable socio-economic group counts as exploitation, while unintended bias only becomes exploitation once you know about it and fail to correct it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-kredietscore-versus-fraudedetectie","legacy_id":"raip:example:example-kredietscore-versus-fraudedetectie","type":"example","slug":"example-kredietscore-versus-fraudedetectie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5a1a997b620fa26e8adefd9d483829d1806f32c4ed5f49b443938c4e11e5ddaa","label":"Credit scoring and fraud detection at the same bank","summary":"A lender uses a model that gives individual applicants a score on which the acceptance decision rests. The same institution also runs a separate model that flags suspicious transactions for fraud investigation.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Assess each model separately against its own intended purpose, since a model scoring a natural person creditworthiness is high-risk while a model whose main intended use is fraud detection falls outside.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-kredietscoring-en-telematica-buiten-verbod","legacy_id":"raip:example:example-kredietscoring-en-telematica-buiten-verbod","type":"example","slug":"example-kredietscoring-en-telematica-buiten-verbod","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"95b5c5219bd8df03d5e381c97f95c2cd1f99ba08d0735bc7414ee24b7014163a","label":"Credit scoring and telematics premiums remain permitted","summary":"A lender assesses creditworthiness on the basis of income, expenses and other financial and economic circumstances. An insurer raises the premium of a driver whose telematics data show persistent speeding.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Scoring is allowed where you use only data relevant to the purpose and the consequence stays proportionate, and sectoral rules prescribing which data count as relevant provide your strongest justification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-lichte-finetuning-geen-modelaanbieder","legacy_id":"raip:example:example-lichte-finetuning-geen-modelaanbieder","type":"example","slug":"example-lichte-finetuning-geen-modelaanbieder","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a0504fa697e8667f830394948b6e8bd455caaf6a2902ddf1a2aaf833293c887d","label":"Light fine-tuning does not make you a model provider","summary":"A bank fine-tunes an existing general-purpose AI model on its own product documentation and customer questions, using a fraction of the original compute, and builds a customer chatbot around it that it offers under its own name.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If your fine-tuning stays well below one third of the original compute you do not become the model provider, but the obligations for the AI system you offer under your own name still apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-locatiegebonden-predictive-policing","legacy_id":"raip:example:example-locatiegebonden-predictive-policing","type":"example","slug":"example-locatiegebonden-predictive-policing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"638e4a97ebe4939869af5a59d1b8b325610d1ebc47429ffad63a36731256ace2","label":"Place-based predictive policing falls outside the prohibition","summary":"A police force uses an AI system that scores the likelihood of crime in different areas of a city, based on past crime rates per area, street maps and supporting information, to decide where to deploy more patrols.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Place-based prediction falls outside the prohibition, but only as long as the area score does not become an element in the profile of an individual, because that turns the assessment person-based.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-hogeschool-aanmelding-toetsing","legacy_id":"raip:example:example-logging-hogeschool-aanmelding-toetsing","type":"example","slug":"example-logging-hogeschool-aanmelding-toetsing","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"87cc04e5994d67a08654e7bda8c7ea6eb508508cf029630e0faf71818cbd70bb","label":"Logging in admission and assessment: what the institution keeps in its own hands","summary":"A university of applied sciences uses a purchased AI system that ranks student admissions and also raises flags during digital assessment. The logs sit in the supplier environment, which hands them over on request. The teaching organisation wonders whether that settles the matter or whether the school retains a duty of its own.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires a high-risk AI system to technically allow for the automatic recording of events (logs) over the lifetime of the system, and Article 12(2) ties that recording to a level of traceability appropriate to the intended purpose of the system. Article 26(6) provides that deployers keep the automatically generated logs to the extent those logs are under their control, for a period appropriate to the intended purpose, of at least six months, unless applicable Union or national law provides otherwise, in particular Union law on the protection of personal data. Article 19(1) places a corresponding retention duty on providers for the logs generated by their systems that are under their control, likewise for at least six months.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"On our reading, the fact that the supplier hosts the logs does not by itself place the school outside Article 26(6): what matters is whether the logs are under its control. The Regulation does not define that notion, and on our reading server location is not decisive in itself; the question is whether you can actually and contractually dispose of those logs, and it has to be answered for each procurement. So agree at procurement that the institution can request, export and itself retain the logs for the chosen period, and record which admission and assessment events that covers. Take data protection into account at the same time, because the same provision allows other Union or national law to cap the retention period.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-productielijn-veiligheidscomponent","legacy_id":"raip:example:example-logging-productielijn-veiligheidscomponent","type":"example","slug":"example-logging-productielijn-veiligheidscomponent","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"624d417df4b70bdd1072de6b663f188dd48de9556bd5866eabfc9f1da5fe3d3a","label":"Logging on the production line: which logs the manufacturer keeps and which the factory keeps","summary":"A manufacturer supplies an AI system that runs as a safety component inside the machinery of a production line and also drives quality control. The factory operating the line keeps only the alerts visible in the local controller; the rest of the recording flows to the supplier environment. The question is who has to keep which logs when it later has to be reconstructed why the line was halted.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the lifetime of the system. Under Article 12(2), those logging capabilities must enable the recording of events relevant for identifying situations that may result in the system presenting a risk within the meaning of Article 79(1) or in a substantial modification, for facilitating the post-market monitoring referred to in Article 72, and for monitoring the operation of the high-risk AI systems referred to in Article 26(5). Article 19(1) obliges providers to keep those automatically generated logs to the extent they are under their control, for a period appropriate to the intended purpose of the system, of at least six months, unless applicable Union or national law provides otherwise. Article 26(6) places a corresponding retention duty on deployers for the logs under their control, with the same six-month floor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 19 together with Article 26(6) as leaving the manufacturer, acting here as the provider, and the factory, acting as the deployer, each with a retention duty of its own for the logs under its control. The Regulation does not say when logs count as being under your control, and on our reading the place where the recording physically lands does not settle that by itself; the question has to be answered system by system. For a production line that means recording which events stay in the machinery controller and which travel to the supplier, and securing access to that second set contractually before you need it. Leave that unarranged and you risk being unable to trace a line stoppage or a quality control rejection back to the behaviour of the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2), Article 19(1) and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-logging-taakverdeling-werkvloer","legacy_id":"raip:example:example-logging-taakverdeling-werkvloer","type":"example","slug":"example-logging-taakverdeling-werkvloer","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"be80038e3b50070a20f07e501c8a3a9c35fff975654135c454e9a4c5a9b96545","label":"Logging in task allocation at work: evidence about the system or a file on the employee","summary":"An employer deploys an AI system that handles task allocation among staff and summarises their performance for the performance review. HR wants to know what record of those outcomes has to be retained when an employee objects months later to a promotion decision.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 12(1) requires high-risk AI systems to technically allow for the automatic recording of events (logs) over the lifetime of the system. Article 12(2)(c) names, as one of the purposes of those logging capabilities, monitoring the operation of the systems referred to in Article 26(5), and that paragraph obliges deployers to monitor operation on the basis of the instructions for use and, where relevant, to inform the provider in accordance with Article 72. Article 26(6) obliges deployers to keep the automatically generated logs to the extent they are under their control, for a period appropriate to the intended purpose, of at least six months, unless applicable Union or national law provides otherwise. Article 19(1) sets out a corresponding retention duty for providers, with the same six-month floor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2)(c), Article 19(1) and Article 26(5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 12(2) as putting the logging capabilities there first of all to follow risks, substantial modifications and the operation of the system, not to sharpen judgements about individual staff. Whether that statement of purpose also limits what the retained logs may later be used for is something Article 12 does not say: on our reading that limit has to come from data protection law, to which Article 26(6) itself refers. For HR a practical line follows: keep what is needed to trace an outcome and to carry out the monitoring under Article 26(5), and settle in writing beforehand whether those same files may double as a performance record. Bear in mind that the six-month floor can be shorter than the period within which an employee challenges a promotion decision; the Regulation does not govern that evidential position.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1) and (2)(c), Article 19(1) and Article 26(5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-model-bevroren-na-uitrol","legacy_id":"raip:example:example-model-bevroren-na-uitrol","type":"example","slug":"example-model-bevroren-na-uitrol","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8a1ada45cda845e74037fba5b19ffbe0faa783b4e5418e0db9651eca6f28137d","label":"Model that stops learning after deployment","summary":"An insurer deploys a trained model that ranks claims by complexity. After deployment the model learns nothing new; the supplier retrains only periodically in a controlled release, so its behaviour is entirely stable between releases.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Self learning behaviour after deployment is optional and not a ground for exclusion, so a frozen model that stays entirely stable between releases does not escape the definition on that basis.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-model-met-systeemrisico-aanpassen","legacy_id":"raip:example:example-model-met-systeemrisico-aanpassen","type":"example","slug":"example-model-met-systeemrisico-aanpassen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"95e0bbd15dfc1a3246cd0aee299ef42b39f5bfb283b1ce4a8cfa84a630448d8c","label":"Modifying a systemic-risk model pulls the heaviest duties to you","summary":"A downstream actor modifies an existing systemic-risk model so substantially that the change exceeds the threshold, and publishes the result as its own model.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Where a modification of a systemic-risk model crosses the threshold, the result is presumed to have high-impact capabilities, so estimate the compute in advance and notify the Commission within two weeks.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-mural-sessie-verboden-praktijken","legacy_id":"raip:example:example-mural-sessie-verboden-praktijken","type":"example","slug":"example-mural-sessie-verboden-praktijken","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffc7d4ae1ad4f2f1e05bb2f6fca39286346ea8245ca46aaae063743a8bee08f5","label":"A dedicated session on prohibited practices for the development team","summary":"In 2024 Mural ran a mandatory AI training for all staff with a 93 percent completion rate, and additionally organised a live interactive session for the AI team specifically on prohibited practices and high-risk categories. For that team the legal function built a visual mind map on a digital whiteboard, with templates and direct references to the provisions.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two layers side by side: a baseline for everyone and a deeper session for the team that makes the choices. That second layer is where Article 4 earns its keep, because prohibited practices and high-risk categories are design questions rather than awareness questions. The completion rate is not a goal in itself, but it is the kind of figure that later lets you show the measure actually reached the organisation.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-navigatiesysteem-metadata-markering","legacy_id":"raip:example:example-navigatiesysteem-metadata-markering","type":"example","slug":"example-navigatiesysteem-metadata-markering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"adbb8b7ed3847e0882cb8250c761c61daf88599660fae3bf9cbaf98b813664f9","label":"In-car navigation: lighter marking is enough","summary":"A car manufacturer builds a generative AI system into the navigation unit that composes spoken and written route instructions. The output stays inside the vehicle and technical measures prevent it from being exported or shared.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The lighter marking is conditional, because it holds only while technical measures demonstrably prevent the output from leaving the product, so document those measures before relying on this route.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-onderwijs-eye-tracking-online-tentamen","legacy_id":"raip:example:example-onderwijs-eye-tracking-online-tentamen","type":"example","slug":"example-onderwijs-eye-tracking-online-tentamen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ad302d79910ccb034717f506ed1d38cb0ce5453cabd08c3fd48e2b96868f7558","label":"Eye tracking in online exams versus emotion detection","summary":"An education institution uses eye tracking software during online exams to follow students' gaze point and eye movement, to detect whether unauthorised material is being used.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Measuring where someone looks is not emotion recognition, but the moment the same system infers a state such as arousal or anxiety it becomes prohibited, so bound the functionality explicitly.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-opensource-in-naam-maar-niet-in-de-zin-van-de-verordening","legacy_id":"raip:example:example-opensource-in-naam-maar-niet-in-de-zin-van-de-verordening","type":"example","slug":"example-opensource-in-naam-maar-niet-in-de-zin-van-de-verordening","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5dc00034cfc1ea6015891add4d5e3a85e7be426cdfab0e9ff0cbb59949b927fc","label":"Open source in name, but not within the meaning of the Regulation","summary":"Three providers call their model open source. The first licence allows non-commercial research only. The second requires a separate commercial licence once monthly active users pass a threshold. The third gives the model away for free but hosts it exclusively on its own platform where visitors are served paid advertisements.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A usage restriction is not automatically fatal: you may include specific, proportionate and non-discriminatory safety terms, whereas a monthly active user threshold or a separate commercial licence disqualifies the licence.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-opensource-uitzondering-reikwijdte","legacy_id":"raip:example:example-opensource-uitzondering-reikwijdte","type":"example","slug":"example-opensource-uitzondering-reikwijdte","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"343545ffd930f1ac833f9ccee1245bbcff4baea04a7761a75768ec02b879598c","label":"What the open-source exemption does and does not cover","summary":"A research group publishes a general-purpose AI model under a free and open-source licence and makes the weights, architecture and usage information publicly available. The model carries no systemic risk.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A free and open-source release without systemic risk lifts the technical documentation duties and the authorised representative, but the copyright policy and the public training-content summary continue to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-optimalisatie-versnellen-geen-ai-systeem","legacy_id":"raip:example:example-optimalisatie-versnellen-geen-ai-systeem","type":"example","slug":"example-optimalisatie-versnellen-geen-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"338231316dc9f139ea48aad3d9b0406a1c7cc7bbf94c8a06ed9d69e4f722d3c1","label":"Machine learning that only speeds up an existing optimisation calculation","summary":"A grid operator uses a machine learning model to approximate parameters inside a classical optimisation calculation built on linear and logistic regression. The model changes nothing about the decision rules themselves, it only makes a long established calculation method faster and cheaper.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If your model only makes a long established calculation method faster and leaves the decision rules untouched, record both points, because they are what carries the conclusion that you fall outside the definition.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-politie-model-bijtrainen-opsporing","legacy_id":"raip:example:example-politie-model-bijtrainen-opsporing","type":"example","slug":"example-politie-model-bijtrainen-opsporing","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f76e99119daefd7c5cfc07f8db92500ea93ce6a13b3e86aff47818a0a15cb89a","label":"Police fine-tuning a model for investigations: settle the role question first","summary":"A police service fine-tunes an open general-purpose model on its own files from ongoing criminal investigations, so that detectives can see links between suspects and cases sooner. The fine-tuned model stays inside the service and is not made available to anyone else. The question is whether the service thereby becomes a provider of a general-purpose AI model itself, and so falls under Article 53.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 53(1) requires providers of general-purpose AI models to do four things: draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at a minimum the information set out in Annex XI so that it can be provided on request to the AI Office and the national competent authorities; draw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the model, containing at a minimum the elements set out in Annex XII; put in place a policy to comply with Union law on copyright and related rights; and draw up and make publicly available a sufficiently detailed summary about the content used for training, according to a template provided by the AI Office. Article 53(2) provides that the obligations under points (a) and (b) do not apply to providers of models released under a free and open-source licence that allows for the access, usage, modification and distribution of the model, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available, and that this exception does not apply to general-purpose AI models with systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Start with your role, because merely using someone else's model does not by itself make you a model provider; Article 53 does not say at what point a service that fine-tunes crosses that line, and the point deserves an explicit answer rather than an assumption. A further question comes before Article 53: whether your fine-tuned investigation model has been placed on the market within the meaning of the Regulation. That it never leaves the service does not settle this on its own, since the Commission's guidelines on the scope of the obligations for providers of general-purpose AI models also treat internal use affecting the rights of natural persons as placing on the market. We read paragraph 2 as attaching the open-source exception to your own model rather than carrying it over automatically from the model you started out with: if you do not publish the weights and architecture of the fine-tuned model, which is the obvious course in criminal matters, then on that reading the exception is not open to you, and the duties under points (c) and (d) remain in place in any event, since paragraph 2 lifts only points (a) and (b). So record, version by version, exactly what you changed, on which data and to what end, because that record is what decides whether you stand here as a user or as a provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-hr-beoordelingssysteem","legacy_id":"raip:example:example-post-market-monitoring-hr-beoordelingssysteem","type":"example","slug":"example-post-market-monitoring-hr-beoordelingssysteem","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"834c3d7f217e8710ac5698e4b555f10d6b66e59eddbb6facca765496ad4b791d","label":"Assessing staff: signals from the workplace flowing back to the provider","summary":"A provider supplies a system that summarises employee performance data and supports HR in promotion decisions. After a year in use, departments turn out to apply it differently than intended, and managers factor the outputs into the performance review. The question is what the provider is supposed to know about that.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system in a manner proportionate to the nature of the AI technologies and the risks of the high-risk AI system. Article 72(2) requires that system to actively and systematically collect, document and analyse relevant data, which may be provided by deployers or collected through other sources, on performance throughout the system's lifetime, allowing the provider to evaluate continuous compliance with the requirements set out in Chapter III, Section 2. Article 72(3) provides that the system is based on a plan forming part of the technical documentation referred to in Annex IV, and instructs the Commission to adopt an implementing act laying down detailed provisions establishing a template for that plan and the list of elements to be included in it; the Regulation sets 2 February 2026 as the date for that act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that use which departs from what was intended is exactly the kind of real-world data paragraph 2 has in mind, because it bears on the human oversight and the intended purpose laid down in Section 2. Paragraph 3 points to a Commission template for which the Regulation sets 2 February 2026 as the date; check whether that template has since been adopted and align with it if so, since paragraph 4 refers to it as well. In the meantime we would not put the design of your monitoring on hold for it: which data you need already follows from the requirements the system must continue to meet. Agree with the organisations using the system on the route by which employee complaints and deviations in assessments reach you.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-proctoring-tentamens","legacy_id":"raip:example:example-post-market-monitoring-proctoring-tentamens","type":"example","slug":"example-post-market-monitoring-proctoring-tentamens","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"683c18d4fac97ff4db4363416589f34e9615625ed4323784e0b292b8d25ad231","label":"Proctoring during exams: which real-world data the institution reports back","summary":"A vendor offers proctoring software that flags possible cheating during exams. Several universities of applied sciences use the system, each with its own assessment formats and its own student populations. The vendor wants to know which real-world data it must keep collecting after roll-out, and from whom.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system, proportionate to the nature of the AI technologies and the risks of the system. Article 72(2) provides that this system actively and systematically collects, documents and analyses relevant data which may be provided by deployers or collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of those systems with the requirements set out in Chapter III, Section 2. Where relevant, monitoring includes an analysis of the interaction with other AI systems. Article 72(3) provides that the system is based on a plan forming part of the technical documentation referred to in Annex IV.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The duty sits with the provider, but the useful signals arise in education itself: unfounded suspicions, student complaints, differences between programmes and assessment formats. Our reading is that paragraph 2 allows deployers to supply that data while leaving the duty to collect and analyse it with the provider. What the article does not settle is the route by which the data reaches you, or whether the institutions are bound to supply it; that is something you have to arrange with them and cannot read out of Article 72. We would therefore fix that route before the system goes live, and would also set out in the plan how you break performance down by assessment format and by group, since an average across all schools hides precisely the pattern you are looking for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-post-market-monitoring-veiligheidscomponent-productielijn","legacy_id":"raip:example:example-post-market-monitoring-veiligheidscomponent-productielijn","type":"example","slug":"example-post-market-monitoring-veiligheidscomponent-productielijn","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1ed8bb9e9486b8528de2cce401e4f0ce0bed59bd284ede4a90ac5703f85dc09","label":"Safety component on the production line: the manufacturer keeps watching after delivery","summary":"A manufacturer supplies an AI safety component that halts machinery on a production line as soon as someone comes too close to the robot. The component already falls under product legislation for machinery, and the manufacturer runs quality control and incident follow-up for it. The question is what Article 72 adds on top of that.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 72(1) requires providers to establish and document a post-market monitoring system in a manner proportionate to the nature of the AI technologies and the risks of the high-risk AI system. Article 72(3) provides that this system is based on a post-market monitoring plan, and that the plan forms part of the technical documentation referred to in Annex IV. Article 72(4) gives providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, the choice of integrating the necessary elements described in paragraphs 1, 2 and 3 into those systems and plans, using the template referred to in paragraph 3, provided this achieves an equivalent level of protection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1), (3) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Our reading is that Article 72 does not force a second, separate monitoring structure here: paragraph 4 gives you the choice of housing the elements in the system and plan you already run under product legislation, using the template from paragraph 3 and as long as the level of protection remains equivalent. That route stands or falls on a question the article does not answer for you: does the applicable product legislation genuinely have an established post-market monitoring system and plan, or do you run quality control and incident follow-up that were never established as such. Beyond that, you need to be able to show that the signals coming off the factory floor genuinely speak to continued compliance with the high-risk AI requirements, and not only to the mechanical safety of the machine. We would therefore record, for each production signal, which requirement it touches, so that integration does not become dilution.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1), (3) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-proctoring-bij-online-tentamen","legacy_id":"raip:example:example-proctoring-bij-online-tentamen","type":"example","slug":"example-proctoring-bij-online-tentamen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b796e01831c8d43b31b52e5f8bbb75f1ba9a64dbf5e9bbacb0ad7055d7572ad","label":"Proctoring software during an online exam","summary":"A university of applied sciences uses software during online exams that flags possible cheating from webcam images and mouse movement. A flag triggers an automatic notification to the exam board.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"With proctoring software the timing decides: live monitoring during a graded test falls under point 3(d), while checking submitted work afterwards stays outside that use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-proctoring-tentamen-incidentmelding","legacy_id":"raip:example:example-proctoring-tentamen-incidentmelding","type":"example","slug":"example-proctoring-tentamen-incidentmelding","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9acab6c994b68ac7110c3307f8907ee18580a895ef51f8ed17588a3e03b73504","label":"Proctoring during an exam overshoots: from signal to reporting duty","summary":"A university of applied sciences uses proctoring software during an online exam and finds that a group of students is systematically and wrongly flagged as suspicious, after which grades were withdrawn. Teaching staff and the examination board want to know whether this pattern is a serious incident and, if so, who has to report it and within what time.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) obliges the provider of a high-risk AI system placed on the Union market to report serious incidents to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established the causal link or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident. Article 73(5) allows an initial, incomplete report followed by a complete report where this is necessary to ensure timely reporting. Article 73(7) provides that upon receiving a report concerning a serious incident as referred to in Article 3, point (49)(c), the market surveillance authority informs the national public authorities or bodies referred to in Article 77(1). Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2), (5) and (7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 73 as meaning that an incident in education is rarely a single dramatic moment: the signal sits in the pattern in exam results, and the institution sees that pattern before the software supplier does. Whether that pattern amounts to a serious incident is a separate question: it turns on whether the wrongful flagging and the withdrawal of grades count as an infringement of obligations protecting fundamental rights within the meaning of Article 3, point (49)(c), and Article 73 does not make that assessment for you. Leaving the question open until your own investigation is finished carries a risk, because the Article 73(2) period runs from awareness. Set up your examination and complaints process so that such a pattern reaches the provider within days; Article 26(5) also puts a notification duty on the institution itself as deployer, towards the provider, the importer or distributor and the market surveillance authority. The initial, incomplete report of Article 73(5) is the pressure valve here; waiting for a finished investigation report is not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2), (5) and (7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-realtime-gezichtsherkenning-voetbalstadion","legacy_id":"raip:example:example-realtime-gezichtsherkenning-voetbalstadion","type":"example","slug":"example-realtime-gezichtsherkenning-voetbalstadion","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5b4b3c29ead39b1e417d5e1d6feb664466d6fd9bf91e0731a8d2f25bafda2b37","label":"Live facial recognition at a football stadium","summary":"Police install a van with mobile cameras and live facial recognition at the main entrance of a stadium during a European Championship match. The watchlist covers people suspected of offences ranging from serious crime to fraud and burglary, plus people of possible intelligence interest and vulnerable persons with mental health issues. There is no information linking a specific person to this event.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A watchlist that mixes different kinds of suspicion and is not tied to the specific event is too unspecific, and the presence of one person for whom deployment would be allowed does not legitimise the whole operation.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-recidiverisico-bij-politie","legacy_id":"raip:example:example-recidiverisico-bij-politie","type":"example","slug":"example-recidiverisico-bij-politie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9681a826f0f7dc00134cfe89fc052ca08f5ced8e606b6a265d8bcbb97893f590","label":"Reoffending risk assessment at a police force","summary":"A police force uses a model that estimates, per suspect, the likelihood of committing another offence, based on the case file and previously established behaviour. That outcome feeds into the prioritisation of ongoing investigations.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Record which verifiable facts your risk assessment rests on, because an assessment tied to established involvement in a criminal offence is high-risk, whereas one resting solely on profiling is prohibited.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-satelliet-bandbreedte-optimalisatie","legacy_id":"raip:example:example-satelliet-bandbreedte-optimalisatie","type":"example","slug":"example-satelliet-bandbreedte-optimalisatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c13bb70063151ac3ad4847947b5b89b85d779d944fc5b7163cc39d4fbd181e66","label":"Satellite network allocating bandwidth with a predictive model","summary":"A satellite operator allocates power and bandwidth across transponders using a machine learning model that predicts network traffic, because classical optimisation struggles with demand that varies sharply by region and by moment. Performance is comparable to established methods in the field.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Automatic self-adjustment need not bring your system within the definition where it mainly improves computational performance, although the guidelines say only that such systems may be excluded under those conditions.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-satirische-deepfake-van-politicus","legacy_id":"raip:example:example-satirische-deepfake-van-politicus","type":"example","slug":"example-satirische-deepfake-van-politicus","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"31f23b655c6bec989cd6f0b0173a0b5bb4c9db33290d5beb0a6db3366e7e2c8c","label":"Satirical deep fake of a politician: lighter, not exempt","summary":"A satirical outlet publishes an AI-manipulated image of an existing politician, placed in a scene that humorously criticises a policy decision. Style and context make it immediately clear that this is satire.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Satire only lightens the form of the disclosure and not the duty itself, so make sure the satirical character is evident to your audience and respect the rights of the person depicted.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-schaakprogramma-minimax-heuristiek","legacy_id":"raip:example:example-schaakprogramma-minimax-heuristiek","type":"example","slug":"example-schaakprogramma-minimax-heuristiek","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ea77388b96fa6332db5b79bba1180f77661ed8b1cec9f73bed38f1cb4fd1b001","label":"Chess program using minimax and heuristic evaluation","summary":"A software company releases a chess program that assesses board positions using a minimax algorithm with heuristic evaluation functions. The program has never learned from game data; it applies pre-programmed rules and search strategies to find a strong move.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"That your system never learned from data does not settle the question, because the guidelines also count logic and knowledge based approaches as AI techniques and do not tie the definition to a chosen technique.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-securitymonitoring-kritieke-digitale-infrastructuur","legacy_id":"raip:example:example-securitymonitoring-kritieke-digitale-infrastructuur","type":"example","slug":"example-securitymonitoring-kritieke-digitale-infrastructuur","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8dd8de28fda79bd209141410f49769cdb9af6a28ce4f10a431b5106d06367115","label":"Security monitoring by a SaaS company: cybersecurity alone is not a safety component","summary":"A software company supplies a SaaS platform that monitors network traffic at an operator of critical digital infrastructure and reports anomalous patterns to that customer's security team. Its developers see that use at such an operator may fall under point 2 of Annex III and wonder whether their own product therefore becomes a high-risk AI system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that point 2 of Annex III lists AI systems intended to be used as safety components in the management and operation of, among other things, critical digital infrastructure, and that Recital 55 draws a clear distinction between a safety component and a cybersecurity component. To fall within point 2, an AI system must not be used solely for cybersecurity purposes; without a direct safety role it cannot be a safety component in critical infrastructure and therefore cannot be classified as high-risk under Article 6(2). As examples of systems used solely for cybersecurity and thus falling outside point 2, they list an AI honeypot that identifies and neutralises cyber threats in real time, technology that actively engages with potential attackers to learn new attack patterns, a system supporting the detection of unauthorised access, and a system that detects suspicious email addresses and identifies stolen data. They add that an AI system is classified as a safety component in critical infrastructure only where it is used by an entity identified as a critical entity by a Member State under the CER Directive, and that this interpretation does not require that status to be disclosed to a third-party provider. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read this passage as a line drawn function by function rather than customer by customer: the fact that your client operates critical digital infrastructure does not by itself turn your monitoring product into a safety component. What we cannot settle from the text is where mere flagging ends and a safety function begins, because the same guidelines also count monitoring and detecting situations that may directly lead to physical harm among the safety functions. The open question is therefore whether your SaaS platform stands apart from the systems that drive physical control, or in practice becomes part of them. So record, per product function, what the system performs and what it expressly leaves to the operator, because that distinction carries your entire classification and is hard to reconstruct after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-smals-rolprofielen-en-projectstart","legacy_id":"raip:example:example-smals-rolprofielen-en-projectstart","type":"example","slug":"example-smals-rolprofielen-en-projectstart","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"23fb87bc7f14d8f5925f1e94862a3ea39a7c494853a75a2c5c5b57bbc4723f04","label":"Role profiles and a kick-off session per AI project at a public sector IT provider","summary":"Smals, which supplies IT to Belgian public administrations, describes the knowledge each role needs: all staff know capabilities, limits and internal guidelines, AI ambassadors spot and prioritise use cases, AI experts know governance and technique, and legal staff and the data protection officer get separate deep dives. Before every new AI project there is also a session for all stakeholders on the capabilities, limits, risks and governance of that specific system.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In the repository, first look for practices from organisations that resemble yours in sector, size and role as provider or deployer, before choosing a setup for your own staff.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","source_locator":"Living repository of AI literacy practices, practice submitted by the organisation concerned","source_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-spamfilter-gelabelde-e-mail","legacy_id":"raip:example:example-spamfilter-gelabelde-e-mail","type":"example","slug":"example-spamfilter-gelabelde-e-mail","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1411c9d87110551bba4d5d08451f8c3763a13949ed89ec5750f7718f43a2e14a","label":"Spam filter trained on labelled email","summary":"An organisation adopts an email filter that was trained during its building phase on a set of messages humans labelled as spam or not spam. Once in use, the filter independently assesses new incoming email and classifies it based on the patterns it learned.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A recognisable learning pattern in your system yields no ready made qualification, because the guidelines ask you to assess the specific architecture and functionality against all seven elements of Article 3(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-spellingcorrectie-versus-ai-samenvatting","legacy_id":"raip:example:example-spellingcorrectie-versus-ai-samenvatting","type":"example","slug":"example-spellingcorrectie-versus-ai-samenvatting","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"34695663784b66c47375e24451a84fbfaa83ccdef6acf03f04a06b2691a06233","label":"Spell checking needs no marking, an AI summary does","summary":"A publisher uses the same AI tool for two things: correcting spelling and cleaning up formatting in submitted pieces, and producing summaries and rewrites of those same pieces.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception attaches to the function and not to the tool, so assess per use whether meaning, style or structure changes and mark only the outputs where it does.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-statische-schatting-servicedesk-en-winkel","legacy_id":"raip:example:example-statische-schatting-servicedesk-en-winkel","type":"example","slug":"example-statische-schatting-servicedesk-en-winkel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cc82501c8752239bc269f5a5f8543c76fb77cf20d7c59eece7f51a5cc8cc160d","label":"Static estimation of resolution time and daily sales","summary":"A service desk shows customers an expected resolution time calculated as the mean from historical tickets. A retail chain uses a trivial predictor to estimate how many units of a product it will sell each day, as a starting point for purchasing planning.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Keep testing whether your estimate really does no more than return an average, because as soon as you build in more complex relationships you lose the basis for this exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-synthetische-avatar-van-de-ceo","legacy_id":"raip:example:example-synthetische-avatar-van-de-ceo","type":"example","slug":"example-synthetische-avatar-van-de-ceo","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0d7922e086836f953958dcd7514950c9f43c5ae02a17d6d5e796d639a079642a","label":"A synthetic avatar of your own CEO is a deep fake","summary":"A company has a realistic synthetic avatar of its own CEO deliver a new year message thanking employees for last year's results. The video goes to the intranet and to the company's social media channels.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The final Commission guidelines on Article 50 treat this case as a worked example under the transparency obligations. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Consent from the executive depicted and a benign purpose are irrelevant because the test is objective, so apply a visible or audible label to the video before it is distributed.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, worked examples under Article 50","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-toelating-hogeschool-registratie-eu-databank","legacy_id":"raip:example:example-toelating-hogeschool-registratie-eu-databank","type":"example","slug":"example-toelating-hogeschool-registratie-eu-databank","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3d53527e1fe64875c7712e50282816d365b64c9b924e3a6965b22cf6c50a7dff","label":"Admission system at a higher education institution: who registers in the EU database","summary":"A higher education institution procures an AI system that organises student applications and enrolment and produces an admission recommendation for each candidate in its vocational programmes. The supplier says it handles the conformity assessment itself and affixes the CE marking. What is left unresolved is whether the institution still has a step of its own to take before the system goes into use in its teaching.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 43(2) provides that for high-risk AI systems referred to in points 2 to 8 of Annex III, providers follow the conformity assessment procedure based on internal control set out in Annex VI, which does not provide for the involvement of a notified body. Article 47(1) requires the provider to draw up, for each high-risk AI system, a written machine-readable, physical or electronically signed EU declaration of conformity and to keep it at the disposal of the national competent authorities for ten years after the system has been placed on the market or put into service. Article 49(1) requires the provider or, where applicable, the authorised representative to register themselves and their system in the EU database referred to in Article 71 before an Annex III high-risk system is placed on the market or put into service, with the exception of the systems listed in point 2 of Annex III. Article 49(3) provides that deployers that are public authorities or Union institutions, bodies, offices or agencies, or persons acting on their behalf, register themselves, select the system and register its use in that same database before putting such a system into service or using it, again with the exception of the systems listed in point 2 of Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(2), Article 47(1) and Article 49(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"We read Article 49 as two separate registrations: paragraph 1 covers the provider and its system, paragraph 3 covers your own use, and on that reading the first does not relieve you of the second. The hinge question for the institution is therefore not whether the supplier does its job, but whether it is a public authority within the meaning of paragraph 3. The Regulation does not define that term, and until that is settled it remains open whether the institution must itself appear in the EU database. In practice we would move the request for the EU declaration of conformity and the registration number into the procurement stage, so that the question does not turn into a blocker just before an application period opens.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(2), Article 47(1) and Article 49(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-triage-spoedeisende-hulp","legacy_id":"raip:example:example-triage-spoedeisende-hulp","type":"example","slug":"example-triage-spoedeisende-hulp","version":"1.0.0","effective_at":"2026-05-19T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"62d16510c753780018aa9840884d802dfdc1b68e969a525fc0d205fdd486c3f3","label":"Emergency triage system: two routes to high risk","summary":"A hospital uses AI to prioritise incoming patients at the emergency department. The question is not whether the system is high-risk but by which route: as a medical device under product legislation, or directly under Annex III.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 state that an emergency healthcare patient triage system may qualify as a medical device; where it then meets Article 6(1), it is high-risk via Annex I and sectoral rules apply. A triage system that is not a medical device is high-risk via Article 6(2) and point 5(d) of Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (334) and (335)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"First establish whether your triage system is a medical device, because that question decides the whole route: via Annex I the assessment travels with the medical conformity assessment and its date, via Annex III the separate timeline of Article 6(2) applies. Either way the outcome is high-risk, so postponing that determination only creates uncertainty about which regime to set up.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (334) and (335)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-veiligheidscomponent-elektriciteitsnet","legacy_id":"raip:example:example-veiligheidscomponent-elektriciteitsnet","type":"example","slug":"example-veiligheidscomponent-elektriciteitsnet","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"999c2c1b6e1f5f82c4228179194f60799f489e21ca8e908f818183f96d2bdf5a","label":"Two AI systems at one grid operator, two regimes","summary":"A grid operator uses an AI model that automatically balances load and disconnects parts of the electricity network to prevent outages. The same organisation also runs a chatbot that helps customers with billing questions.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Map your AI function by function rather than organisation-wide, because only systems that directly protect the physical integrity of the infrastructure are safety components, while supportive and customer-facing tools fall outside.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-verkoopdashboard-beschrijvende-analyse","legacy_id":"raip:example:example-verkoopdashboard-beschrijvende-analyse","type":"example","slug":"example-verkoopdashboard-beschrijvende-analyse","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e61b71a0487403e6ed06fb28cd204f5735f1f9862c9c3301ef6700a849fcaa5c","label":"Sales dashboard that summarises but recommends nothing","summary":"A commercial team uses reporting software that applies statistical methods to calculate total sales, average sales per region and trends over time, and displays them in charts. The dashboard makes no suggestion about how to improve sales or which products to promote.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"If your dashboard did start making suggestions, that alone would not turn it into an AI system, since the guidelines state that non-AI systems can generate recommendations as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","source_locator":"Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-webshop-kredietcheck-technisch-dossier","legacy_id":"raip:example:example-webshop-kredietcheck-technisch-dossier","type":"example","slug":"example-webshop-kredietcheck-technisch-dossier","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d78a5fb746a80b877e3392af6e2f5baa03e844e1777db2c3b305ccb327eb0704","label":"Webshop builds its own consumer credit check: what belongs in the file","summary":"A non-food retail chain lets customers pay later in its webshop and decides at checkout whether a consumer qualifies. The team builds that assessment system in house, on top of a pre-trained model supplied by a vendor. The question is what has to be on record before the feature goes live, and who has to put it there.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 11(1) requires the technical documentation of a high-risk AI system to be drawn up before that system is placed on the market or put into service, and to be kept up to date. It must be drawn up so as to demonstrate compliance with the requirements of that Section and to give national competent authorities and notified bodies the necessary information, in a clear and comprehensive form, to assess that compliance; it contains at a minimum the elements set out in Annex IV. Annex IV lists those elements as applicable to the AI system concerned, and asks among other things for the methods and steps performed for development, including, where relevant, recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified by the provider, for the validation and testing procedures used, and for a description of relevant changes made by the provider to the system through its lifecycle. SMEs, including start-ups, may supply those elements in a simplified manner; where they take that route, they must use the simplified form the Commission is to establish for that purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 11 puts the documentation duty on the provider, so the first open question here is who that provider is. If the creditworthiness assessment of consumers counts as high-risk in your situation, then in our reading there is a strong case that a webshop assembling the system itself and putting it into service under its own name is no longer merely a deployer but ends up on the provider side, carrying the documentation duty that comes with it. Article 11 does not settle that allocation of roles, so test it against the definitions and against Article 25 before assuming the file is your vendor's problem. In our reading the hard part in retail is not the first version of the file but the pace afterwards, because a webshop often ships changes per release while the file stays frozen at the state it had when the feature went into service. So contract for the provenance, training and testing information that Annex IV expects from you when you buy the pre-trained model, and assign per release who updates the file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"editorial","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:example:example-welzijnschatbot-riskante-adviezen","legacy_id":"raip:example:example-welzijnschatbot-riskante-adviezen","type":"example","slug":"example-welzijnschatbot-riskante-adviezen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9ac5d75a669107312143c6be24979e75112619f63fcccb230eb8bf27c15910bc","label":"Well-being chatbot pushes users toward dangerous behaviour","summary":"A provider markets an AI chatbot meant to help users maintain a healthy lifestyle, with tailored advice on exercise and mental rest. In practice the chatbot exploits individual vulnerabilities and pushes people into dangerous habits, such as excessive sport without rest or water.","topics":["examples"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Good intentions offer no protection: once a system can foreseeably push users toward serious harm and no preventive or mitigating measures were taken, the prohibition applies even without intent.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","source_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-4-no-mandatory-course-or-certificate","legacy_id":"raip:guidance:guidance-article-4-no-mandatory-course-or-certificate","type":"guidance","slug":"guidance-article-4-no-mandatory-course-or-certificate","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8e07dd9efd3545029344dab517fe03c043b41d3bb1e72327c553bd9f48dc126b","label":"No mandatory course format, no certificate, no exam and no AI officer","summary":"Article 4 prescribes no form. The Commission confirms that no certificate is required, no obligation to measure knowledge exists, no training is mandatory and no governance structure is prescribed.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-4-no-mandatory-course-or-certificate-scope","operator":"all","description":"Applies to providers and deployers of AI systems, who take measures to support AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf."}],"exceptions":[{"id":"guidance-article-4-no-mandatory-course-or-certificate-exception","operator":"not","description":"For deployers of high-risk AI systems, a separate obligation under Article 26 will apply in addition, requiring them to ensure that staff working with the system are sufficiently trained to handle it and ensure human oversight. That duty goes beyond Article 4, but it does not apply yet: it becomes applicable on 2 December 2027 for standalone high-risk systems under Annex III and on 2 August 2028 for high-risk systems embedded in products under Annex I."}],"statements":[{"kind":"official_fact","text":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This guidance cuts both ways and both are abused. The supply side of the market sells certificates and exams as a legal requirement: that is demonstrably wrong, because the Commission states literally that no certificate is needed and that there is no obligation to measure knowledge. The other side is the organisation that concludes from the same answer that nothing is required. That is equally wrong. In the same Q&A the Commission says that merely forwarding the instructions for use might be ineffective, and it expects a reasoned choice based on your role, your risks and your people's knowledge gaps. The correct reading is therefore: no prescribed format, but a demonstrable measure. That makes the internal record named in the Q&A the practical heart of your file. And note the nuance about technical staff: a data scientist is not automatically done, because the organisation must still verify that this person knows its own systems and the associated risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Stop steering on certificates and steer on a demonstrable, reasoned measure. Record what you did, for which groups, why that format fits their role and the risks of the systems they use, and keep a simple internal record as the Q&A suggests. Differentiate by role rather than giving everyone the same module, and include your technical staff with a specific component on your own systems and risks. Replace the mere forwarding of instructions for use with something that is demonstrably read and understood.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-4-scope-and-enforcement","legacy_id":"raip:guidance:guidance-article-4-scope-and-enforcement","type":"guidance","slug":"guidance-article-4-scope-and-enforcement","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"254d354a849f9911e88468cf6c6729b1306cfe0a77bcec4a4cf765a8628cc132","label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","summary":"The duty to take measures also covers contractors, service providers and sometimes clients. Supervision lies not with the AI Office but with national market surveillance authorities, enforcing since 2 August 2026.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-4-scope-and-enforcement-scope","operator":"all","description":"Applies regardless of place of establishment, as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the Union."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things are consistently underestimated here. The first is the circle of people. Many organisations translate Article 4 into a staff programme and forget the seconded workers, the call centre, the implementation agency and the freelancers who use the same systems daily. The Q&A expressly widens that circle to everyone within the organisational remit, and even leaves the door open to clients where the risk calls for it. The second is who will come knocking. Because the AI Office gets all the attention, organisations assume Article 4 is a Brussels file. It is not: this runs through the national market surveillance authority. The most useful sentence for your own prioritisation is that a sanction is more likely where there is proof of an incident caused by a lack of appropriate training and guidance. Enforcement will therefore rarely start with a spot check on your training plan, and far more often with an incident after which the question becomes whether the person involved was prepared. That makes the file reactively useful, and therefore worth having in order now.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Extend your target list from permanent staff to everyone working with your AI systems under your direction, including contingent workers, contractors and implementation partners, and write that expectation into your procurement and hiring terms. Assess per system whether clients or affected persons also need an explanation of how AI-assisted decisions affect them. Structure your records so that after an incident you can show within a day which measures the person involved had received and when. Finally, establish which national market surveillance authority is competent for you, because that is your counterpart, not the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 4 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-ai-agent-self-disclosure","legacy_id":"raip:guidance:guidance-article-50-ai-agent-self-disclosure","type":"guidance","slug":"guidance-article-50-ai-agent-self-disclosure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1169f3717da19ed6a14a80d5af186da930548a1825b628884c181c5f30a28762","label":"AI agents must disclose both their AI nature and on whose behalf they act","summary":"An AI agent that makes bookings, handles correspondence or concludes contracts must identify itself as AI and state on whose behalf it is acting, including towards the person instructing it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-ai-agent-self-disclosure-scope","operator":"all","description":"Applies as soon as the agent is capable of interacting with the person instructing it or with other natural persons in the execution of the task."}],"exceptions":[{"id":"guidance-article-50-ai-agent-self-disclosure-exception","operator":"not","description":"Purely machine-to-machine communication between agents whose outputs are not intended to reach a natural person falls outside the disclosure duty of Article 50(1), and intermediate reasoning steps and non-perceptible actions fall outside the marking duty of Article 50(2)."}],"statements":[{"kind":"official_fact","text":"Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Here the guidelines go further than most organisations expect. The obligation is twofold: not only 'I am AI', but also 'I act on behalf of this party'. That turns agentic email, procurement and negotiation into a design question rather than a line in a footer. Two things are systematically missed. First, the disclosure duty also runs towards your own instructing party, at key steps such as authorisation and validation, and particularly where the agent builds on outputs from other AI systems rather than on human input. Second, the provider's uncertainty resolves nothing: if the provider cannot determine in advance whether the agent will reach a human, the answer is not 'then it does not apply' but 'then you build the disclosure into the architecture by default'. An agent that stays quiet until it is certain a human is reading is not what is intended.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat your agent's disclosure as an architecture requirement, not a prompt instruction that can be overridden per task. Ensure every outbound channel of the agent, meaning email, chat, telephony and forms, carries both the AI origin and the instructing organisation by default. Also build confirmation moments towards your own user at authorisation, reporting and validation, and flag explicitly there when the agent is building on output from another AI system. Finally, mark the perceptible content the agent produces in line with Article 50(2), but not the internal reasoning steps.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-artistic-attenuated-disclosure","legacy_id":"raip:guidance:guidance-article-50-artistic-attenuated-disclosure","type":"guidance","slug":"guidance-article-50-artistic-attenuated-disclosure","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2a6556bdda279577904e1a80ab7717e80a0a64056312645e38596a105deabf05","label":"Artistic or satirical work is not exempt but attenuated, and the informative character always prevails","summary":"For deep fakes in evidently artistic, creative, satirical or fictional work, the disclosure must not hamper the work, but it remains mandatory. Where the content mixes in an informative or commercial character, the standard label applies.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-artistic-attenuated-disclosure-scope","operator":"all","description":"The deep fake must evidently form part of an artistic, creative, satirical, fictional or analogous work or programme, assessed case by case by the deployer."}],"exceptions":[{"id":"guidance-article-50-artistic-attenuated-disclosure-exception","operator":"not","description":"Where content combines multiple characters, the informative character always prevails and the standard labelling requirements apply; content that is exclusively informative or commercial and recognisable as such, such as news reporting, falls outside the lighter regime."}],"statements":[{"kind":"official_fact","text":"Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two misconceptions dominate here. The first is that 'creative work' is an exemption. It is not: you must still disclose, only in a way that does not ruin the work, for example in the credits, in an accompanying notice, or at the start of the video rather than as a permanent block across the image. The second misconception is more serious and hits marketing directly. Advertising is not automatically creative work. The guidelines cite teleshopping-style videos and synthetic influencers demonstrating a product precisely as examples falling outside the category, and further state that where characters mix, the informative one always prevails. So anyone making a funny, clearly stylised campaign that also carries a product claim falls back on the standard label. Finally, note the evidence requirement: if the audience could doubt whether it is seeing satire or real news, it is by definition not evident and the lighter regime does not apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess per production whether the work is unmistakably artistic, satirical or fictional for your audience, and briefly record that assessment against the three factors in point (122): stylistic features, publication context and audience expectation. For campaigns and commercial video, default to the standard label and rely on the lighter regime only in rare cases. For evidently creative work, choose a disclosure that leaves the work intact, for example at the start or in the credits, bearing in mind that the information must be clear and distinguishable and that people joining later must also be able to perceive it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-code-of-practice-effect","legacy_id":"raip:guidance:guidance-article-50-code-of-practice-effect","type":"guidance","slug":"guidance-article-50-code-of-practice-effect","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f7e48914cd44ef9874aef29ccdbd4580232937021d6c4a85de660ca6ae24ce8d","label":"Signing the code of practice is voluntary, but not signing means proving it yourself","summary":"Signing the code of practice on transparency of AI-generated content is voluntary and not signing is not in itself non-compliance. Those who do not sign must demonstrate compliance by other means, including a gap analysis against the code.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-code-of-practice-effect-scope","operator":"all","description":"Applies to providers and deployers of generative AI systems within the scope of Article 50(2) and (4)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content states that signing is voluntary and that not signing does not constitute non-compliance with the AI Act. That same Q&A states that the code has two sections, one for providers on marking AI-generated or manipulated content in machine-readable formats and the related detection mechanisms, and one for deployers on the disclosure and labelling of deep fakes and of certain AI-generated or manipulated text on matters of public interest. It further states that signatories may, subject to a positive assessment by the Commission and the AI Board, rely on the code to demonstrate compliance with their obligations under Article 50 regardless of their place of establishment, and that the deadline for inclusion in the initial list of signatories was 27 July 2026 at 18:00 CEST, with later signature remaining possible but not appearing on that initial list. The Commission guidelines of 20 July 2026 state in point (146) that providers and deployers within the scope of Article 50(2) and (4) may demonstrate compliance by adhering to a code of practice assessed as adequate under Article 50(7), and that such a code does not replace the Regulation or the guidelines but complements them as the only Union-wide recognised practical framework for that purpose. Point (147) states that compliance may also be demonstrated through other adequate means, that for signatories supervisory activities will focus on whether they have adhered to the code and implemented the measures it contains, and that opting out of sections results in losing the benefit of facilitated demonstration of compliance for that part. Point (148) states that non-signatories are expected to demonstrate through other adequate means how they comply with Article 50(2), (4) and (5) and to explain how their measures ensure compliance, for instance by carrying out a gap analysis comparing their measures with those set out in a code assessed as adequate, and that they will likely face more requests for information and for access. Point (149) states that competent authorities may take commitments implemented in line with a code assessed as adequate into account as a mitigating factor when setting the amount of fines. Point (150) states that if a code is not deemed adequate, the Commission may adopt an implementing act specifying common rules for the implementation of Article 50(2), (4) and (5).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The voluntariness is real, but it is not free. The guidelines shift the burden of proof: signatories are assessed on whether they do what the code says, non-signatories must explain why their own approach suffices. That difference translates into work. Point (148) expects non-signatories to run a gap analysis against the code, which means you have to read the code and benchmark your measures against it either way. Not signing therefore saves you the signature, not the substance. On the other side, point (149) explicitly names adherence in line with the code as a mitigating factor for fines, which makes the code commercially interesting for parties producing large volumes of generated content. Finally, note the opt-out rule: partial signature is possible, but for the sections you skip you fall back into the heavier evidential position. For anyone who missed the initial list, signature remains open; only the listing on that first list has passed.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Decide deliberately whether to sign and record the reasoning. If you do not sign, still carry out the gap analysis named in point (148) and keep it as the core of your file, together with a description of how your own measures cover Article 50(2), (4) and (5). Account for the fact that as a non-signatory you may receive more information and access requests, and structure your documentation accordingly. If you sign but opt out of sections, treat those sections as a non-signatory would and document them separately.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.1, points (146) to (150); Commission Q&A on signing the Code of Practice on Transparency of AI-generated Content (consulted 9 August 2026)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-deployer-perceivable-labelling","legacy_id":"raip:guidance:guidance-article-50-deployer-perceivable-labelling","type":"guidance","slug":"guidance-article-50-deployer-perceivable-labelling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"85008088c20a5e3f90ddaa51118c0e8e86353a579c51168dd58a2f274d497f9e","label":"The deployer cannot rely on the provider's machine-readable marking","summary":"Whoever publishes a deepfake must apply a label perceivable by humans. The watermark or metadata supplied by the provider does not discharge that duty.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-deployer-perceivable-labelling-scope","operator":"all","description":"Applies to deployers of AI systems that generate or manipulate deep fakes in the form of image, audio or video content."}],"exceptions":[{"id":"guidance-article-50-deployer-perceivable-labelling-exception","operator":"not","description":"An attenuated form of disclosure applies to deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works, and an exception applies to use authorised by law to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (117) of the guidelines of 20 July 2026 states that deployers of AI systems generating or manipulating deep fake content must clearly and distinguishably disclose that the content has been artificially created or manipulated, by labelling the output accordingly and disclosing its artificial origin. According to that same point, the labelling or disclosure methods used must be understandable and perceivable by natural persons, for example with visible or audible labels, without those persons needing to rely on any specific technical tools or performing dedicated actions. The point closes expressly by stating that deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2), since those markings are not immediately clear and distinguishable for the natural persons exposed to the deep fake content. Point (12) adds that deployers involved in complex content production and distribution value chains must take proportionate measures to ensure that the labelling they have implemented under Article 50(4) is actually displayed in a clear and distinguishable manner to the targeted and foreseeable audience at the point of first exposure, for example via contractual conditions with distributing partners and via user experience settings and interfaces. Point (14) states that a legal person remains the deployer even where it involves third parties such as contractors or freelancers in the operation of the system on its behalf and under its authority, and that individual employees acting under its instructions and control are not considered separate deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the sharpest role confusion in the whole transparency chain. Provider and deployer carry two different duties aimed at two different audiences: the provider marks machine-readably for systems and supervisors, the deployer labels perceptibly for humans. The common error is that a marketing department or agency assumes the generated image is 'already marked' by the tool and that nothing further is needed at publication. That is wrong. Equally important is how the duty travels down the chain: it does not end with applying the label, but with whether the audience actually sees the label at first exposure. If your label disappears because a platform re-encodes, crops or auto-plays the video without the opening title, the label formally exists but functionally does not. That is why the guidelines expressly name contractual arrangements with distribution partners as a means. And note the last sentence of point (14): you do not pass the deployer role on to the agency or freelancer producing the content for you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add a separate step to your publication process in which a label visible or audible to humans is applied to deep fake content, independent of whatever the generation tool writes into the files. Verify per distribution channel that the label is still visible at first contact after uploading, re-encoding and auto-play. Write the labelling requirement into your terms with agencies, production partners and distribution platforms, and do not assume that engaging an external agency moves the deployer role.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 6.1.2 point (117) and Section 2.3 points (12) and (14)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-disclosure-timing","legacy_id":"raip:guidance:guidance-article-50-disclosure-timing","type":"guidance","slug":"guidance-article-50-disclosure-timing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1d84d58420f8a24a1d13d7b31bea51d92ef06ea18d81146ab84a1a1964afde98","label":"Disclosure at the latest at first interaction, and again for every new person","summary":"The notice that a person is dealing with an AI system must be given at the latest at the time of the first interaction. That moment applies per natural person, not once per system.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-disclosure-timing-scope","operator":"all","description":"Applies to providers of AI systems intended to interact directly with natural persons, and through the horizontal requirements of Article 50(5) to all notices under Article 50(1) to (4)."}],"exceptions":[{"id":"guidance-article-50-disclosure-timing-exception","operator":"not","description":"The information obligation falls away if the interaction is obvious to a reasonably well-informed, observant and circumspect person, or if the system is authorised by law to detect, prevent, investigate or prosecute criminal offences, unless the system is available to the public to report a criminal offence."}],"statements":[{"kind":"official_fact","text":"The final Commission guidelines of 20 July 2026 (C(2026) 5054 final) state in point (33) that the notification mechanism must be embedded in the design of the system and that the notice must be provided during operation of the system and at the latest at the time of the first interaction with the natural person, as required by Article 50(5). Point (143) clarifies that 'first interaction or exposure' refers not only to the first person who encounters the system, but also to any subsequent first interaction with or exposure to the system by any other natural person. For an interactive system, the information must be provided at least once at the start of an interactive session. For content under Article 50(2) and (4), the information obligation applies to each output with respect to any natural person exposed to it. Point (40) adds that a single prominent notification before the first interaction is likely to suffice in most instances, but that in riskier contexts periodic reminders and context-aware disclosures are likely to be necessary, in particular for vulnerable persons, sustained or immersive interactions, financial, insurance, legal or health advice and complaints handling, and AI companions. That same point requires the system to be designed so that it always discloses where it is asked about its nature or the origin of the interaction, or where it can reasonably be assumed from the exchange that the person is likely to be misled or confused about the AI origin.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The trap is the word 'first'. Many organisations read it as a one-off announcement when the chatbot launches, or as a line in a welcome email that every visitor is assumed to have seen. The guidelines read it as an obligation that arises anew for each natural person who encounters the system or its output for the first time. A second common error is assuming that a notice at the start of the session covers the whole customer journey. If the role of the system changes mid-session, or the interaction is long and concerns money, health or law, the Commission expects repetition. The third trap is letting the system dodge the question when a user directly asks whether they are speaking to a human. That is not permitted: the question must always be answered honestly, whatever notice was given earlier.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document for each customer contact channel at what moment the notice appears, and test it with a fresh session from a new device so you see what a first-time visitor sees rather than what a logged-in employee sees. Also build a hard rule into the system prompt or conversation logic that forces the system to confirm its AI origin as soon as it is asked or as soon as the user addresses it as a human. Finally, decide for your higher-risk channels, such as financial advice, claims handling, care and complaints, whether a single opening notice suffices or whether you need a persistent label or periodic reminders, and record that assessment in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026, Section 3.1.2 points (33) and (40), and Section 7.2 point (143)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-editorial-control-exception","legacy_id":"raip:guidance:guidance-article-50-editorial-control-exception","type":"guidance","slug":"guidance-article-50-editorial-control-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a7748691ed1b2ac94d7c41e397695219b2575d4d9c2404df7917bc6a98623657","label":"The editorial exception: substantive review plus an identifiable responsible person","summary":"No label is needed where the AI text has been substantively reviewed by a human and someone holds editorial responsibility. A spellcheck or a written editorial policy is not enough, and any AI intervention after sign-off voids the exception.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-editorial-control-exception-scope","operator":"all","description":"Both conditions must be met together: substantive human review or editorial control, and an identifiable natural or legal person holding editorial responsibility for the publication."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Point (133) of the guidelines of 20 July 2026 sets two cumulative conditions: the AI-generated or manipulated text must have undergone human review or editorial control, and a natural or legal person must hold editorial responsibility for the publication. Point (134) describes human review as the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement on the subject matter, citing academic peer review and professional validation chains as examples, and states that fact-checking the accuracy of the content is a minimum requirement that must form part of that review. Editorial control is described in that same point as the control exercised in practice by a responsible editorial entity, for example an editor-in-chief, with the authority to approve, alter or reject the substance of the text on substantive grounds, including fact-checking and ensuring the trustworthiness of sources. Point (135) states that superficial, solely formal or procedural checks such as spell-checking or grammatical correction, the mere existence of an editorial policy, automated review processes, and cursory editorial approval without substantive engagement by the human reviewer or the editorial entity cannot fulfil the conditions. Point (136) states that where AI systems are used to modify, supplement or reformulate content following editorial sign-off, the resulting content must be treated as AI-generated or manipulated, and that any substantive AI intervention occurring after the human review or editorial control will cause the exception to become void. Point (138) states that the person holding editorial responsibility must hold the ultimate responsibility over the publication, including the human review or editorial control, and that the identity and contact details of that legal person, natural person or function should be made publicly available in an easily findable location, online for example through a website's terms and conditions or other user-facing legal information, offline for example in a colophon. As examples meeting the conditions the document cites among others an AI-manipulated newspaper article or AI-generated summary subject to the editorial control of the editor-in-chief, an AI-manipulated academic blog that has undergone internal peer review, AI-generated public safety warnings approved by a public official, and AI-generated sustainability reports reviewed by professionals in relevant functions. As examples failing the conditions the document cites a website where AI-generated articles on Union policy are posted without any deliberate human review, and AI-generated articles reviewed and edited by another AI system where a human editor performs a mere superficial grammatical check before publication.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This exception is why most newsrooms and communications departments do not have to label, but it is narrower than it looks. Three pitfalls. First, sequence: many organisations have the text approved and then let an AI tool 'polish it a bit' for SEO, length or tone. Point (136) states literally that any substantive AI intervention after sign-off voids the exception. The AI step must therefore come before the human review, not after it. Second, depth: it must be deliberate examination of the substance with fact-checking as a minimum. An editor who only reads for flow does not qualify, and an AI reviewing another AI certainly does not. Third, visibility: it must be publicly findable who holds editorial responsibility. A colophon or a clear statement in the site's legal information is not a formality but a condition of the exception. Notably, the guidelines expressly place this exception outside the media as well, citing sustainability reports and government warnings. Your compliance or communications function can therefore act as the reviewer, provided the review is genuinely substantive.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Always place your AI step before human approval in the workflow, and technically block any AI edit running after sign-off, including automatic SEO optimisation or shortening. Record per publication stream who performs the substantive review, that fact-checking forms part of it, and who holds editorial responsibility. Publish that responsible function or person with contact details in an easily findable location, for example in the colophon or with the site's legal information. Keep a short record per publication of who reviewed the substance and when, so you can substantiate reliance on the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.3, points (133) to (138) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-insufficient-disclosure-methods","legacy_id":"raip:guidance:guidance-article-50-insufficient-disclosure-methods","type":"guidance","slug":"guidance-article-50-insufficient-disclosure-methods","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a61216744fea363ea209be6924027e8a4cc59cac559a7cc92505d51bc300c12c","label":"What does not suffice on its own as an AI disclosure","summary":"A line in the terms and conditions, a hidden metadata mark or a vague word like 'assistant' will not do. The guidelines name five methods that are insufficient when used alone.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-insufficient-disclosure-methods-scope","operator":"all","description":"Applies to every disclosure under Article 50, because Article 50(5) requires information to be provided in a clear and distinguishable manner and to conform to applicable accessibility requirements."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Point (38) of the guidelines of 20 July 2026 lists techniques that are not necessary and that, when used alone, are insufficient to satisfy Article 50(1) and (5). These are: disclosures contained only in terms and conditions, URLs or documentation, with the document adding that such disclosures may complement but not replace in-context disclosure; machine-readable markings such as metadata or watermarks that are not perceivable by users at the point of interaction, which does not affect their appropriateness for Article 50(2); unclear or ambiguous signals, with the document expressly naming a generic reference to 'assistant', and human-like representations that may mislead users; generalised disclosures that are not sufficiently specific to the system's outputs and interactions, with the document citing as inadequate a statement on a platform offering a variety of services that 'Services on this website use AI'; and technical or capability-based descriptions referring solely to the underlying technology, such as 'this system uses LLMs', without explaining the function or the implications for the user and the artificial origin. Point (142) adds that information is not clear and distinguishable where it can be easily overlooked or missed under normal exposure or interaction conditions, for example where it is included only in a manual, hidden under layers of menu options in an online interface, or part of terms of use that users often do not read.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the list that topples most existing implementations. Three patterns occur structurally and all three fail. First, the legal cover: a line in the terms and conditions or privacy statement saying the organisation uses AI. Second, the technical cover: the argument that the output carries a C2PA mark or watermark and that the user is therefore informed. The guidelines keep those two tracks strictly separate, because a machine-readable mark counts for Article 50(2) but not as a disclosure to the human. Third, the brand-driven cover: giving the chatbot a friendly name and calling it 'your digital assistant'. That precise formulation is named as an example of an ambiguous signal. The popular generic site-wide banner stating that the site uses AI is likewise explicitly labelled insufficient, because it is not specific enough to the actual output.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory where your current AI disclosure sits. If it lives only in the terms and conditions, the privacy statement, a cookie banner or a help page, it does not comply and must move into the interaction itself, close to the input and output field. Replace phrasings such as 'digital assistant' or 'virtual colleague' with an explicit statement that this is an AI system. Keep the machine-readable marking in place for Article 50(2), but do not count it towards the disclosure to the user.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.2 point (38) and Section 7.1 point (142)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-legacy-content-and-transition","legacy_id":"raip:guidance:guidance-article-50-legacy-content-and-transition","type":"guidance","slug":"guidance-article-50-legacy-content-and-transition","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"146b27c7c1ab9d757ed27e3a5f541df95650dc136ed86e5a6a564606636b6b15","label":"Existing systems and legacy content: what does and does not apply retroactively","summary":"Only the machine-readable marking under Article 50(2) has a transitional period for systems already on the market. Legacy content need not be labelled retroactively, but legacy text you publish now must be.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-legacy-content-and-transition-scope","operator":"all","description":"The transitional period to 2 December 2026 applies only to the marking and detection obligation of Article 50(2) and only to generative systems placed on the market or put into service before 2 August 2026."}],"exceptions":[{"id":"guidance-article-50-legacy-content-and-transition-exception","operator":"not","description":"Content generated or manipulated before 2 August 2026, and text on matters of public interest generated and published before that date, need not be marked or labelled retroactively."}],"statements":[{"kind":"official_fact","text":"Point (153) of the guidelines of 20 July 2026 states that under Article 113, Article 50 applies from 2 August 2026 and that all in-scope AI systems placed on the market or put into service in the Union must comply on that date, regardless of their date of placing on the market or putting into service. That same point describes that the regulation amending the AI Act provides a targeted transitional rule concerning only the marking and detection obligations under Article 50(2) for generative AI systems placed on the market or put into service before 2 August 2026, giving providers of those existing systems a transitional period to bring them into conformity by 2 December 2026. Point (153) states expressly that systems that are partly interactive and partly generative may benefit from that transitional period only with regard to the marking obligation under Article 50(2), while compliance with the disclosure obligation for AI systems directly interacting with natural persons must be ensured as of 2 August 2026. Point (154) states that AI-generated or manipulated outputs within the scope of Article 50(2) and deep fakes within the scope of Article 50(4), first subparagraph, generated or manipulated before 2 August 2026 do not need to be marked or labelled retroactively, and that the same applies to texts on matters of public interest that were AI-generated or manipulated and published before that date. That same point states conversely that texts generated or manipulated before 2 August 2026 but published on or after that date must be labelled. Point (154) adds that deployers and other actors in possession of or disseminating pre-existing unlabelled deep fakes are nonetheless encouraged to label them, without being expected to engage in disproportionate efforts such as auditing pre-existing content databases or modifying already printed product packaging. A footnote to point (153) clarifies that the special grandfathering rule of Article 111(2) for high-risk AI systems does not extend to Article 50, because the high-risk obligations and the transparency obligations apply cumulatively.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things get conflated here. The first is the assumption that the transitional period to 2 December 2026 is a general postponement of Article 50. It is not: it covers only the machine-readable marking and detection of Article 50(2). If your system also runs a chat interface, the disclosure to the user had to be in place on 2 August 2026, even though marking of the output may wait until December. The second is the assumption that legacy content is safe. That holds for already published content, but not for your stock. If you had a batch of AI texts produced last year and are only publishing them now, the labelling duty does apply. The same goes for a campaign visual that has been sitting on the shelf for months. Practically, the distinction is not old versus new, but the moment of publication. The encouragement to label pre-existing deep fakes is not a duty, but it is where a supervisor can look at the reasonableness of your choices.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Split your inventory into three: systems interacting directly with people, which have had to disclose since 2 August 2026; generative systems relying on the transitional period to 2 December 2026 for machine-readable marking; and systems doing both, which therefore carry a different date per obligation. Also walk through your content stock: anything still to be published that was AI-generated or substantially edited gets a label at publication, regardless of when it was generated. Record why you are not retroactively labelling already published legacy content, so you can explain that choice.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 8.4, points (153) and (154)","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-obvious-ai-exception","legacy_id":"raip:guidance:guidance-article-50-obvious-ai-exception","type":"guidance","slug":"guidance-article-50-obvious-ai-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a34d3634aef745e469063ab8eeb951a82a032352c34867233c8af9df969b3583","label":"When is AI obvious? The exception applies only where almost no doubt remains","summary":"The exception for obvious AI interaction must be interpreted restrictively. It applies only where almost no doubt remains for an average member of the intended and reasonably foreseeable audience.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-obvious-ai-exception-scope","operator":"all","description":"Assessment per system and per context of use, to be carried out and documented by the provider."}],"exceptions":[{"id":"guidance-article-50-obvious-ai-exception-exception","operator":"not","description":"This exception does not release you from the information obligations under EU consumer protection law: the guidelines state that those obligations apply irrespective of whether the interaction is considered obvious under Article 50(1)."}],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 20 July 2026 place on the provider, in point (42), the burden of assessing and demonstrating the obvious artificial nature of the interaction to a person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. Point (43) anchors that standard in the notion of the 'average consumer' in EU consumer protection law. Point (44) prescribes a two-step assessment: first the provider considers the audience with whom the system is intended and reasonably likely to interact, then how well-informed, observant and circumspect an average member of that audience is. That same point states that the exposed audience does not always equal the target audience, that expected levels are lower where persons with disabilities, elderly people or minors are likely to be part of the audience, and that levels may be higher for an exclusively professional or specialised audience. Point (45) states that the exception should be interpreted restrictively because it deprives natural persons of the right to clear and distinguishable disclosure, that general awareness that AI systems exist does not imply that people recognise them in interactions, and that the exception should be limited to cases where there is almost no doubt left about the nature of the interaction. As examples where the exception does apply, the document lists among others code assistance chatbots available only to professional developers, an internal employee-facing assistant for properly trained and AI-literate staff, systems used only by properly trained health professionals, ambient AI embedded in home appliances, and non-playable characters in a single-player video game. As examples where the exception does not apply, the document lists a robotic companion pet closely resembling its natural equivalent, AI in immersive environments using realistic avatars or voices, and chatbots on online platforms or helpdesks whose outputs users may perceive as human-generated.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most frequently over-claimed exception. The reasoning 'everyone knows this is a chatbot' is explicitly rejected by the guidelines: general awareness that AI exists is not the same as recognition in the actual conversation. What matters is not what your average customer knows, but who could reasonably end up at your system. As soon as your system is publicly accessible, the broader audience of elderly people, children and people with lower digital literacy is by definition included, and the exception falls away. The mirror image matters just as much and is often missed: for a strictly internal assistant used by trained staff, the Commission does expressly recognise the exception. Note the condition embedded in that example, namely that the staff are actually trained and AI-literate. That ties this exception directly to your Article 4 measures: without demonstrably AI-literate staff, the foundation for relying on the exception falls away.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Rely on this exception only for systems with a closed, professional user base, and record the two-step assessment in writing: who is the target audience, who else could reach it, and why almost no doubt remains for an average member of that audience. For anything publicly accessible, assume you must disclose. Link any internal reliance on the exception to your Article 4 file, so you can show that the staff concerned were genuinely prepared for the use of that system.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.2.1, points (42) to (45) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-standard-editing-exception","legacy_id":"raip:guidance:guidance-article-50-standard-editing-exception","type":"guidance","slug":"guidance-article-50-standard-editing-exception","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f1546b07eee9af5d0cecc75dfbe5f14aa1e16230be04bb1bc71fc1df8bfbd590","label":"Standard editing versus semantic change under the marking obligation","summary":"Spellchecking, formatting and minor image corrections fall outside the marking obligation. An AI summary, rewrite or face replacement falls inside it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-standard-editing-exception-scope","operator":"all","description":"Applies to providers of AI systems generating or manipulating synthetic audio, image, video or text content, in the context of the machine-readable marking and detection obligation of Article 50(2)."}],"exceptions":[{"id":"guidance-article-50-standard-editing-exception-exception","operator":"not","description":"Alongside standard editing and non-substantial alteration, a third exception applies to generative systems authorised by law to generate or manipulate synthetic content to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (90) of the guidelines of 20 July 2026 describes standard editing as the process of preparing existing content for publication or distribution, such as small edits to improve readability, grammar, quality and format, without generating new content. According to that same point, editing goes beyond standard editing where the content is changed in a material way through substantive or structural modifications that affect its meaning, style or intent. Point (91) addresses the second exception, for systems that do not substantially alter the input data provided by the deployer or the semantics thereof, and states that an alteration is substantial where the input data or its semantics have been manipulated significantly during output generation, to be assessed against factors including format, media content type, style and changes affecting meaning, style or intent. Point (92) provides that where a system can be used both for generation or manipulation and for minor non-substantial alterations, the obligation does not apply to the content altered in a minor non-substantial manner. As examples falling under the exception the document lists among others grammar correction and spellchecking, minor stylistic polishing that does not change substance or messaging, AI-generated translations, formatting and format conversion, noise reduction, minor cropping and colour corrections, removal of dust spots and red-eye, blurring of faces, rescaling of video clips and transcriptions of conversations. As examples of semantic changes that do require marking the document lists among others AI-generated summaries of text, paraphrasing or rewriting that changes style, structure and meaning, removal, replacement or insertion of objects or persons, face replacement, synthesis of realistic speech in a specific person's voice and the creation of composite images.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The dividing line is meaning, not effort and not whether a human was involved. That produces two outcomes that surprise many organisations. The first: an AI-generated summary sits explicitly on the marking side. Summarising feels like editing, but the guidelines classify it as semantic change. Anyone auto-generating summaries of articles, reports or case files is therefore inside the marking obligation. The second, mirror-image: an AI-generated translation sits on the exempt side, as does transcription. That is the opposite of what many editorial teams assume. Finally, note point (92): the question is not what your tool can do, but what actually happened to the content in the specific case. The same tool can fall outside the obligation in one use and inside it in another.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Sort your AI applications into two buckets: editing without semantic change, and producing or changing meaning. Put summarising, rewriting, image editing where persons or objects disappear or appear, and voice cloning explicitly into the second bucket, and spellchecking, formatting, translation and transcription into the first. Record the classification per application with a short justification, because the guidelines require a case-by-case assessment rather than a per-tool one.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 4.3, points (90) to (92) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-article-50-text-public-interest-scope","legacy_id":"raip:guidance:guidance-article-50-text-public-interest-scope","type":"guidance","slug":"guidance-article-50-text-public-interest-scope","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9fb49d781c2baa1dd229fae39e2ad59138943aa93e275bc0c92e554a4ffbca83","label":"Which AI text needs a label: published, informing the public, on a matter of public interest","summary":"The labelling duty for AI text applies only where three elements coincide: the text is published, is intended to inform the public, and concerns a matter of public interest.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-article-50-text-public-interest-scope-scope","operator":"all","description":"The three elements are cumulative: only where the text is published, seeks to inform the public and concerns a matter of public interest does the disclosure duty arise."}],"exceptions":[{"id":"guidance-article-50-text-public-interest-scope-exception","operator":"not","description":"The duty falls away where the AI-generated or manipulated text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication, and where use is authorised by law to detect, prevent, investigate or prosecute criminal offences."}],"statements":[{"kind":"official_fact","text":"Point (131) of the guidelines of 20 July 2026 splits the scope of Article 50(4), second subparagraph, into three elements. Published text means the text is accessible by an indeterminate, fairly large number of unrelated potential readers simultaneously or successively, whether or not against payment such as a subscription. Text is not considered published where access is restricted to specific individuals within a closed, private group, for example a small closed group on an instant messaging app or a group that is too small or insignificant; the document cites as examples of unpublished text private interpersonal correspondence for professional purposes and organisation-internal texts or communications such as publications on internal corporate networks. Informing the public means the text intends to communicate knowledge, opinions or facts; short texts that do not materially communicate knowledge, opinions or facts cannot be deemed to inform the public. Matters of public interest are, according to that same point, generally those relevant to society at large, at local, national, Union or international level, and meriting public debate or scrutiny; the document includes texts on politics and democratic processes, public administration and services, the administration of justice and law enforcement, the protection of fundamental rights, public security, public health, environmental protection, consumer safety, and any economic, financial, political, scientific or cultural development that may be a relevant subject of public debate, noting that what counts as public interest can evolve over time and across contexts. As examples within scope the document cites an AI-generated summary of a human-authored article on a newspaper's website discussing a recent town council decision, AI-manipulated parts of a lifestyle-website article comparing the effects of various diets on a particular disease, AI-manipulated corporate reports containing investor information published on a listed company's website, and an AI-generated message on a meteorological institute's social media profile warning citizens about stormy weather and precautionary measures. Outside scope the document places among others AI-generated fantasy novels, AI-manipulated text that is part of a company's advertisement or product descriptions without claims relating to for example health, consumer safety or sustainability, a news summary generated by a chatbot that is only available to the user who prompted it, and AI-manipulated text by a consultant advising a client on measures for regulatory compliance.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The reflex is to read this as a media rule that only concerns newsrooms. The examples show otherwise. A listed company with AI-edited investor information on its own website is inside. A meteorological institute posting a storm warning on social media is inside. A lifestyle site with health claims is inside. What binds those cases is not that they are journalism, but that a broad audience draws information from them about something that affects society. The second nuance sits on the other side: an advertisement or product description falls outside, but only as long as it carries no claims about health, consumer safety or sustainability. Sustainability claims in commercial copy therefore move into scope. The third nuance is the split between internal and published: your intranet and your one-to-one correspondence fall outside, even where the content is socially relevant. And note: the presence of the AI-generated summary of a human-authored article in the example list means the automatic summary feature under a news article can by itself trigger the labelling duty.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Walk through your publication channels and flag where AI generates or substantially edits text: news items, knowledge articles, annual reports and investor information, public information and citizen warnings, and sustainability or health claims. Assess per channel whether the text is published in the sense of the guidelines, meaning accessible to an indeterminate and fairly large audience. Treat automatic summary features on articles as a separate, standalone assessment rather than as part of the underlying article.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.2.1 point (131) and the accompanying example lists","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider","legacy_id":"raip:guidance:guidance-gpai-downstream-modifier-becomes-provider","type":"guidance","slug":"guidance-gpai-downstream-modifier-becomes-provider","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188","label":"When a downstream party that fine-tunes becomes a GPAI provider itself","summary":"Not every modification makes you a provider. The indicative threshold is a modification using more than a third of the original model's training compute, and your obligations are then limited to the modification.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"guidance-gpai-downstream-modifier-becomes-provider-scope","operator":"all","description":"Applies to downstream actors distinct from the original provider and not acting on its behalf, who modify or fine-tune a general-purpose AI model, with or without integrating it into an AI system."}],"exceptions":[{"id":"guidance-gpai-downstream-modifier-becomes-provider-exception","operator":"not","description":"If you become the provider of the modified model, obligations remain limited to the modification itself: the technical documentation covers the change, and the copyright policy and training-content summary cover only the data used in the modification."}],"statements":[{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) on the scope of the obligations for providers of general-purpose AI models state in point (61) that it is not necessary for every modification of such a model to lead to the downstream modifier being considered the provider of the modified model, in line with the Blue Guide, which states that a product subject to important changes or overhauls aiming to modify its original performance, purpose or type may be considered a new product. Point (62) states that the Commission considers a downstream modifier to become the provider of the modified model only if the modification leads to a significant change in the model's generality, capabilities or systemic risk. Point (63) sets the indicative criterion: a downstream modifier is considered to be the provider where the training compute used for the modification is greater than a third of the training compute of the original model. Point (64) states that where the downstream modifier cannot be expected to know that value, for example because it has not been communicated by the provider of the original model, and cannot estimate it, the threshold is replaced by a third of 10 to the power of 25 FLOP where the original model is a model with systemic risk, and otherwise by a third of 10 to the power of 23 FLOP. Point (65) explains that a modification of that size is expected to display a significant change justifying the transparency obligations of Article 53(1)(a) and (b), that such a modification can be expected to have used a significant amount of data relevant to the copyright policy and the public summary of training content under Article 53(1)(c) and (d), and that where the original model has systemic risk the modified model can be expected to present significantly different systemic risk. Point (67) notes that currently few modifications meet this criterion, that the number of downstream modifiers becoming providers may increase over time, and that the criterion is thus primarily forward-looking. Point (68) states that in the case of a modification the obligations are limited to that modification: the documentation under Article 53(1)(a) and (b) is limited to information on the modification, and the copyright policy under point (c) and the summary of training content under point (d) are limited to the data used as part of the modification. Point (69) states that a downstream modifier who becomes a provider must also comply with Article 54, which means appointing an authorised representative established in the Union to the extent that the modifier is itself established outside the Union. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities and is therefore considered a model with systemic risk, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical message is more reassuring than most organisations expect, with one catch. Ordinary fine-tuning on your own documents, RAG, prompt engineering or a LoRA adapter comes nowhere near a third of the training compute of a large base model. The Commission itself says that few modifications currently meet the criterion. Anyone adapting a model for their own use therefore generally does not become a GPAI provider. The catch sits in point (64): if you do not know the original model's training compute and cannot estimate it, you fall back on an absolute threshold of a third of 10 to the power of 23 FLOP. That is a considerably lower bar than a third of a large model, and with closed models whose compute is not published, that is exactly the scenario you are in. The second trap is the systemic-risk chain: if you modify a model already designated as having systemic risk and thereby become a provider, you inherit that label and the duty to notify the Commission. On the positive side, obligations in that case remain limited to your own modification: you do not have to reproduce the original model's documentation or training-content summary.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per modified model which base model you use, which modification method you apply and how much compute that modification consumed, so you can test the criterion rather than speculate about it. Ask the base model's provider for the training compute and document the answer, because if you cannot know that value you fall back on the considerably lower absolute threshold. Also check whether the base model is designated as having systemic risk, because that changes both the threshold and the consequences of crossing it. Reassess this judgement at every substantial retraining, since the Commission itself indicates that the number of downstream modifiers becoming providers is expected to grow.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 53 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-lists-legislation-not-products","legacy_id":"raip:guidance:guidance-high-risk-annex-i-lists-legislation-not-products","type":"guidance","slug":"guidance-high-risk-annex-i-lists-legislation-not-products","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3fd1da47cb4c99a33d5e7595a433bec0d9a5c1686b866fc247c7b1bb499b6864","label":"Annex I lists legislation, not products","summary":"Annex I contains no list of high-risk products but an exhaustive list of harmonisation legislation. The AI Act does not extend the scope of that product legislation and does not change a product's risk profile.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Your starting point is therefore not the AI Act but your existing product file. The question is not whether your product appears on an AI list, because no such list exists. The question is whether your product already fell under one of the listed regulations or directives before AI was added to it. If not, this route does not bring you into the high-risk regime, however advanced the AI system is. The draft guidelines do note that for this classification the concept of safety component may be read as excluding public interests in the sectoral legislation that go beyond health, safety and fundamental rights, such as risks relating to radio spectrum use or electromagnetic compatibility. Those interests therefore do not contribute to the qualification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start your classification with an inventory of the product legislation that already applies to your portfolio today, and record per product line which regulation or directive covers you. That overview is reusable and prevents you from redoing the entire analysis for each AI feature.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (23) to (26)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-section-a-versus-section-b","legacy_id":"raip:guidance:guidance-high-risk-annex-i-section-a-versus-section-b","type":"guidance","slug":"guidance-high-risk-annex-i-section-a-versus-section-b","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3f1e607c8b0c4c04678119a5b3c69fe5a732c7c91393a9ddd0947ec82fbbd277","label":"Section A and Section B of Annex I trigger different requirement sets","summary":"For products under Section A of Annex I the full set of high-risk requirements applies. For Section B only Article 6(1), Articles 102 to 109 and Article 112 apply.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This distinction determines the size of your project. Two organisations can both correctly conclude they have a high-risk AI system and still face a completely different work package. If you are in Section A, the full set applies: risk management system, data quality, technical documentation, logging, transparency towards deployers, human oversight, accuracy and robustness. If you are in Section B, the requirement set is materially narrower. So check first which section your legislation sits in, before you set budget and planning.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"In your classification note, record not only that you fall under Annex I but also under which section. Attach the corresponding requirement set immediately, so that your project plan is correctly sized from the outset.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-annex-i-two-cumulative-conditions","legacy_id":"raip:guidance:guidance-high-risk-annex-i-two-cumulative-conditions","type":"guidance","slug":"guidance-high-risk-annex-i-two-cumulative-conditions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da0604d8c4d9bc6e309a1ff0bd7cf963a65eac7ddb309e26d69a2ff6533f417e","label":"Two cumulative conditions for high-risk under Annex I","summary":"An AI system only becomes high-risk under Article 6(1) when two conditions are met at the same time: the system is itself a regulated product or a safety component of one, and that product must undergo third-party conformity assessment.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is a filter with two screens, and both must be passed. In practice organisations stop at the first screen and conclude their product is high-risk simply because sectoral product legislation applies to it. That is premature. The second screen, mandatory third-party involvement, removes a substantial share. The reverse also holds: anyone who looks only at the CE route and skips the safety component question will miss systems that only enter through the failure route. You must therefore ask both questions separately and record both answers.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system in a regulated product, record a two-part classification note: first whether the system is a product or a safety component, then whether a third party must be involved for that product. Keep both answers with their reasoning in your technical documentation, so that during an audit you do not have to reconstruct after the fact why you reached your conclusion.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (27) and (21)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-article-6-3-filter-mechanism","legacy_id":"raip:guidance:guidance-high-risk-article-6-3-filter-mechanism","type":"guidance","slug":"guidance-high-risk-article-6-3-filter-mechanism","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d6fc330373b2b9b704080d8d34c00f20be28c6ee7ba1357e09733209bdfd75ef","label":"The Article 6(3) filter: four exhaustive grounds, to be read narrowly","summary":"A system falling within Annex III can still stay outside high-risk if one of four grounds is met and the system does not perform profiling. The provider makes that call itself, must document the assessment before placing the system on the market, and must register the system in the EU database.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, Article 6(3) sets out four grounds on which a provider may exempt a system from high-risk classification: performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment absent proper human review, and performing a preparatory task. Paragraph (88) of this draft states these grounds are exhaustive but alternative, that there is no separate independent risk test, and that they must be interpreted narrowly because Article 6(3) is an exception to rules that among other things protect fundamental rights. Paragraph (87) states the filter applies only to systems under Article 6(2) and not to systems under Article 6(1). Paragraph (89) states a system always remains high-risk where it performs profiling. Paragraph (90) adds that the filter does not apply where the system forms part of a complex system whose combined intended purpose or joint outputs materially influence an individual decision, including agentic AI. Paragraphs (113) to (116) of this draft describe that this is a self-assessment by the provider, that Article 6(4) requires documenting the assessment before placing on the market and registering in the Article 71 EU database, and that the assessment must contain at least the intended purpose, why the system falls under Article 6(2), which Article 6(3) condition applies and why, and why the system does not perform profiling. Paragraph (117) of these draft guidelines points to Articles 80 and 99 where an authority finds a system was misclassified as non high-risk to circumvent the rules.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The filter is not a soft way out but a documented and visible decision. You leave the Chapter III high-risk obligations, but in exchange you appear in the public EU database and your reasoning must be available to the regulator at any time. For buyers that is a gift: the draft guidelines expressly encourage deployers to check that database to see whether a vendor relies on the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Write the filter file in four fixed blocks: intended purpose, why it falls under Annex III, which ground you invoke with reasoning, and why there is no profiling. Never rely on the filter because the risk feels low, since that free-standing test does not exist. When procuring, always check the EU database before believing a vendor who says its system is not high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-article-6-two-routes","legacy_id":"raip:guidance:guidance-high-risk-article-6-two-routes","type":"guidance","slug":"guidance-high-risk-article-6-two-routes","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5b469bba143ed5b34c1afab440aee9ca78c70f2d513b65ee8c21990ecb393de7","label":"Article 6 has two separate routes to high-risk","summary":"An AI system can be high-risk in two ways. Either it is itself a product, or a safety component of a product, covered by the Annex I product legislation and that product must undergo third-party conformity assessment (Article 6(1)). Or it falls within one of the use cases listed in Annex III (Article 6(2)). The two routes have their own criteria and their own application dates.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The two routes are not interchangeable. The Annex I route turns on product legislation and on whether a third party must assess conformity, not on whether the system assesses people. The Annex III route turns on intended purpose and use case. A system can in theory touch both routes, but you must work through them separately. The exemption mechanism also differs: under the draft guidelines the Article 6(3) filter applies only to the Annex III route and not to the Annex I route.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record in your register which route you assessed and with what outcome. Start with the Annex I question where hardware, machinery, medical devices or toys are involved, and with the Annex III question where the system touches people or access to services. Plan your programme against the earlier of the two dates that applies to you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-broad-marketing-and-gpai-systems","legacy_id":"raip:guidance:guidance-high-risk-broad-marketing-and-gpai-systems","type":"guidance","slug":"guidance-high-risk-broad-marketing-and-gpai-systems","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81fc87af44dd5631c6f242e98843aada30a807c4dcf29a9aafaa85879df1c01a","label":"Broadly positioned and general purpose AI systems: a disclaimer is not enough","summary":"If you market a system broadly without consistently limiting its application, high-risk use cases will be read into its intended purpose. Merely stating in the terms of service that high-risk uses are excluded is insufficient where the rest of your presentation in fact enables or promotes such uses.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This mainly affects providers of broad assistants, agents and platforms who say the product is not meant for HR, education or credit assessment, but show demos, templates or customer stories in exactly those contexts. The draft guidelines look at the whole of your communications, not at the strictest sentence in the small print. For buyers it means a vendor hiding behind a clause does not relieve you of your own assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"If you genuinely want to exclude high-risk use, make that real in the product and not only on paper. Remove demos and examples in excluded domains, build technical or contractual blocks, and make sure sales, website and documentation draw the same line. If you cannot sustain that, assume high-risk and build your evidence file accordingly.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-classification-is-not-permission","legacy_id":"raip:guidance:guidance-high-risk-classification-is-not-permission","type":"guidance","slug":"guidance-high-risk-classification-is-not-permission","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"10104adb4730a287ecda1ce0947349ec478e5cc9d9d911bf13da50045befa6fb","label":"High-risk does not mean prohibited, and not high-risk does not mean permitted","summary":"Classification answers one question: which Chapter III obligations apply. It says nothing about whether the use itself is lawful. Prohibited practices, data protection, consumer law, product safety and national law continue to apply in full.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This removes two errors of reasoning. The first is that a high-risk label equals a ban, which stops projects unnecessarily. The second, and the more dangerous one, is that an outcome of not high-risk means you have a free hand. A system can fall outside high-risk and at the same time be a prohibited practice, or fail on data protection or sector rules.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run the classification test and the lawfulness test as two separate steps and record both outcomes separately. Always test first against the Article 5 prohibited practices, enforceable since 2 February 2025, and only then against Article 6. Finish with a short check on data protection and sector-specific law, even where the system turns out not to be high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-complex-and-agentic-systems","legacy_id":"raip:guidance:guidance-high-risk-complex-and-agentic-systems","type":"guidance","slug":"guidance-high-risk-complex-and-agentic-systems","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e272b329ca696236a70acdbff8f97585e4b61e1b22565101e8694ca61a7f4a2c","label":"Split and agentic architectures are assessed as a whole","summary":"You cannot avoid classification by splitting a high-risk function into separate modules. The draft assesses the combined configuration.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This hits modern architecture head-on: a chain of agents, tools and model calls. Four subsystems that are each neatly preparatory on their own still form a high-risk system once the chain in practice drives the decision.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess at chain level, not component level. Record where separability genuinely lies, and show the exempted module can be put into service independently without contributing to the high-risk purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-filter-documentation-and-registration","legacy_id":"raip:guidance:guidance-high-risk-filter-documentation-and-registration","type":"guidance","slug":"guidance-high-risk-filter-documentation-and-registration","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7234971feba6fc42df535faf220f4b3aadca4a744b6d41564a4441545e4ba01a","label":"Relying on the exception requires documentation and registration","summary":"The exception is a provider self-assessment, but not a free pass. The draft sets out four mandatory components of the assessment and links registration and supervision to it.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are not binding and describe in paragraphs 113 to 117 that applying the filter mechanism depends on a provider self-assessment, that the assessment must be documented before the system is placed on the market or put into service, and that the system must be registered in the EU database under Article 71 to ensure traceability of exempted systems. Under the draft, the assessment must contain four components: a description of the intended purpose, a description of why the system would qualify as high-risk under Article 6(2), a description of which condition or conditions of Article 6(3) are considered to apply and why, and a description of why the system does not perform profiling. The record must be available at any time on request of the market surveillance authority, and the draft encourages deployers to verify use of the exception in the Article 71 database as part of their due diligence. The draft further notes that market surveillance authorities may under Article 80 evaluate the classification, require the system to be brought into compliance and demand corrective action, and may impose penalties under Article 99 where a system was misclassified to circumvent the high-risk requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exemption shifts the work, it does not remove it. You trade the full Chapter III regime for a documented and publicly traceable justification that a supervisor can request and challenge. For deployers, the database is conversely a procurement check.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build one fixed template covering the four mandatory components and date the assessment before market introduction. In procurement, always ask whether the supplier relies on Article 6(3) and whether that appears in the Article 71 database.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7.3 and 2.7.4, paragraphs 113 to 117","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-filter-four-conditions","legacy_id":"raip:guidance:guidance-high-risk-filter-four-conditions","type":"guidance","slug":"guidance-high-risk-filter-four-conditions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ebf775e247fe97fee67dba869fa855a95df9d16f8ec7a817fbf080597a1e753","label":"The Article 6(3) filter: four alternative conditions, to be read narrowly","summary":"A system that falls within an Annex III use case can still escape high-risk classification if it meets one of four conditions. The draft guidelines make clear this is not a broad escape route.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the European Commission's draft guidelines of 19 May 2026, which are not binding and were published for stakeholder consultation, the following applies (paragraphs 84 to 90): the filter mechanism only works for systems that would be high-risk under Article 6(2) and Annex III, not for systems that are high-risk under Article 6(1) and Annex I; the four conditions (narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations without replacing or influencing the previously completed human assessment without proper human review, and preparatory task) are exhaustive but alternative; there is no separate, independent risk test alongside those conditions; and because Article 6(3) is an exception to rules that also protect fundamental rights, the conditions must be interpreted narrowly and always read in light of the requirement that the system does not materially influence the outcome of decision-making.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical question is not whether your system feels low risk, but whether it demonstrably fits one of the four described task types. The absence of a separate risk test cuts both ways: you do not need to make a general risk assessment, but you also cannot invoke one when none of the four conditions fits.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each system, set out which of the four conditions you rely on and why, in the document's own vocabulary. If you rely on more than one, name each separately. If the reasoning feels strained, assume the narrow reading works against you and treat the system as high-risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Sections IV.2.7 and 2.7.1, paragraphs 84 to 90","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-human-involvement-does-not-declassify","legacy_id":"raip:guidance:guidance-high-risk-human-involvement-does-not-declassify","type":"guidance","slug":"guidance-high-risk-human-involvement-does-not-declassify","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e0dab5a5fe2940b50bf147b06dee417a119fbe3888f65e39c8df060913aebfea","label":"A human in the loop does not make a system low-risk","summary":"Human involvement does not change the intended purpose and therefore has no effect on classification under Article 6(2). Human oversight is a compliance requirement for high-risk systems, not an escape from the classification.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (70) that the only relevant determinant for qualification under Article 6(2) is whether the intended purpose of the system includes one of the use cases listed in Annex III, that human involvement cannot change the purpose and area in which a system is intended to be used, and that human involvement therefore has no effect on classification. The same paragraph states that human oversight is instead a prerequisite for compliance with the rules for high-risk systems under Article 14. Paragraph (71) of this draft adds that the type and degree of human involvement may play a role for the Article 6(3) filter, but only to demonstrate that the tasks are narrow procedural or preparatory in nature or that the system only improves a previously completed human activity, and that a provider cannot categorise a system as low risk simply by adding a requirement of human involvement.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This defeats the most common defence in practice, namely that a human always looks at it anyway. That sentence changes nothing about the classification. Human involvement only becomes relevant when you can show that the system itself plays no more than a narrow procedural or preparatory role, and that is a far heavier test than an approval button.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Delete the sentence that a human is in the loop from your classification reasoning. Instead describe exactly what the system does in the decision process and at what moment. Use the degree of human involvement only as support within one of the four Article 6(3) grounds, and keep evidence that the review is genuinely substantive.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, section 2.1, paragraphs (70) and (71)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-human-oversight-no-declassification","legacy_id":"raip:guidance:guidance-high-risk-human-oversight-no-declassification","type":"guidance","slug":"guidance-high-risk-human-oversight-no-declassification","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9124b610886a642919da8ee9b2e63bae08e06271624198ce5721f6c5683b10fb","label":"A human in the loop does not make a system low-risk","summary":"Human oversight is a compliance requirement for high-risk systems, not a way to escape classification. Human involvement only counts when determining what task the system performs.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"In the non-binding draft guidelines of 19 May 2026, the Commission states in paragraphs 70 and 71 that classification under Article 6(2) depends solely on whether the system's intended purpose falls within an Annex III use case. Human involvement cannot change the purpose and area of intended use and therefore has no effect on that classification; human oversight is instead a condition for compliance under Article 14. Under the draft, the type and degree of human involvement can play a role in the filter mechanism, but only to demonstrate that the system's tasks are narrow procedural or preparatory in nature, or merely improve a previously completed human activity. The draft expressly adds that a provider cannot label a system as low-risk simply by adding a human involvement requirement to it.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common reassurance that a human always reviews the output changes nothing about classification. In fact, the document's examples dismiss formal human review precisely where the output in practice weighs heavily on the outcome.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Base your classification on the intended purpose, not on your workflow. If you want to use human involvement in the argument, tie it to the system's task type and show the human assessment is substantive and complete, not a formality.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.1, paragraphs 70 and 71","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-improve-not-review","legacy_id":"raip:guidance:guidance-high-risk-improve-not-review","type":"guidance","slug":"guidance-high-risk-improve-not-review","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"656a4e99b759d1c8c8dd12d60ae912d80508379745a885f99fa72e1e825b230b","label":"Improving is deliberately different from reviewing","summary":"The second condition requires a completed human activity with a result that the system only refines. A materially different outcome does not qualify.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are a non-binding draft and state in paragraphs 94 to 96 that Article 6(3)(b) requires three cumulative elements: a human activity that has been completed, a result flowing from it, and improvement of that result by the AI system. The system may therefore not replace or autonomously perform the human activity. The draft notes the EU legislature deliberately chose the word improve rather than review, so the system must not be intended to provide a materially different result but to verify or refine the activity, and that any improvement must not change the rights, protection, legal or economic position of the persons affected. As an example that does not qualify, the draft cites a system that checks a human-made decision, plan or construction and provides a substantially different solution. As examples serving an auxiliary improvement function, the draft cites systems that flag errors or contradictions in finalised human work as quality assurance, systems that map conclusions to evidentiary records to strengthen traceability of a decision without substituting human judgment, and systems that convert human-validated content for interoperability or accessibility purposes.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This condition is narrower than it sounds. A writing assistant that sharpens the wording of a completed judgment fits; a second-opinion model that redoes the judgment does not, however useful it may be substantively.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make the sequence in your process demonstrable: the human judgment is recorded first, only then does the system act. Record that scores, conclusions and outcomes are not altered by the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(b), paragraphs 94 to 96","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-intended-purpose-is-the-anchor","legacy_id":"raip:guidance:guidance-high-risk-intended-purpose-is-the-anchor","type":"guidance","slug":"guidance-high-risk-intended-purpose-is-the-anchor","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8f7455feefe96374d1cb47b4dc57d2d947ef8ef83fd2cd04797cf00177b3eb33","label":"Intended purpose is the anchor of classification","summary":"Intended purpose determines whether a system is high-risk. That purpose is set not only by the technical documentation but also by the instructions for use, promotional materials, sales materials and statements by the provider. Reasonably foreseeable misuse falls by definition outside the intended purpose.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (10) that the intended purpose of an AI system plays an important role in its classification as high-risk, and that under Article 3(12) intended purpose is the use for which the provider intends the system, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, statements and technical documentation. Paragraph (11) of that draft adds that providers must clearly describe the envisaged use, including the system's functionalities, leaving no ambiguity as to scope and intended use. Paragraph (13) of these draft guidelines places the assessment with the provider, supervised by the competent market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Marketing is legal material here. What your website, sales deck or demo promises counts towards establishing the intended purpose, even if the technical documentation is more cautious. A gap between what the system does in practice and how its purpose is described will not protect you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Have one owner for the intended-purpose description and review the instructions for use, technical documentation, website, sales material and demo scripts against each other annually. Also describe explicitly which contexts and applications are and are not intended, and keep that wording identical across all channels.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraphs (10), (11) and (13)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-must-first-be-an-ai-system","legacy_id":"raip:guidance:guidance-high-risk-must-first-be-an-ai-system","type":"guidance","slug":"guidance-high-risk-must-first-be-an-ai-system","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eb62d3811c86970025c6b5235267569779e7a3149fe73059a242756c17a2368f","label":"First the definition question: is it an AI system at all?","summary":"Before classification comes into play, the system must meet the definition of an AI system in Article 3(1). Not every software application and not every automated decision-making system falls within the AI Act.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, before a system can be classified as high-risk it must first qualify as an AI system within the meaning of Article 3(1) of the AI Act (paragraph 8). Paragraph (9) of that draft states expressly that not every software application or automated decision-making system falls within the scope of the regulation, and refers for the interpretation of the definition to the separate guidelines on the definition of an AI system (C(2025) 5053).","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is a genuine preliminary question, not a formality. Classic rule-based software, fixed calculation rules and simple automation that does not infer from input how to generate output never reach the classification question. At the same time this is not an escape route: the definition guidelines are broad and in practice the burden of showing that something falls outside the definition rests on you.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include an explicit definition-test field in your AI register, with the reasoning why a system is or is not an AI system. Run that test before you invest time in the Annex I or Annex III analysis, and record the result so you can show it during an inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.1, paragraphs (8) and (9)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-natural-persons-scope","legacy_id":"raip:guidance:guidance-high-risk-natural-persons-scope","type":"guidance","slug":"guidance-high-risk-natural-persons-scope","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4e7381817402e04bb3dd0998f913b3b24106a92090aad3a0fad3fffc67011457","label":"Only the assessment of natural persons falls within these use cases","summary":"Systems assessing only legal persons fall outside the relevant Annex III use cases. Self-employed people and sole traders do count as natural persons, however.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, published as a non-binding draft, clarify in paragraphs 72 to 74 that a natural person is distinct from a legal person and that the notion is not limited to consumers: sole traders, independent professions and other self-employed persons also count as natural persons in relation to their commercial activity, including persons acting in a professional capacity such as consultants, designers and journalists. A system that assesses natural persons falls within the use case regardless of whether it also assesses legal persons; systems intended only to assess legal persons or companies fall outside it. The draft gives as an example that a system assessing the creditworthiness of companies based on company data, balance sheets and financial statements does not qualify as evaluating a natural person, and that an owner assessed to back a company loan also falls outside point 5(b) because the company, not the individual, is the primary beneficiary of the credit.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The boundary does not run along sector or sensitivity, but along who is being assessed. Watch the trap on the other side: as soon as your B2B system also assesses freelancers and sole traders, you are back inside the use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"State unambiguously in the intended purpose whether natural persons are part of the assessed population. Exclude that use contractually and technically if you want to stay outside the use case, because mixed use pulls the whole system in.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.2, paragraphs 72 to 74","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-preparatory-versus-decisive","legacy_id":"raip:guidance:guidance-high-risk-preparatory-versus-decisive","type":"guidance","slug":"guidance-high-risk-preparatory-versus-decisive","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5949170ab144d33aebcd0c63bafdfb84bcb158968ee437e2f0b691b532c4aada","label":"Preparatory or decisive: general input is allowed, a specific recommendation is not","summary":"The preparatory task under Article 6(3)(d) precedes the assessment. Once the system evaluates the specific case or makes a recommendation, the exception is gone.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the non-binding draft guidelines of 19 May 2026, the notion of preparatory in Article 6(3)(d) refers to tasks occurring prior to the actual assessment process, which distinguishes it from the narrow procedural task in point (a) that may also occur during the assessment as long as it is clearly delimited (paragraphs 103 and 104). The draft cites as examples from Recital 53 indexing, searching, processing and linking: tasks that add structure to the input but do not themselves provide an assessment leading to an outcome (paragraph 106). Under paragraph 107, the decisive factor is the task's role in the decision-making process and its proximity to the final human decision. Paragraph 108 adds that output feeding a human operator's assessment can only be preparatory if it is a general input or supplementary information, and that a system producing a specific recommendation or evaluation of the case plays a decisive role and is therefore not preparatory.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The dividing line is workable in practice: laying out information is allowed, interpreting the case is not. A system that surfaces legal provisions, jurisdiction and internal guidance stays preparatory; the same system drawing a conclusion for this file no longer is.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Test your system on one question: does the output produce anything specific to this case that points towards an outcome? If so, assume high-risk. Where possible, build a hard separation between information retrieval and assessment logic.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1(d), paragraphs 103 to 108","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-profiling-blocks-filter","legacy_id":"raip:guidance:guidance-high-risk-profiling-blocks-filter","type":"guidance","slug":"guidance-high-risk-profiling-blocks-filter","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"de66ad718cdb5bc2e7ffd33ce48de1951647c3988431407e26b500ef41a92521","label":"Profiling always blocks the exception, even when a condition would otherwise fit","summary":"As soon as the system profiles, the Article 6(3) exemption is ruled out. The draft guidelines give three cumulative elements against which you test this.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026, which are a non-binding draft document, explain in paragraphs 89 and 109 to 112 that a system listed in Annex III always remains high-risk where it performs profiling within the meaning of Article 4(4) GDPR, Article 3(4) of Directive (EU) 2016/680 or Article 3(5) of Regulation (EU) 2018/1725. Under the draft, profiling consists of three cumulative elements: automated processing, carried out on personal data, with the objective of evaluating personal aspects relating to a natural person. The draft states the first element is always satisfied for AI systems, so the provider must mainly establish whether personal data form the input and whether personal aspects are being evaluated. The draft adds that a simple classification on characteristics such as age, sex or height does not automatically amount to profiling, because a form of prediction, assessment or inference must be present.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The profiling bar is the sharpest brake on the filter mechanism. Many systems that at first sight perform a tidy preparatory or procedural task still fail here because along the way they predict or judge something about a person. Note that this may be a person other than the subject of the decision, for example the assessor themselves.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"State explicitly in your file which data the system ingests, whether those are personal data, and whether a prediction, score or inference about a person arises anywhere. Consider anonymisation or aggregation at source if you want to preserve the exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Section IV.2.7.1 paragraph 89 and section IV.2.7.2, paragraphs 109 to 112","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-safety-component-autonomous-definition","legacy_id":"raip:guidance:guidance-high-risk-safety-component-autonomous-definition","type":"guidance","slug":"guidance-high-risk-safety-component-autonomous-definition","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c929f0dcf3a5d6c5e0133edcbe649b200e7fa07453e03961c6a2e1a0255eae8a","label":"Safety component is an autonomous AI Act concept","summary":"For classification purposes only the definition of safety component in Article 3(14) AI Act counts. Definitions of the same term in sectoral product legislation are not relevant here.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the draft guidelines of 19 May 2026, which are non-binding and may still change, the definition of safety component in Article 3(14) AI Act is an autonomous definition with its own meaning, independent of definitions of safety component in other Union harmonisation legislation. The draft guidelines state that this definition ensures uniform interpretation of the concept across all sectors covered by Annex I, and that in assessing whether an AI system is a safety component only Article 3(14) AI Act is relevant, not the definition in any legislation listed in Annex I. Article 3(14) describes a safety component as a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most underestimated pitfall in the entire chapter. Many technical teams have worked for years with the notion of safety component as defined by their own sectoral standard, for instance in the machinery tradition or the medical devices world. That reflex produces the wrong outcome. The AI Act concept is broader than many sectoral definitions, precisely because it includes the failure route. A component that has never been designated a safety component in your sectoral file may well be one under the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run the safety component test again using only the text of Article 3(14), even if your product has had a sectoral safety file for years. Have a second reviewer who is not steeped in the sectoral tradition read along, because that person will more readily spot where the AI Act is broader than your habit.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (32) and (33)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-safety-function-versus-failure-route","legacy_id":"raip:guidance:guidance-high-risk-safety-function-versus-failure-route","type":"guidance","slug":"guidance-high-risk-safety-function-versus-failure-route","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cef01d5437965eec1281d90fe2a0d784862f3905a04f90adbae923fe5b48fc33","label":"Two routes to safety component: intent or consequence","summary":"An AI system is a safety component via two alternative routes. Either it is intended to fulfil a safety function, or its failure or malfunctioning endangers health, safety or property.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are a draft document without binding force and read Article 3(14) as two alternative scenarios. In the first scenario the AI system fulfils a safety function, meaning that its intended purpose, as determined by the provider, is to prevent or mitigate risks to the health and safety of persons or property. The draft guidelines note that the mere fact that an AI system is integrated into or operates within a product subject to safety regulation does not in itself mean it fulfils a safety function. In the second scenario the system is a safety component because its failure or malfunctioning could endanger the health and safety of persons or property. The draft guidelines summarise this in a table: the safety function is intent-based and strongly provider-controlled, evidenced by instructions of use, technical documentation and promotional materials, while the failure route is consequence-based and risk-based with lower provider control, evidenced by system architecture, failure modes and effects.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"You can steer the first route, not the second. That is the whole point. A provider determines the intended purpose and can therefore choose not to claim a safety function in the documentation. The draft guidelines close that exit with the failure route, which looks at what happens when things go wrong, regardless of what you wrote down. The guidelines list forms of failure including incorrect outputs such as false positives and false negatives, loss of function or availability, performance instability or drift, timing or latency errors, and misclassification leading to hazardous control decisions. Note the lower bound as well: the likelihood of failure must not be a merely theoretical possibility, and reputational harm, purely financial loss, minor service degradation or inconvenience without a safety hazard do not count.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document the two routes separately. For the safety function, record what you communicate as intended purpose in the instructions of use, technical documentation and sales materials, and keep those three consistent. For the failure route, produce a failure mode analysis noting for each failure form whether there is a path to injury or damage to property. That analysis is also your evidence towards a market surveillance authority.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (34) to (44), including table 1","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-single-compliance-framework-sectoral-integration","legacy_id":"raip:guidance:guidance-high-risk-single-compliance-framework-sectoral-integration","type":"guidance","slug":"guidance-high-risk-single-compliance-framework-sectoral-integration","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bdbd9514e94771ae555ba26afdebf49ceca4dfb3dd3c1ee7db306c34c76532a2","label":"Integrating AI Act requirements into existing risk and quality systems","summary":"The AI Act allows you to add AI-specific risks to your existing risk management and quality management systems, so that you can work within a single compliance framework.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"According to the draft guidelines of 19 May 2026, which are expressly published as a draft for stakeholder feedback and have no binding force, the AI Act provides mechanisms to reduce the compliance burden for economic operators. The draft guidelines cite Article 8(2) AI Act on the interplay with sectoral legislation, Article 9(10) AI Act on risk management and Article 17(3) AI Act on quality management, which allow economic operators to add, where necessary and appropriate, an assessment of AI-specific risks to already existing risk and quality management systems. Article 40 AI Act further requires that harmonised standards under the AI Act be consistent with standards developed under the Annex I harmonisation legislation. The draft guidelines state that these mechanisms enable economic operators to meet both the AI Act and the harmonisation legislation within a single compliance framework, thereby avoiding duplication of effort while maintaining a high level of protection of health, safety and fundamental rights.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most reassuring point in the entire chapter, and at the same time the most underused. Manufacturers who already have a mature quality management system, for instance under a sectoral standard, do not need to set up a second system alongside it. You extend what is already there. That saves not only cost but above all the fragmentation in which your AI file becomes detached from your product file and the two start contradicting each other during an audit. The practical gain lies in a shared risk register in which AI risks are included as a category, not as a separate document.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Extend your existing risk register and quality manual with an AI chapter instead of building a parallel AI management system. Appoint an owner who manages both the sectoral file and the AI file, so that changes to the product automatically touch the AI assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (61) and (62)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-standalone-software-updates-and-add-ons","legacy_id":"raip:guidance:guidance-high-risk-standalone-software-updates-and-add-ons","type":"guidance","slug":"guidance-high-risk-standalone-software-updates-and-add-ons","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e6419b609560f8d6e6bbecfdb48762778743aca84f68ced7ce5dad5e6ef752fc","label":"Standalone software, updates and remote services can also be high-risk","summary":"Article 6(1) applies regardless of whether the AI system is embedded in the product or placed on the market independently. A software update, add-on or remote service can therefore be high-risk in its own right.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 are non-binding and still under consultation, and clarify that Article 6(1) AI Act applies irrespective of whether the AI system is embedded within the product or placed on the market or put into service independently. An AI system supplied for example as a software update, an add-on or a remote service may therefore be classified as high-risk under Article 6(1), provided all conditions of that provision are met. The draft guidelines also distinguish the case where the AI system is the product itself: that is so where it is independently placed on the market, has its own intended purpose, and is directly regulated by the harmonisation legislation listed in Annex I. As an example the draft guidelines cite Regulation (EU) 2023/1230, the Machinery Regulation, whose definition of machinery-related products explicitly includes certain software, which may therefore itself be a regulated product and be classified as high-risk provided third-party conformity assessment is required. The draft guidelines further state that an AI system which is a safety component of a regulated product should be evaluated as part of that product's overall safety assessment, even where it is also placed on the market independently of that product.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This affects a growing group of suppliers who believe they are outside the regime because they do not make a physical product. Anyone supplying an AI module that is later loaded into a machine, lift or vehicle may well be a provider of a high-risk AI system. The same holds for over-the-air updates that change or add an existing safety function. The flip side is that your assessment is not detached from the product: the draft guidelines require your component to be weighed in the overall safety assessment of the product it lands in. That requires coordination with the manufacturer and clear arrangements on information exchange.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which regulated products your software ends up in and which safety-relevant functions your updates touch. Set out contractually what information you supply to the product manufacturer for their safety assessment, and treat an update that changes a safety function as a trigger to re-test the classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (22), (30) and (31)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-substantial-modification-article-25","legacy_id":"raip:guidance:guidance-high-risk-substantial-modification-article-25","type":"guidance","slug":"guidance-high-risk-substantial-modification-article-25","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"cf761dadbb93aa15f6b1773ef8ac6d7a5dec66037327356ff1634cabdd7ee54d","label":"When a customer or distributor itself becomes the provider","summary":"Distributors, importers, deployers and other third parties can take on provider obligations. That happens when you put your own name or trademark on a system, when you make a substantial modification to a high-risk system, and when you change the intended purpose of a non high-risk system so that it becomes high-risk.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, note in paragraph (14) that distributors, importers, deployers or other third parties may become subject to provider obligations under Article 25(1) where they, first, put their name or trademark on a high-risk AI system already placed on the market or put into service; second, make a substantial modification to a high-risk AI system already placed on the market or put into service in such a way that it remains a high-risk AI system; or third, modify the intended purpose of an AI system, including a general-purpose AI system, which had not been classified as high-risk, in such a way that the system becomes a high-risk AI system under Article 6. A footnote to that paragraph announces that the Commission is preparing separate guidelines on responsibilities along the AI value chain under Article 25.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The third situation is the most underestimated. An organisation that buys a broadly deployable model or assistant and then aims it at recruitment, employee evaluation or access to services changes the intended purpose and can thereby become the provider of a high-risk system, with the full set of obligations. White labelling under your own brand is also enough, without changing a single line of code.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Introduce a standing check before you rebrand, modify or repurpose a procured AI system. Assess for each change whether you land in one of the three Article 25(1) situations and record that assessment. Make this part of your procurement and change process, not a one-off project check.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (14) and its footnote 6","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:guidance:guidance-high-risk-third-party-conformity-assessment-module-choice","legacy_id":"raip:guidance:guidance-high-risk-third-party-conformity-assessment-module-choice","type":"guidance","slug":"guidance-high-risk-third-party-conformity-assessment-module-choice","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"81c96c1b43f6d6e80d5cbf98a9485b411e186e75b1d5e77f2efd6932c7dad7b4","label":"Module choice does not change the classification","summary":"The fact that a manufacturer may opt for internal control based on harmonised standards does not affect the high-risk classification. Classification follows the level of enhanced scrutiny required by the product legislation, not the procedure chosen.","topics":["guidance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The draft guidelines of 19 May 2026 have the status of a non-binding draft and clarify the second condition as follows. The AI Act does not itself determine the applicable conformity assessment procedures but relies on the choice of procedures established under the Annex I harmonisation legislation. Decision 768/2008/EC sets out eight main modules A to H. For all modules except module A the involvement of a notified body is required; module C does not require such involvement but is always combined with modules that do; for modules A1 and A2 a notified body or accredited in-house body is required only in the production phase. The draft guidelines then state explicitly that the fact that harmonisation legislation may allow a manufacturer to rely on internal control based on harmonised standards, as one procedural option, does not affect the classification of an AI system as high-risk under Article 6(1). The choice of module gives the manufacturer procedural flexibility to demonstrate compliance but confers no discretion to determine the risk classification under the AI Act. The decisive factor is that the product, under the Annex I legislation, is subject to enhanced regulatory scrutiny before it may lawfully be placed on the market, scrutiny ensured through the requirement of third-party conformity assessment or equivalent mechanisms, including internal control subject to mandatory application of harmonised standards published in the Official Journal. The draft guidelines point out that the Union legislature expressly confirmed this logic in recital 15 of Regulation (EU) 2025/2509 on the safety of toys.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Here the draft guidelines close the most obvious escape route. The reasoning many manufacturers hoped to use ran: we apply harmonised standards, therefore we use module A, therefore no third party is involved, therefore we are not high-risk. The Commission reverses that. What matters is not the chosen procedure but the level of protection the legislature considered necessary for that product type. Anyone who has built the module A route into their compliance planning must now revisit that assumption. The toys and machinery regulations are explicitly named as sectors where this plays out.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Test your classification not against the module you actually use, but against whether the legislature prescribed enhanced scrutiny for your product type. If your sectoral legislation permits internal control only subject to mandatory application of harmonised standards, assume you fall within the high-risk regime and plan your AI Act track accordingly.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","source_locator":"Draft guidelines Annex I, points (50) to (59)","source_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:annex-iii-eight-areas","legacy_id":"raip:obligation:annex-iii-eight-areas","type":"obligation","slug":"annex-iii-eight-areas","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6","label":"Annex III: the eight areas separately","summary":"Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open here is not the text but the boundary and the form. The eight points are reproduced verbatim, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Publishing the points as separate objects is also our choice; the Regulation gives a list and not eight self-standing norms. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own. It also remains unclear how Article 6(3) works out per area: the exception is drafted in general terms, but the profiling proviso bites in almost every case in one area and rarely in another. Finally, we have checked that Regulation (EU) 2026/1744 inserts Article 6(1a) to (1c) without renumbering or amending paragraphs 2 and 3; if that changes, the route in this object changes with it.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:map-system-to-annex-iii-area"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text"],"conditions":[{"id":"annex-iii-eight-areas-intended-purpose","operator":"any","description":"Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes."},{"id":"annex-iii-eight-areas-route","operator":"all","description":"Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order."},{"id":"annex-iii-eight-areas-article-25-role-shift","operator":"any","description":"The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself."}],"exceptions":[{"id":"annex-iii-eight-areas-article-6-3-derogation","operator":"not","description":"Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk."},{"id":"annex-iii-eight-areas-article-6-4-documentation","operator":"all","description":"The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request."}],"statements":[{"kind":"official_fact","text":"The introductory sentence of Annex III reads: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas. Eight numbered areas follow. 1. Biometrics, in so far as their use is permitted under relevant Union or national law. 2. Critical infrastructure. 3. Education and vocational training. 4. Employment, workers’ management and access to self-employment. 5. Access to and enjoyment of essential private services and essential public services and benefits. 6. Law enforcement, in so far as their use is permitted under relevant Union or national law. 7. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law. 8. Administration of justice and democratic processes. The full text of each point, with its lettered subpoints, sits on the object for that area.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex III is not fixed. Article 7(1) empowers the Commission to add or amend use cases in Annex III by delegated act, and Article 7(3) to remove them. Article 7(1)(a) requires the system to be intended for use in one of the areas listed in Annex III. The eight areas are therefore the stable layer; the lettered subpoints inside them can change without the Regulation itself being revised.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 7(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Seven of the eight areas are subdivided into lettered subpoints in the text: point 1 into (a) to (c), point 3 into (a) to (d), point 4 into (a) and (b), point 5 into (a) to (d), point 6 into (a) to (e), point 7 into (a) to (d) and point 8 into (a) and (b). Point 2 has no lettered subpoints. We therefore count twenty-four lettered subpoints across seven areas. That number appears nowhere in the Regulation: it is our count of the text as it stands at our knowledge date, and a delegated act under Article 7 can silently make it stale.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Reading Annex III as one block leads to the wrong question. The question is not whether your organisation works in one of the eight areas, because nearly everyone does: a hospital touches point 5, a school point 3, and every employer point 4. The question is whether the intended purpose of this one system coincides with the description of a lettered subpoint. A CV parser that only deduplicates repeat applications does something other than a system that evaluates candidates, and yet both get filed under recruitment in practice. Note the order too. Points 1, 6 and 7 carry the condition that the use must be permitted, and that is where Article 5 comes first. Emotion recognition in the workplace and in education is prohibited under Article 5(1)(f), except where the system is placed on the market or put into service for medical or safety reasons; whoever reverses that builds a conformity file for something that is not allowed. Finally, the area also determines which duties then weigh heavily. Article 86 gives a right to an explanation for decisions based on any system listed in Annex III other than point 2, and Article 27 requires bodies governed by public law and private providers of public services to carry out a fundamental rights impact assessment on every Annex III route other than point 2, with point 5(b) and (c) extending that duty to any deployer. For systems already on the market before the application date, the separate transitional rule of Article 111(2) applies as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system, record in your register not that it falls under Annex III but which point and which lettered subpoint it touches, with the intended purpose in your own words alongside. The eight area objects sit in the graph under the slugs annex-iii-area-1-biometrics through annex-iii-area-8-justice-and-democratic-processes; refer to those rather than to Annex III as a whole. Add four fields: is the use permitted, and if not, why is Article 5 not engaged; has the Article 6(3) test been carried out, which of the four conditions was met, and has the assessment been documented and the system registered under Article 6(4) and Article 49(2); does the system perform profiling, because the exception then falls away; and who carries the provider role after Article 25. Repeat that record on every change to the intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"related","href":"https://www.praxikon.com/nl/annex-iii","label":"The eight areas on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:annex-iii-high-risk","legacy_id":"raip:obligation:annex-iii-high-risk","type":"obligation","slug":"annex-iii-high-risk","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c0afd1789ed393ba3f9ce04205bd74b4831ff0fd58146108fdd8dd08d2f4f6c9","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-change-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-classifier"],"conditions":[{"id":"annex-iii-listed-purpose","operator":"all","description":"The intended purpose falls within a use case listed in Annex III."},{"id":"article-6-2-route","operator":"all","description":"Classification follows Article 6(2)."}],"exceptions":[{"id":"article-6-3-exception","operator":"not","description":"A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented."}],"statements":[{"kind":"official_fact","text":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-10-data-governance","legacy_id":"raip:obligation:article-10-data-governance","type":"obligation","slug":"article-10-data-governance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b6992c5a6d684dd828c8b00a7239e768eee9d4a5cb4fdbc4fbaee3dbf561d91","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-10-data-governance-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-10-data-governance-record"],"control_ids":["praxikon:eu:ai-act:control:article-10-data-governance-control"],"template_ids":["praxikon:eu:ai-act:template:article-10-data-governance-legal-text"],"conditions":[{"id":"article-10-data-governance-scope","operator":"all","description":"The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data."}],"exceptions":[{"id":"article-10-data-governance-exception","operator":"not","description":"For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions)."}],"statements":[{"kind":"official_fact","text":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-11-technical-documentation","legacy_id":"raip:obligation:article-11-technical-documentation","type":"obligation","slug":"article-11-technical-documentation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15571dc37c23ef11a79a3b7b9b7d5674ee4fc7161cc4a9bb8f62321f66294a2c","label":"Article 11: technical documentation","summary":"The technical file demonstrating before market placement that a high-risk system meets the requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-11-technical-documentation-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-11-technical-documentation-record"],"control_ids":["praxikon:eu:ai-act:control:article-11-technical-documentation-control"],"template_ids":["praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text"],"conditions":[{"id":"article-11-technical-documentation-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-11-technical-documentation-exception","operator":"not","description":"Small providers (SMEs) may provide the documentation in the simplified form established by the Commission."}],"statements":[{"kind":"official_fact","text":"Article 11 requires technical documentation drawn up before market placement, kept up to date and containing the Annex IV elements, so that compliance with Section 2 is demonstrable to supervisors.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buying organisations, Annex IV is the checklist of what you must be able to request contractually from your supplier; without that file you cannot meet your own Article 26 duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the right to access the technical documentation in AI procurement and supplier contracts now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-11-technical-documentation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 11 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-111-legacy-public-systems","legacy_id":"raip:obligation:article-111-legacy-public-systems","type":"obligation","slug":"article-111-legacy-public-systems","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4","label":"Article 111(2): legacy high-risk systems and the 2 August 2030 date","summary":"High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The text above is the consolidated text and has been checked against the Official Journal; what is preliminary is our reading of it. First, the cut off date. The amended paragraph 2 refers not to a date but to the date of application of Chapter III referred to in Article 113, and since the Digital Omnibus Article 113, third paragraph, point (c) gives two: 2 December 2027 for Annex III and 2 August 2028 for Annex I. We therefore read the cut off as route dependent. A defensible alternative reading is that the reference points at the general application date of Chapter III as a whole, that is 2 August 2026, because Sections 4 and 5 of that Chapter were not deferred; on that reading the cut off would effectively still be 2 August 2026. We follow the route dependent reading because point (c) expressly names Sections 1, 2 and 3, and those are the Sections carrying the requirements the grace period exists for. Second, the notion of a significant change in the design. That is not the same wording as the defined substantial modification used elsewhere in the Regulation, and there is no guidance or case law saying whether a model update, a retraining run or a new data source counts. We read it as a change that touches the intended purpose, the functioning or the risk profile, and not as every release. Third, the reach of intended to be used by public authorities. It is unclear whether a system supplied to both public and private customers falls under it in full, and whether a private party carrying out a public task is a public authority. We read the intention as following from the market the system is offered for and not from the legal form of the individual customer.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends","praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable"],"action_ids":["praxikon:eu:ai-act:action:assess-significant-design-change","praxikon:eu:ai-act:action:plan-legacy-public-system-compliance"],"evidence_ids":["praxikon:eu:ai-act:evidence:legacy-system-transition-register"],"control_ids":["praxikon:eu:ai-act:control:design-change-review-gate"],"template_ids":["praxikon:eu:ai-act:template:article-111-legal-text"],"conditions":[{"id":"article-111-2-scope-article-5-unaffected","operator":"all","description":"The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed."},{"id":"article-111-2-scope-limited-to-chapter-iii","operator":"all","description":"The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them."},{"id":"article-111-2-legacy-scope","operator":"all","description":"Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date."},{"id":"article-111-2-type-and-model","operator":"all","description":"The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union."},{"id":"article-111-2-public-authority-deadline","operator":"all","description":"Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged."}],"exceptions":[{"id":"article-111-2-exception-annex-x-systems","operator":"not","description":"Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030."}],"statements":[{"kind":"official_fact","text":"Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The grace period in paragraph 2 applies where the type and model of an AI system has already been placed on the market. If at least one individual unit was lawfully placed on the market or put into service before the cut off date, the grace period also covers other units of the same type and model, which may be offered without additional obligations, requirements or mandatory additional certification, as long as the design remains unchanged. On a significant change to the design after the cut off date the provider must fully comply with all relevant provisions applicable to high-risk AI systems, including the conformity assessment requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this provision is read exactly the wrong way round. Executives hear that existing systems are left alone and conclude that nothing is needed until well into the 2030s. That is wrong in two ways. For a public sector organisation the second sentence gives no escape but a deadline, and it applies whether or not you change anything about the system. And for everyone the transitional rule concerns only the high-risk requirements: Article 4 has been running since February 2025 and Article 50 since August 2026, with legacy generative systems having only until 2 December 2026 to get the machine-readable marking of Article 50(2) in order. The first sentence, moreover, is not a resting place but a switch. As soon as the design is significantly changed you must comply fully with what applies to high-risk systems, the conformity assessment first of all; those duties do follow the shifted calendar of 2 December 2027 and 2 August 2028. That switching moment rarely arises at a time you choose: it arises on a supplier update, a migration or a new data source. Two things therefore matter more than the date itself. You need to know when the first unit of each type and model reached the market, because that is the decisive date and without it you cannot later show which track a system was on. And you need a moment in your change process at which someone assesses whether a change is significant, before it goes live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per type and model of your high-risk AI systems when the first unit was placed on the market or put into service, and whether the system is intended to be used by public authorities. Record that determination with a date and a reasoning, and note which route applies, because that decides whether your cut off is 2 December 2027 or 2 August 2028. For the systems intended for public authority use, set a plan towards 2 August 2030 that counts back from the conformity assessment and the registration, not from the end date. Also build into your change and release process a review moment at which someone records whether an intended design change is significant, before the change goes into production. Separately, check whether Article 111(4) catches you: if so you have until 2 December 2026 for the marking under Article 50(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-12-logging","legacy_id":"raip:obligation:article-12-logging","type":"obligation","slug":"article-12-logging","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"92daf8448d3471e5014ea66a2dc2731909f2689e5e3bdb243f49a75572002f20","label":"Article 12: logging and traceability","summary":"Automatic recording of events over the lifetime of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-12-logging-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-12-logging-record"],"control_ids":["praxikon:eu:ai-act:control:article-12-logging-control"],"template_ids":["praxikon:eu:ai-act:template:article-12-logging-legal-text"],"conditions":[{"id":"article-12-logging-scope","operator":"all","description":"The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control."}],"exceptions":[{"id":"article-12-logging-exception","operator":"not","description":"The retention period may be limited by Union or national law, including data protection."}],"statements":[{"kind":"official_fact","text":"Article 12 requires high-risk AI systems to be technically capable of automatically recording events over their lifetime, for traceability, risk signalling and post-market monitoring; Article 19 and Article 26(6) govern log retention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Logging is the backbone of all other evidence: without logs an incident cannot be reconstructed and a monitoring duty cannot be fulfilled. Buyers should already test whether a system is technically capable of this.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include logging capability and log access as a requirement in every AI purchase and assign the retention regime (who, where, how long) per system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-12-logging","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 12 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-13-instructions","legacy_id":"raip:obligation:article-13-instructions","type":"obligation","slug":"article-13-instructions","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"818266e8912de0d2c95a38a4a16c67b1aad02d10359b3571710fd757c678819b","label":"Article 13: transparency towards deployers","summary":"Comprehensible instructions for use and system information so deployers can operate the system correctly.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-13-instructions-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-13-instructions-record"],"control_ids":["praxikon:eu:ai-act:control:article-13-instructions-control"],"template_ids":["praxikon:eu:ai-act:template:article-13-instructions-legal-text"],"conditions":[{"id":"article-13-instructions-scope","operator":"all","description":"The provider supplies a high-risk system; the deployer uses it according to the instructions."}],"exceptions":[{"id":"article-13-instructions-exception","operator":"not","description":"The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed."}],"statements":[{"kind":"official_fact","text":"Article 13 requires high-risk systems to be designed transparently enough for deployers to interpret and use the output, with instructions covering purpose, accuracy, limitations, human oversight and maintenance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The instructions are the hinge between provider and deployer duties: what the provider fails to supply here, the deployer cannot deliver under Article 26. Ask for it explicitly at procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Translate received instructions per system into internal work instructions per role and record who received them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-13-instructions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 13 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-14-human-oversight","legacy_id":"raip:obligation:article-14-human-oversight","type":"obligation","slug":"article-14-human-oversight","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"02da6ce26c5036d2cdea0842564e14a1227cd8f8e5fe5e67e15b52cd5332f98b","label":"Article 14: human oversight","summary":"High-risk AI must be designed so that humans can effectively oversee it and intervene.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-14-human-oversight-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-14-human-oversight-record"],"control_ids":["praxikon:eu:ai-act:control:article-14-human-oversight-control"],"template_ids":["praxikon:eu:ai-act:template:article-14-human-oversight-legal-text"],"conditions":[{"id":"article-14-human-oversight-scope","operator":"all","description":"The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons."}],"exceptions":[{"id":"article-14-human-oversight-exception","operator":"not","description":"For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there."}],"statements":[{"kind":"official_fact","text":"Article 14 requires high-risk systems to be effectively overseeable by natural persons, with measures enabling them to understand the system, correctly interpret output, remain aware of automation bias, and decide not to use, to disregard or to stop the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Oversight on paper is not oversight: the law names automation bias explicitly, so a human who may only click through does not count. Effective oversight requires understanding, time and mandate, which ties directly into the Article 4 literacy measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Appoint the overseeing persons per (upcoming) high-risk system now, train them specifically and record their mandate to intervene in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-14-human-oversight","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 14 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-15-accuracy-robustness","legacy_id":"raip:obligation:article-15-accuracy-robustness","type":"obligation","slug":"article-15-accuracy-robustness","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d","label":"Article 15: accuracy, robustness and cybersecurity","summary":"Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-15-accuracy-robustness-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record"],"control_ids":["praxikon:eu:ai-act:control:article-15-accuracy-robustness-control"],"template_ids":["praxikon:eu:ai-act:template:article-15-accuracy-robustness-legal-text"],"conditions":[{"id":"article-15-accuracy-robustness-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-15-accuracy-robustness-exception","operator":"not","description":"Systems that continue learning after deployment carry additional requirements to control feedback loops and drift."}],"statements":[{"kind":"official_fact","text":"Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 15 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-16-provider-obligations","legacy_id":"raip:obligation:article-16-provider-obligations","type":"obligation","slug":"article-16-provider-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275","label":"Article 16: the twelve duties of a provider of a high-risk AI system","summary":"Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:assign-article-16-provider-duties"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-16-provider-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-16-pre-market-release-gate"],"template_ids":["praxikon:eu:ai-act:template:article-16-provider-obligations-legal-text"],"conditions":[{"id":"article-16-provider-obligations-scope","operator":"all","description":"Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-16-provider-obligations-exception","operator":"not","description":"A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph)."}],"statements":[{"kind":"official_fact","text":"Article 16 requires providers of high-risk AI systems to do twelve things. They must ensure their systems comply with the requirements of Chapter III, Section 2 (point (a)); indicate on the system or, where that is not possible, on its packaging or accompanying documentation, their name, registered trade name or registered trade mark and the address at which they can be contacted (point (b)); have a quality management system in place complying with Article 17 (point (c)); keep the documentation referred to in Article 18 (point (d)); keep the automatically generated logs referred to in Article 19 when under their control (point (e)); ensure the system undergoes the conformity assessment procedure referred to in Article 43 prior to being placed on the market or put into service (point (f)); draw up an EU declaration of conformity in accordance with Article 47 (point (g)); affix the CE marking in accordance with Article 48 (point (h)); comply with the registration obligations referred to in Article 49(1) (point (i)); take the necessary corrective actions and provide the information required under Article 20 (point (j)); upon a reasoned request of a national competent authority, demonstrate conformity with the requirements of Section 2 (point (k)); and ensure the system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 (point (l)).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 16 reads like a table of contents and is therefore often planned as a single roadmap line. It is twelve separate duties with widely differing lead times: building a quality management system takes months, affixing a CE marking takes a day. The bigger trap sits in Article 25(1): anyone who puts their own brand on an existing high-risk system, substantially modifies it, or changes the intended purpose of a non-high-risk system so that it becomes high-risk counts as a provider and inherits all twelve points without ever having built anything. In the branding scenario of point (a) this applies without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated, but you must have made and be able to show those arrangements in advance. In practice this catches parties that white-label AI or apply a general-purpose model to an Annex III use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First determine whether you are a provider or whether Article 25 makes you one, then work out the twelve points as twelve separate work packages with an owner and a date. Start with points (c) and (f), because they set the lead time of the whole track.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 16 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-17-quality-management","legacy_id":"raip:obligation:article-17-quality-management","type":"obligation","slug":"article-17-quality-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d04f5f23729c5c48f26262f0e266c680dce5753d12543479b1ea672bbe1c6e9","label":"Article 17: quality management system","summary":"The documented quality system through which a high-risk AI provider structurally assures compliance.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-17-quality-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-17-quality-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-17-quality-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-17-quality-management-legal-text"],"conditions":[{"id":"article-17-quality-management-scope","operator":"all","description":"The provider places high-risk AI systems on the market or puts them into service."}],"exceptions":[{"id":"article-17-quality-management-exception","operator":"not","description":"Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form."}],"statements":[{"kind":"official_fact","text":"Article 17 requires a documented quality management system covering a compliance strategy, design and development procedures, data management, risk management, post-market monitoring, incident reporting and an accountability structure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The QMS is the umbrella over all other provider duties: those with the separate files but no system connecting them fail exactly this article in an audit.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build the QMS not as a separate document but as an index on top of the existing files (risk, data, documentation, monitoring) with owners per procedure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-17-quality-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 17 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-18-document-retention","legacy_id":"raip:obligation:article-18-document-retention","type":"obligation","slug":"article-18-document-retention","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb","label":"Article 18: documentation keeping","summary":"The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:keep-high-risk-documentation-available"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-18-retention-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-18-retention-review"],"template_ids":["praxikon:eu:ai-act:template:article-18-legal-text"],"conditions":[{"id":"article-18-scope","operator":"all","description":"Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service."},{"id":"article-18-financial-institutions-regime","operator":"all","description":"Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a) the technical documentation referred to in Article 11; (b) the documentation concerning the quality management system referred to in Article 17; (c) the documentation concerning the changes approved by notified bodies, where applicable; (d) the decisions and other documents issued by the notified bodies, where applicable; (e) the EU declaration of conformity referred to in Article 47. Paragraph 2 provides that each Member State shall determine conditions under which that documentation remains at the disposal of the national competent authorities for the period indicated for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period. Paragraph 3 provides that providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended application dates for Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), are 2 December 2027 for the standalone Annex III route and 2 August 2028 for high-risk AI in products covered by the Annex I harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Four things here are our reading and not the text. First the application date: Regulation (EU) 2026/1744 does not name Article 18 separately, so the fact that this duty moves with 2 December 2027 and 2 August 2028 follows from its placement in Chapter III, Section 3, and not from an explicit provision. Second the starting moment. Paragraph 1 names the placing on the market and the putting into service side by side without choosing, and for a system where both moments occur that is years of difference at the end of the period. Counting from the later moment is the only count that falls short under neither reading, and that is what we would advise a provider. The other reading is defensible: in Union product law the placing on the market is usually the moment that counts, and then the period ends earlier. Third a substantially modified version: the text is silent, and it is equally defensible that every version gets its own period as that the original one continues. Fourth the reach of paragraph 3: it names only the technical documentation, so we keep points (b) to (e) under the general regime until the contrary is settled. Paragraph 2, finally, is addressed to the Member State and not to you. The Netherlands has not yet determined those conditions, so what happens to your file on insolvency or cessation of activity currently follows from contract and not from law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Watch the boundaries of this duty, because they get crossed in both directions. The automatically generated logs are not among the five components: they fall under Article 19, with its own and much shorter period of at least six months, appropriate to the intended purpose, and with a clause for financial institutions that parallels paragraph 3. So do not stretch the ten years to your logs, and conversely do not settle for six months for your documentation. For a provider established in a third country the actual availability moreover sits with two parties at once: Article 22(3)(b) requires the authorised representative to keep, for ten years, the contact details of the provider, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body at the disposal of the competent authorities and of the bodies referred to in Article 74(10). Two files that drift apart are worse than one. Point (e) overlaps with Article 47(1), which gives the declaration of conformity its own ten year period, and under Article 23(5) the importer carries ten years again for the certificate, the instructions for use and the declaration of conformity. That overlap is no reason to drop one of the periods: they are independent duties of different parties. It is a reason to choose a place of retention where they coincide. On the GDPR, finally: a retention duty under Union law is itself a ground under Article 6(1)(c) GDPR, and the storage limitation of Article 5(1)(e) permits retention that the law requires. The question is therefore not whether it is allowed but how far it reaches. Ten years applies to what Article 18(1) names, and not to everything created along the way: separate test sets, log samples and raw data dumps from the documentation you must be able to produce.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"This is the duty that asks nothing at the moment you take it on and everything at the moment you have forgotten it. Ten years is longer than the average life of a supplier contract, a document management system and a product team. In the organisations where we encounter this, the five components rarely sit in one archive: the quality system sits with compliance, the notified body decisions with certification, the declaration of conformity with legal. That is not law, but it is common enough that it is worth checking before you assume your situation is different. Whoever first assembles the documents when an authority asks discovers that retention in fact depended on a person and not on a process. Note also the side that is not about you: paragraph 2 concerns the situation where the provider or its representative goes bankrupt, and that is exactly the risk you run as a customer of a small supplier. It is a contracting question before it becomes a compliance question.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Designate per high-risk system one place of retention where the five components of paragraph 1 come together. Record side by side when the system was placed on the market and when it was put into service, and calculate the end date from the later of those two moments, so that you do not fall short under either reading. Set that end date as a commitment in a system that survives a change of staff, and keep the Article 19 logs separately with their own period. If you work with an authorised representative, record who holds which copy, because Article 22(3)(b) places the same availability on them as well. When procuring a high-risk system, put in the contract what happens to the documentation if the supplier stops or goes bankrupt, because paragraph 2 leaves that arrangement to national law that does not yet exist in the Netherlands.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-18-document-retention","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-20-corrective-actions","legacy_id":"raip:obligation:article-20-corrective-actions","type":"obligation","slug":"article-20-corrective-actions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3da4413e7f76d6cd26cf52cc894dc8b6637916ab4ed1d39776d4446a96c5232c","label":"Article 20: corrective actions and duty of information","summary":"A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.","topics":["high-risk-requirements","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-corrective-action-procedure"],"evidence_ids":["praxikon:eu:ai-act:evidence:corrective-action-record"],"control_ids":["praxikon:eu:ai-act:control:non-conformity-escalation-gate"],"template_ids":["praxikon:eu:ai-act:template:article-20-legal-text"],"conditions":[{"id":"article-20-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as they consider, or have reason to consider, that a system they have placed on the market or put into service is not in conformity with this Regulation. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028."},{"id":"article-20-risk-trigger","operator":"any","description":"The second layer in paragraph 2 is added only where the system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk. The investigation of causes and the duty to inform the market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44, then come on top of the corrective actions under paragraph 1."},{"id":"article-20-article-25-1-becoming-provider","operator":"any","description":"The distributor, the importer and the deployer appear here as affected parties, but that is not their only possible position. Anyone who puts their name or trade mark on a high-risk system already placed on the market, who substantially modifies such a system, or who changes the intended purpose of a system not classified as high-risk so that it becomes high-risk, is considered a provider under Article 25(1) and is subject to the obligations of Article 16. Point (j) of that Article routes straight to Article 20, so this provision then becomes a duty of their own rather than a notification arriving from someone else. In the trade mark case this applies without prejudice to contractual arrangements allocating the obligations otherwise."}],"exceptions":[{"id":"article-20-legacy-systems-article-111-2","operator":"not","description":"Article 20 is by definition about systems already placed on the market or put into service, and that is exactly the group covered by the transitional rule of Article 111(2). That provision was replaced by Article 1, point (39)(a), of Regulation (EU) 2026/1744 and now reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation applies to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The cut-off is therefore no longer a fixed date in paragraph 2: the date of 2 August 2026 that stood there until that amendment has been removed, and the amended paragraph names no date of its own. The carve-out in paragraph 1 covers systems that are components of the large-scale IT systems listed in Annex X; paragraph 1 was not amended and keeps a cut-off of its own. For systems intended to be used by public authorities the reprieve in paragraph 2 does not hold: there, compliance with the requirements and obligations is due by 2 August 2030 in any event. Which date of application of Chapter III is the cut-off is an open point: the object on Article 111 reads it as route dependent, so 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route, and marks that reading expressly as preliminary. That question is carried there, not here."}],"statements":[{"kind":"official_fact","text":"Paragraph 1. Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly. Paragraph 2. Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), of Regulation (EU) 2026/1744, replacing Article 113, third paragraph, point (c), of Regulation (EU) 2024/1689","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This provision is rarely read as a procedure, and that is exactly where it goes wrong. Article 20 places four measures side by side that differ sharply in practice, and those four are not legally equivalent. Recall and withdrawal are defined in Article 3(16) and (17), and the knowledge base carries those terms separately; the difference between them is the point in the chain. Bringing a system into conformity is the patch. Disabling is the odd one out: it is practically the heaviest switch, because it stops a customer who is running the system, and it is at the same time the only one of the four the Regulation nowhere defines. Anyone who copies that word into a contract or procedure without deciding for themselves what it means leaves the heaviest measure the vaguest. The second half is the notification, and in practice that is what fails most often. Paragraph 1 asks you to reach your distributors and, where applicable, your deployers, authorised representatives and importers, which is only possible if you hold a current list of who runs the system in which version and through which contact you reach them. That list is not a by-product of your CRM: resale, white labelling and integration mean you have customers you do not know.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 and Article 73 are often built as a single reporting channel, and that goes wrong in two ways. The trigger differs: Article 73 concerns a serious incident that has occurred, Article 20(2) a risk within the meaning of Article 79(1), that is, a risk to the health, safety or fundamental rights of persons. That is not a tidy split between past and future: a serious incident that has occurred usually also means the system presents a risk, so in practice both provisions often fire at the same time. Nor do the recipients differ entirely, because both routes run to market surveillance authorities. The difference sits in the detail: Article 73(1) points to the authorities of the Member States where the incident occurred, Article 20(2) to the authorities competent for the system concerned, and only Article 20(2) adds the notified body that issued a certificate under Article 44. Only Article 73, moreover, sets hard deadlines. So build one internal process with two exits, not two separate channels and not one channel that forgets the notified body.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two things within this duty are unsettled. First, what \"immediately\" requires: Article 20 sets no period. The closest anchor in the Regulation is Article 73(2), which ties \"immediately\" to the moment the provider has established a causal link between the system and the incident, or the reasonable likelihood of such a link, with an outer limit of fifteen days after becoming aware. We read Article 20 in that light: act once the signal is confirmed, and not only after a full internal investigation has been completed, because paragraph 2 places the investigation of causes alongside the measures rather than before them. A defensible alternative reading is that a provider first has reasonable time to verify and that \"immediately\" only starts running once the non-conformity is established. Second, the threshold \"reason to consider\": it is nowhere settled whether a complaint from a deployer, a deviating test result or a signal from the post-market monitoring of Article 72 already meets it. Whoever records that themselves can later demonstrate the moment of becoming aware; whoever does not has to reconstruct it after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Write out the four measures in paragraph 1 as four concrete scenarios with an owner, a decision maker and a lead time, and decide for yourself what disabling means in your system, because the Regulation does not define that term. Test at least once whether you can actually disable or recall a system without needing a fresh decision to do so. Also keep a record, per system version, of who runs it and through which contact you reach that party, and record which signal meets the \"reason to consider\" threshold in your organisation, so that the moment of becoming aware is demonstrable rather than something reconstructed after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-20-corrective-actions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities","legacy_id":"raip:obligation:article-21-cooperation-with-authorities","type":"obligation","slug":"article-21-cooperation-with-authorities","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3","label":"Article 21: cooperation with competent authorities","summary":"Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here, and the status carries a cost that we state alongside them. First, who the competent authority is. Article 21 refers without qualification to a competent authority. Article 3(48) defines the national competent authority as a notifying authority or a market surveillance authority, and provides in the same point that, as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities are construed as references to the European Data Protection Supervisor. We read Article 21 as addressing those national competent authorities. The stronger alternative reading is that competence follows Chapter IX: the market surveillance authority designated by the Member State, the financial supervisor via Article 74(6), the data protection supervisory authority via Article 74(8), the European Data Protection Supervisor via Article 74(9), and, for a delimited group of systems, the AI Office via Article 75 as amended by Regulation (EU) 2026/1744, which already applies. On that reading you prepare for a different counterpart than the one we assume here. Second, what paragraph 2 asks when the logs are in fact held by the deployer. The text limits the duty to logs under your control but does not say whether you must arrange access contractually in order to retain that control. We read no separate duty into it; that is our reading and not the text. What is settled here is the date of application, and that corrects an earlier reading of ours. Article 1, point (40)(b), of Regulation (EU) 2026/1744 replaces Article 113, third paragraph, point (c), and expressly sets Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), at 2 December 2027 for systems classified as high-risk pursuant to Article 6(2) and Annex III and at 2 August 2028 for those classified as high-risk pursuant to Article 6(1) and Annex I. Article 21 sits in Section 3 and is therefore covered by that provision in so many words; the fact that the omnibus does not name Article 21 individually changes nothing, because the provision operates per Section. The cost of this status: a preliminary reading does not count in the per-situation derivation of obligations, so the log access of paragraph 2 and the language rule do not surface there, and Article 16(k) covers only the demonstration of conformity. The object stays reachable through its own page, the deadline index and the API.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-authority-information-request"],"evidence_ids":["praxikon:eu:ai-act:evidence:authority-request-response-file"],"control_ids":["praxikon:eu:ai-act:control:authority-request-intake-and-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-21-legal-text"],"conditions":[{"id":"article-21-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act."},{"id":"article-21-legacy-systems","operator":"any","description":"For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case."},{"id":"article-21-confidentiality-treatment","operator":"all","description":"What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side."}],"exceptions":[{"id":"article-21-log-access-limits","operator":"not","description":"Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies \"as applicable\", and it applies \"to the extent such logs are under their control\". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Paragraph 2 provides that, upon a reasoned request by a competent authority, providers shall also give the requesting competent authority, as applicable, access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control. Paragraph 3 provides that any information obtained by a competent authority pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings of Article 21, verbatim. Article 22(3), point (c), requires the authorised representative to provide a competent authority, upon a reasoned request, with all the information and documentation necessary to demonstrate conformity with the requirements set out in Section 2, including access to the logs referred to in Article 12(1) to the extent such logs are under the control of the provider; the final subparagraph of that paragraph provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities. Article 19(1) provides that the provider keeps the logs under its control for a period appropriate to the intended purpose, of at least six months. Article 26(6) imposes the same period of at least six months on the deployer for the logs under its control. Article 99(5) subjects the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of total worldwide annual turnover for the preceding financial year, whichever is higher.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings as Regulation (EU) 2026/1744 left them. Article 1, point (34), amends Article 77. The heading now reads \"Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities\". Paragraph 1 now provides that national public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, have the power to request and access any information or documentation created or maintained pursuant to this Regulation from the relevant market surveillance authority, in accessible language and machine-readable format by electronic means, where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction, and that the Article is without prejudice to the competences, tasks, powers and independence of those authorities or bodies. The restriction to the systems listed in Annex III, the requirement of an accessible format and the after-the-fact notification of the market surveillance authority are gone. Inserted paragraph 1a provides that the market surveillance authority grants that access, including by requesting the information or documentation from the provider or the deployer where necessary and without undue delay. Inserted paragraph 1b requires market surveillance authorities and those authorities or bodies to cooperate closely and to provide each other with mutual assistance, including exchange of information. Article 99(4) still does not list Article 21 after the amendment: Article 1, point (38)(b), only inserts a point (da) there on the obligations of providers and operators pursuant to Article 25(2) and (4).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The timeline this object rests on is stated in so many words in the amended Regulation. Article 1, point (40)(b), replaces Article 113, third paragraph, point (c), so that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Article 1, point (39)(a), replaces Article 111(2), so that the grace period is tied to the date of application of Chapter III referred to in Article 113 and no longer to 2 August 2026, while retaining 2 August 2030 for systems intended to be used by public authorities. Article 1, point (2)(a), replaces Article 2(2), so that for systems classified as high-risk under Article 6(1) related to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 apply; Article 21 is not on that list. Article 1, point (41), deletes point 1 of Annex I, Section A, and adds Regulation (EU) 2023/1230 on machinery to Annex I, Section B.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Most of what is requested here already exists under the Regulation: the technical documentation of Article 11, the logs of Articles 12 and 19, the quality management system of Article 17, the conformity file of Article 43. Two things are genuinely additional. Article 19 requires you to keep the logs; Article 21(2) requires you to give an authority access to them, which is a different act. And the language rule of paragraph 1 is additional, because you deliver in an official language of the institutions of the Union chosen by the Member State concerned, not in the language you find most convenient. There is nothing to agree there; find out which language the Member State concerned has indicated and budget translation capacity for a technical file. Three further things go wrong in practice. Your documentation exists but is spread across teams and systems, so assembling it takes weeks. Your documentation belongs to a different system version than the one the question is about, in which case you demonstrate the conformity of something else. And the logs are gone: Article 19(1) and Article 26(6) ask for at least six months, so a request arriving later can meet an empty drawer. A provider established in a third country should also expect the request to land with its authorised representative: Article 22(3), point (c), imposes nearly the same delivery on him and the mandate empowers him to be addressed in addition to or instead of the provider. Article 21 is not the only channel either, but that second channel now runs differently. Under amended Article 77(1) a fundamental rights body requests information or documentation from the relevant market surveillance authority rather than directly from you, in accessible language and machine-readable format, and the restriction to Annex III systems has gone. Under inserted paragraph 1a that market surveillance authority may then request the material from you or from the deployer without undue delay. So expect a fundamental rights question to reach you as a request from the market surveillance authority, in a format a machine can read, and with its own route to testing under Article 77(3). On paragraph 3, finally, no comfortable story: Article 78 protects what you hand over only in accordance with Union or national law, carves out the cases of Article 5 of Directive (EU) 2016/943 for trade secrets and source code, and in paragraph 4 leaves the exchange of information, the dissemination of warnings and information duties under national criminal law unaffected. It is a rule on handling, not a shield.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat this as a delivery exercise rather than a documentation question. Record per high-risk system where each part of the conformity file sits, which system version it belongs to and who can assemble it within an agreed period. Find out which official language of the institutions of the Union the Member State concerned has indicated, and plan translation capacity instead of a language agreement. Determine per customer contract whether the automatically generated logs are under your control or with the deployer, and check that your retention period reaches the six months of Article 19(1), because otherwise the question can no longer be answered after half a year. If you are established outside the Union, record that your authorised representative can deliver the same file, since under Article 22(3), point (c), he is addressed in addition to or instead of you. And let nobody improvise in the answer: supplying incorrect, incomplete or misleading information in reply to a request is a separate ground for a fine under Article 99(5), in a different band from the obligations that Article 99(4) does list.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-23-importer-obligations","legacy_id":"raip:obligation:article-23-importer-obligations","type":"obligation","slug":"article-23-importer-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1a3e0958b87d5b96c66eb024898d343fb1a7f570e3fcffbfe56521278f17b278","label":"Article 23: obligations of importers","summary":"Before placing a system on the market the importer verifies four things about the provider, and afterwards carries its own retention, information and notification package with a ten-year term.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:importer"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-importer-verification-checklist"],"evidence_ids":["praxikon:eu:ai-act:evidence:importer-verification-record"],"control_ids":["praxikon:eu:ai-act:control:importer-stop-and-notify-control"],"template_ids":["praxikon:eu:ai-act:template:article-23-importer-obligations-legal-text"],"conditions":[{"id":"article-23-importer-obligations-scope","operator":"all","description":"Applies to importers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-23-importer-obligations-exception","operator":"not","description":"If you put your own name or trade mark on the system, substantially modify it, or change the intended purpose so that it becomes high-risk, Article 25(1) treats you as a provider and the duties of Article 16 apply instead of those of Article 23."}],"statements":[{"kind":"official_fact","text":"Article 23(1) requires importers, before placing a high-risk AI system on the market, to verify that the relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider (point (a)), that the provider has drawn up the technical documentation in accordance with Article 11 and Annex IV (point (b)), that the system bears the required CE marking and is accompanied by the EU declaration of conformity referred to in Article 47 and instructions for use (point (c)), and that the provider has appointed an authorised representative in accordance with Article 22(1) (point (d)). Article 23(2) provides that an importer with sufficient reason to consider that the system is not in conformity, is falsified or is accompanied by falsified documentation shall not place it on the market until it has been brought into conformity, and that where the system presents a risk within the meaning of Article 79(1) the importer shall inform the provider, the authorised representative and the market surveillance authorities. Paragraph 3 requires indication of name, registered trade name or registered trade mark and contact address. Paragraph 4 requires storage and transport conditions that do not jeopardise compliance with Section 2. Paragraph 5 requires keeping, for 10 years, a copy of the certificate issued by the notified body and, where applicable, of the instructions for use and of the EU declaration of conformity referred to in Article 47. Paragraph 6 requires providing all necessary information and documentation upon a reasoned request in a language easily understood by the authority, and ensuring the technical documentation can be made available. Paragraph 7 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 23 gets underestimated because it looks like document control, and largely it is: you do not have to revalidate the model, you have to be able to show that you checked the four points. The pain sits elsewhere. Point (d) is the one that most often fails in practice: many providers outside the EU have not appointed an authorised representative, and then you simply may not place the system on the market, however far along the deal is. And paragraph 5 puts the ten-year term on you, not on the supplier: if that supplier no longer exists in five years, you still have to produce the documents.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Move the four verifications of Article 23(1) to the moment before contract signature instead of before delivery. Request the declaration of conformity, the technical documentation, proof of the Article 43 procedure and the authorised representative's details as a condition precedent in the purchase contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-23-importer-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-24-distributor-obligations","legacy_id":"raip:obligation:article-24-distributor-obligations","type":"obligation","slug":"article-24-distributor-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"97f76fe79b4762a462b986a893ed4abc4685865bbfe1eae0a28589d4f3564419","label":"Article 24: obligations of distributors","summary":"Before making a system available on the market the distributor verifies the marking, the declaration and the instructions for use plus compliance by provider and importer, and must afterwards be able to correct, withdraw or recall.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":["praxikon:eu:ai-act:actor:distributor"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-distributor-market-check"],"evidence_ids":["praxikon:eu:ai-act:evidence:distributor-check-and-action-log"],"control_ids":["praxikon:eu:ai-act:control:distributor-corrective-action-control"],"template_ids":["praxikon:eu:ai-act:template:article-24-distributor-obligations-legal-text"],"conditions":[{"id":"article-24-distributor-obligations-scope","operator":"all","description":"Applies to distributors of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-24-distributor-obligations-exception","operator":"not","description":"If you put your own name or trade mark on the system, substantially modify it, or change the intended purpose so that it becomes high-risk, Article 25(1) treats you as a provider and the duties of Article 16 apply instead of those of Article 24."}],"statements":[{"kind":"official_fact","text":"Article 24(1) requires distributors, before making a high-risk AI system available on the market, to verify that it bears the required CE marking, that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47 and instructions for use, and that the provider and the importer of that system, as applicable, have complied with their obligations laid down in Article 16, points (b) and (c), and Article 23(3). Paragraph 2 prohibits making the system available while the distributor considers or has reason to consider, on the basis of the information in its possession, that it does not comply with the requirements of Section 2, and requires notification of the provider or the importer where the system presents a risk within the meaning of Article 79(1). Paragraph 3 requires storage and transport conditions that do not jeopardise compliance. Paragraph 4 requires a distributor that considers or has reason to consider that a system already made available does not comply with Section 2 to take the corrective actions necessary to bring it into conformity, to withdraw it or recall it, or to ensure that the provider, the importer or any relevant operator takes those actions; where the system presents a risk within the meaning of Article 79(1) it shall immediately inform the provider or importer and the competent authorities, giving details of the non-compliance and of any corrective actions taken. Paragraph 5 requires providing, upon a reasoned request, all information and documentation regarding actions taken under paragraphs 1 to 4. Paragraph 6 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The check in paragraph 1 looks light but contains an awkward element: you must also verify that the provider has complied with Article 16, point (c), which is having a quality management system in place under Article 17. You cannot see that on the packaging. In practice you anchor it in supplier terms with a statement from the provider and record what you checked. The centre of gravity of Article 24 sits in paragraph 4 though: many resellers assume recall is the manufacturer's business, while the provision also places that action on you, with the option of ensuring another party carries it out. That ensuring requires contractual grip arranged in advance, not during an incident.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the three checks of paragraph 1 in your resell or delivery process and keep a record per contract of what you saw. Also make sure you can tell within a day which customer uses which system in which version, because without that overview you cannot execute paragraph 4.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-24-distributor-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-26-deployer-obligations","legacy_id":"raip:obligation:article-26-deployer-obligations","type":"obligation","slug":"article-26-deployer-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-and-empower-human-oversight"],"evidence_ids":["praxikon:eu:ai-act:evidence:deployer-use-dossier"],"control_ids":["praxikon:eu:ai-act:control:deployer-suspension-and-incident-control"],"template_ids":["praxikon:eu:ai-act:template:article-26-deployer-obligations-legal-text"],"conditions":[{"id":"article-26-deployer-obligations-scope","operator":"all","description":"Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-26-deployer-obligations-exception","operator":"not","description":"Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law."}],"statements":[{"kind":"official_fact","text":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-27-fria","legacy_id":"raip:obligation:article-27-fria","type":"obligation","slug":"article-27-fria","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:fria-assess"],"evidence_ids":["praxikon:eu:ai-act:evidence:fria-report"],"control_ids":["praxikon:eu:ai-act:control:fria-pre-deployment-gate"],"template_ids":["praxikon:eu:ai-act:template:fria-questionnaire"],"conditions":[{"id":"fria-annex-iii-high-risk","operator":"all","description":"The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2."},{"id":"fria-covered-deployer","operator":"any","description":"The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c)."}],"exceptions":[{"id":"fria-emergency-notification","operator":"not","description":"In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself."}],"statements":[{"kind":"official_fact","text":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-27-fria","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-28-39-notified-bodies","legacy_id":"raip:obligation:article-28-39-notified-bodies","type":"obligation","slug":"article-28-39-notified-bodies","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"244200659e300ee841c99c7ece25bf19795a8036b16b7faca26e35a05ecae3b1","label":"Articles 28 to 39: notifying authorities and notified bodies","summary":"Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.","topics":["conformity","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:verify-notified-body-standing"],"evidence_ids":["praxikon:eu:ai-act:evidence:notified-body-standing-record"],"control_ids":["praxikon:eu:ai-act:control:notified-body-continuity-review"],"template_ids":["praxikon:eu:ai-act:template:article-28-39-legal-text"],"conditions":[{"id":"article-28-39-scope","operator":"all","description":"Practically engaged as soon as a notified body comes into the picture for your system. Within Annex III that is, under Article 43(1), only for the biometrics of point 1, and then only along the Annex VII procedure. Within Annex I, Section A, it happens through the sectoral conformity assessment of Article 43(3). For the systems of points 2 to 8 of Annex III, which follow the internal control of Annex VI, no notified body is involved and this Section has no direct bearing on you. The Section itself has applied since 2 August 2025 and therefore well before the underlying high-risk obligations bite: the notification chain has to exist before there is anything to assess."},{"id":"article-28-39-subcontracting-consent","operator":"all","description":"Article 33(3) makes the agreement of the provider a condition for subcontracting: activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. That is a right you can exercise only if you ask about it, because the provision does not prescribe any active notice to you."}],"exceptions":[{"id":"article-28-39-third-country-bodies","operator":"not","description":"Article 39 rules out a free choice of a foreign body. Only conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies, and then only where they meet the requirements laid down in Article 31 or ensure an equivalent level of compliance."},{"id":"article-28-39-presumption-limited","operator":"not","description":"The presumption in Article 32 is narrow. A conformity assessment body is presumed to comply with the requirements of Article 31 in so far as the applicable harmonised standards cover those requirements and their references have been published in the Official Journal of the European Union. Without that publication the presumption does not operate, and it never reaches further than what the standard covers."}],"statements":[{"kind":"official_fact","text":"Article 28(1) provides: Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States. Paragraph 3 provides: Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded. Paragraph 5 provides: Notifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis. Article 29(1) provides: Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established. Paragraph 2 provides: The application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31. Article 30(1) provides: Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31. Paragraph 2, as replaced by Article 1, point (16), of Regulation (EU) 2026/1744, provides: Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1. The second subparagraph of that paragraph empowers the Commission to amend Annex XIV by delegated act. Until 27 July 2026 paragraph 2 carried no such list of codes; since then it sets the scope of the designation. Paragraph 4 provides: The conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 28(1), (3) and (5); Article 29(1) and (2); Article 30(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 28(8), as added by Article 1, point (14), of Regulation (EU) 2026/1744, provides: notifying authorities designated pursuant to this Regulation that are responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both pursuant to this Regulation and that legislation is provided with the possibility to submit a single application and undergoes a unified assessment procedure, where the relevant Union harmonisation legislation provides for such a procedure. A conformity assessment body designated pursuant to more than one piece of that legislation shall have to apply only once to be designated pursuant to this Regulation, and a designation pursuant to this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which it is designated. Paragraph 9 provides that a notifying authority designated pursuant to that legislation is also the notifying authority for the application of that procedure, unless the Member State designates another notifying authority for this Regulation. Article 29(4), as replaced by Article 1, point (15), provides that notified bodies undergoing the unified assessment procedure shall submit the single application to the notifying authority designated pursuant to that Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (14) to (16), amending Articles 28, 29 and 30","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 31(1) provides: A notified body shall be established under the national law of a Member State and shall have legal personality. Paragraph 4 provides: Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. Paragraph 5 provides: Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. Paragraph 6 provides: Notified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Paragraph 8 provides: Notified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned. Paragraph 11 provides: The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 32 provides: Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements. Article 33(1) provides: Where a notified body subcontracts specific tasks connected with the conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 31, and shall inform the notifying authority accordingly. Paragraph 2 provides: Notified bodies shall take full responsibility for the tasks performed by any subcontractors or subsidiaries. Paragraph 3 provides: Activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available. Paragraph 4 provides: The relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation shall be kept at the disposal of the notifying authority for a period of five years from the termination date of the subcontracting.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 34(1) provides: Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43. Paragraph 2 provides: Notified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation. Paragraph 3 provides: Notified bodies shall make available and submit upon request all relevant documentation, including the providers documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section. Article 35(1) provides: The Commission shall assign a single identification number to each notified body, even where a body is notified under more than one Union act. Paragraph 2 provides: The Commission shall make publicly available the list of the bodies notified under this Regulation, including their identification numbers and the activities for which they have been notified. The Commission shall ensure that the list is kept up to date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 36(3) provides: Where a notified body decides to cease its conformity assessment activities, it shall inform the notifying authority and the providers concerned as soon as possible and, in the case of a planned cessation, at least one year before ceasing its activities. The certificates of the notified body may remain valid for a period of nine months after cessation of the notified body activities, on condition that another notified body has confirmed in writing that it will assume responsibilities for the high-risk AI systems covered by those certificates. The latter notified body shall complete a full assessment of the high-risk AI systems affected by the end of that nine-month-period before issuing new certificates for those systems. Where the notified body has ceased its activity, the notifying authority shall withdraw the designation. Paragraph 5 provides: Where its designation has been suspended, restricted, or fully or partially withdrawn, the notified body shall inform the providers concerned within 10 days. Paragraph 6 provides: In the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall take appropriate steps to ensure that the files of the notified body concerned are kept, and to make them available to notifying authorities in other Member States and to market surveillance authorities at their request. Paragraph 9 provides: With the exception of certificates unduly issued, and where a designation has been withdrawn, the certificates shall remain valid for a period of nine months under the following circumstances: (a) the national competent authority of the Member State in which the provider of the high-risk AI system covered by the certificate has its registered place of business has confirmed that there is no risk to health, safety or fundamental rights associated with the high-risk AI systems concerned; and (b) another notified body has confirmed in writing that it will assume immediate responsibility for those AI systems and completes its assessment within 12 months of the withdrawal of the designation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 37(1) provides: The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the requirements laid down in Article 31 and of its applicable responsibilities. Paragraph 2 provides: The notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned. Paragraph 4 provides: Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including the suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. Article 38(1) provides: The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies. Paragraph 2 provides: Each notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives. Paragraph 3 provides: The Commission shall provide for the exchange of knowledge and best practices between notifying authorities. Article 39 provides: Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 37(1), (2) and (4); Article 38(1) to (3); Article 39","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this Section as the supplier terms of your conformity assessor, because that is exactly what it is. Three points in it go wrong in practice. The first is the independence requirement of Article 31(4) and (5). It prohibits not only the obvious double role but rules out consultancy services in particular. Anyone who has his high-risk file built by the advisory firm that later performs the assessment buys a certificate that can be challenged on that ground. Separate those two purchases at the outset, not halfway through. The second is Article 31(1) read alongside Article 39. The body must be established under the national law of a Member State and have legal personality; a body from a third country comes into the picture only where the Union has concluded an agreement with that country. For a group that places its worldwide certification with a single house, that is a hard limit: the European assessment must sit with a European notified legal person, and the group brand name says nothing about that. The third is Article 33. Subcontracting is allowed, but only with your agreement, and the body retains full responsibility for what the subcontractor does. The provision does not oblige it to tell you of its own motion; it only makes its subsidiaries publicly available. So ask, and record the answer, because without the question the agreement never comes up.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two provisions in this Section work in your favour and are rarely used. Article 34(2) is the first. It requires the body to avoid unnecessary burdens for providers and to take due account of your size, your sector, your structure and the complexity of the system, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises. That is not a policy aspiration but an operational obligation of the body, and it sits alongside Article 31(8), which demands the same proportionality in its procedures. The second sentence of paragraph 2 immediately bounds it: the degree of rigour and the level of protection stand. The practical reading is therefore not that a small provider has to demonstrate less, but that the road there must be proportionate. If you are handed a standard package plainly designed for a different kind of organisation, this is the provision on which you raise it. Article 36 is the second. It holds the scenario that hits a provider hardest and appears in no project plan: your body ceases or loses its designation. Your certificates then remain valid for at most nine months, and only where another notified body has confirmed in writing that it will assume responsibility. You hear about it within ten days, and that is the only deadline in this Section that runs directly to you. The follow-on steps for the certificate itself sit in the object on Article 44; what matters here is that the continuity of your market access depends on a party over which you have no control. So treat the notified body as a supplier with concentration risk, and not as a quality mark.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether this Section touches you at all: only where your system goes through a notified body via Annex VII or via the sectoral route of Article 43(3). If it does, check four things in the Commission public list at the moment of choice and annually thereafter: is the body still listed, what identification number does it carry, for which conformity assessment activities and which types of AI systems is it notified, and has its designation been restricted or suspended. Record for each choice that you tested the independence of Article 31(4) and (5), in particular whether the same group previously advised you on the same system. When placing the assignment, ask explicitly which tasks are subcontracted to a subcontractor or a subsidiary, give or withhold your agreement under Article 33(3) in writing, and provide in the contract that any change to it requires your agreement again. Add two clauses: a duty on the body to report any change to its designation, mirroring the ten days of Article 36(5), and a handover clause describing which files you get back within what period if it ceases. Finally, keep a second notified body in view that is notified for your type of system, so that the nine months of Article 36(3) and (9) become a handover rather than a search.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-28-39-notified-bodies","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4-ai-literacy","legacy_id":"raip:obligation:article-4-ai-literacy","type":"obligation","slug":"article-4-ai-literacy","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7a9516670dfca5dd7dcc96ae019e5714f843e20235abd3e9d92b71eb42445ff1","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-4-measures"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-4-measures-record"],"control_ids":["praxikon:eu:ai-act:control:article-4-periodic-review"],"template_ids":["praxikon:eu:ai-act:template:article-4-measures-plan"],"conditions":[{"id":"article-4-in-scope-ai","operator":"all","description":"The organisation is a provider or deployer of an AI system within scope."}],"exceptions":[{"id":"article-4-no-specific-level","operator":"not","description":"The provision does not require a specific individual level to be guaranteed."}],"statements":[{"kind":"official_fact","text":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Official amending regulation"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications","legacy_id":"raip:obligation:article-40-42-standards-and-specifications","type":"obligation","slug":"article-40-42-standards-and-specifications","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c","label":"Articles 40 to 42: standards, common specifications and presumption of conformity","summary":"A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.","topics":["conformity","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open is the anchoring of the duty holder. Of the three Articles only Article 41(5) contains a rule of conduct addressed to a role this graph knows: providers of high-risk AI systems or general-purpose AI models must duly justify that they have adopted at least equivalent technical solutions where they do not apply a common specification. The object is anchored on that paragraph. A defensible alternative reading treats Articles 40 to 42 as entirely institutional, with an empty duty holder and `out_of_scope`, and hangs the justification on Article 11 and Annex IV, where the technical documentation is described. On that reading the recommended action and the file below move to the object on Article 11; the substance does not change, the basis does. Also open is where the justification must be recorded. Article 41(5) prescribes no form, no place and no recipient. We read it as belonging in the technical documentation, because that is the only file a market surveillance authority can request under Article 21; that is an inference and not text. Not open is the dating: Articles 40, 41 and 42 sit in Chapter III, Section 5, and that Section is not excepted in the third paragraph of Article 113, so the general application date of the second paragraph governs, 2 August 2026.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:justify-standards-and-specification-choices"],"evidence_ids":["praxikon:eu:ai-act:evidence:standards-conformity-justification-file"],"control_ids":["praxikon:eu:ai-act:control:official-journal-citation-watch"],"template_ids":["praxikon:eu:ai-act:template:article-40-42-legal-text"],"conditions":[{"id":"article-40-42-publication-condition","operator":"all","description":"The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal."},{"id":"article-40-42-justification-condition","operator":"all","description":"The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route."}],"exceptions":[{"id":"article-40-42-presumption-is-rebuttable","operator":"not","description":"A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements."},{"id":"article-40-42-specification-withdrawn","operator":"not","description":"Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis."}],"statements":[{"kind":"official_fact","text":"The final subparagraph of Article 40(2), as added by Article 1, point (17), of Regulation (EU) 2026/1744, provides: the Commission shall request, in accordance with Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation. Article 42(3), added by Article 1, point (18), provides: where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (17) and (18), amending Article 40(2) and Article 42","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 40(1) provides: High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations. Paragraph 2 provides: In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum. When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation. Paragraph 3 provides: The participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(1) provides: The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and: (i) the request has not been accepted by any of the European standardisation organisations; or (ii) the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or (iii) the relevant harmonised standards insufficiently address fundamental rights concerns; or (iv) the harmonised standards do not comply with the request; and (b) no reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period. When drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67. Paragraph 2 provides: Before preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled. Paragraph 3 provides: High-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(4) provides: Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V. Paragraph 5 provides: Where providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto. Paragraph 6 provides: Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 42(1) provides: High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4). Paragraph 2 provides: High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The word everything turns on is presumed. A presumption of conformity is not proof of compliance and it is rebuttable: it shifts who has to demonstrate what, and nothing more. If a market surveillance authority shows that your system in fact does not meet a requirement of Section 2, the standard you applied does not stop that. Two limits set out in the text itself come on top. The first is the coverage limit: the presumption operates only in so far as the standard or the specification covers the requirements or obligations concerned. EN 18286 shows exactly what that means, because the coverage statement accompanying that standard expressly excludes Article 17(2) to (4) and Article 72; whatever falls outside the coverage you substantiate yourself. The second is the publication limit: without a reference in the Official Journal of the European Union no presumption arises, however complete the standard may be. That is why all twelve standard objects in data/ai-act/graph/standards.ts carry guidance and not applicable. So anyone hearing a supplier say that his product meets the European standard and is therefore AI Act compliant is hearing two leaps at once: from coverage to completeness, and from standard to legal effect.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Article 41 is often dismissed as an emergency valve that will never be used, and that is the wrong call. The European standards under standardisation request M/613 are not all available yet: the standards layer in data/ai-act/graph/standards.ts shows one completed EN and six deliverables still at drafting or enquiry stage. That is precisely the state described by the conditions of Article 41(1), point (a)(ii), and point (b), and so the common specification route remains practically relevant. For you that means two things. First, an implementing act may appear for a requirement of Section 2 that you did not see coming and that touches your design choices; those acts are adopted under the examination procedure of Article 98(2) and not in consultation with individual providers. Second, there is then a paragraph that asks something of you directly: paragraph 5. If you do not apply the common specification, you must duly justify that your technical solution is at least equivalent. That is the only place in these three Articles where you have to write something yourself, and the text does not say where. In practice that justification belongs in the technical documentation, because that is the file that has to be handed over upon a reasoned request. Article 42 is narrower than it looks and is overrated for that reason. Paragraph 1 touches only Article 10(4) and not the rest of the data governance of Article 10; paragraph 2 touches only the cybersecurity requirements of Article 15 and only where the references of the scheme under Regulation (EU) 2019/881 have been published in the Official Journal. A certificate under a scheme not yet published yields no presumption, and a presumption on Article 15 says nothing about your Article 9, 11, 12, 13 or 14.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build a coverage matrix per high-risk system and per general-purpose AI model: put every requirement of Section 2 that applies to you in the left column, and next to it which harmonised standard, which common specification or which document of your own covers that requirement. Note per row whether the reference of that standard has been published in the Official Journal of the European Union, because only those rows carry a presumption; the remaining rows call for evidence of your own. For every requirement where a common specification exists that you do not apply, write a justification under Article 41(5): which technical solution you adopted, why it is at least equivalent to what the specification demands, and which test shows it. Include that justification in the technical documentation so that it can travel immediately upon a reasoned request. Set up a standing check on publications in the Official Journal as well: a new reference switches a presumption on, and under Article 41(4) repeals an existing common specification, which can remove the basis under a row of your matrix. If you want to rely on Article 42, record why your training and testing data reflect the geographical, behavioural, contextual or functional setting within which the system is intended to be used, and confine the conclusion to Article 10(4). For the cybersecurity route, first check whether the references of the scheme under Regulation (EU) 2019/881 appear in the Official Journal; without that publication the certificate is a good document with no legal effect under Article 15.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(4); Article 15; Article 43(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-44-notified-body-certificates","legacy_id":"raip:obligation:article-44-notified-body-certificates","type":"obligation","slug":"article-44-notified-body-certificates","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"458f4f14180a115bbccca9bac5e76eae0e9642c92bc0831b57b8e803ebb447b9","label":"Article 44: certificates of notified bodies","summary":"A certificate issued by a notified body is valid for at most five years for AI systems covered by Annex I and at most four years for AI systems covered by Annex III, and may be extended at the request of the provider after a re-assessment. Where the system no longer meets the requirements of Section 2, the body shall, taking account of the principle of proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes corrective action within an appropriate deadline it sets so as to ensure compliance with those requirements. An appeal procedure against that decision is available.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"What this Article asks of a provider remains unsettled. The text addresses the notified body alone and imposes no duty at all on the provider. We read a practical consequence into it, namely that whoever holds a certificate watches its expiry date, asks for a re-assessment in time and is able to correct within the deadline set by the body. A defensible alternative reading is that for the provider Article 44 merely describes what the body does and that his duties follow entirely from Articles 16, 17 and 43. On that reading the recommended action and the file below hang on Article 43 rather than Article 44; the substance does not change, the basis does. On the dating that doubt no longer exists: Article 44 sits in Section 5 of Chapter III, the third paragraph of Article 113 excepts only Sections 1, 2 and 3 of that Chapter, and so the general application date of the second paragraph of Article 113 governs, 2 August 2026. When the provision bites in practice does differ per route: for the systems of Annex III the underlying obligations run from 2 December 2027 and for the regulated products of Annex I from 2 August 2028, while the Section B products of Annex I fall outside this Article altogether since 27 July 2026. Those two dates do not fit in a field that carries one, which is why the field carries the application date of the Article itself. It also remains unclear whom the last sentence of paragraph 3 addresses: an appeal procedure against decisions of the notified bodies shall be available, but the text does not say who provides it. That the route exists is stated.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:manage-notified-body-certificate"],"evidence_ids":["praxikon:eu:ai-act:evidence:notified-body-certificate-record"],"control_ids":["praxikon:eu:ai-act:control:certificate-expiry-monitoring"],"template_ids":["praxikon:eu:ai-act:template:article-44-legal-text"],"conditions":[{"id":"article-44-scope","operator":"all","description":"Applies as soon as a notified body has issued a certificate for a high-risk AI system. That happens along two routes. The certificate under Annex VII, which under Article 43(1) and (2) arises within Annex III only for the biometrics of point 1. There it can arise along two ways: a provider who has applied harmonised standards or common specifications may under the first subparagraph of paragraph 1 choose between the internal control of Annex VI and the procedure involving a notified body of Annex VII, and the second subparagraph makes Annex VII mandatory in the four cases it lists. And the certificate issued under Article 43(3) as replaced with effect from 27 July 2026, within the sectoral conformity assessment of the products of Annex I, Section A, where the body is notified under that sectoral legislation, where the quality management system of Article 17 is assessed as well, and where point 3, points 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. For the products of Annex I, Section B, which cover machinery since 27 July 2026, this Article has no bearing: the amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to those systems, and Article 44 is not in that list. Nor does it bear on the systems of points 2 to 8 of Annex III, which under Article 43(2) follow the internal control of Annex VI, where no notified body is involved."}],"exceptions":[{"id":"article-44-exception-corrective-action","operator":"not","description":"Paragraph 3 withholds suspension, withdrawal or restriction where compliance with the requirements of Section 2 is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body. The principle of proportionality also allows the body to confine itself to restrictions instead of withdrawal."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that certificates issued by notified bodies in accordance with Annex VII shall be drawn up in a language which can be easily understood by the relevant authorities in the Member State in which the notified body is established. Paragraph 2 provides that certificates shall be valid for the period they indicate, which shall not exceed five years for AI systems covered by Annex I and four years for AI systems covered by Annex III, that at the request of the provider the validity may be extended for further periods, each not exceeding five years and four years respectively, based on a re-assessment in accordance with the applicable conformity assessment procedures, and that any supplement to a certificate shall remain valid provided that the certificate which it supplements is valid. Paragraph 3 provides that where a notified body finds that an AI system no longer meets the requirements set out in Section 2, it shall, taking account of the principle of proportionality, suspend or withdraw the certificate issued or impose restrictions on it, unless compliance with those requirements is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body, that the notified body shall give reasons for its decision, and that an appeal procedure against decisions of the notified bodies, including on conformity certificates issued, shall be available.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 43 sets out along which route a certificate arises and when it must be earned again. Paragraph 1 lets the provider of the systems listed in point 1 of Annex III choose between the internal control of Annex VI and the procedure involving a notified body of Annex VII where he has applied harmonised standards or common specifications, and makes the Annex VII procedure mandatory in four cases: the harmonised standards referred to in Article 40 do not exist and the common specifications referred to in Article 41 are not available; the provider has not applied, or has applied only part of, the harmonised standard; the common specifications referred to in point (a) exist but the provider has not applied them; or one or more of the harmonised standards referred to in point (a) has been published with a restriction, and then only on the part of the standard that was restricted. Paragraph 2 provides that for the systems of points 2 to 8 of Annex III providers follow the internal control of Annex VI, for which the involvement of a notified body is not required. Paragraph 4 provides that high-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new procedure whenever they are substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer, and that for systems that continue to learn, changes predetermined by the provider at the moment of the initial conformity assessment and part of the technical documentation referred to in point 2(f) of Annex IV do not constitute a substantial modification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 of Article 43 was replaced with effect from 27 July 2026. Under the text in force, the provider of a high-risk AI system covered by the Union harmonisation legislation listed in Section A of Annex I follows the relevant conformity assessment procedure as required in accordance with that harmonisation legislation, the requirements set out in Section 2 of this Chapter apply to those systems and form part of that assessment, an assessment of the quality management system set out in Article 17 is also undertaken, and points 3, 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. The second subparagraph gives notified bodies notified under that harmonisation legislation the power to assess the conformity of those systems with the requirements of Section 2, provided that their compliance with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under that harmonisation legislation, which is evidenced through the assessment as part of the existing notification, and requires those same bodies, without prejudice to Article 28, to apply for designation in accordance with Section 4 of this Chapter by 28 January 2028. The third subparagraph provides that a manufacturer entitled under that harmonisation legislation to rely on a conformity assessment not involving a third party may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41 covering all requirements of Section 2, that the classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of conformity assessment procedure provided to those manufacturers, and that those manufacturers are not required to choose a procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if that harmonisation legislation does not require it. The fourth subparagraph provides that the provider of a system both covered by that harmonisation legislation and falling within one of the categories listed in Annex III follows the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (19), replacing Article 43(3)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex I was amended with effect from 27 July 2026: in Section A, point 1 was deleted, and in Section B, point 21 was added, referring to Regulation (EU) 2023/1230 on machinery. Article 2(2), likewise replaced, provides that for AI systems classified as high-risk in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 apply, and that Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (2)(a), replacing Article 2(2), and point (41), amending Annex I"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 36 governs what happens to certificates already issued where the notified body itself is concerned. Paragraph 3 provides that a body deciding to cease its conformity assessment activities shall inform the notifying authority and the providers concerned as soon as possible, and in the case of a planned cessation at least one year beforehand, and that its certificates may remain valid for nine months after the cessation on condition that another notified body has confirmed in writing that it will assume responsibility, that other body carrying out a full assessment before the end of those nine months before issuing new certificates. Paragraph 5 provides that a notified body whose designation is suspended, restricted or withdrawn in whole or in part shall inform the providers concerned within ten days. Paragraph 7 provides that in that case the notifying authority shall assess the impact on the certificates issued, shall require the body to suspend or withdraw within a reasonable period any certificates unduly issued, and shall provide the national competent authorities of the Member State in which the provider has its registered place of business with all relevant information on the certificates whose suspension or withdrawal it has ordered. Paragraph 8, point (b), provides that where the notifying authority establishes that the body is not capable of supporting existing certificates issued, the provider of the system covered by the certificate shall confirm in writing to the national competent authorities of the Member State of its registered place of business, within three months of the suspension or restriction, that another qualified notified body will temporarily assume the monitoring of and responsibility for the certificates. Paragraph 9 provides that upon withdrawal of a designation certificates, with the exception of those unduly issued, remain valid for nine months where the national competent authority has confirmed that there is no risk and another notified body has confirmed in writing that it assumes immediate responsibility and will complete its assessment within twelve months of the withdrawal.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 45(2), point (b), provides that each notified body shall inform the other notified bodies of Union technical documentation assessment certificates or any supplements thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, of the certificates and supplements which it has issued.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 45(2), point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Point (c) of the third paragraph of Article 113 was replaced with effect from 27 July 2026 and now provides that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. That deferral concerns those three Sections alone. Article 44 sits in Section 5 of Chapter III and therefore falls under the general application date given in the second paragraph of Article 113: 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Start with the question whether this Article touches you at all, because for most high-risk systems the answer is no. Of Annex III only the biometrics of point 1 pass through a notified body, and there only where you choose that route yourself or where one of the four cases in the second subparagraph of Article 43(1) arises; points 2 to 8 follow the internal control of Annex VI and produce no certificate whatsoever. Whoever does hold a certificate usually holds it through the regulated products of Annex I, Section A, and that certificate comes out of the sectoral conformity assessment of Article 43(3) rather than out of Annex VII. Check first which Section carries your product, because that shifted on 27 July 2026: machinery was taken out of Section A and placed in Section B as Regulation (EU) 2023/1230, and for Section B products the amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable. Article 44 is not among them, so for AI in machinery this Article no longer bears, while it applies in full to the remaining products of Section A. On that Section A route the assessment is moreover wider than it was: since 27 July 2026 the quality management system of Article 17 is assessed as well, and point 3, points 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. That difference is practical: the language requirement of paragraph 1 is tied to the Annex VII certificate and does not carry over unchanged to that sectoral route, whereas the five years of paragraph 2 simply apply. The mistake the Article exposes is the idea that conformity assessment is a project that ends. The certificate has an end date, at most four years for an Annex III system and at most five for an Annex I product, and the re-assessment that carries the extension itself takes time. Whoever knocks on the door only in the final month stands on the expiry date without valid paper while the system simply runs in production. The clock is moreover not the most frequent reason to go back. Article 43(4) sends a system through the assessment again whenever it is substantially modified, including where you only keep using it internally; only changes you predetermined and recorded in the technical documentation do not count. In practice that trigger arrives years before the expiry date. Where things do go wrong, the response of the body is not binary: the principle of proportionality in paragraph 3 allows it to confine itself to restrictions instead of withdrawal, correcting within the deadline it sets holds off the measure, and an appeal procedure against its decision is available. Count on none of the three as a matter of course, but know that they exist. Nor should you count on starting afresh elsewhere after a refusal: Article 45(2), point (b), obliges the body to inform its peer bodies of certificates refused, withdrawn, suspended or restricted. Also put 28 January 2028 in your diary, even though that date is not addressed to you. The second subparagraph of the new Article 43(3) lets bodies notified only under the sectoral legislation of Annex I, Section A, assess conformity with Section 2, but only where their compliance with Article 31(4), (5), (10) and (11) has already been assessed in their existing notification, and requires those same bodies to apply for designation under Section 4 by that date. The recital accompanying the amendment describes that power as an arrangement for eighteen months from 27 July 2026. So ask your body what its status is and whether it is applying, because who can carry out your assessment after that date depends on it. Finally, watch the side that has nothing to do with your system. A notified body can cease its activities or lose its designation. Article 36 then gives you nine months, but only where another body assumes responsibility in writing, and the body must inform you within ten days. In a suspension where the authority establishes that your body can no longer support the existing certificates, there is even a genuine duty on you: to confirm in writing to your national competent authority, within three months, which other qualified body will temporarily take over the monitoring. That is the only hard deadline in this whole block that lands on your desk.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (19), replacing Article 43(3)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (2)(a), replacing Article 2(2), and point (41), amending Annex I"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 45(2), point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish per high-risk system whether there is a certificate at all, and along which route it was issued: Annex VII or the sectoral procedure of Article 43(3). Check while doing so whether your product still sits in Section A of Annex I since 27 July 2026, because for the Section B products, machinery among them, the amended Article 2(2) does not make this Article apply. Then record which certificate belongs to it, which notified body issued it, on what date it expires and which supplements are attached to it, and put that expiry date in the same watch list as your contracts. Plan the extension request well before the expiry date, because the extension rests on a re-assessment in accordance with the applicable conformity assessment procedures. Also tie your change management to Article 43(4): determine per change whether it is substantial, and record the predetermined changes of a learning system in the technical documentation of point 2(f) of Annex IV, because only those do not count as a substantial modification. Designate who receives a message from the notified body, so that a deadline set for corrective action does not expire in a general inbox, and keep the appeal procedure of paragraph 3 open as a route alongside correcting itself. Finally, bring the body itself into the same watch list: track whether it ceases its activities or loses its designation, ask whether it is filing the application for designation under Section 4 that the second subparagraph of Article 43(3) requires of it by 28 January 2028, and make sure you can file the confirmation of Article 36(8), point (b), in writing with your national competent authority within three months.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-44-notified-body-certificates","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment","legacy_id":"raip:obligation:article-46-derogation-from-conformity-assessment","type":"obligation","slug":"article-46-derogation-from-conformity-assessment","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1750dded1098676522ac2284e471cb504967e1c6055f5c0a19d556778c2e3792","label":"Article 46: derogation from conformity assessment procedure","summary":"By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.","topics":["conformity","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"What the provision says is settled; who the duty holder is in this model is not. Article 46 addresses the market surveillance authority (paragraphs 1, 3 and 6) and the Commission (paragraph 5). The provider and the deployer are the requesting party and the party that bears the consequences, and they therefore sit in `affected_actor_ids` with `duty_holder_uncertainty_status: out_of_scope`. A defensible alternative reading writes the market surveillance authority in as duty holder: it exists as an actor in this dataset, and paragraphs 3 and 6 impose a notification and a withdrawal on it that read as duties. On that reading it moves from `oversight_actor_ids` to `duty_holder_ids` and the provider and deployer stay as affected parties; the substance of this object does not change, the basis does. We keep it in the oversight role because no other obligation in this dataset names it as addressee and the meaning of the field would otherwise differ within the same dataset. What also remains uncertain is what the limited period of paragraph 1 is: the text names no maximum and ties the duration only to the exceptional reasons justifying the derogation and to the conformity assessment being carried out. Anyone building on this route cannot read from the text how long it may last. On the dating there is no such doubt: Article 46 sits in Section 5 of Chapter III, the third paragraph of Article 113 excepts only Sections 1, 2 and 3 and its point (b) concerns Section 4, so the general application date of the second paragraph governs, 2 August 2026. On Regulation (EU) 2026/1744. That text was retrieved after all on 6 September 2026 from the Publications Office Cellar service and is archived in data/ai-act/review/sources/reg-eu-2026-1744-nl.txt and -en.txt. The amending regulation carries forty-three amendment points in its Article 1; which of those are reflected in the local legal texts is recorded per point in data/ai-act/review/consolidation-manifest.json. Where a point touches this Article, that is stated below with the statement concerned.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-article-46-derogation-request"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-46-derogation-request-file"],"control_ids":["praxikon:eu:ai-act:control:article-46-derogation-exit-review"],"template_ids":["praxikon:eu:ai-act:template:article-46-legal-text"],"conditions":[{"id":"article-46-exceptional-grounds","operator":"any","description":"The authorisation may be granted only for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That list is the entire basis: a commercial interest, a delivery deadline or a tender date is not in it."},{"id":"article-46-justified-request-and-territory","operator":"all","description":"A duly justified request is required, the authorisation comes from a market surveillance authority, it concerns specific high-risk AI systems, and it operates solely within the territory of the Member State concerned. It is moreover for a limited period while the necessary conformity assessment procedures are being carried out, and the completion of those procedures shall be undertaken without undue delay."},{"id":"article-46-section-2-compliance","operator":"all","description":"The authorisation is issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The derogation therefore concerns the procedure of Article 43 and not the substantive requirements of Articles 8 to 15: those must be met before the authorisation exists."}],"exceptions":[{"id":"article-46-urgency-without-prior-authorisation","operator":"not","description":"Paragraph 2 removes the prior authorisation in a duly justified situation of urgency for exceptional reasons of public security or in the case of a specific, substantial and imminent threat to the life or physical safety of natural persons. Only law-enforcement authorities and civil protection authorities may rely on it, and only for putting into service, provided that such authorisation is requested during or after the use without undue delay."},{"id":"article-46-annex-i-section-a-carve-out","operator":"not","description":"Paragraph 7 excludes this Article for high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I. There, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply. For a regulated product, Article 46 is therefore not a route."},{"id":"article-46-sensitive-operational-data","operator":"not","description":"The notification duty in paragraph 3 towards the Commission and the other Member States shall not cover sensitive operational data in relation to the activities of law-enforcement authorities. The authorisation itself stands; the flow of data around it is limited."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides the following. By way of derogation from Article 43 and upon a duly justified request, any market surveillance authority may authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That authorisation shall be for a limited period while the necessary conformity assessment procedures are being carried out, taking into account the exceptional reasons justifying the derogation. The completion of those procedures shall be undertaken without undue delay. Paragraph 2 provides the following. In a duly justified situation of urgency for exceptional reasons of public security or in the case of specific, substantial and imminent threat to the life or physical safety of natural persons, law-enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation referred to in paragraph 1, provided that such authorisation is requested during or after the use without undue delay. If the authorisation referred to in paragraph 1 is refused, the use of the high-risk AI system shall be stopped with immediate effect and all the results and outputs of such use shall be immediately discarded.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides the following. The authorisation referred to in paragraph 1 shall be issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The market surveillance authority shall inform the Commission and the other Member States of any authorisation issued pursuant to paragraphs 1 and 2. This obligation shall not cover sensitive operational data in relation to the activities of law-enforcement authorities. Paragraph 4 provides the following. Where, within 15 calendar days of receipt of the information referred to in paragraph 3, no objection has been raised by either a Member State or the Commission in respect of an authorisation issued by a market surveillance authority of a Member State in accordance with paragraph 1, that authorisation shall be deemed justified.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(3)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 5 provides the following. Where, within 15 calendar days of receipt of the notification referred to in paragraph 3, objections are raised by a Member State against an authorisation issued by a market surveillance authority of another Member State, or where the Commission considers the authorisation to be contrary to Union law, or the conclusion of the Member States regarding the compliance of the system as referred to in paragraph 3 to be unfounded, the Commission shall, without delay, enter into consultations with the relevant Member State. The operators concerned shall be consulted and have the possibility to present their views. Having regard thereto, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant operators. Paragraph 6 provides the following. Where the Commission considers the authorisation unjustified, it shall be withdrawn by the market surveillance authority of the Member State concerned. Paragraph 7 provides the following. For high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(5)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only route in the Regulation along which a high-risk AI system reaches the market or is put into service without a completed conformity assessment, and that is exactly why it is not a commercial route. Three things make that firm. The grounds are exhaustive and none of them is about the supplier: public security, the protection of life and health of persons, environmental protection, the protection of key industrial and infrastructural assets. A tight delivery deadline, a tender closing in, or a notified body with a waiting list are not among them. The derogation moreover concerns only the procedure of Article 43 and not the substance: paragraph 3 allows the authorisation only where the market surveillance authority concludes that the system complies with the requirements of Section 2. So it does not buy you time to do Articles 9 to 15 later; at most it buys time for the paperwork of the assessment. And it is closed off geographically: the authorisation operates within the territory of the Member State concerned, which means a system running on this basis in one Member State simply has no basis in the next. Note finally paragraph 7. For high-risk AI systems related to products under Section A of Annex I this Article is not a route: there, only the derogations of the sectoral harmonisation legislation apply. Anyone building a regulated product therefore looks for the exit in his own sectoral framework and not here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 reverses the order and that is the heaviest part of this Article for whoever uses it. In a situation of urgency a law-enforcement authority or a civil protection authority may put the system into service first and request the authorisation afterwards, provided that happens without undue delay. The other side sits in the same sentence: if the authorisation is refused, use stops with immediate effect and all results and outputs of that use are immediately discarded. That is not a suspension but a rollback, and it reaches what was produced in the meantime. Anyone starting on this basis must therefore know in advance which decisions, files, alerts and derived datasets count as results and outputs and how they can be found; working out afterwards what the system touched is too late by then, and a decision that rested on such an output is left standing without support. There is also a European aftermath that lands on the requester without him being a party to it. The market surveillance authority informs the Commission and the other Member States, and after 15 calendar days without objection the authorisation is deemed justified. If an objection is raised, by a Member State or by the Commission, the Commission enters into consultations, the operators concerned are consulted and the Commission decides. If it considers the authorisation unjustified, the market surveillance authority withdraws it. For the organisation that means: an authorisation is not firm for the first fifteen days, and it stays withdrawable afterwards. Plan for those two moments, and make sure the conformity assessment genuinely continues in the meantime, because the text names no maximum duration and ties the limited period only to the completion of those procedures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat this route as a contingency plan and not as a planning option. Establish, before you need it, whether it is open to you at all: if your system sits in a product from Section A of Annex I, paragraph 7 closes it and you look for the derogation in your sectoral framework. If it is open, draft the reasoning document now: which of the four exceptional reasons you invoke, on which facts, why delay is not possible, and why this system in particular. Add to it the evidence that the system complies with the requirements of Section 2, because without that conclusion the market surveillance authority cannot issue the authorisation. Record where the conformity assessment stands and what still has to happen, with an end date, and name the person who carries that procedure through while the system runs. If you prepare for the reversed order of paragraph 2, that comes with an exit plan written in advance: which decisions, files, alerts and derived datasets count as results and outputs, how they can be traced per system version, who discards them, within what period, and what happens to decisions that rested on them. Put the fifteen calendar days after the notification of paragraph 3 in your calendar as the moment the authorisation first counts as justified, and reckon with withdrawal after that. Finally, set out in supplier contracts who submits the request, who supplies the reasoning and who bears the cost if the authorisation is refused or withdrawn.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-46-derogation-from-conformity-assessment","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-49-registration","legacy_id":"raip:obligation:article-49-registration","type":"obligation","slug":"article-49-registration","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"95cd9f806f657817dbdc6e5aa1c1b74b37239b8513edc6ad054fd87eaf7b858f","label":"Article 49: registration in the EU database before the system reaches the market","summary":"The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-49-registration-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-49-pre-market-registration-gate"],"template_ids":["praxikon:eu:ai-act:template:article-49-legal-text"],"conditions":[{"id":"article-49-route-secure-section","operator":"any","description":"Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it."},{"id":"article-49-scope-provider","operator":"any","description":"Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3)."},{"id":"article-49-scope-public-deployer","operator":"any","description":"Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III."},{"id":"article-49-timing","operator":"all","description":"Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used."}],"exceptions":[{"id":"article-49-exception-annex-iii-point-2","operator":"not","description":"This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database."}],"statements":[{"kind":"editorial_interpretation","text":"Two readings existed of the date on this object, and Chef chose between them on 6 September 2026. Article 49 sits in Section 5 of Chapter III, and the third paragraph of Article 113 names a Section of Chapter III twice: point (b) names Section 4 and sets it at 2 August 2025, and point (c) names Sections 1, 2 and 3, with the exception of Article 6(5). Section 5 appears in neither point, nor in point (a) or point (d). Article 49 therefore falls under the general date in the second paragraph, and that is the date this object carries: 2 August 2026. Whoever places an Annex III system on the market today without registering is late, not early. The practical reading is not written away but sits alongside it: the duty only acquires an object once a high-risk AI system exists, and that status arises through Article 6(2) and Annex III on 2 December 2027, the date named in point (c) of the third paragraph as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744. That date sits in high_risk_regime_from and the ground of the chosen date in timing_basis. The decision is recorded in data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Paragraph 1 provides that, before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71. Paragraph 2 provides that, before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71. Paragraph 3 provides that, before putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that, for high-risk AI systems referred to in points 1, 6 and 7 of Annex III, in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 of this Article shall be in a secure non-public section of the EU database referred to in Article 71 and shall include only the following information, as applicable, referred to in: (a) Section A, points 1 to 10, of Annex VIII, with the exception of points 6, 8 and 9; (b) Section B, points 1 to 5, and points 8 and 9 of Annex VIII; (c) Section C, points 1 to 3, of Annex VIII; (d) points 1, 2, 3 and 5, of Annex IX. Only the Commission and national authorities referred to in Article 74(8) shall have access to the respective restricted sections of the EU database listed in the first subparagraph of this paragraph. Paragraph 5 provides that high-risk AI systems referred to in point 2 of Annex III shall be registered at national level.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Paragraph 2 is the most expensive sentence in this article and it is missed systematically. Anyone invoking the Article 6(3) exception for an Annex III system believes they have stepped out of the high-risk regime. That is true for the requirements on the system, but not for the registration: it is precisely that provider that registers itself and that system in the EU database, and does so before it is placed on the market or put into service. The exception is therefore not free. It is paid for in visibility: your name, your system and the Article 6(3) condition you rely on end up in a publicly searchable register, exactly where you thought you would stay out of sight. The mistake that follows is predictable and expensive. An organisation carries out the Article 6(3) assessment properly, documents it, and skips the registration because in its mind that belongs to the high-risk regime. The result is that the database holds no trace of a choice it did in fact make deliberately, and that a regulator meets it as a party that simply failed to register the system. The matching piece of evidence already exists in this knowledge base as the registration record for the Article 6(3) route and hangs off the Annex III obligation; the object below covers registration under paragraphs 1, 3, 4 and 5. Note the sequence, finally. Registration is a precondition, not a notification afterwards. Delivering first and registering later repairs nothing: the moment the duty is breached is the placing on the market itself.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Read Article 49 together with Article 71 and with Article 26(8), because those three form a chain that in practice stalls at its weakest point. Article 71 describes the database and says who fills in which fields; Article 49 says when that must happen and by whom; Article 26(8) turns the result into a procurement condition. That last one is the sharpest: a deployer with the status of a public authority that establishes that the system it intends to use is not registered in the EU database shall not use that system and shall inform the provider or the distributor. For a supplier that means a missing registration is not an administrative backlog but a block on the public market, and the party raising it with you is your own customer. For a public sector organisation it means the check belongs in the procurement process and not at the moment of deployment. Two routes deviate and are forgotten for exactly that reason. The first is paragraph 4: for the areas of law enforcement, migration, asylum and border control management the registration moves into a secure non-public section with a shorter list of fields, and only the Commission and the national authorities referred to in Article 74(8) can look into it. That is not an exemption but a different counter, and whoever reads it as an exemption registers nothing. The second is paragraph 5: the systems in point 2 of Annex III, critical infrastructure, are registered at national level. The Regulation does not say which national register that is, so you answer that question in national law and not here. For a grid operator or a water utility that is the difference between an existing counter and a search that only starts once the system is already running.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make registration a hard gate in the release process, before the moment of placing on the market or putting into service, not after. Work through three questions per system. First: does the intended purpose fall under a point of Annex III, and if so, under which point. Second: are you relying on Article 6(3). If you are, the registration in paragraph 2 is your duty and not your choice, and you register yourself and that system, together with the condition you rely on. Third: if it concerns point 2 of Annex III, the registration does not go to the EU database but to national level, and you locate that counter before you need the system. If you are a public sector organisation, do not only register yourself but also select the system and register its use, and build the Article 26(8) check into your procurement process: no deployment as long as the provider entry is not in the database, with a written notification to the provider or the distributor where it is missing. If you supply into the areas of law enforcement, migration, asylum or border control management, record that your registration runs through the secure non-public section and which limited fields go into it. Keep, per system, the registration number, the date of registration and the name of the person who submitted it, together with the system version the entry relates to, and update that entry as soon as the intended purpose, the status or the conformity documentation changes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-49-registration","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis","legacy_id":"raip:obligation:article-4a-bias-testing-legal-basis","type":"obligation","slug":"article-4a-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffee7eb28c48cc8a2586f097f3abec38cbe7590c73e15b9845f9295f8f095d4c","label":"Article 4a: legal basis for bias testing with special categories of personal data","summary":"Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are open here, and the risk runs the other way round than with a right such as Article 86: a broad reading here benefits the controller and not the data subject, because this concerns data on ethnicity, health, religion, trade union membership and sexual orientation. Where in doubt the narrow reading is therefore the safe one. First, the reach of \"other AI systems and models\" in paragraph 2, which on its face covers any AI system and any model and for which no delimitation exists. We read it on its face, but with the threshold in paragraph 2, point (a), as the real boundary: without a consequence for health and safety, fundamental rights or prohibited discrimination there is no basis. A defensible alternative reading is that paragraph 2 is confined to systems comparable to the examples in recital 9, such as scoring tools for permits and public services. Second, the relationship with Article 9 GDPR. Recital 9 states that the extension is subject to the same limitations, conditions and safeguards and thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, so we read Article 4a as the Union law measure that point requires, with the safeguards carried by the six conditions themselves. The counterargument stands against that and has not gone away, but it has narrowed since 27 July 2026: the anchoring sits in a recital and not in the article, and the article itself designates no ground from Article 9(2). What no longer supports that counterargument is Article 2(7). Until 27 July 2026 that paragraph left the GDPR unaffected without reservation, but it was replaced by Article 1, point 2(b), of Regulation (EU) 2026/1744 and now reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The Union legislature therefore carved the reservation out for Article 4a precisely, which points towards reading Article 4a as the Union law measure itself rather than a mere cross-reference to the GDPR. Anyone citing this object while quoting the former wording of Article 2(7) is quoting a replaced provision. A defensible alternative reading remains that a national or Union measure with specific safeguards is still needed alongside it, but it now rests only on the absence of an express designation in the article itself. On the date from which the basis operates, part is settled and part is not. What is settled is what recital 9 says, namely that the basis should apply from the date of entry into application of Regulation (EU) 2024/1689; that has been read and is not a house reading. What remains open is which date this object therefore carries. We hold to 27 July 2026, the day Article 4a entered the text, because a basis that was not yet there was in fact not available. The alternative reading follows recital 9 literally and lets the basis reach back to the date of application of the base Regulation. That difference is not academic for anyone who has to justify processing from that period. The editorial statement below marks that choice as our inference.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted"],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":["praxikon:eu:ai-act:control:bias-testing-data-deletion"],"template_ids":["praxikon:eu:ai-act:template:article-4a-legal-text"],"conditions":[{"id":"article-4a-paragraph-1-high-risk-provider-only","operator":"all","description":"Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2."},{"id":"article-4a-paragraph-2-wider-circle-with-harm-threshold","operator":"all","description":"Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it."},{"id":"article-4a-cumulative-conditions","operator":"all","description":"The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data."}],"exceptions":[{"id":"article-4a-no-duty-to-test","operator":"not","description":"Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, to the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur: (a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data; (b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation; (c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations; (d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties; (e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and (f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 2 provides that providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that: (a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and (b) all of the conditions and safeguards set out in paragraph 1 are applied. Paragraph 2 closes with a separate subparagraph: this paragraph does not create any obligation to conduct such bias detection and correction. Article 4a has no paragraph 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts Article 4a into Regulation (EU) 2024/1689 by Article 1, point 6, and deletes Article 10(5) by Article 1, point 9(b). The same point 9 replaces Article 10(1) and Article 10(6) so that they now refer to the quality criteria in Article 4a(1). The basis therefore no longer sits with the requirements for high-risk systems in Chapter III, but as a standalone article in Chapter I, immediately after Article 4, while Article 10 refers back to it from the outside. In the Dutch language version of the Official Journal the inserted article is numbered \"artikel 4 bis\"; \"Article 4a\" is the English numbering of the same provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same amending Regulation replaces Article 2(7) of Regulation (EU) 2024/1689 by Article 1, point 2(b). Since 27 July 2026 that paragraph reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The previous version of that paragraph carried no such reservation for Article 4a.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 9 of Regulation (EU) 2026/1744 states that bias detection and correction constitute a substantial public interest, that the extended legal basis is subject to the same limitations, conditions and safeguards as the existing Article 10(5), and that this thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, Article 10(2), point (g), of Regulation (EU) 2018/1725 and Article 10, point (a), of Directive (EU) 2016/680. The same recital states that the legal basis established by Article 4a should apply from the date of entry into application of Regulation (EU) 2024/1689, so as to enable providers of high-risk AI systems lawfully to undertake bias detection and correction activities in preparation for compliance with the requirements for high-risk AI systems. Article 4 of the amending Regulation governs only entry into force on the third day following publication and provides for no deferred application; the amended Article 113, third paragraph, point (a), provides that Chapters I and II apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026. Article 4a sits in Chapter I and falls outside that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Three things matter more in practice than the relocation itself. The first is that this article instructs you to do nothing. Paragraph 2 says so in as many words, and no date by which anything must be done belongs with it either. The second, and the more dangerous misreading, is that the move into Chapter I means you may now start collecting sensitive attributes because you want to run fairness measurements. What has widened is the set of parties, not the room inside the basis: recital 9 expressly states that the same limitations, conditions and safeguards apply as under the former Article 10(5). In practice it therefore starts with a written justification of why synthetic or anonymised data do not suffice, and not with assembling a dataset. The third is the condition that bites hardest and appears in no summary: point (d) provides that the data are not transmitted, transferred or otherwise accessed by other parties. That is in effect a ban on outsourcing. An external fairness vendor, a bias auditing firm, a research partner or a cloud party that can reach the data itself does not fit inside this basis, however good the contract. Anyone who intended to buy in their bias testing must run it in house here, or work with data that are not a special category. Finally, watch your own documentation: records of processing, data protection impact assessments and AI policy documents that refer to Article 10(5) have been referring to a deleted provision since 27 July 2026. The same holds for documents citing Article 2(7) to argue that the GDPR prevails without qualification: that paragraph too has been replaced and now expressly reserves Articles 4a and 59. Two dates to close on, and the second is our inference rather than source text. Article 4a sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025, but the provision only entered the text on 27 July 2026; we therefore treat 27 July 2026 as the day the basis actually became available, while recital 9 states that it should apply from the date of entry into application of Regulation (EU) 2024/1689. Finally, note that the requirements in Article 10(2), points (f) and (g), which paragraph 1 refers to, themselves only start to apply on 2 December 2027 for Annex III systems and on 2 August 2028 for Annex I systems. The basis therefore deliberately runs ahead of the duty you use it for, exactly as recital 9 intends.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Carry out the data protection impact assessment before you start. Processing special categories at scale for bias testing engages Article 35 GDPR in almost every case, and Article 4a does not remove that assessment: it supplies the legal basis, not the risk appraisal. Then record, per processing operation, which paragraph of Article 4a you rely on, for which system or model, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access and at what point the data are deleted. In the same pass, review your record of processing activities, your impact assessments and your AI policy documents for references to Article 10(5) and replace them with Article 4a. Set the deletion moment as a monitored deadline rather than an intention, verify that no external party can reach the data, and align the justification with your data protection officer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4a-bias-testing-legal-basis","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-5-prohibited-practices","legacy_id":"raip:obligation:article-5-prohibited-practices","type":"obligation","slug":"article-5-prohibited-practices","version":"1.0.0","effective_at":"2025-02-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"674c4b85d1cf177b2ab9256989e18b2d685fdb69388f02f22bcc8cebd4f5faf8","label":"Article 5: prohibited practices","summary":"The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.","topics":["prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-5-screen"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-5-screening-record"],"control_ids":["praxikon:eu:ai-act:control:article-5-intake-gate"],"template_ids":["praxikon:eu:ai-act:template:article-5-legal-text"],"conditions":[{"id":"article-5-listed-practice","operator":"any","description":"Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement."}],"exceptions":[{"id":"article-5-narrow-exceptions","operator":"not","description":"The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance."}],"statements":[{"kind":"official_fact","text":"The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5, Article 99(3) and Article 113(a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment to Article 5 and transition to 2 December 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(a)-(h)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5 read with Article 6 classification order","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-5-prohibited-practices","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 5 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-50-transparency","legacy_id":"raip:obligation:article-50-transparency","type":"obligation","slug":"article-50-transparency","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"239fbac0e4728dc239352b2f88b199c3cc098082ff72e2972b4b5e8a2b121406","label":"Article 50: transparency","summary":"Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-50-disclosure"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-50-implementation-record"],"control_ids":["praxikon:eu:ai-act:control:article-50-release-check"],"template_ids":["praxikon:eu:ai-act:template:article-50-checklist"],"conditions":[{"id":"article-50-direct-interaction","operator":"any","description":"An AI system is intended to interact directly with natural persons."},{"id":"article-50-synthetic-content","operator":"any","description":"The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario."}],"exceptions":[{"id":"article-50-obvious-interaction","operator":"not","description":"The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context."},{"id":"article-50-legacy-marking-grace","operator":"not","description":"Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026."}],"statements":[{"kind":"official_fact","text":"Article 50 applies since 2 August 2026. The precise duty differs by scenario: direct AI interaction, machine-readable marking, emotion recognition or biometric categorisation, deepfakes and certain public-interest text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1)-(5) and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A generic rule that all AI content must always carry a visible label is too broad. First classify the specific Article 50 scenario.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Final guidelines, scope by Article 50 paragraph","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each system, record the applicable paragraph, responsible actor, implemented disclosure or marking and how it was tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Implementation guidance for providers and deployers","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-50-transparency","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","label":"Final Commission guidelines"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification","legacy_id":"raip:obligation:article-52-systemic-risk-classification","type":"obligation","slug":"article-52-systemic-risk-classification","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fda72f0c021ed141ad0881c569a2e4d7e59aefdcec7c95a562b9f547352a974e","label":"Article 52: notification of a GPAI model with systemic risk","summary":"The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"settled","interpretation_note":null,"obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply"],"action_ids":["praxikon:eu:ai-act:action:notify-systemic-risk-threshold","praxikon:eu:ai-act:action:request-systemic-risk-reassessment"],"evidence_ids":["praxikon:eu:ai-act:evidence:systemic-risk-notification-file"],"control_ids":["praxikon:eu:ai-act:control:systemic-risk-notification-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-52-legal-text"],"conditions":[{"id":"article-52-notification-trigger","operator":"all","description":"Applies to the provider of a general-purpose AI model as soon as that model meets the condition in Article 51(1), point (a): high impact capabilities, which under Article 51(2) are presumed where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. The two-week period runs from the moment that requirement is met or it becomes known that it will be met. The second route to systemic risk, a Commission designation under Article 51(1), point (b), or Article 52(4), is not covered here: Article 52(1) refers only to point (a)."}],"exceptions":[{"id":"article-52-legacy-models-transitional","operator":"not","description":"For general-purpose AI models placed on the market before 2 August 2025, Article 111(3) provides that the provider shall take the necessary steps to comply with the obligations of this Regulation by 2 August 2027. For those models the governing date is therefore 2 August 2027 and not the two-week period."}],"statements":[{"kind":"official_fact","text":"Article 51(1), point (a), classifies a general-purpose AI model as a model with systemic risk where it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; Article 51(2) provides that a model is presumed to have such capabilities where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. Article 51(1), point (b), reads in full: based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. The requirement of equivalent capabilities or impact and the anchoring in Annex XIII are therefore part of the norm and not only of the procedure. Article 51(3) provides in addition: the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. The 10^25 threshold above is therefore movable; as long as that act does not exist, the threshold applies as it stands in paragraph 2. See data/ai-act/delegated-acts.json, key praxikon:eu:ai-act:delegated-act:article-51-3-thresholds. Article 52(1) refers only to point (a) and provides that the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met, and that the notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. Paragraph 2 allows the provider to present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although the model meets that requirement, it does not present systemic risks due to its specific characteristics and should therefore not be classified as a general-purpose AI model with systemic risk. Paragraph 3 provides that where the Commission concludes that those arguments are not sufficiently substantiated and the provider was not able to demonstrate that the model does not present systemic risks due to its specific characteristics, it shall reject those arguments and the model shall be considered to be a general-purpose AI model with systemic risk. Paragraph 4 empowers the Commission to designate a model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of the criteria set out in Annex XIII, and empowers it to adopt delegated acts in accordance with Article 97 to amend Annex XIII by specifying and updating the criteria set out in that Annex. Paragraph 5 provides that upon a reasoned request of a provider whose model has been designated pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII, that such a request shall contain objective, detailed and new reasons that have arisen since the designation decision, that providers may request reassessment at the earliest six months after the designation decision, and that where the Commission decides to maintain the designation a further six months must pass. Paragraph 6 provides that the Commission shall ensure that a list of general-purpose AI models with systemic risk is published and kept up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 111 states that the cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Recital 112 states that the provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a model will meet the requirements that lead to the presumption, and that this is especially relevant in relation to the threshold of floating point operations because training takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers are able to know if their model would meet the threshold before the training is completed. The same recital states that in the context of that notification the provider should be able to demonstrate that the model exceptionally does not present systemic risks, that the information allows the AI Office to anticipate the placing on the market of models with systemic risks, and that it is especially important for models planned to be released as open-source. Recital 113 states that the Commission should be empowered to designate a model where it becomes aware that the model meets the requirements which previously had either not been known or of which the provider failed to notify it, and that a system of qualified alerts from the scientific panel should exist in addition to the monitoring activities of the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(3) provides that providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) state in point (63) that a downstream modifier is considered to be the provider of the modified model where the training compute used for the modification is greater than a third of the training compute of the original model, and in point (64) that where the downstream modifier cannot know and cannot estimate the original value, that threshold is replaced by a third of 10^25 FLOP where the original model is a model with systemic risk and otherwise by a third of 10^23 FLOP. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1). The guidelines are not binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission enforcement powers for general-purpose AI models and the fine regime of Article 101 have been active since 2 August 2026. Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only duty in this chapter with a numbered deadline, and two weeks is short. Other duties are also tied to a clock, only without a figure: Article 55(1), point (c), requires serious incidents to be reported to the AI Office without undue delay. The question here is therefore not whether you can notify, but whether you see the threshold being crossed in time. Recital 112 leaves little room to push that back: the legislator expressly assumes that the upfront allocation of compute lets you know before training ends that you will meet the threshold. The remaining edge question is how firm that knowledge is for a run not yet allocated, and it is small next to the duty itself. Four things are missed in practice. The first is the transitional rule: if your model was already on the market before 2 August 2025, Article 111(3) gives you until 2 August 2027, and that is the difference between two weeks and two years. The second is the reach of the trigger: only the threshold route of Article 51(1), point (a), starts this clock. If your model is designated by the Commission under Article 51(1), point (b), or Article 52(4), Article 55 begins without Article 52 asking anything of you. The third is the reversal in the last sentence of paragraph 1: if the Commission becomes aware of a model it was not notified about, it may designate it, and you then hold the conversation from a designation rather than from your own file. Since 2 August 2026 the Article 101 fine regime stands behind that. The fourth is the rebuttal route in paragraph 2: those arguments belong with the notification and not after it, so they must already be ready at the moment you notify. Once designated, only paragraph 5 remains, and that route is slow: six months after the decision at the earliest, and only with objective, detailed and new reasons that have arisen since it. The text names the Commission as addressee; recital 112 and Article 55(1), point (c), name the AI Office, which performs this task within the Commission. For an organisation that merely uses an external model this article does not bite: it addresses the provider of the model. That does not put further development out of reach: under point (71) of guidelines C(2025) 5045 final, a party that becomes the provider of a systemic-risk model through a modification must notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model and not merely a user, and whether your model was already on the market before 2 August 2025, because the date in Article 111(3) then applies instead of the two-week period. If you are the provider of a new model, record the planned and the consumed training compute per training run, including pre-training, synthetic data generation and fine-tuning, because recital 111 counts all three. Agree who notifies once the threshold comes into view, so the two-week period is not spent finding an owner, and tie that to the moment compute is allocated rather than to the end of the run. Keep the reasoning with which you would argue that the model does not present systemic risks ready before you notify, because it belongs with the notification. If you have already been designated under paragraph 4, build deliberately towards objective, detailed and new reasons that have arisen since the designation decision, because only those get you to a reassessment after six months. Retain the notification, the substantiation sent with it, any reassessment request and the Commission response as a living file per model version.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-52-systemic-risk-classification","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines C(2025) 5045 final on the scope of the GPAI obligations"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-53-gpai","legacy_id":"raip:obligation:article-53-gpai","type":"obligation","slug":"article-53-gpai","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55f22a1c21f936ec956fc61f7db4f29defb4524294046799c13af57745cd8b36","label":"Article 53: GPAI model providers","summary":"Documentation, information, copyright and transparency duties for providers of general-purpose AI models.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:gpai-document"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-compliance-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-documentation-change-control"],"template_ids":["praxikon:eu:ai-act:template:gpai-guide"],"conditions":[{"id":"gpai-union-market","operator":"all","description":"The party is a provider of a GPAI model placed on the Union market."},{"id":"gpai-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the duties apply from that time. Models placed on the market before 2 August 2025 must comply by 2 August 2027."}],"exceptions":[{"id":"gpai-open-source-limited-exception","operator":"not","description":"The open-source exception is limited and retains, among other things, the copyright policy and public training-content summary. Additional duties apply to models with systemic risk."}],"statements":[{"kind":"official_fact","text":"Article 53 applies since 2 August 2025 to new GPAI models. Providers maintain technical documentation, provide information to downstream providers, operate a Union copyright policy and publish a sufficiently detailed summary of training content.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1), Annex XI and Annex XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable obligations by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An organisation merely using an external GPAI model does not thereby automatically become a GPAI model provider. First determine its role in the value chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Scope and provider qualification guidance","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record model versions, role qualification, documentation owners, downstream information, copyright policy and training summary in one change-controlled file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53 and Annexes XI-XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-53-gpai","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative","legacy_id":"raip:obligation:article-54-gpai-authorised-representative","type":"obligation","slug":"article-54-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c470c29e8f0c2ad222dc0517b6a9437615474bfc6429e9c37b90eb35572d5c5","label":"Article 54: authorised representative of a provider of a GPAI model","summary":"A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-gpai-authorised-representative"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-representative-mandate-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-mandate-review"],"template_ids":["praxikon:eu:ai-act:template:article-54-legal-text"],"conditions":[{"id":"article-54-scope","operator":"all","description":"Applies where the model qualifies as a general-purpose AI model within the meaning of Article 3(63), its provider is established in a third country, and that model is placed on the Union market. The appointment is made by written mandate within the meaning of Article 3(5), which is not only given but also accepted, and it is made before the model is placed on the market. The moment at which the latter occurs is fixed less sharply for a model than for a system; see the editorial interpretation."},{"id":"article-54-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the appointment duty applies from that moment. Providers of models placed on the market before 2 August 2025 shall, under Article 111(3), take the necessary steps to comply with the obligations of the Regulation by 2 August 2027."}],"exceptions":[{"id":"article-54-open-source-exception","operator":"not","description":"Paragraph 6 excludes the obligation for providers of AI models released under a free and open-source licence that allows access, usage, modification and distribution, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available. That exception falls away as soon as the model presents a systemic risk. Whether a given release qualifies is a factual test that has not been settled anywhere; we read it narrowly, so a partially public release does not qualify."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union. Paragraph 2 provides that the provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider. Paragraph 3 provides that the authorised representative shall perform the tasks specified in the mandate received from the provider, that it shall provide a copy of the mandate to the AI Office upon request in one of the official languages of the institutions of the Union, and that for the purposes of the Regulation the mandate shall empower the authorised representative to carry out the following tasks: (a) verify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider; (b) keep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative; (c) provide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in that Chapter; (d) cooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union. Paragraph 4 provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with the Regulation. Paragraph 5 provides that the authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to the Regulation, and that in such a case it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor. Paragraph 6 provides that the obligation set out in that Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 113(3)(b) provides that Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Article 54 sits in Chapter V and therefore applies from 2 August 2025.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. Article 101 is excluded by Article 113(3)(b) from the earlier application of Chapter XII and has therefore applied since 2 August 2026. The obligation in Article 54 has thus applied since 2 August 2025, while the Commission fining power behind it exists only since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in the Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article touches two parties that rarely see themselves that way. The first is the model provider outside the Union that assumes nothing is required until a European customer asks: paragraph 1 places the appointment before the placing on the market, so the representative should exist before the first user in the Union can access the model. The second is the European party that accepts the mandate. It is not stepping into a mailbox role, but note how paragraph 3 is built: the first sentence obliges it to perform the tasks the mandate assigns to it, and only then does the article list what the mandate empowers it to do. Points (a) to (d) are therefore mandate content and empowerment, and its duty runs through them. That is where this article leaves its sharpest question open: is a representative that accepts a mandate omitting task (a) or (b) itself in breach, or does the failure rest entirely with the provider that drew up the mandate. We read paragraph 3 as making the list mandatory minimum content, so that a mandate lacking it does not satisfy the article, which leaves the provider answerable under paragraph 1 and the representative answerable for what it did accept. A defensible alternative reading is that a representative signing without those powers takes on a task it cannot discharge and thereby falls short itself. So do not assume the ten year retention in point (b) rests on you automatically, or automatically does not; write it out. Paragraph 5 closes this off in a way that is often missed: a representative that considers, or has reason to consider, that the provider is breaching its obligations terminates the mandate and immediately informs the AI Office. That is a duty rather than a power, and it calls for access to the documentation agreed in advance and for a moment at which that access is tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Three things about the timeline and the scope. First, the difference between duty and enforcement: the duty has applied since 2 August 2025, but Article 101 is excluded from the earlier application, so the Commission can only fine since 2 August 2026. For a provider outside the Union discovering today that it has no representative, that means: in breach for well over a year, and now also exposed to a fine. Second, the relationship with Article 22. That article carries the same figure for high-risk AI systems, starting on 2 December 2027 and 2 August 2028; Article 54 is the separate route for general-purpose AI models and has applied since 2 August 2025. Anyone looking up the role of authorised representative finds both and needs to know which route applies. Third, the trigger in paragraph 1. The Regulation fixes the moment of placing on the market less sharply for a model than for a system, and for a model made available only through an interface from a third country there is no case law. We read the duty as starting once the model is made available to users in the Union in the course of a commercial activity, because paragraph 1 attaches to placing on the market and not to establishment in the Union. A defensible alternative reading is that making a model available through an interface is not placing the model itself on the market, so that the duty only arises on an actual supply of the model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model or only a user, because only the provider appoints. If you are established outside the Union, put the mandate in writing before the model becomes available here, and write the four tasks in paragraph 3 into it expressly, together with the access to the Annex XI documentation and the point of contact under paragraph 4. If your model was already on the market before 2 August 2025, work to 2 August 2027 rather than to today. If you are only now discovering that there is no representative, assume the duty has run since 2 August 2025 and that the Commission has been able to fine since 2 August 2026; remedy first and record when you did. If you accept a mandate, agree in advance how you carry out the verification in paragraph 3(a), who holds the copy for ten years, and at what moment you test whether termination under paragraph 5 is called for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-54-gpai-authorised-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/54","label":"Read Article 54 in the AI Act Explorer"},{"relation":"related","href":"/en/ai-act/artikel/53","label":"Article 53: the duties the representative verifies"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk","legacy_id":"raip:obligation:article-55-gpai-systemic-risk","type":"obligation","slug":"article-55-gpai-systemic-risk","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589","label":"Article 55: GPAI models with systemic risk","summary":"Additional duties for the most capable general-purpose AI models, on top of Article 53.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record"],"control_ids":["praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control"],"template_ids":["praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text"],"conditions":[{"id":"article-55-gpai-systemic-risk-scope","operator":"all","description":"The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission."}],"exceptions":[{"id":"article-55-gpai-systemic-risk-exception","operator":"not","description":"The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance."}],"statements":[{"kind":"official_fact","text":"Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 55 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice","legacy_id":"raip:obligation:article-56-gpai-codes-of-practice","type":"obligation","slug":"article-56-gpai-codes-of-practice","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6e6afc9742736b52408f8c38c9435fc8be751641392f5d0b5d57a34afee4c1c","label":"Article 56: codes of practice for general-purpose AI models","summary":"The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.","topics":["governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record"],"control_ids":["praxikon:eu:ai-act:control:article-56-code-commitment-review"],"template_ids":["praxikon:eu:ai-act:template:article-56-legal-text"],"conditions":[{"id":"article-56-scope-gpai-provider","operator":"any","description":"Arises for the provider of a general-purpose AI model: it may be invited under paragraph 3 to participate in the drawing up of a code of practice, and under paragraph 7 to adhere to a code of practice."},{"id":"article-56-scope-value-chain","operator":"any","description":"Arises for other stakeholders: paragraph 3 names civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, that may support the process."}],"exceptions":[{"id":"article-56-limited-adherence-without-systemic-risk","operator":"not","description":"Paragraph 7 provides that for providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code. A provider without a systemic-risk model therefore does not have to sign up to the systemic-risk part in order to rely on the code."},{"id":"article-56-voluntary-instrument","operator":"not","description":"Article 56 does not impose a separate obligation on the provider. Paragraphs 3 and 7 speak of inviting, not of requiring, and the obligations themselves remain those of Articles 53 and 55. Not signing is therefore not an infringement of Article 56."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches. Paragraph 2 provides that the AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues: (a) the means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments; (b) the adequate level of detail for the summary about the content used for training; (c) the identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate; (d) the measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain. Paragraph 3 provides that the AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that the AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level. Paragraph 5 provides that the AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants. Paragraph 6, as replaced by Article 1, point (21), of Regulation (EU) 2026/1744, provides that the Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice. The power to approve a code of practice by implementing act and give it general validity within the Union, which sat in the second subparagraph of paragraph 6 until 27 July 2026, lapsed with that replacement. Paragraph 7 provides that the AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (21), replacing Article 56(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 8 provides that the AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards. Paragraph 9 provides that codes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7. The second subparagraph of paragraph 9 provides that if, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A code of practice is a voluntary instrument, and that word does all the work here. Signing creates no new obligation: your obligations remain those of Articles 53 and 55, and Article 56 changes nothing about them. Not signing is not an infringement either, because paragraphs 3 and 7 speak of inviting and not of requiring. What does shift is the burden of proof. A provider adhering to a code can point to a shared elaboration, assessed by the AI Office and the Board, when a regulator asks how it keeps its documentation up to date, how detailed its summary about the training content is, or how it assesses and manages systemic risk. A provider that does not sign has to write that elaboration itself and defend it itself, up to and including the question why its own approach is at least as good. That is not a legal difference in the norm, but it is a large difference in what is on the table when something is asked. Two things that are often conflated here. First: paragraph 7 allows a provider without a systemic-risk model to limit itself to the obligations in Article 53, unless it explicitly declares its interest in the full code. Partial participation is therefore an expressly foreseen choice and not half-heartedness. Second: paragraph 9 puts a stick behind the door that does not rest on you but does reach you. If no code comes about, or if the AI Office deems it inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. Those rules, unlike a code, are not voluntary.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Precision is in order about the state of play, because this is where the market overstates the most. It is established that the General-Purpose AI Code of Practice was published on 10 July 2025; that code is archived in this repository as three chapter PDF files, on transparency, copyright and safety and security, and it is present as a source record in this knowledge base. Whether an approving implementing act followed was not established for the period up to 27 July 2026, and after that date it is no longer the right question: paragraph 6 no longer carries that power. Since then the question is whether the Commission has published its assessment of adequacy. That too is not established here, and for as long as that is the case you must not read anywhere that the code has been approved or has general validity within the Union. That distinction is not a formality: a published code is a text you can voluntarily adhere to, a code approved by implementing act is on top of that an instrument with general validity in the Union. Anyone mistaking the first for the second overestimates what a signature buys and underestimates what they still have to record themselves. The content of the three chapters was also not read in this build, so nothing in this object says anything about what exactly is in them. In practice that means the following. Check the approval status yourself and by date before you rely on the code in a conversation with a regulator or a customer, and record which version of the code and which chapter your adherence relates to. A code may be reviewed and adapted under paragraph 8, in particular in light of emerging standards, so a reliance on the code without a version reference ages on its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the question whether you adhere to a code of practice as a decision that is taken and recorded, not as something that happens by itself. Record per model: do you adhere to a code, to which version and to which chapter, and if not, which elaboration of your own you apply instead for the issues named in paragraph 2, namely keeping the information in Article 53(1), points (a) and (b), up to date, the level of detail of the summary about the training content, and, where you offer a systemic-risk model, the identification and management of systemic risk. Decide explicitly whether under paragraph 7 the obligations in Article 53 are enough for you or whether you join the full code, and note that choice with a date and an authorised signatory. Before you rely on a code externally, check whether the Commission has published its assessment of adequacy under the amended paragraph 6, and claim no more than you can point at that moment. Do not ask for an approving implementing act: that power has not existed since 27 July 2026, and asking for it is asking for a decision nobody can take any more. Finally, put a review moment in your own calendar: paragraph 8 provides for review and adaptation of codes in light of emerging standards, and paragraph 9 allows the Commission to lay down common rules where a code fails to appear or is deemed inadequate, and both change what you are relying on without anyone calling you.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-56-gpai-codes-of-practice","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes","legacy_id":"raip:obligation:article-57-regulatory-sandboxes","type":"obligation","slug":"article-57-regulatory-sandboxes","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2706a2688e0c2d602f40bf5b061f6dba9310214d79ef9a74b47600c72bf69226","label":"Article 57: AI regulatory sandboxes","summary":"Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-57-sandbox-application-and-plan"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-57-written-proof-and-exit-report"],"control_ids":["praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield"],"template_ids":["praxikon:eu:ai-act:template:article-57-regulatory-sandboxes-legal-text"],"conditions":[{"id":"article-57-regulatory-sandboxes-scope","operator":"all","description":"Relevant where you are a provider or prospective provider of an innovative AI system that you want to develop, train, test or validate before placing it on the market or putting it into service, and you want up-front certainty about classification or about how you meet the requirements of this Regulation."}],"exceptions":[{"id":"article-57-regulatory-sandboxes-exception","operator":"not","description":"Participation is voluntary. Article 57 places the duty on the Member State to provide a sandbox, not on you to join one. A Member State may also fulfil that duty by participating in an existing sandbox with equivalent national coverage. Article 57(4) leaves other regulatory sandboxes established under Union or national law unaffected."}],"statements":[{"kind":"official_fact","text":"Article 57(1) requires Member States to ensure that their competent authorities establish at least one AI regulatory sandbox at national level. The text of Regulation (EU) 2024/1689 as published in the Official Journal provides that the sandbox shall be operational by 2 August 2026, and that wording still stands unchanged on 9 August 2026 in the article text published by the European Commission. The timeline the European Commission publishes after the Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 places the milestone at 2 August 2027 instead, stating \"Member States should have at least one AI regulatory sandbox per country operational\". The consolidated text of Article 57(1) after the Omnibus has not been verified at article level; rely on the consolidated version on EUR-Lex for the exact date. Chapter VI, which contains Article 57, is not among the exceptions in Article 113 and therefore applies since 2 August 2026. Article 57(1) further provides that the obligation may also be fulfilled by participating in an existing sandbox, in so far as that participation provides an equivalent level of national coverage. Article 57(5) defines the sandbox as a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time, pursuant to a specific sandbox plan agreed between the provider or prospective provider and the competent authority, before the system is placed on the market or put into service. Such sandboxes may include testing in real world conditions supervised therein. Article 57(15) requires the AI Office to make publicly available, and keep up to date, a list of planned and existing sandboxes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common mistake is to read the sandbox as a delay or an exemption. It is neither. Article 57(11) leaves the competent authority's supervisory and corrective powers fully intact and expressly empowers it to suspend your testing or your participation, temporarily or permanently, where risks cannot be effectively mitigated. A sandbox is useful for exactly one profile: you are building an AI system that is likely to fall under Annex III, you are uncertain about its classification or about how to meet Chapter III, Section 2, and you want that uncertainty resolved before you go to market. If you are purely a deployer buying a system, the sandbox is not your route: at most you can join as a partner of the provider under Article 58(2), point (b). Second trap: 2 August 2027 is a duty on the Member State, not on you. The date on this item is therefore 2 August 2026: from that moment Chapter VI applies and the route is open to you. You cannot hang your own preparation on that date, and the date says nothing about whether your national sandbox will actually have capacity by then. Third trap: people confuse the Article 57 sandbox with Article 60 real-world testing. These are two distinct routes with different conditions. Real-world testing can take place inside the sandbox (Article 57(5) and Article 58(4)) or outside it under Article 60, and the safeguards differ.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish your role: only providers and prospective providers can enter on their own. Then use the AI Office's published list of planned and existing sandboxes (Article 57(15)) to find the sandbox open to you, in your Member State or jointly with others. Before you apply, state exactly which uncertainty you want resolved, ideally focused on classification under Article 6 or on a specific requirement in Chapter III, Section 2. Plan for the three-month decision period that Article 58(2), point (a), requires the implementing acts to ensure, build it into your product timeline, and ask the competent authority in writing which period it currently applies. On entry, record in writing what the sandbox plan covers, and on exit request both the written proof and the exit report.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-57-regulatory-sandboxes","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 57 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route","legacy_id":"raip:obligation:article-6-1-annex-i-product-route","type":"obligation","slug":"article-6-1-annex-i-product-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"69936813db0c35758e25c435a583907437346b30c52f1b9943517c31b41f9369","label":"Article 6(1): the product route to high risk","summary":"An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is mainly open is what condition (b) requires. The text of paragraph 1, point (b), asks whether the product must undergo a third-party conformity assessment, which reads as a reference to the procedure actually prescribed. Article 43(3), third subparagraph, as replaced by Regulation (EU) 2026/1744, points the other way: it subjects the opt-out from third-party assessment to an additional condition under this Regulation and expressly provides that classification as a high-risk AI system does not affect the choice of procedure. That presupposes such systems are high risk. The Commission draft guidelines of 19 May 2026 say the same: the fact that a manufacturer may rely on internal control based on harmonised standards does not affect classification under Article 6(1). We follow that reading and therefore assume a module A route does not take your system out of high risk where the legislature prescribed enhanced scrutiny for that product type. A defensible alternative reading holds to the letter of point (b): only those actually required to involve a third party fall under this route, and Article 43(3) concerns the procedure for an already classified system rather than classification itself. While the guidelines remain draft and the Court has not ruled, that difference in outcome is real. Second open point: the dates diverge within this route. Chapter III, Sections 1 to 3, applies from 2 August 2028, but Articles 102 to 110 apply from 27 July 2026. That range overlaps with what remains for products under Section B of Annex I but does not coincide with it: for Section B the amended Article 2(2) makes Article 6(1), Article 60a and Articles 102 to 112 applicable, so two articles more than the new point (d) brings forward. The date on this object is the Chapter III date, not that of the sectoral amendments. Third open point: machinery moved from Section A to Section B by the same amending Regulation. How the requirements land there depends on delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028 and have not yet been adopted.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-annex-i-product-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-i-product-route-record"],"control_ids":["praxikon:eu:ai-act:control:annex-i-product-route-change-gate"],"template_ids":["praxikon:eu:ai-act:template:article-6-1-legal-text"],"conditions":[{"id":"article-6-1-covered-product","operator":"all","description":"The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I. Whether the system is placed on the market independently of that product is irrelevant."},{"id":"article-6-1-third-party-assessment","operator":"all","description":"That product, or the AI system as a product itself, is required under that same harmonisation legislation to undergo a third-party conformity assessment with a view to its placing on the market or putting into service. Both conditions must be fulfilled together."}],"exceptions":[{"id":"article-6-1bis-non-safety-function","operator":"not","description":"Article 6(1a), inserted by Regulation (EU) 2026/1744, provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back as soon as failure or malfunctioning would endanger health and safety."},{"id":"article-6-1quater-non-health-safety-assessment","operator":"not","description":"Article 6(1c), as inserted, provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 43(3) was replaced by Regulation (EU) 2026/1744. The third subparagraph of the new text reads: where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by that harmonisation legislation. The first subparagraph of the same paragraph provides that the requirements set out in Chapter III, Section 2, apply to those high-risk AI systems and form part of that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(2) was replaced by Regulation (EU) 2026/1744 and reads: for AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. Articles 57, 58 and 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation. The original text named only Article 6(1), Articles 102 to 109 and Article 112, and limited the effect of Article 57 in the same way.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends Annex I: in Section A point 1 is deleted and in Section B point 21 is added, Regulation (EU) 2023/1230 on machinery. Point 1 of Section A was Directive 2006/42/EC on machinery. Machinery therefore moves from Section A to Section B. Regulation (EU) 2023/1230 is amended at the same time so that the Commission adopts delegated acts supplementing Annex III to that Regulation with health and safety requirements for AI systems classified as high risk pursuant to Article 6(1) of Regulation (EU) 2024/1689, reflecting the requirements of Chapter III, Section 2, and Articles 17, 19, 72 and 73. Those delegated acts shall apply by 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(1), point (e), provides that this Regulation applies to product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark. Article 25(3) provides that in the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system and shall be subject to the obligations under Article 16 under either of the following circumstances: (a) the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer; (b) the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market. Article 25(3) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The text of Article 113, third paragraph, point (c), as published in the Official Journal provides that Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces point (c) of the third paragraph of Article 113 with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The same amendment adds a point (d) to that paragraph: Articles 102 to 110 shall apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(2) was replaced and reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The inserted Article 2(13) provides that for high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection, and such limitation does not reduce the overall level of protection provided for by this Regulation. By 2 August 2027 the Commission shall adopt delegated acts specifying the systems concerned, the requirements that may be limited, the conditions and the scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (3), inserting Article 2(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For most organisations the first question is not whether their system is AI, but what function their AI component performs and which section of Annex I their product falls under. What often goes wrong is the idea that the conformity route chosen determines the classification: we apply harmonised standards, therefore internal control, therefore no third party, therefore no high risk. That reasoning does not hold. The replaced Article 43(3) attaches an additional condition under this Regulation to the opt-out and states in the same subparagraph that classification as a high-risk AI system does not affect the choice of procedure, and the draft guidelines of 19 May 2026 read Article 6(1) the same way. Where you can genuinely fall outside this route is through the inserted paragraphs 1a and 1c: a model that solely supports throughput or quality control and whose failure does not endanger health and safety, and a product that needed a third party only because of radio spectrum or electromagnetic interference. Two further things go wrong in practice. The first is the date: whoever put 2 December 2027 in the plan because that was the date in the news is planning on the Annex III route and not their own, and whoever notes only 2 August 2028 misses that Articles 102 to 110 have applied since 27 July 2026. The second is the section: machinery has been in Section B since 27 July 2026, no longer in Section A. For a machine builder that means a different regime, with the requirements landing through delegated acts in Annex III to Regulation (EU) 2023/1230 rather than directly through Chapter III of this Regulation. What stands: if you do not build the AI system yourself but put it in your product under your own brand, Article 2(1), point (e), and Article 25(3) make you the provider, with the obligations of Article 16, and not merely a customer of your software supplier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"List per product which Annex I legal act it falls under and whether that is Section A or Section B after the amendment of 27 July 2026, which conformity assessment procedure applies there, and which AI functions are safety components within the meaning of Article 3, point (14). Test classification not against the module you actually use but against whether the legislature prescribed enhanced scrutiny for that product type. For Section A products the provider follows the procedure required under that legal act and the requirements of Chapter III, Section 2, form part of that assessment; if you use the opt-out in Article 43(3), record which harmonised standards cover all requirements of Section 2. Determine whether Article 2(1), point (e), or Article 25(3) makes you the provider yourself. Plan on 2 August 2028 for Chapter III, and track separately that Articles 102 to 110 have applied since 27 July 2026. For existing products check whether Article 111(2) spares you as long as the design is not significantly changed, and whether 2 August 2030 applies for systems intended for use by public authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1-annex-i-product-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route","legacy_id":"raip:obligation:article-6-1bis-1quater-route","type":"obligation","slug":"article-6-1bis-1quater-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1a3c8f90e9a6725cbe17956c5c8b7e1eef30c09b708afd4f0758b446f53b35f","label":"Article 6(1a) to (1c): the tightened classification route","summary":"The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The legal text below is settled; our reading of the route is not, which is why the whole object stands as preliminary. Three things. First, the sharpest textual tension, and it is not where you would look for it. In the adopted text of paragraph 1a the qualifier \"non-safety related aspects of\" governs the entire list, including user assistance and performance optimisation. In recital 7 that qualifier attaches to quality control alone: it says this does not in particular include AI systems intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or non-safety related aspects for quality control operations. We read the operative text, so with the qualifier across the whole list. A defensible alternative is the recital-conform, narrower reading in which only quality control is limited to non-safety related aspects and the rest is excluded unconditionally. Second, what paragraph 1a looks at. The text says \"are used\", while recital 7 is explicit: the safety function should be an intended purpose of the system, determined by the provider, and the mere fact that an AI system is integrated into or operates within a regulated product does not, in itself, mean that it fulfils a safety function. That second sentence and the amended definition in Article 3, point (14), make this question less open than it seems; we read it as the intended purpose. The alternative reading remains that actual use decides, so that a provider loses the exclusion as soon as a customer deploys the system differently. Third, from when. The amended definition sits in Chapter I and operates now, and the paragraphs have been binding law since 27 July 2026. They steer a live classification only once the route itself applies: 2 December 2027 for Annex III, point 2, and 2 August 2028 for the Annex I route. A defensible alternative reading is that the paragraphs, sitting in Chapter III, Section 1, do not operate at all before the later date. One point of candour: the published definition object on Article 3, point (14), still carries the unamended text and the reading that a component need not have an identifiable safety function. That is exactly what is qualified here, and while both objects stand side by side the text in this object governs.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:assess-safety-component-role"],"evidence_ids":["praxikon:eu:ai-act:evidence:safety-component-assessment-record"],"control_ids":["praxikon:eu:ai-act:control:safety-component-reassessment-trigger"],"template_ids":["praxikon:eu:ai-act:template:article-6-1bis-1quater-legal-text"],"conditions":[{"id":"article-6-1-annex-i-route","operator":"any","description":"Applies where it must be determined whether an AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and whether that product is required to undergo a third-party conformity assessment. Because paragraph 1a writes itself for the purposes of this Regulation, the delimitation also bears on Annex III, point 2, where the notion of safety component is used for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity."},{"id":"article-6-1-section-a-only","operator":"all","description":"For the consequences under Chapter III only Annex I, Section A, counts. For products under Section B, including machinery since Regulation (EU) 2023/1230 was moved there, the amended Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 apply."}],"exceptions":[{"id":"article-6-1bis-non-safety-functions","operator":"not","description":"Paragraph 1a provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back: AI systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components."},{"id":"article-6-1quater-non-safety-conformity-assessment","operator":"not","description":"Paragraph 1c provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered as fulfilling the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Article 6(1) provides: irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts three paragraphs into Article 6. Paragraph 1a: \"For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.\" Paragraph 1b: \"Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.\" Paragraph 1c: \"A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).\"","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends the definition in Article 3, point (14). As amended it reads: \"safety component\" means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. Article 3 sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025. This amended definition therefore operates from the entry into force of the amending Regulation on 27 July 2026 and not only from some later application date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended Article 113, third paragraph, point (c), provides that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The added point (d) provides that Articles 102 to 110 shall apply from 27 July 2026. Annex III, point 2, uses the notion of safety component for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; that route falls under the 2 December 2027 date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation moves machinery out of Chapter III. In Annex I, Section A, point 1 (the reference to Directive 2006/42/EC) is deleted and Section B gains point 21: Regulation (EU) 2023/1230 on machinery. The amended Article 2(2) reads that for AI systems classified as high-risk in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. The amended Article 43(3) adds that the classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to manufacturers of products covered by Annex I, Section A, and that those manufacturers are not required to choose a procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if the Section A legislation does not require it. The new Article 2(13) provides that specific requirements or obligations under Articles 9 to 15 and 17 to 25 may be limited where Section A legislation provides an equivalent or higher level of protection, and obliges the Commission to adopt delegated acts on this by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"What changes in practice is what the discussion is about. Until now it was about whether your product falls under Annex I and whether a third party is involved. Those two questions remain, but a third one belongs in front of them: what function does your AI component actually perform. A recommendation model that optimises when a machine is serviced, or a model that improves throughput on a line, sits in the list in paragraph 1a, and such functions often ended up classified as safety components simply because they ran inside a regulated product. Be careful with quality control as an example: paragraph 1a names only the non-safety related aspects of it, and in many regulated products a vision model that flags deviations is safety QC. Paragraph 1b draws the line: as soon as failure or malfunctioning would endanger health and safety, the exclusion does not count. The question therefore moves from your product file to your failure analysis, and at most providers that analysis is recorded nowhere. Paragraph 1c is narrower: anyone who needed a third party only because of radio spectrum or electromagnetic interference does not meet paragraph 1, point (b), by that route. That paragraph too requires a weighing, because it works only if the third party is mandatory solely on account of those other risks; where your product falls under several Annex I acts, a second act may still satisfy the condition on health and safety grounds. Two things finally that move the stakes. Machinery no longer runs through this route: Regulation (EU) 2023/1230 now sits in Annex I, Section B, and for those products the amended Article 2(2) means Chapter III does not apply at all. And for Section A products the same Regulation pushes the other way: the amended Article 43(3) says expressly that classification under Article 6(1) does not affect the choice of conformity assessment procedure and pushes nobody towards a notified body who was not already headed there. So build your failure analysis as your own file, not as something you will have to put in front of a notified body anyway.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"This is our recommendation and not a legal duty: paragraphs 1a to 1c are delimiting rules and impose no obligation on anyone. First establish whether your product falls under Annex I, Section A or Section B; for Section B, which now includes machinery, Chapter III stops here. For Section A, record per AI component which function it performs, whether that is a safety function within the meaning of the amended Article 3, point (14), and what happens on failure or malfunctioning. Note which of the three paragraphs you apply and why. Use that file to support your own classification, not because a notified body asks for it: the amended Article 43(3) points the other way. Keep two dates apart: 2 December 2027 for the route via Annex III, point 2, and 2 August 2028 for the route via Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1bis-1quater-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-60-real-world-testing","legacy_id":"raip:obligation:article-60-real-world-testing","type":"obligation","slug":"article-60-real-world-testing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6306b9a0abce6764b0c4ebf4968aacf23cd2483dba7b750f1cb18716886ea751","label":"Article 60: testing in real world conditions outside a sandbox","summary":"If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-60-testing-plan-and-authorisation"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-61-informed-consent-record"],"control_ids":["praxikon:eu:ai-act:control:article-60-oversight-and-incident-response"],"template_ids":["praxikon:eu:ai-act:template:article-60-real-world-testing-legal-text"],"conditions":[{"id":"article-60-real-world-testing-scope","operator":"all","description":"Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22."}],"exceptions":[{"id":"article-60-real-world-testing-exception","operator":"not","description":"Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level."}],"statements":[{"kind":"official_fact","text":"Article 60(1) provides that testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, in accordance with that Article and the real-world testing plan, without prejudice to the prohibitions under Article 5. The Commission specifies the detailed elements of that plan by implementing act. The third subparagraph of paragraph 1 provides that the paragraph is without prejudice to Union or national law on the testing in real world conditions of high-risk AI systems related to products covered by the Union harmonisation legislation listed in Annex I. Article 60(2) allows providers or prospective providers to test at any time before placing on the market or putting into service, on their own or in partnership with one or more deployers or prospective deployers. Article 60(3) provides that such testing is without prejudice to any ethical review required by Union or national law. Article 60(4), point (f), caps the duration: no longer than necessary to achieve its objectives and in any case no longer than six months, which may be extended by an additional six months subject to prior notification to the market surveillance authority with an explanation of the need. Article 60(4), point (g), requires that subjects belonging to vulnerable groups due to age or disability are appropriately protected. Article 60(9) expressly states that the provider or prospective provider remains fully subject to applicable Union and national law on any damage caused in the course of their testing in real world conditions. Chapter VI, which contains Article 60, is not among the exceptions in Article 113 and applies since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Many organisations call what they do a pilot and assume that keeps them outside the Regulation. Article 60 shows that this does not hold once you test an Annex III system in real world conditions with real people and real outcomes. A full regime then applies: a plan, prior approval, registration with a Union-wide unique single identification number, informed consent, and a hard six-month clock with a maximum six-month extension. The heaviest requirement in practice is Article 60(4), point (k): the predictions, recommendations or decisions of the system must be capable of being effectively reversed and disregarded. If you are testing a selection, scoring or triage system whose output feeds straight into the workflow with nobody able to reverse it, your design does not qualify, however careful your consent form is. Note the timing too, because it is commercially interesting. Chapter VI applies since 2 August 2026, while the core obligations for standalone Annex III systems only apply from 2 December 2027. The testing route is therefore open before the requirements themselves bite, and that is exactly the window in which to validate your design rather than rebuild it later. Finally, Article 60(3) leaves any ethical review required under other law fully in place, and Article 60(9) expressly states that you remain fully subject to the applicable law on damage caused during the testing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory which running or planned trials are in fact real-world testing: real users, real data, outputs that feed into the workflow. Test those first against Article 60(4), point (k): can the output genuinely be reversed and disregarded? If not, redesign the trial before you submit anything. Then choose deliberately between two routes: supervised testing inside a sandbox under Article 57(5) and Article 58(4), or outside a sandbox under Article 60. Plan the six months realistically and decide in advance at which point you will request an extension, since that requires prior notification with a reasoned explanation. Check whether an ethical review is mandatory in your domain and start it in parallel, because Article 60(3) does not exempt you from it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-60-real-world-testing","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 60 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","legacy_id":"raip:obligation:article-61-informed-consent","type":"obligation","slug":"article-61-informed-consent","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e7ff043231fa794c9c21494315ad879b5bac9ab1195f761cfec85493be5acd92","label":"Article 61: informed consent of test subjects for testing in real world conditions","summary":"If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.","topics":["fundamental-rights","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-61-subject-information-pack"],"control_ids":["praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review"],"template_ids":["praxikon:eu:ai-act:template:article-61-legal-text"],"conditions":[{"id":"article-61-scope","operator":"all","description":"Applies for the purpose of testing in real world conditions under Article 60, that is where you are a provider or prospective provider of a high-risk AI system listed in Annex III and you test that system in real world conditions outside an AI regulatory sandbox. Article 60(4), point (i), makes informed consent in accordance with Article 61 one of the cumulative conditions under which such testing is allowed. Consent is obtained per subject prior to their participation. Article 61 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."},{"id":"article-61-joint-testing","operator":"any","description":"If under Article 60(2) you test in partnership with one or more deployers or prospective deployers, the condition stays with you as the provider, even where that party is the one in contact with the subject. Article 60(4), point (h), requires you and that party to conclude an agreement specifying your tasks and responsibilities; that is where you record who informs, who obtains the consent and who keeps the file."}],"exceptions":[{"id":"article-61-law-enforcement-carve-out","operator":"not","description":"The only exception sits not in Article 61 but in Article 60(4), point (i): in the case of law enforcement, where seeking informed consent would prevent the AI system from being tested in real world conditions, testing may proceed without that consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test is performed. Outside that context there is no exception to consent; Article 61 contains none of its own."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: for the purpose of testing in real world conditions under Article 60, freely-given informed consent shall be obtained from the subjects of testing prior to their participation in such testing and after their having been duly informed with concise, clear, relevant, and understandable information regarding: (a) the nature and objectives of the testing in real world conditions and the possible inconvenience that may be linked to their participation; (b) the conditions under which the testing in real world conditions is to be conducted, including the expected duration of the subject or subjects participation; (c) their rights, and the guarantees regarding their participation, in particular their right to refuse to participate in, and the right to withdraw from, testing in real world conditions at any time without any resulting detriment and without having to provide any justification; (d) the arrangements for requesting the reversal or the disregarding of the predictions, recommendations or decisions of the AI system; (e) the Union-wide unique single identification number of the testing in real world conditions in accordance with Article 60(4) point (c), and the contact details of the provider or its legal representative from whom further information can be obtained. Paragraph 2 provides: the informed consent shall be dated and documented and a copy shall be given to the subjects of testing or their legal representative.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 61(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 60(4), point (i), sets as a condition: the subjects of the testing in real world conditions have given informed consent in accordance with Article 61, or in the case of law enforcement, where the seeking of informed consent would prevent the AI system from being tested, the testing itself and the outcome of the testing in the real world conditions shall not have any negative effect on the subjects, and their personal data shall be deleted after the test is performed. Article 60(5) provides: any subjects of the testing in real world conditions, or their legally designated representative, as appropriate, may, without any resulting detriment and without having to provide any justification, withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data. The withdrawal of the informed consent shall not affect the activities already carried out. Article 60(2), as replaced by Article 1, point (24), of Regulation (EU) 2026/1744, provides: providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the high-risk AI system on their own or in partnership with one or more deployers or prospective deployers. Until 27 July 2026 that paragraph named only the Annex III route; the consent of Article 61 therefore now also applies when testing high-risk AI in a regulated product under Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only place in this Regulation where the individual consent of a natural person is a condition. Nowhere else does the lawfulness of something you do turn on a signature from the person it affects. That makes it tempting to reuse the existing GDPR consent form, and that is exactly where it goes wrong. Consent under Article 61 is consent to take part in a test; it is one of the cumulative conditions in Article 60(4) under which you may test in real world conditions. Whether, and on what basis, personal data may be processed in that test is not governed by Article 61 and this Regulation does not say so here. That remains a question of data protection law, and you answer it separately. The two do not coincide and one does not replace the other. Look as well at the content of the five points, because two of them appear in no standard form. Point (e) requires the Union-wide unique single identification number of the testing from Article 60(4), point (c). That number arises on registration, so you can only approach the subject once that registration is done; anyone who recruits first and registers afterwards has inverted the order. Point (d) requires you to explain how someone can request the reversal or the disregarding of the predictions, recommendations or decisions of the system. That is not only information: Article 60(4), point (k), requires those outputs to be capable of being effectively reversed and disregarded. If you cannot describe that mechanism, it probably does not exist and your test design does not qualify.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Note the difference between paragraph 1 and paragraph 2, because organisations usually build only one of the two. Paragraph 1 is about informing beforehand: concise, clear, relevant and understandable, on five topics. Paragraph 2 is about the evidence afterwards: the consent is dated, is documented, and the subject is given a copy. A tick box in an app that leaves a line in a log file does not satisfy paragraph 2: no copy was given and usually there is no dating that can be shown independently of the logging system. So build two artefacts rather than one: the information pack you hand over, and the dated consent record you keep and of which the subject holds a copy. A second point missed in the design is withdrawal. Article 61(1), point (c), promises the subject a right to withdraw at any time without detriment and without justification, and Article 60(5) works that out: withdrawal is always possible, immediate and permanent deletion of the personal data may be requested, and the withdrawal does not affect the activities already carried out. Anyone who promises that right in the form but has no route to carry it out has not delivered on the promise. The practical question is therefore not how your form reads, but who receives the withdrawal on Monday morning, within what period the data disappear, and where that is recorded. Finally, do not leave the division of roles implicit. If you test together with a deployer, that party is often the one facing the subject, while the condition stays with you as the provider. Article 60(4), point (h), gives you the instrument to settle that, and that is the agreement specifying your tasks and responsibilities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Draw up an information pack per test that names each of the five points of paragraph 1 separately, and check the pack line by line against those five points rather than against your existing privacy notice. Obtain the Union-wide unique single identification number from the registration under Article 60(4), point (c), and put it in the pack together with the contact details of the provider or the legal representative before you approach the first subject. Under point (d), describe the concrete mechanism through which someone can request the reversal or the disregarding of an output, with the place the request arrives and the period within which it is handled. Record a dated consent per subject and give a copy to the subject or the legal representative; keep that record separately from your application logs, so you can show it without consulting the system. Set up a withdrawal route with a named recipient, a period and a processing step for the request for immediate and permanent deletion of personal data, and rehearse that route once before the test starts. In the agreement with your deployer under Article 60(4), point (h), record who informs, who obtains consent, who keeps the record and who receives a withdrawal. If you test in the law enforcement domain and are considering the exception in Article 60(4), point (i), record in advance why seeking consent would prevent the testing, and how you ensure that the test has no negative effect and that the personal data are deleted after the test.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-62-sme-support-measures","legacy_id":"raip:obligation:article-62-sme-support-measures","type":"obligation","slug":"article-62-sme-support-measures","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"89d0012409a5635c7734726e3fa30d2a1fa3427dc6277cfe8f675f151cd5d5dc","label":"Article 62: measures for providers and deployers that are SMEs or start-ups","summary":"Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-62-claim-sme-facilities"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-62-sme-status-record"],"control_ids":["praxikon:eu:ai-act:control:article-62-fee-and-access-review"],"template_ids":["praxikon:eu:ai-act:template:article-62-legal-text"],"conditions":[{"id":"article-62-scope","operator":"all","description":"The priority access in paragraph 1, point (a), applies to SMEs, including start-ups, having a registered office or a branch in the Union, and only to the extent that they fulfil the eligibility conditions and selection criteria. The reduction of fees in paragraph 2 attaches to conformity assessments under Article 43 and to the capacity of an SME provider, including start-ups. Article 62 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."}],"exceptions":[{"id":"article-62-priority-access-not-exclusive","operator":"not","description":"Paragraph 1, point (a), expressly states that the priority access shall not preclude other SMEs, including start-ups, other than those referred to in that paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria. Priority is therefore an order of precedence and not an exclusive right, and it releases nobody from the eligibility conditions and selection criteria."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: Member States shall undertake the following actions: (a) provide SMEs, including start-ups, having a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes, to the extent that they fulfil the eligibility conditions and selection criteria; the priority access shall not preclude other SMEs, including start-ups, other than those referred to in this paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria; (b) organise specific awareness raising and training activities on the application of this Regulation tailored to the needs of SMEs including start-ups, deployers and, as appropriate, local public authorities; (c) utilise existing dedicated channels and where appropriate, establish new ones for communication with SMEs including start-ups, deployers, other innovators and, as appropriate, local public authorities to provide advice and respond to queries about the implementation of this Regulation, including as regards participation in AI regulatory sandboxes; (d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process. Paragraph 2 provides: the specific interests and needs of the SME providers, including start-ups, shall be taken into account when setting the fees for conformity assessment under Article 43, reducing those fees proportionately to their size, market size and other relevant indicators.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 62(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides: the AI Office shall undertake the following actions: (a) provide standardised templates for areas covered by this Regulation, as specified by the Board in its request; (b) develop and maintain a single information platform providing easy to use information in relation to this Regulation for all operators across the Union; (c) organise appropriate communication campaigns to raise awareness about the obligations arising from this Regulation; (d) evaluate and promote the convergence of best practices in public procurement procedures in relation to AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 62(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 62 is not an exemption but a facility, and that distinction is the whole article. Nowhere does it say that an SME or a start-up has to comply with less. What changes is the price and the access: priority access to the AI regulatory sandbox, tailored training and awareness raising, a channel to put questions, a seat at the standardisation table, and reduced fees for conformity assessment under Article 43. Anyone reading this article as an SME regime with lighter requirements is looking at the wrong provision; the only relief from a substantive requirement in this Regulation sits in Article 63 and touches only the quality management system of Article 17. Since 27 July 2026 that relief is available to SMEs, including start-ups, and no longer to microenterprises alone: Article 1, point (26), of Regulation (EU) 2026/1744 replaced Article 63(1) to that effect. A standalone small enterprise that is not a microenterprise therefore does fall within it, provided it has no partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Read paragraph 2 carefully as well, because it says something stronger than is usually assumed. It is not a power but an instruction: the fees are reduced, proportionately to the size of the provider, the market size and other relevant indicators. If you receive a quotation for a conformity assessment without that proportionality being made visible, that is a question you can put and whose answer you can record. Do not confuse that reduction with free access to an AI regulatory sandbox: that sits in Article 58(2), point (d), applies to SMEs including start-ups, and expressly leaves standing the exceptional costs that national competent authorities may recover in a fair and proportionate manner. Two different provisions, two different flows of money.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"In practice the core of this article is that you have to ask for it yourself. The Member State grants priority access to those who come forward and meet the eligibility conditions and selection criteria; priority will not operate by itself for anyone who does not apply. That makes two things important. First, that you can show you are an SME in the sense in which the Regulation uses that word, and that you have a registered office or a branch in the Union; that is a matter of file, not of conversation. Second, that you know which national body in your Member State staffs the channel in paragraph 1, point (c), because that channel is meant to provide advice and answer queries about implementation, including on participation in a sandbox. Point (d) is almost always skipped and is the most valuable part for a technical company: the participation of SMEs in the standardisation development process is facilitated. The harmonised standards will settle what counts as sufficient in practice; having a say in that text is cheaper than having to build to it later. Finally, factor paragraph 3 into your own planning. The AI Office provides standardised templates and maintains a single information platform. As long as no template exists for your topic, you build your own document; once one arrives, it is a template and not a licence, and the substantive requirement stays the same.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record once whether your organisation is an SME or a start-up in the sense in which this Regulation uses that word, with the reasoning and the date attached, and whether you have a registered office or a branch in the Union; refresh that file at every change in the corporate structure. Find out which national competent authority in your Member State runs the AI regulatory sandbox and which channel it offers for questions about implementation, and use that channel before you buy an expensive external route. If you apply for a conformity assessment under Article 43, ask explicitly with the quotation how the reduction proportionate to your size, the market size and other relevant indicators has been applied, and keep that answer with your procurement file. Sign up for the standardisation development process on the topics that touch your product, because that is the cheapest place to influence what later counts as sufficient. Before you build your own template, check whether the AI Office has already provided one, and use the single information platform as a first source rather than a secondary summary. Finally, do not assume that any of these facilities lightens a substantive requirement: in your planning, set out next to each facility which requirement continues to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-62-sme-support-measures","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-63-sme-derogations","legacy_id":"raip:obligation:article-63-sme-derogations","type":"obligation","slug":"article-63-sme-derogations","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"249cec1c5363acf6ee7e50aca22d6a1f93b27a07655d9cb2d2ebd8494810bcde","label":"Article 63: derogations for SMEs in the quality management system","summary":"SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Until 27 July 2026 this read microenterprises; Article 1, point (26), of Regulation (EU) 2026/1744 replaced paragraph 1 and widened the circle to SMEs. Which elements those are is for the Commission to set out in guidelines, considering the needs of SMEs and without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 rules out any wider reading: the provision shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.","topics":["high-risk-requirements","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-63-sme-eligibility-record"],"control_ids":["praxikon:eu:ai-act:control:article-63-simplification-boundary-review"],"template_ids":["praxikon:eu:ai-act:template:article-63-legal-text"],"conditions":[{"id":"article-63-scope","operator":"all","description":"Two cumulative conditions. The organisation is an SME, including a start-up, within the meaning of Recommendation 2003/361/EC, and it does not have partner enterprises or linked enterprises within the meaning of that Recommendation. A standalone small enterprise that is not a microenterprise is therefore covered since 27 July 2026. The thresholds and the notions of partner enterprise and linked enterprise sit in that Recommendation and not in this Regulation; anyone relying on this article tests against that text. The benefit touches only the quality management system required by Article 17, and only those elements of it that the Commission designates in its guidelines. Article 63 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."}],"exceptions":[{"id":"article-63-no-exemption-from-other-requirements","operator":"not","description":"Paragraph 2 expressly provides that paragraph 1 shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73. The risk management system, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity, post-market monitoring and the reporting of serious incidents therefore continue to apply in full."}],"statements":[{"kind":"official_fact","text":"Paragraph 1, as replaced by Article 1, point (26), of Regulation (EU) 2026/1744, provides: SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 provides: paragraph 1 of this Article shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 63(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 17(1) is the obligation to which the derogation in Article 63 relates and provides: providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects: (a) a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system; (b) techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article is called derogations and that word does more harm than good. Nothing is abolished. Paragraph 1 says that certain elements of a single obligation, the quality management system of Article 17, may be complied with in a simplified manner. Paragraph 2 then says in as many words that this shall not be interpreted as exempting those operators from other requirements or obligations under this Regulation, and names nine of them: Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73. That is the enumeration that heads off the misunderstanding, and it covers exactly the heaviest requirements: risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and cybersecurity, post-market monitoring, and the reporting of serious incidents. A microenterprise providing a high-risk system therefore does very nearly everything a large company does; only the form in which the quality management system is written down may be lighter. Two things to settle now. First the entry test, because it is stricter than it looks: on top of the thresholds in Recommendation 2003/361/EC there is the additional condition that you have no partner enterprises or linked enterprises within the meaning of that Recommendation. A holding by a parent company or a shared shareholder can break that condition, and that is a structural question you do not want to raise in the last week before an assessment. Second the reach of the simplification: which elements exactly may be lighter is not in the Regulation but in guidelines the Commission develops under this article. We make no claim here about which elements those are or whether those guidelines already exist; until they do, you build the Article 17 system as it stands and keep a note of which parts you would later want to simplify.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Put Article 63 next to Article 62 and the picture sharpens. Article 62 lowers the price and the threshold, Article 63 simplifies the form of a document. Together they are the only two places in this Regulation where the size of an undertaking legally makes a difference, and neither touches the substantive requirements for high-risk AI systems. Anyone who hears in a sales conversation or a grant application that the AI Regulation is softer for small companies can test that against these two articles and will find the claim too broad. Think as well about the commercial side of paragraph 2. The nine articles it names are precisely the items a buyer asks for: the risk management system, the data governance, the technical documentation, the logs, the instructions for use, the human oversight, the performance and security figures, the post-market monitoring and the incident reporting. A microenterprise invoking Article 63 in order not to produce those items will be found out in the first serious procurement process, before a regulator comes into view at all. The sensible reading is therefore the reverse: use Article 63 to keep your quality management system small and workable, and invest the time you win in the nine topics of paragraph 2, because that is what both your customer and your market surveillance authority will judge you on.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First test whether you fall within scope and record that test: are you a microenterprise within the meaning of Recommendation 2003/361/EC, and do you genuinely have no partner enterprises or linked enterprises within the meaning of that Recommendation? Put that second question to whoever knows the shareholding structure rather than to the product team, and repeat the test at every investment round or acquisition. Then build the Article 17 quality management system in full, and mark in your own documentation which elements you would want to simplify once the Commission guidelines on that exist; that way you do not start over when that text appears. Next, make an explicit list of the nine articles paragraph 2 names and set out per article who in your organisation produces the corresponding item and where it sits; that is the same list a buyer asks for and a market surveillance authority walks through. Put no sentence in quotations or contracts suggesting that your size releases you from a requirement. Finally, check whether Article 62 gives you something Article 63 does not, such as the reduced conformity assessment fee or priority access to a sandbox; those two tracks run separately and you can use both.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-63-sme-derogations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-71-eu-database","legacy_id":"raip:obligation:article-71-eu-database","type":"obligation","slug":"article-71-eu-database","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ceaa3da5b4cb893e068c9cbe5094b7934da65e8a20cc7cf57546945c0b877c06","label":"Article 71: EU database for high-risk AI systems listed in Annex III","summary":"The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things about the law itself are unsettled here. First, the date. Article 71 falls under the general application date of 2 August 2026, while the entry duties in paragraphs 2 and 3 hang on the registration in Article 49, whose Annex III route was shifted to 2 December 2027 by Regulation (EU) 2026/1744. We therefore read the practical deadline as 2 December 2027. Two alternative readings are defensible, and they point in opposite directions: the mild one is that the database exists from 2 August 2026 and only the entering follows the later date, so whoever registers earlier is not being early but on time; the hard one is that the amended Article 113, third paragraph, point (c), names only Chapter III, Sections 1, 2 and 3, while Article 49 sits in Section 5 of that same Chapter, so the registration duty may not have moved with it and you may already be late rather than early. Anyone planning against this deadline is planning against our reading and not against a settled fact. Second, the Article 60 route. Article 60 sits in Chapter VI and the provider or prospective provider testing in real world conditions today must register under Article 60(4), point (c), in accordance with Article 71(4). Whether that route moved with the Annex III deferral or already runs under the general date of 2 August 2026 is unsettled. The fact that 2026/1744 widened the scope of Article 60 to Annex I Section A and placed an Article 60a alongside it for Annex I Section B makes that question larger rather than smaller. This object does not carry that duty and the status here says nothing about it. Settled, and therefore no longer a ground for the preliminary status: the content of Section B of Annex VIII. Article 1, point (42), of Regulation (EU) 2026/1744 deletes points 7 and 9, and the reading above follows that text rather than the base regulation. One cross-reference does follow from it that the legislator did not chase down: Article 49(4) is unamended and still lists point 9 of Section B for the secure section, a point that no longer exists. Whoever works through that list literally is looking for a field that is not there. In addition, and this expressly does not carry the status because it is not an unsettled reading but a coverage gap of this dataset: paragraphs 1 and 6 address the Commission, which is not an actor here, so this object carries only the entry duties of paragraphs 2 and 3; and paragraph 3 also names whoever acts on behalf of a public authority, a role that does not exist separately alongside the body governed by public law, so a private party registering on behalf of a public authority has to assess for itself whether paragraph 3 rests on it.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date"],"action_ids":["praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data"],"evidence_ids":["praxikon:eu:ai-act:evidence:eu-database-entry-record"],"control_ids":["praxikon:eu:ai-act:control:eu-database-entry-currency"],"template_ids":["praxikon:eu:ai-act:template:article-71-legal-text"],"conditions":[{"id":"article-71-scope","operator":"any","description":"Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use."}],"exceptions":[{"id":"article-71-exception-annex-iii-point-2","operator":"not","description":"Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database."},{"id":"article-71-exception-secure-section","operator":"not","description":"Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there."},{"id":"article-71-exception-real-world-testing","operator":"not","description":"Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission shall, in collaboration with the Member States, set up and maintain an EU database containing the information referred to in paragraphs 2 and 3 concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60, and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications the Commission shall consult the relevant experts, and when updating them the Board. Paragraph 2 provides that the data listed in Sections A and B of Annex VIII shall be entered into the database by the provider or, where applicable, by the authorised representative. Paragraph 3 provides that the data listed in Section C of Annex VIII shall be entered by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4). Paragraph 4 provides that, with the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner, and that the information should be easily navigable and machine-readable. The same paragraph provides that the information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible to the public. Paragraph 5 provides that the database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation, and that such information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer. Paragraph 6 provides that the Commission shall be the controller of the database, shall make adequate technical and administrative support available to providers, prospective providers and deployers, and that the database shall comply with the applicable accessibility requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 71(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex VIII sets out which information is submitted upon registration and kept up to date thereafter. Section A, for providers registering in accordance with Article 49(1), lists thirteen points, including the name, address and contact details of the provider and of the authorised representative, the trade name and any additional unambiguous reference allowing identification and traceability of the system, a description of the intended purpose and of the components and functions supported, a basic and concise description of the information used and of the operating logic, the status of the system, the details and a scanned copy of the notified body certificate where applicable, the Member States where the system is available, a copy of the EU declaration of conformity referred to in Article 47 and the electronic instructions for use, which are not provided for the law enforcement, migration, asylum and border control management areas of points 1, 6 and 7 of Annex III. Section C, for deployers registering under Article 49(3), lists five points: the name, address and contact details of the deployer, the same details of the person submitting information on its behalf, the URL of the entry of the system in the database by its provider, a summary of the findings of the fundamental rights impact assessment carried out in accordance with Article 27, and where applicable a summary of the data protection impact assessment. Neither Section was amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Section B","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 22 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 49(4) lists exhaustively what goes into the secure non-public section, and that is less than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. The final subparagraph provides that only the Commission and the national authorities referred to in Article 74(8) have access to the respective restricted sections of the database. Annex IX carries the information provided upon registration of testing in real world conditions and kept up to date thereafter, and lists five points: a Union wide unique single identification number of the testing, the name and contact details of the provider or prospective provider and of the deployers involved, a short description of the AI system and its intended purpose together with the information needed to identify it, a summary of the main characteristics of the testing plan, and information on the suspension or termination of the testing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 60(4), point (c), provides that the provider or prospective provider has registered the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management that registration takes place in the secure non-public section in accordance with Article 49(4), point (d), and for the systems referred to in point 2 of Annex III in accordance with Article 49(5). Article 60 sits in Chapter VI of the Regulation, on measures in support of innovation. That point (c) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(4), point (c), Article 49(4) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The scope of Article 60 itself was amended. Article 1, point (24), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 60(1) and Article 60(2): testing in real world conditions outside AI regulatory sandboxes is now also open to providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, alongside the systems listed in Annex III. Article 1, point (25), inserts an Article 60a for high-risk AI systems covered by the harmonisation legislation listed in Section B of Annex I: Member States may adopt frameworks for real-world testing for those systems, must notify the Commission of any such framework before implementing it, and those frameworks must among other things ensure compliance with Article 60(2), (3), (4)(d)-(j) and (5)-(9). The registration duty in Article 60(4), point (c), which refers to Article 71(4), falls outside that enumeration.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 1, point (40), of Regulation (EU) 2026/1744 amends the THIRD paragraph of Article 113, which is where points (a) to (d) sit. Point (40)(b) replaces point (c) with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Two things belong with that and are often left out: the exception for Article 6(5) falls outside this deferral, and point (40)(c) adds a point (d) under which Articles 102 to 110 apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 131 explains why the database exists and how far the public availability reaches. It names as the aim facilitating the work of the Commission and the Member States and increasing transparency towards the public, states that this part of the database should be publicly accessible and free of charge and that the information should be easily searchable, understandable and machine-readable, and that the database should be user-friendly, for example by offering search functionalities including through keywords, so that the general public can find the registration information. It adds that any substantial modification of high-risk AI systems should also be registered in the database, that access to the secure non-public section should be strictly limited to the Commission and, as regards their national section, to market surveillance authorities, and that the database should comply with the requirements of Directive (EU) 2019/882.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the entry as a publication and not as a form. Designate per system the natural person who has the legal authority to register, because paragraph 5 provides that their name and contact details go into the database. Write the description of the intended purpose, of the operating logic and, for a public deployer, the summary of the fundamental rights impact assessment so that you can let them be read without explanation. Settle the sequence in your procurement contract: point 3 of Section C asks for the URL of the entry of the system in the database by its provider, so a municipality can only complete its Section C after its supplier has entered Section A. Record within what period the supplier delivers that URL and what happens if it does not. Also record when the entry was last checked against reality and tie that to your change and decommissioning process, so that status, Member States and declaration of conformity move with it. On procurement, check that the system is listed in the database before you put it into use: if it is not listed, a deployer may not use it under Article 26(8) and has to inform the provider or the distributor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-71-eu-database","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-72-post-market-monitoring","legacy_id":"raip:obligation:article-72-post-market-monitoring","type":"obligation","slug":"article-72-post-market-monitoring","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6fe04840ffe25ded5e84488a9486d4fa3f46720b9c66ce47d2244110d9e33098","label":"Article 72: post-market monitoring","summary":"Systematic monitoring of high-risk AI in real use, after market placement.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-72-post-market-monitoring-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record"],"control_ids":["praxikon:eu:ai-act:control:article-72-post-market-monitoring-control"],"template_ids":["praxikon:eu:ai-act:template:article-72-post-market-monitoring-legal-text"],"conditions":[{"id":"article-72-post-market-monitoring-scope","operator":"all","description":"The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals."}],"exceptions":[{"id":"article-72-post-market-monitoring-exception","operator":"not","description":"The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes."}],"statements":[{"kind":"official_fact","text":"Article 72 obliges providers to operate a post-market monitoring system with a plan forming part of the technical documentation, collecting relevant real-world data to evaluate continued compliance with Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Compliance does not stop at go-live: this article turns compliance into a continuous state. For deployers it is also the basis to force suppliers to act on deviations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Design the monitoring together with the Article 12 logging: the same data flows feed both duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-72-post-market-monitoring","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 72 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-73-incident-reporting","legacy_id":"raip:obligation:article-73-incident-reporting","type":"obligation","slug":"article-73-incident-reporting","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df","label":"Article 73: serious incident reporting","summary":"The duty to report serious incidents with high-risk AI, under strict deadlines.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-73-incident-reporting-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-73-incident-reporting-record"],"control_ids":["praxikon:eu:ai-act:control:article-73-incident-reporting-control"],"template_ids":["praxikon:eu:ai-act:template:article-73-incident-reporting-legal-text"],"conditions":[{"id":"article-73-incident-reporting-scope","operator":"all","description":"A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment."}],"exceptions":[{"id":"article-73-incident-reporting-exception","operator":"not","description":"For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication."}],"statements":[{"kind":"official_fact","text":"Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 73 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties","legacy_id":"raip:obligation:article-75-ai-office-high-risk-duties","type":"obligation","slug":"article-75-ai-office-high-risk-duties","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"83a34bbb496960e909b28ca4cdcd4338b787f6e6e306f03413d405f05029c671","label":"Article 75(1a) and (1e): reporting to and assessment by the AI Office","summary":"If you are the provider of a high-risk AI system subject to the competence of the AI Office, you report serious incidents to the Office rather than to your national authority, with the machinery and the deadlines of Article 73(2) to (9) applying in full, and the Office still transmits the information to your national market surveillance authority. Where that system is subject to a third-party conformity assessment under Article 43, the Office is responsible for it, the notified body acts on behalf of the Commission, and you pay the costs directly to that body.","topics":["enforcement","governance","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The two duties themselves are literal in the text; the date is our derivation. Article 75 sits in Chapter IX, which has applied since 2 August 2026, but both paragraphs address only the provider of a high-risk AI system, and that status only arises when Chapter III, Sections 1 to 3, becomes applicable. That date depends on the route, which the repair after the cross-review made sharper: point (c) of the third paragraph of Article 113, as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744, gives 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I. The Annex I route does not drop out here: the four carve-outs in Article 75(1) sit inside point (a), and point (b) independently brings a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine under the competence of the AI Office, including where it is high-risk through Annex I. We carry the earlier of the two in deadline_at, 2 December 2027, matching the sister object article-21-cooperation-with-authorities, which carries the same class of duty holder; for a system entering through point (b) and Annex I the date is 2 August 2028. A defensible alternative reading is that paragraph 1a, as a Chapter IX provision, already operates from 2 August 2026 and therefore applies immediately to any system that is at some point classified as high-risk; on that reading you set up the reporting route to the AI Office now. That is the safer choice and it costs little. It is further uncertain exactly when paragraph 1e bites: Article 43 sits in Chapter III, Section 5, which is not among the deferred Sections 1 to 3, but a third-party conformity assessment only arises once a system is classified as high-risk. The cost of this status is that a preliminary reading is skipped by lib/answer/derive-obligations.ts, so this reporting route does not surface in the per-situation derivation; the object stays reachable through its own page, the deadline index and the API.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:route-high-risk-duties-to-ai-office"],"evidence_ids":["praxikon:eu:ai-act:evidence:ai-office-incident-and-assessment-record"],"control_ids":["praxikon:eu:ai-act:control:ai-office-proceeding-response"],"template_ids":["praxikon:eu:ai-act:template:article-75-legal-text"],"conditions":[{"id":"article-75-high-risk-duties-scope","operator":"all","description":"Applies to providers of AI systems that fall under the competence of the AI Office pursuant to Article 75(1) and that are classified as high-risk. The replaced paragraph 1 carries two independent routes, and the four carve-outs at (i) to (iv) sit inside point (a) alone. Along point (a) Annex I systems fall outside the competence, as do point 2 of Annex III and point 8 as regards the administration of justice; point 8(b), on influencing elections and referenda, is not carved out. Point (b) is a route of its own: a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine falls under the competence of the AI Office even where one of the carve-outs in point (a) applies. Anyone testing point (a) alone places such a system outside this obligation wrongly. Those duties start to apply when Chapter III, Sections 1 to 3, becomes applicable, and that date depends on the route: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I, which point (b) can bring into view. The deadline_at field carries the earlier of the two."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Paragraph 1a provides that, by way of derogation from Article 73, providers of high-risk AI systems subject to the competence of the AI Office pursuant to paragraph 1 of that Article shall report any serious incidents to the AI Office. Article 73(2) to (9) shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in the territory of which the provider or its legal representative is situated. Paragraph 1e provides that the AI Office shall be responsible for conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to a third-party conformity assessment pursuant to Article 43, before such systems are placed on the market or put into service. The Commission shall entrust the performance of those tests or assessments to notified bodies designated in accordance with this Regulation, in which case the notified body acts on behalf of the Commission, and the Commission may withdraw the delegation with immediate effect where a notified body does not perform those tasks adequately. The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for a third-party conformity assessment to the Commission, and that provider shall pay the costs directly to the notified body.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is not a clean change of counter. Paragraph 1a moves the address of the report and nothing more: Article 73(2) to (9) continues to apply mutatis mutandis, so the deadlines, the immediate initial report, the investigation and the duty to cooperate stay exactly as they are, and the AI Office transmits the relevant information to the market surveillance authority of your Member State in any event. Anyone who concludes from this that the Article 73 clock has stopped will miss the duty on the day things go wrong. Paragraph 1e is the heavier of the two and is most often overlooked, because it is not a reporting duty but a change of route in your market access: where your high-risk system falls under the competence of the Office and under a third-party conformity assessment, that assessment now runs through the Commission, a notified body carries it out on behalf of the Commission, and you carry the bill, paid directly to that body. Two things to do now: budget the cost in your planning rather than at the moment of application, and take into account that the Commission may withdraw a delegation with immediate effect, so your assessment can change hands while it is running.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per high-risk system whether it falls under the competence of the AI Office, and adjust your incident procedure accordingly: the same form, the same Article 73 deadlines, a different address. State explicitly in that procedure that the Office forwards the report to your national market surveillance authority, so that nobody assumes a second report is needed or that the national authority drops out of the picture. For systems that require a third-party conformity assessment, check whether that assessment will run through the Commission, budget the fees you pay directly to the notified body, and plan generous lead time, because an assessment before the system is placed on the market is a blocking step and not an administrative afterthought.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-75-ai-office-high-risk-duties","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance","legacy_id":"raip:obligation:article-75-market-surveillance-assistance","type":"obligation","slug":"article-75-market-surveillance-assistance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9ae93e711b67b4eb9e0212da4542e3e5d0eb4495a90fe1b956b58472f4461925","label":"Article 75: market surveillance, mutual assistance and the powers of the AI Office","summary":"For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.","topics":["enforcement","governance","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Four things are unsettled here. First, what this provision asks of you: it addresses the AI Office and the market surveillance authorities and imposes no literal duty on the organisation in this object. We read a practical consequence into it, namely that you must know in advance which authority is competent and must be able to answer a demand or an inspection within the period set; that is our reading and not the text. The literal duties in Article 75 sit in the separate object article-75-ai-office-high-risk-duties. Second, the delineation in paragraph 1: whether the model and the system were developed by the same provider or within the same undertaking is a question of fact on which no guidance exists, and the four carve-outs put the case back with a national authority per system. Third, the language versions of the amending regulation diverge on the limitation period in Article 75c(8): the Dutch edition says three years, the English edition five years. We render per language what that edition says and pick no winner; until a corrigendum, plan on the longer period. Fourth, there is still no consolidated text of Article 75, so the amended heading, the replaced paragraph 1 and the inserted articles can only be read in the amending text. The cost of this status is real: a preliminary reading is skipped by lib/answer/derive-obligations.ts, so this object does not appear in the per-situation derivation. A defensible alternative reading is that this provision is purely a division of competence for you and that your preparation is governed entirely by Article 21, Article 26 and Article 73.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-competent-supervisor"],"evidence_ids":["praxikon:eu:ai-act:evidence:supervisor-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:ai-office-proceeding-response"],"template_ids":["praxikon:eu:ai-act:template:article-75-legal-text"],"conditions":[{"id":"article-75-scope","operator":"any","description":"Applies to AI systems based on a general-purpose AI model where the model and the system are developed by the same provider or by providers forming part of the same undertaking, and to AI systems that constitute or are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The exclusive competence applies to the providers of those systems, and to deployers only where they are also the provider or form part of the same undertaking as the provider."},{"id":"article-75-timing","operator":"all","description":"The allocation of competence itself operates from 2 August 2026, because Article 75 sits in Chapter IX. It covers the obligations that apply at that moment, such as the prohibition in Article 5, the transparency duties of Article 50 and the obligations for general-purpose AI models. The two literal duties the amending regulation places on the provider, the reporting route of paragraph 1a and the fees of paragraph 1e, attach to high-risk status and therefore follow 2 December 2027; they sit in the separate object article-75-ai-office-high-risk-duties."}],"exceptions":[{"id":"article-75-exception-carve-outs","operator":"not","description":"Paragraph 1, point (a) carves four groups out of the exclusive competence of the AI Office: AI systems related to products covered by the Union harmonisation legislation listed in Annex I, systems referred to in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and systems referred to in point 8 of Annex III as regards the administration of justice. Who is competent instead differs per group and is not always \"the market surveillance authority\": for financial institutions Article 74(6) points to the national authority responsible for their financial supervision, and for law enforcement, border management and the administration of justice Article 74(8) has the Member State designate either the data protection supervisory authority or another authority under the same conditions. Which body that is per Member State does not follow from the Regulation."}],"statements":[{"kind":"official_fact","text":"Paragraph 2 provides that where the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly. Paragraph 3 provides that where a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 75(2)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces the heading of Article 75 with \"Market surveillance and control of AI systems and mutual assistance\" and replaces paragraph 1: the AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to, point (a), AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of (i) AI systems related to products covered by the Union harmonisation legislation listed in Annex I, (ii) AI systems referred to in point 2 of Annex III, (iii) AI systems provided by law enforcement authorities, border management authorities and financial institutions insofar as those systems fall under Article 74(6), and (iv) AI systems referred to in point 8 of Annex III as regards the administration of justice; and, point (b), AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The final subparagraph provides that the exclusive competence applies to the providers of those systems, and to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same regulation inserts paragraphs 1b to 1d and paragraph 2a. Paragraph 1b requires the authorities involved in the application of the Regulation to cooperate actively with the AI Office and to provide it the necessary assistance, including in connection with inspections or other enforcement measures carried out in the territory of a Member State. Paragraph 1c provides that the Office shall be assisted by the relevant market surveillance authority when investigatory or enforcement action involves access to a public authority data or AI system. Paragraph 1d provides that before taking a decision that would prohibit or restrict the system being made available or put into service on a national market, or a decision to withdraw or recall it from such market, the Office shall without undue delay notify the market surveillance authority competent for that market of its intention. Paragraph 2a allows a market surveillance authority with well-founded and sufficient reasons to suspect an infringement to request, through the single point of contact designated under Article 70(2), that the AI Office assess the matter; that request shall be duly reasoned and shall state at least the provider or deployer concerned, the relevant facts and the provisions allegedly infringed, and the requesting authority. The Office informs the point of contact without undue delay and in any event no later than four months after receipt whether it will exercise its powers, or why it will not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1b) to (1d) and (2a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75a gives the AI Office all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020, and authorises it to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance. Paragraph 2 allows the Office, on reasonable grounds, to start an investigation, of which it notifies the operator, and provides that it may exercise its powers on its own initiative or following a complaint received pursuant to Article 85, even before starting an investigation. Paragraph 3 allows information requests by simple request or by decision; with a simple request the Office states that there is no obligation to reply but that a voluntary reply must be correct and not misleading, and in both cases it indicates the fines provided for in Article 99(5), and by decision also the right to review by the Court of Justice; a copy of the request goes to the national market surveillance authority. Paragraph 4 allows remote and on-site inspections in which officials may enter business premises, examine and copy books and data, ask for oral or written explanations and seal premises; where national law requires authorisation by a judicial authority, the Office applies for it and the national judicial authority verifies that the coercive measures envisaged are neither arbitrary nor excessive. Paragraph 6 allows the Office to order operators to provide access to and explanations relating to their AI systems and to impose on an operator an obligation to retain all data and documents deemed necessary to assess compliance. Paragraph 7 allows the appointment of independent external experts and auditors, and paragraph 8 provides that information collected shall be used only for the purpose of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Article 75a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75b allows the Office to make commitments offered by the operator during proceedings under Article 75a(2) binding by decision and to declare that there are no further grounds for action; it may reopen the proceedings where there has been a material change in the facts, where the operator acts contrary to its commitments, or where the decision was based on incomplete, incorrect or misleading information, and it rejects inadequate commitments in a reasoned decision. Article 75c provides in paragraph 1 that the Office adopts a decision establishing non-compliance, in paragraph 2 that it first communicates its preliminary findings, and in paragraph 3 that the decision may order the operator to take the necessary measures within a reasonable period and that the operator shall provide the Office with a description of the measures it has taken. Paragraph 4 provides that such a decision may be accompanied by penalties in accordance with Article 99(3) to (7), which apply mutatis mutandis to the AI Office, and that in particular the following are subject to fines as referred to in Article 99(4): (a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4), (b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 as well as those specified in Article 75a, and (c) failure to comply with a commitment made binding pursuant to Article 75b; the supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 allows periodic penalty payments to compel submission to an investigation, compliance with an information request ordered by decision, submission to an ordered inspection, the provision of correct or complete answers or explanations in the context of an ordered inspection, compliance with corrective actions, compliance with a binding commitment, or compliance with a decision under paragraph 1; those payments shall, where applicable, not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 8 sets a limitation period: the Dutch edition in the Official Journal says three years, the English edition says five years. Article 75d applies Article 18 of Regulation (EU) 2019/1020 mutatis mutandis in paragraph 1, safeguards the rights of defence and access to the file under negotiated disclosure in paragraph 2, and provides in paragraph 4 that the Office publishes its decisions under Articles 75b and 75c stating the names of the parties and the main content, including any penalties imposed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75b, 75c and 75d","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical question behind this provision is simple and rarely asked: who comes knocking. What is new is not that the AI Office appears, because the old paragraph 1 already gave it powers to monitor and supervise systems where the model and the system come from the same provider. What is new is that this competence becomes exclusive rather than shared, that it extends to providers within the same undertaking, that a second category is added in the form of designated very large online platforms and search engines, that four groups are carved out of it, and that Articles 75a to 75d give the Office a toolkit of its own. That toolkit is the point. An information request comes as a simple request or by decision; with a simple request you need not answer, but whoever answers voluntarily must answer correctly and not misleadingly, and with a decision the clock runs. An inspection extends to entering business premises, copying data and sealing cabinets and systems, with a real safeguard in front of it: where national law requires judicial authorisation, the Office applies for it and that judge verifies that the coercive measures are neither arbitrary nor excessive. Commitments are a genuine way out, but they become binding, the decision is published with the names of the parties, and the proceedings reopen if the facts change materially, if you act contrary to them, or if your information turns out to be incomplete or incorrect. Two things that are rarely seen. The trigger need not come from an authority: Article 75a(2) lets the Office exercise its powers following a complaint under Article 85, even before an investigation is running. And cost recovery is not unconditional: the Office may fully reclaim its supervision costs insofar as they relate to instances of non-compliance, so supervision costs you money when you are in the wrong and not merely because supervision happened. The line between the two regimes sits in paragraph 1 and it is not trivial; answer it once per system and record it, rather than working it out at the moment a demand arrives.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, points (31) and (32)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per AI system which authority is competent, record the outcome and the reasoning, and revisit that record whenever the model, the provider or the corporate structure changes. Designate someone who receives an information request, a notice of investigation or an announced inspection, and have that person first establish whether it is a simple request or a decision, because that determines whether there is a duty to reply and which period runs. Make sure technical documentation, logs and assessments can be produced in full and per version on request, and take into account that under Article 75a(6) the Office may order you to retain all data and documents it deems necessary; such an order overrides your own deletion routines. Do not count on harmless incompleteness: incorrect, incomplete or misleading information is a separate ground for a fine under Article 99(5), and a periodic penalty payment can also be imposed where you fail to give correct or complete answers during an ordered inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75a and 75c","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-75-market-surveillance-assistance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: the right to complain that can start a proceeding"},{"relation":"related","href":"/en/ai-act/artikel/99","label":"Article 99: the fine bands to which Article 75c refers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-78-confidentiality","legacy_id":"raip:obligation:article-78-confidentiality","type":"obligation","slug":"article-78-confidentiality","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fe3d73fa9cc874bc4fc12b0f664ff4e60e68de553dfc7bf0c64c38bc1350c8e3","label":"Article 78: confidentiality of what you submit to an authority","summary":"The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:mark-confidential-material-on-submission"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-78-submission-register"],"control_ids":["praxikon:eu:ai-act:control:article-78-disclosure-review"],"template_ids":["praxikon:eu:ai-act:template:article-78-legal-text"],"conditions":[{"id":"article-78-scope","operator":"all","description":"Applies to all information and data obtained by the Commission, the market surveillance authorities, the notified bodies and any other natural or legal person involved in the application of this Regulation in carrying out their tasks and activities. The protection operates in accordance with Union or national law and not on its own."},{"id":"article-78-strict-necessity","operator":"all","description":"Paragraph 2 limits what an authority may request: only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of its powers in accordance with this Regulation and with Regulation (EU) 2019/1020. Two follow-on duties attach to that: adequate and effective cybersecurity measures, and deletion as soon as the data is no longer needed for the purpose for which it was obtained."}],"exceptions":[{"id":"article-78-trade-secrets-directive-carve-out","operator":"not","description":"The protection of intellectual property, confidential business information and trade secrets, including source code, applies except in the cases referred to in Article 5 of Directive (EU) 2016/943. Point (a) of paragraph 1 says so in as many words."},{"id":"article-78-information-exchange-unaffected","operator":"not","description":"Paragraph 4 provides that paragraphs 1, 2 and 3 do not affect the rights or obligations of the Commission, the Member States and their relevant authorities, or those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor the obligations of the parties concerned to provide information under criminal law of the Member States. Confidentiality under this article is therefore not a duty of silence between authorities."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a) the intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943; (b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits; (c) public and national security interests; (d) the conduct of criminal or administrative proceedings; (e) information classified pursuant to Union or national law. Paragraph 2 provides that the authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020, that they shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and that they shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides that, without prejudice to paragraphs 1 and 2, information exchanged on a confidential basis between the national competent authorities or between national competent authorities and the Commission shall not be disclosed without prior consultation of the originating national competent authority and the deployer when high-risk AI systems referred to in point 1, 6 or 7 of Annex III are used by law enforcement, border control, immigration or asylum authorities and when such disclosure would jeopardise public and national security interests. This exchange of information shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities. The second subparagraph of paragraph 3 provides that when the law enforcement, immigration or asylum authorities are providers of high-risk AI systems referred to in point 1, 6 or 7 of Annex III, the technical documentation referred to in Annex IV shall remain within the premises of those authorities, that those authorities shall ensure that the market surveillance authorities referred to in Article 74(8) and (9), as applicable, can, upon request, immediately access the documentation or obtain a copy thereof, and that only staff of the market surveillance authority holding the appropriate level of security clearance shall be allowed to access that documentation or any copy thereof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that paragraphs 1, 2 and 3 shall not affect the rights or obligations of the Commission, Member States and their relevant authorities, as well as those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor shall they affect the obligations of the parties concerned to provide information under criminal law of the Member States. Paragraph 5 provides that the Commission and Member States may exchange, where necessary and in accordance with relevant provisions of international and trade agreements, confidential information with regulatory authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of confidentiality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article as the answer to the question your supplier asks and that you ask yourself as soon as you have to hand something over. The protection is real and it names source code expressly, which is unusually explicit in Union law. But it is a duty of the recipient and not a right of refusal for the party submitting. Article 21(1) requires the provider, upon a reasoned request, to give all the information and documentation necessary to demonstrate conformity; Article 78 does not say you may withhold anything, it says what the recipient must do afterwards. Anyone who inverts that and refuses on grounds of confidentiality is legally empty-handed. Two limits on top, because they get missed in practice. The first is Article 5 of Directive (EU) 2016/943: that exception sits verbatim in point (a) and it covers, among other things, exercising the right to freedom of expression and information and revealing misconduct in the general public interest. The second is paragraph 4: between authorities, and when disseminating warnings, confidentiality does not operate as a lock. Your file can therefore reach another Member State without that being a breach. What does work in your favour is paragraph 2. That is a strict necessity test on the request itself, with a retention limit attached: deletion as soon as the data is no longer needed for the purpose for which it was obtained. That is a question you can put to an authority and whose answer you can record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"There is an asymmetry in this article that is rarely noticed. Paragraph 3 gives one set of parties a heavy extra protection: where a high-risk system from point 1, 6 or 7 of Annex III is used by a law enforcement, border control, immigration or asylum authority, information exchanged on a confidential basis may not be disclosed without prior consultation of the originating authority and the deployer, and the technical documentation stays physically within the premises of that authority where it is itself the provider. For a commercial provider in exactly the same Annex III areas that arrangement does not apply. The practical conclusion is not that one is better protected than the other, but that you need to know which side you are on: if you supply such an authority, your documentation travels a different path from your own archive, and you settle that path in the contract rather than after the fact. Note also what this article does not govern. It says nothing about the public availability of the EU database in Article 71, whose public part is meant to be found, and nothing about what a deployer must explain to an affected person under Article 86. Confidentiality towards a regulator and transparency towards a citizen are two separate tracks in this Regulation, and it is a mistake to try to close one with the other.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Mark on every submission which part you regard as confidential business information, trade secret or source code, and why, and keep a register of what you handed to whom on what date. That register is your only starting point if you later want to know whether something left the circle. When asked for additional data, ask about the necessity within the meaning of paragraph 2 and about the purpose for which the data is obtained, and record the answer; that is not a refusal and it is the only way to be able to invoke the retention limit of paragraph 2 later. Put in supplier contracts who receives a request from an authority, who decides what is handed over, and that the other party is informed within an agreed period. If you supply a law enforcement, border control, immigration or asylum authority, record where the technical documentation stays physically and who has access to it. Finally, do not assume that confidentiality releases you from Article 21: the duty to deliver on request stands apart from the recipient’s duty to handle what is delivered with care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-78-confidentiality","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements","legacy_id":"raip:obligation:article-8-compliance-with-requirements","type":"obligation","slug":"article-8-compliance-with-requirements","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f","label":"Article 8: compliance with the requirements for high-risk AI systems","summary":"High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.","topics":["conformity","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What the provision asks of a provider is settled; when it asks it has been derived here. Article 8 sits in Chapter III, Section 2, and names no date of its own. The timeline canon dates the high-risk requirements per route and not per chapter: 2 December 2027 for the systems that are high-risk through Annex III, and 2 August 2028 for those that are high-risk through Annex I. Those two dates do not fit in a field that carries one. `deadline_at` therefore carries 2 December 2027, the earlier of the two and the same date already carried by the objects for Articles 9 to 15. A defensible alternative reading is that a chapeau provision should carry no date of its own and that the dating belongs with the seven requirements it sits above; on that reading this field reads as the earliest of the two routes and not as the date of Article 8. On either reading: for a system inside a regulated product under Annex I, 2 December 2027 is too early and 2 August 2028 is the date that counts. What also remains open is the content of the second measure in paragraph 1. The generally acknowledged state of the art is not a term the Regulation defines and not a synonym for a harmonised standard; anyone who equates it with the standard of Article 40 closes an open measure. On Regulation (EU) 2026/1744. That text was retrieved after all on 6 September 2026 from the Publications Office Cellar service and is archived in data/ai-act/review/sources/reg-eu-2026-1744-nl.txt and -en.txt. The amending regulation carries forty-three amendment points in its Article 1; which of those are reflected in the local legal texts is recorded per point in data/ai-act/review/consolidation-manifest.json. Where a point touches this Article, that is stated below with the statement concerned.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification"],"control_ids":["praxikon:eu:ai-act:control:article-8-integrated-documentation-review"],"template_ids":["praxikon:eu:ai-act:template:article-8-legal-text"],"conditions":[{"id":"article-8-scope","operator":"all","description":"Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision."},{"id":"article-8-two-measures","operator":"all","description":"Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing."},{"id":"article-8-annex-i-product","operator":"any","description":"Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing."}],"exceptions":[{"id":"article-8-integration-is-a-choice","operator":"not","description":"The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that high-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements. Paragraph 2 provides that, where a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 8(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read Article 8 not as an eighth requirement alongside the seven of Articles 9 to 15, but as the provision that says how those seven are to be read. It does two things none of the seven does itself. The first is that it brings in a measure from outside the Regulation. Article 8 is the only article in Section 2 that names the generally acknowledged state of the art, and that means the bar moves. A file that sufficed at the first conformity assessment does not necessarily still suffice some years later, without a single word of the Regulation changing: what was the state of the art then is no longer the state of the art later. The Regulation provides no re-certification rhythm for this beyond the substantial modification of Article 43(4), so anyone who does not set a rhythm of their own has none. Note also what the measure is not. The state of the art is not a synonym for a harmonised standard: Article 40 gives a presumption of conformity to whoever applies such a standard, but Article 8 sets an open measure alongside it that does not stop applying once the standard has been ticked off. The second is that paragraph 1 designates the risk management system of Article 9 as the instrument through which compliance with the other requirements is assessed. Article 9 is therefore not one requirement beside the other six but the file in which you show that you have met the other six at the right level. An organisation that keeps its risk analysis as a separate document beside the technical documentation misses exactly that connection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 is the anti-duplication provision, and in practice it is rarely used. It concerns the product that contains an AI system and falls both under this Regulation and under the Union harmonisation legislation of Section A of Annex I: that is precisely the route of Article 6(1). Two different things are stated. The first is an allocation: the provider is responsible for his product being fully compliant with everything the sectoral legislation requires. It does not say that the AI Act replaces or lightens the sectoral requirements, nor that the sectoral assessment swallows the requirements of Section 2; it says that both stacks apply at once and that the provider of the product covers both. The second is a choice, not a duty: he may integrate the testing and reporting processes, the information and the documentation on the product into the documentation and procedures the sectoral legislation already prescribes. We see two mistakes there. The first is that the AI Act file is built beside the existing technical file, with two versions of the same risk analysis that drift apart after two releases; that is exactly the duplication paragraph 2 seeks to avoid. The second is that the integration happens but cannot be found. Whoever enters the sectoral conformity assessment of Article 43(3) must be able to point, per requirement of Articles 9 to 15, to where in the existing file the answer sits. Integrating is therefore not merging into invisibility; it is a cross-reference per requirement, and that is the form in which the choice of paragraph 2 actually saves work.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record once, per high-risk system, what you regard as the generally acknowledged state of the art, with the sources: which harmonised standards or common specifications you apply, which of them you do not apply and why, and which evaluation method, benchmark or test set you use for this application area. Attach a fixed re-assessment moment to it, for instance annually and at every release, and hang that record on the risk management file of Article 9 rather than on a separate document; paragraph 1 designates that file as the instrument through which compliance is assessed. Note against which intended purpose each requirement of Articles 9 to 15 has been met, so that a change of intended purpose visibly touches the whole series. If your system sits in a product also covered by Section A of Annex I, make the choice of paragraph 2 explicit before you start and record who made it: one combined file or two files. If you combine, build a cross-reference table that points, per requirement of Section 2, to where in the existing technical file the answer sits, and let that table travel through the sectoral assessment. If you keep two files, record who keeps them in step and on which change both are updated.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-85-right-to-complain","legacy_id":"raip:obligation:article-85-right-to-complain","type":"obligation","slug":"article-85-right-to-complain","version":"2.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c6e765304e4a6ec68888e1611d72b0dae35de32e420bd1f947eff02c902433f5","label":"Article 85: right to lodge a complaint with the market surveillance authority","summary":"Anyone with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority. For an organisation that means your own staff, customers and candidates have a route to the regulator that does not run through you.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The right itself is settled; what it asks of you is not. Article 85 addresses the market surveillance authority and imposes no literal duty on the organisation complained about: there is no deadline, no duty to inform and no requirement to set up an internal complaints channel. We nonetheless read a practical consequence into it, namely that you must be able to rebut a complaint with recorded evidence at the moment the authority asks, and that is not the same as a duty following from the text. A defensible alternative reading is that this article is purely procedural for you and that your preparation is governed entirely by Article 26 and Article 72. It is also unclear how this right to complain relates to the right to complain under the GDPR where the same conduct engages both.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-for-a-complaint"],"evidence_ids":["praxikon:eu:ai-act:evidence:explanation-request-record"],"control_ids":["praxikon:eu:ai-act:control:explanation-request-routing"],"template_ids":["praxikon:eu:ai-act:template:article-85-legal-text"],"conditions":[{"id":"article-85-scope","operator":"all","description":"Applies as soon as anyone has grounds to consider that the Regulation has been infringed. There is no standing threshold: the right belongs to any person, and the complaint goes to the market surveillance authority of the Member State concerned."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority. In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical meaning of this article lies not in what it instructs you to do but in whom it gives a route. An employee who thinks the scheduling or appraisal system is wrong, a rejected candidate, a customer who feels mishandled: they do not have to convince you first and do not have to show standing. The complaint arrives at the authority, and the first question you then face is about record keeping: which system, which version, which assessment was carried out and when. That is the same record keeping Articles 26 and 72 already require of you, and that is exactly the point. Whoever has that file answers a complaint with documents; whoever does not answers it with a reconstruction after the fact, and a regulator reads that differently. Note too that this right does not depend on harm or on a decision, whereas the right to an explanation in Article 86 does.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assume a complaint starts at the authority and not with you. Make sure that per AI system you can show which assessment was carried out, by whom, on what date and against which system version, and keep that as a living file rather than a one-off document. Also agree internally who receives a question from an authority and within what period.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-85-right-to-complain","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 85 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-86-right-to-explanation","legacy_id":"raip:obligation:article-86-right-to-explanation","type":"obligation","slug":"article-86-right-to-explanation","version":"2.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"62515aef8dd5cfe3e72e71bd0d1f12da34f9cbe0d884940264d26bce0c911b49","label":"Article 86: right to an explanation of a decision","summary":"A person affected by a decision that a deployer takes on the basis of the output of a high-risk AI system listed in Annex III may request an explanation of the role of that system in the decision-making procedure and of the main elements of the decision taken.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"One thing is unsettled here: how deep the explanation has to go. The Regulation asks for clear and meaningful explanations of the role of the system and the main elements of the decision taken, but there is no case law and no guidance saying whether a description of the factors used is enough or whether it concerns the weighting in the individual case. We read it as the latter, because the text speaks of the decision taken rather than of the system in general. The date question is no longer open: decision D1 of 6 September 2026 chooses the text reading, so Article 86 applies from 2 August 2026 to systems already in use at that point. The practical reading, that the right only acquires an object once the Annex III regime operates on 2 December 2027, is not written away but sits as an annotation in high_risk_regime_from.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:handle-explanation-requests"],"evidence_ids":["praxikon:eu:ai-act:evidence:explanation-request-record"],"control_ids":["praxikon:eu:ai-act:control:explanation-request-routing"],"template_ids":["praxikon:eu:ai-act:template:article-86-legal-text"],"conditions":[{"id":"article-86-scope","operator":"all","description":"Applies where a deployer takes a decision about a natural person on the basis of the output of a high-risk AI system listed in Annex III, with the exception of point 2 of that Annex, and that decision produces legal effects or similarly significantly affects that person in a way they consider to have an adverse impact on their health, safety or fundamental rights."}],"exceptions":[{"id":"article-86-exception-union-or-national-law","operator":"not","description":"Paragraph 2 excludes the right for AI systems where exceptions from, or restrictions to, that obligation follow from Union or national law in compliance with Union law. Paragraph 3 further limits the right to cases where it is not otherwise provided for under Union law, which makes the boundary with Article 22 GDPR a case-by-case question."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 gives any affected person subject to a decision taken by the deployer on the basis of the output of a high-risk AI system listed in Annex III, with the exception of point 2 of that Annex, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights, the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and of the main elements of the decision taken. Paragraph 2 provides that paragraph 1 does not apply to the use of AI systems for which exceptions from, or restrictions to, that obligation follow from Union or national law in compliance with Union law. Paragraph 3 provides that this Article applies only to the extent that the right referred to in paragraph 1 is not otherwise provided for under Union law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This right reaches you through a different channel than the rest of the Regulation. A regulator writes to you; a candidate or a citizen calls or emails, usually at your existing complaints or objections desk. That desk does not know today that an AI system was in the process, let alone what role it played, and that is where it goes wrong. Two things therefore matter more than the legal depth of the explanation itself: that your front line recognises such a request, and that it can be traced per decision which system in which version contributed to it. Without the second you can explain how your system works in general but not what happened in this case, and the latter is what is being asked. Note also the relationship with Article 22 GDPR: where that article already grants a right, Article 86 steps back, but the scope differs enough that you cannot settle the question in the abstract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record, per Annex III system that contributes to decisions about people, which decision was supported by which system version, and make sure your complaints or objections desk recognises a request for an explanation and routes it to someone who can answer it. Also determine per process whether Article 22 GDPR already grants a right, because Article 86 then steps back.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-86-right-to-explanation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-87-reporting-infringements","legacy_id":"raip:obligation:article-87-reporting-infringements","type":"obligation","slug":"article-87-reporting-infringements","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6","label":"Article 87: reporting of infringements and protection of reporting persons","summary":"The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.","topics":["fundamental-rights","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"requires_legal_judgment","interpretation_status":"preliminary","interpretation_note":"The reference is settled; what it asks of you is not. Article 87 consists of one sentence and makes Directive (EU) 2019/1937 applicable to reporting and to the protection of reporting persons. It imposes no channel requirement of its own, sets no deadline and names no threshold: those sit in Articles 8, 9 and 21 of that Directive and in national transposition law, a layer this dataset does not carry as a source. That is why no duty holder is assigned here and the status is requires_legal_judgment. The sharpest open point is the fit with national law: the material scope of the Directive is tied through Article 2(1)(a) to the Union acts in its Annex, and Regulation (EU) 2024/1689 is not in that Annex. One reading is that Article 87 operates directly and that national law tying its scope to that Annex simply lags behind; the other is that the protection only becomes practically available through the national channel, so that the extension requires national transposition. We have not settled that. What we do read into it is a practical consequence: an organisation that must already have a reporting channel must be able to receive a report about an AI system through it. Settled and not unclear is that the personal scope of the Directive is work-related; Article 4 is explicit about that. What is open is only what remains outside that context, and whether that amounts to the complaint route of Article 85 without the protection of Article 87.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:open-a-protected-reporting-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:infringement-report-record"],"control_ids":["praxikon:eu:ai-act:control:reporting-person-protection"],"template_ids":["praxikon:eu:ai-act:template:article-87-legal-text"],"conditions":[{"id":"article-87-scope","operator":"all","description":"The trigger is a report of an infringement of this Regulation, whatever the risk class of the system: a report about an AI system outside the high-risk category is covered just as much. The protection itself is not unconditional. It comes from Directive (EU) 2019/1937, which in Article 4 requires the person reporting to have obtained the information in a work-related context, and in Article 6(1)(a) requires reasonable grounds to believe that what was reported was true and fell within the scope of that Directive."}],"exceptions":[{"id":"article-87-no-internal-channel-below-threshold","operator":"any","description":"Article 87 creates no channel requirement. That requirement comes from Article 8 of Directive (EU) 2019/1937. Paragraph 1 places it on legal entities in the private and the public sector; paragraph 3 limits paragraph 1 in the private sector to entities with 50 or more workers. That threshold is not general, however. Paragraph 4 provides that the threshold in paragraph 3 shall not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, following a risk assessment, to require entities with fewer than 50 workers as well. Paragraph 9 applies paragraph 1 to all legal entities in the public sector, with the option for a Member State to exempt municipalities under 10 000 inhabitants and other small public entities. Below fifty workers there is therefore not simply no channel requirement: it depends on the sector you fall in and on what your Member State has decided. The right to report and the protection of the person reporting exist in any event, through the external route of Article 10 of that Directive."},{"id":"article-87-national-scope-not-settled","operator":"any","description":"The material scope of Directive (EU) 2019/1937 runs through Article 2(1)(a), which refers to the Union acts listed in the Annex to that Directive. Regulation (EU) 2024/1689 was not added to that Annex: it makes the Directive applicable directly, in Article 87. National transposition law that ties its own scope to that same Annex, such as the Dutch Wet bescherming klokkenluiders, may therefore lag behind the Regulation. Whether a report about an AI system falls under national law as a result is not settled."}],"statements":[{"kind":"official_fact","text":"Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article is short because the work was done elsewhere, and that is exactly why it gets overlooked. Its practical meaning lies in the direction of travel: Articles 85 and 86 concern who knocks on your door from outside, Article 87 concerns who steps out from within. That is almost always the first person to notice something. The developer who knows the logging has not run for months, the recruiter who sees the selection model filtering out candidates on something that should never have been in it: they hold the facts a regulator only obtains after an investigation. Three things follow. If you must already have a reporting channel, that channel must be able to receive such a report and recognise it as touching the AI Regulation, because a report handled as a general complaint disappears into a different process. Whether you must have that channel is not a matter of a single number. Article 8(3) of Directive (EU) 2019/1937 imposes the channel requirement in the private sector at fifty or more workers, but paragraph 4 sets that threshold aside for entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, after a risk assessment, to require smaller entities as well, and paragraph 9 imposes the requirement on all legal entities in the public sector, with an optional exemption a Member State may make for municipalities with fewer than ten thousand inhabitants or fewer than fifty workers, and for other public entities with fewer than fifty workers. Below fifty workers the question is therefore which sector you are in and what your Member State has decided, not whether you clear the threshold. If you are genuinely outside each of those cases the channel need not exist, and even then the person reporting has somewhere to go: Article 10 of that Directive gives them an external route to the competent authority without having to report internally first, and Article 15 permits public disclosure under conditions. And the protection is not a formality, but it is not enforced through this Regulation: Article 19 of the Directive prohibits retaliation and Article 21 sets out the protective measures, and enforcement runs through national whistleblower law, in the Netherlands through the Huis voor Klokkenluiders and the civil courts. Article 99 of this Regulation does not list Article 87 among the fineable infringements; there is therefore no AI Act fine for disadvantaging a person who reported. Note too that the report here does not depend on a decision or on harm, whereas the right to an explanation in Article 86 does.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First determine whether Directive (EU) 2019/1937 and national transposition law apply to you at all: below fifty workers there is in principle no channel requirement, in which case this object is not a set-up question for you. If you are covered, check whether your existing reporting channel recognises a report about an AI system and whether whoever receives it knows the AI Regulation may be engaged. Record per report what was reported, about which system, what was done with it and when feedback was given, and measure that against the deadlines in Article 9(1) of that Directive: acknowledgement of receipt within seven days under point (b), feedback within three months under point (f). Keep the identity of the person reporting out of what goes to line managers (Article 16), retain no longer than necessary and proportionate (Article 18(1)), and record an oral report only with consent (Article 18(2) to (4)). Also decide whether you will handle anonymous reports: Article 6(2) leaves that choice to the Member State, so check what your national law says. Finally, put to your lawyer the question whether your national whistleblower act already covers AI Act infringements, because such an act usually ties its scope to the Annex to the Directive and Regulation (EU) 2024/1689 is not listed there.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: right to lodge a complaint with the market surveillance authority"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-9-risk-management","legacy_id":"raip:obligation:article-9-risk-management","type":"obligation","slug":"article-9-risk-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53","label":"Article 9: risk management system","summary":"A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-9-risk-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-9-risk-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-9-risk-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-9-risk-management-legal-text"],"conditions":[{"id":"article-9-risk-management-scope","operator":"all","description":"The system is high-risk under Article 6 and the provider places it on the market or puts it into service."}],"exceptions":[{"id":"article-9-risk-management-exception","operator":"not","description":"Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope."}],"statements":[{"kind":"official_fact","text":"Article 9 requires a risk management system as a continuous, iterative process across the entire lifecycle, with identification, analysis, evaluation and mitigation of risks to health, safety and fundamental rights, and testing to determine the most appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is not a one-off risk analysis but a living process: most organisations have an assessment, but no cycle that reruns on every change. The cycle is what a supervisor will request.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start the risk management file now for systems that will become high-risk towards 2 December 2027: today’s design and procurement choices determine tomorrow’s residual risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-9-risk-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 9 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct","legacy_id":"raip:obligation:article-95-voluntary-codes-of-conduct","type":"obligation","slug":"article-95-voluntary-codes-of-conduct","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b71546d72d3dbc5918daae97128ae05900c52ce93ba71de9866e90de4176e14","label":"Article 95: codes of conduct for voluntary application of specific requirements","summary":"The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-95-voluntary-commitment-register"],"control_ids":["praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review"],"template_ids":["praxikon:eu:ai-act:template:article-95-legal-text"],"conditions":[{"id":"article-95-scope","operator":"all","description":"Paragraph 1 expressly concerns AI systems other than high-risk AI systems, and the voluntary application to them of some or all of the requirements set out in Chapter III, Section 2. Paragraph 2 is wider and concerns the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives. Article 95 sits in Chapter X, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."},{"id":"article-95-who-may-draw-up","operator":"any","description":"Paragraph 3 sets out who may draw up a code of conduct: individual providers or deployers of AI systems, organisations representing them, or both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. A code may cover one or more AI systems, taking into account the similarity of the intended purpose of the relevant systems."}],"exceptions":[{"id":"article-95-no-substitute-for-a-requirement","operator":"not","description":"Article 95 contains no provision that sets aside, suspends or replaces an obligation under this Regulation. The word voluntary refers to the application of requirements that precisely do not apply to the system concerned, and not to the requirements that do apply. A code of conduct on AI literacy leaves Article 4 untouched, and a code of conduct on transparency leaves Article 50 untouched."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: the AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements. Paragraph 2 provides: the AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to: (a) applicable elements provided for in Union ethical guidelines for trustworthy AI; (b) assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI; (c) promoting AI literacy, in particular that of persons dealing with the development, operation and use of AI; (d) facilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders participation in that process; (e) assessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides: codes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems. Paragraph 4, as replaced by Article 1, point (35), of Regulation (EU) 2026/1744, provides: the AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and small mid-cap enterprises, when encouraging and facilitating the drawing up of codes of conduct.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article first for what it is not. It imposes no duty on your organisation: paragraphs 1, 2 and 4 address the AI Office and the Member States, and paragraph 3 only says who may draw a code up. And paragraph 1 is expressly about AI systems other than high-risk AI systems. That is the core of the provision and at the same time the source of the biggest misunderstanding in practice. The common thought is that a code of conduct can replace a mandatory requirement, or that signing one produces a form of compliance a regulator can hold against you or count in your favour. Neither is in the text. The voluntariness in Article 95 concerns requirements that precisely do not apply to your system: Chapter III, Section 2, contains the requirements for high-risk AI systems, and Article 95 invites you to apply some or all of those requirements to a system that is not high-risk. The reverse, a lighter reading of a requirement that does apply, is not on offer in this article. Two limits go with that. Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy. Article 95(2), point (c), names promoting AI literacy as a possible element of a code of conduct. That is not a duplication: the first is the duty, the second is the superstructure. A code of conduct on AI literacy is therefore a fine addition and never a replacement of Article 4. The same holds for transparency: Article 50 imposes a number of transparency duties, and a code that says something about them leaves Article 50 untouched. Anyone suggesting in a tender document or annual report that a code covers one of those duties is making a claim the text does not support.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Then read the article for what it does offer, because that is underestimated. This is the only place in the Regulation that says what an organisation can do of its own accord, and the enumeration in paragraph 2 is strikingly concrete. It names assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI. That topic appears nowhere else in the Regulation as something you can do, and for many organisations it is the topic a board is already asking about. It further names facilitating an inclusive and diverse design, including through inclusive and diverse development teams and the involvement of stakeholders in that process, and assessing and preventing the negative impact on vulnerable persons or groups, including as regards accessibility for persons with a disability and gender equality. Note the form paragraph 2 prescribes alongside, because it separates a serious code from a statement of intent: clear objectives and key performance indicators to measure the achievement of those objectives. A code without measurable indicators does not meet the form the provision itself describes. In practice this is where you can hook your own AI policy onto the Regulation without promising anything you cannot deliver. The most useful use is the inverse application of paragraph 1: for a system that is not high-risk, deliberately adopt part of Chapter III, Section 2, for example the keeping of logs or the documentation of data quality, and say which part you are not adopting and why. That is defensible and it is preparation as well, because a system sometimes changes classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First make the separation visible in your own documentation: set out in two columns what you must do and what you do voluntarily, and make sure no line from the second column is used as cover for a line from the first. Then test every existing ethical code, AI policy document or supplier promise against that separation, because that is usually where the blending sits. If you are considering a code under Article 95, choose deliberately between the two routes: the paragraph 1 route for a system that is not high-risk, where you name which requirements of Chapter III, Section 2, you adopt and which you do not, or the paragraph 2 route for specific requirements across all your AI systems. In both cases give the code the form paragraph 2 describes: clear objectives and key performance indicators with which you measure the achievement, with a named owner and a moment of measurement. Then pick the elements that genuinely mean something to you rather than all five; environmental sustainability, AI literacy, inclusive and diverse design and the impact on vulnerable persons are separate topics with separate data. If you are an SME or a start-up, ask your national competent authority or the AI Office what support for drawing one up is available, because paragraph 4 requires your interests and needs to be taken into account. Finally, put no wording in quotations, tender responses or annual reports from which a reader could infer that participation in a code of conduct covers an obligation under the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-95-voluntary-codes-of-conduct","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-99-101-penalties","legacy_id":"raip:obligation:article-99-101-penalties","type":"obligation","slug":"article-99-101-penalties","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eebb183c9d9b58597388256d80ac73dc95eca9b9c98dd975ed907b55791e6905","label":"Article 99, 100 and 101: the penalty structure per obligation","summary":"The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.","topics":["enforcement","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"Three things are unsettled here. First, whether an obligation not named in Article 99(3) to (5) carries a ceiling from the Regulation itself. We read Article 16, point (a), which obliges the provider to ensure that its high-risk systems comply with the requirements of Chapter III, Section 2, as meaning that non-compliance with Articles 9 to 15 by a provider is at the same time non-compliance with Article 16 and therefore sits inside the 3 percent ceiling, and Article 26 the same way for the deployer, including the duties that Article 26(5) draws in through Article 72 and Article 73. A defensible alternative reading is that the enumeration in paragraph 4 is meant strictly and covers only the duties written in Article 16 and Article 26 themselves, leaving the level for Articles 9 to 15 entirely to the national rules that paragraph 1 requires Member States to lay down. Second, what undertaking and total worldwide annual turnover in paragraphs 3 to 5 cover: the Regulation does not define this, and the difference between the turnover of the legal person fined and that of the group it belongs to is an order of magnitude in practice. We hold to the group reading because undertaking is construed that way in Union competition law, but that provenance is exactly the weak point: the Regulation nowhere refers to it, and the reading that the fined legal person is meant is equally defensible as long as there is no case law under this Regulation. Third, how far Article 75c(4) displaces the enumeration in paragraph 4: on its terms that provision governs enforcement by the AI Office over the operators of Article 75(1), and whether anything follows from it for the national route is unsettled. We read it narrowly, that is for the Office alone, and that is a reading and not settled law.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-99-101-penalty-exposure-register"],"control_ids":["praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record"],"template_ids":["praxikon:eu:ai-act:template:article-99-101-legal-text"],"conditions":[{"id":"article-99-101-penalties-scope","operator":"all","description":"Relevant as soon as you are an operator within the meaning of the Regulation, that is a provider, product manufacturer, deployer, authorised representative, importer or distributor, and one of the provisions named in Article 99(3), (4) or (5) is engaged. The Article 101 regime is additionally relevant where you are a provider of a general-purpose AI model, because there the Commission fines you itself. If you fall within the competence of the AI Office under Article 75(1), Article 75c is added on top."}],"exceptions":[{"id":"article-99-101-penalties-exception","operator":"not","description":"Paragraph 6 reverses the calculation for SMEs, including start-ups: for them the lower of the percentage and the amount applies, where for other undertakings it is the higher of the two, and it does so for every fine referred to in Article 99. The inserted paragraph 6a does the same for small mid-cap enterprises, but expressly only for paragraphs 4 and 5, so the Article 5 band is not reversed for them. Paragraph 8 leaves it to each Member State to determine to what extent administrative fines may be imposed on public authorities and bodies established in that Member State, so the ceiling for a public organisation does not follow from the Regulation. Paragraph 9 allows the fine to be imposed by the competent national courts or by other bodies rather than by the authority in some Member States."}],"statements":[{"kind":"official_fact","text":"Paragraph 1, as replaced by Regulation (EU) 2026/1744, requires Member States to lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, provides that those penalties shall be effective, proportionate and dissuasive, and requires Member States to take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties. Paragraph 2 requires Member States to notify those rules to the Commission without delay and at the latest by the date of entry into application, and to notify any subsequent amendment without delay. Paragraph 3 sets, for non-compliance with the prohibition of the AI practices referred to in Article 5, administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Paragraph 4 sets, for non-compliance with provisions related to operators or notified bodies other than those laid down in Article 5, fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of that same turnover, whichever is higher, and enumerates: obligations of providers pursuant to Article 16, of authorised representatives pursuant to Article 22, of importers pursuant to Article 23, of distributors pursuant to Article 24, point (da) inserted by Regulation (EU) 2026/1744, obligations of providers and operators pursuant to Article 25(2) and (4), obligations of deployers pursuant to Article 26, requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34, and transparency obligations for providers and deployers pursuant to Article 50. Paragraph 5 sets, for the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request, fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of that same turnover, whichever is higher. Paragraph 6 provides that in the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. The paragraph 6a inserted by Regulation (EU) 2026/1744 provides that in the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower. Paragraph 7 enumerates what is taken into account when deciding whether to impose a fine and when deciding on the amount: the nature, gravity and duration of the infringement and of its consequences, whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement, whether other authorities have already fined that operator for infringements of other Union or national law resulting from the same activity or omission, the size, annual turnover and market share of the operator, any other aggravating or mitigating factor such as financial benefits gained or losses avoided, the degree of cooperation with the national competent authorities, the degree of responsibility of the operator taking into account the technical and organisational measures it implemented, the manner in which the infringement became known to the authorities and whether the operator notified it, the intentional or negligent character of the infringement, and any action taken by the operator to mitigate the harm suffered by the affected persons. Paragraph 8 provides that each Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Paragraph 9 provides that, depending on the legal system of the Member State, the rules may be applied in such a manner that fines are imposed by competent national courts or by other bodies, with equivalent effect. Paragraph 10 subjects the exercise of these powers to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process. Paragraph 11 requires Member States to report annually to the Commission on the administrative fines they issued and on any related litigation or judicial proceedings. Chapter XII, which contains Article 99, has applied since 2 August 2025, with the exception of Article 101; the amendments to Article 99 have applied since 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (38)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (40)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of this Regulation, failed to comply with a request for a document or for information pursuant to Article 91 or supplied incorrect, incomplete or misleading information, failed to comply with a measure requested under Article 93, or failed to make available access to the model with a view to conducting an evaluation pursuant to Article 92. In fixing the amount of the fine or periodic penalty payment, regard shall be had to the nature, gravity and duration of the infringement, taking due account of the principles of proportionality and appropriateness, and the Commission shall also take into account commitments made in accordance with Article 93(3) or made in relevant codes of practice in accordance with Article 56. Paragraph 2 requires the Commission to communicate its preliminary findings to the provider and give it an opportunity to be heard before adopting the decision. Paragraph 3 provides that fines imposed shall be effective, proportionate and dissuasive. Paragraph 4 provides that information on fines imposed shall also be communicated to the Board as appropriate. Paragraph 5 gives the Court of Justice of the European Union unlimited jurisdiction to review decisions of the Commission fixing a fine and provides that it may cancel, reduce or increase the fine. Paragraph 6 requires the Commission to adopt implementing acts containing detailed arrangements and procedural safeguards for proceedings that may lead to a decision under paragraph 1. Article 101 is excluded from the earlier application of Chapter XII and has therefore applied since 2 August 2026. Alongside this regime, Article 100 carries its own scheme for Union institutions, bodies, offices and agencies: the European Data Protection Supervisor may impose administrative fines on them of up to EUR 1 500 000 for non-compliance with the prohibition in Article 5 and up to EUR 750 000 for non-compliance with other requirements or obligations under this Regulation. Regulation (EU) 2026/1744 did not amend Articles 100 and 101.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 100(1)-(3)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75c(4), inserted by Regulation (EU) 2026/1744, provides that a decision of the AI Office may be accompanied by the imposition of penalties in accordance with Article 99(3) to (7), which provisions apply mutatis mutandis to the Office in the execution of its supervision and enforcement tasks referred to in Article 75(1). In particular, the following are subject to administrative fines as referred to in Article 99(4): infringement of any applicable provision of this Regulation, including those not listed in Article 99(4); failure to comply with decisions or measures adopted pursuant to Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 and the powers specified in Article 75a; and failure to comply with a commitment made binding pursuant to Article 75b. The supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 additionally allows the Office to impose periodic penalty payments to compel, among other things, submission to an investigation, compliance with an information request, submission to an inspection or compliance with a binding commitment; those payments shall not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 6 gives the Court of Justice unlimited jurisdiction over decisions of the Office fixing a fine or periodic penalty payment, and paragraph 8 subjects the powers of the Office to a limitation period of five years, with the same period for the power to enforce decisions taken. Note: the two authentic language editions of Regulation (EU) 2026/1744 diverge here. The English edition states five years in both subparagraphs of Article 75c(8); the Dutch edition states three years in both subparagraphs of Article 75 quater(8). This statement renders in each language what the edition in that language says and makes no silent choice. The implementing act under Article 75d(3) is to specify both subparagraphs, including the circumstances in which the limitation periods are interrupted; until it exists, the divergence remains an open question of interpretation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The ceiling follows the provision, not the harm. That is the point routinely missed in boardrooms: a single amount gets budgeted for \"the AI Act fine\", while operators face three bands in Article 99 and there are separate regimes on top for Union institutions and for providers of general-purpose AI models. The highest band, EUR 35 million or 7 percent, belongs to Article 5 alone. Until recently that was a list of practices you either engage in or do not, but since the amendment of Article 5 that is no longer true: for the new prohibitions on sexual imagery, placing on the market is also prohibited where such generation is a reasonably foreseeable and reproducible outcome and the system lacks reasonable and adequate technical safety measures and safeguards. That is a duty to take measures inside the highest band, and it applies from 2 December 2026. The middle band, EUR 15 million or 3 percent, belongs to the enumeration in paragraph 4: the role duties of the provider, the authorised representative, the importer, the distributor and the deployer, since 27 July 2026 also Article 25(2) and (4), plus Article 50. What is not named there is at least as interesting: Article 4 and Article 27 do not appear, and the requirements of Chapter III reach the ceiling at most through Article 16 and Article 26. Note that Article 72 and Article 73 do come within reach for the deployer, because Article 26(5) obliges it to inform in accordance with Article 72 and declares Article 73 applicable mutatis mutandis, and Article 26 is named in paragraph 4. Two further things. Paragraph 5 turns answering an information request badly into its own fine category at 1 percent, independently of the underlying infringement. And paragraph 7 is not a discount scheme: it works both ways, because its opening words concern the decision whether or not to impose a fine and point (e) expressly names aggravating factors such as financial benefits gained. What you can steer are the factors you can evidence: your technical and organisational measures, your notification behaviour, your cooperation, and what you did after an incident to mitigate the harm suffered by affected persons. Two dates that matter in practice: the prohibition in Article 5 has applied since 2 February 2025 but Chapter XII only since 2 August 2025, so for conduct in between there is no administrative fine under Article 99(3). That gap does not return for the new Article 5 prohibitions of 2 December 2026: Chapter XII will by then have applied for well over a year, so the penalty regime exists on the day those prohibitions start to apply. And whoever falls within the competence of the AI Office must drop the idea that the enumeration in paragraph 4 is closed: Article 75c(4) places infringement of any applicable provision in the EUR 15 million or 3 percent band there, expressly including provisions not listed in paragraph 4.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (7)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add a column to your obligations register carrying the ceiling that belongs to each entry, with three values: Article 99(3), Article 99(4), or national law under Article 99(1). Determine per general-purpose AI model that you provide yourself whether the Commission's Article 101 regime is added on top, and determine whether you fall under Article 75(1), because the Article 75c regime with periodic penalty payments then applies as well. Also record, per obligation, which of the factors in Article 99(7) you could actually show, in particular the technical and organisational measures implemented, your notification behaviour, your cooperation with the authority and the steps you take to mitigate harm to affected persons, because that is the part of the amount you can influence yourself. This is our recommendation and not a duty under the Regulation: Article 99 addresses the Member States and imposes no deadline whatsoever on an operator.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-99-101-penalties","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:conformity-ce-registration","legacy_id":"raip:obligation:conformity-ce-registration","type":"obligation","slug":"conformity-ce-registration","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2ba6e413ff6670e5896f31ee36839ff048b04b714b4c13decc1ed8e0d2f9186","label":"Articles 43-49: conformity assessment, CE and registration","summary":"The route from assessment to CE marking and EU database registration before market placement of high-risk AI.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:conformity-ce-registration-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:conformity-ce-registration-record"],"control_ids":["praxikon:eu:ai-act:control:conformity-ce-registration-control"],"template_ids":["praxikon:eu:ai-act:template:conformity-ce-registration-legal-text"],"conditions":[{"id":"conformity-ce-registration-scope","operator":"all","description":"The provider places a high-risk system on the market; public deployers also register their use."}],"exceptions":[{"id":"conformity-ce-registration-exception","operator":"not","description":"For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking."}],"statements":[{"kind":"official_fact","text":"Article 43 governs the conformity assessment, Article 47 the EU declaration of conformity, Article 48 the CE marking and Article 49 the registration in the EU database before market placement or putting into service, including registration of the Article 6(3) assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buyers this is the simplest supplier check there is: ask for the declaration of conformity and the registration number. No declaration means the system may not be there by 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Plan the conformity route backwards from 2 December 2027: standards selection, assessment, declaration and registration together take months, not weeks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/conformity-ce-registration","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 43-49 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:value-chain-representative","legacy_id":"raip:obligation:value-chain-representative","type":"obligation","slug":"value-chain-representative","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38342a3db27dd0959f29e10415d9217331e2056d163b17a95fef284213092d52","label":"Articles 22-25: value chain and authorised representative","summary":"Role shifts in the AI value chain and the mandatory representative for non-EU providers.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:value-chain-representative-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:value-chain-representative-record"],"control_ids":["praxikon:eu:ai-act:control:value-chain-representative-control"],"template_ids":["praxikon:eu:ai-act:template:value-chain-representative-legal-text"],"conditions":[{"id":"value-chain-representative-scope","operator":"all","description":"A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU."}],"exceptions":[{"id":"value-chain-representative-exception","operator":"not","description":"Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties."}],"statements":[{"kind":"official_fact","text":"Article 25 provides that a distributor, importer, deployer or third party becomes the provider when it puts its name on a high-risk system, substantially modifies it or changes its intended purpose so it becomes high-risk; Article 22 obliges third-country providers to appoint a written authorised representative in the Union.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The most dangerous role switch is the unintended one: your own layer on top of a procured model, your own brand on a tool, and you suddenly carry the full provider duties. This belongs as a standing question in every AI project.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the role question in the AI register and in project gates, and contractually define who supplies which information and cooperation on changes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/value-chain-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 22-25 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-en-18286-quality-management-system","legacy_id":"raip:standard:standard-en-18286-quality-management-system","type":"standard","slug":"standard-en-18286-quality-management-system","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ee0b79f8c9aae4f696785a3ea1ca801363acd98f156c62c5a3d8ef85e20ac5b6","label":"EN 18286:2026: quality management system for EU AI Act regulatory purposes","summary":"The first completed European standard under the AI Act standardisation request: the quality management system that Article 17 requires from providers of high-risk AI systems.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-en-18286-quality-management-system-scope","operator":"all","description":"Relevant to providers of high-risk AI systems, who must have a quality management system in place by 2 December 2027 (Annex III standalone) or 2 August 2028 (Annex I embedded in regulated products)."}],"exceptions":[{"id":"standard-en-18286-quality-management-system-exception","operator":"not","description":"According to that same coverage statement the standard does not cover Article 17(2) to (4) or Article 72; those obligations must be substantiated independently."}],"statements":[{"kind":"official_fact","text":"EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the first time the AI Act quality requirements exist as an auditable normative text, which is worth more than its legal status suggests. The common trap runs the other way: people read \"first harmonised standard\" and assume compliance now carries evidentiary weight. As long as the reference is not in the Official Journal, EN 18286 is simply a well-structured document with no legal presumption. You still carry the burden of showing your system meets Article 17. Conversely, anyone building on this structure now will not have to rebuild after citation.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Use the clause structure of EN 18286 as the table of contents for your quality dossier: separate the organisational clauses (governance, leadership, planning, support, management review) from the per-system clauses (lifecycle, operations, post-market monitoring, incident handling). Record which internal document evidences each clause. Note explicitly that Article 17(2) to (4) and Article 72 fall outside the standard and must be substantiated separately.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 17 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-en-iso-iec-42001-ai-management-system","legacy_id":"raip:standard:standard-en-iso-iec-42001-ai-management-system","type":"standard","slug":"standard-en-iso-iec-42001-ai-management-system","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ee10b85a24a9bf7b3568085d9b7505cba98678fa0ec51d64f233cedb479aae9","label":"EN ISO/IEC 42001: artificial intelligence management system","summary":"The certifiable organisation-level AI management system, a European standard since 2026, but not a harmonised standard under the AI Act.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-en-iso-iec-42001-ai-management-system-scope","operator":"all","description":"Usable by both providers and deployers seeking to structure AI governance organisation-wide."}],"exceptions":[{"id":"standard-en-iso-iec-42001-ai-management-system-exception","operator":"not","description":"Certification against ISO/IEC 42001 replaces no AI Act obligation and does not shift the burden of proof."}],"statements":[{"kind":"official_fact","text":"ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 42001:2026, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most expensive misconception in the whole standards layer: an ISO/IEC 42001 certificate is not AI Act conformity. The certificate shows you have a governance structure, not that a specific high-risk system meets the regulation. Documented gaps against Article 17 include the absence of a per-system regulatory compliance strategy, of predetermined change management for continuously learning systems, of the Article 73 serious incident reporting timelines, and of a structured fundamental rights assessment. Vendors saying \"ISO 42001 certified, therefore AI Act ready\" are selling you a certificate, not your dossier.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 42001:2026, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Use ISO/IEC 42001 as the organisational layer (policy, roles, management review, internal audit) and put the per-system layer on top: a dedicated dossier per high-risk system along the clauses of EN 18286. Deliberately close the gaps named above: per-system compliance strategy, predetermined change management, incident reporting process with the Article 73 timelines, and fundamental rights assessment. In procurement, ask not for the certificate but for the statement of applicability and the audit report.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 42001:2026, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 17 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-iso-iec-12792-transparency-taxonomy","legacy_id":"raip:standard:standard-iso-iec-12792-transparency-taxonomy","type":"standard","slug":"standard-iso-iec-12792-transparency-taxonomy","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f05c734a543acf72052d1f7a806928e4df6af5ae0509212b9892215750dfc967","label":"ISO/IEC 12792: transparency taxonomy of AI systems","summary":"The international taxonomy of transparency information elements, usable as a checklist for the Article 13 instructions for use.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"ISO/IEC 12792:2025 (Information technology: Artificial intelligence: Transparency taxonomy of AI systems) was published in November 2025 by ISO/IEC JTC 1/SC 42. It specifies a taxonomy of information elements to help stakeholders identify and address transparency needs, and describes the semantics of those elements and their relevance to different stakeholders' objectives. The text was adopted as a European standard as EN ISO/IEC 12792:2025. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 13 the designated deliverable is prEN 18229-3.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 12792:2025, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The value lies in the completeness check: the taxonomy shows which information elements you can forget, and that is exactly where instructions for use fall short in practice. What it is not: a template that satisfies Article 13. The regulation itself determines what the instructions for use must contain, including the provider's details, characteristics and limitations, accuracy metrics, oversight measures and expected lifetime. Also watch the confusion with Article 50: those transparency obligations have applied since 2 August 2026 and fall on providers of AI systems that interact directly with natural persons or generate synthetic content, and on deployers of emotion recognition, biometric categorisation and deepfakes. They apply regardless of high-risk classification. For systems already placed on the market before 2 August 2026, the machine-readable marking under Article 50(2) has a transition until 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 12792:2025, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Structure your instructions for use as a numbered list following the elements of Article 13(3) one for one, and use the ISO/IEC 12792 taxonomy alongside it as a checklist for missing elements. Keep Article 50 transparency information separate, since it addresses the end user rather than the deployer.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 12792:2025, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 13 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-iso-iec-23894-ai-risk-management-guidance","legacy_id":"raip:standard:standard-iso-iec-23894-ai-risk-management-guidance","type":"standard","slug":"standard-iso-iec-23894-ai-risk-management-guidance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"97f89403e72d95ecd362a023a4bb4ee38d74bde7f30f7997125dfeb6f0e72c63","label":"ISO/IEC 23894: guidance on risk management for AI","summary":"The international guidance for AI-specific risk management, usable as an interim structure while prEN 18228 remains in draft.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"ISO/IEC 23894:2023 (Information technology: Artificial intelligence: Guidance on risk management) was published in February 2023 and is the first international standard dealing specifically with risk management for AI. It is non-prescriptive and built on the ISO 31000 structure. The text was adopted by CEN-CENELEC as EN ISO/IEC 23894:2024. It is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40 of the AI Act. The deliverable intended to do so for Article 9 is prEN 18228.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 23894:2024, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"ISO/IEC 23894 gives you the vocabulary and process flow of AI risk management, and that is usable today. Where it falls short: it is guidance, not a requirements set, and it is written from organisational risk while Article 9 starts from risk to the health, safety and fundamental rights of others. A risk register built entirely along ISO/IEC 23894 therefore does not automatically cover Article 9. Use it as scaffolding, not as evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 23894:2024, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Adopt the ISO/IEC 23894 process flow (context, identification, analysis, evaluation, treatment, monitoring, recording) and add two AI Act-specific fields per risk: who outside your organisation can be affected, and what residual risk you deem acceptable on what justification. That lets you connect the register to the final EN 18228 without rebuilding it.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN ISO/IEC 23894:2024, European adoption via CEN-CENELEC","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 9 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-iso-iec-24029-robustness-neural-networks","legacy_id":"raip:standard:standard-iso-iec-24029-robustness-neural-networks","type":"standard","slug":"standard-iso-iec-24029-robustness-neural-networks","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"90a88e1eab0ea2115fc69dcffb95fd81f4beda2674e8a39e98349b2cddc54e5e","label":"ISO/IEC 24029 series: assessment of the robustness of neural networks","summary":"The international series making neural network robustness testable, usable as methodology under Article 15 while prEN 18229-2 remains in draft.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-iso-iec-24029-robustness-neural-networks-scope","operator":"all","description":"Particularly relevant to high-risk systems based on neural networks."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"ISO/IEC TR 24029-1:2021 (Assessment of the robustness of neural networks, Part 1: Overview) is a technical report mapping the topic and available assessment methods. ISO/IEC 24029-2:2023 (Part 2: Methodology for the use of formal methods) describes the application of formal methods in assessing robustness. The series is aimed at AI developers and users assessing robustness across the lifecycle. Neither part is cited in the Official Journal, so no presumption of conformity under Article 40 arises. For Article 15 the designated deliverable is prEN 18229-2, which as at June 2026 was still in drafting.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC TR 24029-1:2021 and ISO/IEC 24029-2:2023, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Part 1 is a technical report and therefore not a requirements set: it gives an overview, not a benchmark. Part 2 is the sharper text substantively, but formal methods are only feasible for relatively bounded models. For large generative models you hit the limits quickly, leaving empirical testing. The trap is making a robustness claim measured only on the average test set: Article 15 is specifically about behaviour under errors, faults and unexpected input.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC TR 24029-1:2021 and ISO/IEC 24029-2:2023, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Choose deliberately per system between formal verification (for bounded models) and empirical stress testing, and record the choice and its justification. Test explicitly on out-of-distribution input, missing fields and edge cases, and document the performance degradation observed. Add those results to the technical documentation and to the instructions for use where they define the limits of use.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC TR 24029-1:2021 and ISO/IEC 24029-2:2023, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 15 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-iso-iec-5259-data-quality-machine-learning","legacy_id":"raip:standard:standard-iso-iec-5259-data-quality-machine-learning","type":"standard","slug":"standard-iso-iec-5259-data-quality-machine-learning","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9fcb6844fee38f7cddc5546b1fc8835cbf284965148c69abc788b201cb2c685e","label":"ISO/IEC 5259 series: data quality for analytics and machine learning","summary":"The five-part international series on data quality, in practice the most usable structure for the Article 10 data governance dossier.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"The ISO/IEC 5259 series (Artificial intelligence: Data quality for analytics and machine learning) comprises five parts: part 1 (overview, terminology and examples), part 2 (data quality measures), part 3 (data quality management requirements and guidelines) and part 4 (data quality process framework), all published in 2024, plus part 5 (data quality governance framework), published in February 2025. CEN-CENELEC has adopted parts as European standards, including EN ISO/IEC 5259-4:2025 and EN ISO/IEC 5259-3:2025. No part is cited in the Official Journal, so no presumption of conformity under Article 40 arises. The deliverable intended to do so for Article 10 is prEN 18284.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 5259 series, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is currently the most concrete help available for Article 10, because part 2 actually makes data quality measurable rather than merely discussing it. What it is not: coverage of Article 10. The regulation asks for things the series does not address, such as examination for possible bias with a view to fundamental rights and representativeness for the specific intended user population in the EU. A dataset scoring well on every 5259 measure can still structurally under-represent a population group.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 5259 series, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Use part 2 to fix a small number of hard quality measures per dataset and part 4 to describe the process that maintains them. Add two AI Act fields the series does not cover: representativeness for the intended user population, and the outcome of the bias examination with the measures taken. Retain the measurement results per dataset version, not only for the latest version.","citations":[{"source_id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","source_locator":"ISO/IEC 5259 series, ISO/IEC JTC 1/SC 42","source_url":"https://www.iso.org/committee/6794475.html","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18228-ai-risk-management","legacy_id":"raip:standard:standard-pren-18228-ai-risk-management","type":"standard","slug":"standard-pren-18228-ai-risk-management","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"efc0d590e74fcc9850050e3c063c288082c701a96530ffc6c49dcaaea71ea1b4","label":"prEN 18228: AI risk management for high-risk systems","summary":"The draft European standard filling in the Article 9 risk management system, built on a product-safety logic rather than an enterprise-risk logic.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-pren-18228-ai-risk-management-scope","operator":"all","description":"Relevant to providers preparing for the high-risk obligations applying from 2 December 2027 (Annex III) or 2 August 2028 (Annex I)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18228 (AI risk management) is the JTC 21 deliverable under M/613 intended to confer presumption of conformity with Article 9 of the AI Act: the risk management system that providers of high-risk AI systems must establish, implement, document and maintain across the full lifecycle. The public Enquiry ran until 30 July 2026. The standard has not yet been published as an EN and is not cited in the Official Journal. The prEN designation means it is a draft text.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The distinguishing feature is the perspective. prEN 18228 is written from product safety: it concerns risks to the health, safety and fundamental rights of third parties, not risks to your organisation. Anyone filling an Article 9 dossier with an existing ISO 31000 or ERM register makes exactly the mistake this standard exposes: that register looks inward, Article 9 looks outward. And a draft standard is not yet evidence: you can adopt the method, but you cannot prove anything with it towards a supervisory authority today.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build your Article 9 risk register now with an outward view: for each foreseeable use and foreseeable misuse, name the person or group who can be affected, the measure that reduces the risk, and the residual risk that remains. Keep the structure separate from your ERM register so the final EN 18228 can be mapped over it later without rewriting the content.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 9 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18229-1-logging","legacy_id":"raip:standard:standard-pren-18229-1-logging","type":"standard","slug":"standard-pren-18229-1-logging","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"163333159c9f358bd74a4ac8364a7f497d5deb28d366166b00650b93b87f5a13","label":"prEN 18229-1: AI trustworthiness framework part 1, logging","summary":"The draft European standard for the automatic event recording that Article 12 requires of high-risk AI systems.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-pren-18229-1-logging-scope","operator":"all","description":"Providers build in the logging capability (Article 12) and keep the logs under their control (Article 19); deployers retain the logs generated by the system (Article 26(6))."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18229-1 (AI trustworthiness framework, Part 1: Logging) is the JTC 21 deliverable under M/613 for Article 12 of the AI Act: high-risk AI systems must technically allow for the automatic recording of events over their lifetime. As at June 2026 the deliverable was at the Enquiry stage. It has not yet been published as an EN and is not cited in the Official Journal.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-1 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12; Article 19; Article 26(6); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Logging is the obligation that is cheapest to get right now and most expensive to repair later, because a system that does not log cannot start logging retroactively. Mind the split of roles: the provider must build in the logging capability, the deployer must retain the logs. Buying a system without checking whether it logs means buying a hole in your own dossier. This standard is still a draft text and therefore carries no evidentiary weight yet.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-1 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12; Article 19; Article 26(6); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Put the logging requirement in your procurement terms and in the acceptance test: which events are recorded, with what timestamp, how long they are retained, and how you export them to a supervisory authority. Document those answers per system now, so the final EN 18229-1 only needs to be mapped against what you already record.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-1 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12; Article 19; Article 26(6); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 12 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18229-2-accuracy-robustness","legacy_id":"raip:standard:standard-pren-18229-2-accuracy-robustness","type":"standard","slug":"standard-pren-18229-2-accuracy-robustness","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0e893c917fe9435350acafd09346a9557045fb27dfdea30ab46091cf9cdb7e23","label":"prEN 18229-2: AI trustworthiness framework part 2, accuracy and robustness","summary":"The draft European standard meant to make the appropriate level of accuracy and robustness under Article 15 measurable.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18229-2 (AI trustworthiness framework, Part 2: Accuracy and robustness) is the JTC 21 deliverable under M/613 for Article 15 of the AI Act, which requires high-risk AI systems to achieve an appropriate level of accuracy, robustness and cybersecurity and to declare accuracy metrics in the instructions for use. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-2 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 15 leaves open what \"appropriate\" means, and that open norm is precisely what this deliverable would fill in. Until it is finished, you must justify yourself which accuracy level fits your application and why. The common trap is putting a single percentage in the instructions for use without stating on which population and under which conditions it was measured: that is not a metric, it is a marketing figure. A supervisory authority will ask about the measurement setup.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-2 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record a test protocol per high-risk system: which metric, which test population, which subgroups measured separately, and what performance degradation under out-of-distribution conditions is acceptable. Use the ISO/IEC 24029 series for robustness methodology and retain the raw test results, not only the summary.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-2 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 15 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18229-3-transparency-human-oversight","legacy_id":"raip:standard:standard-pren-18229-3-transparency-human-oversight","type":"standard","slug":"standard-pren-18229-3-transparency-human-oversight","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7ec718d0ce2778b5802f6a916ccbf5c3cb159bdee9050681b3b4bf9697ba111c","label":"prEN 18229-3: AI trustworthiness framework part 3, transparency and human oversight","summary":"The draft European standard for the transparency and oversight requirements of Articles 13 and 14 for high-risk AI systems.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-pren-18229-3-transparency-human-oversight-scope","operator":"all","description":"Providers design in the oversight measures under Article 14; under Article 26(2) deployers assign natural persons with the necessary competence, training and authority and give them the mandate they need."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18229-3 (AI trustworthiness framework, Part 3: Transparency and human oversight) is the JTC 21 deliverable under M/613 addressing Articles 13 and 14 of the AI Act: transparency and provision of information to deployers, and the design for effective human oversight of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. This deliverable concerns Article 14 (high-risk) and not the Article 50 transparency obligations, which apply since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-3 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 13 and 14; Article 26(2); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Human oversight is the obligation that most often exists on paper and fails in practice. Article 14 requires the designated person to be able to genuinely understand, override and reverse the output. A staff member with thirty seconds per case and no mandate to deviate is not human oversight, only a signature. The common mistake is waiting for this standard while the bottleneck is not technical but organisational: mandate, time and escalation route.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-3 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 13 and 14; Article 26(2); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Describe per high-risk system who exercises oversight, what information that person sees at the decision moment, how much time is allotted, what mandate exists to deviate, and how a deviation is recorded. Those four answers are the core of your Article 14 evidence and will not change with the final normative text.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18229-3 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 13 and 14; Article 26(2); Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 14 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18284-dataset-quality-governance","legacy_id":"raip:standard:standard-pren-18284-dataset-quality-governance","type":"standard","slug":"standard-pren-18284-dataset-quality-governance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e0b691537e172f662c412c1a0b09f589f84d1aec77e74ec3cde19a5648db4282","label":"prEN 18284: quality and governance of datasets in AI","summary":"The draft European standard operationalising the Article 10 data governance requirements for training, validation and testing data.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-pren-18284-dataset-quality-governance-scope","operator":"all","description":"Applies to providers of high-risk AI systems that are trained on data."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18284 (Artificial intelligence: Quality and governance of datasets in AI) is the JTC 21 deliverable under M/613 for Article 10 of the AI Act, which sets requirements for the training, validation and testing datasets of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18284 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 10 is where most organisations actually fail, because they never recorded the provenance and processing history of their data. prEN 18284 will turn that recording into a normative requirement. The common mistake is waiting for the standard before starting data lineage: that documentation is almost impossible to reconstruct retroactively. What you do not record now cannot be proven two years from now.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18284 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start a dataset passport per high-risk system now: provenance, collection method, processing steps, representativeness for the intended user population, known gaps and the bias examination performed. Use the ISO/IEC 5259 series as an interim structure and keep the fields generic so they can be renamed to the terminology of the final EN 18284.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18284 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:standard:standard-pren-18285-conformity-assessment-framework","legacy_id":"raip:standard:standard-pren-18285-conformity-assessment-framework","type":"standard","slug":"standard-pren-18285-conformity-assessment-framework","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6912ad1f00cd9830b1995fd9ea6e88df0aeb116adb20a4655378cb061d173ff0","label":"prEN 18285: conformity assessment framework for AI systems","summary":"The draft European standard operationalising the conformity assessment procedure of Article 43 and Annex VII.","topics":["standards"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"standard-pren-18285-conformity-assessment-framework-scope","operator":"all","description":"The Article 43 conformity assessment rests on the provider. The authorised representative established in the Union keeps the EU declaration of conformity and the technical documentation available to the supervisory authority and cooperates with it under Article 22."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18285 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43 and Annex VII; Article 22; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the deliverable that determines how heavily the rest weighs. For most Annex III systems the provider may self-assess (internal control), but that does not mean nothing is required: it means you must be able to show the complete dossier yourself. The trap is thinking self-assessment is light. The notified body is absent, the burden of proof is not. While prEN 18285 remains in draft, there is no recognised blueprint for that self-assessment and you must justify the structure yourself.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18285 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43 and Annex VII; Article 22; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per system which assessment route applies (internal control or notified body) and build your dossier as one an external party would have to be able to read, even where you self-assess. Plan backwards from 2 December 2027 for standalone Annex III systems and 2 August 2028 for systems embedded in regulated products.","citations":[{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18285 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43 and Annex VII; Article 22; Article 40","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"guidance","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 43 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:annex-iii-classifier","legacy_id":"raip:template:annex-iii-classifier","type":"template","slug":"annex-iii-classifier","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dae4e0cfcd90846c10fa8ab1777f21308410df28876ab6df9e201a05ea6f9155","label":"Annex III classification route","summary":"Public classifier for the high-risk use cases in Annex III.","topics":["high-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-high-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/annex-iii","label":"Open the eight public classification routes"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text","legacy_id":"raip:template:annex-iii-eight-areas-legal-text","type":"template","slug":"annex-iii-eight-areas-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c5ef654d7cb162b35619676f49abb8eb27afe33e30747965ffcca11cd78f8e1b","label":"Full text of Annex III","summary":"The full text of Annex III, with all eight areas and their lettered subpoints, in the public AI Act Explorer and on EUR-Lex.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:annex-iii-eight-areas"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-10-data-governance-legal-text","legacy_id":"raip:template:article-10-data-governance-legal-text","type":"template","slug":"article-10-data-governance-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c4525b47886b0b8562a281f37b58eb8c859ae33c2f6ab6398220d1bf7b9936d3","label":"Full text of Article 10","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-10-data-governance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/10","label":"Read Article 10 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text","legacy_id":"raip:template:article-11-technical-documentation-legal-text","type":"template","slug":"article-11-technical-documentation-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b4a8665dde718cd9f5128ee43bae41a35bb1e93957f80397aea2c0d6ce9f675","label":"Full text of Article 11","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-11-technical-documentation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/11","label":"Read Article 11 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-111-legal-text","legacy_id":"raip:template:article-111-legal-text","type":"template","slug":"article-111-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38dd22cf8878f0f09dbd8e27001f8de7d6cbe4017cb5495e1203f560fc43c032","label":"Full text of Article 111","summary":"The legal text on EUR-Lex: the base text in Regulation (EU) 2024/1689 and the replacement of paragraph 2 and the addition of paragraph 4 in Regulation (EU) 2026/1744. Reading only the base text means reading the 2024 version.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-111-legacy-public-systems"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-12-logging-legal-text","legacy_id":"raip:template:article-12-logging-legal-text","type":"template","slug":"article-12-logging-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0b388455f428f11dfb5468f87917aefff00ef5a2a79a9e13bafe13ef4285badf","label":"Full text of Article 12","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-12-logging"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/12","label":"Read Article 12 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-13-instructions-legal-text","legacy_id":"raip:template:article-13-instructions-legal-text","type":"template","slug":"article-13-instructions-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"417dfd58e9c213b4628e05547f8ba669a5b1a1055dcc9d8168c4800c87ea4620","label":"Full text of Article 13","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-13-instructions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/13","label":"Read Article 13 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-14-human-oversight-legal-text","legacy_id":"raip:template:article-14-human-oversight-legal-text","type":"template","slug":"article-14-human-oversight-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"503e54076c77a49f21f87deeb88184e6553063cb2cab5f172eb9cbea96c9c4b1","label":"Full text of Article 14","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-14-human-oversight"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/14","label":"Read Article 14 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-15-accuracy-robustness-legal-text","legacy_id":"raip:template:article-15-accuracy-robustness-legal-text","type":"template","slug":"article-15-accuracy-robustness-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"79ee3412f8d237f653302e9cf55ba8b88316d39bb0ad16e64b2e9e990e55f56c","label":"Full text of Article 15","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-15-accuracy-robustness"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/15","label":"Read Article 15 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-16-provider-obligations-legal-text","legacy_id":"raip:template:article-16-provider-obligations-legal-text","type":"template","slug":"article-16-provider-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"838d057e1bea1f6bdaa626ad24caaca47eb7c7c9e7f2b79df5f2c2ed388b0cc1","label":"Full text of Article 16","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-16-provider-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/16","label":"Read Article 16 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-17-quality-management-legal-text","legacy_id":"raip:template:article-17-quality-management-legal-text","type":"template","slug":"article-17-quality-management-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2ae55f99f1425e8cb858449719be7600a688e08cbc12fdb3d587349e6ee5fdde","label":"Full text of Article 17","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-17-quality-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/17","label":"Read Article 17 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-18-legal-text","legacy_id":"raip:template:article-18-legal-text","type":"template","slug":"article-18-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5b19503bf7f4e44688a2cb2d46d0b3fd964c943e51457f098e6fe67621b617b6","label":"Full text of Article 18","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-18-document-retention"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-20-legal-text","legacy_id":"raip:template:article-20-legal-text","type":"template","slug":"article-20-legal-text","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1edca0766aeb841b20cb9b62190036da59294de8a16be4f816ec2d4de55574fe","label":"Full text of Article 20","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-20-corrective-actions"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/20","label":"Read Article 20 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-21-legal-text","legacy_id":"raip:template:article-21-legal-text","type":"template","slug":"article-21-legal-text","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6c650dd1517a7b9b44d210f0a3473d686534005db42bbec15ad667a10f9e163a","label":"Full text of Article 21","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/21","label":"Read Article 21 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-23-importer-obligations-legal-text","legacy_id":"raip:template:article-23-importer-obligations-legal-text","type":"template","slug":"article-23-importer-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a496206177b88595c0276aede65fe7f0033c3c4c9816f5f7a1f2ac1dbdba380b","label":"Full text of Article 23","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-23-importer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/23","label":"Read Article 23 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-24-distributor-obligations-legal-text","legacy_id":"raip:template:article-24-distributor-obligations-legal-text","type":"template","slug":"article-24-distributor-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"db0d18d585624e430c992f65eb6f1af0b9bb5164e61ac183727a4af1c8a34d13","label":"Full text of Article 24","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-24-distributor-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/24","label":"Read Article 24 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-26-deployer-obligations-legal-text","legacy_id":"raip:template:article-26-deployer-obligations-legal-text","type":"template","slug":"article-26-deployer-obligations-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d5675ff568eed50bfad51b263032a2053826fa1ea99c99abe9bb592f92be72c2","label":"Full text of Article 26","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-26-deployer-obligations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/26","label":"Read Article 26 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-28-39-legal-text","legacy_id":"raip:template:article-28-39-legal-text","type":"template","slug":"article-28-39-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2edf393dfa2fe74bf11228eb660a7444be2bfb03743c383af94184e0cb25b7e1","label":"Full text of Articles 28 to 39","summary":"The full legal text of Chapter III, Section 4, in the public AI Act Explorer.","topics":["conformity","governance","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-28-39-notified-bodies"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-4-measures-plan","legacy_id":"raip:template:article-4-measures-plan","type":"template","slug":"article-4-measures-plan","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"857b4bd32f2868a918b0191bcbd624dcb65accca8e079afc2b3bbe0b3841a101","label":"AI literacy measures plan","summary":"Public route for structuring measures by role and context.","topics":["ai-literacy","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4-ai-literacy"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/article-4-evidence-dossier-checklist","label":"Open public evidence checklist"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-40-42-legal-text","legacy_id":"raip:template:article-40-42-legal-text","type":"template","slug":"article-40-42-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c4a1106adef541ad597e53d491a3a36b69ab01d73665e29e5f4d8f69acc225f","label":"Full text of Articles 40, 41 and 42","summary":"The full legal text of the standards and specifications provisions in the public AI Act Explorer.","topics":["conformity","standards","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-44-legal-text","legacy_id":"raip:template:article-44-legal-text","type":"template","slug":"article-44-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8ea67cd2cf17a8ccb86925fc89ecc093671ad3a66c7d439b788b98c8a9e0dd96","label":"Full text of Article 44","summary":"The official text of the Regulation on EUR-Lex, where Article 44 sits in Chapter III, Section 5. The link opens the Regulation as a whole rather than the Article on its own.","topics":["conformity","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-44-notified-body-certificates"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-46-legal-text","legacy_id":"raip:template:article-46-legal-text","type":"template","slug":"article-46-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"801b3ecc173370ecda6103846a61c25523d8306cc59e786f4d60680039c6fa9b","label":"Full text of Article 46","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","enforcement","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-49-legal-text","legacy_id":"raip:template:article-49-legal-text","type":"template","slug":"article-49-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"99afd160adb9c52a65b3e2ca6ad65004286fc9e6dd22bf6fe2e6d76ffe8a7097","label":"Full text of Article 49","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","high-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-49-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-4a-legal-text","legacy_id":"raip:template:article-4a-legal-text","type":"template","slug":"article-4a-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ed6adebe93cb3f7dc0c2e75c30d886e16819253dd953317fafbd656e6480fac8","label":"Full text of Article 4a","summary":"The full text of Article 4a as inserted and published in the Official Journal of 24 July 2026.","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-5-legal-text","legacy_id":"raip:template:article-5-legal-text","type":"template","slug":"article-5-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"035492482a5c481e790573a6949745f1da8b49792bfb28bb377c4bba7c92d48f","label":"Full text of Article 5","summary":"The full legal text of the prohibited practices with all categories and exceptions, in the public AI Act Explorer.","topics":["prohibited-practices","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-5-prohibited-practices"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/5","label":"Read Article 5 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-50-checklist","legacy_id":"raip:template:article-50-checklist","type":"template","slug":"article-50-checklist","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"165eaabca3372655df0955fa11ee94e3125d67b5adfa1a7f26157df5f031b26f","label":"Article 50 checklist","summary":"Public decision route for the distinct transparency obligations.","topics":["template","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/ai-transparency-notice","label":"Open public transparency template"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-52-legal-text","legacy_id":"raip:template:article-52-legal-text","type":"template","slug":"article-52-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0d6085f7e5a1c6077dfe6516ca71e7c72924b01b8c61674bdc18d18b2d740bcf","label":"Full text of Article 52","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-54-legal-text","legacy_id":"raip:template:article-54-legal-text","type":"template","slug":"article-54-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"20ea620fe652fa973a8cdfb0a2f0be479c107896b90803a79ebe529a3eb5d896","label":"Full text of Article 54","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text","legacy_id":"raip:template:article-55-gpai-systemic-risk-legal-text","type":"template","slug":"article-55-gpai-systemic-risk-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a78c5debbb73f96dc47f83d6dfb91f50e9ed69d412126deaa23afb74bbe8e31e","label":"Full text of Article 55","summary":"The full legal text in the public AI Act Explorer.","topics":["gpai-systemic-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/55","label":"Read Article 55 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-56-legal-text","legacy_id":"raip:template:article-56-legal-text","type":"template","slug":"article-56-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a88041020566d088c724fed811dea3f8f4b46e002abf1ea84943798a7d3c12b1","label":"Full text of Article 56","summary":"The full legal text in the public AI Act Explorer.","topics":["governance","gpai","gpai-systemic-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-57-regulatory-sandboxes-legal-text","legacy_id":"raip:template:article-57-regulatory-sandboxes-legal-text","type":"template","slug":"article-57-regulatory-sandboxes-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a450df3b7e1b9407df652959c71ba0c2406714c0fe9b00512d3ffa3953d78b14","label":"Full text of Article 57","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/57","label":"Read Article 57 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-6-1-legal-text","legacy_id":"raip:template:article-6-1-legal-text","type":"template","slug":"article-6-1-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"94d919e36dac16c0d666fc5ab294ed86dd101260cb47a68805a41c8ed62d41b9","label":"Full text of Article 6 and Annex I","summary":"The full legal text in the public AI Act Explorer, alongside the amending Regulation.","topics":["high-risk","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-6-1bis-1quater-legal-text","legacy_id":"raip:template:article-6-1bis-1quater-legal-text","type":"template","slug":"article-6-1bis-1quater-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f96e5ef70dd116756fb84b8177f61c2216721b42a51448d8f846fcc907ad885c","label":"Full text of the inserted paragraphs","summary":"The full text of the amendment to Article 6 as published in the Official Journal of 24 July 2026, inserted by Article 1, point (8), of Regulation (EU) 2026/1744.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"in_force","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-60-real-world-testing-legal-text","legacy_id":"raip:template:article-60-real-world-testing-legal-text","type":"template","slug":"article-60-real-world-testing-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3cb72c16ed3875f5a3a60a7863584dc3d266458e6321dfd3147f848e8117e94d","label":"Full text of Article 60","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-60-real-world-testing"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/60","label":"Read Article 60 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-61-legal-text","legacy_id":"raip:template:article-61-legal-text","type":"template","slug":"article-61-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1f2ccc47832ea74dfde342e51d6cb186ba10db8aaaeebf76fa35da40d96a947f","label":"Full text of Article 61","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-61-informed-consent"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-62-legal-text","legacy_id":"raip:template:article-62-legal-text","type":"template","slug":"article-62-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4534941e9499960418b412b90441aaf840aa4e71b3514a79e6ec262c84a35065","label":"Full text of Article 62","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-62-sme-support-measures"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-63-legal-text","legacy_id":"raip:template:article-63-legal-text","type":"template","slug":"article-63-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ec0523774f08bbb05cba744ff8e41cf9b59da0a32e25e17babed6da1c984f22d","label":"Full text of Article 63","summary":"The full legal text in the public AI Act Explorer.","topics":["innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-63-sme-derogations"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-71-legal-text","legacy_id":"raip:template:article-71-legal-text","type":"template","slug":"article-71-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8a1119c835b0c193ee9babdb1c971fe94175cc6d036c84cce14d5b06733f1e29","label":"Full text of Article 71","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-71-eu-database"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-72-post-market-monitoring-legal-text","legacy_id":"raip:template:article-72-post-market-monitoring-legal-text","type":"template","slug":"article-72-post-market-monitoring-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1efe1f458525f1f6e47913d9ae599436bbc52f3279073f80478f74c1fe6e7880","label":"Full text of Article 72","summary":"The full legal text in the public AI Act Explorer.","topics":["post-market","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-72-post-market-monitoring"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/72","label":"Read Article 72 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-73-incident-reporting-legal-text","legacy_id":"raip:template:article-73-incident-reporting-legal-text","type":"template","slug":"article-73-incident-reporting-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f22615858521d40a4f31851f27377f587e2f8cbdccb351ee2e6756d4d23706be","label":"Full text of Article 73","summary":"The full legal text in the public AI Act Explorer.","topics":["post-market","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-73-incident-reporting"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/73","label":"Read Article 73 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-75-legal-text","legacy_id":"raip:template:article-75-legal-text","type":"template","slug":"article-75-legal-text","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b16cc8dd84acdbcfa590b3ddea07240e2aceb9a9e0e39d28a11673fea95e8872","label":"Full text of Article 75","summary":"The full legal text in the public AI Act Explorer. Note: the amended heading, the replaced paragraph 1, the inserted paragraphs 1a to 1e and 2a and the inserted Articles 75a to 75d appear in the amending regulation and not yet in a consolidated edition of the base regulation.","topics":["enforcement","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties","praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/75","label":"Read Article 75 in the AI Act Explorer"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-78-legal-text","legacy_id":"raip:template:article-78-legal-text","type":"template","slug":"article-78-legal-text","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38acb4e27d0f5910d94c017f7ac296770ef0755c26c294021c73fcb24c6b0a4b","label":"Full text of Article 78","summary":"The full legal text in the public AI Act Explorer.","topics":["enforcement","governance","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-78-confidentiality"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-8-legal-text","legacy_id":"raip:template:article-8-legal-text","type":"template","slug":"article-8-legal-text","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d31f2f1852cfa24ffc8c354279e254efad2e321cdc7593aa0f8276abb6273173","label":"Full text of Article 8","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"upcoming","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-85-legal-text","legacy_id":"raip:template:article-85-legal-text","type":"template","slug":"article-85-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ea32cf6875d143054b642f32c8164abd78af390b9ad3d8269cb220455aad9676","label":"Full text of Article 85","summary":"The full legal text in the public AI Act Explorer.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-85-right-to-complain"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 85 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-86-legal-text","legacy_id":"raip:template:article-86-legal-text","type":"template","slug":"article-86-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d4534952b99e8701244ddcb34211875abf71ffebfdb6c8e807e7a0e99cf5b368","label":"Full text of Article 86","summary":"The full legal text in the public AI Act Explorer.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-86-right-to-explanation"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-87-legal-text","legacy_id":"raip:template:article-87-legal-text","type":"template","slug":"article-87-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"764086ec2d32ab381d4e8f07fdd5422ec782b6c635a6eb268ea91f0454b3217e","label":"Full text of Article 87","summary":"The full legal text in the public AI Act Explorer.","topics":["fundamental-rights","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-87-reporting-infringements"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-9-risk-management-legal-text","legacy_id":"raip:template:article-9-risk-management-legal-text","type":"template","slug":"article-9-risk-management-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a9514f57564fd4a3e11a591c10c252f43e0e34c72665cb90781ba7e689bb0f69","label":"Full text of Article 9","summary":"The full legal text in the public AI Act Explorer.","topics":["high-risk-requirements","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-9-risk-management"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/9","label":"Read Article 9 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-95-legal-text","legacy_id":"raip:template:article-95-legal-text","type":"template","slug":"article-95-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"897fa221621292b8949e435ccf291d959f3d1921042fd557b3b2f9a9a6c3bcb3","label":"Full text of Article 95","summary":"The full legal text in the public AI Act Explorer.","topics":["governance","innovation","template"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:article-99-101-legal-text","legacy_id":"raip:template:article-99-101-legal-text","type":"template","slug":"article-99-101-legal-text","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7e27faa67b597a48f3b20d7c3676ee69327f3a5b564b70fbf9222855e1edfbb7","label":"Full text of Article 99, 100 and 101","summary":"The full legal text in the public AI Act Explorer. Note that the explorer shows the original 2024 text, so for paragraph 1, point (da) and paragraph 6a of Article 99 you also need Regulation (EU) 2026/1744, to which the second source link points.","topics":["enforcement","template"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-99-101-penalties"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:conformity-ce-registration-legal-text","legacy_id":"raip:template:conformity-ce-registration-legal-text","type":"template","slug":"conformity-ce-registration-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"da4e79a386e5b81a43a23d49b7934181d9a557f404f917b7cbbdb9f6b0986cfa","label":"Full text of Article 43","summary":"The full legal text in the public AI Act Explorer.","topics":["conformity","template"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:conformity-ce-registration"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/43","label":"Read Article 43 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:fria-questionnaire","legacy_id":"raip:template:fria-questionnaire","type":"template","slug":"fria-questionnaire","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"12fdf535a33a65f7bf33ab56dbdc41763fd6bca2a7906eded6a46083b829990b","label":"FRIA questionnaire","summary":"Public generator for structuring a fundamental rights impact assessment.","topics":["fundamental-rights","template"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-27-fria"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/fria","label":"Open public FRIA template"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:gpai-guide","legacy_id":"raip:template:gpai-guide","type":"template","slug":"gpai-guide","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a2469dd7c21ddf62f3b35aa0078b856acda090edba8b66b46aef18f7a3abfd3c","label":"GPAI obligations route","summary":"Public guide to GPAI model obligations and exceptions.","topics":["gpai","template"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/gpai-gids","label":"Open GPAI guide"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:template:value-chain-representative-legal-text","legacy_id":"raip:template:value-chain-representative-legal-text","type":"template","slug":"value-chain-representative-legal-text","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd85b9ea413e52e72f7df326246c40517c3d873c63035c874a97911ff4d7797e","label":"Full text of Article 25","summary":"The full legal text in the public AI Act Explorer.","topics":["template","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:value-chain-representative"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/ai-act/artikel/25","label":"Read Article 25 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":{"nl":"CEN-CENELEC JTC 21: Europese normen onder normalisatieverzoek M/613","en":"CEN-CENELEC JTC 21: European standards under standardisation request M/613"},"publisher":{"nl":"CEN-CENELEC JTC 21","en":"CEN-CENELEC JTC 21"},"canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"952a677040f5a8facb59fc7e89676b9127e1c9e4a36e191112c7f7c1dcd45a94","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:cen-cenelec-jtc21"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":{"nl":"Vragen en antwoorden over AI-geletterdheid","en":"AI literacy questions and answers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"a07599c1c5af5cb25fbe1a72caecc7f0093326202cea7949a43d7a89c6c7f038","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-literacy-qa"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-repository","title":{"nl":"Levend repository van AI-geletterdheidspraktijken","en":"Living repository of AI literacy practices"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/ai-literacy-practices","eli":null,"source_version":"living-repository-checked-2026-08-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"4e94b1079cbf3075021a7505dbe803bb4e4bd5a21fa917573012b95a2dabcff7","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-literacy-repository"},{"id":"praxikon:eu:ai-act:source:commission-ai-system-definition-guidelines","title":{"nl":"Richtsnoeren over de definitie van een AI-systeem, C(2025) 5053 final","en":"Guidelines on the definition of an AI system, C(2025) 5053 final"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application","eli":null,"source_version":"c-2025-5053-final-2025-07-29","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"51b321c2804bc3c4deb4c0d3b19d039a9b8eecaf06c56a4bb3ade3f7d36128b8","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-system-definition-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":{"nl":"Richtsnoeren over Artikel 50","en":"Guidelines on Article 50"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"3c3d066f0294692b398f096861adb89198f3d6062939237a97b35fa9ced4d39d","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-article-50-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":{"nl":"Ontwerprichtsnoeren over de classificatie van hoog-risico AI-systemen","en":"Draft guidelines on the classification of high-risk AI systems"},"publisher":{"nl":"Europese Commissie (AI Office)","en":"European Commission (AI Office)"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"1560a59f57f0d9c0c6fe9d1a370772d43e93c21c6686db6ab198f44712dcb8d3","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-draft-high-risk-classification-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","title":{"nl":"Richtsnoeren over verboden AI-praktijken, C(2025) 5052 final","en":"Guidelines on prohibited AI practices, C(2025) 5052 final"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null,"source_version":"c-2025-5052-final-2025-07-29","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"5abfc9ac7322566cc0c6f47865437049be46dd0c2a12f282f247e123667329ca","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-prohibited-practices-guidelines"},{"id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","title":{"nl":"Richtlijn (EU) 2019/1937 inzake de bescherming van personen die inbreuken op het Unierecht melden","en":"Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj","source_version":"original-oj-2019-11-26","verified_at":"2026-09-06T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"2c76f0ccbfefa16c95ca202883ed31d30dfa21498f4895b621abab2fb9dbb706","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:dir-eu-2019-1937"},{"id":"praxikon:eu:ai-act:source:gpai-code-of-practice","title":{"nl":"Praktijkcode voor AI voor algemene doeleinden","en":"General-Purpose AI Code of Practice"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null,"source_version":"published-2025-07-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"c5c59097f402c229249c30efeda4e895ca79c2617adcdf954c890c5456cd4123","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:gpai-code-of-practice"},{"id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","title":{"nl":"ISO/IEC JTC 1/SC 42: internationale normen voor artificiele intelligentie","en":"ISO/IEC JTC 1/SC 42: international standards for artificial intelligence"},"publisher":{"nl":"ISO/IEC JTC 1/SC 42","en":"ISO/IEC JTC 1/SC 42"},"canonical_url":"https://www.iso.org/committee/6794475.html","eli":null,"source_version":"catalogue-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"50d723c8c721474cf3cb49fddecdfe4cbd517a9f6c6f83ddc529a9c7c5f94503","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:iso-iec-jtc1-sc42"},{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"},{"id":"praxikon:eu:ai-act:source:transparency-code-of-practice","title":{"nl":"Praktijkcode over transparantie van door AI gegenereerde inhoud","en":"Code of Practice on transparency of AI-generated content"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content","eli":null,"source_version":"published-2026-06-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"81a4a50dce1b7f73e526f865ce726eaf7678774c869a0b54ace6c2c4f9fd4a28","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:transparency-code-of-practice"}]},"links":{"self":"https://www.praxikon.com/api/v1/entities?lang=en","alternate":"https://www.praxikon.com/api/v1/entities?lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}