{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.1.0","schema_version":"1.4.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","count":64,"filters":{"id":null,"type":"definition","role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:definition:definitie-aanbieder","legacy_id":"raip:definition:definitie-aanbieder","type":"definition","slug":"definitie-aanbieder","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b8efafa63e2c337eb9399702aedafa0893df6229ccce4aeaef40b78aa10ee6cc","label":"Provider","summary":"The role carrying the heaviest obligations, and the role organisations most often end up in by accident.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(3) defines a provider as a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Many organisations believe they are a provider because they use a model. Use alone is not the test: the dividing line is placing on the market or putting into service under your own name or trademark. Someone who modifies or fine-tunes a general-purpose AI model and places the result on the market does, however, become a provider of that modified model; recital 109 then limits the obligations to that modification or fine-tuning. Conversely, organisations wrongly assume they can never be a provider because they sell nothing: having a system developed counts, free of charge counts, and an internally built tool that you put into service under your own name for your own use makes you a provider alongside being a deployer. Article 25(1) also moves a distributor, importer, deployer or third party into the provider role for a high-risk system when it puts its name or trademark on it, makes a substantial modification, or changes the intended purpose so that the system becomes high risk.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess the role question per system, not per organisation, and record the answer with its reasoning. Include three fields in the register: under whose name or trademark the system is offered or put into service, who developed it or had it developed, and whether the intended purpose or configuration has changed since deployment. Reassess those fields on every substantial modification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-aangemelde-instantie","legacy_id":"raip:definition:definitie-aangemelde-instantie","type":"definition","slug":"definitie-aangemelde-instantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c69ff95d0f54baf97cf6f991713e65639055000d24cc73ec9b28ed7b02e585f0","label":"Notified body","summary":"A conformity assessment body notified in accordance with this regulation and other relevant Union harmonisation legislation. Only notified bodies may carry out the external assessments under the AI Act.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(22) defines a notified body as a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The biggest misconception is that every high-risk system must pass through a notified body. That is wrong: for most Annex III systems, internal control by the provider itself suffices. External involvement mainly arises for biometrics and for products already covered by the Annex I harmonisation legislation, where existing product certification absorbs the AI requirements. Anyone who routinely demands a notified body certificate in a tender is often demanding something that does not exist for that system, and thereby excludes suitable suppliers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each high-risk system, determine whether external assessment is legally required before writing that requirement into a contract or tender, and record the analysis. If you do require notified body involvement, note the body's identification number and scope and verify them in the official Union database.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(22)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-aanmeldende-autoriteit","legacy_id":"raip:definition:definitie-aanmeldende-autoriteit","type":"definition","slug":"definitie-aanmeldende-autoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1248a9564ca01fe98a65faaf82e2d18cc7b2f73d960ef2a4d8462d71e3223f49","label":"Notifying authority","summary":"The national authority responsible for setting up and carrying out the procedures for assessing, designating and notifying conformity assessment bodies, and for monitoring them.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(19) defines notifying authority as the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The notifying authority is not your point of contact and does not supervise you. It approves the assessors. That distinction is often missed in the market: companies approach the notifying authority when they should be dealing with the market surveillance authority. For most organisations the practical significance is indirect but real: as long as Member States have designated few bodies, capacity is limited for the systems that do require external assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in your dossier which national bodies are relevant for your sector and what role each has, so that a notification or question does not go to the wrong party. Explicitly distinguish the notifying authority, the market surveillance authority and any notified body used by your supplier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(19)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-bureau","legacy_id":"raip:definition:definitie-ai-bureau","type":"definition","slug":"definitie-ai-bureau","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9a2b7365580dacf63ba54252ec6f0f0829465fe648555e08b9d410a35ddd4c4c","label":"AI Office","summary":"Not a standalone authority but a function within the European Commission. For general-purpose AI models the AI Office is your supervisor; for ordinary AI systems it is not.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(47) defines the AI Office as the Commission's function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in the Commission Decision of 24 January 2024. References in the Regulation to the AI Office are to be construed as references to the Commission.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The final sentence matters most: in law the AI Office is the Commission. There is no separate agency to appeal to, and the powers are the Commission's powers. In practice, for providers of general-purpose AI models the AI Office is the enforcer. The Article 53 obligations have applied since 2 August 2025 and have been enforceable since 2 August 2026. For ordinary AI systems your contact is not the AI Office but the national market surveillance authority. Organisations routinely send questions to the wrong desk and lose time doing so.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Set out in your escalation and contact map who approaches whom: questions and notifications about general-purpose AI models go to the AI Office, questions about AI systems go to the national market surveillance authority. Assign one internal owner per route.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(47)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-geletterdheid","legacy_id":"raip:definition:definitie-ai-geletterdheid","type":"definition","slug":"definitie-ai-geletterdheid","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5c27e9360af4aea6af04b202ce93a0d4062298d0823734a74e169a1fdf743c26","label":"AI literacy","summary":"Skills, knowledge and understanding that enable providers, deployers and affected persons to deploy AI systems in an informed way and to become aware of the opportunities, risks and possible harm of AI.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(56) defines AI literacy as skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations under this Regulation, to make an informed deployment of AI systems and to gain awareness of the opportunities and risks of AI and the possible harm it can cause.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition is role-bound: literacy must match the rights and obligations of the person concerned, so it means something different for a recruiter than for a developer or a compliance lead. That is where practice goes wrong. Organisations buy one generic e-learning for everyone and consider themselves done, whereas the definition asks for understanding that matches what a person actually does with AI. Article 4 has applied since 2 February 2025 and, following the Digital Omnibus, Regulation (EU) 2026/1744 which entered into force on 27 July 2026, has become an obligation to take measures without a guaranteed individual level. That lowers the bar for the outcome, not for the evidence: you must still show which measures you took and why they are appropriate.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record which roles in your organisation work with AI, what level of knowledge and understanding each role requires, which measure you put in place for it and when. Retain participation and dates per person, and repeat the measure when someone changes role or a new AI system is taken into use, so you can show at any moment who is demonstrably prepared.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(56)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-model-voor-algemene-doeleinden","legacy_id":"raip:definition:definitie-ai-model-voor-algemene-doeleinden","type":"definition","slug":"definitie-ai-model-voor-algemene-doeleinden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"795f4732b91cc2ce447293a5033eb5f17030d362ee7c05787c7f1c49ee8bc1de","label":"General-purpose AI model (GPAI model)","summary":"The model is not the system, and that distinction determines which chapter of obligations applies to you.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-ai-model-voor-algemene-doeleinden-exception","operator":"not","description":"AI models used for research, development or prototyping activities before they are placed on the market fall outside the definition."}],"statements":[{"kind":"official_fact","text":"Article 3(63) defines a general-purpose AI model as an AI model, including where such a model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models used for research, development or prototyping activities before they are placed on the market. Point 66 separately defines a general-purpose AI system as an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Model and system are used interchangeably in practice, and that is the heart of the confusion. Point 63 concerns the model, point 66 the system built on top of it. Obligations for GPAI models rest on the model provider; an organisation embedding that model in its own application is in principle dealing with the regime for AI systems. Two further things are missed. The definition expressly excludes models used for research, development or prototyping before they are placed on the market, so the exception lapses at the moment of placing on the market. And the phrase regardless of the way the model is placed on the market means that openly released models can fall within the definition too. On timing: Article 53 has applied since 2 August 2025, the enforcement powers of the Commission and the AI Office and the fines of Article 101 have been active since 2 August 2026, and for models placed on the market before 2 August 2025 the period runs until 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Distinguish the model layer and the system layer explicitly in your register, and record per application which underlying model is used, from which provider, and whether your organisation itself places that model on the market. When developing your own models, record the moment the research or prototyping stage ends, because that is where the regime begins.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(63), (66)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-systeem","legacy_id":"raip:definition:definitie-ai-systeem","type":"definition","slug":"definitie-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f53a73dad1a5bd2972b6b81d011d5b96864dbc53a56c9ba55a34737f711c2a0f","label":"AI system","summary":"The gateway definition of the Regulation's system track: if your application falls outside it, the obligations for AI systems do not apply. General-purpose AI models run on a separate track under Article 3(63), with their own obligations in Article 53.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(1) defines an AI system as a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two mirror-image errors. First, treating only generative AI and language models as AI systems, which leaves classic scoring models, matching algorithms and predictive models out of the register even though they clearly infer how to generate outputs. Second, calling every piece of software AI, which makes the register useless. The hinge is the word infers: a system that merely executes a rule written by a human infers nothing. Note also the word may in may exhibit adaptiveness: adaptiveness after deployment is a possibility, not a condition. A model frozen after training is still an AI system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every application, record three answers in your AI register with a date and the name of the assessor: does it operate with some degree of autonomy, does it infer from input how to generate output, and what is that output. When the outcome is negative, keep the reasoning, because that is the document with which you later explain why the system is out of scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ai-testomgeving-voor-regelgeving","legacy_id":"raip:definition:definitie-ai-testomgeving-voor-regelgeving","type":"definition","slug":"definitie-ai-testomgeving-voor-regelgeving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5da6b3a335b4c33877c537f2df3ddeb3e74de36c2531ff6bb9dd33f60afb5fb6","label":"AI regulatory sandbox","summary":"A controlled framework set up by a competent authority in which you may temporarily develop, train, validate and test an innovative AI system under regulatory supervision, following a sandbox plan.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(55) defines an AI regulatory sandbox as a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The biggest misconception is that a sandbox grants an exemption from the Regulation. It does not. The framework is controlled and time-limited and operates under regulatory supervision; it does not suspend obligations. The definition also expressly names prospective providers, so parties that have not yet placed anything on the market can take part. Anyone using the term as marketing language without admission by a competent authority is using it incorrectly.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether your participation has been formally admitted by a competent authority, which period applies, which sandbox plan governs it and which obligations continue to apply during participation. Include the sandbox outcomes in your technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(55)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-beoogd-doel","legacy_id":"raip:definition:definitie-beoogd-doel","type":"definition","slug":"definitie-beoogd-doel","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3fdd25e29c42777568dc8e8cac6eecbf53b2a1c6f8c092e9d09e9f6331010b1a","label":"Intended purpose","summary":"The use set by the provider on which the entire risk classification and assessment rest.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(12) defines intended purpose as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two things are structurally missed. First, the intended purpose is set by the provider, not by what you as a deployer do with the system. Second, and this hits providers hard: the intended purpose is derived not only from the manual but also from promotional and sales materials and from statements. A marketing claim that the system is also suitable for recruitment or for creditworthiness assessment therefore widens the intended purpose and can shift the risk classification. For deployers the mirror-image warning applies: use outside the intended purpose is not free. It can amount to reasonably foreseeable misuse, and under Article 25(1)(c) it can amount to a change of intended purpose that makes you the provider yourself, but only where the system thereby becomes a high-risk AI system in accordance with Article 6.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Have marketing and product management align claims about application areas explicitly with the instructions for use and the technical documentation, and record that those three sources carry the same scope. As a deployer, record per system the intended purpose as described by the supplier alongside your actual use, and flag every difference as a decision point.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-bijzondere-categorieen-persoonsgegevens","legacy_id":"raip:definition:definitie-bijzondere-categorieen-persoonsgegevens","type":"definition","slug":"definitie-bijzondere-categorieen-persoonsgegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d064259aa75aae71e530774d78a8d3b15f97468076b11be82f686cde95fdf357","label":"Special categories of personal data","summary":"The sensitive data categories from the GDPR and related European rules, imported here because the AI Act attaches both a prohibition and a narrow exception to them.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(37) defines special categories of personal data as the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition cross-refers, but the AI Act gives it two independent consequences. First, it touches Article 5, enforceable since 2 February 2025: biometric categorisation that infers individually sensitive attributes such as race, political opinions, trade union membership, religion, sex life or sexual orientation is prohibited. Second, Article 10(5) contains an exception permitting processing of special category data where strictly necessary to detect and correct bias in high-risk systems. That exception is consistently read too broadly. It applies only to high-risk systems, only where other means demonstrably do not suffice, with technical limits on reuse and transmission, and with deletion once the bias has been addressed. It is not a general basis for starting to collect sensitive attributes because you want to run fairness measurements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether you rely on Article 10(5), for which high-risk system, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access, and at what point the data are deleted. Align this with your data protection officer and cross-reference from your AI dossier to the corresponding data protection impact assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(37)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-gegevens","legacy_id":"raip:definition:definitie-biometrische-gegevens","type":"definition","slug":"definitie-biometrische-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"de8709be1f53c0c58a6f7fb9f6ac1724dff49b2f4f2cde17fd9075fd50c95ce0","label":"Biometric data","summary":"The AI Act uses its own, broader wording than the GDPR, and that difference decides whether you land in Annex III or Article 5.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(34) defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Almost everyone reads the GDPR definition into this one. That goes wrong on a point that is legally decisive: Article 4(14) GDPR requires that the processing allows or confirms unique identification, and that requirement does not appear in point 34 of the AI Act. Data on behavioural characteristics such as keystroke rhythm, gait or voice features can therefore be biometric data under the AI Act even where identification is not the aim. Anyone basing their AI inventory on the GDPR qualification risks missing systems falling under Article 5 or Annex III. For the GDPR side of the same processing, that Regulation continues to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assess biometrics in your AI register separately from the GDPR assessment and record both outcomes side by side. Include systems that process behavioural characteristics without an identification purpose, such as fraud detection on typing behaviour or voice analysis in the customer contact chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(34)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie","legacy_id":"raip:definition:definitie-biometrische-identificatie","type":"definition","slug":"definitie-biometrische-identificatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c3eeaee7409efa91d2f46e04aa682d173ed02d56c169d19b6bb7f7923710a33","label":"Biometric identification","summary":"A one-to-many comparison against a database, to be distinguished from the one-to-one verification of point 36.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(35) defines biometric identification as the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database. Point 36 separately defines biometric verification as the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Identification and verification are used interchangeably in conversations with suppliers, while the difference determines the regime. Identification is one-to-many: the system searches for who someone is by comparing against a database holding data on individuals. Verification is one-to-one: the system confirms whether someone is who they claim to be. Access control with a face scan against the employee's own badge record is verification; a camera running faces past a watchlist is identification. A detail that is rarely noticed: point 35 also mentions psychological features, while the definition of biometric data in point 34 does not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in writing for each biometric application whether the comparison is one-to-one or one-to-many, which database is compared against and who controls that database. Ask for this as a hard requirement during procurement, because vendor material rarely speaks in these terms and the answer determines whether you end up in Article 5 or in Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(35)-(36)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-achteraf","legacy_id":"raip:definition:definitie-biometrische-identificatie-op-afstand-achteraf","type":"definition","slug":"definitie-biometrische-identificatie-op-afstand-achteraf","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e23f14491485a8d0e49063f6f81943dcb8a627dbeeb0b2886b11154ffba28cce","label":"Post-remote biometric identification system","summary":"The residual category: any remote identification that is not real-time. Not prohibited, but high-risk, and subject to its own authorisation regime in law enforcement.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(43) defines this as a remote biometric identification system other than a real-time remote biometric identification system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A residual category is not a free zone. Searching recorded footage for individuals after the fact does not fall under the Article 5 prohibition, but it is high-risk under Annex III, point 1(a) from 2 December 2027. For law enforcement, Article 26(10) applies as well: use requires, in principle, prior authorisation, or authorisation requested without undue delay, from a judicial or independent administrative authority, tied to a specific criminal offence. Organisations that offer \"we only look back afterwards\" as reassurance are confusing the absence of a prohibition with the absence of obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each search, record who authorised it, which offence or legal basis it rests on, which period and which footage were searched, and what the outcome was.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(43)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-in-real-time","legacy_id":"raip:definition:definitie-biometrische-identificatie-op-afstand-in-real-time","type":"definition","slug":"definitie-biometrische-identificatie-op-afstand-in-real-time","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"17a55cf94f879698b7063eab7013f6ef08e4daa2a7edf45073ccdb9ab50c46bf","label":"Real-time remote biometric identification system","summary":"Remote identification where capture, comparison and identification happen without significant delay. The legislator explicitly closed the escape route of an artificial delay.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(42) defines this as a remote biometric identification system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification but also limited short delays, in order to avoid circumvention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The reference to limited short delays is deliberate. It shuts down the design in which a buffer of seconds or minutes is added so the operator can claim the system is not real-time. The distinction matters enormously: the use of real-time remote identification in publicly accessible spaces for law enforcement has been prohibited in principle since 2 February 2025 under Article 5(1)(h), with narrow exceptions requiring prior authorisation and a national legal basis.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document the processing architecture and the measured latency of the system, including test results. A statement that you \"buffer\" is not a defence if identification becomes actionable within seconds or minutes in practice.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(42)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ce-markering","legacy_id":"raip:definition:definitie-ce-markering","type":"definition","slug":"definitie-ce-markering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6f70390736fed31fbad7adf8fe20472b3acc91e453b8fa07a92578e6203f8df0","label":"CE marking","summary":"The marking by which a provider indicates that an AI system conforms to the requirements of Chapter III, Section 2 and to other applicable Union harmonisation legislation providing for its affixing.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(24) defines CE marking as a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The CE marking is a declaration by the provider itself, not a regulator's seal and not a quality label. It belongs solely to high-risk AI systems, so a supplier presenting CE marking as a selling point for an ordinary chatbot is telling you the wrong story. Conversely, the absence of CE marking is not a shortcoming for a system that is not high-risk. For high-risk systems this becomes relevant from 2 December 2027 for Annex III and 2 August 2028 for Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every high-risk AI system, request the EU declaration of conformity that must sit behind the CE marking and keep it in your dossier, together with the system version it relates to. Do not accept a reference to CE marking without the underlying declaration as evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(24)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordeling","legacy_id":"raip:definition:definitie-conformiteitsbeoordeling","type":"definition","slug":"definitie-conformiteitsbeoordeling","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a4e48a70b8962f16e951ff6bcfbce1b42d2f5ae1e6be57c5e76ab98f73fa004b","label":"Conformity assessment","summary":"The process of demonstrating that a high-risk AI system meets the requirements of Chapter III, Section 2. It is the evidence step for high-risk systems, not for all AI.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(20) defines conformity assessment as the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two misconceptions dominate. The first is that every AI application needs a conformity assessment: the definition expressly limits it to high-risk systems. The second is that conformity assessment equals an external audit: for most Annex III systems the internal control route of Article 43 suffices, with the provider itself demonstrating that the requirements are met. If you conclude you are not high-risk, substantiate that conclusion in writing rather than assuming it silently. The obligations apply to Annex III systems from 2 December 2027 and to Annex I products from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record your risk classification in writing for each AI system, including the reasoning, even where the outcome is that it is not high-risk. Where it is high-risk, also record which route you follow, internal control or involvement of a notified body, and which evidence per requirement of Chapter III, Section 2 sits in the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(20)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordelingsinstantie","legacy_id":"raip:definition:definitie-conformiteitsbeoordelingsinstantie","type":"definition","slug":"definitie-conformiteitsbeoordelingsinstantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c6d3757fe90472979ef062df91c77f44600ee5a330a5b6998fa70ebcb58ce6bd","label":"Conformity assessment body","summary":"A body that performs third-party conformity assessment activities, including testing, certification and inspection.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(21) defines a conformity assessment body as a body that performs third-party conformity assessment activities, including testing, certification and inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The key phrase is third party. An internal audit function, a consultancy or your own quality team is not a conformity assessment body, however thorough the work. Note also the difference from a notified body in point 22: every notified body is a conformity assessment body, but not the reverse. Only after notification may a body carry out the statutory assessments under this regulation. Certificates from bodies that are not notified have commercial value but no legal status under the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Before purchasing an external assessment, verify that the body is in fact notified for the relevant scope and record the evidence in your dossier. For every external report, note the role the party had, adviser or notified body, so it never later appears that an advisory report was a statutory assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(21)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-deepfake","legacy_id":"raip:definition:definitie-deepfake","type":"definition","slug":"definitie-deepfake","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b0c2f8ddba451add6e0ecd11ee18e5941ab3e4527dc4b59200029d389c60e2eb","label":"Deep fake","summary":"Far broader than fake videos of famous people: objects, places, entities and events are covered too.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(60) defines a deep fake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The name pushes the reading in the wrong direction. Under this Regulation a deep fake is not limited to fake footage of famous people: the definition expressly also names objects, places, entities and events. An AI-generated photo of an existing building, a demonstration that never happened, or a product image that reads as a real photograph can therefore be a deep fake. Two boundaries matter. The definition names image, audio and video; pure text is not covered, although Article 50 has its own rule for certain publications. And content resembling a non-existent person falls outside point 60, while it may still fall under the marking duty for synthetic output. Article 50 has applied since 2 August 2026; the only transition concerns the machine-readable marking of Article 50(2) for systems already on the market before 2 August 2026, running until 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which departments publish AI-generated image, audio or video content, including marketing, communications, training and customer contact, and record per channel how the artificial origin is disclosed. Include generated images of existing locations and products, because those are precisely the ones rarely recognised as deep fakes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(60)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-distributeur","legacy_id":"raip:definition:definitie-distributeur","type":"definition","slug":"definitie-distributeur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"8113722b7f4a5259c937696ebb6364c374c7ec0e0db2f09bc0cab4f8455d442f","label":"Distributor","summary":"Any link in the supply chain that makes an AI system available on the Union market and is neither provider nor importer.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"definitie-distributeur-scope","operator":"all","description":"Applies only to a party in the supply chain that is neither the provider nor the importer."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(7) defines a distributor as a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Resellers, systems integrators, marketplaces and staffing firms that ship software along with their service often assume they fall outside the Regulation because they build nothing. The definition is a residual category: if you are neither provider nor importer in the chain, and you make the system available on the Union market, you are a distributor. Note point 10: making available on the market means supply in the course of a commercial activity, whether for payment or free of charge. Passing something on free or offering a trial version is covered too. Put your own name or trademark on it and the role shifts to provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map which AI systems your organisation passes on to third parties, including free of charge and as a by-product of a service, and record per system whose name or trademark it carries. Set out in your resale contracts who holds which role, so that it is not disputed later who the provider was.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-downstreamaanbieder","legacy_id":"raip:definition:definitie-downstreamaanbieder","type":"definition","slug":"definitie-downstreamaanbieder","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"64567f634b5d9591bc7e867174cd0cf0c7de78cd05d5943f26798df581a0927c","label":"Downstream provider","summary":"A provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether that model is provided by themselves and vertically integrated or obtained from another entity on a contractual basis.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(68) defines a downstream provider as a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the definition organisations most often get wrong about their own role. Anyone integrating a third party model into their own product or service and offering it under their own name is a downstream provider and therefore a provider, not merely a deployer. The words regardless of whether make clear that it does not matter whether you built the model yourself. Your position determines what information you must be able to obtain from the model provider: providers of general-purpose AI models must under Article 53 make documentation available to downstream providers, an obligation applying since 2 August 2025 and enforceable since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record which underlying model is integrated, from which party, and whether that makes you a downstream provider. Include in the contract with the model provider which Article 53 documentation you receive, and keep that documentation in your own file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(68)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-emotieherkenningssysteem","legacy_id":"raip:definition:definitie-emotieherkenningssysteem","type":"definition","slug":"definitie-emotieherkenningssysteem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5e7b6617eec86ff450259e231ea73b3b429437f6ffd36bf4a6ea689c94bd219d","label":"Emotion recognition system","summary":"Prohibited in the workplace and in education since 2 February 2025; elsewhere an information duty under Article 50 applies since 2 August 2026.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-emotieherkenningssysteem-exception","operator":"not","description":"The Article 5(1)(f) prohibition does not apply where the use of the AI system is intended to be put in place or into the market for medical or safety reasons."}],"statements":[{"kind":"official_fact","text":"Article 3(39) defines an emotion recognition system as an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. Article 5(1)(f) prohibits placing on the market, putting into service for this specific purpose, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two scoping errors. First, assuming that every form of sentiment analysis is covered. The definition requires the inference to be made on the basis of biometric data. Sentiment analysis on written text, without biometrics, falls outside point 39 even though it feels comparable. Second, thinking only of facial expressions, while voice analysis in a call centre and posture analysis from camera footage are equally covered. Note also the word intentions alongside emotions: systems predicting purchase readiness or aggression from biometrics fall within the definition. Outside the workplace and education, emotion recognition is not prohibited, but it is listed in Annex III, point 1(c) and therefore counts as a high-risk AI system there once Article 6(2) becomes applicable on 2 December 2027. In addition, since 2 August 2026 the deployer carries the Article 50(3) duty to inform the exposed persons, except for systems permitted by law to detect, prevent, investigate or prosecute criminal offences.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map where voice, facial or posture analysis runs in your organisation, including as part of a larger package such as quality monitoring in customer contact, access control or proctoring. Assess per application whether biometric data forms the basis and whether the context is workplace or education; record that assessment, because this is the category carrying a fine of up to EUR 35 million or 7 percent of worldwide turnover.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(39)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-ernstig-incident","legacy_id":"raip:definition:definitie-ernstig-incident","type":"definition","slug":"definitie-ernstig-incident","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b2c183f2dea17656eef982882a75bbebec3dec2519ac961d86b33fdd86801fbf","label":"Serious incident","summary":"Four categories of consequence, one of which is an infringement of fundamental rights protection. No physical harm is needed before a notification duty arises.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to: (a) the death of a person or serious harm to a person's health, (b) a serious and irreversible disruption of the management or operation of critical infrastructure, (c) the infringement of obligations under Union law intended to protect fundamental rights, or (d) serious harm to property or the environment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Point (c) is the provision organisations miss most often. An infringement of Union law protecting fundamental rights counts as a serious incident, even with no one physically injured. Systematic discrimination in a candidate screening system, in credit scoring or in the allocation of benefits can therefore be notifiable. \"Indirectly\" counts too: what matters is not only the direct output but the consequence further down the process. Providers of high-risk systems report to the market surveillance authority under Article 73, on short deadlines: in principle within 15 days of becoming aware, 2 days for a widespread infringement or serious disruption of critical infrastructure and 10 days in the event of death. That duty bites from the high-risk dates, Annex III on 2 December 2027 and Annex I on 2 August 2028, but incident logging should start now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Set up an incident register now that captures the four categories of point 49 separately, with a timestamp at the moment of awareness. Run one drill to confirm you can file a complete notification within two days; that is the tightest deadline and an ad hoc process will not meet it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(49)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gebruiksinstructies","legacy_id":"raip:definition:definitie-gebruiksinstructies","type":"definition","slug":"definitie-gebruiksinstructies","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"36ea5a9c1adf2d4c04734855fb040c503286546625eeaacfec1e1e732f4bf78c","label":"Instructions for use","summary":"The information the provider supplies to inform the deployer about, in particular, the intended purpose and proper use of an AI system. It is the hinge between the provider's obligations and the deployer's.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(15) defines instructions for use as the information provided by the provider to inform the deployer of, in particular, an AI system's intended purpose and proper use.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this goes wrong in two directions. Providers deliver marketing material or a technical manual instead of instructions that state the intended purpose and the limits of correct use. And deployers file those instructions without reading them, even though Article 26 requires them to use the system in accordance with them. A deployer operating outside the instructions for use can be treated as a provider under Article 25 and thereby take on the full set of provider obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the current instructions for use for each AI system in your dossier, with version number and date of receipt. Also record who in your organisation has read them, which uses you derive as permitted, and which uses you have explicitly prohibited in your own internal work instruction.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(15)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gebruiksverantwoordelijke","legacy_id":"raip:definition:definitie-gebruiksverantwoordelijke","type":"definition","slug":"definitie-gebruiksverantwoordelijke","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0e873b1862c2479a06c94ff9d198956c2f1ad38bdcc68dc41fb3f573f8f25e81","label":"Deployer","summary":"The role that virtually every organisation buying and using AI ends up in.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[{"id":"definitie-gebruiksverantwoordelijke-exception","operator":"not","description":"Use in the course of a personal non-professional activity falls outside the definition."}],"statements":[{"kind":"official_fact","text":"Article 3(4) defines a deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The role is routinely reduced to user, and that is where it goes wrong. The individual employee operating the tool is not the deployer; the legal entity using the system under its authority is. The second trap is the exception: it covers only personal non-professional use. An employee who takes up an AI tool on their own initiative for work does not fall under that exception, and the organisation remains the deployer even without a procurement contract. Shadow AI is therefore not a grey area but simply an unregistered system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per system which legal entity uses it under its authority, including tools a department procured itself or switched on within an existing licence. Add a periodic inventory of AI features that vendors have activated inside existing software, because those rarely arrive through procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-geharmoniseerde-norm","legacy_id":"raip:definition:definitie-geharmoniseerde-norm","type":"definition","slug":"definitie-geharmoniseerde-norm","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"70a5ec3eac27ea95162009985906f76819f9368b8019430397847748a6f4fdb7","label":"Harmonised standard","summary":"A European standard published in the Official Journal which, if you apply it, produces a presumption of conformity. This is the fastest route to demonstrability, but the AI Act standards are not finished yet.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(27) defines a harmonised standard as a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Textually this is a cross-reference, but the practical weight sits in Article 40: if you apply a harmonised standard whose reference has been published in the Official Journal, you are presumed to comply with the corresponding requirement. That removes a great deal of evidentiary burden. The problem as of the reference date is that the standardisation work at CEN and CENELEC is not yet fully completed and published, so organisations cannot currently lean on a ready-made presumption of conformity. Waiting for the standards is not viable, because the Annex III obligations arrive on 2 December 2027 and the Annex I ones on 2 August 2028. You therefore have to build demonstrability yourself and align later.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Maintain a register recording, per requirement from Chapter III, which standard, framework or internal control you rely on and why that choice covers the requirement. Structure that register so you can replace a row once the harmonised standard is published, without having to rewrite your entire dossier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(27)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-geinformeerde-toestemming","legacy_id":"raip:definition:definitie-geinformeerde-toestemming","type":"definition","slug":"definitie-geinformeerde-toestemming","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ab248474c9e870bf5f61b6dc9b78cd334224361527ea7ef7012cf449b5261b7c","label":"Informed consent","summary":"A subject's freely given, specific, unambiguous and voluntary expression of willingness to take part in a particular real-world test, after having been informed of all aspects relevant to that decision.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(59) defines informed consent as a subject's freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject's decision to participate.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Note the word particular: consent applies to one specific test, not to your testing programme as a whole and not to a next version of the system. A general clause in terms of use or an employment contract does not meet this. It is also a concept of its own under the AI Act and not the same as consent as a legal basis under the GDPR, so you cannot cover both with a single form. If the design of the test changes materially, you need fresh consent.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Use a separate consent form for each test containing the information relevant to the decision, and record when and how consent was given and how it can be withdrawn. Document separately that consent was voluntary, particularly for employees.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(59)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gemachtigde","legacy_id":"raip:definition:definitie-gemachtigde","type":"definition","slug":"definitie-gemachtigde","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1793ad1268e6a72c62e9c52cbdd27c80e19e72172e7d9ecc775c0f350e6c0d2d","label":"Authorised representative","summary":"The European point of contact for a provider from outside the Union, valid only on the basis of a written mandate.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"definitie-gemachtigde-scope","operator":"all","description":"The authorised representative is located or established in the Union and has received and accepted a written mandate."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(5) defines an authorised representative as a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common error is that a European sales partner, reseller or subsidiary assumes it is automatically the authorised representative. That does not follow from the commercial relationship. The definition sets two cumulative requirements: the mandate is written, and it is not only given but also accepted. Without that document there is no authorised representative and the supervisory authority in the Union has no formal point of contact for that provider. A second misconception is that appointing an authorised representative transfers the provider role. It does not: the representative acts on behalf of the provider, and the provider remains the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Ask every supplier from outside the Union for the name, registered address and contact details of the authorised representative and for a copy or confirmation of the accepted written mandate. Store it with the system file, because it is the first thing you need once a supervisory authority requests information about a system you source from outside the Union.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gemeenschappelijke-specificatie","legacy_id":"raip:definition:definitie-gemeenschappelijke-specificatie","type":"definition","slug":"definitie-gemeenschappelijke-specificatie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"421ebb1712528befa2715115a21d98edf0bf2e164e2351f776bfcbbfd3bf3489","label":"Common specification","summary":"Technical specifications the Commission can adopt itself when harmonised standards are missing or fall short. The fallback that prevents the AI Act from stalling because standardisation is delayed.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(28) defines a common specification as a set of technical specifications as defined in Article 2, point (4), of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition exists because the legislator anticipated that standardisation would not be ready in time. Article 41 allows the Commission to adopt common specifications through implementing acts, with the same effect: applying them creates a presumption of conformity. The misunderstanding is that a common specification would be optional in practice. It is not: anyone deviating must show that their own technical solution is at least equivalent to the intended level of protection, and that reasoning must sit in the technical documentation. Deviating is allowed, but it costs more documentation than following.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Track the Commission's implementing acts and record which common specifications apply to your system. If you choose your own solution, explicitly document which element you do not follow, which alternative measure you take, and on the basis of which analysis you conclude the level of protection is equivalent.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(28)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-gevoelige-operationele-gegevens","legacy_id":"raip:definition:definitie-gevoelige-operationele-gegevens","type":"definition","slug":"definitie-gevoelige-operationele-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6bc6d19db61ff6157ceb0a90fe6d02e2a0a935cff58b07e9ce125caca6ad9d71","label":"Sensitive operational data","summary":"Operational data around detection and prosecution whose disclosure could harm criminal proceedings. The concept on which the law enforcement exceptions to transparency rest.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(38) defines sensitive operational data as operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the key with which the AI Act softens transparency obligations for law enforcement without removing them. Registration of high-risk systems used by law enforcement authorities takes place in a secure, non-public section of the EU database, and certain information need not be made public where it concerns sensitive operational data. Where it goes wrong: the concept is sometimes stretched to cover anything a public body would rather not share. That does not hold, because the definition is doubly bounded, namely by the criminal law context and by a concrete risk to the integrity of criminal proceedings. Outside that context it is no basis for withholding documentation; commercially confidential information follows a separate route. Equally important: it limits publication, not the access of the competent market surveillance authority.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per system which parts of your registration and documentation you designate as sensitive operational data, on what concrete ground disclosure could harm the integrity of criminal proceedings, who makes that assessment and when it is reviewed. Keep a non-sensitive summary available, so you can still account for the system without touching ongoing proceedings.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(38)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-importeur","legacy_id":"raip:definition:definitie-importeur","type":"definition","slug":"definitie-importeur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5929cd13fabbde75a31e8c36d3c791127c89b1aa48d8441e74ef87a49f5fd62c","label":"Importer","summary":"Whoever places on the Union market a system bearing the name or trademark of a party established in a third country.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(6) defines an importer as a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical trap is the assumption that importer has to do with customs or with the invoice flow. The test is different: do you place on the Union market for the first time a system bearing the name or trademark of a party from a third country. Someone who only takes a US service for their own use is not an importer but a deployer. Someone who passes on that same system under their own name or trademark is not an importer but a provider. The importer role sits exactly in between: passing it on with the third party's mark still on it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record three data points per AI system in your supplier register: the country of establishment of the party whose name or trademark the system bears, whether your organisation is the first to make the system available on the Union market, and under which name that happens. Those three fields together determine whether you are an importer, a distributor or a provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-in-de-handel-brengen","legacy_id":"raip:definition:definitie-in-de-handel-brengen","type":"definition","slug":"definitie-in-de-handel-brengen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7609bd6024e0675b2a5d459b010ccc5fa73c1556181f65fb346395f733e85ea1","label":"Placing on the market","summary":"The first moment a system or model is made available on the Union market, and therefore the trigger for many obligations.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(9) defines placing on the market as the first making available of an AI system or a general-purpose AI model on the Union market. Point 10 adds that making available on the market means the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The most persistent error is assuming that a sale or a price must be involved. Point 10 explicitly says whether in return for payment or free of charge. A free trial, an openly available model or a no-cost pilot at a customer can amount to placing on the market. The second error is confusing this concept with putting into service. Placing on the market concerns the market; a system you build and use purely internally is not placed on the market, but it is put into service, and that is an independent trigger in its own right.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each system and model the date of first making available in the Union, together with its form: sale, free trial, open release or pilot. That date determines which regime and which transitional period apply, and it is the first thing a supervisory authority will put next to your file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(9)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-in-gebruik-stellen","legacy_id":"raip:definition:definitie-in-gebruik-stellen","type":"definition","slug":"definitie-in-gebruik-stellen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"40f1cd7abe7b92d00b279e86fa695c94699acacbd644f4125e347401d180dd79","label":"Putting into service","summary":"The concept that brings internally built systems which are never sold within the scope of the Regulation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(11) defines putting into service as the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the trap for organisations that build their own systems. The reasoning runs: we sell nothing, so we place nothing on the market, so provider obligations do not apply. The words or for own use close off that route. As soon as you start using a self-built system in the Union for its intended purpose, you have put it into service, and under point 3 you are a provider as well as a deployer. Note also for first use: a system still running in a test environment and not used for its intended purpose has not yet been put into service.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Register for every internally developed AI system the date on which it went into production for its intended purpose, and note explicitly that your organisation is both provider and deployer. Tie the start of your file-building to that date, and assess immediately whether the system is high risk, because the technical documentation of Article 11 and the logging of Article 12 then apply from that moment and the file need not be reconstructed after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-inputdata","legacy_id":"raip:definition:definitie-inputdata","type":"definition","slug":"definitie-inputdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f2f8b703dc2d81858c6766ab6f7ca4e844f569071af7e99d0de1749bbff9b5c1","label":"Input data","summary":"The data entering the system or acquired by it, on the basis of which it produces its output. This is the data definition that touches the deployer, not just the provider.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(33) defines input data as data provided to or directly acquired by an AI system on the basis of which the system produces an output.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is where responsibility moves to your side of the table. Article 26(4) requires the deployer to ensure that input data are relevant and sufficiently representative in view of the intended purpose, to the extent it exercises control over them. The most persistent misconception is that data quality is the supplier's problem. Prompts, uploaded CVs, sensor readings, customer files and connected source systems are all input data, and an excellently built system produces unusable outcomes when you feed it outdated or skewed data. Note the second half of the definition as well: data the system acquires itself, for instance through a camera or an API, are equally input data and therefore fall within your duty of care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which input data are used, which source systems they come from, who owns their quality and representativeness, how often that is checked, and how long the input is retained in the logs. Explicitly name the input sources you do not control, since that marks the boundary of your duty of care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(33)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-kritieke-infrastructuur","legacy_id":"raip:definition:definitie-kritieke-infrastructuur","type":"definition","slug":"definitie-kritieke-infrastructuur","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2f9688d6fbfc93d1a18ed0b3009a83c9fa9ca70529193ef905e1438b53837445","label":"Critical infrastructure","summary":"Critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557, the CER Directive. The AI Act gives no definition of its own here but aligns with that framework.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(62) provides that critical infrastructure means critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This cross-reference looks like a formality but has direct consequences for the risk class. Annex III, point 2, classifies AI systems as high risk where they are intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity. Anyone wanting to know whether they fall within that scope must consult the CER Directive and the national designation of critical entities rather than invent a definition of their own. Organisations get this wrong because designation differs per Member State.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record whether your organisation or your customer has been designated as a critical entity under the national transposition of Directive (EU) 2022/2557, and link that determination to your risk classification under Annex III, point 2, with date and source.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(62)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-markttoezichtautoriteit","legacy_id":"raip:definition:definitie-markttoezichtautoriteit","type":"definition","slug":"definitie-markttoezichtautoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"33d5e1ae9840557e2d286646345f725d31d173d29cd696b6c028efbc2ada46be","label":"Market surveillance authority","summary":"The national supervisor that enforces the AI Act on the market, with the powers from the general market surveillance regulation. This is the party that comes knocking and requests your documentation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(26) defines the market surveillance authority as the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The confusion lies in distinguishing it from two other players. The notifying authority designates notified bodies and does no enforcement towards you; the Commission's AI Office supervises general-purpose AI models under Article 53, which has applied since 2 August 2025 and has been enforceable since 2 August 2026. The market surveillance authority is your actual enforcement contact point for AI systems: it can request technical documentation and logs, demand access to training and testing data sets, and restrict, withdraw or recall a system. The reference to Regulation (EU) 2019/1020 is not a formality, because through it the supervisor inherits a substantial toolkit of powers that did not need restating in the AI Act.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which market surveillance authority is competent (this differs per sector and per Member State where you offer it), who inside your organisation is the point of contact, and within how many working days you can supply the technical documentation, the logs and the data set descriptions. Rehearse that delivery once, because the deadline the supervisor sets is short.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(26)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-nationale-bevoegde-autoriteit","legacy_id":"raip:definition:definitie-nationale-bevoegde-autoriteit","type":"definition","slug":"definitie-nationale-bevoegde-autoriteit","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"68e66efba97d9301506986942cb0b5559676c13e74b683e6a04131755f934feb","label":"National competent authority","summary":"An umbrella term for two very different roles: the notifying authority and the market surveillance authority. For EU institutions the European Data Protection Supervisor takes their place.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(48) defines a national competent authority as a notifying authority or a market surveillance authority. As regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities are to be construed as references to the European Data Protection Supervisor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition bundles two roles that should not be confused. The notifying authority designates and supervises conformity assessment bodies; as a deploying organisation you will rarely deal with it. The market surveillance authority supervises you, requests documentation, receives serious incident reports and imposes measures. Member States were required to designate and publish these authorities by 2 August 2025. The fact that designation is not fully settled in some Member States changes nothing about your obligations: the duties rest on you, not on the supervisor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every market in which you operate, track which market surveillance authority is competent for your sector, who inside your organisation handles contact and who is authorised to file notifications. State that contact point in your technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(48)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-niet-persoonsgebonden-gegevens","legacy_id":"raip:definition:definitie-niet-persoonsgebonden-gegevens","type":"definition","slug":"definitie-niet-persoonsgebonden-gegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6030cd84e362fe78bf9921f4e12b6d6018095b99b973465833b9144135e6040","label":"Non-personal data","summary":"Everything that is not personal data. The category exists to make clear that the AI Act applies even when no personal data is involved.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(51) defines non-personal data as data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This residual category is the proof that the AI Act is not a privacy law. The data and data governance requirements in Article 10, the technical documentation in Article 11 and the logging in Article 12 apply equally where you work only with machine data, sensor data or synthetic data. \"There is no personal data in it\" is at most a GDPR argument and never an AI Act exemption. In practice, technical teams use this argument to avoid documentation duties in industrial and infrastructure applications, which are exactly the applications that can fall under Annex I and Annex III.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each dataset whether it contains personal data, but never let that answer determine whether you produce the AI Act documentation. Assess documentation duties on the system's risk classification, not on the nature of the data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(51)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-openbare-ruimte","legacy_id":"raip:definition:definitie-openbare-ruimte","type":"definition","slug":"definitie-openbare-ruimte","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"896ab14f18c3e7c26c51a80be2ec11c4cb7993d3ab0327d4e9335cd0b954d295","label":"Publicly accessible space","summary":"Any physical place, publicly or privately owned, accessible to an undetermined number of people. Access conditions and capacity limits are irrelevant.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(44) defines a publicly accessible space as any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply and regardless of potential capacity restrictions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The familiar argument \"it is our own premises, so not a public space\" does not hold. Shops, stations, airports, stadiums, cinemas, hospital waiting rooms and shopping centres are publicly accessible spaces, even where ticketing, house rules or a capacity cap apply. What matters is whether the circle of visitors is undetermined. An office floor open only to your own staff normally falls outside, because that circle is determined. This concept switches the Article 5 prohibition on real-time remote identification on or off, and feeds through into Annex III classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"In your camera and biometrics register, mark for each location whether it is a publicly accessible space within the meaning of point 44, with a short justification. Do this before you procure a system, not after.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(44)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-operator","legacy_id":"raip:definition:definitie-operator","type":"definition","slug":"definitie-operator","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9b6f7e5b05a7c4b4fb0ecd210e6a6d585a78ef0309b31a7358b91e81e90dcc6c","label":"Operator","summary":"The umbrella term for all six roles in the chain, and not the person operating the controls.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(8) defines an operator as a provider, product manufacturer, deployer, authorised representative, importer or distributor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Operator is read as the person who operates the system day to day. That is precisely what it does not mean. It is an umbrella term: where a provision addresses operators, it addresses all six listed roles at once. Anyone who skips operator obligations in a gap analysis because they believe they are only a deployer misses provisions that do apply to them. Note also that product manufacturer appears in this list as a role but is not separately defined in Article 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add an operator column to your compliance overview that spells out the six roles explicitly, so that for each provision it is visible which roles are affected. Record per AI system every role your organisation holds for that specific system, because there is usually more than one.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(8)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-persoonsgegevens","legacy_id":"raip:definition:definitie-persoonsgegevens","type":"definition","slug":"definitie-persoonsgegevens","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5f531533c5f033ec83c79b8dbe127db1de6e7a95344d8a02855f2838f3d57b0e","label":"Personal data","summary":"The AI Act deliberately creates no separate concept here and refers to the GDPR. Your GDPR records and your AI Act file must therefore cover the same data.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(50) defines personal data as personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The cross-reference looks dull but has a practical effect: there is no room for a separate AI Act reading of what constitutes personal data. Where the AI Act does open space, such as Article 10(5) permitting processing of special categories to detect and correct bias in high-risk systems, GDPR safeguards apply in full and additional conditions attach. Organisations that keep AI governance and privacy in separate files end up with conflicting descriptions of the same processing, precisely when a supervisor asks for both.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Link every AI system in your AI register to the corresponding processing activity in your GDPR record, using one shared identifier, so that a single change updates both files.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(50)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-plan-voor-testen-onder-reele-omstandigheden","legacy_id":"raip:definition:definitie-plan-voor-testen-onder-reele-omstandigheden","type":"definition","slug":"definitie-plan-voor-testen-onder-reele-omstandigheden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9070268d8aca95a4a3f19619bce98e681a8e5e4a2b3b454824b10249b3b702e5","label":"Real-world testing plan","summary":"The document in which you set out in advance how you will test an AI system outside the lab: objective, methodology, scope, who takes part, for how long and how you monitor it. Without this plan, testing in real-world conditions is not permitted.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(53) defines a real-world testing plan as a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this goes wrong because organisations keep calling a pilot with real users a pilot and assume nothing applies. As soon as you trial an AI system with real people in a real environment, you fall under the regime of Article 57 or 60, and that requires a plan drawn up in advance that can be reviewed. A test plan written after the fact to fill a file does not meet the definition, because the essence of the concept is that the design is fixed beforehand.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every real-world test, record a single document containing the eight elements from the definition: objective, methodology, geographical scope, the population involved, duration, monitoring, organisation and conduct. Link that document to the registration of the test and retain it with the date of approval.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(53)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-prestaties-ai-systeem","legacy_id":"raip:definition:definitie-prestaties-ai-systeem","type":"definition","slug":"definitie-prestaties-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d5ba2214f5fc1d09014b5705fdf602a7d9569bfb5ecc37b8a9edb76ea2dcf91","label":"Performance of an AI system","summary":"The ability of an AI system to achieve its intended purpose. Performance is therefore measured against the intended purpose, not against a standalone technical score.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(18) defines performance of an AI system as the ability of an AI system to achieve its intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition ties performance firmly to the intended purpose in point 12. An accuracy of 94 percent is therefore no answer to whether the system performs, as long as it is not established what it is meant for and for which group of people that score holds. A model that scores well on average but performs structurally worse for a subgroup does not achieve the intended purpose for that group. That is exactly what Article 15 on accuracy and robustness and Article 10 on data quality target.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record which performance metrics you use, which threshold is acceptable for the intended purpose, and how those metrics break down per relevant subgroup. Repeat the measurement periodically and retain the results, so you can demonstrate performance drift before a supervisory authority asks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(18)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-proefpersoon","legacy_id":"raip:definition:definitie-proefpersoon","type":"definition","slug":"definitie-proefpersoon","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2a16ab809e3d8274195aecfa9c536f70c3b6014bd6eb681db9591735bdf484a0","label":"Subject","summary":"For the purpose of real-world testing, a subject is a natural person who participates in such a test. The term comes from the testing regime, not from data protection law.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(58) defines subject, for the purpose of real-world testing, as a natural person who participates in testing in real-world conditions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition looks trivial but determines who is protected. Whoever is a subject is entitled to informed consent under point 59 and to the safeguards of Articles 57 and 60. The misunderstanding lies in assuming that only external test participants are subjects. Employees who work with a test system during their job can also be subjects, and precisely for them the voluntariness of consent is a sensitive point given the hierarchical relationship.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each test, keep a record of the subjects or of the clearly delimited group they come from, with the date of their consent and how they were informed. Assess separately whether employees participate as subjects and how you safeguard voluntariness.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(58)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-profilering","legacy_id":"raip:definition:definitie-profilering","type":"definition","slug":"definitie-profilering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"a93aa74cab4873b611f98e223294c400f8b1a82e9a410d48051d44b8ef4a8624","label":"Profiling","summary":"Taken from the GDPR, but decisive in the AI Act: an Annex III system that profiles always remains high-risk.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(52) defines profiling as profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the most important of the three GDPR cross-references. Article 6(3) offers an exception under which an Annex III system is nonetheless not treated as high-risk, for instance because it performs a narrow procedural task or only preparatory work. That exception falls away entirely once the system profiles within the meaning of the GDPR: automated processing to evaluate personal aspects such as performance, reliability, behaviour, health or preferences. In practice most recruitment, credit scoring and fraud detection applications do profile, so the exception many organisations invoke rarely holds.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each Annex III system, record explicitly whether it profiles within the meaning of Article 4(4) GDPR, with the reasoning and the date. Keep that reasoning with your Article 6(3) assessment; it is the first document a supervisor will ask for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(52)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-rechtshandhaving","legacy_id":"raip:definition:definitie-rechtshandhaving","type":"definition","slug":"definitie-rechtshandhaving","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b70b2d63ec22c2531647bfd7cc878332768a97516194ee3eb176298a54e2b8ca","label":"Law enforcement","summary":"The activity, not the authority. Work carried out on behalf of a law enforcement authority is covered as well, including where a private party performs it.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(46) defines law enforcement as activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The words \"on their behalf\" are decisive. A vendor, forensic analysis firm or contracted data specialist working for the police operates inside the law enforcement regime, with the corresponding safeguards and registration duties. Conversely, fraud investigation by an insurer, internal integrity investigations and private security are not law enforcement. Those organisations cannot use the exceptions and fall squarely under the ordinary regime, including the prohibition on real-time remote identification as it applies to them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each deployment, record whether it falls inside or outside law enforcement, naming the commissioning authority and the contractual documents. Put that qualification in the contract so vendor and client apply the same regime.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(46)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-rechtshandhavingsinstantie","legacy_id":"raip:definition:definitie-rechtshandhavingsinstantie","type":"definition","slug":"definitie-rechtshandhavingsinstantie","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0860e2540f9c082630db246bc258237fdef48cea528e516e89b08a015444f834","label":"Law enforcement authority","summary":"Not just the police and prosecution service. Also any other body entrusted under national law with public authority for detection, prosecution or public security.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(45) covers (a) any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security, and (b) any other body or entity entrusted by Member State law to exercise public authority and public powers for those same purposes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Point (b) draws the circle far wider than people expect. Special enforcement officers, specialised investigation services, parts of municipal enforcement and private bodies with a statutory public task can all fall within it. This is not a label without consequences: the status changes the regime. Law enforcement authorities may rely, under strict conditions, on exceptions in Article 5, register their high-risk use in a non-public section of the EU database under Article 49(4), and are subject to their own safeguards in Article 26. An organisation that wrongly treats itself as a law enforcement authority builds its compliance file on the wrong footing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each team and each AI system, record the statutory basis on which you enforce and whether that makes you a law enforcement authority. Have that qualification reviewed legally before you rely on any exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(45)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-redelijkerwijs-te-voorzien-misbruik","legacy_id":"raip:definition:definitie-redelijkerwijs-te-voorzien-misbruik","type":"definition","slug":"definitie-redelijkerwijs-te-voorzien-misbruik","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1d878f952a65193ba15fd9063f41f55c720ebde6a05151597fae5090dcedab7c","label":"Reasonably foreseeable misuse","summary":"Use outside the intended purpose that the provider could have seen coming, and must therefore anticipate.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(13) defines reasonably foreseeable misuse as the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The word misuse suggests bad intent, or a user error. That is the wrong reading. It concerns behaviour that is simply predictable: an employee who also uses a summarisation tool for decision-making, a chatbot receiving questions it was not built for, a model fed input by another system through an integration. The second error is the belief that excluding a use in the manual removes the risk. Not being mentioned in the manual is not the same as not being foreseeable. Note also the explicit mention of interaction with other systems, including other AI systems: chained and agentic set-ups fall squarely within it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep a short list per system of foreseeable deviating use, fed by incidents, helpdesk questions and end-user signals, and note for each entry which measure was taken. Include the integrations with other systems explicitly in that list, because that is where use nobody designed emerges.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-risico","legacy_id":"raip:definition:definitie-risico","type":"definition","slug":"definitie-risico","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"367cbb58e793aeabc5e16e675d752f5d1d4e20ec3f1a1e7f088983c7f5a9d467","label":"Risk","summary":"Risk is the combination of the probability of harm occurring and the severity of that harm. It is the unit of measurement underpinning the entire regulation, from prohibited practices to the Article 9 risk management system.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(2) defines risk as the combination of the probability of an occurrence of harm and the severity of that harm.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition looks trivial but decides who is right in a dispute. Many organisations assess AI risk as the chance of a technical failure, whereas the regulation looks at harm to people's health, safety and fundamental rights. A model that rarely fails but that, when it does, wrongly excludes someone from a job or a benefit scores high in AI Act terms, not low. Without separately substantiating probability and severity, you have an opinion rather than a risk assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI application, record in your register what harm you foresee, to whom, how likely you consider it, how severe the consequence is, and the source of that estimate. Use one fixed scale for probability and severity across all applications so scores are comparable and you can show the classification was not ad hoc.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-substantiele-wijziging","legacy_id":"raip:definition:definitie-substantiele-wijziging","type":"definition","slug":"definitie-substantiele-wijziging","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1695d1dc88c1730de688ee4975230bf449ed94ea90a06e6ce04434b17759537d","label":"Substantial modification","summary":"A change to an AI system after it has been placed on the market or put into service that the provider did not foresee in the initial conformity assessment, and that affects compliance with Chapter III, Section 2 or changes the intended purpose.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(23) defines substantial modification as a change to an AI system after its placing on the market or putting into service which was not foreseen or planned by the provider in the initial conformity assessment and as a result of which compliance with the requirements set out in Chapter III, Section 2 is affected, or which results in a modification of the intended purpose for which the AI system was assessed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition decides when you must reassess, and it contains an escape route that is often missed: changes the provider foresaw and planned in the conformity assessment are not substantial modifications. A system that keeps learning within predefined boundaries therefore falls outside it in principle, while a model you retrain on a new population or repurpose does not. Note also the link with Article 25: if you change the intended purpose, you as deployer can become the provider. The legal term is substantial modification, not material change.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep a change log per AI system with the date, nature of the change, the reason, and the assessment of whether it is a substantial modification, including who determined that. Agree with your provider in advance which changes were already foreseen in the conformity assessment, so you do not have to argue afterwards about whether reassessment was required.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(23)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-categorisering","legacy_id":"raip:definition:definitie-systeem-voor-biometrische-categorisering","type":"definition","slug":"definitie-systeem-voor-biometrische-categorisering","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fbcbc185dd0893403d5dd704758abe9fa3be327d9869bfb1ee5af1f03e17eb86","label":"Biometric categorisation system","summary":"An AI system that assigns people to categories on the basis of their biometric data. The carve-out for functions ancillary to another commercial service is narrow and is routinely read far too broadly in practice.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(40) defines a biometric categorisation system as an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Categorising is not the same as identifying: you are not establishing who someone is, you are attaching a label. That does not make it harmless. Sorting people by sensitive attributes such as race, political opinion, trade union membership, religion or sexual orientation has been prohibited under Article 5 since 2 February 2025, and since 2 August 2026 Article 50(3) requires you to inform the people the system is applied to. The carve-out only applies where the categorisation is strictly necessary on technical grounds for another service, for example an image filter that has to locate facial features. Commercial convenience is not technical necessity.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record for each system which categories it assigns, which biometric features it uses and for what purpose. If you rely on the carve-out, document the technical necessity in the system description, and build the Article 50(3) information duty into your user-facing notices.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(40)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-identificatie-op-afstand","legacy_id":"raip:definition:definitie-systeem-voor-biometrische-identificatie-op-afstand","type":"definition","slug":"definitie-systeem-voor-biometrische-identificatie-op-afstand","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7c72e1b3c6b064394fd0d86cfbe44bc02d19b83bb6de7e8bc5b790de3ed19eb7","label":"Remote biometric identification system","summary":"An AI system that identifies people without their active involvement, typically at a distance, by comparing them against a reference database. The decisive words are \"active involvement\".","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(41) defines a remote biometric identification system as an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance, through the comparison of a person's biometric data with the biometric data contained in a reference database.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The hinge is whether the person actively participates. An employee placing a finger on a reader or presenting their face to gain entry is actively involved: that is biometric verification within the meaning of point 36, not remote identification. A camera that silently matches passers-by against a database does fall within scope, and such systems are high-risk under Annex III, point 1 in any event, with all attendant obligations from 2 December 2027. Vendors often sell this as \"smart access control\", while the reference database and the absence of cooperation are what actually decide the classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every camera or biometric system, establish and document two things: is there a reference database behind it, and does the person actively cooperate. Those two answers determine whether you land in Annex III and whether the Article 5 prohibition comes into play.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(41)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeem-voor-monitoring-na-in-de-handel-brengen","legacy_id":"raip:definition:definitie-systeem-voor-monitoring-na-in-de-handel-brengen","type":"definition","slug":"definitie-systeem-voor-monitoring-na-in-de-handel-brengen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"52b7a3c34b19d54d31fb01524d1d71983825954390b43016beb44963a8cad530","label":"Post-market monitoring system","summary":"The set of activities through which a provider keeps following how its AI system behaves in practice after launch, so it can intervene in time. Conformity is a starting point, not an end point.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(25) defines this as all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service, for the purpose of identifying any need to immediately apply necessary corrective or preventive actions.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is where organisations consistently slip: they treat the conformity assessment as the finish line and organise nothing afterwards. The definition instead establishes a continuous obligation covering the entire lifetime of the system, elaborated in Article 72 into a mandatory monitoring plan. It is not about waiting passively for a complaint, but about actively collecting and reviewing. For high-risk systems this bites from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), but the monitoring system must be designed in from the start, since otherwise you have no historical data to demonstrate drift or degradation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI system which signals you collect (complaints, support tickets, anomalous outcomes, performance measurements over time), who reviews them, at what frequency, and which threshold triggers a corrective action or a serious incident report. Keep the review records with date and model version, so you can later show that you did not start measuring only after an incident.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(25)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-systeemrisico","legacy_id":"raip:definition:definitie-systeemrisico","type":"definition","slug":"definitie-systeemrisico","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c8c6caf33ae18fc4a6b0088d737650a27551b660acde096bddbd180a4584802f","label":"Systemic risk","summary":"A concept that applies exclusively to GPAI models, and that is unrelated to the high-risk classification of AI systems.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(65) defines systemic risk as a risk specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society as a whole, that can be propagated at scale across the value chain. Point 64 defines high-impact capabilities as capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. Article 51(2) provides that a model is presumed to have such capabilities when the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10 to the power of 25.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Systemic risk is often used in conversation as a synonym for high risk, and sometimes, borrowed from the financial sector, as a synonym for systemic importance. Both are wrong. Under this Regulation systemic risk is exclusively a qualification of a general-purpose AI model, never of an AI system and never of an organisation. A second misconception is that the threshold of 10 to the power of 25 floating point operations is the definition. It is not: that threshold sits in Article 51(2) and operates as a presumption, while under Article 51(1)(b) the Commission may also classify a model, on its own initiative or following a qualified alert from the scientific panel, where it has capabilities or an impact equivalent to those in point (a), having regard to the criteria in Annex XIII. For virtually every organisation this concept concerns their supplier rather than themselves; the relevant question is then which model you use and what the provider documents about it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per AI application which underlying GPAI model is used and whether the provider designates that model as one with systemic risk, and keep the documentation or model card on which you base that. Use this information in supplier conversations rather than as your own classification, because the qualification belongs to the model provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(64)-(65), Article 51(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-terugroepen-ai-systeem","legacy_id":"raip:definition:definitie-terugroepen-ai-systeem","type":"definition","slug":"definitie-terugroepen-ai-systeem","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f4d2c87792a00e0b1002f3ada4386e8240f9778baefb9b8461ef4e671bd0cd89","label":"Recall of an AI system","summary":"A measure aimed at returning an AI system to the provider, taking it out of service, or disabling its use, where that system has already been made available to deployers. A recall reaches systems already in use.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(16) defines recall of an AI system as any measure aiming to achieve the return to the provider, the taking out of service, or the disabling of the use of an AI system made available to deployers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The difference from withdrawal is the point in the chain. A recall reaches the customer already running the system, while withdrawal only stops what has not yet been delivered. For software a recall is rarely physical: it is a disabled feature, a revoked licence key or a blocked API. Organisations underestimate that a provider may be required under Article 20 to recall a system you depend on operationally, so you need to know today what you will do if a core system is switched off tomorrow.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each AI system, record who at the provider can announce a recall, through which channel you will receive that notice, and what fallback you have if the system becomes unusable immediately. Put these arrangements in the contract and test at least annually that the notification channel works.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(16)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testdata","legacy_id":"raip:definition:definitie-testdata","type":"definition","slug":"definitie-testdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"391375ba99e7c076813061d93db1fcfa0ac49f2c5e52448359b0abf0830367e7","label":"Testing data","summary":"Data for an independent evaluation confirming expected performance, which must take place beforehand: before the system is placed on the market or put into service.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(32) defines testing data as data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Two words carry this definition: independent and before. Independent means the testing data must not have been used in training or tuning; the moment you go back and adjust the model based on the test results, your test set is contaminated and you need a new one. Before means the confirmation happens in advance, not as a reconstruction after a supervisor asks. In practice this fails most often with continuously updated systems: every substantial modification calls for a fresh independent confirmation, not a reference to last year's measurement. For high-risk systems this bites from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the test set sealed off and separated from the development team, and record the measurement results per relevant subgroup, with date, model version and the metric used. Tie every substantial modification to a fresh testing round and note who performed the evaluation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(32)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testen-onder-reele-omstandigheden","legacy_id":"raip:definition:definitie-testen-onder-reele-omstandigheden","type":"definition","slug":"definitie-testen-onder-reele-omstandigheden","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"462eb93f173779fad096bb2f06a0467b6764a8920030b4912a1c59c601205c7e","label":"Testing in real-world conditions","summary":"Temporarily testing an AI system for its intended purpose outside the lab, in order to gather reliable data and assess conformity. It does not count as placing on the market or putting into service, provided you meet all conditions of Article 57 or 60.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(57) defines testing in real-world conditions as the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation; it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The exception stands or falls on the word provided. If you do not meet all conditions of Article 57 or 60, your test is no longer a test but a putting into service, with all the obligations that entails and an enforcement exposure you did not see coming. In practice this shows up in pilots that quietly continue, tests that are extended to more users or sites, and systems that simply stay in production after the pilot period. Temporary means temporary.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each test, record the start and end dates, the intended purpose being tested, the legal basis in Article 57 or 60, and an explicit decision point at the end: stop, extend under the same conditions, or move to putting into service with the full set of obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(57)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-testomgevingsplan","legacy_id":"raip:definition:definitie-testomgevingsplan","type":"definition","slug":"definitie-testomgevingsplan","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"d58656e46ce10c410330e0fd13609d719fc0d554b8e33dcf30b9fd4096513081","label":"Sandbox plan","summary":"The agreement between you and the supervisory authority about what you will do in an AI regulatory sandbox: objectives, conditions, timeframe, methodology and requirements. It is a two-sided document, not an internal plan.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(54) defines a sandbox plan as a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The distinction from point 53 is often missed. The real-world testing plan is your own test design; the sandbox plan is a document agreed with the competent authority. That means you cannot change it unilaterally, and departing from the agreed conditions affects your participation in the sandbox. It is also the document with which you can later demonstrate that the supervisor knew what you were doing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Keep the signed or confirmed sandbox plan under version control and record every change together with the competent authority's agreement. Record in your file which activities fell within the agreed scope and which were kept outside it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(54)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-trainingsdata","legacy_id":"raip:definition:definitie-trainingsdata","type":"definition","slug":"definitie-trainingsdata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ef859e4087e8a7ceaa231ae837f6477f14ad93fb7a3b9faf98497d7b8313abe9","label":"Training data","summary":"Data used to fit the learnable parameters of an AI system. Narrowly defined, and precisely for that reason decisive for who carries which data governance obligation.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(29) defines training data as data used for training an AI system through fitting its learnable parameters.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition is deliberately technical: it covers only data that actually fit the learnable parameters. Data you pass in a prompt or place in a retrieval index are not training data, and that distinction determines whether Article 10 on data governance applies to you. Where it goes wrong: organisations that fine-tune an existing model with their own data assume they remain mere users, while they are fitting learnable parameters and quickly become a downstream provider with documentation obligations of their own. For general-purpose AI models there is additionally the public summary of training content under Article 53, applicable since 2 August 2025 and enforceable since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per data set its origin, the basis on which you may use it, the period over which it was collected, which processing steps were applied, and which known limitations or skews it contains. Keep training data administratively separate from validation and testing data, and explicitly log every occasion on which you fine-tune an external model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(29)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-uit-de-handel-nemen","legacy_id":"raip:definition:definitie-uit-de-handel-nemen","type":"definition","slug":"definitie-uit-de-handel-nemen","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2482d5e315cec62e5648d6abd0385eecdee52a794798bc48f2f6a506ee223348","label":"Withdrawal of an AI system","summary":"A measure aimed at preventing an AI system that is in the supply chain from being made available on the market. It stops distribution, not use by existing customers.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(17) defines withdrawal of an AI system as any measure aiming to prevent an AI system in the supply chain being made available on the market.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the lighter counterpart to a recall and is frequently confused with it, including in contracts. Withdrawal only affects units still in the chain at importers and distributors. Anyone already using the system notices nothing until a recall follows. For your own procurement the practical question is whether a supplier that withdraws its product still delivers updates, patches and support, or whether you are left with a system that is commercially dead but operationally live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include in procurement contracts that the provider informs you as soon as it withdraws an AI system, even if you already use it, and record which maintenance and security updates you will still receive afterwards and for how long.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(17)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-validatiedata","legacy_id":"raip:definition:definitie-validatiedata","type":"definition","slug":"definitie-validatiedata","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4771ce3b2faa0f52b26fd42f2d915c301b392c7f3d128ff560c4183e2a98868c","label":"Validation data","summary":"Data with which you evaluate and tune the trained system, including its non-learnable parameters, to prevent underfitting and overfitting. Meant for tuning, not for producing the final score.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(30) defines validation data as data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The legislator deliberately separated validation from testing, because the classic error is using the same data both for tuning hyperparameters and for reporting final performance. You then measure your own choices back and overstate accuracy, while Article 15 requires a realistic level of accuracy that is stated in the instructions for use. In supervisory conversations this is one of the first things that stands out: an impressive accuracy figure without a separate, untouched test set.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record which tuning decisions were made on validation data, how many evaluation rounds took place and which configuration was ultimately chosen. Ensure the validation data are never used for the figure you cite in the instructions for use and the technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(30)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-validatiedataset","legacy_id":"raip:definition:definitie-validatiedataset","type":"definition","slug":"definitie-validatiedataset","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b7e609baae36b231e16a3fdde9d8681deb4529b66c942984c2c7793877d13b1b","label":"Validation data set","summary":"The form validation data may take: a separate data set or part of the training data set, as a fixed or variable split. The law leaves the method open, but not the explainability.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(31) defines a validation data set as a separate data set or part of the training data set, either as a fixed or variable split.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This definition looks redundant but settles a concrete argument: may you use cross-validation instead of a fixed holdout. The answer is yes, because a variable split is expressly allowed. The flip side is that the burden shifts to reproducibility. If your split changes per run and you do not record the splitting rule, you cannot afterwards show that your reported performance is not the result of a lucky split. For data sets with a time ordering or with heavily represented subgroups, a random split is moreover misleading, while Article 10 specifically demands representativeness.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record in the technical documentation which split you use, whether it is fixed or variable, which splitting rule or seed applies, and why that split suits the nature of the data. Keep this per model version, so a later retest is reproducible.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(31)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-veiligheidscomponent","legacy_id":"raip:definition:definitie-veiligheidscomponent","type":"definition","slug":"definitie-veiligheidscomponent","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"82b2bd6ae24f5ede7ef37bd40b03e99e2024a962e24dd7cbb7f7676595fe8e63","label":"Safety component","summary":"One of the two routes into the high-risk classification of Article 6(1), and often overlooked outside manufacturing.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(14) defines a safety component as a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The definition contains two independent tests joined by an or, and the second is almost always forgotten. A component need not have an identifiable safety function: it is enough that its failure or malfunctioning endangers the health and safety of persons or property. Property counts too, not only injury. The second misconception is that this concept only matters for machinery and medical devices. It is the gateway to Article 6(1), and therefore to the high-risk route via Annex I, which becomes applicable on 2 August 2028 for AI embedded in regulated products. Being a safety component is not sufficient in itself. Article 6(1) sets two cumulative conditions: alongside point (a), point (b) requires that the product, or the AI system as a product, must undergo third-party conformity assessment under the Annex I Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Run both tests separately for each AI system and record both answers: does it fulfil a safety function, and what happens on failure or malfunctioning. Involve the product safety specialist or the product manufacturer, because that assessment belongs alongside the existing product conformity assessment and not in a separate AI track.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2025-02-02T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-wijdverbreide-inbreuk","legacy_id":"raip:definition:definitie-wijdverbreide-inbreuk","type":"definition","slug":"definitie-wijdverbreide-inbreuk","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bb625a0755e50f4c81ec2042b0840b7bce5cdc560ecfb5dc8348f5234e15ac05","label":"Widespread infringement","summary":"An act or omission contrary to Union law protecting the interests of individuals that harms the collective interests of persons in at least two other Member States, or that, with common features, occurs concurrently and is committed by the same operator in at least three Member States.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(61) defines a widespread infringement as any act or omission contrary to Union law protecting the interest of individuals which: (a) has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which (i) the act or omission originated or took place, (ii) the provider concerned or, where applicable, its authorised representative is located or established, or (iii) the deployer is established, where the infringement is committed by the deployer; or (b) has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This concept does not determine what is prohibited but how supervision is organised. Once a shortcoming in your AI system plays out the same way in several Member States, it stops being a series of separate national files and becomes one coordinated enforcement track. That is exactly the exposure of standardised software: one setting, one model or one flaw in the logic hits everywhere at once and therefore almost automatically meets the common features criterion. Note that the second limb expressly refers to the same operator, which brings deployers into scope and not only providers.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Map the Member States in which the same AI system or configuration is used and track which incidents and complaints share the same root cause across borders. Ensure that a correction made in one country is demonstrably rolled out in the others as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(61)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:definition:definitie-zwevendekommabewerking-flop","legacy_id":"raip:definition:definitie-zwevendekommabewerking-flop","type":"definition","slug":"definitie-zwevendekommabewerking-flop","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"19fb0acd8e5e74b53182b1168df1505c0d7447ea4958d578708685882580b049","label":"Floating-point operation (FLOP)","summary":"Any mathematical operation or assignment involving floating-point numbers. This is the unit of computation with which the Regulation measures the scale of training of a general-purpose AI model.","topics":["definitions"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 3(67) defines a floating-point operation as any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A technical definition with legal bite: FLOP is the yardstick for determining whether a general-purpose AI model is presumed to have high-impact capabilities and therefore systemic risk, using the cumulative training compute threshold in Article 51. That turns an engineering number into a compliance fact. In practice the problem is record keeping: many organisations can no longer establish afterwards how much compute went into training, while that very figure determines which regime applies and whether notification to the Commission is required.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every model you train or significantly further train, record the cumulative amount of compute in FLOP, the measurement method and the hardware used, and keep that record with the model's technical documentation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(67)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2024-08-01T00:00:00.000Z","links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 3 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"}]},"links":{"self":"https://www.praxikon.com/api/v1/entities?lang=en&type=definition","alternate":"https://www.praxikon.com/api/v1/entities?lang=en&type=definition&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}