{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":54,"filters":{"id":null,"type":"obligation","role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:obligation:annex-iii-eight-areas","legacy_id":"raip:obligation:annex-iii-eight-areas","type":"obligation","slug":"annex-iii-eight-areas","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6","label":"Annex III: the eight areas separately","summary":"Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open here is not the text but the boundary and the form. The eight points are reproduced verbatim, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Publishing the points as separate objects is also our choice; the Regulation gives a list and not eight self-standing norms. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own. It also remains unclear how Article 6(3) works out per area: the exception is drafted in general terms, but the profiling proviso bites in almost every case in one area and rarely in another. Finally, we have checked that Regulation (EU) 2026/1744 inserts Article 6(1a) to (1c) without renumbering or amending paragraphs 2 and 3; if that changes, the route in this object changes with it.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:map-system-to-annex-iii-area"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text"],"conditions":[{"id":"annex-iii-eight-areas-intended-purpose","operator":"any","description":"Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes."},{"id":"annex-iii-eight-areas-route","operator":"all","description":"Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order."},{"id":"annex-iii-eight-areas-article-25-role-shift","operator":"any","description":"The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself."}],"exceptions":[{"id":"annex-iii-eight-areas-article-6-3-derogation","operator":"not","description":"Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk."},{"id":"annex-iii-eight-areas-article-6-4-documentation","operator":"all","description":"The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request."}],"statements":[{"kind":"official_fact","text":"The introductory sentence of Annex III reads: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas. Eight numbered areas follow. 1. Biometrics, in so far as their use is permitted under relevant Union or national law. 2. Critical infrastructure. 3. Education and vocational training. 4. Employment, workers’ management and access to self-employment. 5. Access to and enjoyment of essential private services and essential public services and benefits. 6. Law enforcement, in so far as their use is permitted under relevant Union or national law. 7. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law. 8. Administration of justice and democratic processes. The full text of each point, with its lettered subpoints, sits on the object for that area.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex III is not fixed. Article 7(1) empowers the Commission to add or amend use cases in Annex III by delegated act, and Article 7(3) to remove them. Article 7(1)(a) requires the system to be intended for use in one of the areas listed in Annex III. The eight areas are therefore the stable layer; the lettered subpoints inside them can change without the Regulation itself being revised.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 7(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Seven of the eight areas are subdivided into lettered subpoints in the text: point 1 into (a) to (c), point 3 into (a) to (d), point 4 into (a) and (b), point 5 into (a) to (d), point 6 into (a) to (e), point 7 into (a) to (d) and point 8 into (a) and (b). Point 2 has no lettered subpoints. We therefore count twenty-four lettered subpoints across seven areas. That number appears nowhere in the Regulation: it is our count of the text as it stands at our knowledge date, and a delegated act under Article 7 can silently make it stale.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Reading Annex III as one block leads to the wrong question. The question is not whether your organisation works in one of the eight areas, because nearly everyone does: a hospital touches point 5, a school point 3, and every employer point 4. The question is whether the intended purpose of this one system coincides with the description of a lettered subpoint. A CV parser that only deduplicates repeat applications does something other than a system that evaluates candidates, and yet both get filed under recruitment in practice. Note the order too. Points 1, 6 and 7 carry the condition that the use must be permitted, and that is where Article 5 comes first. Emotion recognition in the workplace and in education is prohibited under Article 5(1)(f), except where the system is placed on the market or put into service for medical or safety reasons; whoever reverses that builds a conformity file for something that is not allowed. Finally, the area also determines which duties then weigh heavily. Article 86 gives a right to an explanation for decisions based on any system listed in Annex III other than point 2, and Article 27 requires bodies governed by public law and private providers of public services to carry out a fundamental rights impact assessment on every Annex III route other than point 2, with point 5(b) and (c) extending that duty to any deployer. For systems already on the market before the application date, the separate transitional rule of Article 111(2) applies as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system, record in your register not that it falls under Annex III but which point and which lettered subpoint it touches, with the intended purpose in your own words alongside. The eight area objects sit in the graph under the slugs annex-iii-area-1-biometrics through annex-iii-area-8-justice-and-democratic-processes; refer to those rather than to Annex III as a whole. Add four fields: is the use permitted, and if not, why is Article 5 not engaged; has the Article 6(3) test been carried out, which of the four conditions was met, and has the assessment been documented and the system registered under Article 6(4) and Article 49(2); does the system perform profiling, because the exception then falls away; and who carries the provider role after Article 25. Repeat that record on every change to the intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"related","href":"https://www.praxikon.com/nl/annex-iii","label":"The eight areas on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:annex-iii-high-risk","legacy_id":"raip:obligation:annex-iii-high-risk","type":"obligation","slug":"annex-iii-high-risk","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c0afd1789ed393ba3f9ce04205bd74b4831ff0fd58146108fdd8dd08d2f4f6c9","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-change-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-classifier"],"conditions":[{"id":"annex-iii-listed-purpose","operator":"all","description":"The intended purpose falls within a use case listed in Annex III."},{"id":"article-6-2-route","operator":"all","description":"Classification follows Article 6(2)."}],"exceptions":[{"id":"article-6-3-exception","operator":"not","description":"A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented."}],"statements":[{"kind":"official_fact","text":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-10-data-governance","legacy_id":"raip:obligation:article-10-data-governance","type":"obligation","slug":"article-10-data-governance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b6992c5a6d684dd828c8b00a7239e768eee9d4a5cb4fdbc4fbaee3dbf561d91","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-10-data-governance-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-10-data-governance-record"],"control_ids":["praxikon:eu:ai-act:control:article-10-data-governance-control"],"template_ids":["praxikon:eu:ai-act:template:article-10-data-governance-legal-text"],"conditions":[{"id":"article-10-data-governance-scope","operator":"all","description":"The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data."}],"exceptions":[{"id":"article-10-data-governance-exception","operator":"not","description":"For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions)."}],"statements":[{"kind":"official_fact","text":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-11-technical-documentation","legacy_id":"raip:obligation:article-11-technical-documentation","type":"obligation","slug":"article-11-technical-documentation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15571dc37c23ef11a79a3b7b9b7d5674ee4fc7161cc4a9bb8f62321f66294a2c","label":"Article 11: technical documentation","summary":"The technical file demonstrating before market placement that a high-risk system meets the requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-11-technical-documentation-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-11-technical-documentation-record"],"control_ids":["praxikon:eu:ai-act:control:article-11-technical-documentation-control"],"template_ids":["praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text"],"conditions":[{"id":"article-11-technical-documentation-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-11-technical-documentation-exception","operator":"not","description":"Small providers (SMEs) may provide the documentation in the simplified form established by the Commission."}],"statements":[{"kind":"official_fact","text":"Article 11 requires technical documentation drawn up before market placement, kept up to date and containing the Annex IV elements, so that compliance with Section 2 is demonstrable to supervisors.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buying organisations, Annex IV is the checklist of what you must be able to request contractually from your supplier; without that file you cannot meet your own Article 26 duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the right to access the technical documentation in AI procurement and supplier contracts now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-11-technical-documentation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 11 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-111-legacy-public-systems","legacy_id":"raip:obligation:article-111-legacy-public-systems","type":"obligation","slug":"article-111-legacy-public-systems","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4","label":"Article 111(2): legacy high-risk systems and the 2 August 2030 date","summary":"High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The text above is the consolidated text and has been checked against the Official Journal; what is preliminary is our reading of it. First, the cut off date. The amended paragraph 2 refers not to a date but to the date of application of Chapter III referred to in Article 113, and since the Digital Omnibus Article 113, third paragraph, point (c) gives two: 2 December 2027 for Annex III and 2 August 2028 for Annex I. We therefore read the cut off as route dependent. A defensible alternative reading is that the reference points at the general application date of Chapter III as a whole, that is 2 August 2026, because Sections 4 and 5 of that Chapter were not deferred; on that reading the cut off would effectively still be 2 August 2026. We follow the route dependent reading because point (c) expressly names Sections 1, 2 and 3, and those are the Sections carrying the requirements the grace period exists for. Second, the notion of a significant change in the design. That is not the same wording as the defined substantial modification used elsewhere in the Regulation, and there is no guidance or case law saying whether a model update, a retraining run or a new data source counts. We read it as a change that touches the intended purpose, the functioning or the risk profile, and not as every release. Third, the reach of intended to be used by public authorities. It is unclear whether a system supplied to both public and private customers falls under it in full, and whether a private party carrying out a public task is a public authority. We read the intention as following from the market the system is offered for and not from the legal form of the individual customer.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends","praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable"],"action_ids":["praxikon:eu:ai-act:action:assess-significant-design-change","praxikon:eu:ai-act:action:plan-legacy-public-system-compliance"],"evidence_ids":["praxikon:eu:ai-act:evidence:legacy-system-transition-register"],"control_ids":["praxikon:eu:ai-act:control:design-change-review-gate"],"template_ids":["praxikon:eu:ai-act:template:article-111-legal-text"],"conditions":[{"id":"article-111-2-scope-article-5-unaffected","operator":"all","description":"The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed."},{"id":"article-111-2-scope-limited-to-chapter-iii","operator":"all","description":"The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them."},{"id":"article-111-2-legacy-scope","operator":"all","description":"Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date."},{"id":"article-111-2-type-and-model","operator":"all","description":"The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union."},{"id":"article-111-2-public-authority-deadline","operator":"all","description":"Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged."}],"exceptions":[{"id":"article-111-2-exception-annex-x-systems","operator":"not","description":"Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030."}],"statements":[{"kind":"official_fact","text":"Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The grace period in paragraph 2 applies where the type and model of an AI system has already been placed on the market. If at least one individual unit was lawfully placed on the market or put into service before the cut off date, the grace period also covers other units of the same type and model, which may be offered without additional obligations, requirements or mandatory additional certification, as long as the design remains unchanged. On a significant change to the design after the cut off date the provider must fully comply with all relevant provisions applicable to high-risk AI systems, including the conformity assessment requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this provision is read exactly the wrong way round. Executives hear that existing systems are left alone and conclude that nothing is needed until well into the 2030s. That is wrong in two ways. For a public sector organisation the second sentence gives no escape but a deadline, and it applies whether or not you change anything about the system. And for everyone the transitional rule concerns only the high-risk requirements: Article 4 has been running since February 2025 and Article 50 since August 2026, with legacy generative systems having only until 2 December 2026 to get the machine-readable marking of Article 50(2) in order. The first sentence, moreover, is not a resting place but a switch. As soon as the design is significantly changed you must comply fully with what applies to high-risk systems, the conformity assessment first of all; those duties do follow the shifted calendar of 2 December 2027 and 2 August 2028. That switching moment rarely arises at a time you choose: it arises on a supplier update, a migration or a new data source. Two things therefore matter more than the date itself. You need to know when the first unit of each type and model reached the market, because that is the decisive date and without it you cannot later show which track a system was on. And you need a moment in your change process at which someone assesses whether a change is significant, before it goes live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per type and model of your high-risk AI systems when the first unit was placed on the market or put into service, and whether the system is intended to be used by public authorities. Record that determination with a date and a reasoning, and note which route applies, because that decides whether your cut off is 2 December 2027 or 2 August 2028. For the systems intended for public authority use, set a plan towards 2 August 2030 that counts back from the conformity assessment and the registration, not from the end date. Also build into your change and release process a review moment at which someone records whether an intended design change is significant, before the change goes into production. Separately, check whether Article 111(4) catches you: if so you have until 2 December 2026 for the marking under Article 50(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-12-logging","legacy_id":"raip:obligation:article-12-logging","type":"obligation","slug":"article-12-logging","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"92daf8448d3471e5014ea66a2dc2731909f2689e5e3bdb243f49a75572002f20","label":"Article 12: logging and traceability","summary":"Automatic recording of events over the lifetime of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-12-logging-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-12-logging-record"],"control_ids":["praxikon:eu:ai-act:control:article-12-logging-control"],"template_ids":["praxikon:eu:ai-act:template:article-12-logging-legal-text"],"conditions":[{"id":"article-12-logging-scope","operator":"all","description":"The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control."}],"exceptions":[{"id":"article-12-logging-exception","operator":"not","description":"The retention period may be limited by Union or national law, including data protection."}],"statements":[{"kind":"official_fact","text":"Article 12 requires high-risk AI systems to be technically capable of automatically recording events over their lifetime, for traceability, risk signalling and post-market monitoring; Article 19 and Article 26(6) govern log retention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Logging is the backbone of all other evidence: without logs an incident cannot be reconstructed and a monitoring duty cannot be fulfilled. Buyers should already test whether a system is technically capable of this.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include logging capability and log access as a requirement in every AI purchase and assign the retention regime (who, where, how long) per system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-12-logging","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 12 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-13-instructions","legacy_id":"raip:obligation:article-13-instructions","type":"obligation","slug":"article-13-instructions","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"818266e8912de0d2c95a38a4a16c67b1aad02d10359b3571710fd757c678819b","label":"Article 13: transparency towards deployers","summary":"Comprehensible instructions for use and system information so deployers can operate the system correctly.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-13-instructions-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-13-instructions-record"],"control_ids":["praxikon:eu:ai-act:control:article-13-instructions-control"],"template_ids":["praxikon:eu:ai-act:template:article-13-instructions-legal-text"],"conditions":[{"id":"article-13-instructions-scope","operator":"all","description":"The provider supplies a high-risk system; the deployer uses it according to the instructions."}],"exceptions":[{"id":"article-13-instructions-exception","operator":"not","description":"The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed."}],"statements":[{"kind":"official_fact","text":"Article 13 requires high-risk systems to be designed transparently enough for deployers to interpret and use the output, with instructions covering purpose, accuracy, limitations, human oversight and maintenance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The instructions are the hinge between provider and deployer duties: what the provider fails to supply here, the deployer cannot deliver under Article 26. Ask for it explicitly at procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Translate received instructions per system into internal work instructions per role and record who received them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-13-instructions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 13 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-14-human-oversight","legacy_id":"raip:obligation:article-14-human-oversight","type":"obligation","slug":"article-14-human-oversight","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"02da6ce26c5036d2cdea0842564e14a1227cd8f8e5fe5e67e15b52cd5332f98b","label":"Article 14: human oversight","summary":"High-risk AI must be designed so that humans can effectively oversee it and intervene.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-14-human-oversight-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-14-human-oversight-record"],"control_ids":["praxikon:eu:ai-act:control:article-14-human-oversight-control"],"template_ids":["praxikon:eu:ai-act:template:article-14-human-oversight-legal-text"],"conditions":[{"id":"article-14-human-oversight-scope","operator":"all","description":"The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons."}],"exceptions":[{"id":"article-14-human-oversight-exception","operator":"not","description":"For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there."}],"statements":[{"kind":"official_fact","text":"Article 14 requires high-risk systems to be effectively overseeable by natural persons, with measures enabling them to understand the system, correctly interpret output, remain aware of automation bias, and decide not to use, to disregard or to stop the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Oversight on paper is not oversight: the law names automation bias explicitly, so a human who may only click through does not count. Effective oversight requires understanding, time and mandate, which ties directly into the Article 4 literacy measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Appoint the overseeing persons per (upcoming) high-risk system now, train them specifically and record their mandate to intervene in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-14-human-oversight","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 14 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-15-accuracy-robustness","legacy_id":"raip:obligation:article-15-accuracy-robustness","type":"obligation","slug":"article-15-accuracy-robustness","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"96fcf15ac99ca507169f462e66eaebb72ab06b66e3754b0cf69a69347ed4dc6d","label":"Article 15: accuracy, robustness and cybersecurity","summary":"Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-15-accuracy-robustness-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record"],"control_ids":["praxikon:eu:ai-act:control:article-15-accuracy-robustness-control"],"template_ids":["praxikon:eu:ai-act:template:article-15-accuracy-robustness-legal-text"],"conditions":[{"id":"article-15-accuracy-robustness-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-15-accuracy-robustness-exception","operator":"not","description":"Systems that continue learning after deployment carry additional requirements to control feedback loops and drift."}],"statements":[{"kind":"official_fact","text":"Article 15 requires high-risk systems to achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the lifecycle, including resilience against errors and AI-specific attacks such as data poisoning and adversarial examples.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Accuracy here is not a marketing number but a declared, testable value stated in the instructions for use and held against you in production.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Ask suppliers now for declared accuracy levels and test reports, and set up production monitoring against those levels.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 15(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-15-accuracy-robustness","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 15 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-16-provider-obligations","legacy_id":"raip:obligation:article-16-provider-obligations","type":"obligation","slug":"article-16-provider-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275","label":"Article 16: the twelve duties of a provider of a high-risk AI system","summary":"Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:assign-article-16-provider-duties"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-16-provider-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-16-pre-market-release-gate"],"template_ids":["praxikon:eu:ai-act:template:article-16-provider-obligations-legal-text"],"conditions":[{"id":"article-16-provider-obligations-scope","operator":"all","description":"Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-16-provider-obligations-exception","operator":"not","description":"A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph)."}],"statements":[{"kind":"official_fact","text":"Article 16 requires providers of high-risk AI systems to do twelve things. They must ensure their systems comply with the requirements of Chapter III, Section 2 (point (a)); indicate on the system or, where that is not possible, on its packaging or accompanying documentation, their name, registered trade name or registered trade mark and the address at which they can be contacted (point (b)); have a quality management system in place complying with Article 17 (point (c)); keep the documentation referred to in Article 18 (point (d)); keep the automatically generated logs referred to in Article 19 when under their control (point (e)); ensure the system undergoes the conformity assessment procedure referred to in Article 43 prior to being placed on the market or put into service (point (f)); draw up an EU declaration of conformity in accordance with Article 47 (point (g)); affix the CE marking in accordance with Article 48 (point (h)); comply with the registration obligations referred to in Article 49(1) (point (i)); take the necessary corrective actions and provide the information required under Article 20 (point (j)); upon a reasoned request of a national competent authority, demonstrate conformity with the requirements of Section 2 (point (k)); and ensure the system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 (point (l)).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 16 reads like a table of contents and is therefore often planned as a single roadmap line. It is twelve separate duties with widely differing lead times: building a quality management system takes months, affixing a CE marking takes a day. The bigger trap sits in Article 25(1): anyone who puts their own brand on an existing high-risk system, substantially modifies it, or changes the intended purpose of a non-high-risk system so that it becomes high-risk counts as a provider and inherits all twelve points without ever having built anything. In the branding scenario of point (a) this applies without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated, but you must have made and be able to show those arrangements in advance. In practice this catches parties that white-label AI or apply a general-purpose model to an Annex III use case.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First determine whether you are a provider or whether Article 25 makes you one, then work out the twelve points as twelve separate work packages with an owner and a date. Start with points (c) and (f), because they set the lead time of the whole track.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 16(a)-(l)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 16 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-17-quality-management","legacy_id":"raip:obligation:article-17-quality-management","type":"obligation","slug":"article-17-quality-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7d04f5f23729c5c48f26262f0e266c680dce5753d12543479b1ea672bbe1c6e9","label":"Article 17: quality management system","summary":"The documented quality system through which a high-risk AI provider structurally assures compliance.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-17-quality-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-17-quality-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-17-quality-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-17-quality-management-legal-text"],"conditions":[{"id":"article-17-quality-management-scope","operator":"all","description":"The provider places high-risk AI systems on the market or puts them into service."}],"exceptions":[{"id":"article-17-quality-management-exception","operator":"not","description":"Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form."}],"statements":[{"kind":"official_fact","text":"Article 17 requires a documented quality management system covering a compliance strategy, design and development procedures, data management, risk management, post-market monitoring, incident reporting and an accountability structure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The QMS is the umbrella over all other provider duties: those with the separate files but no system connecting them fail exactly this article in an audit.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build the QMS not as a separate document but as an index on top of the existing files (risk, data, documentation, monitoring) with owners per procedure.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-17-quality-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 17 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-18-document-retention","legacy_id":"raip:obligation:article-18-document-retention","type":"obligation","slug":"article-18-document-retention","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0971f35c7a7daaf1306f4fbd7ae98680b8b1e2da44b5a84a5abf7d7610cbdbfb","label":"Article 18: documentation keeping","summary":"The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:keep-high-risk-documentation-available"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-18-retention-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-18-retention-review"],"template_ids":["praxikon:eu:ai-act:template:article-18-legal-text"],"conditions":[{"id":"article-18-scope","operator":"all","description":"Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service."},{"id":"article-18-financial-institutions-regime","operator":"all","description":"Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e)."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the provider shall, for a period ending 10 years after the high-risk AI system has been placed on the market or put into service, keep at the disposal of the national competent authorities: (a) the technical documentation referred to in Article 11; (b) the documentation concerning the quality management system referred to in Article 17; (c) the documentation concerning the changes approved by notified bodies, where applicable; (d) the decisions and other documents issued by the notified bodies, where applicable; (e) the EU declaration of conformity referred to in Article 47. Paragraph 2 provides that each Member State shall determine conditions under which that documentation remains at the disposal of the national competent authorities for the period indicated for the cases when a provider or its authorised representative established on its territory goes bankrupt or ceases its activity prior to the end of that period. Paragraph 3 provides that providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law shall maintain the technical documentation as part of the documentation kept under the relevant Union financial services law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended application dates for Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), are 2 December 2027 for the standalone Annex III route and 2 August 2028 for high-risk AI in products covered by the Annex I harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Four things here are our reading and not the text. First the application date: Regulation (EU) 2026/1744 does not name Article 18 separately, so the fact that this duty moves with 2 December 2027 and 2 August 2028 follows from its placement in Chapter III, Section 3, and not from an explicit provision. Second the starting moment. Paragraph 1 names the placing on the market and the putting into service side by side without choosing, and for a system where both moments occur that is years of difference at the end of the period. Counting from the later moment is the only count that falls short under neither reading, and that is what we would advise a provider. The other reading is defensible: in Union product law the placing on the market is usually the moment that counts, and then the period ends earlier. Third a substantially modified version: the text is silent, and it is equally defensible that every version gets its own period as that the original one continues. Fourth the reach of paragraph 3: it names only the technical documentation, so we keep points (b) to (e) under the general regime until the contrary is settled. Paragraph 2, finally, is addressed to the Member State and not to you. The Netherlands has not yet determined those conditions, so what happens to your file on insolvency or cessation of activity currently follows from contract and not from law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Watch the boundaries of this duty, because they get crossed in both directions. The automatically generated logs are not among the five components: they fall under Article 19, with its own and much shorter period of at least six months, appropriate to the intended purpose, and with a clause for financial institutions that parallels paragraph 3. So do not stretch the ten years to your logs, and conversely do not settle for six months for your documentation. For a provider established in a third country the actual availability moreover sits with two parties at once: Article 22(3)(b) requires the authorised representative to keep, for ten years, the contact details of the provider, a copy of the EU declaration of conformity, the technical documentation and, if applicable, the certificate issued by the notified body at the disposal of the competent authorities and of the bodies referred to in Article 74(10). Two files that drift apart are worse than one. Point (e) overlaps with Article 47(1), which gives the declaration of conformity its own ten year period, and under Article 23(5) the importer carries ten years again for the certificate, the instructions for use and the declaration of conformity. That overlap is no reason to drop one of the periods: they are independent duties of different parties. It is a reason to choose a place of retention where they coincide. On the GDPR, finally: a retention duty under Union law is itself a ground under Article 6(1)(c) GDPR, and the storage limitation of Article 5(1)(e) permits retention that the law requires. The question is therefore not whether it is allowed but how far it reaches. Ten years applies to what Article 18(1) names, and not to everything created along the way: separate test sets, log samples and raw data dumps from the documentation you must be able to produce.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"This is the duty that asks nothing at the moment you take it on and everything at the moment you have forgotten it. Ten years is longer than the average life of a supplier contract, a document management system and a product team. In the organisations where we encounter this, the five components rarely sit in one archive: the quality system sits with compliance, the notified body decisions with certification, the declaration of conformity with legal. That is not law, but it is common enough that it is worth checking before you assume your situation is different. Whoever first assembles the documents when an authority asks discovers that retention in fact depended on a person and not on a process. Note also the side that is not about you: paragraph 2 concerns the situation where the provider or its representative goes bankrupt, and that is exactly the risk you run as a customer of a small supplier. It is a contracting question before it becomes a compliance question.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Designate per high-risk system one place of retention where the five components of paragraph 1 come together. Record side by side when the system was placed on the market and when it was put into service, and calculate the end date from the later of those two moments, so that you do not fall short under either reading. Set that end date as a commitment in a system that survives a change of staff, and keep the Article 19 logs separately with their own period. If you work with an authorised representative, record who holds which copy, because Article 22(3)(b) places the same availability on them as well. When procuring a high-risk system, put in the contract what happens to the documentation if the supplier stops or goes bankrupt, because paragraph 2 leaves that arrangement to national law that does not yet exist in the Netherlands.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 18(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-18-document-retention","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 18 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/18","label":"Read Article 18 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-20-corrective-actions","legacy_id":"raip:obligation:article-20-corrective-actions","type":"obligation","slug":"article-20-corrective-actions","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"3da4413e7f76d6cd26cf52cc894dc8b6637916ab4ed1d39776d4446a96c5232c","label":"Article 20: corrective actions and duty of information","summary":"A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.","topics":["high-risk-requirements","post-market"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-corrective-action-procedure"],"evidence_ids":["praxikon:eu:ai-act:evidence:corrective-action-record"],"control_ids":["praxikon:eu:ai-act:control:non-conformity-escalation-gate"],"template_ids":["praxikon:eu:ai-act:template:article-20-legal-text"],"conditions":[{"id":"article-20-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as they consider, or have reason to consider, that a system they have placed on the market or put into service is not in conformity with this Regulation. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028."},{"id":"article-20-risk-trigger","operator":"any","description":"The second layer in paragraph 2 is added only where the system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk. The investigation of causes and the duty to inform the market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44, then come on top of the corrective actions under paragraph 1."},{"id":"article-20-article-25-1-becoming-provider","operator":"any","description":"The distributor, the importer and the deployer appear here as affected parties, but that is not their only possible position. Anyone who puts their name or trade mark on a high-risk system already placed on the market, who substantially modifies such a system, or who changes the intended purpose of a system not classified as high-risk so that it becomes high-risk, is considered a provider under Article 25(1) and is subject to the obligations of Article 16. Point (j) of that Article routes straight to Article 20, so this provision then becomes a duty of their own rather than a notification arriving from someone else. In the trade mark case this applies without prejudice to contractual arrangements allocating the obligations otherwise."}],"exceptions":[{"id":"article-20-legacy-systems-article-111-2","operator":"not","description":"Article 20 is by definition about systems already placed on the market or put into service, and that is exactly the group covered by the transitional rule of Article 111(2). That provision was replaced by Article 1, point (39)(a), of Regulation (EU) 2026/1744 and now reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation applies to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The cut-off is therefore no longer a fixed date in paragraph 2: the date of 2 August 2026 that stood there until that amendment has been removed, and the amended paragraph names no date of its own. The carve-out in paragraph 1 covers systems that are components of the large-scale IT systems listed in Annex X; paragraph 1 was not amended and keeps a cut-off of its own. For systems intended to be used by public authorities the reprieve in paragraph 2 does not hold: there, compliance with the requirements and obligations is due by 2 August 2030 in any event. Which date of application of Chapter III is the cut-off is an open point: the object on Article 111 reads it as route dependent, so 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route, and marks that reading expressly as preliminary. That question is carried there, not here."}],"statements":[{"kind":"official_fact","text":"Paragraph 1. Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly. Paragraph 2. Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), of Regulation (EU) 2026/1744, replacing Article 113, third paragraph, point (c), of Regulation (EU) 2024/1689","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This provision is rarely read as a procedure, and that is exactly where it goes wrong. Article 20 places four measures side by side that differ sharply in practice, and those four are not legally equivalent. Recall and withdrawal are defined in Article 3(16) and (17), and the knowledge base carries those terms separately; the difference between them is the point in the chain. Bringing a system into conformity is the patch. Disabling is the odd one out: it is practically the heaviest switch, because it stops a customer who is running the system, and it is at the same time the only one of the four the Regulation nowhere defines. Anyone who copies that word into a contract or procedure without deciding for themselves what it means leaves the heaviest measure the vaguest. The second half is the notification, and in practice that is what fails most often. Paragraph 1 asks you to reach your distributors and, where applicable, your deployers, authorised representatives and importers, which is only possible if you hold a current list of who runs the system in which version and through which contact you reach them. That list is not a by-product of your CRM: resale, white labelling and integration mean you have customers you do not know.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 and Article 73 are often built as a single reporting channel, and that goes wrong in two ways. The trigger differs: Article 73 concerns a serious incident that has occurred, Article 20(2) a risk within the meaning of Article 79(1), that is, a risk to the health, safety or fundamental rights of persons. That is not a tidy split between past and future: a serious incident that has occurred usually also means the system presents a risk, so in practice both provisions often fire at the same time. Nor do the recipients differ entirely, because both routes run to market surveillance authorities. The difference sits in the detail: Article 73(1) points to the authorities of the Member States where the incident occurred, Article 20(2) to the authorities competent for the system concerned, and only Article 20(2) adds the notified body that issued a certificate under Article 44. Only Article 73, moreover, sets hard deadlines. So build one internal process with two exits, not two separate channels and not one channel that forgets the notified body.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two things within this duty are unsettled. First, what \"immediately\" requires: Article 20 sets no period. The closest anchor in the Regulation is Article 73(2), which ties \"immediately\" to the moment the provider has established a causal link between the system and the incident, or the reasonable likelihood of such a link, with an outer limit of fifteen days after becoming aware. We read Article 20 in that light: act once the signal is confirmed, and not only after a full internal investigation has been completed, because paragraph 2 places the investigation of causes alongside the measures rather than before them. A defensible alternative reading is that a provider first has reasonable time to verify and that \"immediately\" only starts running once the non-conformity is established. Second, the threshold \"reason to consider\": it is nowhere settled whether a complaint from a deployer, a deviating test result or a signal from the post-market monitoring of Article 72 already meets it. Whoever records that themselves can later demonstrate the moment of becoming aware; whoever does not has to reconstruct it after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Write out the four measures in paragraph 1 as four concrete scenarios with an owner, a decision maker and a lead time, and decide for yourself what disabling means in your system, because the Regulation does not define that term. Test at least once whether you can actually disable or recall a system without needing a fresh decision to do so. Also keep a record, per system version, of who runs it and through which contact you reach that party, and record which signal meets the \"reason to consider\" threshold in your organisation, so that the moment of becoming aware is demonstrable rather than something reconstructed after the fact.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-20-corrective-actions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 20 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities","legacy_id":"raip:obligation:article-21-cooperation-with-authorities","type":"obligation","slug":"article-21-cooperation-with-authorities","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3","label":"Article 21: cooperation with competent authorities","summary":"Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here, and the status carries a cost that we state alongside them. First, who the competent authority is. Article 21 refers without qualification to a competent authority. Article 3(48) defines the national competent authority as a notifying authority or a market surveillance authority, and provides in the same point that, as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities are construed as references to the European Data Protection Supervisor. We read Article 21 as addressing those national competent authorities. The stronger alternative reading is that competence follows Chapter IX: the market surveillance authority designated by the Member State, the financial supervisor via Article 74(6), the data protection supervisory authority via Article 74(8), the European Data Protection Supervisor via Article 74(9), and, for a delimited group of systems, the AI Office via Article 75 as amended by Regulation (EU) 2026/1744, which already applies. On that reading you prepare for a different counterpart than the one we assume here. Second, what paragraph 2 asks when the logs are in fact held by the deployer. The text limits the duty to logs under your control but does not say whether you must arrange access contractually in order to retain that control. We read no separate duty into it; that is our reading and not the text. What is settled here is the date of application, and that corrects an earlier reading of ours. Article 1, point (40)(b), of Regulation (EU) 2026/1744 replaces Article 113, third paragraph, point (c), and expressly sets Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), at 2 December 2027 for systems classified as high-risk pursuant to Article 6(2) and Annex III and at 2 August 2028 for those classified as high-risk pursuant to Article 6(1) and Annex I. Article 21 sits in Section 3 and is therefore covered by that provision in so many words; the fact that the omnibus does not name Article 21 individually changes nothing, because the provision operates per Section. The cost of this status: a preliminary reading does not count in the per-situation derivation of obligations, so the log access of paragraph 2 and the language rule do not surface there, and Article 16(k) covers only the demonstration of conformity. The object stays reachable through its own page, the deadline index and the API.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-authority-information-request"],"evidence_ids":["praxikon:eu:ai-act:evidence:authority-request-response-file"],"control_ids":["praxikon:eu:ai-act:control:authority-request-intake-and-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-21-legal-text"],"conditions":[{"id":"article-21-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act."},{"id":"article-21-legacy-systems","operator":"any","description":"For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case."},{"id":"article-21-confidentiality-treatment","operator":"all","description":"What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side."}],"exceptions":[{"id":"article-21-log-access-limits","operator":"not","description":"Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies \"as applicable\", and it applies \"to the extent such logs are under their control\". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Paragraph 2 provides that, upon a reasoned request by a competent authority, providers shall also give the requesting competent authority, as applicable, access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control. Paragraph 3 provides that any information obtained by a competent authority pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings of Article 21, verbatim. Article 22(3), point (c), requires the authorised representative to provide a competent authority, upon a reasoned request, with all the information and documentation necessary to demonstrate conformity with the requirements set out in Section 2, including access to the logs referred to in Article 12(1) to the extent such logs are under the control of the provider; the final subparagraph of that paragraph provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities. Article 19(1) provides that the provider keeps the logs under its control for a period appropriate to the intended purpose, of at least six months. Article 26(6) imposes the same period of at least six months on the deployer for the logs under its control. Article 99(5) subjects the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of total worldwide annual turnover for the preceding financial year, whichever is higher.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings as Regulation (EU) 2026/1744 left them. Article 1, point (34), amends Article 77. The heading now reads \"Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities\". Paragraph 1 now provides that national public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, have the power to request and access any information or documentation created or maintained pursuant to this Regulation from the relevant market surveillance authority, in accessible language and machine-readable format by electronic means, where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction, and that the Article is without prejudice to the competences, tasks, powers and independence of those authorities or bodies. The restriction to the systems listed in Annex III, the requirement of an accessible format and the after-the-fact notification of the market surveillance authority are gone. Inserted paragraph 1a provides that the market surveillance authority grants that access, including by requesting the information or documentation from the provider or the deployer where necessary and without undue delay. Inserted paragraph 1b requires market surveillance authorities and those authorities or bodies to cooperate closely and to provide each other with mutual assistance, including exchange of information. Article 99(4) still does not list Article 21 after the amendment: Article 1, point (38)(b), only inserts a point (da) there on the obligations of providers and operators pursuant to Article 25(2) and (4).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The timeline this object rests on is stated in so many words in the amended Regulation. Article 1, point (40)(b), replaces Article 113, third paragraph, point (c), so that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Article 1, point (39)(a), replaces Article 111(2), so that the grace period is tied to the date of application of Chapter III referred to in Article 113 and no longer to 2 August 2026, while retaining 2 August 2030 for systems intended to be used by public authorities. Article 1, point (2)(a), replaces Article 2(2), so that for systems classified as high-risk under Article 6(1) related to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 apply; Article 21 is not on that list. Article 1, point (41), deletes point 1 of Annex I, Section A, and adds Regulation (EU) 2023/1230 on machinery to Annex I, Section B.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Most of what is requested here already exists under the Regulation: the technical documentation of Article 11, the logs of Articles 12 and 19, the quality management system of Article 17, the conformity file of Article 43. Two things are genuinely additional. Article 19 requires you to keep the logs; Article 21(2) requires you to give an authority access to them, which is a different act. And the language rule of paragraph 1 is additional, because you deliver in an official language of the institutions of the Union chosen by the Member State concerned, not in the language you find most convenient. There is nothing to agree there; find out which language the Member State concerned has indicated and budget translation capacity for a technical file. Three further things go wrong in practice. Your documentation exists but is spread across teams and systems, so assembling it takes weeks. Your documentation belongs to a different system version than the one the question is about, in which case you demonstrate the conformity of something else. And the logs are gone: Article 19(1) and Article 26(6) ask for at least six months, so a request arriving later can meet an empty drawer. A provider established in a third country should also expect the request to land with its authorised representative: Article 22(3), point (c), imposes nearly the same delivery on him and the mandate empowers him to be addressed in addition to or instead of the provider. Article 21 is not the only channel either, but that second channel now runs differently. Under amended Article 77(1) a fundamental rights body requests information or documentation from the relevant market surveillance authority rather than directly from you, in accessible language and machine-readable format, and the restriction to Annex III systems has gone. Under inserted paragraph 1a that market surveillance authority may then request the material from you or from the deployer without undue delay. So expect a fundamental rights question to reach you as a request from the market surveillance authority, in a format a machine can read, and with its own route to testing under Article 77(3). On paragraph 3, finally, no comfortable story: Article 78 protects what you hand over only in accordance with Union or national law, carves out the cases of Article 5 of Directive (EU) 2016/943 for trade secrets and source code, and in paragraph 4 leaves the exchange of information, the dissemination of warnings and information duties under national criminal law unaffected. It is a rule on handling, not a shield.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat this as a delivery exercise rather than a documentation question. Record per high-risk system where each part of the conformity file sits, which system version it belongs to and who can assemble it within an agreed period. Find out which official language of the institutions of the Union the Member State concerned has indicated, and plan translation capacity instead of a language agreement. Determine per customer contract whether the automatically generated logs are under your control or with the deployer, and check that your retention period reaches the six months of Article 19(1), because otherwise the question can no longer be answered after half a year. If you are established outside the Union, record that your authorised representative can deliver the same file, since under Article 22(3), point (c), he is addressed in addition to or instead of you. And let nobody improvise in the answer: supplying incorrect, incomplete or misleading information in reply to a request is a separate ground for a fine under Article 99(5), in a different band from the obligations that Article 99(4) does list.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-23-importer-obligations","legacy_id":"raip:obligation:article-23-importer-obligations","type":"obligation","slug":"article-23-importer-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1a3e0958b87d5b96c66eb024898d343fb1a7f570e3fcffbfe56521278f17b278","label":"Article 23: obligations of importers","summary":"Before placing a system on the market the importer verifies four things about the provider, and afterwards carries its own retention, information and notification package with a ten-year term.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:importer"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:importer"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-importer-verification-checklist"],"evidence_ids":["praxikon:eu:ai-act:evidence:importer-verification-record"],"control_ids":["praxikon:eu:ai-act:control:importer-stop-and-notify-control"],"template_ids":["praxikon:eu:ai-act:template:article-23-importer-obligations-legal-text"],"conditions":[{"id":"article-23-importer-obligations-scope","operator":"all","description":"Applies to importers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-23-importer-obligations-exception","operator":"not","description":"If you put your own name or trade mark on the system, substantially modify it, or change the intended purpose so that it becomes high-risk, Article 25(1) treats you as a provider and the duties of Article 16 apply instead of those of Article 23."}],"statements":[{"kind":"official_fact","text":"Article 23(1) requires importers, before placing a high-risk AI system on the market, to verify that the relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider (point (a)), that the provider has drawn up the technical documentation in accordance with Article 11 and Annex IV (point (b)), that the system bears the required CE marking and is accompanied by the EU declaration of conformity referred to in Article 47 and instructions for use (point (c)), and that the provider has appointed an authorised representative in accordance with Article 22(1) (point (d)). Article 23(2) provides that an importer with sufficient reason to consider that the system is not in conformity, is falsified or is accompanied by falsified documentation shall not place it on the market until it has been brought into conformity, and that where the system presents a risk within the meaning of Article 79(1) the importer shall inform the provider, the authorised representative and the market surveillance authorities. Paragraph 3 requires indication of name, registered trade name or registered trade mark and contact address. Paragraph 4 requires storage and transport conditions that do not jeopardise compliance with Section 2. Paragraph 5 requires keeping, for 10 years, a copy of the certificate issued by the notified body and, where applicable, of the instructions for use and of the EU declaration of conformity referred to in Article 47. Paragraph 6 requires providing all necessary information and documentation upon a reasoned request in a language easily understood by the authority, and ensuring the technical documentation can be made available. Paragraph 7 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 23 gets underestimated because it looks like document control, and largely it is: you do not have to revalidate the model, you have to be able to show that you checked the four points. The pain sits elsewhere. Point (d) is the one that most often fails in practice: many providers outside the EU have not appointed an authorised representative, and then you simply may not place the system on the market, however far along the deal is. And paragraph 5 puts the ten-year term on you, not on the supplier: if that supplier no longer exists in five years, you still have to produce the documents.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Move the four verifications of Article 23(1) to the moment before contract signature instead of before delivery. Request the declaration of conformity, the technical documentation, proof of the Article 43 procedure and the authorised representative's details as a condition precedent in the purchase contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 23(1)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-23-importer-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 23 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-24-distributor-obligations","legacy_id":"raip:obligation:article-24-distributor-obligations","type":"obligation","slug":"article-24-distributor-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"97f76fe79b4762a462b986a893ed4abc4685865bbfe1eae0a28589d4f3564419","label":"Article 24: obligations of distributors","summary":"Before making a system available on the market the distributor verifies the marking, the declaration and the instructions for use plus compliance by provider and importer, and must afterwards be able to correct, withdraw or recall.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_ids":["praxikon:eu:ai-act:actor:distributor"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:distributor"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:run-distributor-market-check"],"evidence_ids":["praxikon:eu:ai-act:evidence:distributor-check-and-action-log"],"control_ids":["praxikon:eu:ai-act:control:distributor-corrective-action-control"],"template_ids":["praxikon:eu:ai-act:template:article-24-distributor-obligations-legal-text"],"conditions":[{"id":"article-24-distributor-obligations-scope","operator":"all","description":"Applies to distributors of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-24-distributor-obligations-exception","operator":"not","description":"If you put your own name or trade mark on the system, substantially modify it, or change the intended purpose so that it becomes high-risk, Article 25(1) treats you as a provider and the duties of Article 16 apply instead of those of Article 24."}],"statements":[{"kind":"official_fact","text":"Article 24(1) requires distributors, before making a high-risk AI system available on the market, to verify that it bears the required CE marking, that it is accompanied by a copy of the EU declaration of conformity referred to in Article 47 and instructions for use, and that the provider and the importer of that system, as applicable, have complied with their obligations laid down in Article 16, points (b) and (c), and Article 23(3). Paragraph 2 prohibits making the system available while the distributor considers or has reason to consider, on the basis of the information in its possession, that it does not comply with the requirements of Section 2, and requires notification of the provider or the importer where the system presents a risk within the meaning of Article 79(1). Paragraph 3 requires storage and transport conditions that do not jeopardise compliance. Paragraph 4 requires a distributor that considers or has reason to consider that a system already made available does not comply with Section 2 to take the corrective actions necessary to bring it into conformity, to withdraw it or recall it, or to ensure that the provider, the importer or any relevant operator takes those actions; where the system presents a risk within the meaning of Article 79(1) it shall immediately inform the provider or importer and the competent authorities, giving details of the non-compliance and of any corrective actions taken. Paragraph 5 requires providing, upon a reasoned request, all information and documentation regarding actions taken under paragraphs 1 to 4. Paragraph 6 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The check in paragraph 1 looks light but contains an awkward element: you must also verify that the provider has complied with Article 16, point (c), which is having a quality management system in place under Article 17. You cannot see that on the packaging. In practice you anchor it in supplier terms with a statement from the provider and record what you checked. The centre of gravity of Article 24 sits in paragraph 4 though: many resellers assume recall is the manufacturer's business, while the provision also places that action on you, with the option of ensuring another party carries it out. That ensuring requires contractual grip arranged in advance, not during an incident.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the three checks of paragraph 1 in your resell or delivery process and keep a record per contract of what you saw. Also make sure you can tell within a day which customer uses which system in which version, because without that overview you cannot execute paragraph 4.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 24(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-24-distributor-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 24 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-26-deployer-obligations","legacy_id":"raip:obligation:article-26-deployer-obligations","type":"obligation","slug":"article-26-deployer-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-and-empower-human-oversight"],"evidence_ids":["praxikon:eu:ai-act:evidence:deployer-use-dossier"],"control_ids":["praxikon:eu:ai-act:control:deployer-suspension-and-incident-control"],"template_ids":["praxikon:eu:ai-act:template:article-26-deployer-obligations-legal-text"],"conditions":[{"id":"article-26-deployer-obligations-scope","operator":"all","description":"Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-26-deployer-obligations-exception","operator":"not","description":"Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law."}],"statements":[{"kind":"official_fact","text":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-27-fria","legacy_id":"raip:obligation:article-27-fria","type":"obligation","slug":"article-27-fria","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","topics":["fundamental-rights","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:credit-or-insurance-deployer","praxikon:eu:ai-act:actor:public-law-body","praxikon:eu:ai-act:actor:public-service-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:fria-assess"],"evidence_ids":["praxikon:eu:ai-act:evidence:fria-report"],"control_ids":["praxikon:eu:ai-act:control:fria-pre-deployment-gate"],"template_ids":["praxikon:eu:ai-act:template:fria-questionnaire"],"conditions":[{"id":"fria-annex-iii-high-risk","operator":"all","description":"The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2."},{"id":"fria-covered-deployer","operator":"any","description":"The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c)."}],"exceptions":[{"id":"fria-emergency-notification","operator":"not","description":"In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself."}],"statements":[{"kind":"official_fact","text":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-27-fria","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 27 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-28-39-notified-bodies","legacy_id":"raip:obligation:article-28-39-notified-bodies","type":"obligation","slug":"article-28-39-notified-bodies","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"244200659e300ee841c99c7ece25bf19795a8036b16b7faca26e35a05ecae3b1","label":"Articles 28 to 39: notifying authorities and notified bodies","summary":"Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.","topics":["conformity","governance"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:verify-notified-body-standing"],"evidence_ids":["praxikon:eu:ai-act:evidence:notified-body-standing-record"],"control_ids":["praxikon:eu:ai-act:control:notified-body-continuity-review"],"template_ids":["praxikon:eu:ai-act:template:article-28-39-legal-text"],"conditions":[{"id":"article-28-39-scope","operator":"all","description":"Practically engaged as soon as a notified body comes into the picture for your system. Within Annex III that is, under Article 43(1), only for the biometrics of point 1, and then only along the Annex VII procedure. Within Annex I, Section A, it happens through the sectoral conformity assessment of Article 43(3). For the systems of points 2 to 8 of Annex III, which follow the internal control of Annex VI, no notified body is involved and this Section has no direct bearing on you. The Section itself has applied since 2 August 2025 and therefore well before the underlying high-risk obligations bite: the notification chain has to exist before there is anything to assess."},{"id":"article-28-39-subcontracting-consent","operator":"all","description":"Article 33(3) makes the agreement of the provider a condition for subcontracting: activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. That is a right you can exercise only if you ask about it, because the provision does not prescribe any active notice to you."}],"exceptions":[{"id":"article-28-39-third-country-bodies","operator":"not","description":"Article 39 rules out a free choice of a foreign body. Only conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies, and then only where they meet the requirements laid down in Article 31 or ensure an equivalent level of compliance."},{"id":"article-28-39-presumption-limited","operator":"not","description":"The presumption in Article 32 is narrow. A conformity assessment body is presumed to comply with the requirements of Article 31 in so far as the applicable harmonised standards cover those requirements and their references have been published in the Official Journal of the European Union. Without that publication the presumption does not operate, and it never reaches further than what the standard covers."}],"statements":[{"kind":"official_fact","text":"Article 28(1) provides: Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States. Paragraph 3 provides: Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded. Paragraph 5 provides: Notifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis. Article 29(1) provides: Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established. Paragraph 2 provides: The application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31. Article 30(1) provides: Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31. Paragraph 2, as replaced by Article 1, point (16), of Regulation (EU) 2026/1744, provides: Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1. The second subparagraph of that paragraph empowers the Commission to amend Annex XIV by delegated act. Until 27 July 2026 paragraph 2 carried no such list of codes; since then it sets the scope of the designation. Paragraph 4 provides: The conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 28(1), (3) and (5); Article 29(1) and (2); Article 30(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 28(8), as added by Article 1, point (14), of Regulation (EU) 2026/1744, provides: notifying authorities designated pursuant to this Regulation that are responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both pursuant to this Regulation and that legislation is provided with the possibility to submit a single application and undergoes a unified assessment procedure, where the relevant Union harmonisation legislation provides for such a procedure. A conformity assessment body designated pursuant to more than one piece of that legislation shall have to apply only once to be designated pursuant to this Regulation, and a designation pursuant to this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which it is designated. Paragraph 9 provides that a notifying authority designated pursuant to that legislation is also the notifying authority for the application of that procedure, unless the Member State designates another notifying authority for this Regulation. Article 29(4), as replaced by Article 1, point (15), provides that notified bodies undergoing the unified assessment procedure shall submit the single application to the notifying authority designated pursuant to that Union harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (14) to (16), amending Articles 28, 29 and 30","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 31(1) provides: A notified body shall be established under the national law of a Member State and shall have legal personality. Paragraph 4 provides: Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. Paragraph 5 provides: Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. Paragraph 6 provides: Notified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Paragraph 8 provides: Notified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned. Paragraph 11 provides: The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 32 provides: Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements. Article 33(1) provides: Where a notified body subcontracts specific tasks connected with the conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 31, and shall inform the notifying authority accordingly. Paragraph 2 provides: Notified bodies shall take full responsibility for the tasks performed by any subcontractors or subsidiaries. Paragraph 3 provides: Activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available. Paragraph 4 provides: The relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation shall be kept at the disposal of the notifying authority for a period of five years from the termination date of the subcontracting.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 34(1) provides: Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43. Paragraph 2 provides: Notified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation. Paragraph 3 provides: Notified bodies shall make available and submit upon request all relevant documentation, including the providers documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section. Article 35(1) provides: The Commission shall assign a single identification number to each notified body, even where a body is notified under more than one Union act. Paragraph 2 provides: The Commission shall make publicly available the list of the bodies notified under this Regulation, including their identification numbers and the activities for which they have been notified. The Commission shall ensure that the list is kept up to date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 36(3) provides: Where a notified body decides to cease its conformity assessment activities, it shall inform the notifying authority and the providers concerned as soon as possible and, in the case of a planned cessation, at least one year before ceasing its activities. The certificates of the notified body may remain valid for a period of nine months after cessation of the notified body activities, on condition that another notified body has confirmed in writing that it will assume responsibilities for the high-risk AI systems covered by those certificates. The latter notified body shall complete a full assessment of the high-risk AI systems affected by the end of that nine-month-period before issuing new certificates for those systems. Where the notified body has ceased its activity, the notifying authority shall withdraw the designation. Paragraph 5 provides: Where its designation has been suspended, restricted, or fully or partially withdrawn, the notified body shall inform the providers concerned within 10 days. Paragraph 6 provides: In the event of the restriction, suspension or withdrawal of a designation, the notifying authority shall take appropriate steps to ensure that the files of the notified body concerned are kept, and to make them available to notifying authorities in other Member States and to market surveillance authorities at their request. Paragraph 9 provides: With the exception of certificates unduly issued, and where a designation has been withdrawn, the certificates shall remain valid for a period of nine months under the following circumstances: (a) the national competent authority of the Member State in which the provider of the high-risk AI system covered by the certificate has its registered place of business has confirmed that there is no risk to health, safety or fundamental rights associated with the high-risk AI systems concerned; and (b) another notified body has confirmed in writing that it will assume immediate responsibility for those AI systems and completes its assessment within 12 months of the withdrawal of the designation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 37(1) provides: The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the requirements laid down in Article 31 and of its applicable responsibilities. Paragraph 2 provides: The notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned. Paragraph 4 provides: Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including the suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. Article 38(1) provides: The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies. Paragraph 2 provides: Each notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives. Paragraph 3 provides: The Commission shall provide for the exchange of knowledge and best practices between notifying authorities. Article 39 provides: Conformity assessment bodies established under the law of a third country with which the Union has concluded an agreement may be authorised to carry out the activities of notified bodies under this Regulation, provided that they meet the requirements laid down in Article 31 or they ensure an equivalent level of compliance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 37(1), (2) and (4); Article 38(1) to (3); Article 39","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this Section as the supplier terms of your conformity assessor, because that is exactly what it is. Three points in it go wrong in practice. The first is the independence requirement of Article 31(4) and (5). It prohibits not only the obvious double role but rules out consultancy services in particular. Anyone who has his high-risk file built by the advisory firm that later performs the assessment buys a certificate that can be challenged on that ground. Separate those two purchases at the outset, not halfway through. The second is Article 31(1) read alongside Article 39. The body must be established under the national law of a Member State and have legal personality; a body from a third country comes into the picture only where the Union has concluded an agreement with that country. For a group that places its worldwide certification with a single house, that is a hard limit: the European assessment must sit with a European notified legal person, and the group brand name says nothing about that. The third is Article 33. Subcontracting is allowed, but only with your agreement, and the body retains full responsibility for what the subcontractor does. The provision does not oblige it to tell you of its own motion; it only makes its subsidiaries publicly available. So ask, and record the answer, because without the question the agreement never comes up.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 31(1), (4), (5), (6), (8) and (11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 32; Article 33(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Two provisions in this Section work in your favour and are rarely used. Article 34(2) is the first. It requires the body to avoid unnecessary burdens for providers and to take due account of your size, your sector, your structure and the complexity of the system, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises. That is not a policy aspiration but an operational obligation of the body, and it sits alongside Article 31(8), which demands the same proportionality in its procedures. The second sentence of paragraph 2 immediately bounds it: the degree of rigour and the level of protection stand. The practical reading is therefore not that a small provider has to demonstrate less, but that the road there must be proportionate. If you are handed a standard package plainly designed for a different kind of organisation, this is the provision on which you raise it. Article 36 is the second. It holds the scenario that hits a provider hardest and appears in no project plan: your body ceases or loses its designation. Your certificates then remain valid for at most nine months, and only where another notified body has confirmed in writing that it will assume responsibility. You hear about it within ten days, and that is the only deadline in this Section that runs directly to you. The follow-on steps for the certificate itself sit in the object on Article 44; what matters here is that the continuity of your market access depends on a party over which you have no control. So treat the notified body as a supplier with concentration risk, and not as a quality mark.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 34(1) to (3); Article 35(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether this Section touches you at all: only where your system goes through a notified body via Annex VII or via the sectoral route of Article 43(3). If it does, check four things in the Commission public list at the moment of choice and annually thereafter: is the body still listed, what identification number does it carry, for which conformity assessment activities and which types of AI systems is it notified, and has its designation been restricted or suspended. Record for each choice that you tested the independence of Article 31(4) and (5), in particular whether the same group previously advised you on the same system. When placing the assignment, ask explicitly which tasks are subcontracted to a subcontractor or a subsidiary, give or withhold your agreement under Article 33(3) in writing, and provide in the contract that any change to it requires your agreement again. Add two clauses: a duty on the body to report any change to its designation, mirroring the ten days of Article 36(5), and a handover clause describing which files you get back within what period if it ceases. Finally, keep a second notified body in view that is notified for your type of system, so that the nine months of Article 36(3) and (9) become a handover rather than a search.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1) and (3); Article 44(2); Article 113, third paragraph, point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (6) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-28-39-notified-bodies","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Chapter III, Section 4, on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/31","label":"Read Article 31 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4-ai-literacy","legacy_id":"raip:obligation:article-4-ai-literacy","type":"obligation","slug":"article-4-ai-literacy","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"7a9516670dfca5dd7dcc96ae019e5714f843e20235abd3e9d92b71eb42445ff1","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","topics":["ai-literacy"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-4-measures"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-4-measures-record"],"control_ids":["praxikon:eu:ai-act:control:article-4-periodic-review"],"template_ids":["praxikon:eu:ai-act:template:article-4-measures-plan"],"conditions":[{"id":"article-4-in-scope-ai","operator":"all","description":"The organisation is a provider or deployer of an AI system within scope."}],"exceptions":[{"id":"article-4-no-specific-level","operator":"not","description":"The provision does not require a specific individual level to be guaranteed."}],"statements":[{"kind":"official_fact","text":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Official amending regulation"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications","legacy_id":"raip:obligation:article-40-42-standards-and-specifications","type":"obligation","slug":"article-40-42-standards-and-specifications","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c","label":"Articles 40 to 42: standards, common specifications and presumption of conformity","summary":"A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.","topics":["conformity","standards"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open is the anchoring of the duty holder. Of the three Articles only Article 41(5) contains a rule of conduct addressed to a role this graph knows: providers of high-risk AI systems or general-purpose AI models must duly justify that they have adopted at least equivalent technical solutions where they do not apply a common specification. The object is anchored on that paragraph. A defensible alternative reading treats Articles 40 to 42 as entirely institutional, with an empty duty holder and `out_of_scope`, and hangs the justification on Article 11 and Annex IV, where the technical documentation is described. On that reading the recommended action and the file below move to the object on Article 11; the substance does not change, the basis does. Also open is where the justification must be recorded. Article 41(5) prescribes no form, no place and no recipient. We read it as belonging in the technical documentation, because that is the only file a market surveillance authority can request under Article 21; that is an inference and not text. Not open is the dating: Articles 40, 41 and 42 sit in Chapter III, Section 5, and that Section is not excepted in the third paragraph of Article 113, so the general application date of the second paragraph governs, 2 August 2026.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:justify-standards-and-specification-choices"],"evidence_ids":["praxikon:eu:ai-act:evidence:standards-conformity-justification-file"],"control_ids":["praxikon:eu:ai-act:control:official-journal-citation-watch"],"template_ids":["praxikon:eu:ai-act:template:article-40-42-legal-text"],"conditions":[{"id":"article-40-42-publication-condition","operator":"all","description":"The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal."},{"id":"article-40-42-justification-condition","operator":"all","description":"The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route."}],"exceptions":[{"id":"article-40-42-presumption-is-rebuttable","operator":"not","description":"A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements."},{"id":"article-40-42-specification-withdrawn","operator":"not","description":"Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis."}],"statements":[{"kind":"official_fact","text":"The final subparagraph of Article 40(2), as added by Article 1, point (17), of Regulation (EU) 2026/1744, provides: the Commission shall request, in accordance with Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation. Article 42(3), added by Article 1, point (18), provides: where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (17) and (18), amending Article 40(2) and Article 42","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 40(1) provides: High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations. Paragraph 2 provides: In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum. When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation. Paragraph 3 provides: The participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(1) provides: The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and: (i) the request has not been accepted by any of the European standardisation organisations; or (ii) the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or (iii) the relevant harmonised standards insufficiently address fundamental rights concerns; or (iv) the harmonised standards do not comply with the request; and (b) no reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period. When drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67. Paragraph 2 provides: Before preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled. Paragraph 3 provides: High-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 41(4) provides: Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V. Paragraph 5 provides: Where providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto. Paragraph 6 provides: Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 42(1) provides: High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4). Paragraph 2 provides: High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The word everything turns on is presumed. A presumption of conformity is not proof of compliance and it is rebuttable: it shifts who has to demonstrate what, and nothing more. If a market surveillance authority shows that your system in fact does not meet a requirement of Section 2, the standard you applied does not stop that. Two limits set out in the text itself come on top. The first is the coverage limit: the presumption operates only in so far as the standard or the specification covers the requirements or obligations concerned. EN 18286 shows exactly what that means, because the coverage statement accompanying that standard expressly excludes Article 17(2) to (4) and Article 72; whatever falls outside the coverage you substantiate yourself. The second is the publication limit: without a reference in the Official Journal of the European Union no presumption arises, however complete the standard may be. That is why all twelve standard objects in data/ai-act/graph/standards.ts carry guidance and not applicable. So anyone hearing a supplier say that his product meets the European standard and is therefore AI Act compliant is hearing two leaps at once: from coverage to completeness, and from standard to legal effect.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 40(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Article 41 is often dismissed as an emergency valve that will never be used, and that is the wrong call. The European standards under standardisation request M/613 are not all available yet: the standards layer in data/ai-act/graph/standards.ts shows one completed EN and six deliverables still at drafting or enquiry stage. That is precisely the state described by the conditions of Article 41(1), point (a)(ii), and point (b), and so the common specification route remains practically relevant. For you that means two things. First, an implementing act may appear for a requirement of Section 2 that you did not see coming and that touches your design choices; those acts are adopted under the examination procedure of Article 98(2) and not in consultation with individual providers. Second, there is then a paragraph that asks something of you directly: paragraph 5. If you do not apply the common specification, you must duly justify that your technical solution is at least equivalent. That is the only place in these three Articles where you have to write something yourself, and the text does not say where. In practice that justification belongs in the technical documentation, because that is the file that has to be handed over upon a reasoned request. Article 42 is narrower than it looks and is overrated for that reason. Paragraph 1 touches only Article 10(4) and not the rest of the data governance of Article 10; paragraph 2 touches only the cybersecurity requirements of Article 15 and only where the references of the scheme under Regulation (EU) 2019/881 have been published in the Official Journal. A certificate under a scheme not yet published yields no presumption, and a presumption on Article 15 says nothing about your Article 9, 11, 12, 13 or 14.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 42(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null},{"source_id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","source_locator":"prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613","source_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Build a coverage matrix per high-risk system and per general-purpose AI model: put every requirement of Section 2 that applies to you in the left column, and next to it which harmonised standard, which common specification or which document of your own covers that requirement. Note per row whether the reference of that standard has been published in the Official Journal of the European Union, because only those rows carry a presumption; the remaining rows call for evidence of your own. For every requirement where a common specification exists that you do not apply, write a justification under Article 41(5): which technical solution you adopted, why it is at least equivalent to what the specification demands, and which test shows it. Include that justification in the technical documentation so that it can travel immediately upon a reasoned request. Set up a standing check on publications in the Official Journal as well: a new reference switches a presumption on, and under Article 41(4) repeals an existing common specification, which can remove the basis under a row of your matrix. If you want to rely on Article 42, record why your training and testing data reflect the geographical, behavioural, contextual or functional setting within which the system is intended to be used, and confine the conclusion to Article 10(4). For the cybersecurity route, first check whether the references of the scheme under Regulation (EU) 2019/881 appear in the Official Journal; without that publication the certificate is a good document with no legal effect under Article 15.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 41(4), (5) and (6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(4); Article 15; Article 43(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Articles 40 to 42 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/40","label":"Read Article 40 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-44-notified-body-certificates","legacy_id":"raip:obligation:article-44-notified-body-certificates","type":"obligation","slug":"article-44-notified-body-certificates","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"458f4f14180a115bbccca9bac5e76eae0e9642c92bc0831b57b8e803ebb447b9","label":"Article 44: certificates of notified bodies","summary":"A certificate issued by a notified body is valid for at most five years for AI systems covered by Annex I and at most four years for AI systems covered by Annex III, and may be extended at the request of the provider after a re-assessment. Where the system no longer meets the requirements of Section 2, the body shall, taking account of the principle of proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes corrective action within an appropriate deadline it sets so as to ensure compliance with those requirements. An appeal procedure against that decision is available.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"What this Article asks of a provider remains unsettled. The text addresses the notified body alone and imposes no duty at all on the provider. We read a practical consequence into it, namely that whoever holds a certificate watches its expiry date, asks for a re-assessment in time and is able to correct within the deadline set by the body. A defensible alternative reading is that for the provider Article 44 merely describes what the body does and that his duties follow entirely from Articles 16, 17 and 43. On that reading the recommended action and the file below hang on Article 43 rather than Article 44; the substance does not change, the basis does. On the dating that doubt no longer exists: Article 44 sits in Section 5 of Chapter III, the third paragraph of Article 113 excepts only Sections 1, 2 and 3 of that Chapter, and so the general application date of the second paragraph of Article 113 governs, 2 August 2026. When the provision bites in practice does differ per route: for the systems of Annex III the underlying obligations run from 2 December 2027 and for the regulated products of Annex I from 2 August 2028, while the Section B products of Annex I fall outside this Article altogether since 27 July 2026. Those two dates do not fit in a field that carries one, which is why the field carries the application date of the Article itself. It also remains unclear whom the last sentence of paragraph 3 addresses: an appeal procedure against decisions of the notified bodies shall be available, but the text does not say who provides it. That the route exists is stated.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:manage-notified-body-certificate"],"evidence_ids":["praxikon:eu:ai-act:evidence:notified-body-certificate-record"],"control_ids":["praxikon:eu:ai-act:control:certificate-expiry-monitoring"],"template_ids":["praxikon:eu:ai-act:template:article-44-legal-text"],"conditions":[{"id":"article-44-scope","operator":"all","description":"Applies as soon as a notified body has issued a certificate for a high-risk AI system. That happens along two routes. The certificate under Annex VII, which under Article 43(1) and (2) arises within Annex III only for the biometrics of point 1. There it can arise along two ways: a provider who has applied harmonised standards or common specifications may under the first subparagraph of paragraph 1 choose between the internal control of Annex VI and the procedure involving a notified body of Annex VII, and the second subparagraph makes Annex VII mandatory in the four cases it lists. And the certificate issued under Article 43(3) as replaced with effect from 27 July 2026, within the sectoral conformity assessment of the products of Annex I, Section A, where the body is notified under that sectoral legislation, where the quality management system of Article 17 is assessed as well, and where point 3, points 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. For the products of Annex I, Section B, which cover machinery since 27 July 2026, this Article has no bearing: the amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to those systems, and Article 44 is not in that list. Nor does it bear on the systems of points 2 to 8 of Annex III, which under Article 43(2) follow the internal control of Annex VI, where no notified body is involved."}],"exceptions":[{"id":"article-44-exception-corrective-action","operator":"not","description":"Paragraph 3 withholds suspension, withdrawal or restriction where compliance with the requirements of Section 2 is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body. The principle of proportionality also allows the body to confine itself to restrictions instead of withdrawal."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that certificates issued by notified bodies in accordance with Annex VII shall be drawn up in a language which can be easily understood by the relevant authorities in the Member State in which the notified body is established. Paragraph 2 provides that certificates shall be valid for the period they indicate, which shall not exceed five years for AI systems covered by Annex I and four years for AI systems covered by Annex III, that at the request of the provider the validity may be extended for further periods, each not exceeding five years and four years respectively, based on a re-assessment in accordance with the applicable conformity assessment procedures, and that any supplement to a certificate shall remain valid provided that the certificate which it supplements is valid. Paragraph 3 provides that where a notified body finds that an AI system no longer meets the requirements set out in Section 2, it shall, taking account of the principle of proportionality, suspend or withdraw the certificate issued or impose restrictions on it, unless compliance with those requirements is ensured by appropriate corrective action taken by the provider of the system within an appropriate deadline set by the notified body, that the notified body shall give reasons for its decision, and that an appeal procedure against decisions of the notified bodies, including on conformity certificates issued, shall be available.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 43 sets out along which route a certificate arises and when it must be earned again. Paragraph 1 lets the provider of the systems listed in point 1 of Annex III choose between the internal control of Annex VI and the procedure involving a notified body of Annex VII where he has applied harmonised standards or common specifications, and makes the Annex VII procedure mandatory in four cases: the harmonised standards referred to in Article 40 do not exist and the common specifications referred to in Article 41 are not available; the provider has not applied, or has applied only part of, the harmonised standard; the common specifications referred to in point (a) exist but the provider has not applied them; or one or more of the harmonised standards referred to in point (a) has been published with a restriction, and then only on the part of the standard that was restricted. Paragraph 2 provides that for the systems of points 2 to 8 of Annex III providers follow the internal control of Annex VI, for which the involvement of a notified body is not required. Paragraph 4 provides that high-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new procedure whenever they are substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer, and that for systems that continue to learn, changes predetermined by the provider at the moment of the initial conformity assessment and part of the technical documentation referred to in point 2(f) of Annex IV do not constitute a substantial modification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 of Article 43 was replaced with effect from 27 July 2026. Under the text in force, the provider of a high-risk AI system covered by the Union harmonisation legislation listed in Section A of Annex I follows the relevant conformity assessment procedure as required in accordance with that harmonisation legislation, the requirements set out in Section 2 of this Chapter apply to those systems and form part of that assessment, an assessment of the quality management system set out in Article 17 is also undertaken, and points 3, 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. The second subparagraph gives notified bodies notified under that harmonisation legislation the power to assess the conformity of those systems with the requirements of Section 2, provided that their compliance with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under that harmonisation legislation, which is evidenced through the assessment as part of the existing notification, and requires those same bodies, without prejudice to Article 28, to apply for designation in accordance with Section 4 of this Chapter by 28 January 2028. The third subparagraph provides that a manufacturer entitled under that harmonisation legislation to rely on a conformity assessment not involving a third party may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41 covering all requirements of Section 2, that the classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of conformity assessment procedure provided to those manufacturers, and that those manufacturers are not required to choose a procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if that harmonisation legislation does not require it. The fourth subparagraph provides that the provider of a system both covered by that harmonisation legislation and falling within one of the categories listed in Annex III follows the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (19), replacing Article 43(3)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex I was amended with effect from 27 July 2026: in Section A, point 1 was deleted, and in Section B, point 21 was added, referring to Regulation (EU) 2023/1230 on machinery. Article 2(2), likewise replaced, provides that for AI systems classified as high-risk in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 apply, and that Articles 57, 58 and 59 apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that harmonisation legislation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (2)(a), replacing Article 2(2), and point (41), amending Annex I"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 36 governs what happens to certificates already issued where the notified body itself is concerned. Paragraph 3 provides that a body deciding to cease its conformity assessment activities shall inform the notifying authority and the providers concerned as soon as possible, and in the case of a planned cessation at least one year beforehand, and that its certificates may remain valid for nine months after the cessation on condition that another notified body has confirmed in writing that it will assume responsibility, that other body carrying out a full assessment before the end of those nine months before issuing new certificates. Paragraph 5 provides that a notified body whose designation is suspended, restricted or withdrawn in whole or in part shall inform the providers concerned within ten days. Paragraph 7 provides that in that case the notifying authority shall assess the impact on the certificates issued, shall require the body to suspend or withdraw within a reasonable period any certificates unduly issued, and shall provide the national competent authorities of the Member State in which the provider has its registered place of business with all relevant information on the certificates whose suspension or withdrawal it has ordered. Paragraph 8, point (b), provides that where the notifying authority establishes that the body is not capable of supporting existing certificates issued, the provider of the system covered by the certificate shall confirm in writing to the national competent authorities of the Member State of its registered place of business, within three months of the suspension or restriction, that another qualified notified body will temporarily assume the monitoring of and responsibility for the certificates. Paragraph 9 provides that upon withdrawal of a designation certificates, with the exception of those unduly issued, remain valid for nine months where the national competent authority has confirmed that there is no risk and another notified body has confirmed in writing that it assumes immediate responsibility and will complete its assessment within twelve months of the withdrawal.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 45(2), point (b), provides that each notified body shall inform the other notified bodies of Union technical documentation assessment certificates or any supplements thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, of the certificates and supplements which it has issued.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 45(2), point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Point (c) of the third paragraph of Article 113 was replaced with effect from 27 July 2026 and now provides that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. That deferral concerns those three Sections alone. Article 44 sits in Section 5 of Chapter III and therefore falls under the general application date given in the second paragraph of Article 113: 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Start with the question whether this Article touches you at all, because for most high-risk systems the answer is no. Of Annex III only the biometrics of point 1 pass through a notified body, and there only where you choose that route yourself or where one of the four cases in the second subparagraph of Article 43(1) arises; points 2 to 8 follow the internal control of Annex VI and produce no certificate whatsoever. Whoever does hold a certificate usually holds it through the regulated products of Annex I, Section A, and that certificate comes out of the sectoral conformity assessment of Article 43(3) rather than out of Annex VII. Check first which Section carries your product, because that shifted on 27 July 2026: machinery was taken out of Section A and placed in Section B as Regulation (EU) 2023/1230, and for Section B products the amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable. Article 44 is not among them, so for AI in machinery this Article no longer bears, while it applies in full to the remaining products of Section A. On that Section A route the assessment is moreover wider than it was: since 27 July 2026 the quality management system of Article 17 is assessed as well, and point 3, points 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. That difference is practical: the language requirement of paragraph 1 is tied to the Annex VII certificate and does not carry over unchanged to that sectoral route, whereas the five years of paragraph 2 simply apply. The mistake the Article exposes is the idea that conformity assessment is a project that ends. The certificate has an end date, at most four years for an Annex III system and at most five for an Annex I product, and the re-assessment that carries the extension itself takes time. Whoever knocks on the door only in the final month stands on the expiry date without valid paper while the system simply runs in production. The clock is moreover not the most frequent reason to go back. Article 43(4) sends a system through the assessment again whenever it is substantially modified, including where you only keep using it internally; only changes you predetermined and recorded in the technical documentation do not count. In practice that trigger arrives years before the expiry date. Where things do go wrong, the response of the body is not binary: the principle of proportionality in paragraph 3 allows it to confine itself to restrictions instead of withdrawal, correcting within the deadline it sets holds off the measure, and an appeal procedure against its decision is available. Count on none of the three as a matter of course, but know that they exist. Nor should you count on starting afresh elsewhere after a refusal: Article 45(2), point (b), obliges the body to inform its peer bodies of certificates refused, withdrawn, suspended or restricted. Also put 28 January 2028 in your diary, even though that date is not addressed to you. The second subparagraph of the new Article 43(3) lets bodies notified only under the sectoral legislation of Annex I, Section A, assess conformity with Section 2, but only where their compliance with Article 31(4), (5), (10) and (11) has already been assessed in their existing notification, and requires those same bodies to apply for designation under Section 4 by that date. The recital accompanying the amendment describes that power as an arrangement for eighteen months from 27 July 2026. So ask your body what its status is and whether it is applying, because who can carry out your assessment after that date depends on it. Finally, watch the side that has nothing to do with your system. A notified body can cease its activities or lose its designation. Article 36 then gives you nine months, but only where another body assumes responsibility in writing, and the body must inform you within ten days. In a suspension where the authority establishes that your body can no longer support the existing certificates, there is even a genuine duty on you: to confirm in writing to your national competent authority, within three months, which other qualified body will temporarily take over the monitoring. That is the only hard deadline in this whole block that lands on your desk.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (19), replacing Article 43(3)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Article 1, point (2)(a), replacing Article 2(2), and point (41), amending Annex I"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 45(2), point (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish per high-risk system whether there is a certificate at all, and along which route it was issued: Annex VII or the sectoral procedure of Article 43(3). Check while doing so whether your product still sits in Section A of Annex I since 27 July 2026, because for the Section B products, machinery among them, the amended Article 2(2) does not make this Article apply. Then record which certificate belongs to it, which notified body issued it, on what date it expires and which supplements are attached to it, and put that expiry date in the same watch list as your contracts. Plan the extension request well before the expiry date, because the extension rests on a re-assessment in accordance with the applicable conformity assessment procedures. Also tie your change management to Article 43(4): determine per change whether it is substantial, and record the predetermined changes of a learning system in the technical documentation of point 2(f) of Annex IV, because only those do not count as a substantial modification. Designate who receives a message from the notified body, so that a deadline set for corrective action does not expire in a general inbox, and keep the appeal procedure of paragraph 3 open as a route alongside correcting itself. Finally, bring the body itself into the same watch list: track whether it ceases its activities or loses its designation, ask whether it is filing the application for designation under Section 4 that the second subparagraph of Article 43(3) requires of it by 28 January 2028, and make sure you can file the confirmation of Article 36(8), point (b), in writing with your national competent authority within three months.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 44(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 36(3), (5), (7), (8) and (9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-44-notified-body-certificates","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"The Regulation on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment","legacy_id":"raip:obligation:article-46-derogation-from-conformity-assessment","type":"obligation","slug":"article-46-derogation-from-conformity-assessment","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1750dded1098676522ac2284e471cb504967e1c6055f5c0a19d556778c2e3792","label":"Article 46: derogation from conformity assessment procedure","summary":"By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.","topics":["conformity","enforcement"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"What the provision says is settled; who the duty holder is in this model is not. Article 46 addresses the market surveillance authority (paragraphs 1, 3 and 6) and the Commission (paragraph 5). The provider and the deployer are the requesting party and the party that bears the consequences, and they therefore sit in `affected_actor_ids` with `duty_holder_uncertainty_status: out_of_scope`. A defensible alternative reading writes the market surveillance authority in as duty holder: it exists as an actor in this dataset, and paragraphs 3 and 6 impose a notification and a withdrawal on it that read as duties. On that reading it moves from `oversight_actor_ids` to `duty_holder_ids` and the provider and deployer stay as affected parties; the substance of this object does not change, the basis does. We keep it in the oversight role because no other obligation in this dataset names it as addressee and the meaning of the field would otherwise differ within the same dataset. What also remains uncertain is what the limited period of paragraph 1 is: the text names no maximum and ties the duration only to the exceptional reasons justifying the derogation and to the conformity assessment being carried out. Anyone building on this route cannot read from the text how long it may last. On the dating there is no such doubt: Article 46 sits in Section 5 of Chapter III, the third paragraph of Article 113 excepts only Sections 1, 2 and 3 and its point (b) concerns Section 4, so the general application date of the second paragraph governs, 2 August 2026. On Regulation (EU) 2026/1744. That text was retrieved after all on 6 September 2026 from the Publications Office Cellar service and is archived in data/ai-act/review/sources/reg-eu-2026-1744-nl.txt and -en.txt. The amending regulation carries forty-three amendment points in its Article 1; which of those are reflected in the local legal texts is recorded per point in data/ai-act/review/consolidation-manifest.json. Where a point touches this Article, that is stated below with the statement concerned.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-article-46-derogation-request"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-46-derogation-request-file"],"control_ids":["praxikon:eu:ai-act:control:article-46-derogation-exit-review"],"template_ids":["praxikon:eu:ai-act:template:article-46-legal-text"],"conditions":[{"id":"article-46-exceptional-grounds","operator":"any","description":"The authorisation may be granted only for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That list is the entire basis: a commercial interest, a delivery deadline or a tender date is not in it."},{"id":"article-46-justified-request-and-territory","operator":"all","description":"A duly justified request is required, the authorisation comes from a market surveillance authority, it concerns specific high-risk AI systems, and it operates solely within the territory of the Member State concerned. It is moreover for a limited period while the necessary conformity assessment procedures are being carried out, and the completion of those procedures shall be undertaken without undue delay."},{"id":"article-46-section-2-compliance","operator":"all","description":"The authorisation is issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The derogation therefore concerns the procedure of Article 43 and not the substantive requirements of Articles 8 to 15: those must be met before the authorisation exists."}],"exceptions":[{"id":"article-46-urgency-without-prior-authorisation","operator":"not","description":"Paragraph 2 removes the prior authorisation in a duly justified situation of urgency for exceptional reasons of public security or in the case of a specific, substantial and imminent threat to the life or physical safety of natural persons. Only law-enforcement authorities and civil protection authorities may rely on it, and only for putting into service, provided that such authorisation is requested during or after the use without undue delay."},{"id":"article-46-annex-i-section-a-carve-out","operator":"not","description":"Paragraph 7 excludes this Article for high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I. There, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply. For a regulated product, Article 46 is therefore not a route."},{"id":"article-46-sensitive-operational-data","operator":"not","description":"The notification duty in paragraph 3 towards the Commission and the other Member States shall not cover sensitive operational data in relation to the activities of law-enforcement authorities. The authorisation itself stands; the flow of data around it is limited."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides the following. By way of derogation from Article 43 and upon a duly justified request, any market surveillance authority may authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. That authorisation shall be for a limited period while the necessary conformity assessment procedures are being carried out, taking into account the exceptional reasons justifying the derogation. The completion of those procedures shall be undertaken without undue delay. Paragraph 2 provides the following. In a duly justified situation of urgency for exceptional reasons of public security or in the case of specific, substantial and imminent threat to the life or physical safety of natural persons, law-enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation referred to in paragraph 1, provided that such authorisation is requested during or after the use without undue delay. If the authorisation referred to in paragraph 1 is refused, the use of the high-risk AI system shall be stopped with immediate effect and all the results and outputs of such use shall be immediately discarded.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides the following. The authorisation referred to in paragraph 1 shall be issued only if the market surveillance authority concludes that the high-risk AI system complies with the requirements of Section 2. The market surveillance authority shall inform the Commission and the other Member States of any authorisation issued pursuant to paragraphs 1 and 2. This obligation shall not cover sensitive operational data in relation to the activities of law-enforcement authorities. Paragraph 4 provides the following. Where, within 15 calendar days of receipt of the information referred to in paragraph 3, no objection has been raised by either a Member State or the Commission in respect of an authorisation issued by a market surveillance authority of a Member State in accordance with paragraph 1, that authorisation shall be deemed justified.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(3)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 5 provides the following. Where, within 15 calendar days of receipt of the notification referred to in paragraph 3, objections are raised by a Member State against an authorisation issued by a market surveillance authority of another Member State, or where the Commission considers the authorisation to be contrary to Union law, or the conclusion of the Member States regarding the compliance of the system as referred to in paragraph 3 to be unfounded, the Commission shall, without delay, enter into consultations with the relevant Member State. The operators concerned shall be consulted and have the possibility to present their views. Having regard thereto, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant operators. Paragraph 6 provides the following. Where the Commission considers the authorisation unjustified, it shall be withdrawn by the market surveillance authority of the Member State concerned. Paragraph 7 provides the following. For high-risk AI systems related to products covered by Union harmonisation legislation listed in Section A of Annex I, only the derogations from the conformity assessment established in that Union harmonisation legislation shall apply.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 46(5)-(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only route in the Regulation along which a high-risk AI system reaches the market or is put into service without a completed conformity assessment, and that is exactly why it is not a commercial route. Three things make that firm. The grounds are exhaustive and none of them is about the supplier: public security, the protection of life and health of persons, environmental protection, the protection of key industrial and infrastructural assets. A tight delivery deadline, a tender closing in, or a notified body with a waiting list are not among them. The derogation moreover concerns only the procedure of Article 43 and not the substance: paragraph 3 allows the authorisation only where the market surveillance authority concludes that the system complies with the requirements of Section 2. So it does not buy you time to do Articles 9 to 15 later; at most it buys time for the paperwork of the assessment. And it is closed off geographically: the authorisation operates within the territory of the Member State concerned, which means a system running on this basis in one Member State simply has no basis in the next. Note finally paragraph 7. For high-risk AI systems related to products under Section A of Annex I this Article is not a route: there, only the derogations of the sectoral harmonisation legislation apply. Anyone building a regulated product therefore looks for the exit in his own sectoral framework and not here.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 reverses the order and that is the heaviest part of this Article for whoever uses it. In a situation of urgency a law-enforcement authority or a civil protection authority may put the system into service first and request the authorisation afterwards, provided that happens without undue delay. The other side sits in the same sentence: if the authorisation is refused, use stops with immediate effect and all results and outputs of that use are immediately discarded. That is not a suspension but a rollback, and it reaches what was produced in the meantime. Anyone starting on this basis must therefore know in advance which decisions, files, alerts and derived datasets count as results and outputs and how they can be found; working out afterwards what the system touched is too late by then, and a decision that rested on such an output is left standing without support. There is also a European aftermath that lands on the requester without him being a party to it. The market surveillance authority informs the Commission and the other Member States, and after 15 calendar days without objection the authorisation is deemed justified. If an objection is raised, by a Member State or by the Commission, the Commission enters into consultations, the operators concerned are consulted and the Commission decides. If it considers the authorisation unjustified, the market surveillance authority withdraws it. For the organisation that means: an authorisation is not firm for the first fifteen days, and it stays withdrawable afterwards. Plan for those two moments, and make sure the conformity assessment genuinely continues in the meantime, because the text names no maximum duration and ties the limited period only to the completion of those procedures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat this route as a contingency plan and not as a planning option. Establish, before you need it, whether it is open to you at all: if your system sits in a product from Section A of Annex I, paragraph 7 closes it and you look for the derogation in your sectoral framework. If it is open, draft the reasoning document now: which of the four exceptional reasons you invoke, on which facts, why delay is not possible, and why this system in particular. Add to it the evidence that the system complies with the requirements of Section 2, because without that conclusion the market surveillance authority cannot issue the authorisation. Record where the conformity assessment stands and what still has to happen, with an end date, and name the person who carries that procedure through while the system runs. If you prepare for the reversed order of paragraph 2, that comes with an exit plan written in advance: which decisions, files, alerts and derived datasets count as results and outputs, how they can be traced per system version, who discards them, within what period, and what happens to decisions that rested on them. Put the fifteen calendar days after the notification of paragraph 3 in your calendar as the moment the authorisation first counts as justified, and reckon with withdrawal after that. Finally, set out in supplier contracts who submits the request, who supplies the reasoning and who bears the cost if the authorisation is refused or withdrawn.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43(1), (2) and (4); Article 47(1); Article 48(1); Article 49(1); Article 79(1); Chapter III, Section 5, and Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-46-derogation-from-conformity-assessment","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 46 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/46","label":"Read Article 46 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-49-registration","legacy_id":"raip:obligation:article-49-registration","type":"obligation","slug":"article-49-registration","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"95cd9f806f657817dbdc6e5aa1c1b74b37239b8513edc6ad054fd87eaf7b858f","label":"Article 49: registration in the EU database before the system reaches the market","summary":"The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-49-registration-dossier"],"control_ids":["praxikon:eu:ai-act:control:article-49-pre-market-registration-gate"],"template_ids":["praxikon:eu:ai-act:template:article-49-legal-text"],"conditions":[{"id":"article-49-route-secure-section","operator":"any","description":"Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it."},{"id":"article-49-scope-provider","operator":"any","description":"Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3)."},{"id":"article-49-scope-public-deployer","operator":"any","description":"Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III."},{"id":"article-49-timing","operator":"all","description":"Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used."}],"exceptions":[{"id":"article-49-exception-annex-iii-point-2","operator":"not","description":"This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database."}],"statements":[{"kind":"editorial_interpretation","text":"Two readings existed of the date on this object, and Chef chose between them on 6 September 2026. Article 49 sits in Section 5 of Chapter III, and the third paragraph of Article 113 names a Section of Chapter III twice: point (b) names Section 4 and sets it at 2 August 2025, and point (c) names Sections 1, 2 and 3, with the exception of Article 6(5). Section 5 appears in neither point, nor in point (a) or point (d). Article 49 therefore falls under the general date in the second paragraph, and that is the date this object carries: 2 August 2026. Whoever places an Annex III system on the market today without registering is late, not early. The practical reading is not written away but sits alongside it: the duty only acquires an object once a high-risk AI system exists, and that status arises through Article 6(2) and Annex III on 2 December 2027, the date named in point (c) of the third paragraph as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744. That date sits in high_risk_regime_from and the ground of the chosen date in timing_basis. The decision is recorded in data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"official_fact","text":"Paragraph 1 provides that, before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71. Paragraph 2 provides that, before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71. Paragraph 3 provides that, before putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that, for high-risk AI systems referred to in points 1, 6 and 7 of Annex III, in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 of this Article shall be in a secure non-public section of the EU database referred to in Article 71 and shall include only the following information, as applicable, referred to in: (a) Section A, points 1 to 10, of Annex VIII, with the exception of points 6, 8 and 9; (b) Section B, points 1 to 5, and points 8 and 9 of Annex VIII; (c) Section C, points 1 to 3, of Annex VIII; (d) points 1, 2, 3 and 5, of Annex IX. Only the Commission and national authorities referred to in Article 74(8) shall have access to the respective restricted sections of the EU database listed in the first subparagraph of this paragraph. Paragraph 5 provides that high-risk AI systems referred to in point 2 of Annex III shall be registered at national level.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Paragraph 2 is the most expensive sentence in this article and it is missed systematically. Anyone invoking the Article 6(3) exception for an Annex III system believes they have stepped out of the high-risk regime. That is true for the requirements on the system, but not for the registration: it is precisely that provider that registers itself and that system in the EU database, and does so before it is placed on the market or put into service. The exception is therefore not free. It is paid for in visibility: your name, your system and the Article 6(3) condition you rely on end up in a publicly searchable register, exactly where you thought you would stay out of sight. The mistake that follows is predictable and expensive. An organisation carries out the Article 6(3) assessment properly, documents it, and skips the registration because in its mind that belongs to the high-risk regime. The result is that the database holds no trace of a choice it did in fact make deliberately, and that a regulator meets it as a party that simply failed to register the system. The matching piece of evidence already exists in this knowledge base as the registration record for the Article 6(3) route and hangs off the Annex III obligation; the object below covers registration under paragraphs 1, 3, 4 and 5. Note the sequence, finally. Registration is a precondition, not a notification afterwards. Delivering first and registering later repairs nothing: the moment the duty is breached is the placing on the market itself.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Read Article 49 together with Article 71 and with Article 26(8), because those three form a chain that in practice stalls at its weakest point. Article 71 describes the database and says who fills in which fields; Article 49 says when that must happen and by whom; Article 26(8) turns the result into a procurement condition. That last one is the sharpest: a deployer with the status of a public authority that establishes that the system it intends to use is not registered in the EU database shall not use that system and shall inform the provider or the distributor. For a supplier that means a missing registration is not an administrative backlog but a block on the public market, and the party raising it with you is your own customer. For a public sector organisation it means the check belongs in the procurement process and not at the moment of deployment. Two routes deviate and are forgotten for exactly that reason. The first is paragraph 4: for the areas of law enforcement, migration, asylum and border control management the registration moves into a secure non-public section with a shorter list of fields, and only the Commission and the national authorities referred to in Article 74(8) can look into it. That is not an exemption but a different counter, and whoever reads it as an exemption registers nothing. The second is paragraph 5: the systems in point 2 of Annex III, critical infrastructure, are registered at national level. The Regulation does not say which national register that is, so you answer that question in national law and not here. For a grid operator or a water utility that is the difference between an existing counter and a search that only starts once the system is already running.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make registration a hard gate in the release process, before the moment of placing on the market or putting into service, not after. Work through three questions per system. First: does the intended purpose fall under a point of Annex III, and if so, under which point. Second: are you relying on Article 6(3). If you are, the registration in paragraph 2 is your duty and not your choice, and you register yourself and that system, together with the condition you rely on. Third: if it concerns point 2 of Annex III, the registration does not go to the EU database but to national level, and you locate that counter before you need the system. If you are a public sector organisation, do not only register yourself but also select the system and register its use, and build the Article 26(8) check into your procurement process: no deployment as long as the provider entry is not in the database, with a written notification to the provider or the distributor where it is missing. If you supply into the areas of law enforcement, migration, asylum or border control management, record that your registration runs through the secure non-public section and which limited fields go into it. Keep, per system, the registration number, the date of registration and the name of the person who submitted it, together with the system version the entry relates to, and update that entry as soon as the intended purpose, the status or the conformity documentation changes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-49-registration","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 49 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/49","label":"Read Article 49 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis","legacy_id":"raip:obligation:article-4a-bias-testing-legal-basis","type":"obligation","slug":"article-4a-bias-testing-legal-basis","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ffee7eb28c48cc8a2586f097f3abec38cbe7590c73e15b9845f9295f8f095d4c","label":"Article 4a: legal basis for bias testing with special categories of personal data","summary":"Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).","topics":["fundamental-rights","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are open here, and the risk runs the other way round than with a right such as Article 86: a broad reading here benefits the controller and not the data subject, because this concerns data on ethnicity, health, religion, trade union membership and sexual orientation. Where in doubt the narrow reading is therefore the safe one. First, the reach of \"other AI systems and models\" in paragraph 2, which on its face covers any AI system and any model and for which no delimitation exists. We read it on its face, but with the threshold in paragraph 2, point (a), as the real boundary: without a consequence for health and safety, fundamental rights or prohibited discrimination there is no basis. A defensible alternative reading is that paragraph 2 is confined to systems comparable to the examples in recital 9, such as scoring tools for permits and public services. Second, the relationship with Article 9 GDPR. Recital 9 states that the extension is subject to the same limitations, conditions and safeguards and thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, so we read Article 4a as the Union law measure that point requires, with the safeguards carried by the six conditions themselves. The counterargument stands against that and has not gone away, but it has narrowed since 27 July 2026: the anchoring sits in a recital and not in the article, and the article itself designates no ground from Article 9(2). What no longer supports that counterargument is Article 2(7). Until 27 July 2026 that paragraph left the GDPR unaffected without reservation, but it was replaced by Article 1, point 2(b), of Regulation (EU) 2026/1744 and now reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The Union legislature therefore carved the reservation out for Article 4a precisely, which points towards reading Article 4a as the Union law measure itself rather than a mere cross-reference to the GDPR. Anyone citing this object while quoting the former wording of Article 2(7) is quoting a replaced provision. A defensible alternative reading remains that a national or Union measure with specific safeguards is still needed alongside it, but it now rests only on the absence of an express designation in the article itself. On the date from which the basis operates, part is settled and part is not. What is settled is what recital 9 says, namely that the basis should apply from the date of entry into application of Regulation (EU) 2024/1689; that has been read and is not a house reading. What remains open is which date this object therefore carries. We hold to 27 July 2026, the day Article 4a entered the text, because a basis that was not yet there was in fact not available. The alternative reading follows recital 9 literally and lets the basis reach back to the date of application of the base Regulation. That difference is not academic for anyone who has to justify processing from that period. The editorial statement below marks that choice as our inference.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted"],"action_ids":["praxikon:eu:ai-act:action:record-bias-testing-legal-basis"],"evidence_ids":["praxikon:eu:ai-act:evidence:bias-testing-necessity-record"],"control_ids":["praxikon:eu:ai-act:control:bias-testing-data-deletion"],"template_ids":["praxikon:eu:ai-act:template:article-4a-legal-text"],"conditions":[{"id":"article-4a-paragraph-1-high-risk-provider-only","operator":"all","description":"Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2."},{"id":"article-4a-paragraph-2-wider-circle-with-harm-threshold","operator":"all","description":"Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it."},{"id":"article-4a-cumulative-conditions","operator":"all","description":"The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data."}],"exceptions":[{"id":"article-4a-no-duty-to-test","operator":"not","description":"Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, to the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur: (a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data; (b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation; (c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations; (d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties; (e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and (f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 2 provides that providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that: (a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and (b) all of the conditions and safeguards set out in paragraph 1 are applied. Paragraph 2 closes with a separate subparagraph: this paragraph does not create any obligation to conduct such bias detection and correction. Article 4a has no paragraph 3.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts Article 4a into Regulation (EU) 2024/1689 by Article 1, point 6, and deletes Article 10(5) by Article 1, point 9(b). The same point 9 replaces Article 10(1) and Article 10(6) so that they now refer to the quality criteria in Article 4a(1). The basis therefore no longer sits with the requirements for high-risk systems in Chapter III, but as a standalone article in Chapter I, immediately after Article 4, while Article 10 refers back to it from the outside. In the Dutch language version of the Official Journal the inserted article is numbered \"artikel 4 bis\"; \"Article 4a\" is the English numbering of the same provision.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same amending Regulation replaces Article 2(7) of Regulation (EU) 2024/1689 by Article 1, point 2(b). Since 27 July 2026 that paragraph reads: \"Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.\" The previous version of that paragraph carried no such reservation for Article 4a.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 9 of Regulation (EU) 2026/1744 states that bias detection and correction constitute a substantial public interest, that the extended legal basis is subject to the same limitations, conditions and safeguards as the existing Article 10(5), and that this thereby ensures compliance with Article 9(2), point (g), of Regulation (EU) 2016/679, Article 10(2), point (g), of Regulation (EU) 2018/1725 and Article 10, point (a), of Directive (EU) 2016/680. The same recital states that the legal basis established by Article 4a should apply from the date of entry into application of Regulation (EU) 2024/1689, so as to enable providers of high-risk AI systems lawfully to undertake bias detection and correction activities in preparation for compliance with the requirements for high-risk AI systems. Article 4 of the amending Regulation governs only entry into force on the third day following publication and provides for no deferred application; the amended Article 113, third paragraph, point (a), provides that Chapters I and II apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026. Article 4a sits in Chapter I and falls outside that exception.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Three things matter more in practice than the relocation itself. The first is that this article instructs you to do nothing. Paragraph 2 says so in as many words, and no date by which anything must be done belongs with it either. The second, and the more dangerous misreading, is that the move into Chapter I means you may now start collecting sensitive attributes because you want to run fairness measurements. What has widened is the set of parties, not the room inside the basis: recital 9 expressly states that the same limitations, conditions and safeguards apply as under the former Article 10(5). In practice it therefore starts with a written justification of why synthetic or anonymised data do not suffice, and not with assembling a dataset. The third is the condition that bites hardest and appears in no summary: point (d) provides that the data are not transmitted, transferred or otherwise accessed by other parties. That is in effect a ban on outsourcing. An external fairness vendor, a bias auditing firm, a research partner or a cloud party that can reach the data itself does not fit inside this basis, however good the contract. Anyone who intended to buy in their bias testing must run it in house here, or work with data that are not a special category. Finally, watch your own documentation: records of processing, data protection impact assessments and AI policy documents that refer to Article 10(5) have been referring to a deleted provision since 27 July 2026. The same holds for documents citing Article 2(7) to argue that the GDPR prevails without qualification: that paragraph too has been replaced and now expressly reserves Articles 4a and 59. Two dates to close on, and the second is our inference rather than source text. Article 4a sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025, but the provision only entered the text on 27 July 2026; we therefore treat 27 July 2026 as the day the basis actually became available, while recital 9 states that it should apply from the date of entry into application of Regulation (EU) 2024/1689. Finally, note that the requirements in Article 10(2), points (f) and (g), which paragraph 1 refers to, themselves only start to apply on 2 December 2027 for Annex III systems and on 2 August 2028 for Annex I systems. The basis therefore deliberately runs ahead of the duty you use it for, exactly as recital 9 intends.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 2(b), replacing Article 2(7)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Carry out the data protection impact assessment before you start. Processing special categories at scale for bias testing engages Article 35 GDPR in almost every case, and Article 4a does not remove that assessment: it supplies the legal basis, not the risk appraisal. Then record, per processing operation, which paragraph of Article 4a you rely on, for which system or model, why synthetic or anonymised data do not suffice, which technical and organisational safeguards apply, who has access and at what point the data are deleted. In the same pass, review your record of processing activities, your impact assessments and your AI policy documents for references to Article 10(5) and replace them with Article 4a. Set the deletion moment as a monitored deadline rather than an intention, verify that no external party can reach the data, and align the justification with your data protection officer.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-4a-bias-testing-legal-basis","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted Article 4a on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-5-prohibited-practices","legacy_id":"raip:obligation:article-5-prohibited-practices","type":"obligation","slug":"article-5-prohibited-practices","version":"1.0.0","effective_at":"2025-02-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"674c4b85d1cf177b2ab9256989e18b2d685fdb69388f02f22bcc8cebd4f5faf8","label":"Article 5: prohibited practices","summary":"The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.","topics":["prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-5-screen"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-5-screening-record"],"control_ids":["praxikon:eu:ai-act:control:article-5-intake-gate"],"template_ids":["praxikon:eu:ai-act:template:article-5-legal-text"],"conditions":[{"id":"article-5-listed-practice","operator":"any","description":"Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement."}],"exceptions":[{"id":"article-5-narrow-exceptions","operator":"not","description":"The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance."}],"statements":[{"kind":"official_fact","text":"The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5, Article 99(3) and Article 113(a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment to Article 5 and transition to 2 December 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(a)-(h)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5 read with Article 6 classification order","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-5-prohibited-practices","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 5 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-50-transparency","legacy_id":"raip:obligation:article-50-transparency","type":"obligation","slug":"article-50-transparency","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"239fbac0e4728dc239352b2f88b199c3cc098082ff72e2972b4b5e8a2b121406","label":"Article 50: transparency","summary":"Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-50-disclosure"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-50-implementation-record"],"control_ids":["praxikon:eu:ai-act:control:article-50-release-check"],"template_ids":["praxikon:eu:ai-act:template:article-50-checklist"],"conditions":[{"id":"article-50-direct-interaction","operator":"any","description":"An AI system is intended to interact directly with natural persons."},{"id":"article-50-synthetic-content","operator":"any","description":"The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario."}],"exceptions":[{"id":"article-50-obvious-interaction","operator":"not","description":"The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context."},{"id":"article-50-legacy-marking-grace","operator":"not","description":"Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026."}],"statements":[{"kind":"official_fact","text":"Article 50 applies since 2 August 2026. The precise duty differs by scenario: direct AI interaction, machine-readable marking, emotion recognition or biometric categorisation, deepfakes and certain public-interest text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1)-(5) and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A generic rule that all AI content must always carry a visible label is too broad. First classify the specific Article 50 scenario.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Final guidelines, scope by Article 50 paragraph","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each system, record the applicable paragraph, responsible actor, implemented disclosure or marking and how it was tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Implementation guidance for providers and deployers","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-50-transparency","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","label":"Final Commission guidelines"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification","legacy_id":"raip:obligation:article-52-systemic-risk-classification","type":"obligation","slug":"article-52-systemic-risk-classification","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fda72f0c021ed141ad0881c569a2e4d7e59aefdcec7c95a562b9f547352a974e","label":"Article 52: notification of a GPAI model with systemic risk","summary":"The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"settled","interpretation_note":null,"obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply"],"action_ids":["praxikon:eu:ai-act:action:notify-systemic-risk-threshold","praxikon:eu:ai-act:action:request-systemic-risk-reassessment"],"evidence_ids":["praxikon:eu:ai-act:evidence:systemic-risk-notification-file"],"control_ids":["praxikon:eu:ai-act:control:systemic-risk-notification-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-52-legal-text"],"conditions":[{"id":"article-52-notification-trigger","operator":"all","description":"Applies to the provider of a general-purpose AI model as soon as that model meets the condition in Article 51(1), point (a): high impact capabilities, which under Article 51(2) are presumed where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. The two-week period runs from the moment that requirement is met or it becomes known that it will be met. The second route to systemic risk, a Commission designation under Article 51(1), point (b), or Article 52(4), is not covered here: Article 52(1) refers only to point (a)."}],"exceptions":[{"id":"article-52-legacy-models-transitional","operator":"not","description":"For general-purpose AI models placed on the market before 2 August 2025, Article 111(3) provides that the provider shall take the necessary steps to comply with the obligations of this Regulation by 2 August 2027. For those models the governing date is therefore 2 August 2027 and not the two-week period."}],"statements":[{"kind":"official_fact","text":"Article 51(1), point (a), classifies a general-purpose AI model as a model with systemic risk where it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; Article 51(2) provides that a model is presumed to have such capabilities where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. Article 51(1), point (b), reads in full: based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. The requirement of equivalent capabilities or impact and the anchoring in Annex XIII are therefore part of the norm and not only of the procedure. Article 51(3) provides in addition: the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. The 10^25 threshold above is therefore movable; as long as that act does not exist, the threshold applies as it stands in paragraph 2. See data/ai-act/delegated-acts.json, key praxikon:eu:ai-act:delegated-act:article-51-3-thresholds. Article 52(1) refers only to point (a) and provides that the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met, and that the notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. Paragraph 2 allows the provider to present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although the model meets that requirement, it does not present systemic risks due to its specific characteristics and should therefore not be classified as a general-purpose AI model with systemic risk. Paragraph 3 provides that where the Commission concludes that those arguments are not sufficiently substantiated and the provider was not able to demonstrate that the model does not present systemic risks due to its specific characteristics, it shall reject those arguments and the model shall be considered to be a general-purpose AI model with systemic risk. Paragraph 4 empowers the Commission to designate a model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of the criteria set out in Annex XIII, and empowers it to adopt delegated acts in accordance with Article 97 to amend Annex XIII by specifying and updating the criteria set out in that Annex. Paragraph 5 provides that upon a reasoned request of a provider whose model has been designated pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII, that such a request shall contain objective, detailed and new reasons that have arisen since the designation decision, that providers may request reassessment at the earliest six months after the designation decision, and that where the Commission decides to maintain the designation a further six months must pass. Paragraph 6 provides that the Commission shall ensure that a list of general-purpose AI models with systemic risk is published and kept up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 111 states that the cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Recital 112 states that the provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a model will meet the requirements that lead to the presumption, and that this is especially relevant in relation to the threshold of floating point operations because training takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers are able to know if their model would meet the threshold before the training is completed. The same recital states that in the context of that notification the provider should be able to demonstrate that the model exceptionally does not present systemic risks, that the information allows the AI Office to anticipate the placing on the market of models with systemic risks, and that it is especially important for models planned to be released as open-source. Recital 113 states that the Commission should be empowered to designate a model where it becomes aware that the model meets the requirements which previously had either not been known or of which the provider failed to notify it, and that a system of qualified alerts from the scientific panel should exist in addition to the monitoring activities of the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(3) provides that providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) state in point (63) that a downstream modifier is considered to be the provider of the modified model where the training compute used for the modification is greater than a third of the training compute of the original model, and in point (64) that where the downstream modifier cannot know and cannot estimate the original value, that threshold is replaced by a third of 10^25 FLOP where the original model is a model with systemic risk and otherwise by a third of 10^23 FLOP. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1). The guidelines are not binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission enforcement powers for general-purpose AI models and the fine regime of Article 101 have been active since 2 August 2026. Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only duty in this chapter with a numbered deadline, and two weeks is short. Other duties are also tied to a clock, only without a figure: Article 55(1), point (c), requires serious incidents to be reported to the AI Office without undue delay. The question here is therefore not whether you can notify, but whether you see the threshold being crossed in time. Recital 112 leaves little room to push that back: the legislator expressly assumes that the upfront allocation of compute lets you know before training ends that you will meet the threshold. The remaining edge question is how firm that knowledge is for a run not yet allocated, and it is small next to the duty itself. Four things are missed in practice. The first is the transitional rule: if your model was already on the market before 2 August 2025, Article 111(3) gives you until 2 August 2027, and that is the difference between two weeks and two years. The second is the reach of the trigger: only the threshold route of Article 51(1), point (a), starts this clock. If your model is designated by the Commission under Article 51(1), point (b), or Article 52(4), Article 55 begins without Article 52 asking anything of you. The third is the reversal in the last sentence of paragraph 1: if the Commission becomes aware of a model it was not notified about, it may designate it, and you then hold the conversation from a designation rather than from your own file. Since 2 August 2026 the Article 101 fine regime stands behind that. The fourth is the rebuttal route in paragraph 2: those arguments belong with the notification and not after it, so they must already be ready at the moment you notify. Once designated, only paragraph 5 remains, and that route is slow: six months after the decision at the earliest, and only with objective, detailed and new reasons that have arisen since it. The text names the Commission as addressee; recital 112 and Article 55(1), point (c), name the AI Office, which performs this task within the Commission. For an organisation that merely uses an external model this article does not bite: it addresses the provider of the model. That does not put further development out of reach: under point (71) of guidelines C(2025) 5045 final, a party that becomes the provider of a systemic-risk model through a modification must notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model and not merely a user, and whether your model was already on the market before 2 August 2025, because the date in Article 111(3) then applies instead of the two-week period. If you are the provider of a new model, record the planned and the consumed training compute per training run, including pre-training, synthetic data generation and fine-tuning, because recital 111 counts all three. Agree who notifies once the threshold comes into view, so the two-week period is not spent finding an owner, and tie that to the moment compute is allocated rather than to the end of the run. Keep the reasoning with which you would argue that the model does not present systemic risks ready before you notify, because it belongs with the notification. If you have already been designated under paragraph 4, build deliberately towards objective, detailed and new reasons that have arisen since the designation decision, because only those get you to a reassessment after six months. Retain the notification, the substantiation sent with it, any reassessment request and the Commission response as a living file per model version.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-52-systemic-risk-classification","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines C(2025) 5045 final on the scope of the GPAI obligations"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-53-gpai","legacy_id":"raip:obligation:article-53-gpai","type":"obligation","slug":"article-53-gpai","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"55f22a1c21f936ec956fc61f7db4f29defb4524294046799c13af57745cd8b36","label":"Article 53: GPAI model providers","summary":"Documentation, information, copyright and transparency duties for providers of general-purpose AI models.","topics":["gpai"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:gpai-document"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-compliance-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-documentation-change-control"],"template_ids":["praxikon:eu:ai-act:template:gpai-guide"],"conditions":[{"id":"gpai-union-market","operator":"all","description":"The party is a provider of a GPAI model placed on the Union market."},{"id":"gpai-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the duties apply from that time. Models placed on the market before 2 August 2025 must comply by 2 August 2027."}],"exceptions":[{"id":"gpai-open-source-limited-exception","operator":"not","description":"The open-source exception is limited and retains, among other things, the copyright policy and public training-content summary. Additional duties apply to models with systemic risk."}],"statements":[{"kind":"official_fact","text":"Article 53 applies since 2 August 2025 to new GPAI models. Providers maintain technical documentation, provide information to downstream providers, operate a Union copyright policy and publish a sufficiently detailed summary of training content.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1), Annex XI and Annex XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable obligations by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"An organisation merely using an external GPAI model does not thereby automatically become a GPAI model provider. First determine its role in the value chain.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Scope and provider qualification guidance","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record model versions, role qualification, documentation owners, downstream information, copyright policy and training summary in one change-controlled file.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53 and Annexes XI-XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-53-gpai","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative","legacy_id":"raip:obligation:article-54-gpai-authorised-representative","type":"obligation","slug":"article-54-gpai-authorised-representative","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0c470c29e8f0c2ad222dc0517b6a9437615474bfc6429e9c37b90eb35572d5c5","label":"Article 54: authorised representative of a provider of a GPAI model","summary":"A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.","topics":["gpai","value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-53-gpai","praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-gpai-authorised-representative"],"evidence_ids":["praxikon:eu:ai-act:evidence:gpai-representative-mandate-file"],"control_ids":["praxikon:eu:ai-act:control:gpai-mandate-review"],"template_ids":["praxikon:eu:ai-act:template:article-54-legal-text"],"conditions":[{"id":"article-54-scope","operator":"all","description":"Applies where the model qualifies as a general-purpose AI model within the meaning of Article 3(63), its provider is established in a third country, and that model is placed on the Union market. The appointment is made by written mandate within the meaning of Article 3(5), which is not only given but also accepted, and it is made before the model is placed on the market. The moment at which the latter occurs is fixed less sharply for a model than for a system; see the editorial interpretation."},{"id":"article-54-market-date-transition","operator":"any","description":"For models placed on the market from 2 August 2025, the appointment duty applies from that moment. Providers of models placed on the market before 2 August 2025 shall, under Article 111(3), take the necessary steps to comply with the obligations of the Regulation by 2 August 2027."}],"exceptions":[{"id":"article-54-open-source-exception","operator":"not","description":"Paragraph 6 excludes the obligation for providers of AI models released under a free and open-source licence that allows access, usage, modification and distribution, and whose parameters, including the weights, the information on the model architecture and the information on model usage, are made publicly available. That exception falls away as soon as the model presents a systemic risk. Whether a given release qualifies is a factual test that has not been settled anywhere; we read it narrowly, so a partially public release does not qualify."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that, prior to placing a general-purpose AI model on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union. Paragraph 2 provides that the provider shall enable its authorised representative to perform the tasks specified in the mandate received from the provider. Paragraph 3 provides that the authorised representative shall perform the tasks specified in the mandate received from the provider, that it shall provide a copy of the mandate to the AI Office upon request in one of the official languages of the institutions of the Union, and that for the purposes of the Regulation the mandate shall empower the authorised representative to carry out the following tasks: (a) verify that the technical documentation specified in Annex XI has been drawn up and all obligations referred to in Article 53 and, where applicable, Article 55 have been fulfilled by the provider; (b) keep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities, for a period of 10 years after the general-purpose AI model has been placed on the market, and the contact details of the provider that appointed the authorised representative; (c) provide the AI Office, upon a reasoned request, with all the information and documentation, including that referred to in point (b), necessary to demonstrate compliance with the obligations in that Chapter; (d) cooperate with the AI Office and competent authorities, upon a reasoned request, in any action they take in relation to the general-purpose AI model, including when the model is integrated into AI systems placed on the market or put into service in the Union. Paragraph 4 provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities, on all issues related to ensuring compliance with the Regulation. Paragraph 5 provides that the authorised representative shall terminate the mandate if it considers or has reason to consider the provider to be acting contrary to its obligations pursuant to the Regulation, and that in such a case it shall also immediately inform the AI Office about the termination of the mandate and the reasons therefor. Paragraph 6 provides that the obligation set out in that Article shall not apply to providers of general-purpose AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, unless the general-purpose AI models present systemic risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 3(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 113(3)(b) provides that Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Article 54 sits in Chapter V and therefore applies from 2 August 2025.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. Article 101 is excluded by Article 113(3)(b) from the earlier application of Chapter XII and has therefore applied since 2 August 2026. The obligation in Article 54 has thus applied since 2 August 2025, while the Commission fining power behind it exists only since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in the Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article touches two parties that rarely see themselves that way. The first is the model provider outside the Union that assumes nothing is required until a European customer asks: paragraph 1 places the appointment before the placing on the market, so the representative should exist before the first user in the Union can access the model. The second is the European party that accepts the mandate. It is not stepping into a mailbox role, but note how paragraph 3 is built: the first sentence obliges it to perform the tasks the mandate assigns to it, and only then does the article list what the mandate empowers it to do. Points (a) to (d) are therefore mandate content and empowerment, and its duty runs through them. That is where this article leaves its sharpest question open: is a representative that accepts a mandate omitting task (a) or (b) itself in breach, or does the failure rest entirely with the provider that drew up the mandate. We read paragraph 3 as making the list mandatory minimum content, so that a mandate lacking it does not satisfy the article, which leaves the provider answerable under paragraph 1 and the representative answerable for what it did accept. A defensible alternative reading is that a representative signing without those powers takes on a task it cannot discharge and thereby falls short itself. So do not assume the ten year retention in point (b) rests on you automatically, or automatically does not; write it out. Paragraph 5 closes this off in a way that is often missed: a representative that considers, or has reason to consider, that the provider is breaching its obligations terminates the mandate and immediately informs the AI Office. That is a duty rather than a power, and it calls for access to the documentation agreed in advance and for a moment at which that access is tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Three things about the timeline and the scope. First, the difference between duty and enforcement: the duty has applied since 2 August 2025, but Article 101 is excluded from the earlier application, so the Commission can only fine since 2 August 2026. For a provider outside the Union discovering today that it has no representative, that means: in breach for well over a year, and now also exposed to a fine. Second, the relationship with Article 22. That article carries the same figure for high-risk AI systems, starting on 2 December 2027 and 2 August 2028; Article 54 is the separate route for general-purpose AI models and has applied since 2 August 2025. Anyone looking up the role of authorised representative finds both and needs to know which route applies. Third, the trigger in paragraph 1. The Regulation fixes the moment of placing on the market less sharply for a model than for a system, and for a model made available only through an interface from a third country there is no case law. We read the duty as starting once the model is made available to users in the Union in the course of a commercial activity, because paragraph 1 attaches to placing on the market and not to establishment in the Union. A defensible alternative reading is that making a model available through an interface is not placing the model itself on the market, so that the duty only arises on an actual supply of the model.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model or only a user, because only the provider appoints. If you are established outside the Union, put the mandate in writing before the model becomes available here, and write the four tasks in paragraph 3 into it expressly, together with the access to the Annex XI documentation and the point of contact under paragraph 4. If your model was already on the market before 2 August 2025, work to 2 August 2027 rather than to today. If you are only now discovering that there is no representative, assume the duty has run since 2 August 2025 and that the Commission has been able to fine since 2 August 2026; remedy first and record when you did. If you accept a mandate, agree in advance how you carry out the verification in paragraph 3(a), who holds the copy for ten years, and at what moment you test whether termination under paragraph 5 is called for.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 54(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 101(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-54-gpai-authorised-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 54 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/54","label":"Read Article 54 in the AI Act Explorer"},{"relation":"related","href":"/en/ai-act/artikel/53","label":"Article 53: the duties the representative verifies"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines for GPAI model providers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk","legacy_id":"raip:obligation:article-55-gpai-systemic-risk","type":"obligation","slug":"article-55-gpai-systemic-risk","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589","label":"Article 55: GPAI models with systemic risk","summary":"Additional duties for the most capable general-purpose AI models, on top of Article 53.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record"],"control_ids":["praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control"],"template_ids":["praxikon:eu:ai-act:template:article-55-gpai-systemic-risk-legal-text"],"conditions":[{"id":"article-55-gpai-systemic-risk-scope","operator":"all","description":"The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission."}],"exceptions":[{"id":"article-55-gpai-systemic-risk-exception","operator":"not","description":"The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance."}],"statements":[{"kind":"official_fact","text":"Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 55 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice","legacy_id":"raip:obligation:article-56-gpai-codes-of-practice","type":"obligation","slug":"article-56-gpai-codes-of-practice","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6e6afc9742736b52408f8c38c9435fc8be751641392f5d0b5d57a34afee4c1c","label":"Article 56: codes of practice for general-purpose AI models","summary":"The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.","topics":["governance","gpai","gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record"],"control_ids":["praxikon:eu:ai-act:control:article-56-code-commitment-review"],"template_ids":["praxikon:eu:ai-act:template:article-56-legal-text"],"conditions":[{"id":"article-56-scope-gpai-provider","operator":"any","description":"Arises for the provider of a general-purpose AI model: it may be invited under paragraph 3 to participate in the drawing up of a code of practice, and under paragraph 7 to adhere to a code of practice."},{"id":"article-56-scope-value-chain","operator":"any","description":"Arises for other stakeholders: paragraph 3 names civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, that may support the process."}],"exceptions":[{"id":"article-56-limited-adherence-without-systemic-risk","operator":"not","description":"Paragraph 7 provides that for providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code. A provider without a systemic-risk model therefore does not have to sign up to the systemic-risk part in order to rely on the code."},{"id":"article-56-voluntary-instrument","operator":"not","description":"Article 56 does not impose a separate obligation on the provider. Paragraphs 3 and 7 speak of inviting, not of requiring, and the obligations themselves remain those of Articles 53 and 55. Not signing is therefore not an infringement of Article 56."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches. Paragraph 2 provides that the AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues: (a) the means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments; (b) the adequate level of detail for the summary about the content used for training; (c) the identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate; (d) the measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain. Paragraph 3 provides that the AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that the AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level. Paragraph 5 provides that the AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants. Paragraph 6, as replaced by Article 1, point (21), of Regulation (EU) 2026/1744, provides that the Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice. The power to approve a code of practice by implementing act and give it general validity within the Union, which sat in the second subparagraph of paragraph 6 until 27 July 2026, lapsed with that replacement. Paragraph 7 provides that the AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (21), replacing Article 56(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 8 provides that the AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards. Paragraph 9 provides that codes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7. The second subparagraph of paragraph 9 provides that if, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A code of practice is a voluntary instrument, and that word does all the work here. Signing creates no new obligation: your obligations remain those of Articles 53 and 55, and Article 56 changes nothing about them. Not signing is not an infringement either, because paragraphs 3 and 7 speak of inviting and not of requiring. What does shift is the burden of proof. A provider adhering to a code can point to a shared elaboration, assessed by the AI Office and the Board, when a regulator asks how it keeps its documentation up to date, how detailed its summary about the training content is, or how it assesses and manages systemic risk. A provider that does not sign has to write that elaboration itself and defend it itself, up to and including the question why its own approach is at least as good. That is not a legal difference in the norm, but it is a large difference in what is on the table when something is asked. Two things that are often conflated here. First: paragraph 7 allows a provider without a systemic-risk model to limit itself to the obligations in Article 53, unless it explicitly declares its interest in the full code. Partial participation is therefore an expressly foreseen choice and not half-heartedness. Second: paragraph 9 puts a stick behind the door that does not rest on you but does reach you. If no code comes about, or if the AI Office deems it inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. Those rules, unlike a code, are not voluntary.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Precision is in order about the state of play, because this is where the market overstates the most. It is established that the General-Purpose AI Code of Practice was published on 10 July 2025; that code is archived in this repository as three chapter PDF files, on transparency, copyright and safety and security, and it is present as a source record in this knowledge base. Whether an approving implementing act followed was not established for the period up to 27 July 2026, and after that date it is no longer the right question: paragraph 6 no longer carries that power. Since then the question is whether the Commission has published its assessment of adequacy. That too is not established here, and for as long as that is the case you must not read anywhere that the code has been approved or has general validity within the Union. That distinction is not a formality: a published code is a text you can voluntarily adhere to, a code approved by implementing act is on top of that an instrument with general validity in the Union. Anyone mistaking the first for the second overestimates what a signature buys and underestimates what they still have to record themselves. The content of the three chapters was also not read in this build, so nothing in this object says anything about what exactly is in them. In practice that means the following. Check the approval status yourself and by date before you rely on the code in a conversation with a regulator or a customer, and record which version of the code and which chapter your adherence relates to. A code may be reviewed and adapted under paragraph 8, in particular in light of emerging standards, so a reliance on the code without a version reference ages on its own.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the question whether you adhere to a code of practice as a decision that is taken and recorded, not as something that happens by itself. Record per model: do you adhere to a code, to which version and to which chapter, and if not, which elaboration of your own you apply instead for the issues named in paragraph 2, namely keeping the information in Article 53(1), points (a) and (b), up to date, the level of detail of the summary about the training content, and, where you offer a systemic-risk model, the identification and management of systemic risk. Decide explicitly whether under paragraph 7 the obligations in Article 53 are enough for you or whether you join the full code, and note that choice with a date and an authorised signatory. Before you rely on a code externally, check whether the Commission has published its assessment of adequacy under the amended paragraph 6, and claim no more than you can point at that moment. Do not ask for an approving implementing act: that power has not existed since 27 July 2026, and asking for it is asking for a decision nobody can take any more. Finally, put a review moment in your own calendar: paragraph 8 provides for review and adaptation of codes in light of emerging standards, and paragraph 9 allows the Commission to lay down common rules where a code fails to appear or is deemed inadequate, and both change what you are relying on without anyone calling you.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 56(1)-(9)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:gpai-code-of-practice","source_locator":"Code of Practice for General-Purpose AI, 10 July 2025","source_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-56-gpai-codes-of-practice","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 56 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/56","label":"Read Article 56 in the AI Act Explorer"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","label":"General-Purpose AI Code of Practice at the European Commission"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes","legacy_id":"raip:obligation:article-57-regulatory-sandboxes","type":"obligation","slug":"article-57-regulatory-sandboxes","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2706a2688e0c2d602f40bf5b061f6dba9310214d79ef9a74b47600c72bf69226","label":"Article 57: AI regulatory sandboxes","summary":"Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-57-sandbox-application-and-plan"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-57-written-proof-and-exit-report"],"control_ids":["praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield"],"template_ids":["praxikon:eu:ai-act:template:article-57-regulatory-sandboxes-legal-text"],"conditions":[{"id":"article-57-regulatory-sandboxes-scope","operator":"all","description":"Relevant where you are a provider or prospective provider of an innovative AI system that you want to develop, train, test or validate before placing it on the market or putting it into service, and you want up-front certainty about classification or about how you meet the requirements of this Regulation."}],"exceptions":[{"id":"article-57-regulatory-sandboxes-exception","operator":"not","description":"Participation is voluntary. Article 57 places the duty on the Member State to provide a sandbox, not on you to join one. A Member State may also fulfil that duty by participating in an existing sandbox with equivalent national coverage. Article 57(4) leaves other regulatory sandboxes established under Union or national law unaffected."}],"statements":[{"kind":"official_fact","text":"Article 57(1) requires Member States to ensure that their competent authorities establish at least one AI regulatory sandbox at national level. The text of Regulation (EU) 2024/1689 as published in the Official Journal provides that the sandbox shall be operational by 2 August 2026, and that wording still stands unchanged on 9 August 2026 in the article text published by the European Commission. The timeline the European Commission publishes after the Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 places the milestone at 2 August 2027 instead, stating \"Member States should have at least one AI regulatory sandbox per country operational\". The consolidated text of Article 57(1) after the Omnibus has not been verified at article level; rely on the consolidated version on EUR-Lex for the exact date. Chapter VI, which contains Article 57, is not among the exceptions in Article 113 and therefore applies since 2 August 2026. Article 57(1) further provides that the obligation may also be fulfilled by participating in an existing sandbox, in so far as that participation provides an equivalent level of national coverage. Article 57(5) defines the sandbox as a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time, pursuant to a specific sandbox plan agreed between the provider or prospective provider and the competent authority, before the system is placed on the market or put into service. Such sandboxes may include testing in real world conditions supervised therein. Article 57(15) requires the AI Office to make publicly available, and keep up to date, a list of planned and existing sandboxes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The common mistake is to read the sandbox as a delay or an exemption. It is neither. Article 57(11) leaves the competent authority's supervisory and corrective powers fully intact and expressly empowers it to suspend your testing or your participation, temporarily or permanently, where risks cannot be effectively mitigated. A sandbox is useful for exactly one profile: you are building an AI system that is likely to fall under Annex III, you are uncertain about its classification or about how to meet Chapter III, Section 2, and you want that uncertainty resolved before you go to market. If you are purely a deployer buying a system, the sandbox is not your route: at most you can join as a partner of the provider under Article 58(2), point (b). Second trap: 2 August 2027 is a duty on the Member State, not on you. The date on this item is therefore 2 August 2026: from that moment Chapter VI applies and the route is open to you. You cannot hang your own preparation on that date, and the date says nothing about whether your national sandbox will actually have capacity by then. Third trap: people confuse the Article 57 sandbox with Article 60 real-world testing. These are two distinct routes with different conditions. Real-world testing can take place inside the sandbox (Article 57(5) and Article 58(4)) or outside it under Article 60, and the safeguards differ.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish your role: only providers and prospective providers can enter on their own. Then use the AI Office's published list of planned and existing sandboxes (Article 57(15)) to find the sandbox open to you, in your Member State or jointly with others. Before you apply, state exactly which uncertainty you want resolved, ideally focused on classification under Article 6 or on a specific requirement in Chapter III, Section 2. Plan for the three-month decision period that Article 58(2), point (a), requires the implementing acts to ensure, build it into your product timeline, and ask the competent authority in writing which period it currently applies. On entry, record in writing what the sandbox plan covers, and on exit request both the written proof and the exit report.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 57(1)-(17), Article 58, Article 113; as amended by Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-57-regulatory-sandboxes","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 57 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route","legacy_id":"raip:obligation:article-6-1-annex-i-product-route","type":"obligation","slug":"article-6-1-annex-i-product-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"69936813db0c35758e25c435a583907437346b30c52f1b9943517c31b41f9369","label":"Article 6(1): the product route to high risk","summary":"An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is mainly open is what condition (b) requires. The text of paragraph 1, point (b), asks whether the product must undergo a third-party conformity assessment, which reads as a reference to the procedure actually prescribed. Article 43(3), third subparagraph, as replaced by Regulation (EU) 2026/1744, points the other way: it subjects the opt-out from third-party assessment to an additional condition under this Regulation and expressly provides that classification as a high-risk AI system does not affect the choice of procedure. That presupposes such systems are high risk. The Commission draft guidelines of 19 May 2026 say the same: the fact that a manufacturer may rely on internal control based on harmonised standards does not affect classification under Article 6(1). We follow that reading and therefore assume a module A route does not take your system out of high risk where the legislature prescribed enhanced scrutiny for that product type. A defensible alternative reading holds to the letter of point (b): only those actually required to involve a third party fall under this route, and Article 43(3) concerns the procedure for an already classified system rather than classification itself. While the guidelines remain draft and the Court has not ruled, that difference in outcome is real. Second open point: the dates diverge within this route. Chapter III, Sections 1 to 3, applies from 2 August 2028, but Articles 102 to 110 apply from 27 July 2026. That range overlaps with what remains for products under Section B of Annex I but does not coincide with it: for Section B the amended Article 2(2) makes Article 6(1), Article 60a and Articles 102 to 112 applicable, so two articles more than the new point (d) brings forward. The date on this object is the Chapter III date, not that of the sectoral amendments. Third open point: machinery moved from Section A to Section B by the same amending Regulation. How the requirements land there depends on delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028 and have not yet been adopted.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-annex-i-product-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-i-product-route-record"],"control_ids":["praxikon:eu:ai-act:control:annex-i-product-route-change-gate"],"template_ids":["praxikon:eu:ai-act:template:article-6-1-legal-text"],"conditions":[{"id":"article-6-1-covered-product","operator":"all","description":"The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I. Whether the system is placed on the market independently of that product is irrelevant."},{"id":"article-6-1-third-party-assessment","operator":"all","description":"That product, or the AI system as a product itself, is required under that same harmonisation legislation to undergo a third-party conformity assessment with a view to its placing on the market or putting into service. Both conditions must be fulfilled together."}],"exceptions":[{"id":"article-6-1bis-non-safety-function","operator":"not","description":"Article 6(1a), inserted by Regulation (EU) 2026/1744, provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back as soon as failure or malfunctioning would endanger health and safety."},{"id":"article-6-1quater-non-health-safety-assessment","operator":"not","description":"Article 6(1c), as inserted, provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 43(3) was replaced by Regulation (EU) 2026/1744. The third subparagraph of the new text reads: where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by that harmonisation legislation. The first subparagraph of the same paragraph provides that the requirements set out in Chapter III, Section 2, apply to those high-risk AI systems and form part of that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(2) was replaced by Regulation (EU) 2026/1744 and reads: for AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. Articles 57, 58 and 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation. The original text named only Article 6(1), Articles 102 to 109 and Article 112, and limited the effect of Article 57 in the same way.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends Annex I: in Section A point 1 is deleted and in Section B point 21 is added, Regulation (EU) 2023/1230 on machinery. Point 1 of Section A was Directive 2006/42/EC on machinery. Machinery therefore moves from Section A to Section B. Regulation (EU) 2023/1230 is amended at the same time so that the Commission adopts delegated acts supplementing Annex III to that Regulation with health and safety requirements for AI systems classified as high risk pursuant to Article 6(1) of Regulation (EU) 2024/1689, reflecting the requirements of Chapter III, Section 2, and Articles 17, 19, 72 and 73. Those delegated acts shall apply by 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 2(1), point (e), provides that this Regulation applies to product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark. Article 25(3) provides that in the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system and shall be subject to the obligations under Article 16 under either of the following circumstances: (a) the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer; (b) the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market. Article 25(3) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The text of Article 113, third paragraph, point (c), as published in the Official Journal provides that Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces point (c) of the third paragraph of Article 113 with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The same amendment adds a point (d) to that paragraph: Articles 102 to 110 shall apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(2) was replaced and reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The inserted Article 2(13) provides that for high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection, and such limitation does not reduce the overall level of protection provided for by this Regulation. By 2 August 2027 the Commission shall adopt delegated acts specifying the systems concerned, the requirements that may be limited, the conditions and the scope.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (3), inserting Article 2(13)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For most organisations the first question is not whether their system is AI, but what function their AI component performs and which section of Annex I their product falls under. What often goes wrong is the idea that the conformity route chosen determines the classification: we apply harmonised standards, therefore internal control, therefore no third party, therefore no high risk. That reasoning does not hold. The replaced Article 43(3) attaches an additional condition under this Regulation to the opt-out and states in the same subparagraph that classification as a high-risk AI system does not affect the choice of procedure, and the draft guidelines of 19 May 2026 read Article 6(1) the same way. Where you can genuinely fall outside this route is through the inserted paragraphs 1a and 1c: a model that solely supports throughput or quality control and whose failure does not endanger health and safety, and a product that needed a third party only because of radio spectrum or electromagnetic interference. Two further things go wrong in practice. The first is the date: whoever put 2 December 2027 in the plan because that was the date in the news is planning on the Annex III route and not their own, and whoever notes only 2 August 2028 misses that Articles 102 to 110 have applied since 27 July 2026. The second is the section: machinery has been in Section B since 27 July 2026, no longer in Section A. For a machine builder that means a different regime, with the requirements landing through delegated acts in Annex III to Regulation (EU) 2023/1230 rather than directly through Chapter III of this Regulation. What stands: if you do not build the AI system yourself but put it in your product under your own brand, Article 2(1), point (e), and Article 25(3) make you the provider, with the obligations of Article 16, and not merely a customer of your software supplier.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"List per product which Annex I legal act it falls under and whether that is Section A or Section B after the amendment of 27 July 2026, which conformity assessment procedure applies there, and which AI functions are safety components within the meaning of Article 3, point (14). Test classification not against the module you actually use but against whether the legislature prescribed enhanced scrutiny for that product type. For Section A products the provider follows the procedure required under that legal act and the requirements of Chapter III, Section 2, form part of that assessment; if you use the opt-out in Article 43(3), record which harmonised standards cover all requirements of Section 2. Determine whether Article 2(1), point (e), or Article 25(3) makes you the provider yourself. Plan on 2 August 2028 for Chapter III, and track separately that Articles 102 to 110 have applied since 27 July 2026. For existing products check whether Article 111(2) spares you as long as the design is not significantly changed, and whether 2 August 2030 applies for systems intended for use by public authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (19), replacing Article 43(3), third subparagraph","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 2(1), point (e), and Article 25(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2028-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1-annex-i-product-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route","legacy_id":"raip:obligation:article-6-1bis-1quater-route","type":"obligation","slug":"article-6-1bis-1quater-route","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"b1a3c8f90e9a6725cbe17956c5c8b7e1eef30c09b708afd4f0758b446f53b35f","label":"Article 6(1a) to (1c): the tightened classification route","summary":"The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The legal text below is settled; our reading of the route is not, which is why the whole object stands as preliminary. Three things. First, the sharpest textual tension, and it is not where you would look for it. In the adopted text of paragraph 1a the qualifier \"non-safety related aspects of\" governs the entire list, including user assistance and performance optimisation. In recital 7 that qualifier attaches to quality control alone: it says this does not in particular include AI systems intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or non-safety related aspects for quality control operations. We read the operative text, so with the qualifier across the whole list. A defensible alternative is the recital-conform, narrower reading in which only quality control is limited to non-safety related aspects and the rest is excluded unconditionally. Second, what paragraph 1a looks at. The text says \"are used\", while recital 7 is explicit: the safety function should be an intended purpose of the system, determined by the provider, and the mere fact that an AI system is integrated into or operates within a regulated product does not, in itself, mean that it fulfils a safety function. That second sentence and the amended definition in Article 3, point (14), make this question less open than it seems; we read it as the intended purpose. The alternative reading remains that actual use decides, so that a provider loses the exclusion as soon as a customer deploys the system differently. Third, from when. The amended definition sits in Chapter I and operates now, and the paragraphs have been binding law since 27 July 2026. They steer a live classification only once the route itself applies: 2 December 2027 for Annex III, point 2, and 2 August 2028 for the Annex I route. A defensible alternative reading is that the paragraphs, sitting in Chapter III, Section 1, do not operate at all before the later date. One point of candour: the published definition object on Article 3, point (14), still carries the unamended text and the reading that a component need not have an identifiable safety function. That is exactly what is qualified here, and while both objects stand side by side the text in this object governs.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:assess-safety-component-role"],"evidence_ids":["praxikon:eu:ai-act:evidence:safety-component-assessment-record"],"control_ids":["praxikon:eu:ai-act:control:safety-component-reassessment-trigger"],"template_ids":["praxikon:eu:ai-act:template:article-6-1bis-1quater-legal-text"],"conditions":[{"id":"article-6-1-annex-i-route","operator":"any","description":"Applies where it must be determined whether an AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and whether that product is required to undergo a third-party conformity assessment. Because paragraph 1a writes itself for the purposes of this Regulation, the delimitation also bears on Annex III, point 2, where the notion of safety component is used for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity."},{"id":"article-6-1-section-a-only","operator":"all","description":"For the consequences under Chapter III only Annex I, Section A, counts. For products under Section B, including machinery since Regulation (EU) 2023/1230 was moved there, the amended Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 apply."}],"exceptions":[{"id":"article-6-1bis-non-safety-functions","operator":"not","description":"Paragraph 1a provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back: AI systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components."},{"id":"article-6-1quater-non-safety-conformity-assessment","operator":"not","description":"Paragraph 1c provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered as fulfilling the condition in paragraph 1, point (b)."}],"statements":[{"kind":"official_fact","text":"Article 6(1) provides: irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 inserts three paragraphs into Article 6. Paragraph 1a: \"For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.\" Paragraph 1b: \"Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.\" Paragraph 1c: \"A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).\"","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation amends the definition in Article 3, point (14). As amended it reads: \"safety component\" means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. Article 3 sits in Chapter I, which under Article 113, third paragraph, point (a), has applied since 2 February 2025. This amended definition therefore operates from the entry into force of the amending Regulation on 27 July 2026 and not only from some later application date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 3(14)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The amended Article 113, third paragraph, point (c), provides that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The added point (d) provides that Articles 102 to 110 shall apply from 27 July 2026. Annex III, point 2, uses the notion of safety component for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity; that route falls under the 2 December 2027 date.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same Regulation moves machinery out of Chapter III. In Annex I, Section A, point 1 (the reference to Directive 2006/42/EC) is deleted and Section B gains point 21: Regulation (EU) 2023/1230 on machinery. The amended Article 2(2) reads that for AI systems classified as high-risk in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 112 shall apply. The amended Article 43(3) adds that the classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to manufacturers of products covered by Annex I, Section A, and that those manufacturers are not required to choose a procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if the Section A legislation does not require it. The new Article 2(13) provides that specific requirements or obligations under Articles 9 to 15 and 17 to 25 may be limited where Section A legislation provides an equivalent or higher level of protection, and obliges the Commission to adopt delegated acts on this by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"What changes in practice is what the discussion is about. Until now it was about whether your product falls under Annex I and whether a third party is involved. Those two questions remain, but a third one belongs in front of them: what function does your AI component actually perform. A recommendation model that optimises when a machine is serviced, or a model that improves throughput on a line, sits in the list in paragraph 1a, and such functions often ended up classified as safety components simply because they ran inside a regulated product. Be careful with quality control as an example: paragraph 1a names only the non-safety related aspects of it, and in many regulated products a vision model that flags deviations is safety QC. Paragraph 1b draws the line: as soon as failure or malfunctioning would endanger health and safety, the exclusion does not count. The question therefore moves from your product file to your failure analysis, and at most providers that analysis is recorded nowhere. Paragraph 1c is narrower: anyone who needed a third party only because of radio spectrum or electromagnetic interference does not meet paragraph 1, point (b), by that route. That paragraph too requires a weighing, because it works only if the third party is mandatory solely on account of those other risks; where your product falls under several Annex I acts, a second act may still satisfy the condition on health and safety grounds. Two things finally that move the stakes. Machinery no longer runs through this route: Regulation (EU) 2023/1230 now sits in Annex I, Section B, and for those products the amended Article 2(2) means Chapter III does not apply at all. And for Section A products the same Regulation pushes the other way: the amended Article 43(3) says expressly that classification under Article 6(1) does not affect the choice of conformity assessment procedure and pushes nobody towards a notified body who was not already headed there. So build your failure analysis as your own file, not as something you will have to put in front of a notified body anyway.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"This is our recommendation and not a legal duty: paragraphs 1a to 1c are delimiting rules and impose no obligation on anyone. First establish whether your product falls under Annex I, Section A or Section B; for Section B, which now includes machinery, Chapter III stops here. For Section A, record per AI component which function it performs, whether that is a safety function within the meaning of the amended Article 3, point (14), and what happens on failure or malfunctioning. Note which of the three paragraphs you apply and why. Use that file to support your own classification, not because a notified body asks for it: the amended Article 43(3) points the other way. Keep two dates apart: 2 December 2027 for the route via Annex III, point 2, and 2 August 2028 for the route via Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Inserted Article 6(1a)-(1c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 2(2), Article 43(3) and Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"in_force","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-6-1bis-1quater-route","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Inserted paragraphs on EUR-Lex"},{"relation":"related","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 6 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-60-real-world-testing","legacy_id":"raip:obligation:article-60-real-world-testing","type":"obligation","slug":"article-60-real-world-testing","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6306b9a0abce6764b0c4ebf4968aacf23cd2483dba7b750f1cb18716886ea751","label":"Article 60: testing in real world conditions outside a sandbox","summary":"If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.","topics":["innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-60-testing-plan-and-authorisation"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-61-informed-consent-record"],"control_ids":["praxikon:eu:ai-act:control:article-60-oversight-and-incident-response"],"template_ids":["praxikon:eu:ai-act:template:article-60-real-world-testing-legal-text"],"conditions":[{"id":"article-60-real-world-testing-scope","operator":"all","description":"Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22."}],"exceptions":[{"id":"article-60-real-world-testing-exception","operator":"not","description":"Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level."}],"statements":[{"kind":"official_fact","text":"Article 60(1) provides that testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, in accordance with that Article and the real-world testing plan, without prejudice to the prohibitions under Article 5. The Commission specifies the detailed elements of that plan by implementing act. The third subparagraph of paragraph 1 provides that the paragraph is without prejudice to Union or national law on the testing in real world conditions of high-risk AI systems related to products covered by the Union harmonisation legislation listed in Annex I. Article 60(2) allows providers or prospective providers to test at any time before placing on the market or putting into service, on their own or in partnership with one or more deployers or prospective deployers. Article 60(3) provides that such testing is without prejudice to any ethical review required by Union or national law. Article 60(4), point (f), caps the duration: no longer than necessary to achieve its objectives and in any case no longer than six months, which may be extended by an additional six months subject to prior notification to the market surveillance authority with an explanation of the need. Article 60(4), point (g), requires that subjects belonging to vulnerable groups due to age or disability are appropriately protected. Article 60(9) expressly states that the provider or prospective provider remains fully subject to applicable Union and national law on any damage caused in the course of their testing in real world conditions. Chapter VI, which contains Article 60, is not among the exceptions in Article 113 and applies since 2 August 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Many organisations call what they do a pilot and assume that keeps them outside the Regulation. Article 60 shows that this does not hold once you test an Annex III system in real world conditions with real people and real outcomes. A full regime then applies: a plan, prior approval, registration with a Union-wide unique single identification number, informed consent, and a hard six-month clock with a maximum six-month extension. The heaviest requirement in practice is Article 60(4), point (k): the predictions, recommendations or decisions of the system must be capable of being effectively reversed and disregarded. If you are testing a selection, scoring or triage system whose output feeds straight into the workflow with nobody able to reverse it, your design does not qualify, however careful your consent form is. Note the timing too, because it is commercially interesting. Chapter VI applies since 2 August 2026, while the core obligations for standalone Annex III systems only apply from 2 December 2027. The testing route is therefore open before the requirements themselves bite, and that is exactly the window in which to validate your design rather than rebuild it later. Finally, Article 60(3) leaves any ethical review required under other law fully in place, and Article 60(9) expressly states that you remain fully subject to the applicable law on damage caused during the testing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Inventory which running or planned trials are in fact real-world testing: real users, real data, outputs that feed into the workflow. Test those first against Article 60(4), point (k): can the output genuinely be reversed and disregarded? If not, redesign the trial before you submit anything. Then choose deliberately between two routes: supervised testing inside a sandbox under Article 57(5) and Article 58(4), or outside a sandbox under Article 60. Plan the six months realistically and decide in advance at which point you will request an extension, since that requires prior notification with a reasoned explanation. Check whether an ethical review is mandatory in your domain and start it in parallel, because Article 60(3) does not exempt you from it.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(1)-(4), Article 60(9), Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-60-real-world-testing","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 60 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","legacy_id":"raip:obligation:article-61-informed-consent","type":"obligation","slug":"article-61-informed-consent","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e7ff043231fa794c9c21494315ad879b5bac9ab1195f761cfec85493be5acd92","label":"Article 61: informed consent of test subjects for testing in real world conditions","summary":"If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.","topics":["fundamental-rights","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-61-subject-information-pack"],"control_ids":["praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review"],"template_ids":["praxikon:eu:ai-act:template:article-61-legal-text"],"conditions":[{"id":"article-61-scope","operator":"all","description":"Applies for the purpose of testing in real world conditions under Article 60, that is where you are a provider or prospective provider of a high-risk AI system listed in Annex III and you test that system in real world conditions outside an AI regulatory sandbox. Article 60(4), point (i), makes informed consent in accordance with Article 61 one of the cumulative conditions under which such testing is allowed. Consent is obtained per subject prior to their participation. Article 61 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."},{"id":"article-61-joint-testing","operator":"any","description":"If under Article 60(2) you test in partnership with one or more deployers or prospective deployers, the condition stays with you as the provider, even where that party is the one in contact with the subject. Article 60(4), point (h), requires you and that party to conclude an agreement specifying your tasks and responsibilities; that is where you record who informs, who obtains the consent and who keeps the file."}],"exceptions":[{"id":"article-61-law-enforcement-carve-out","operator":"not","description":"The only exception sits not in Article 61 but in Article 60(4), point (i): in the case of law enforcement, where seeking informed consent would prevent the AI system from being tested in real world conditions, testing may proceed without that consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test is performed. Outside that context there is no exception to consent; Article 61 contains none of its own."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: for the purpose of testing in real world conditions under Article 60, freely-given informed consent shall be obtained from the subjects of testing prior to their participation in such testing and after their having been duly informed with concise, clear, relevant, and understandable information regarding: (a) the nature and objectives of the testing in real world conditions and the possible inconvenience that may be linked to their participation; (b) the conditions under which the testing in real world conditions is to be conducted, including the expected duration of the subject or subjects participation; (c) their rights, and the guarantees regarding their participation, in particular their right to refuse to participate in, and the right to withdraw from, testing in real world conditions at any time without any resulting detriment and without having to provide any justification; (d) the arrangements for requesting the reversal or the disregarding of the predictions, recommendations or decisions of the AI system; (e) the Union-wide unique single identification number of the testing in real world conditions in accordance with Article 60(4) point (c), and the contact details of the provider or its legal representative from whom further information can be obtained. Paragraph 2 provides: the informed consent shall be dated and documented and a copy shall be given to the subjects of testing or their legal representative.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 61(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 60(4), point (i), sets as a condition: the subjects of the testing in real world conditions have given informed consent in accordance with Article 61, or in the case of law enforcement, where the seeking of informed consent would prevent the AI system from being tested, the testing itself and the outcome of the testing in the real world conditions shall not have any negative effect on the subjects, and their personal data shall be deleted after the test is performed. Article 60(5) provides: any subjects of the testing in real world conditions, or their legally designated representative, as appropriate, may, without any resulting detriment and without having to provide any justification, withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data. The withdrawal of the informed consent shall not affect the activities already carried out. Article 60(2), as replaced by Article 1, point (24), of Regulation (EU) 2026/1744, provides: providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the high-risk AI system on their own or in partnership with one or more deployers or prospective deployers. Until 27 July 2026 that paragraph named only the Annex III route; the consent of Article 61 therefore now also applies when testing high-risk AI in a regulated product under Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only place in this Regulation where the individual consent of a natural person is a condition. Nowhere else does the lawfulness of something you do turn on a signature from the person it affects. That makes it tempting to reuse the existing GDPR consent form, and that is exactly where it goes wrong. Consent under Article 61 is consent to take part in a test; it is one of the cumulative conditions in Article 60(4) under which you may test in real world conditions. Whether, and on what basis, personal data may be processed in that test is not governed by Article 61 and this Regulation does not say so here. That remains a question of data protection law, and you answer it separately. The two do not coincide and one does not replace the other. Look as well at the content of the five points, because two of them appear in no standard form. Point (e) requires the Union-wide unique single identification number of the testing from Article 60(4), point (c). That number arises on registration, so you can only approach the subject once that registration is done; anyone who recruits first and registers afterwards has inverted the order. Point (d) requires you to explain how someone can request the reversal or the disregarding of the predictions, recommendations or decisions of the system. That is not only information: Article 60(4), point (k), requires those outputs to be capable of being effectively reversed and disregarded. If you cannot describe that mechanism, it probably does not exist and your test design does not qualify.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Note the difference between paragraph 1 and paragraph 2, because organisations usually build only one of the two. Paragraph 1 is about informing beforehand: concise, clear, relevant and understandable, on five topics. Paragraph 2 is about the evidence afterwards: the consent is dated, is documented, and the subject is given a copy. A tick box in an app that leaves a line in a log file does not satisfy paragraph 2: no copy was given and usually there is no dating that can be shown independently of the logging system. So build two artefacts rather than one: the information pack you hand over, and the dated consent record you keep and of which the subject holds a copy. A second point missed in the design is withdrawal. Article 61(1), point (c), promises the subject a right to withdraw at any time without detriment and without justification, and Article 60(5) works that out: withdrawal is always possible, immediate and permanent deletion of the personal data may be requested, and the withdrawal does not affect the activities already carried out. Anyone who promises that right in the form but has no route to carry it out has not delivered on the promise. The practical question is therefore not how your form reads, but who receives the withdrawal on Monday morning, within what period the data disappear, and where that is recorded. Finally, do not leave the division of roles implicit. If you test together with a deployer, that party is often the one facing the subject, while the condition stays with you as the provider. Article 60(4), point (h), gives you the instrument to settle that, and that is the agreement specifying your tasks and responsibilities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Draw up an information pack per test that names each of the five points of paragraph 1 separately, and check the pack line by line against those five points rather than against your existing privacy notice. Obtain the Union-wide unique single identification number from the registration under Article 60(4), point (c), and put it in the pack together with the contact details of the provider or the legal representative before you approach the first subject. Under point (d), describe the concrete mechanism through which someone can request the reversal or the disregarding of an output, with the place the request arrives and the period within which it is handled. Record a dated consent per subject and give a copy to the subject or the legal representative; keep that record separately from your application logs, so you can show it without consulting the system. Set up a withdrawal route with a named recipient, a period and a processing step for the request for immediate and permanent deletion of personal data, and rehearse that route once before the test starts. In the agreement with your deployer under Article 60(4), point (h), record who informs, who obtains consent, who keeps the record and who receives a withdrawal. If you test in the law enforcement domain and are considering the exception in Article 60(4), point (i), record in advance why seeking consent would prevent the testing, and how you ensure that the test has no negative effect and that the personal data are deleted after the test.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 61 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/61","label":"Read Article 61 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-62-sme-support-measures","legacy_id":"raip:obligation:article-62-sme-support-measures","type":"obligation","slug":"article-62-sme-support-measures","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"89d0012409a5635c7734726e3fa30d2a1fa3427dc6277cfe8f675f151cd5d5dc","label":"Article 62: measures for providers and deployers that are SMEs or start-ups","summary":"Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-62-claim-sme-facilities"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-62-sme-status-record"],"control_ids":["praxikon:eu:ai-act:control:article-62-fee-and-access-review"],"template_ids":["praxikon:eu:ai-act:template:article-62-legal-text"],"conditions":[{"id":"article-62-scope","operator":"all","description":"The priority access in paragraph 1, point (a), applies to SMEs, including start-ups, having a registered office or a branch in the Union, and only to the extent that they fulfil the eligibility conditions and selection criteria. The reduction of fees in paragraph 2 attaches to conformity assessments under Article 43 and to the capacity of an SME provider, including start-ups. Article 62 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."}],"exceptions":[{"id":"article-62-priority-access-not-exclusive","operator":"not","description":"Paragraph 1, point (a), expressly states that the priority access shall not preclude other SMEs, including start-ups, other than those referred to in that paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria. Priority is therefore an order of precedence and not an exclusive right, and it releases nobody from the eligibility conditions and selection criteria."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: Member States shall undertake the following actions: (a) provide SMEs, including start-ups, having a registered office or a branch in the Union, with priority access to the AI regulatory sandboxes, to the extent that they fulfil the eligibility conditions and selection criteria; the priority access shall not preclude other SMEs, including start-ups, other than those referred to in this paragraph from access to the AI regulatory sandbox, provided that they also fulfil the eligibility conditions and selection criteria; (b) organise specific awareness raising and training activities on the application of this Regulation tailored to the needs of SMEs including start-ups, deployers and, as appropriate, local public authorities; (c) utilise existing dedicated channels and where appropriate, establish new ones for communication with SMEs including start-ups, deployers, other innovators and, as appropriate, local public authorities to provide advice and respond to queries about the implementation of this Regulation, including as regards participation in AI regulatory sandboxes; (d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process. Paragraph 2 provides: the specific interests and needs of the SME providers, including start-ups, shall be taken into account when setting the fees for conformity assessment under Article 43, reducing those fees proportionately to their size, market size and other relevant indicators.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 62(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides: the AI Office shall undertake the following actions: (a) provide standardised templates for areas covered by this Regulation, as specified by the Board in its request; (b) develop and maintain a single information platform providing easy to use information in relation to this Regulation for all operators across the Union; (c) organise appropriate communication campaigns to raise awareness about the obligations arising from this Regulation; (d) evaluate and promote the convergence of best practices in public procurement procedures in relation to AI systems.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 62(1) to (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Article 62 is not an exemption but a facility, and that distinction is the whole article. Nowhere does it say that an SME or a start-up has to comply with less. What changes is the price and the access: priority access to the AI regulatory sandbox, tailored training and awareness raising, a channel to put questions, a seat at the standardisation table, and reduced fees for conformity assessment under Article 43. Anyone reading this article as an SME regime with lighter requirements is looking at the wrong provision; the only relief from a substantive requirement in this Regulation sits in Article 63 and touches only the quality management system of Article 17. Since 27 July 2026 that relief is available to SMEs, including start-ups, and no longer to microenterprises alone: Article 1, point (26), of Regulation (EU) 2026/1744 replaced Article 63(1) to that effect. A standalone small enterprise that is not a microenterprise therefore does fall within it, provided it has no partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Read paragraph 2 carefully as well, because it says something stronger than is usually assumed. It is not a power but an instruction: the fees are reduced, proportionately to the size of the provider, the market size and other relevant indicators. If you receive a quotation for a conformity assessment without that proportionality being made visible, that is a question you can put and whose answer you can record. Do not confuse that reduction with free access to an AI regulatory sandbox: that sits in Article 58(2), point (d), applies to SMEs including start-ups, and expressly leaves standing the exceptional costs that national competent authorities may recover in a fair and proportionate manner. Two different provisions, two different flows of money.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"In practice the core of this article is that you have to ask for it yourself. The Member State grants priority access to those who come forward and meet the eligibility conditions and selection criteria; priority will not operate by itself for anyone who does not apply. That makes two things important. First, that you can show you are an SME in the sense in which the Regulation uses that word, and that you have a registered office or a branch in the Union; that is a matter of file, not of conversation. Second, that you know which national body in your Member State staffs the channel in paragraph 1, point (c), because that channel is meant to provide advice and answer queries about implementation, including on participation in a sandbox. Point (d) is almost always skipped and is the most valuable part for a technical company: the participation of SMEs in the standardisation development process is facilitated. The harmonised standards will settle what counts as sufficient in practice; having a say in that text is cheaper than having to build to it later. Finally, factor paragraph 3 into your own planning. The AI Office provides standardised templates and maintains a single information platform. As long as no template exists for your topic, you build your own document; once one arrives, it is a template and not a licence, and the substantive requirement stays the same.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record once whether your organisation is an SME or a start-up in the sense in which this Regulation uses that word, with the reasoning and the date attached, and whether you have a registered office or a branch in the Union; refresh that file at every change in the corporate structure. Find out which national competent authority in your Member State runs the AI regulatory sandbox and which channel it offers for questions about implementation, and use that channel before you buy an expensive external route. If you apply for a conformity assessment under Article 43, ask explicitly with the quotation how the reduction proportionate to your size, the market size and other relevant indicators has been applied, and keep that answer with your procurement file. Sign up for the standardisation development process on the topics that touch your product, because that is the cheapest place to influence what later counts as sufficient. Before you build your own template, check whether the AI Office has already provided one, and use the single information platform as a first source rather than a secondary summary. Finally, do not assume that any of these facilities lightens a substantive requirement: in your planning, set out next to each facility which requirement continues to apply in full.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 43; Article 58(2), point (d); Article 63; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-62-sme-support-measures","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 62 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/62","label":"Read Article 62 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-63-sme-derogations","legacy_id":"raip:obligation:article-63-sme-derogations","type":"obligation","slug":"article-63-sme-derogations","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"249cec1c5363acf6ee7e50aca22d6a1f93b27a07655d9cb2d2ebd8494810bcde","label":"Article 63: derogations for SMEs in the quality management system","summary":"SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Until 27 July 2026 this read microenterprises; Article 1, point (26), of Regulation (EU) 2026/1744 replaced paragraph 1 and widened the circle to SMEs. Which elements those are is for the Commission to set out in guidelines, considering the needs of SMEs and without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 rules out any wider reading: the provision shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.","topics":["high-risk-requirements","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-63-sme-eligibility-record"],"control_ids":["praxikon:eu:ai-act:control:article-63-simplification-boundary-review"],"template_ids":["praxikon:eu:ai-act:template:article-63-legal-text"],"conditions":[{"id":"article-63-scope","operator":"all","description":"Two cumulative conditions. The organisation is an SME, including a start-up, within the meaning of Recommendation 2003/361/EC, and it does not have partner enterprises or linked enterprises within the meaning of that Recommendation. A standalone small enterprise that is not a microenterprise is therefore covered since 27 July 2026. The thresholds and the notions of partner enterprise and linked enterprise sit in that Recommendation and not in this Regulation; anyone relying on this article tests against that text. The benefit touches only the quality management system required by Article 17, and only those elements of it that the Commission designates in its guidelines. Article 63 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."}],"exceptions":[{"id":"article-63-no-exemption-from-other-requirements","operator":"not","description":"Paragraph 2 expressly provides that paragraph 1 shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73. The risk management system, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity, post-market monitoring and the reporting of serious incidents therefore continue to apply in full."}],"statements":[{"kind":"official_fact","text":"Paragraph 1, as replaced by Article 1, point (26), of Regulation (EU) 2026/1744, provides: SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 provides: paragraph 1 of this Article shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 63(1) and (2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 17(1) is the obligation to which the derogation in Article 63 relates and provides: providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects: (a) a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system; (b) techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article is called derogations and that word does more harm than good. Nothing is abolished. Paragraph 1 says that certain elements of a single obligation, the quality management system of Article 17, may be complied with in a simplified manner. Paragraph 2 then says in as many words that this shall not be interpreted as exempting those operators from other requirements or obligations under this Regulation, and names nine of them: Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73. That is the enumeration that heads off the misunderstanding, and it covers exactly the heaviest requirements: risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and cybersecurity, post-market monitoring, and the reporting of serious incidents. A microenterprise providing a high-risk system therefore does very nearly everything a large company does; only the form in which the quality management system is written down may be lighter. Two things to settle now. First the entry test, because it is stricter than it looks: on top of the thresholds in Recommendation 2003/361/EC there is the additional condition that you have no partner enterprises or linked enterprises within the meaning of that Recommendation. A holding by a parent company or a shared shareholder can break that condition, and that is a structural question you do not want to raise in the last week before an assessment. Second the reach of the simplification: which elements exactly may be lighter is not in the Regulation but in guidelines the Commission develops under this article. We make no claim here about which elements those are or whether those guidelines already exist; until they do, you build the Article 17 system as it stands and keep a note of which parts you would later want to simplify.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Put Article 63 next to Article 62 and the picture sharpens. Article 62 lowers the price and the threshold, Article 63 simplifies the form of a document. Together they are the only two places in this Regulation where the size of an undertaking legally makes a difference, and neither touches the substantive requirements for high-risk AI systems. Anyone who hears in a sales conversation or a grant application that the AI Regulation is softer for small companies can test that against these two articles and will find the claim too broad. Think as well about the commercial side of paragraph 2. The nine articles it names are precisely the items a buyer asks for: the risk management system, the data governance, the technical documentation, the logs, the instructions for use, the human oversight, the performance and security figures, the post-market monitoring and the incident reporting. A microenterprise invoking Article 63 in order not to produce those items will be found out in the first serious procurement process, before a regulator comes into view at all. The sensible reading is therefore the reverse: use Article 63 to keep your quality management system small and workable, and invest the time you win in the nine topics of paragraph 2, because that is what both your customer and your market surveillance authority will judge you on.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First test whether you fall within scope and record that test: are you a microenterprise within the meaning of Recommendation 2003/361/EC, and do you genuinely have no partner enterprises or linked enterprises within the meaning of that Recommendation? Put that second question to whoever knows the shareholding structure rather than to the product team, and repeat the test at every investment round or acquisition. Then build the Article 17 quality management system in full, and mark in your own documentation which elements you would want to simplify once the Commission guidelines on that exist; that way you do not start over when that text appears. Next, make an explicit list of the nine articles paragraph 2 names and set out per article who in your organisation produces the corresponding item and where it sits; that is the same list a buyer asks for and a market surveillance authority walks through. Put no sentence in quotations or contracts suggesting that your size releases you from a requirement. Finally, check whether Article 62 gives you something Article 63 does not, such as the reduced conformity assessment fee or priority access to a sandbox; those two tracks run separately and you can use both.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 17(1); Article 62(2); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-63-sme-derogations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 63 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/63","label":"Read Article 63 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-71-eu-database","legacy_id":"raip:obligation:article-71-eu-database","type":"obligation","slug":"article-71-eu-database","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"ceaa3da5b4cb893e068c9cbe5094b7934da65e8a20cc7cf57546945c0b877c06","label":"Article 71: EU database for high-risk AI systems listed in Annex III","summary":"The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.","topics":["conformity","high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things about the law itself are unsettled here. First, the date. Article 71 falls under the general application date of 2 August 2026, while the entry duties in paragraphs 2 and 3 hang on the registration in Article 49, whose Annex III route was shifted to 2 December 2027 by Regulation (EU) 2026/1744. We therefore read the practical deadline as 2 December 2027. Two alternative readings are defensible, and they point in opposite directions: the mild one is that the database exists from 2 August 2026 and only the entering follows the later date, so whoever registers earlier is not being early but on time; the hard one is that the amended Article 113, third paragraph, point (c), names only Chapter III, Sections 1, 2 and 3, while Article 49 sits in Section 5 of that same Chapter, so the registration duty may not have moved with it and you may already be late rather than early. Anyone planning against this deadline is planning against our reading and not against a settled fact. Second, the Article 60 route. Article 60 sits in Chapter VI and the provider or prospective provider testing in real world conditions today must register under Article 60(4), point (c), in accordance with Article 71(4). Whether that route moved with the Annex III deferral or already runs under the general date of 2 August 2026 is unsettled. The fact that 2026/1744 widened the scope of Article 60 to Annex I Section A and placed an Article 60a alongside it for Annex I Section B makes that question larger rather than smaller. This object does not carry that duty and the status here says nothing about it. Settled, and therefore no longer a ground for the preliminary status: the content of Section B of Annex VIII. Article 1, point (42), of Regulation (EU) 2026/1744 deletes points 7 and 9, and the reading above follows that text rather than the base regulation. One cross-reference does follow from it that the legislator did not chase down: Article 49(4) is unamended and still lists point 9 of Section B for the secure section, a point that no longer exists. Whoever works through that list literally is looking for a field that is not there. In addition, and this expressly does not carry the status because it is not an unsettled reading but a coverage gap of this dataset: paragraphs 1 and 6 address the Commission, which is not an actor here, so this object carries only the entry duties of paragraphs 2 and 3; and paragraph 3 also names whoever acts on behalf of a public authority, a role that does not exist separately alongside the body governed by public law, so a private party registering on behalf of a public authority has to assess for itself whether paragraph 3 rests on it.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date"],"action_ids":["praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data"],"evidence_ids":["praxikon:eu:ai-act:evidence:eu-database-entry-record"],"control_ids":["praxikon:eu:ai-act:control:eu-database-entry-currency"],"template_ids":["praxikon:eu:ai-act:template:article-71-legal-text"],"conditions":[{"id":"article-71-scope","operator":"any","description":"Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use."}],"exceptions":[{"id":"article-71-exception-annex-iii-point-2","operator":"not","description":"Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database."},{"id":"article-71-exception-secure-section","operator":"not","description":"Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there."},{"id":"article-71-exception-real-world-testing","operator":"not","description":"Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission shall, in collaboration with the Member States, set up and maintain an EU database containing the information referred to in paragraphs 2 and 3 concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60, and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications the Commission shall consult the relevant experts, and when updating them the Board. Paragraph 2 provides that the data listed in Sections A and B of Annex VIII shall be entered into the database by the provider or, where applicable, by the authorised representative. Paragraph 3 provides that the data listed in Section C of Annex VIII shall be entered by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4). Paragraph 4 provides that, with the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner, and that the information should be easily navigable and machine-readable. The same paragraph provides that the information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible to the public. Paragraph 5 provides that the database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation, and that such information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer. Paragraph 6 provides that the Commission shall be the controller of the database, shall make adequate technical and administrative support available to providers, prospective providers and deployers, and that the database shall comply with the applicable accessibility requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 71(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex VIII sets out which information is submitted upon registration and kept up to date thereafter. Section A, for providers registering in accordance with Article 49(1), lists thirteen points, including the name, address and contact details of the provider and of the authorised representative, the trade name and any additional unambiguous reference allowing identification and traceability of the system, a description of the intended purpose and of the components and functions supported, a basic and concise description of the information used and of the operating logic, the status of the system, the details and a scanned copy of the notified body certificate where applicable, the Member States where the system is available, a copy of the EU declaration of conformity referred to in Article 47 and the electronic instructions for use, which are not provided for the law enforcement, migration, asylum and border control management areas of points 1, 6 and 7 of Annex III. Section C, for deployers registering under Article 49(3), lists five points: the name, address and contact details of the deployer, the same details of the person submitting information on its behalf, the URL of the entry of the system in the database by its provider, a summary of the findings of the fundamental rights impact assessment carried out in accordance with Article 27, and where applicable a summary of the data protection impact assessment. Neither Section was amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Section B of Annex VIII, for registrations under Article 49(2), was amended. Article 1, point (42), of Regulation (EU) 2026/1744 reads: \"in Annex VIII, section B, points 7 and 9 are deleted\". Deleted are therefore point 7, the short summary of the grounds on which the AI system is considered not to be high-risk in application of the procedure under Article 6(3), and point 9, the statement of any Member States in which the system has been placed on the market, put into service or made available in the Union. The Regulation does not renumber the remaining points. Section B therefore now lists seven points, numbered 1 to 6 and 8: the name, address and contact details of the provider; the same details of another person submitting information on the provider behalf; the same details of the authorised representative where applicable; the trade name and any additional unambiguous reference allowing identification and traceability of the system; a description of the intended purpose; the condition or conditions under Article 6(3) on the basis of which the system is considered not to be high-risk; and the status of the system. Recital 22 of 2026/1744 explains that registration is thereby made simpler and more proportionate, while expressly maintaining that a provider applying Article 6(3) remains obliged to document its assessment before the system is placed on the market or put into service, and that national competent authorities may request that assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Section B","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 22 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 49(4) lists exhaustively what goes into the secure non-public section, and that is less than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. The final subparagraph provides that only the Commission and the national authorities referred to in Article 74(8) have access to the respective restricted sections of the database. Annex IX carries the information provided upon registration of testing in real world conditions and kept up to date thereafter, and lists five points: a Union wide unique single identification number of the testing, the name and contact details of the provider or prospective provider and of the deployers involved, a short description of the AI system and its intended purpose together with the information needed to identify it, a summary of the main characteristics of the testing plan, and information on the suspension or termination of the testing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 60(4), point (c), provides that the provider or prospective provider has registered the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management that registration takes place in the secure non-public section in accordance with Article 49(4), point (d), and for the systems referred to in point 2 of Annex III in accordance with Article 49(5). Article 60 sits in Chapter VI of the Regulation, on measures in support of innovation. That point (c) was not amended by Regulation (EU) 2026/1744.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 60(4), point (c), Article 49(4) and (5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The scope of Article 60 itself was amended. Article 1, point (24), of Regulation (EU) 2026/1744 replaces the first subparagraph of Article 60(1) and Article 60(2): testing in real world conditions outside AI regulatory sandboxes is now also open to providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, alongside the systems listed in Annex III. Article 1, point (25), inserts an Article 60a for high-risk AI systems covered by the harmonisation legislation listed in Section B of Annex I: Member States may adopt frameworks for real-world testing for those systems, must notify the Commission of any such framework before implementing it, and those frameworks must among other things ensure compliance with Article 60(2), (3), (4)(d)-(j) and (5)-(9). The registration duty in Article 60(4), point (c), which refers to Article 71(4), falls outside that enumeration.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 1, point (40), of Regulation (EU) 2026/1744 amends the THIRD paragraph of Article 113, which is where points (a) to (d) sit. Point (40)(b) replaces point (c) with: Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Two things belong with that and are often left out: the exception for Article 6(5) falls outside this deferral, and point (40)(c) adds a point (d) under which Articles 102 to 110 apply from 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 131 explains why the database exists and how far the public availability reaches. It names as the aim facilitating the work of the Commission and the Member States and increasing transparency towards the public, states that this part of the database should be publicly accessible and free of charge and that the information should be easily searchable, understandable and machine-readable, and that the database should be user-friendly, for example by offering search functionalities including through keywords, so that the general public can find the registration information. It adds that any substantial modification of high-risk AI systems should also be registered in the database, that access to the secure non-public section should be strictly limited to the Commission and, as regards their national section, to market surveillance authorities, and that the database should comply with the requirements of Directive (EU) 2019/882.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is one of the few obligations in the Regulation whose output is a public page about your organisation. Article 53(1), point (d), is the other one: the provider of a general-purpose AI model makes public a summary of the training content used. The difference is that the database is your own entry rather than a document on your own site. The rest of your file opens only when a supervisory authority asks; this opens to anyone who can search. On machine readability a caveat applies: the Dutch text of paragraph 4 says the information must be machine-readable, the English says should, and Recital 131 likewise speaks in recommending terms. So count on your text being read, but do not build an assumption of automated readability as a hard requirement. That changes who reads your text. The basic and concise description of the operating logic in Section A is read by competitors, journalists and municipal councils, and the summary of your fundamental rights impact assessment in Section C is read by exactly the people that assessment was about, with one important exception: for points 1, 6 and 7 of Annex III the secure section carries Section C only up to and including point 3, so that very summary is not entered there. Two things follow. First, the entry requires editing rather than form filling: whoever writes the summary as a formality publishes a formality. Second, keeping it current is not a side issue, because Annex VIII requires the information to be kept up to date thereafter and Recital 131 also names substantial modifications, and an entry that still shows a recalled system as in service is visibly wrong.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 49(4) and Annex IX","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recital 131","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat the entry as a publication and not as a form. Designate per system the natural person who has the legal authority to register, because paragraph 5 provides that their name and contact details go into the database. Write the description of the intended purpose, of the operating logic and, for a public deployer, the summary of the fundamental rights impact assessment so that you can let them be read without explanation. Settle the sequence in your procurement contract: point 3 of Section C asks for the URL of the entry of the system in the database by its provider, so a municipality can only complete its Section C after its supplier has entered Section A. Record within what period the supplier delivers that URL and what happens if it does not. Also record when the entry was last checked against reality and tie that to your change and decommissioning process, so that status, Member States and declaration of conformity move with it. On procurement, check that the system is listed in the database before you put it into use: if it is not listed, a deployer may not use it under Article 26(8) and has to inform the provider or the distributor.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex VIII, Sections A and C","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-71-eu-database","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 71 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-72-post-market-monitoring","legacy_id":"raip:obligation:article-72-post-market-monitoring","type":"obligation","slug":"article-72-post-market-monitoring","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"6fe04840ffe25ded5e84488a9486d4fa3f46720b9c66ce47d2244110d9e33098","label":"Article 72: post-market monitoring","summary":"Systematic monitoring of high-risk AI in real use, after market placement.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-72-post-market-monitoring-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record"],"control_ids":["praxikon:eu:ai-act:control:article-72-post-market-monitoring-control"],"template_ids":["praxikon:eu:ai-act:template:article-72-post-market-monitoring-legal-text"],"conditions":[{"id":"article-72-post-market-monitoring-scope","operator":"all","description":"The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals."}],"exceptions":[{"id":"article-72-post-market-monitoring-exception","operator":"not","description":"The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes."}],"statements":[{"kind":"official_fact","text":"Article 72 obliges providers to operate a post-market monitoring system with a plan forming part of the technical documentation, collecting relevant real-world data to evaluate continued compliance with Section 2.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Compliance does not stop at go-live: this article turns compliance into a continuous state. For deployers it is also the basis to force suppliers to act on deviations.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Design the monitoring together with the Article 12 logging: the same data flows feed both duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-72-post-market-monitoring","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 72 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-73-incident-reporting","legacy_id":"raip:obligation:article-73-incident-reporting","type":"obligation","slug":"article-73-incident-reporting","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df","label":"Article 73: serious incident reporting","summary":"The duty to report serious incidents with high-risk AI, under strict deadlines.","topics":["post-market"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-73-incident-reporting-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-73-incident-reporting-record"],"control_ids":["praxikon:eu:ai-act:control:article-73-incident-reporting-control"],"template_ids":["praxikon:eu:ai-act:template:article-73-incident-reporting-legal-text"],"conditions":[{"id":"article-73-incident-reporting-scope","operator":"all","description":"A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment."}],"exceptions":[{"id":"article-73-incident-reporting-exception","operator":"not","description":"For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication."}],"statements":[{"kind":"official_fact","text":"Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 73 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties","legacy_id":"raip:obligation:article-75-ai-office-high-risk-duties","type":"obligation","slug":"article-75-ai-office-high-risk-duties","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"83a34bbb496960e909b28ca4cdcd4338b787f6e6e306f03413d405f05029c671","label":"Article 75(1a) and (1e): reporting to and assessment by the AI Office","summary":"If you are the provider of a high-risk AI system subject to the competence of the AI Office, you report serious incidents to the Office rather than to your national authority, with the machinery and the deadlines of Article 73(2) to (9) applying in full, and the Office still transmits the information to your national market surveillance authority. Where that system is subject to a third-party conformity assessment under Article 43, the Office is responsible for it, the notified body acts on behalf of the Commission, and you pay the costs directly to that body.","topics":["enforcement","governance","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The two duties themselves are literal in the text; the date is our derivation. Article 75 sits in Chapter IX, which has applied since 2 August 2026, but both paragraphs address only the provider of a high-risk AI system, and that status only arises when Chapter III, Sections 1 to 3, becomes applicable. That date depends on the route, which the repair after the cross-review made sharper: point (c) of the third paragraph of Article 113, as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744, gives 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I. The Annex I route does not drop out here: the four carve-outs in Article 75(1) sit inside point (a), and point (b) independently brings a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine under the competence of the AI Office, including where it is high-risk through Annex I. We carry the earlier of the two in deadline_at, 2 December 2027, matching the sister object article-21-cooperation-with-authorities, which carries the same class of duty holder; for a system entering through point (b) and Annex I the date is 2 August 2028. A defensible alternative reading is that paragraph 1a, as a Chapter IX provision, already operates from 2 August 2026 and therefore applies immediately to any system that is at some point classified as high-risk; on that reading you set up the reporting route to the AI Office now. That is the safer choice and it costs little. It is further uncertain exactly when paragraph 1e bites: Article 43 sits in Chapter III, Section 5, which is not among the deferred Sections 1 to 3, but a third-party conformity assessment only arises once a system is classified as high-risk. The cost of this status is that a preliminary reading is skipped by lib/answer/derive-obligations.ts, so this reporting route does not surface in the per-situation derivation; the object stays reachable through its own page, the deadline index and the API.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:route-high-risk-duties-to-ai-office"],"evidence_ids":["praxikon:eu:ai-act:evidence:ai-office-incident-and-assessment-record"],"control_ids":["praxikon:eu:ai-act:control:ai-office-proceeding-response"],"template_ids":["praxikon:eu:ai-act:template:article-75-legal-text"],"conditions":[{"id":"article-75-high-risk-duties-scope","operator":"all","description":"Applies to providers of AI systems that fall under the competence of the AI Office pursuant to Article 75(1) and that are classified as high-risk. The replaced paragraph 1 carries two independent routes, and the four carve-outs at (i) to (iv) sit inside point (a) alone. Along point (a) Annex I systems fall outside the competence, as do point 2 of Annex III and point 8 as regards the administration of justice; point 8(b), on influencing elections and referenda, is not carved out. Point (b) is a route of its own: a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine falls under the competence of the AI Office even where one of the carve-outs in point (a) applies. Anyone testing point (a) alone places such a system outside this obligation wrongly. Those duties start to apply when Chapter III, Sections 1 to 3, becomes applicable, and that date depends on the route: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I, which point (b) can bring into view. The deadline_at field carries the earlier of the two."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Paragraph 1a provides that, by way of derogation from Article 73, providers of high-risk AI systems subject to the competence of the AI Office pursuant to paragraph 1 of that Article shall report any serious incidents to the AI Office. Article 73(2) to (9) shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in the territory of which the provider or its legal representative is situated. Paragraph 1e provides that the AI Office shall be responsible for conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to a third-party conformity assessment pursuant to Article 43, before such systems are placed on the market or put into service. The Commission shall entrust the performance of those tests or assessments to notified bodies designated in accordance with this Regulation, in which case the notified body acts on behalf of the Commission, and the Commission may withdraw the delegation with immediate effect where a notified body does not perform those tasks adequately. The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for a third-party conformity assessment to the Commission, and that provider shall pay the costs directly to the notified body.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is not a clean change of counter. Paragraph 1a moves the address of the report and nothing more: Article 73(2) to (9) continues to apply mutatis mutandis, so the deadlines, the immediate initial report, the investigation and the duty to cooperate stay exactly as they are, and the AI Office transmits the relevant information to the market surveillance authority of your Member State in any event. Anyone who concludes from this that the Article 73 clock has stopped will miss the duty on the day things go wrong. Paragraph 1e is the heavier of the two and is most often overlooked, because it is not a reporting duty but a change of route in your market access: where your high-risk system falls under the competence of the Office and under a third-party conformity assessment, that assessment now runs through the Commission, a notified body carries it out on behalf of the Commission, and you carry the bill, paid directly to that body. Two things to do now: budget the cost in your planning rather than at the moment of application, and take into account that the Commission may withdraw a delegation with immediate effect, so your assessment can change hands while it is running.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record per high-risk system whether it falls under the competence of the AI Office, and adjust your incident procedure accordingly: the same form, the same Article 73 deadlines, a different address. State explicitly in that procedure that the Office forwards the report to your national market surveillance authority, so that nobody assumes a second report is needed or that the national authority drops out of the picture. For systems that require a third-party conformity assessment, check whether that assessment will run through the Commission, budget the fees you pay directly to the notified body, and plan generous lead time, because an assessment before the system is placed on the market is a blocking step and not an administrative afterthought.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-75-ai-office-high-risk-duties","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance","legacy_id":"raip:obligation:article-75-market-surveillance-assistance","type":"obligation","slug":"article-75-market-surveillance-assistance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9ae93e711b67b4eb9e0212da4542e3e5d0eb4495a90fe1b956b58472f4461925","label":"Article 75: market surveillance, mutual assistance and the powers of the AI Office","summary":"For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.","topics":["enforcement","governance","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Four things are unsettled here. First, what this provision asks of you: it addresses the AI Office and the market surveillance authorities and imposes no literal duty on the organisation in this object. We read a practical consequence into it, namely that you must know in advance which authority is competent and must be able to answer a demand or an inspection within the period set; that is our reading and not the text. The literal duties in Article 75 sit in the separate object article-75-ai-office-high-risk-duties. Second, the delineation in paragraph 1: whether the model and the system were developed by the same provider or within the same undertaking is a question of fact on which no guidance exists, and the four carve-outs put the case back with a national authority per system. Third, the language versions of the amending regulation diverge on the limitation period in Article 75c(8): the Dutch edition says three years, the English edition five years. We render per language what that edition says and pick no winner; until a corrigendum, plan on the longer period. Fourth, there is still no consolidated text of Article 75, so the amended heading, the replaced paragraph 1 and the inserted articles can only be read in the amending text. The cost of this status is real: a preliminary reading is skipped by lib/answer/derive-obligations.ts, so this object does not appear in the per-situation derivation. A defensible alternative reading is that this provision is purely a division of competence for you and that your preparation is governed entirely by Article 21, Article 26 and Article 73.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-competent-supervisor"],"evidence_ids":["praxikon:eu:ai-act:evidence:supervisor-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:ai-office-proceeding-response"],"template_ids":["praxikon:eu:ai-act:template:article-75-legal-text"],"conditions":[{"id":"article-75-scope","operator":"any","description":"Applies to AI systems based on a general-purpose AI model where the model and the system are developed by the same provider or by providers forming part of the same undertaking, and to AI systems that constitute or are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The exclusive competence applies to the providers of those systems, and to deployers only where they are also the provider or form part of the same undertaking as the provider."},{"id":"article-75-timing","operator":"all","description":"The allocation of competence itself operates from 2 August 2026, because Article 75 sits in Chapter IX. It covers the obligations that apply at that moment, such as the prohibition in Article 5, the transparency duties of Article 50 and the obligations for general-purpose AI models. The two literal duties the amending regulation places on the provider, the reporting route of paragraph 1a and the fees of paragraph 1e, attach to high-risk status and therefore follow 2 December 2027; they sit in the separate object article-75-ai-office-high-risk-duties."}],"exceptions":[{"id":"article-75-exception-carve-outs","operator":"not","description":"Paragraph 1, point (a) carves four groups out of the exclusive competence of the AI Office: AI systems related to products covered by the Union harmonisation legislation listed in Annex I, systems referred to in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and systems referred to in point 8 of Annex III as regards the administration of justice. Who is competent instead differs per group and is not always \"the market surveillance authority\": for financial institutions Article 74(6) points to the national authority responsible for their financial supervision, and for law enforcement, border management and the administration of justice Article 74(8) has the Member State designate either the data protection supervisory authority or another authority under the same conditions. Which body that is per Member State does not follow from the Regulation."}],"statements":[{"kind":"official_fact","text":"Paragraph 2 provides that where the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly. Paragraph 3 provides that where a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 75(2)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces the heading of Article 75 with \"Market surveillance and control of AI systems and mutual assistance\" and replaces paragraph 1: the AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to, point (a), AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of (i) AI systems related to products covered by the Union harmonisation legislation listed in Annex I, (ii) AI systems referred to in point 2 of Annex III, (iii) AI systems provided by law enforcement authorities, border management authorities and financial institutions insofar as those systems fall under Article 74(6), and (iv) AI systems referred to in point 8 of Annex III as regards the administration of justice; and, point (b), AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The final subparagraph provides that the exclusive competence applies to the providers of those systems, and to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same regulation inserts paragraphs 1b to 1d and paragraph 2a. Paragraph 1b requires the authorities involved in the application of the Regulation to cooperate actively with the AI Office and to provide it the necessary assistance, including in connection with inspections or other enforcement measures carried out in the territory of a Member State. Paragraph 1c provides that the Office shall be assisted by the relevant market surveillance authority when investigatory or enforcement action involves access to a public authority data or AI system. Paragraph 1d provides that before taking a decision that would prohibit or restrict the system being made available or put into service on a national market, or a decision to withdraw or recall it from such market, the Office shall without undue delay notify the market surveillance authority competent for that market of its intention. Paragraph 2a allows a market surveillance authority with well-founded and sufficient reasons to suspect an infringement to request, through the single point of contact designated under Article 70(2), that the AI Office assess the matter; that request shall be duly reasoned and shall state at least the provider or deployer concerned, the relevant facts and the provisions allegedly infringed, and the requesting authority. The Office informs the point of contact without undue delay and in any event no later than four months after receipt whether it will exercise its powers, or why it will not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1b) to (1d) and (2a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75a gives the AI Office all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020, and authorises it to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance. Paragraph 2 allows the Office, on reasonable grounds, to start an investigation, of which it notifies the operator, and provides that it may exercise its powers on its own initiative or following a complaint received pursuant to Article 85, even before starting an investigation. Paragraph 3 allows information requests by simple request or by decision; with a simple request the Office states that there is no obligation to reply but that a voluntary reply must be correct and not misleading, and in both cases it indicates the fines provided for in Article 99(5), and by decision also the right to review by the Court of Justice; a copy of the request goes to the national market surveillance authority. Paragraph 4 allows remote and on-site inspections in which officials may enter business premises, examine and copy books and data, ask for oral or written explanations and seal premises; where national law requires authorisation by a judicial authority, the Office applies for it and the national judicial authority verifies that the coercive measures envisaged are neither arbitrary nor excessive. Paragraph 6 allows the Office to order operators to provide access to and explanations relating to their AI systems and to impose on an operator an obligation to retain all data and documents deemed necessary to assess compliance. Paragraph 7 allows the appointment of independent external experts and auditors, and paragraph 8 provides that information collected shall be used only for the purpose of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Article 75a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75b allows the Office to make commitments offered by the operator during proceedings under Article 75a(2) binding by decision and to declare that there are no further grounds for action; it may reopen the proceedings where there has been a material change in the facts, where the operator acts contrary to its commitments, or where the decision was based on incomplete, incorrect or misleading information, and it rejects inadequate commitments in a reasoned decision. Article 75c provides in paragraph 1 that the Office adopts a decision establishing non-compliance, in paragraph 2 that it first communicates its preliminary findings, and in paragraph 3 that the decision may order the operator to take the necessary measures within a reasonable period and that the operator shall provide the Office with a description of the measures it has taken. Paragraph 4 provides that such a decision may be accompanied by penalties in accordance with Article 99(3) to (7), which apply mutatis mutandis to the AI Office, and that in particular the following are subject to fines as referred to in Article 99(4): (a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4), (b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 as well as those specified in Article 75a, and (c) failure to comply with a commitment made binding pursuant to Article 75b; the supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 allows periodic penalty payments to compel submission to an investigation, compliance with an information request ordered by decision, submission to an ordered inspection, the provision of correct or complete answers or explanations in the context of an ordered inspection, compliance with corrective actions, compliance with a binding commitment, or compliance with a decision under paragraph 1; those payments shall, where applicable, not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 8 sets a limitation period: the Dutch edition in the Official Journal says three years, the English edition says five years. Article 75d applies Article 18 of Regulation (EU) 2019/1020 mutatis mutandis in paragraph 1, safeguards the rights of defence and access to the file under negotiated disclosure in paragraph 2, and provides in paragraph 4 that the Office publishes its decisions under Articles 75b and 75c stating the names of the parties and the main content, including any penalties imposed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75b, 75c and 75d","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical question behind this provision is simple and rarely asked: who comes knocking. What is new is not that the AI Office appears, because the old paragraph 1 already gave it powers to monitor and supervise systems where the model and the system come from the same provider. What is new is that this competence becomes exclusive rather than shared, that it extends to providers within the same undertaking, that a second category is added in the form of designated very large online platforms and search engines, that four groups are carved out of it, and that Articles 75a to 75d give the Office a toolkit of its own. That toolkit is the point. An information request comes as a simple request or by decision; with a simple request you need not answer, but whoever answers voluntarily must answer correctly and not misleadingly, and with a decision the clock runs. An inspection extends to entering business premises, copying data and sealing cabinets and systems, with a real safeguard in front of it: where national law requires judicial authorisation, the Office applies for it and that judge verifies that the coercive measures are neither arbitrary nor excessive. Commitments are a genuine way out, but they become binding, the decision is published with the names of the parties, and the proceedings reopen if the facts change materially, if you act contrary to them, or if your information turns out to be incomplete or incorrect. Two things that are rarely seen. The trigger need not come from an authority: Article 75a(2) lets the Office exercise its powers following a complaint under Article 85, even before an investigation is running. And cost recovery is not unconditional: the Office may fully reclaim its supervision costs insofar as they relate to instances of non-compliance, so supervision costs you money when you are in the wrong and not merely because supervision happened. The line between the two regimes sits in paragraph 1 and it is not trivial; answer it once per system and record it, rather than working it out at the moment a demand arrives.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, points (31) and (32)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per AI system which authority is competent, record the outcome and the reasoning, and revisit that record whenever the model, the provider or the corporate structure changes. Designate someone who receives an information request, a notice of investigation or an announced inspection, and have that person first establish whether it is a simple request or a decision, because that determines whether there is a duty to reply and which period runs. Make sure technical documentation, logs and assessments can be produced in full and per version on request, and take into account that under Article 75a(6) the Office may order you to retain all data and documents it deems necessary; such an order overrides your own deletion routines. Do not count on harmless incompleteness: incorrect, incomplete or misleading information is a separate ground for a fine under Article 99(5), and a periodic penalty payment can also be imposed where you fail to give correct or complete answers during an ordered inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75a and 75c","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-75-market-surveillance-assistance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: the right to complain that can start a proceeding"},{"relation":"related","href":"/en/ai-act/artikel/99","label":"Article 99: the fine bands to which Article 75c refers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-78-confidentiality","legacy_id":"raip:obligation:article-78-confidentiality","type":"obligation","slug":"article-78-confidentiality","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fe3d73fa9cc874bc4fc12b0f664ff4e60e68de553dfc7bf0c64c38bc1350c8e3","label":"Article 78: confidentiality of what you submit to an authority","summary":"The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.","topics":["enforcement","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:mark-confidential-material-on-submission"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-78-submission-register"],"control_ids":["praxikon:eu:ai-act:control:article-78-disclosure-review"],"template_ids":["praxikon:eu:ai-act:template:article-78-legal-text"],"conditions":[{"id":"article-78-scope","operator":"all","description":"Applies to all information and data obtained by the Commission, the market surveillance authorities, the notified bodies and any other natural or legal person involved in the application of this Regulation in carrying out their tasks and activities. The protection operates in accordance with Union or national law and not on its own."},{"id":"article-78-strict-necessity","operator":"all","description":"Paragraph 2 limits what an authority may request: only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of its powers in accordance with this Regulation and with Regulation (EU) 2019/1020. Two follow-on duties attach to that: adequate and effective cybersecurity measures, and deletion as soon as the data is no longer needed for the purpose for which it was obtained."}],"exceptions":[{"id":"article-78-trade-secrets-directive-carve-out","operator":"not","description":"The protection of intellectual property, confidential business information and trade secrets, including source code, applies except in the cases referred to in Article 5 of Directive (EU) 2016/943. Point (a) of paragraph 1 says so in as many words."},{"id":"article-78-information-exchange-unaffected","operator":"not","description":"Paragraph 4 provides that paragraphs 1, 2 and 3 do not affect the rights or obligations of the Commission, the Member States and their relevant authorities, or those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor the obligations of the parties concerned to provide information under criminal law of the Member States. Confidentiality under this article is therefore not a duty of silence between authorities."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that the Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a) the intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943; (b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits; (c) public and national security interests; (d) the conduct of criminal or administrative proceedings; (e) information classified pursuant to Union or national law. Paragraph 2 provides that the authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020, that they shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and that they shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides that, without prejudice to paragraphs 1 and 2, information exchanged on a confidential basis between the national competent authorities or between national competent authorities and the Commission shall not be disclosed without prior consultation of the originating national competent authority and the deployer when high-risk AI systems referred to in point 1, 6 or 7 of Annex III are used by law enforcement, border control, immigration or asylum authorities and when such disclosure would jeopardise public and national security interests. This exchange of information shall not cover sensitive operational data in relation to the activities of law enforcement, border control, immigration or asylum authorities. The second subparagraph of paragraph 3 provides that when the law enforcement, immigration or asylum authorities are providers of high-risk AI systems referred to in point 1, 6 or 7 of Annex III, the technical documentation referred to in Annex IV shall remain within the premises of those authorities, that those authorities shall ensure that the market surveillance authorities referred to in Article 74(8) and (9), as applicable, can, upon request, immediately access the documentation or obtain a copy thereof, and that only staff of the market surveillance authority holding the appropriate level of security clearance shall be allowed to access that documentation or any copy thereof.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 4 provides that paragraphs 1, 2 and 3 shall not affect the rights or obligations of the Commission, Member States and their relevant authorities, as well as those of notified bodies, with regard to the exchange of information and the dissemination of warnings, including in the context of cross-border cooperation, nor shall they affect the obligations of the parties concerned to provide information under criminal law of the Member States. Paragraph 5 provides that the Commission and Member States may exchange, where necessary and in accordance with relevant provisions of international and trade agreements, confidential information with regulatory authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of confidentiality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article as the answer to the question your supplier asks and that you ask yourself as soon as you have to hand something over. The protection is real and it names source code expressly, which is unusually explicit in Union law. But it is a duty of the recipient and not a right of refusal for the party submitting. Article 21(1) requires the provider, upon a reasoned request, to give all the information and documentation necessary to demonstrate conformity; Article 78 does not say you may withhold anything, it says what the recipient must do afterwards. Anyone who inverts that and refuses on grounds of confidentiality is legally empty-handed. Two limits on top, because they get missed in practice. The first is Article 5 of Directive (EU) 2016/943: that exception sits verbatim in point (a) and it covers, among other things, exercising the right to freedom of expression and information and revealing misconduct in the general public interest. The second is paragraph 4: between authorities, and when disseminating warnings, confidentiality does not operate as a lock. Your file can therefore reach another Member State without that being a breach. What does work in your favour is paragraph 2. That is a strict necessity test on the request itself, with a retention limit attached: deletion as soon as the data is no longer needed for the purpose for which it was obtained. That is a question you can put to an authority and whose answer you can record.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 78(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"There is an asymmetry in this article that is rarely noticed. Paragraph 3 gives one set of parties a heavy extra protection: where a high-risk system from point 1, 6 or 7 of Annex III is used by a law enforcement, border control, immigration or asylum authority, information exchanged on a confidential basis may not be disclosed without prior consultation of the originating authority and the deployer, and the technical documentation stays physically within the premises of that authority where it is itself the provider. For a commercial provider in exactly the same Annex III areas that arrangement does not apply. The practical conclusion is not that one is better protected than the other, but that you need to know which side you are on: if you supply such an authority, your documentation travels a different path from your own archive, and you settle that path in the contract rather than after the fact. Note also what this article does not govern. It says nothing about the public availability of the EU database in Article 71, whose public part is meant to be found, and nothing about what a deployer must explain to an affected person under Article 86. Confidentiality towards a regulator and transparency towards a citizen are two separate tracks in this Regulation, and it is a mistake to try to close one with the other.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Mark on every submission which part you regard as confidential business information, trade secret or source code, and why, and keep a register of what you handed to whom on what date. That register is your only starting point if you later want to know whether something left the circle. When asked for additional data, ask about the necessity within the meaning of paragraph 2 and about the purpose for which the data is obtained, and record the answer; that is not a refusal and it is the only way to be able to invoke the retention limit of paragraph 2 later. Put in supplier contracts who receives a request from an authority, who decides what is handed over, and that the other party is informed within an agreed period. If you supply a law enforcement, border control, immigration or asylum authority, record where the technical documentation stays physically and who has access to it. Finally, do not assume that confidentiality releases you from Article 21: the duty to deliver on request stands apart from the recipient’s duty to handle what is delivered with care.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1); Article 74(8) and (9); Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-78-confidentiality","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 78 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/78","label":"Read Article 78 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements","legacy_id":"raip:obligation:article-8-compliance-with-requirements","type":"obligation","slug":"article-8-compliance-with-requirements","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f","label":"Article 8: compliance with the requirements for high-risk AI systems","summary":"High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.","topics":["conformity","high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What the provision asks of a provider is settled; when it asks it has been derived here. Article 8 sits in Chapter III, Section 2, and names no date of its own. The timeline canon dates the high-risk requirements per route and not per chapter: 2 December 2027 for the systems that are high-risk through Annex III, and 2 August 2028 for those that are high-risk through Annex I. Those two dates do not fit in a field that carries one. `deadline_at` therefore carries 2 December 2027, the earlier of the two and the same date already carried by the objects for Articles 9 to 15. A defensible alternative reading is that a chapeau provision should carry no date of its own and that the dating belongs with the seven requirements it sits above; on that reading this field reads as the earliest of the two routes and not as the date of Article 8. On either reading: for a system inside a regulated product under Annex I, 2 December 2027 is too early and 2 August 2028 is the date that counts. What also remains open is the content of the second measure in paragraph 1. The generally acknowledged state of the art is not a term the Regulation defines and not a synonym for a harmonised standard; anyone who equates it with the standard of Article 40 closes an open measure. On Regulation (EU) 2026/1744. That text was retrieved after all on 6 September 2026 from the Publications Office Cellar service and is archived in data/ai-act/review/sources/reg-eu-2026-1744-nl.txt and -en.txt. The amending regulation carries forty-three amendment points in its Article 1; which of those are reflected in the local legal texts is recorded per point in data/ai-act/review/consolidation-manifest.json. Where a point touches this Article, that is stated below with the statement concerned.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification"],"control_ids":["praxikon:eu:ai-act:control:article-8-integrated-documentation-review"],"template_ids":["praxikon:eu:ai-act:template:article-8-legal-text"],"conditions":[{"id":"article-8-scope","operator":"all","description":"Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision."},{"id":"article-8-two-measures","operator":"all","description":"Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing."},{"id":"article-8-annex-i-product","operator":"any","description":"Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing."}],"exceptions":[{"id":"article-8-integration-is-a-choice","operator":"not","description":"The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that high-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements. Paragraph 2 provides that, where a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 8(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read Article 8 not as an eighth requirement alongside the seven of Articles 9 to 15, but as the provision that says how those seven are to be read. It does two things none of the seven does itself. The first is that it brings in a measure from outside the Regulation. Article 8 is the only article in Section 2 that names the generally acknowledged state of the art, and that means the bar moves. A file that sufficed at the first conformity assessment does not necessarily still suffice some years later, without a single word of the Regulation changing: what was the state of the art then is no longer the state of the art later. The Regulation provides no re-certification rhythm for this beyond the substantial modification of Article 43(4), so anyone who does not set a rhythm of their own has none. Note also what the measure is not. The state of the art is not a synonym for a harmonised standard: Article 40 gives a presumption of conformity to whoever applies such a standard, but Article 8 sets an open measure alongside it that does not stop applying once the standard has been ticked off. The second is that paragraph 1 designates the risk management system of Article 9 as the instrument through which compliance with the other requirements is assessed. Article 9 is therefore not one requirement beside the other six but the file in which you show that you have met the other six at the right level. An organisation that keeps its risk analysis as a separate document beside the technical documentation misses exactly that connection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Paragraph 2 is the anti-duplication provision, and in practice it is rarely used. It concerns the product that contains an AI system and falls both under this Regulation and under the Union harmonisation legislation of Section A of Annex I: that is precisely the route of Article 6(1). Two different things are stated. The first is an allocation: the provider is responsible for his product being fully compliant with everything the sectoral legislation requires. It does not say that the AI Act replaces or lightens the sectoral requirements, nor that the sectoral assessment swallows the requirements of Section 2; it says that both stacks apply at once and that the provider of the product covers both. The second is a choice, not a duty: he may integrate the testing and reporting processes, the information and the documentation on the product into the documentation and procedures the sectoral legislation already prescribes. We see two mistakes there. The first is that the AI Act file is built beside the existing technical file, with two versions of the same risk analysis that drift apart after two releases; that is exactly the duplication paragraph 2 seeks to avoid. The second is that the integration happens but cannot be found. Whoever enters the sectoral conformity assessment of Article 43(3) must be able to point, per requirement of Articles 9 to 15, to where in the existing file the answer sits. Integrating is therefore not merging into invisibility; it is a cross-reference per requirement, and that is the form in which the choice of paragraph 2 actually saves work.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record once, per high-risk system, what you regard as the generally acknowledged state of the art, with the sources: which harmonised standards or common specifications you apply, which of them you do not apply and why, and which evaluation method, benchmark or test set you use for this application area. Attach a fixed re-assessment moment to it, for instance annually and at every release, and hang that record on the risk management file of Article 9 rather than on a separate document; paragraph 1 designates that file as the instrument through which compliance is assessed. Note against which intended purpose each requirement of Articles 9 to 15 has been met, so that a change of intended purpose visibly touches the whole series. If your system sits in a product also covered by Section A of Annex I, make the choice of paragraph 2 explicit before you start and record who made it: one combined file or two files. If you combine, build a cross-reference table that points, per requirement of Section 2, to where in the existing technical file the answer sits, and let that table travel through the sectoral assessment. If you keep two files, record who keeps them in step and on which change both are updated.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 8 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/8","label":"Read Article 8 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-85-right-to-complain","legacy_id":"raip:obligation:article-85-right-to-complain","type":"obligation","slug":"article-85-right-to-complain","version":"2.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c6e765304e4a6ec68888e1611d72b0dae35de32e420bd1f947eff02c902433f5","label":"Article 85: right to lodge a complaint with the market surveillance authority","summary":"Anyone with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority. For an organisation that means your own staff, customers and candidates have a route to the regulator that does not run through you.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The right itself is settled; what it asks of you is not. Article 85 addresses the market surveillance authority and imposes no literal duty on the organisation complained about: there is no deadline, no duty to inform and no requirement to set up an internal complaints channel. We nonetheless read a practical consequence into it, namely that you must be able to rebut a complaint with recorded evidence at the moment the authority asks, and that is not the same as a duty following from the text. A defensible alternative reading is that this article is purely procedural for you and that your preparation is governed entirely by Article 26 and Article 72. It is also unclear how this right to complain relates to the right to complain under the GDPR where the same conduct engages both.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-for-a-complaint"],"evidence_ids":["praxikon:eu:ai-act:evidence:explanation-request-record"],"control_ids":["praxikon:eu:ai-act:control:explanation-request-routing"],"template_ids":["praxikon:eu:ai-act:template:article-85-legal-text"],"conditions":[{"id":"article-85-scope","operator":"all","description":"Applies as soon as anyone has grounds to consider that the Regulation has been infringed. There is no standing threshold: the right belongs to any person, and the complaint goes to the market surveillance authority of the Member State concerned."}],"exceptions":[],"statements":[{"kind":"official_fact","text":"Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority. In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical meaning of this article lies not in what it instructs you to do but in whom it gives a route. An employee who thinks the scheduling or appraisal system is wrong, a rejected candidate, a customer who feels mishandled: they do not have to convince you first and do not have to show standing. The complaint arrives at the authority, and the first question you then face is about record keeping: which system, which version, which assessment was carried out and when. That is the same record keeping Articles 26 and 72 already require of you, and that is exactly the point. Whoever has that file answers a complaint with documents; whoever does not answers it with a reconstruction after the fact, and a regulator reads that differently. Note too that this right does not depend on harm or on a decision, whereas the right to an explanation in Article 86 does.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Assume a complaint starts at the authority and not with you. Make sure that per AI system you can show which assessment was carried out, by whom, on what date and against which system version, and keep that as a living file rather than a one-off document. Also agree internally who receives a question from an authority and within what period.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 85","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-85-right-to-complain","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 85 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-86-right-to-explanation","legacy_id":"raip:obligation:article-86-right-to-explanation","type":"obligation","slug":"article-86-right-to-explanation","version":"2.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"62515aef8dd5cfe3e72e71bd0d1f12da34f9cbe0d884940264d26bce0c911b49","label":"Article 86: right to an explanation of a decision","summary":"A person affected by a decision that a deployer takes on the basis of the output of a high-risk AI system listed in Annex III may request an explanation of the role of that system in the decision-making procedure and of the main elements of the decision taken.","topics":["fundamental-rights"],"actor_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"One thing is unsettled here: how deep the explanation has to go. The Regulation asks for clear and meaningful explanations of the role of the system and the main elements of the decision taken, but there is no case law and no guidance saying whether a description of the factors used is enough or whether it concerns the weighting in the individual case. We read it as the latter, because the text speaks of the decision taken rather than of the system in general. The date question is no longer open: decision D1 of 6 September 2026 chooses the text reading, so Article 86 applies from 2 August 2026 to systems already in use at that point. The practical reading, that the right only acquires an object once the Annex III regime operates on 2 December 2027, is not written away but sits as an annotation in high_risk_regime_from.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:handle-explanation-requests"],"evidence_ids":["praxikon:eu:ai-act:evidence:explanation-request-record"],"control_ids":["praxikon:eu:ai-act:control:explanation-request-routing"],"template_ids":["praxikon:eu:ai-act:template:article-86-legal-text"],"conditions":[{"id":"article-86-scope","operator":"all","description":"Applies where a deployer takes a decision about a natural person on the basis of the output of a high-risk AI system listed in Annex III, with the exception of point 2 of that Annex, and that decision produces legal effects or similarly significantly affects that person in a way they consider to have an adverse impact on their health, safety or fundamental rights."}],"exceptions":[{"id":"article-86-exception-union-or-national-law","operator":"not","description":"Paragraph 2 excludes the right for AI systems where exceptions from, or restrictions to, that obligation follow from Union or national law in compliance with Union law. Paragraph 3 further limits the right to cases where it is not otherwise provided for under Union law, which makes the boundary with Article 22 GDPR a case-by-case question."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 gives any affected person subject to a decision taken by the deployer on the basis of the output of a high-risk AI system listed in Annex III, with the exception of point 2 of that Annex, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights, the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and of the main elements of the decision taken. Paragraph 2 provides that paragraph 1 does not apply to the use of AI systems for which exceptions from, or restrictions to, that obligation follow from Union or national law in compliance with Union law. Paragraph 3 provides that this Article applies only to the extent that the right referred to in paragraph 1 is not otherwise provided for under Union law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This right reaches you through a different channel than the rest of the Regulation. A regulator writes to you; a candidate or a citizen calls or emails, usually at your existing complaints or objections desk. That desk does not know today that an AI system was in the process, let alone what role it played, and that is where it goes wrong. Two things therefore matter more than the legal depth of the explanation itself: that your front line recognises such a request, and that it can be traced per decision which system in which version contributed to it. Without the second you can explain how your system works in general but not what happened in this case, and the latter is what is being asked. Note also the relationship with Article 22 GDPR: where that article already grants a right, Article 86 steps back, but the scope differs enough that you cannot settle the question in the abstract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record, per Annex III system that contributes to decisions about people, which decision was supported by which system version, and make sure your complaints or objections desk recognises a request for an explanation and routes it to someone who can answer it. Also determine per process whether Article 22 GDPR already grants a right, because Article 86 then steps back.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 86(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-86-right-to-explanation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 86 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-87-reporting-infringements","legacy_id":"raip:obligation:article-87-reporting-infringements","type":"obligation","slug":"article-87-reporting-infringements","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6","label":"Article 87: reporting of infringements and protection of reporting persons","summary":"The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.","topics":["fundamental-rights","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"requires_legal_judgment","interpretation_status":"preliminary","interpretation_note":"The reference is settled; what it asks of you is not. Article 87 consists of one sentence and makes Directive (EU) 2019/1937 applicable to reporting and to the protection of reporting persons. It imposes no channel requirement of its own, sets no deadline and names no threshold: those sit in Articles 8, 9 and 21 of that Directive and in national transposition law, a layer this dataset does not carry as a source. That is why no duty holder is assigned here and the status is requires_legal_judgment. The sharpest open point is the fit with national law: the material scope of the Directive is tied through Article 2(1)(a) to the Union acts in its Annex, and Regulation (EU) 2024/1689 is not in that Annex. One reading is that Article 87 operates directly and that national law tying its scope to that Annex simply lags behind; the other is that the protection only becomes practically available through the national channel, so that the extension requires national transposition. We have not settled that. What we do read into it is a practical consequence: an organisation that must already have a reporting channel must be able to receive a report about an AI system through it. Settled and not unclear is that the personal scope of the Directive is work-related; Article 4 is explicit about that. What is open is only what remains outside that context, and whether that amounts to the complaint route of Article 85 without the protection of Article 87.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:open-a-protected-reporting-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:infringement-report-record"],"control_ids":["praxikon:eu:ai-act:control:reporting-person-protection"],"template_ids":["praxikon:eu:ai-act:template:article-87-legal-text"],"conditions":[{"id":"article-87-scope","operator":"all","description":"The trigger is a report of an infringement of this Regulation, whatever the risk class of the system: a report about an AI system outside the high-risk category is covered just as much. The protection itself is not unconditional. It comes from Directive (EU) 2019/1937, which in Article 4 requires the person reporting to have obtained the information in a work-related context, and in Article 6(1)(a) requires reasonable grounds to believe that what was reported was true and fell within the scope of that Directive."}],"exceptions":[{"id":"article-87-no-internal-channel-below-threshold","operator":"any","description":"Article 87 creates no channel requirement. That requirement comes from Article 8 of Directive (EU) 2019/1937. Paragraph 1 places it on legal entities in the private and the public sector; paragraph 3 limits paragraph 1 in the private sector to entities with 50 or more workers. That threshold is not general, however. Paragraph 4 provides that the threshold in paragraph 3 shall not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, following a risk assessment, to require entities with fewer than 50 workers as well. Paragraph 9 applies paragraph 1 to all legal entities in the public sector, with the option for a Member State to exempt municipalities under 10 000 inhabitants and other small public entities. Below fifty workers there is therefore not simply no channel requirement: it depends on the sector you fall in and on what your Member State has decided. The right to report and the protection of the person reporting exist in any event, through the external route of Article 10 of that Directive."},{"id":"article-87-national-scope-not-settled","operator":"any","description":"The material scope of Directive (EU) 2019/1937 runs through Article 2(1)(a), which refers to the Union acts listed in the Annex to that Directive. Regulation (EU) 2024/1689 was not added to that Annex: it makes the Directive applicable directly, in Article 87. National transposition law that ties its own scope to that same Annex, such as the Dutch Wet bescherming klokkenluiders, may therefore lag behind the Regulation. Whether a report about an AI system falls under national law as a result is not settled."}],"statements":[{"kind":"official_fact","text":"Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article is short because the work was done elsewhere, and that is exactly why it gets overlooked. Its practical meaning lies in the direction of travel: Articles 85 and 86 concern who knocks on your door from outside, Article 87 concerns who steps out from within. That is almost always the first person to notice something. The developer who knows the logging has not run for months, the recruiter who sees the selection model filtering out candidates on something that should never have been in it: they hold the facts a regulator only obtains after an investigation. Three things follow. If you must already have a reporting channel, that channel must be able to receive such a report and recognise it as touching the AI Regulation, because a report handled as a general complaint disappears into a different process. Whether you must have that channel is not a matter of a single number. Article 8(3) of Directive (EU) 2019/1937 imposes the channel requirement in the private sector at fifty or more workers, but paragraph 4 sets that threshold aside for entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, after a risk assessment, to require smaller entities as well, and paragraph 9 imposes the requirement on all legal entities in the public sector, with an optional exemption a Member State may make for municipalities with fewer than ten thousand inhabitants or fewer than fifty workers, and for other public entities with fewer than fifty workers. Below fifty workers the question is therefore which sector you are in and what your Member State has decided, not whether you clear the threshold. If you are genuinely outside each of those cases the channel need not exist, and even then the person reporting has somewhere to go: Article 10 of that Directive gives them an external route to the competent authority without having to report internally first, and Article 15 permits public disclosure under conditions. And the protection is not a formality, but it is not enforced through this Regulation: Article 19 of the Directive prohibits retaliation and Article 21 sets out the protective measures, and enforcement runs through national whistleblower law, in the Netherlands through the Huis voor Klokkenluiders and the civil courts. Article 99 of this Regulation does not list Article 87 among the fineable infringements; there is therefore no AI Act fine for disadvantaging a person who reported. Note too that the report here does not depend on a decision or on harm, whereas the right to an explanation in Article 86 does.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First determine whether Directive (EU) 2019/1937 and national transposition law apply to you at all: below fifty workers there is in principle no channel requirement, in which case this object is not a set-up question for you. If you are covered, check whether your existing reporting channel recognises a report about an AI system and whether whoever receives it knows the AI Regulation may be engaged. Record per report what was reported, about which system, what was done with it and when feedback was given, and measure that against the deadlines in Article 9(1) of that Directive: acknowledgement of receipt within seven days under point (b), feedback within three months under point (f). Keep the identity of the person reporting out of what goes to line managers (Article 16), retain no longer than necessary and proportionate (Article 18(1)), and record an oral report only with consent (Article 18(2) to (4)). Also decide whether you will handle anonymous reports: Article 6(2) leaves that choice to the Member State, so check what your national law says. Finally, put to your lawyer the question whether your national whistleblower act already covers AI Act infringements, because such an act usually ties its scope to the Annex to the Directive and Regulation (EU) 2024/1689 is not listed there.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: right to lodge a complaint with the market surveillance authority"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-9-risk-management","legacy_id":"raip:obligation:article-9-risk-management","type":"obligation","slug":"article-9-risk-management","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dba4fb36d8780aa218d15aae4742d2183cfcf1fd6f85a6d4db5901b93c9e6c53","label":"Article 9: risk management system","summary":"A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-9-risk-management-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-9-risk-management-record"],"control_ids":["praxikon:eu:ai-act:control:article-9-risk-management-control"],"template_ids":["praxikon:eu:ai-act:template:article-9-risk-management-legal-text"],"conditions":[{"id":"article-9-risk-management-scope","operator":"all","description":"The system is high-risk under Article 6 and the provider places it on the market or puts it into service."}],"exceptions":[{"id":"article-9-risk-management-exception","operator":"not","description":"Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope."}],"statements":[{"kind":"official_fact","text":"Article 9 requires a risk management system as a continuous, iterative process across the entire lifecycle, with identification, analysis, evaluation and mitigation of risks to health, safety and fundamental rights, and testing to determine the most appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is not a one-off risk analysis but a living process: most organisations have an assessment, but no cycle that reruns on every change. The cycle is what a supervisor will request.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Start the risk management file now for systems that will become high-risk towards 2 December 2027: today’s design and procurement choices determine tomorrow’s residual risks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 9(1)-(10)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-9-risk-management","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 9 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct","legacy_id":"raip:obligation:article-95-voluntary-codes-of-conduct","type":"obligation","slug":"article-95-voluntary-codes-of-conduct","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b71546d72d3dbc5918daae97128ae05900c52ce93ba71de9866e90de4176e14","label":"Article 95: codes of conduct for voluntary application of specific requirements","summary":"The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-95-voluntary-commitment-register"],"control_ids":["praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review"],"template_ids":["praxikon:eu:ai-act:template:article-95-legal-text"],"conditions":[{"id":"article-95-scope","operator":"all","description":"Paragraph 1 expressly concerns AI systems other than high-risk AI systems, and the voluntary application to them of some or all of the requirements set out in Chapter III, Section 2. Paragraph 2 is wider and concerns the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives. Article 95 sits in Chapter X, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."},{"id":"article-95-who-may-draw-up","operator":"any","description":"Paragraph 3 sets out who may draw up a code of conduct: individual providers or deployers of AI systems, organisations representing them, or both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. A code may cover one or more AI systems, taking into account the similarity of the intended purpose of the relevant systems."}],"exceptions":[{"id":"article-95-no-substitute-for-a-requirement","operator":"not","description":"Article 95 contains no provision that sets aside, suspends or replaces an obligation under this Regulation. The word voluntary refers to the application of requirements that precisely do not apply to the system concerned, and not to the requirements that do apply. A code of conduct on AI literacy leaves Article 4 untouched, and a code of conduct on transparency leaves Article 50 untouched."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: the AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements. Paragraph 2 provides: the AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to: (a) applicable elements provided for in Union ethical guidelines for trustworthy AI; (b) assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI; (c) promoting AI literacy, in particular that of persons dealing with the development, operation and use of AI; (d) facilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders participation in that process; (e) assessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides: codes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems. Paragraph 4, as replaced by Article 1, point (35), of Regulation (EU) 2026/1744, provides: the AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and small mid-cap enterprises, when encouraging and facilitating the drawing up of codes of conduct.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article first for what it is not. It imposes no duty on your organisation: paragraphs 1, 2 and 4 address the AI Office and the Member States, and paragraph 3 only says who may draw a code up. And paragraph 1 is expressly about AI systems other than high-risk AI systems. That is the core of the provision and at the same time the source of the biggest misunderstanding in practice. The common thought is that a code of conduct can replace a mandatory requirement, or that signing one produces a form of compliance a regulator can hold against you or count in your favour. Neither is in the text. The voluntariness in Article 95 concerns requirements that precisely do not apply to your system: Chapter III, Section 2, contains the requirements for high-risk AI systems, and Article 95 invites you to apply some or all of those requirements to a system that is not high-risk. The reverse, a lighter reading of a requirement that does apply, is not on offer in this article. Two limits go with that. Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy. Article 95(2), point (c), names promoting AI literacy as a possible element of a code of conduct. That is not a duplication: the first is the duty, the second is the superstructure. A code of conduct on AI literacy is therefore a fine addition and never a replacement of Article 4. The same holds for transparency: Article 50 imposes a number of transparency duties, and a code that says something about them leaves Article 50 untouched. Anyone suggesting in a tender document or annual report that a code covers one of those duties is making a claim the text does not support.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Then read the article for what it does offer, because that is underestimated. This is the only place in the Regulation that says what an organisation can do of its own accord, and the enumeration in paragraph 2 is strikingly concrete. It names assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI. That topic appears nowhere else in the Regulation as something you can do, and for many organisations it is the topic a board is already asking about. It further names facilitating an inclusive and diverse design, including through inclusive and diverse development teams and the involvement of stakeholders in that process, and assessing and preventing the negative impact on vulnerable persons or groups, including as regards accessibility for persons with a disability and gender equality. Note the form paragraph 2 prescribes alongside, because it separates a serious code from a statement of intent: clear objectives and key performance indicators to measure the achievement of those objectives. A code without measurable indicators does not meet the form the provision itself describes. In practice this is where you can hook your own AI policy onto the Regulation without promising anything you cannot deliver. The most useful use is the inverse application of paragraph 1: for a system that is not high-risk, deliberately adopt part of Chapter III, Section 2, for example the keeping of logs or the documentation of data quality, and say which part you are not adopting and why. That is defensible and it is preparation as well, because a system sometimes changes classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First make the separation visible in your own documentation: set out in two columns what you must do and what you do voluntarily, and make sure no line from the second column is used as cover for a line from the first. Then test every existing ethical code, AI policy document or supplier promise against that separation, because that is usually where the blending sits. If you are considering a code under Article 95, choose deliberately between the two routes: the paragraph 1 route for a system that is not high-risk, where you name which requirements of Chapter III, Section 2, you adopt and which you do not, or the paragraph 2 route for specific requirements across all your AI systems. In both cases give the code the form paragraph 2 describes: clear objectives and key performance indicators with which you measure the achievement, with a named owner and a moment of measurement. Then pick the elements that genuinely mean something to you rather than all five; environmental sustainability, AI literacy, inclusive and diverse design and the impact on vulnerable persons are separate topics with separate data. If you are an SME or a start-up, ask your national competent authority or the AI Office what support for drawing one up is available, because paragraph 4 requires your interests and needs to be taken into account. Finally, put no wording in quotations, tender responses or annual reports from which a reader could infer that participation in a code of conduct covers an obligation under the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-95-voluntary-codes-of-conduct","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:article-99-101-penalties","legacy_id":"raip:obligation:article-99-101-penalties","type":"obligation","slug":"article-99-101-penalties","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eebb183c9d9b58597388256d80ac73dc95eca9b9c98dd975ed907b55791e6905","label":"Article 99, 100 and 101: the penalty structure per obligation","summary":"The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.","topics":["enforcement","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"Three things are unsettled here. First, whether an obligation not named in Article 99(3) to (5) carries a ceiling from the Regulation itself. We read Article 16, point (a), which obliges the provider to ensure that its high-risk systems comply with the requirements of Chapter III, Section 2, as meaning that non-compliance with Articles 9 to 15 by a provider is at the same time non-compliance with Article 16 and therefore sits inside the 3 percent ceiling, and Article 26 the same way for the deployer, including the duties that Article 26(5) draws in through Article 72 and Article 73. A defensible alternative reading is that the enumeration in paragraph 4 is meant strictly and covers only the duties written in Article 16 and Article 26 themselves, leaving the level for Articles 9 to 15 entirely to the national rules that paragraph 1 requires Member States to lay down. Second, what undertaking and total worldwide annual turnover in paragraphs 3 to 5 cover: the Regulation does not define this, and the difference between the turnover of the legal person fined and that of the group it belongs to is an order of magnitude in practice. We hold to the group reading because undertaking is construed that way in Union competition law, but that provenance is exactly the weak point: the Regulation nowhere refers to it, and the reading that the fined legal person is meant is equally defensible as long as there is no case law under this Regulation. Third, how far Article 75c(4) displaces the enumeration in paragraph 4: on its terms that provision governs enforcement by the AI Office over the operators of Article 75(1), and whether anything follows from it for the national route is unsettled. We read it narrowly, that is for the Office alone, and that is a reading and not settled law.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-99-101-penalty-exposure-register"],"control_ids":["praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record"],"template_ids":["praxikon:eu:ai-act:template:article-99-101-legal-text"],"conditions":[{"id":"article-99-101-penalties-scope","operator":"all","description":"Relevant as soon as you are an operator within the meaning of the Regulation, that is a provider, product manufacturer, deployer, authorised representative, importer or distributor, and one of the provisions named in Article 99(3), (4) or (5) is engaged. The Article 101 regime is additionally relevant where you are a provider of a general-purpose AI model, because there the Commission fines you itself. If you fall within the competence of the AI Office under Article 75(1), Article 75c is added on top."}],"exceptions":[{"id":"article-99-101-penalties-exception","operator":"not","description":"Paragraph 6 reverses the calculation for SMEs, including start-ups: for them the lower of the percentage and the amount applies, where for other undertakings it is the higher of the two, and it does so for every fine referred to in Article 99. The inserted paragraph 6a does the same for small mid-cap enterprises, but expressly only for paragraphs 4 and 5, so the Article 5 band is not reversed for them. Paragraph 8 leaves it to each Member State to determine to what extent administrative fines may be imposed on public authorities and bodies established in that Member State, so the ceiling for a public organisation does not follow from the Regulation. Paragraph 9 allows the fine to be imposed by the competent national courts or by other bodies rather than by the authority in some Member States."}],"statements":[{"kind":"official_fact","text":"Paragraph 1, as replaced by Regulation (EU) 2026/1744, requires Member States to lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, provides that those penalties shall be effective, proportionate and dissuasive, and requires Member States to take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties. Paragraph 2 requires Member States to notify those rules to the Commission without delay and at the latest by the date of entry into application, and to notify any subsequent amendment without delay. Paragraph 3 sets, for non-compliance with the prohibition of the AI practices referred to in Article 5, administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Paragraph 4 sets, for non-compliance with provisions related to operators or notified bodies other than those laid down in Article 5, fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of that same turnover, whichever is higher, and enumerates: obligations of providers pursuant to Article 16, of authorised representatives pursuant to Article 22, of importers pursuant to Article 23, of distributors pursuant to Article 24, point (da) inserted by Regulation (EU) 2026/1744, obligations of providers and operators pursuant to Article 25(2) and (4), obligations of deployers pursuant to Article 26, requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34, and transparency obligations for providers and deployers pursuant to Article 50. Paragraph 5 sets, for the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request, fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of that same turnover, whichever is higher. Paragraph 6 provides that in the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. The paragraph 6a inserted by Regulation (EU) 2026/1744 provides that in the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower. Paragraph 7 enumerates what is taken into account when deciding whether to impose a fine and when deciding on the amount: the nature, gravity and duration of the infringement and of its consequences, whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement, whether other authorities have already fined that operator for infringements of other Union or national law resulting from the same activity or omission, the size, annual turnover and market share of the operator, any other aggravating or mitigating factor such as financial benefits gained or losses avoided, the degree of cooperation with the national competent authorities, the degree of responsibility of the operator taking into account the technical and organisational measures it implemented, the manner in which the infringement became known to the authorities and whether the operator notified it, the intentional or negligent character of the infringement, and any action taken by the operator to mitigate the harm suffered by the affected persons. Paragraph 8 provides that each Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Paragraph 9 provides that, depending on the legal system of the Member State, the rules may be applied in such a manner that fines are imposed by competent national courts or by other bodies, with equivalent effect. Paragraph 10 subjects the exercise of these powers to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process. Paragraph 11 requires Member States to report annually to the Commission on the administrative fines they issued and on any related litigation or judicial proceedings. Chapter XII, which contains Article 99, has applied since 2 August 2025, with the exception of Article 101; the amendments to Article 99 have applied since 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (38)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (40)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of this Regulation, failed to comply with a request for a document or for information pursuant to Article 91 or supplied incorrect, incomplete or misleading information, failed to comply with a measure requested under Article 93, or failed to make available access to the model with a view to conducting an evaluation pursuant to Article 92. In fixing the amount of the fine or periodic penalty payment, regard shall be had to the nature, gravity and duration of the infringement, taking due account of the principles of proportionality and appropriateness, and the Commission shall also take into account commitments made in accordance with Article 93(3) or made in relevant codes of practice in accordance with Article 56. Paragraph 2 requires the Commission to communicate its preliminary findings to the provider and give it an opportunity to be heard before adopting the decision. Paragraph 3 provides that fines imposed shall be effective, proportionate and dissuasive. Paragraph 4 provides that information on fines imposed shall also be communicated to the Board as appropriate. Paragraph 5 gives the Court of Justice of the European Union unlimited jurisdiction to review decisions of the Commission fixing a fine and provides that it may cancel, reduce or increase the fine. Paragraph 6 requires the Commission to adopt implementing acts containing detailed arrangements and procedural safeguards for proceedings that may lead to a decision under paragraph 1. Article 101 is excluded from the earlier application of Chapter XII and has therefore applied since 2 August 2026. Alongside this regime, Article 100 carries its own scheme for Union institutions, bodies, offices and agencies: the European Data Protection Supervisor may impose administrative fines on them of up to EUR 1 500 000 for non-compliance with the prohibition in Article 5 and up to EUR 750 000 for non-compliance with other requirements or obligations under this Regulation. Regulation (EU) 2026/1744 did not amend Articles 100 and 101.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 100(1)-(3)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75c(4), inserted by Regulation (EU) 2026/1744, provides that a decision of the AI Office may be accompanied by the imposition of penalties in accordance with Article 99(3) to (7), which provisions apply mutatis mutandis to the Office in the execution of its supervision and enforcement tasks referred to in Article 75(1). In particular, the following are subject to administrative fines as referred to in Article 99(4): infringement of any applicable provision of this Regulation, including those not listed in Article 99(4); failure to comply with decisions or measures adopted pursuant to Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 and the powers specified in Article 75a; and failure to comply with a commitment made binding pursuant to Article 75b. The supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 additionally allows the Office to impose periodic penalty payments to compel, among other things, submission to an investigation, compliance with an information request, submission to an inspection or compliance with a binding commitment; those payments shall not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 6 gives the Court of Justice unlimited jurisdiction over decisions of the Office fixing a fine or periodic penalty payment, and paragraph 8 subjects the powers of the Office to a limitation period of five years, with the same period for the power to enforce decisions taken. Note: the two authentic language editions of Regulation (EU) 2026/1744 diverge here. The English edition states five years in both subparagraphs of Article 75c(8); the Dutch edition states three years in both subparagraphs of Article 75 quater(8). This statement renders in each language what the edition in that language says and makes no silent choice. The implementing act under Article 75d(3) is to specify both subparagraphs, including the circumstances in which the limitation periods are interrupted; until it exists, the divergence remains an open question of interpretation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The ceiling follows the provision, not the harm. That is the point routinely missed in boardrooms: a single amount gets budgeted for \"the AI Act fine\", while operators face three bands in Article 99 and there are separate regimes on top for Union institutions and for providers of general-purpose AI models. The highest band, EUR 35 million or 7 percent, belongs to Article 5 alone. Until recently that was a list of practices you either engage in or do not, but since the amendment of Article 5 that is no longer true: for the new prohibitions on sexual imagery, placing on the market is also prohibited where such generation is a reasonably foreseeable and reproducible outcome and the system lacks reasonable and adequate technical safety measures and safeguards. That is a duty to take measures inside the highest band, and it applies from 2 December 2026. The middle band, EUR 15 million or 3 percent, belongs to the enumeration in paragraph 4: the role duties of the provider, the authorised representative, the importer, the distributor and the deployer, since 27 July 2026 also Article 25(2) and (4), plus Article 50. What is not named there is at least as interesting: Article 4 and Article 27 do not appear, and the requirements of Chapter III reach the ceiling at most through Article 16 and Article 26. Note that Article 72 and Article 73 do come within reach for the deployer, because Article 26(5) obliges it to inform in accordance with Article 72 and declares Article 73 applicable mutatis mutandis, and Article 26 is named in paragraph 4. Two further things. Paragraph 5 turns answering an information request badly into its own fine category at 1 percent, independently of the underlying infringement. And paragraph 7 is not a discount scheme: it works both ways, because its opening words concern the decision whether or not to impose a fine and point (e) expressly names aggravating factors such as financial benefits gained. What you can steer are the factors you can evidence: your technical and organisational measures, your notification behaviour, your cooperation, and what you did after an incident to mitigate the harm suffered by affected persons. Two dates that matter in practice: the prohibition in Article 5 has applied since 2 February 2025 but Chapter XII only since 2 August 2025, so for conduct in between there is no administrative fine under Article 99(3). That gap does not return for the new Article 5 prohibitions of 2 December 2026: Chapter XII will by then have applied for well over a year, so the penalty regime exists on the day those prohibitions start to apply. And whoever falls within the competence of the AI Office must drop the idea that the enumeration in paragraph 4 is closed: Article 75c(4) places infringement of any applicable provision in the EUR 15 million or 3 percent band there, expressly including provisions not listed in paragraph 4.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (7)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add a column to your obligations register carrying the ceiling that belongs to each entry, with three values: Article 99(3), Article 99(4), or national law under Article 99(1). Determine per general-purpose AI model that you provide yourself whether the Commission's Article 101 regime is added on top, and determine whether you fall under Article 75(1), because the Article 75c regime with periodic penalty payments then applies as well. Also record, per obligation, which of the factors in Article 99(7) you could actually show, in particular the technical and organisational measures implemented, your notification behaviour, your cooperation with the authority and the steps you take to mitigate harm to affected persons, because that is the part of the amount you can influence yourself. This is our recommendation and not a duty under the Regulation: Article 99 addresses the Member States and imposes no deadline whatsoever on an operator.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-99-101-penalties","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:conformity-ce-registration","legacy_id":"raip:obligation:conformity-ce-registration","type":"obligation","slug":"conformity-ce-registration","version":"2.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"e2ba6e413ff6670e5896f31ee36839ff048b04b714b4c13decc1ed8e0d2f9186","label":"Articles 43-49: conformity assessment, CE and registration","summary":"The route from assessment to CE marking and EU database registration before market placement of high-risk AI.","topics":["conformity"],"actor_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:conformity-ce-registration-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:conformity-ce-registration-record"],"control_ids":["praxikon:eu:ai-act:control:conformity-ce-registration-control"],"template_ids":["praxikon:eu:ai-act:template:conformity-ce-registration-legal-text"],"conditions":[{"id":"conformity-ce-registration-scope","operator":"all","description":"The provider places a high-risk system on the market; public deployers also register their use."}],"exceptions":[{"id":"conformity-ce-registration-exception","operator":"not","description":"For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking."}],"statements":[{"kind":"official_fact","text":"Article 43 governs the conformity assessment, Article 47 the EU declaration of conformity, Article 48 the CE marking and Article 49 the registration in the EU database before market placement or putting into service, including registration of the Article 6(3) assessment.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buyers this is the simplest supplier check there is: ask for the declaration of conformity and the registration number. No declaration means the system may not be there by 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Plan the conformity route backwards from 2 December 2027: standards selection, assessment, declaration and registration together take months, not weeks.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":"text_date","high_risk_regime_from":"2027-12-02T00:00:00.000Z","links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/conformity-ce-registration","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 43-49 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"}},{"id":"praxikon:eu:ai-act:obligation:value-chain-representative","legacy_id":"raip:obligation:value-chain-representative","type":"obligation","slug":"value-chain-representative","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"38342a3db27dd0959f29e10415d9217331e2056d163b17a95fef284213092d52","label":"Articles 22-25: value chain and authorised representative","summary":"Role shifts in the AI value chain and the mandatory representative for non-EU providers.","topics":["value-chain"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:value-chain-representative-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:value-chain-representative-record"],"control_ids":["praxikon:eu:ai-act:control:value-chain-representative-control"],"template_ids":["praxikon:eu:ai-act:template:value-chain-representative-legal-text"],"conditions":[{"id":"value-chain-representative-scope","operator":"all","description":"A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU."}],"exceptions":[{"id":"value-chain-representative-exception","operator":"not","description":"Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties."}],"statements":[{"kind":"official_fact","text":"Article 25 provides that a distributor, importer, deployer or third party becomes the provider when it puts its name on a high-risk system, substantially modifies it or changes its intended purpose so it becomes high-risk; Article 22 obliges third-country providers to appoint a written authorised representative in the Union.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The most dangerous role switch is the unintended one: your own layer on top of a procured model, your own brand on a tool, and you suddenly carry the full provider duties. This belongs as a standing question in every AI project.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the role question in the AI register and in project gates, and contractually define who supplies which information and cooperation on changes.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 22 and 25","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/value-chain-representative","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 22-25 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"}}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":{"nl":"CEN-CENELEC JTC 21: Europese normen onder normalisatieverzoek M/613","en":"CEN-CENELEC JTC 21: European standards under standardisation request M/613"},"publisher":{"nl":"CEN-CENELEC JTC 21","en":"CEN-CENELEC JTC 21"},"canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"952a677040f5a8facb59fc7e89676b9127e1c9e4a36e191112c7f7c1dcd45a94","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:cen-cenelec-jtc21"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":{"nl":"Vragen en antwoorden over AI-geletterdheid","en":"AI literacy questions and answers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"a07599c1c5af5cb25fbe1a72caecc7f0093326202cea7949a43d7a89c6c7f038","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-ai-literacy-qa"},{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":{"nl":"Richtsnoeren over Artikel 50","en":"Guidelines on Article 50"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"3c3d066f0294692b398f096861adb89198f3d6062939237a97b35fa9ced4d39d","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-article-50-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"},{"id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","title":{"nl":"Richtlijn (EU) 2019/1937 inzake de bescherming van personen die inbreuken op het Unierecht melden","en":"Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj","source_version":"original-oj-2019-11-26","verified_at":"2026-09-06T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"2c76f0ccbfefa16c95ca202883ed31d30dfa21498f4895b621abab2fb9dbb706","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:dir-eu-2019-1937"},{"id":"praxikon:eu:ai-act:source:gpai-code-of-practice","title":{"nl":"Praktijkcode voor AI voor algemene doeleinden","en":"General-Purpose AI Code of Practice"},"publisher":{"nl":"Europese Commissie / AI Office","en":"European Commission / AI Office"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","eli":null,"source_version":"published-2025-07-10","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"c5c59097f402c229249c30efeda4e895ca79c2617adcdf954c890c5456cd4123","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:gpai-code-of-practice"},{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"}]},"links":{"self":"https://www.praxikon.com/api/v1/obligations?lang=en","alternate":"https://www.praxikon.com/api/v1/obligations?lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}