{"meta":{"dataset_id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","dataset_version":"2.2.0","schema_version":"1.5.0","lang":"en","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","count":20,"query":"article 50","limit":20,"filters":{"id":null,"type":null,"role":null,"duty_holder":null,"topic":null},"identifiers":{"canonical_namespace":"praxikon","canonical_form":"praxikon:<jurisdiction>:<regulation>:<type>:<slug>","legacy_namespace":"raip","legacy_resolution":"permanent","resolved":{"id":null,"role":null,"duty_holder":null}}},"data":[{"id":"praxikon:eu:ai-act:obligation:article-50-transparency","legacy_id":"raip:obligation:article-50-transparency","type":"obligation","slug":"article-50-transparency","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"239fbac0e4728dc239352b2f88b199c3cc098082ff72e2972b4b5e8a2b121406","label":"Article 50: transparency","summary":"Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-50-disclosure"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-50-implementation-record"],"control_ids":["praxikon:eu:ai-act:control:article-50-release-check"],"template_ids":["praxikon:eu:ai-act:template:article-50-checklist"],"conditions":[{"id":"article-50-direct-interaction","operator":"any","description":"An AI system is intended to interact directly with natural persons."},{"id":"article-50-synthetic-content","operator":"any","description":"The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario."}],"exceptions":[{"id":"article-50-obvious-interaction","operator":"not","description":"The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context."},{"id":"article-50-legacy-marking-grace","operator":"not","description":"Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026."}],"statements":[{"kind":"official_fact","text":"Article 50 applies since 2 August 2026. The precise duty differs by scenario: direct AI interaction, machine-readable marking, emotion recognition or biometric categorisation, deepfakes and certain public-interest text.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1)-(5) and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"A generic rule that all AI content must always carry a visible label is too broad. First classify the specific Article 50 scenario.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Final guidelines, scope by Article 50 paragraph","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For each system, record the applicable paragraph, responsible actor, implemented disclosure or marking and how it was tested.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Implementation guidance for providers and deployers","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-50-transparency","label":"Open the human explanation"},{"relation":"official_source","href":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","label":"Final Commission guidelines"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":120},{"id":"praxikon:eu:ai-act:change:2026-08-02-article-50-applicable","legacy_id":"raip:change:2026-08-02-article-50-applicable","type":"change","slug":"2026-08-02-article-50-applicable","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"bd4cbaa1807f88e6c089eaac6e8f8cb22f0633c0711f8cc99597801a6e4a5d84","label":"Article 50 is applicable","summary":"The transparency duties apply since 2 August 2026.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-50-disclosure"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-50-implementation-record"],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Article 50 became applicable on 2 August 2026 and was not postponed by the Digital Omnibus.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50 and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":94},{"id":"praxikon:eu:ai-act:template:article-50-checklist","legacy_id":"raip:template:article-50-checklist","type":"template","slug":"article-50-checklist","version":"1.0.0","effective_at":"2024-08-01T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"165eaabca3372655df0955fa11ee94e3125d67b5adfa1a7f26157df5f031b26f","label":"Article 50 checklist","summary":"Public decision route for the distinct transparency obligations.","topics":["template","transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[],"legal_status":null,"deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"/en/templates/ai-transparency-notice","label":"Open public transparency template"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":91},{"id":"praxikon:eu:ai-act:action:article-50-scenario-triage","legacy_id":"raip:action:article-50-scenario-triage","type":"action","slug":"article-50-scenario-triage","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"dc033c20583465aae87a1bf8e67231cd4e90dd38804a7d491fea62bf5382f1dc","label":"Test every system in your AI register against the five Article 50 scenarios","summary":"For each AI system, walk through the distinct Article 50 scenarios (direct interaction, synthetic output, emotion recognition or biometric categorisation, deep fake, published text on matters of public interest) and record per paragraph whether it applies, does not apply or falls under an exception, with the reason.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[{"id":"article-50-scenario-triage-scope","operator":"all","description":"The system is in your AI register and is placed on the market, put into service or used in the Union."}],"exceptions":[{"id":"article-50-scenario-triage-exception","operator":"not","description":"Article 50(1) does not apply where it is obvious, from the point of view of a reasonably well-informed, observant and circumspect natural person and taking into account the circumstances and the context of use, that the person is interacting with an AI system. In addition, paragraphs 1 to 4 each contain an exception for AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties. In paragraph 1 that latter exception does not apply to systems available for the public to report a criminal offence."}],"statements":[],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 50 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"editorially_reviewed","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":78},{"id":"praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines","legacy_id":"raip:change:2026-07-20-article-50-guidelines","type":"change","slug":"2026-07-20-article-50-guidelines","version":"1.0.0","effective_at":"2026-07-20T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"acb754d01dded0d0bbcfe4cc0a6f8a09b3284fd4f485c6bbb8c6c9464ecad1bc","label":"Final guidelines on Article 50","summary":"The Commission works out the transparency duties and confirms they apply from 2 August 2026.","topics":["transparency"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":["praxikon:eu:ai-act:obligation:article-50-transparency"],"change_ids":[],"action_ids":[],"evidence_ids":[],"control_ids":[],"template_ids":[],"conditions":[],"exceptions":[],"statements":[{"kind":"official_fact","text":"Guidelines C(2026) 5054 final of 20 July 2026 work out the notification and marking duties of Article 50, with worked examples for chatbots, deep fakes and AI texts of public interest.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Commission Guidelines C(2026) 5054 final, 20.7.2026","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}}],"legal_status":"guidance","deadline_at":"2026-07-20T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":64},{"id":"praxikon:eu:ai-act:obligation:article-111-legacy-public-systems","legacy_id":"raip:obligation:article-111-legacy-public-systems","type":"obligation","slug":"article-111-legacy-public-systems","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"f6d9b4b81b0a9ef37eec8fdd812d98a712cc1688491f8db5c61b8a857ee419e4","label":"Article 111(2): legacy high-risk systems and the 2 August 2030 date","summary":"High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.","topics":["high-risk","timeline"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:importer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"The text above is the consolidated text and has been checked against the Official Journal; what is preliminary is our reading of it. First, the cut off date. The amended paragraph 2 refers not to a date but to the date of application of Chapter III referred to in Article 113, and since the Digital Omnibus Article 113, third paragraph, point (c) gives two: 2 December 2027 for Annex III and 2 August 2028 for Annex I. We therefore read the cut off as route dependent. A defensible alternative reading is that the reference points at the general application date of Chapter III as a whole, that is 2 August 2026, because Sections 4 and 5 of that Chapter were not deferred; on that reading the cut off would effectively still be 2 August 2026. We follow the route dependent reading because point (c) expressly names Sections 1, 2 and 3, and those are the Sections carrying the requirements the grace period exists for. Second, the notion of a significant change in the design. That is not the same wording as the defined substantial modification used elsewhere in the Regulation, and there is no guidance or case law saying whether a model update, a retraining run or a new data source counts. We read it as a change that touches the intended purpose, the functioning or the risk profile, and not as every release. Third, the reach of intended to be used by public authorities. It is unclear whether a system supplied to both public and private customers falls under it in full, and whether a private party carrying out a public task is a public authority. We read the intention as following from the market the system is offered for and not from the legal form of the individual customer.","obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-07-27-annex-iii-date","praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends","praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable"],"action_ids":["praxikon:eu:ai-act:action:assess-significant-design-change","praxikon:eu:ai-act:action:plan-legacy-public-system-compliance"],"evidence_ids":["praxikon:eu:ai-act:evidence:legacy-system-transition-register"],"control_ids":["praxikon:eu:ai-act:control:design-change-review-gate"],"template_ids":["praxikon:eu:ai-act:template:article-111-legal-text"],"conditions":[{"id":"article-111-2-scope-article-5-unaffected","operator":"all","description":"The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed."},{"id":"article-111-2-scope-limited-to-chapter-iii","operator":"all","description":"The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them."},{"id":"article-111-2-legacy-scope","operator":"all","description":"Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date."},{"id":"article-111-2-type-and-model","operator":"all","description":"The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union."},{"id":"article-111-2-public-authority-deadline","operator":"all","description":"Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged."}],"exceptions":[{"id":"article-111-2-exception-annex-x-systems","operator":"not","description":"Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030."}],"statements":[{"kind":"official_fact","text":"Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The grace period in paragraph 2 applies where the type and model of an AI system has already been placed on the market. If at least one individual unit was lawfully placed on the market or put into service before the cut off date, the grace period also covers other units of the same type and model, which may be offered without additional obligations, requirements or mandatory additional certification, as long as the design remains unchanged. On a significant change to the design after the cut off date the provider must fully comply with all relevant provisions applicable to high-risk AI systems, including the conformity assessment requirements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"In practice this provision is read exactly the wrong way round. Executives hear that existing systems are left alone and conclude that nothing is needed until well into the 2030s. That is wrong in two ways. For a public sector organisation the second sentence gives no escape but a deadline, and it applies whether or not you change anything about the system. And for everyone the transitional rule concerns only the high-risk requirements: Article 4 has been running since February 2025 and Article 50 since August 2026, with legacy generative systems having only until 2 December 2026 to get the machine-readable marking of Article 50(2) in order. The first sentence, moreover, is not a resting place but a switch. As soon as the design is significantly changed you must comply fully with what applies to high-risk systems, the conformity assessment first of all; those duties do follow the shifted calendar of 2 December 2027 and 2 August 2028. That switching moment rarely arises at a time you choose: it arises on a supplier update, a migration or a new data source. Two things therefore matter more than the date itself. You need to know when the first unit of each type and model reached the market, because that is the decisive date and without it you cannot later show which track a system was on. And you need a moment in your change process at which someone assesses whether a change is significant, before it goes live.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Recital 39 of Regulation (EU) 2026/1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per type and model of your high-risk AI systems when the first unit was placed on the market or put into service, and whether the system is intended to be used by public authorities. Record that determination with a date and a reasoning, and note which route applies, because that decides whether your cut off is 2 December 2027 or 2 August 2028. For the systems intended for public authority use, set a plan towards 2 August 2030 that counts back from the conformity assessment and the registration, not from the end date. Also build into your change and release process a review moment at which someone records whether an intended design change is significant, before the change goes into production. Separately, check whether Article 111(4) catches you: if so you have until 2 December 2026 for the marking under Article 50(2).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"New Article 111(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2030-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-111-legacy-public-systems","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Regulation (EU) 2024/1689 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex, which amends Article 111"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities","legacy_id":"raip:obligation:article-21-cooperation-with-authorities","type":"obligation","slug":"article-21-cooperation-with-authorities","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"559250092044f24993e3f2608cae8b25215c5e18ff58592e1379c9eb746c62a3","label":"Article 21: cooperation with competent authorities","summary":"Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Two things are unsettled here, and the status carries a cost that we state alongside them. First, who the competent authority is. Article 21 refers without qualification to a competent authority. Article 3(48) defines the national competent authority as a notifying authority or a market surveillance authority, and provides in the same point that, as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities are construed as references to the European Data Protection Supervisor. We read Article 21 as addressing those national competent authorities. The stronger alternative reading is that competence follows Chapter IX: the market surveillance authority designated by the Member State, the financial supervisor via Article 74(6), the data protection supervisory authority via Article 74(8), the European Data Protection Supervisor via Article 74(9), and, for a delimited group of systems, the AI Office via Article 75 as amended by Regulation (EU) 2026/1744, which already applies. On that reading you prepare for a different counterpart than the one we assume here. Second, what paragraph 2 asks when the logs are in fact held by the deployer. The text limits the duty to logs under your control but does not say whether you must arrange access contractually in order to retain that control. We read no separate duty into it; that is our reading and not the text. What is settled here is the date of application, and that corrects an earlier reading of ours. Article 1, point (40)(b), of Regulation (EU) 2026/1744 replaces Article 113, third paragraph, point (c), and expressly sets Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), at 2 December 2027 for systems classified as high-risk pursuant to Article 6(2) and Annex III and at 2 August 2028 for those classified as high-risk pursuant to Article 6(1) and Annex I. Article 21 sits in Section 3 and is therefore covered by that provision in so many words; the fact that the omnibus does not name Article 21 individually changes nothing, because the provision operates per Section. The cost of this status: a preliminary reading does not count in the per-situation derivation of obligations, so the log access of paragraph 2 and the language rule do not surface there, and Article 16(k) covers only the demonstration of conformity. The object stays reachable through its own page, the deadline index and the API.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:prepare-authority-information-request"],"evidence_ids":["praxikon:eu:ai-act:evidence:authority-request-response-file"],"control_ids":["praxikon:eu:ai-act:control:authority-request-intake-and-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-21-legal-text"],"conditions":[{"id":"article-21-scope","operator":"all","description":"Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act."},{"id":"article-21-legacy-systems","operator":"any","description":"For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case."},{"id":"article-21-confidentiality-treatment","operator":"all","description":"What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side."}],"exceptions":[{"id":"article-21-log-access-limits","operator":"not","description":"Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies \"as applicable\", and it applies \"to the extent such logs are under their control\". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6)."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides that providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Paragraph 2 provides that, upon a reasoned request by a competent authority, providers shall also give the requesting competent authority, as applicable, access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control. Paragraph 3 provides that any information obtained by a competent authority pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 21(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings of Article 21, verbatim. Article 22(3), point (c), requires the authorised representative to provide a competent authority, upon a reasoned request, with all the information and documentation necessary to demonstrate conformity with the requirements set out in Section 2, including access to the logs referred to in Article 12(1) to the extent such logs are under the control of the provider; the final subparagraph of that paragraph provides that the mandate shall empower the authorised representative to be addressed, in addition to or instead of the provider, by the competent authorities. Article 19(1) provides that the provider keeps the logs under its control for a period appropriate to the intended purpose, of at least six months. Article 26(6) imposes the same period of at least six months on the deployer for the logs under its control. Article 99(5) subjects the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request to administrative fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of total worldwide annual turnover for the preceding financial year, whichever is higher.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The surroundings as Regulation (EU) 2026/1744 left them. Article 1, point (34), amends Article 77. The heading now reads \"Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities\". Paragraph 1 now provides that national public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, have the power to request and access any information or documentation created or maintained pursuant to this Regulation from the relevant market surveillance authority, in accessible language and machine-readable format by electronic means, where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction, and that the Article is without prejudice to the competences, tasks, powers and independence of those authorities or bodies. The restriction to the systems listed in Annex III, the requirement of an accessible format and the after-the-fact notification of the market surveillance authority are gone. Inserted paragraph 1a provides that the market surveillance authority grants that access, including by requesting the information or documentation from the provider or the deployer where necessary and without undue delay. Inserted paragraph 1b requires market surveillance authorities and those authorities or bodies to cooperate closely and to provide each other with mutual assistance, including exchange of information. Article 99(4) still does not list Article 21 after the amendment: Article 1, point (38)(b), only inserts a point (da) there on the obligations of providers and operators pursuant to Article 25(2) and (4).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The timeline this object rests on is stated in so many words in the amended Regulation. Article 1, point (40)(b), replaces Article 113, third paragraph, point (c), so that Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), applies from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I. Article 1, point (39)(a), replaces Article 111(2), so that the grace period is tied to the date of application of Chapter III referred to in Article 113 and no longer to 2 August 2026, while retaining 2 August 2030 for systems intended to be used by public authorities. Article 1, point (2)(a), replaces Article 2(2), so that for systems classified as high-risk under Article 6(1) related to products covered by Annex I, Section B, only Article 6(1), Article 60a and Articles 102 to 112 apply; Article 21 is not on that list. Article 1, point (41), deletes point 1 of Annex I, Section A, and adds Regulation (EU) 2023/1230 on machinery to Annex I, Section B.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (39)(a), replacing Article 111(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-14T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Most of what is requested here already exists under the Regulation: the technical documentation of Article 11, the logs of Articles 12 and 19, the quality management system of Article 17, the conformity file of Article 43. Two things are genuinely additional. Article 19 requires you to keep the logs; Article 21(2) requires you to give an authority access to them, which is a different act. And the language rule of paragraph 1 is additional, because you deliver in an official language of the institutions of the Union chosen by the Member State concerned, not in the language you find most convenient. There is nothing to agree there; find out which language the Member State concerned has indicated and budget translation capacity for a technical file. Three further things go wrong in practice. Your documentation exists but is spread across teams and systems, so assembling it takes weeks. Your documentation belongs to a different system version than the one the question is about, in which case you demonstrate the conformity of something else. And the logs are gone: Article 19(1) and Article 26(6) ask for at least six months, so a request arriving later can meet an empty drawer. A provider established in a third country should also expect the request to land with its authorised representative: Article 22(3), point (c), imposes nearly the same delivery on him and the mandate empowers him to be addressed in addition to or instead of the provider. Article 21 is not the only channel either, but that second channel now runs differently. Under amended Article 77(1) a fundamental rights body requests information or documentation from the relevant market surveillance authority rather than directly from you, in accessible language and machine-readable format, and the restriction to Annex III systems has gone. Under inserted paragraph 1a that market surveillance authority may then request the material from you or from the deployer without undue delay. So expect a fundamental rights question to reach you as a request from the market surveillance authority, in a format a machine can read, and with its own route to testing under Article 77(3). On paragraph 3, finally, no comfortable story: Article 78 protects what you hand over only in accordance with Union or national law, carves out the cases of Article 5 of Directive (EU) 2016/943 for trade secrets and source code, and in paragraph 4 leaves the exchange of information, the dissemination of warnings and information duties under national criminal law unaffected. It is a rule on handling, not a shield.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Treat this as a delivery exercise rather than a documentation question. Record per high-risk system where each part of the conformity file sits, which system version it belongs to and who can assemble it within an agreed period. Find out which official language of the institutions of the Union the Member State concerned has indicated, and plan translation capacity instead of a language agreement. Determine per customer contract whether the automatically generated logs are under your control or with the deployer, and check that your retention period reaches the six months of Article 19(1), because otherwise the question can no longer be answered after half a year. If you are established outside the Union, record that your authorised representative can deliver the same file, since under Article 22(3), point (c), he is addressed in addition to or instead of you. And let nobody improvise in the answer: supplying incorrect, incomplete or misleading information in reply to a request is a separate ground for a fine under Article 99(5), in a different band from the obligations that Article 99(4) does list.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-21-cooperation-with-authorities","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 21 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-26-deployer-obligations","legacy_id":"raip:obligation:article-26-deployer-obligations","type":"obligation","slug":"article-26-deployer-obligations","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"0269a6f883187fb177f26dc8563b035927e5d2ae021e35254c98fce04d637f0c","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:public-law-body"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:appoint-and-empower-human-oversight"],"evidence_ids":["praxikon:eu:ai-act:evidence:deployer-use-dossier"],"control_ids":["praxikon:eu:ai-act:control:deployer-suspension-and-incident-control"],"template_ids":["praxikon:eu:ai-act:template:article-26-deployer-obligations-legal-text"],"conditions":[{"id":"article-26-deployer-obligations-scope","operator":"all","description":"Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028."}],"exceptions":[{"id":"article-26-deployer-obligations-exception","operator":"not","description":"Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law."}],"statements":[{"kind":"official_fact","text":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 26 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification","legacy_id":"raip:obligation:article-52-systemic-risk-classification","type":"obligation","slug":"article-52-systemic-risk-classification","version":"1.0.0","effective_at":"2025-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fda72f0c021ed141ad0881c569a2e4d7e59aefdcec7c95a562b9f547352a974e","label":"Article 52: notification of a GPAI model with systemic risk","summary":"The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.","topics":["gpai-systemic-risk"],"actor_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"affected_actor_ids":[],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:gpai-model-provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"settled","interpretation_note":null,"obligation_ids":[],"change_ids":["praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement","praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply"],"action_ids":["praxikon:eu:ai-act:action:notify-systemic-risk-threshold","praxikon:eu:ai-act:action:request-systemic-risk-reassessment"],"evidence_ids":["praxikon:eu:ai-act:evidence:systemic-risk-notification-file"],"control_ids":["praxikon:eu:ai-act:control:systemic-risk-notification-deadline"],"template_ids":["praxikon:eu:ai-act:template:article-52-legal-text"],"conditions":[{"id":"article-52-notification-trigger","operator":"all","description":"Applies to the provider of a general-purpose AI model as soon as that model meets the condition in Article 51(1), point (a): high impact capabilities, which under Article 51(2) are presumed where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. The two-week period runs from the moment that requirement is met or it becomes known that it will be met. The second route to systemic risk, a Commission designation under Article 51(1), point (b), or Article 52(4), is not covered here: Article 52(1) refers only to point (a)."}],"exceptions":[{"id":"article-52-legacy-models-transitional","operator":"not","description":"For general-purpose AI models placed on the market before 2 August 2025, Article 111(3) provides that the provider shall take the necessary steps to comply with the obligations of this Regulation by 2 August 2027. For those models the governing date is therefore 2 August 2027 and not the two-week period."}],"statements":[{"kind":"official_fact","text":"Article 51(1), point (a), classifies a general-purpose AI model as a model with systemic risk where it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; Article 51(2) provides that a model is presumed to have such capabilities where the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. Article 51(1), point (b), reads in full: based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII. The requirement of equivalent capabilities or impact and the anchoring in Annex XIII are therefore part of the norm and not only of the procedure. Article 51(3) provides in addition: the Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. The 10^25 threshold above is therefore movable; as long as that act does not exist, the threshold applies as it stands in paragraph 2. See data/ai-act/delegated-acts.json, key praxikon:eu:ai-act:delegated-act:article-51-3-thresholds. Article 52(1) refers only to point (a) and provides that the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met, and that the notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. Paragraph 2 allows the provider to present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although the model meets that requirement, it does not present systemic risks due to its specific characteristics and should therefore not be classified as a general-purpose AI model with systemic risk. Paragraph 3 provides that where the Commission concludes that those arguments are not sufficiently substantiated and the provider was not able to demonstrate that the model does not present systemic risks due to its specific characteristics, it shall reject those arguments and the model shall be considered to be a general-purpose AI model with systemic risk. Paragraph 4 empowers the Commission to designate a model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of the criteria set out in Annex XIII, and empowers it to adopt delegated acts in accordance with Article 97 to amend Annex XIII by specifying and updating the criteria set out in that Annex. Paragraph 5 provides that upon a reasoned request of a provider whose model has been designated pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII, that such a request shall contain objective, detailed and new reasons that have arisen since the designation decision, that providers may request reassessment at the earliest six months after the designation decision, and that where the Commission decides to maintain the designation a further six months must pass. Paragraph 6 provides that the Commission shall ensure that a list of general-purpose AI models with systemic risk is published and kept up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Recital 111 states that the cumulative amount of computation used for training includes the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning. Recital 112 states that the provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a model will meet the requirements that lead to the presumption, and that this is especially relevant in relation to the threshold of floating point operations because training takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers are able to know if their model would meet the threshold before the training is completed. The same recital states that in the context of that notification the provider should be able to demonstrate that the model exceptionally does not present systemic risks, that the information allows the AI Office to anticipate the placing on the market of models with systemic risks, and that it is especially important for models planned to be released as open-source. Recital 113 states that the Commission should be empowered to designate a model where it becomes aware that the model meets the requirements which previously had either not been known or of which the provider failed to notify it, and that a system of qualified alerts from the scientific panel should exist in addition to the monitoring activities of the AI Office.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 111(3) provides that providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) state in point (63) that a downstream modifier is considered to be the provider of the modified model where the training compute used for the modification is greater than a third of the training compute of the original model, and in point (64) that where the downstream modifier cannot know and cannot estimate the original value, that threshold is replaced by a third of 10^25 FLOP where the original model is a model with systemic risk and otherwise by a third of 10^23 FLOP. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1). The guidelines are not binding.","citations":[{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The Commission enforcement powers for general-purpose AI models and the fine regime of Article 101 have been active since 2 August 2026. Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 percent of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 91-93, 101 and 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This is the only duty in this chapter with a numbered deadline, and two weeks is short. Other duties are also tied to a clock, only without a figure: Article 55(1), point (c), requires serious incidents to be reported to the AI Office without undue delay. The question here is therefore not whether you can notify, but whether you see the threshold being crossed in time. Recital 112 leaves little room to push that back: the legislator expressly assumes that the upfront allocation of compute lets you know before training ends that you will meet the threshold. The remaining edge question is how firm that knowledge is for a run not yet allocated, and it is small next to the duty itself. Four things are missed in practice. The first is the transitional rule: if your model was already on the market before 2 August 2025, Article 111(3) gives you until 2 August 2027, and that is the difference between two weeks and two years. The second is the reach of the trigger: only the threshold route of Article 51(1), point (a), starts this clock. If your model is designated by the Commission under Article 51(1), point (b), or Article 52(4), Article 55 begins without Article 52 asking anything of you. The third is the reversal in the last sentence of paragraph 1: if the Commission becomes aware of a model it was not notified about, it may designate it, and you then hold the conversation from a designation rather than from your own file. Since 2 August 2026 the Article 101 fine regime stands behind that. The fourth is the rebuttal route in paragraph 2: those arguments belong with the notification and not after it, so they must already be ready at the moment you notify. Once designated, only paragraph 5 remains, and that route is slow: six months after the decision at the earliest, and only with objective, detailed and new reasons that have arisen since it. The text names the Commission as addressee; recital 112 and Article 55(1), point (c), name the AI Office, which performs this task within the Commission. For an organisation that merely uses an external model this article does not bite: it addresses the provider of the model. That does not put further development out of reach: under point (71) of guidelines C(2025) 5045 final, a party that becomes the provider of a systemic-risk model through a modification must notify the Commission in line with Article 52(1).","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First establish whether you are the provider of the model and not merely a user, and whether your model was already on the market before 2 August 2025, because the date in Article 111(3) then applies instead of the two-week period. If you are the provider of a new model, record the planned and the consumed training compute per training run, including pre-training, synthetic data generation and fine-tuning, because recital 111 counts all three. Agree who notifies once the threshold comes into view, so the two-week period is not spent finding an owner, and tie that to the moment compute is allocated rather than to the end of the run. Keep the reasoning with which you would argue that the model does not present systemic risks ready before you notify, because it belongs with the notification. If you have already been designated under paragraph 4, build deliberately towards objective, detailed and new reasons that have arisen since the designation decision, because only those get you to a reassessment after six months. Retain the notification, the substantiation sent with it, any reassessment request and the Commission response as a living file per model version.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 52(1)-(6) with Article 51(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Recitals 111 to 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 111(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-52-systemic-risk-classification","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 52 on EUR-Lex"},{"relation":"related","href":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","label":"Guidelines C(2025) 5045 final on the scope of the GPAI obligations"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance","legacy_id":"raip:obligation:article-75-market-surveillance-assistance","type":"obligation","slug":"article-75-market-surveillance-assistance","version":"1.0.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"9ae93e711b67b4eb9e0212da4542e3e5d0eb4495a90fe1b956b58472f4461925","label":"Article 75: market surveillance, mutual assistance and the powers of the AI Office","summary":"For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.","topics":["enforcement","governance","gpai"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"Four things are unsettled here. First, what this provision asks of you: it addresses the AI Office and the market surveillance authorities and imposes no literal duty on the organisation in this object. We read a practical consequence into it, namely that you must know in advance which authority is competent and must be able to answer a demand or an inspection within the period set; that is our reading and not the text. The literal duties in Article 75 sit in the separate object article-75-ai-office-high-risk-duties. Second, the delineation in paragraph 1: whether the model and the system were developed by the same provider or within the same undertaking is a question of fact on which no guidance exists, and the four carve-outs put the case back with a national authority per system. Third, the language versions of the amending regulation diverge on the limitation period in Article 75c(8): the Dutch edition says three years, the English edition five years. We render per language what that edition says and pick no winner; until a corrigendum, plan on the longer period. Fourth, there is still no consolidated text of Article 75, so the amended heading, the replaced paragraph 1 and the inserted articles can only be read in the amending text. The cost of this status is real: a preliminary reading is skipped by lib/answer/derive-obligations.ts, so this object does not appear in the per-situation derivation. A defensible alternative reading is that this provision is purely a division of competence for you and that your preparation is governed entirely by Article 21, Article 26 and Article 73.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:establish-competent-supervisor"],"evidence_ids":["praxikon:eu:ai-act:evidence:supervisor-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:ai-office-proceeding-response"],"template_ids":["praxikon:eu:ai-act:template:article-75-legal-text"],"conditions":[{"id":"article-75-scope","operator":"any","description":"Applies to AI systems based on a general-purpose AI model where the model and the system are developed by the same provider or by providers forming part of the same undertaking, and to AI systems that constitute or are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The exclusive competence applies to the providers of those systems, and to deployers only where they are also the provider or form part of the same undertaking as the provider."},{"id":"article-75-timing","operator":"all","description":"The allocation of competence itself operates from 2 August 2026, because Article 75 sits in Chapter IX. It covers the obligations that apply at that moment, such as the prohibition in Article 5, the transparency duties of Article 50 and the obligations for general-purpose AI models. The two literal duties the amending regulation places on the provider, the reporting route of paragraph 1a and the fees of paragraph 1e, attach to high-risk status and therefore follow 2 December 2027; they sit in the separate object article-75-ai-office-high-risk-duties."}],"exceptions":[{"id":"article-75-exception-carve-outs","operator":"not","description":"Paragraph 1, point (a) carves four groups out of the exclusive competence of the AI Office: AI systems related to products covered by the Union harmonisation legislation listed in Annex I, systems referred to in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and systems referred to in point 8 of Annex III as regards the administration of justice. Who is competent instead differs per group and is not always \"the market surveillance authority\": for financial institutions Article 74(6) points to the national authority responsible for their financial supervision, and for law enforcement, border management and the administration of justice Article 74(8) has the Member State designate either the data protection supervisory authority or another authority under the same conditions. Which body that is per Member State does not follow from the Regulation."}],"statements":[{"kind":"official_fact","text":"Paragraph 2 provides that where the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly. Paragraph 3 provides that where a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 75(2)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Regulation (EU) 2026/1744 replaces the heading of Article 75 with \"Market surveillance and control of AI systems and mutual assistance\" and replaces paragraph 1: the AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to, point (a), AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of (i) AI systems related to products covered by the Union harmonisation legislation listed in Annex I, (ii) AI systems referred to in point 2 of Annex III, (iii) AI systems provided by law enforcement authorities, border management authorities and financial institutions insofar as those systems fall under Article 74(6), and (iv) AI systems referred to in point 8 of Annex III as regards the administration of justice; and, point (b), AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The final subparagraph provides that the exclusive competence applies to the providers of those systems, and to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"The same regulation inserts paragraphs 1b to 1d and paragraph 2a. Paragraph 1b requires the authorities involved in the application of the Regulation to cooperate actively with the AI Office and to provide it the necessary assistance, including in connection with inspections or other enforcement measures carried out in the territory of a Member State. Paragraph 1c provides that the Office shall be assisted by the relevant market surveillance authority when investigatory or enforcement action involves access to a public authority data or AI system. Paragraph 1d provides that before taking a decision that would prohibit or restrict the system being made available or put into service on a national market, or a decision to withdraw or recall it from such market, the Office shall without undue delay notify the market surveillance authority competent for that market of its intention. Paragraph 2a allows a market surveillance authority with well-founded and sufficient reasons to suspect an infringement to request, through the single point of contact designated under Article 70(2), that the AI Office assess the matter; that request shall be duly reasoned and shall state at least the provider or deployer concerned, the relevant facts and the provisions allegedly infringed, and the requesting authority. The Office informs the point of contact without undue delay and in any event no later than four months after receipt whether it will exercise its powers, or why it will not.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1b) to (1d) and (2a)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75a gives the AI Office all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020, and authorises it to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance. Paragraph 2 allows the Office, on reasonable grounds, to start an investigation, of which it notifies the operator, and provides that it may exercise its powers on its own initiative or following a complaint received pursuant to Article 85, even before starting an investigation. Paragraph 3 allows information requests by simple request or by decision; with a simple request the Office states that there is no obligation to reply but that a voluntary reply must be correct and not misleading, and in both cases it indicates the fines provided for in Article 99(5), and by decision also the right to review by the Court of Justice; a copy of the request goes to the national market surveillance authority. Paragraph 4 allows remote and on-site inspections in which officials may enter business premises, examine and copy books and data, ask for oral or written explanations and seal premises; where national law requires authorisation by a judicial authority, the Office applies for it and the national judicial authority verifies that the coercive measures envisaged are neither arbitrary nor excessive. Paragraph 6 allows the Office to order operators to provide access to and explanations relating to their AI systems and to impose on an operator an obligation to retain all data and documents deemed necessary to assess compliance. Paragraph 7 allows the appointment of independent external experts and auditors, and paragraph 8 provides that information collected shall be used only for the purpose of this Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Article 75a","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75b allows the Office to make commitments offered by the operator during proceedings under Article 75a(2) binding by decision and to declare that there are no further grounds for action; it may reopen the proceedings where there has been a material change in the facts, where the operator acts contrary to its commitments, or where the decision was based on incomplete, incorrect or misleading information, and it rejects inadequate commitments in a reasoned decision. Article 75c provides in paragraph 1 that the Office adopts a decision establishing non-compliance, in paragraph 2 that it first communicates its preliminary findings, and in paragraph 3 that the decision may order the operator to take the necessary measures within a reasonable period and that the operator shall provide the Office with a description of the measures it has taken. Paragraph 4 provides that such a decision may be accompanied by penalties in accordance with Article 99(3) to (7), which apply mutatis mutandis to the AI Office, and that in particular the following are subject to fines as referred to in Article 99(4): (a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4), (b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 as well as those specified in Article 75a, and (c) failure to comply with a commitment made binding pursuant to Article 75b; the supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 allows periodic penalty payments to compel submission to an investigation, compliance with an information request ordered by decision, submission to an ordered inspection, the provision of correct or complete answers or explanations in the context of an ordered inspection, compliance with corrective actions, compliance with a binding commitment, or compliance with a decision under paragraph 1; those payments shall, where applicable, not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 8 sets a limitation period: the Dutch edition in the Official Journal says three years, the English edition says five years. Article 75d applies Article 18 of Regulation (EU) 2019/1020 mutatis mutandis in paragraph 1, safeguards the rights of defence and access to the file under negotiated disclosure in paragraph 2, and provides in paragraph 4 that the Office publishes its decisions under Articles 75b and 75c stating the names of the parties and the main content, including any penalties imposed.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75b, 75c and 75d","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The practical question behind this provision is simple and rarely asked: who comes knocking. What is new is not that the AI Office appears, because the old paragraph 1 already gave it powers to monitor and supervise systems where the model and the system come from the same provider. What is new is that this competence becomes exclusive rather than shared, that it extends to providers within the same undertaking, that a second category is added in the form of designated very large online platforms and search engines, that four groups are carved out of it, and that Articles 75a to 75d give the Office a toolkit of its own. That toolkit is the point. An information request comes as a simple request or by decision; with a simple request you need not answer, but whoever answers voluntarily must answer correctly and not misleadingly, and with a decision the clock runs. An inspection extends to entering business premises, copying data and sealing cabinets and systems, with a real safeguard in front of it: where national law requires judicial authorisation, the Office applies for it and that judge verifies that the coercive measures are neither arbitrary nor excessive. Commitments are a genuine way out, but they become binding, the decision is published with the names of the parties, and the proceedings reopen if the facts change materially, if you act contrary to them, or if your information turns out to be incomplete or incorrect. Two things that are rarely seen. The trigger need not come from an authority: Article 75a(2) lets the Office exercise its powers following a complaint under Article 85, even before an investigation is running. And cost recovery is not unconditional: the Office may fully reclaim its supervision costs insofar as they relate to instances of non-compliance, so supervision costs you money when you are in the wrong and not merely because supervision happened. The line between the two regimes sits in paragraph 1 and it is not trivial; answer it once per system and record it, rather than working it out at the moment a demand arrives.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, points (31) and (32)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Determine per AI system which authority is competent, record the outcome and the reasoning, and revisit that record whenever the model, the provider or the corporate structure changes. Designate someone who receives an information request, a notice of investigation or an announced inspection, and have that person first establish whether it is a simple request or a decision, because that determines whether there is a duty to reply and which period runs. Make sure technical documentation, logs and assessments can be produced in full and per version on request, and take into account that under Article 75a(6) the Office may order you to retain all data and documents it deems necessary; such an order overrides your own deletion routines. Do not count on harmless incompleteness: incorrect, incomplete or misleading information is a separate ground for a fine under Article 99(5), and a periodic penalty payment can also be imposed where you fail to give correct or complete answers during an ordered inspection.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32), Articles 75a and 75c","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-75-market-surveillance-assistance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 75 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: the right to complain that can start a proceeding"},{"relation":"related","href":"/en/ai-act/artikel/99","label":"Article 99: the fine bands to which Article 75c refers"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-87-reporting-infringements","legacy_id":"raip:obligation:article-87-reporting-infringements","type":"obligation","slug":"article-87-reporting-infringements","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"57d296c3c6d5ddab8a529f000c40a1881459a3576d6c39ee4b5c031b9296adf6","label":"Article 87: reporting of infringements and protection of reporting persons","summary":"The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.","topics":["fundamental-rights","governance"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"requires_legal_judgment","interpretation_status":"preliminary","interpretation_note":"The reference is settled; what it asks of you is not. Article 87 consists of one sentence and makes Directive (EU) 2019/1937 applicable to reporting and to the protection of reporting persons. It imposes no channel requirement of its own, sets no deadline and names no threshold: those sit in Articles 8, 9 and 21 of that Directive and in national transposition law, a layer this dataset does not carry as a source. That is why no duty holder is assigned here and the status is requires_legal_judgment. The sharpest open point is the fit with national law: the material scope of the Directive is tied through Article 2(1)(a) to the Union acts in its Annex, and Regulation (EU) 2024/1689 is not in that Annex. One reading is that Article 87 operates directly and that national law tying its scope to that Annex simply lags behind; the other is that the protection only becomes practically available through the national channel, so that the extension requires national transposition. We have not settled that. What we do read into it is a practical consequence: an organisation that must already have a reporting channel must be able to receive a report about an AI system through it. Settled and not unclear is that the personal scope of the Directive is work-related; Article 4 is explicit about that. What is open is only what remains outside that context, and whether that amounts to the complaint route of Article 85 without the protection of Article 87.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:open-a-protected-reporting-route"],"evidence_ids":["praxikon:eu:ai-act:evidence:infringement-report-record"],"control_ids":["praxikon:eu:ai-act:control:reporting-person-protection"],"template_ids":["praxikon:eu:ai-act:template:article-87-legal-text"],"conditions":[{"id":"article-87-scope","operator":"all","description":"The trigger is a report of an infringement of this Regulation, whatever the risk class of the system: a report about an AI system outside the high-risk category is covered just as much. The protection itself is not unconditional. It comes from Directive (EU) 2019/1937, which in Article 4 requires the person reporting to have obtained the information in a work-related context, and in Article 6(1)(a) requires reasonable grounds to believe that what was reported was true and fell within the scope of that Directive."}],"exceptions":[{"id":"article-87-no-internal-channel-below-threshold","operator":"any","description":"Article 87 creates no channel requirement. That requirement comes from Article 8 of Directive (EU) 2019/1937. Paragraph 1 places it on legal entities in the private and the public sector; paragraph 3 limits paragraph 1 in the private sector to entities with 50 or more workers. That threshold is not general, however. Paragraph 4 provides that the threshold in paragraph 3 shall not apply to entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, following a risk assessment, to require entities with fewer than 50 workers as well. Paragraph 9 applies paragraph 1 to all legal entities in the public sector, with the option for a Member State to exempt municipalities under 10 000 inhabitants and other small public entities. Below fifty workers there is therefore not simply no channel requirement: it depends on the sector you fall in and on what your Member State has decided. The right to report and the protection of the person reporting exist in any event, through the external route of Article 10 of that Directive."},{"id":"article-87-national-scope-not-settled","operator":"any","description":"The material scope of Directive (EU) 2019/1937 runs through Article 2(1)(a), which refers to the Union acts listed in the Annex to that Directive. Regulation (EU) 2024/1689 was not added to that Annex: it makes the Directive applicable directly, in Article 87. National transposition law that ties its own scope to that same Annex, such as the Dutch Wet bescherming klokkenluiders, may therefore lag behind the Regulation. Whether a report about an AI system falls under national law as a result is not settled."}],"statements":[{"kind":"official_fact","text":"Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"This article is short because the work was done elsewhere, and that is exactly why it gets overlooked. Its practical meaning lies in the direction of travel: Articles 85 and 86 concern who knocks on your door from outside, Article 87 concerns who steps out from within. That is almost always the first person to notice something. The developer who knows the logging has not run for months, the recruiter who sees the selection model filtering out candidates on something that should never have been in it: they hold the facts a regulator only obtains after an investigation. Three things follow. If you must already have a reporting channel, that channel must be able to receive such a report and recognise it as touching the AI Regulation, because a report handled as a general complaint disappears into a different process. Whether you must have that channel is not a matter of a single number. Article 8(3) of Directive (EU) 2019/1937 imposes the channel requirement in the private sector at fifty or more workers, but paragraph 4 sets that threshold aside for entities falling within the scope of the Union acts referred to in Parts I.B and II of the Annex to that Directive, which cover financial services, anti-money laundering and transport safety among others. Paragraph 7 allows a Member State, after a risk assessment, to require smaller entities as well, and paragraph 9 imposes the requirement on all legal entities in the public sector, with an optional exemption a Member State may make for municipalities with fewer than ten thousand inhabitants or fewer than fifty workers, and for other public entities with fewer than fifty workers. Below fifty workers the question is therefore which sector you are in and what your Member State has decided, not whether you clear the threshold. If you are genuinely outside each of those cases the channel need not exist, and even then the person reporting has somewhere to go: Article 10 of that Directive gives them an external route to the competent authority without having to report internally first, and Article 15 permits public disclosure under conditions. And the protection is not a formality, but it is not enforced through this Regulation: Article 19 of the Directive prohibits retaliation and Article 21 sets out the protective measures, and enforcement runs through national whistleblower law, in the Netherlands through the Huis voor Klokkenluiders and the civil courts. Article 99 of this Regulation does not list Article 87 among the fineable infringements; there is therefore no AI Act fine for disadvantaging a person who reported. Note too that the report here does not depend on a decision or on harm, whereas the right to an explanation in Article 86 does.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First determine whether Directive (EU) 2019/1937 and national transposition law apply to you at all: below fifty workers there is in principle no channel requirement, in which case this object is not a set-up question for you. If you are covered, check whether your existing reporting channel recognises a report about an AI system and whether whoever receives it knows the AI Regulation may be engaged. Record per report what was reported, about which system, what was done with it and when feedback was given, and measure that against the deadlines in Article 9(1) of that Directive: acknowledgement of receipt within seven days under point (b), feedback within three months under point (f). Keep the identity of the person reporting out of what goes to line managers (Article 16), retain no longer than necessary and proportionate (Article 18(1)), and record an oral report only with consent (Article 18(2) to (4)). Also decide whether you will handle anonymous reports: Article 6(2) leaves that choice to the Member State, so check what your national law says. Finally, put to your lawyer the question whether your national whistleblower act already covers AI Act infringements, because such an act usually ties its scope to the Annex to the Directive and Regulation (EU) 2024/1689 is not listed there.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 87","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 8(1), (3), (4), (7) and (9)","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"},{"source_id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","source_locator":"Directive (EU) 2019/1937, Article 9(1), Article 16 and Article 18","source_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-87-reporting-infringements","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 87 on EUR-Lex"},{"relation":"related","href":"/en/ai-act/artikel/85","label":"Article 85: right to lodge a complaint with the market surveillance authority"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct","legacy_id":"raip:obligation:article-95-voluntary-codes-of-conduct","type":"obligation","slug":"article-95-voluntary-codes-of-conduct","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"2b71546d72d3dbc5918daae97128ae05900c52ce93ba71de9866e90de4176e14","label":"Article 95: codes of conduct for voluntary application of specific requirements","summary":"The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.","topics":["governance","innovation"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-95-voluntary-commitment-register"],"control_ids":["praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review"],"template_ids":["praxikon:eu:ai-act:template:article-95-legal-text"],"conditions":[{"id":"article-95-scope","operator":"all","description":"Paragraph 1 expressly concerns AI systems other than high-risk AI systems, and the voluntary application to them of some or all of the requirements set out in Chapter III, Section 2. Paragraph 2 is wider and concerns the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives. Article 95 sits in Chapter X, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026."},{"id":"article-95-who-may-draw-up","operator":"any","description":"Paragraph 3 sets out who may draw up a code of conduct: individual providers or deployers of AI systems, organisations representing them, or both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. A code may cover one or more AI systems, taking into account the similarity of the intended purpose of the relevant systems."}],"exceptions":[{"id":"article-95-no-substitute-for-a-requirement","operator":"not","description":"Article 95 contains no provision that sets aside, suspends or replaces an obligation under this Regulation. The word voluntary refers to the application of requirements that precisely do not apply to the system concerned, and not to the requirements that do apply. A code of conduct on AI literacy leaves Article 4 untouched, and a code of conduct on transparency leaves Article 50 untouched."}],"statements":[{"kind":"official_fact","text":"Paragraph 1 provides: the AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements. Paragraph 2 provides: the AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to: (a) applicable elements provided for in Union ethical guidelines for trustworthy AI; (b) assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI; (c) promoting AI literacy, in particular that of persons dealing with the development, operation and use of AI; (d) facilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders participation in that process; (e) assessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Paragraph 3 provides: codes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems. Paragraph 4, as replaced by Article 1, point (35), of Regulation (EU) 2026/1744, provides: the AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and small mid-cap enterprises, when encouraging and facilitating the drawing up of codes of conduct.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 95(1) to (4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Read this article first for what it is not. It imposes no duty on your organisation: paragraphs 1, 2 and 4 address the AI Office and the Member States, and paragraph 3 only says who may draw a code up. And paragraph 1 is expressly about AI systems other than high-risk AI systems. That is the core of the provision and at the same time the source of the biggest misunderstanding in practice. The common thought is that a code of conduct can replace a mandatory requirement, or that signing one produces a form of compliance a regulator can hold against you or count in your favour. Neither is in the text. The voluntariness in Article 95 concerns requirements that precisely do not apply to your system: Chapter III, Section 2, contains the requirements for high-risk AI systems, and Article 95 invites you to apply some or all of those requirements to a system that is not high-risk. The reverse, a lighter reading of a requirement that does apply, is not on offer in this article. Two limits go with that. Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy. Article 95(2), point (c), names promoting AI literacy as a possible element of a code of conduct. That is not a duplication: the first is the duty, the second is the superstructure. A code of conduct on AI literacy is therefore a fine addition and never a replacement of Article 4. The same holds for transparency: Article 50 imposes a number of transparency duties, and a code that says something about them leaves Article 50 untouched. Anyone suggesting in a tender document or annual report that a code covers one of those duties is making a claim the text does not support.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Then read the article for what it does offer, because that is underestimated. This is the only place in the Regulation that says what an organisation can do of its own accord, and the enumeration in paragraph 2 is strikingly concrete. It names assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI. That topic appears nowhere else in the Regulation as something you can do, and for many organisations it is the topic a board is already asking about. It further names facilitating an inclusive and diverse design, including through inclusive and diverse development teams and the involvement of stakeholders in that process, and assessing and preventing the negative impact on vulnerable persons or groups, including as regards accessibility for persons with a disability and gender equality. Note the form paragraph 2 prescribes alongside, because it separates a serious code from a statement of intent: clear objectives and key performance indicators to measure the achievement of those objectives. A code without measurable indicators does not meet the form the provision itself describes. In practice this is where you can hook your own AI policy onto the Regulation without promising anything you cannot deliver. The most useful use is the inverse application of paragraph 1: for a system that is not high-risk, deliberately adopt part of Chapter III, Section 2, for example the keeping of logs or the documentation of data quality, and say which part you are not adopting and why. That is defensible and it is preparation as well, because a system sometimes changes classification.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"First make the separation visible in your own documentation: set out in two columns what you must do and what you do voluntarily, and make sure no line from the second column is used as cover for a line from the first. Then test every existing ethical code, AI policy document or supplier promise against that separation, because that is usually where the blending sits. If you are considering a code under Article 95, choose deliberately between the two routes: the paragraph 1 route for a system that is not high-risk, where you name which requirements of Chapter III, Section 2, you adopt and which you do not, or the paragraph 2 route for specific requirements across all your AI systems. In both cases give the code the form paragraph 2 describes: clear objectives and key performance indicators with which you measure the achievement, with a named owner and a moment of measurement. Then pick the elements that genuinely mean something to you rather than all five; environmental sustainability, AI literacy, inclusive and diverse design and the impact on vulnerable persons are separate topics with separate data. If you are an SME or a start-up, ask your national competent authority or the AI Office what support for drawing one up is available, because paragraph 4 requires your interests and needs to be taken into account. Finally, put no wording in quotations, tender responses or annual reports from which a reader could infer that participation in a code of conduct covers an obligation under the Regulation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 4; Article 50; Chapter III, Section 2; Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-95-voluntary-codes-of-conduct","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 95 on EUR-Lex"},{"relation":"public_page","href":"/en/ai-act/artikel/95","label":"Read Article 95 in the AI Act Explorer"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-09-06T00:00:00.000Z","next_review_due_at":"2027-03-05T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:article-99-101-penalties","legacy_id":"raip:obligation:article-99-101-penalties","type":"obligation","slug":"article-99-101-penalties","version":"1.0.0","effective_at":"2026-08-02T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"eebb183c9d9b58597388256d80ac73dc95eca9b9c98dd975ed907b55791e6905","label":"Article 99, 100 and 101: the penalty structure per obligation","summary":"The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.","topics":["enforcement","prohibited-practices"],"actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":[],"affected_actor_ids":["praxikon:eu:ai-act:actor:authorised-representative","praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:distributor","praxikon:eu:ai-act:actor:gpai-model-provider","praxikon:eu:ai-act:actor:importer","praxikon:eu:ai-act:actor:provider"],"oversight_actor_ids":["praxikon:eu:ai-act:actor:ai-office","praxikon:eu:ai-act:actor:market-surveillance-authority"],"evidence_owner_ids":[],"duty_holder_uncertainty_status":"out_of_scope","interpretation_status":"preliminary","interpretation_note":"Three things are unsettled here. First, whether an obligation not named in Article 99(3) to (5) carries a ceiling from the Regulation itself. We read Article 16, point (a), which obliges the provider to ensure that its high-risk systems comply with the requirements of Chapter III, Section 2, as meaning that non-compliance with Articles 9 to 15 by a provider is at the same time non-compliance with Article 16 and therefore sits inside the 3 percent ceiling, and Article 26 the same way for the deployer, including the duties that Article 26(5) draws in through Article 72 and Article 73. A defensible alternative reading is that the enumeration in paragraph 4 is meant strictly and covers only the duties written in Article 16 and Article 26 themselves, leaving the level for Articles 9 to 15 entirely to the national rules that paragraph 1 requires Member States to lay down. Second, what undertaking and total worldwide annual turnover in paragraphs 3 to 5 cover: the Regulation does not define this, and the difference between the turnover of the legal person fined and that of the group it belongs to is an order of magnitude in practice. We hold to the group reading because undertaking is construed that way in Union competition law, but that provenance is exactly the weak point: the Regulation nowhere refers to it, and the reading that the fined legal person is meant is equally defensible as long as there is no case law under this Regulation. Third, how far Article 75c(4) displaces the enumeration in paragraph 4: on its terms that provision governs enforcement by the AI Office over the operators of Article 75(1), and whether anything follows from it for the national route is unsettled. We read it narrowly, that is for the Office alone, and that is a reading and not settled law.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-99-101-penalty-exposure-register"],"control_ids":["praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record"],"template_ids":["praxikon:eu:ai-act:template:article-99-101-legal-text"],"conditions":[{"id":"article-99-101-penalties-scope","operator":"all","description":"Relevant as soon as you are an operator within the meaning of the Regulation, that is a provider, product manufacturer, deployer, authorised representative, importer or distributor, and one of the provisions named in Article 99(3), (4) or (5) is engaged. The Article 101 regime is additionally relevant where you are a provider of a general-purpose AI model, because there the Commission fines you itself. If you fall within the competence of the AI Office under Article 75(1), Article 75c is added on top."}],"exceptions":[{"id":"article-99-101-penalties-exception","operator":"not","description":"Paragraph 6 reverses the calculation for SMEs, including start-ups: for them the lower of the percentage and the amount applies, where for other undertakings it is the higher of the two, and it does so for every fine referred to in Article 99. The inserted paragraph 6a does the same for small mid-cap enterprises, but expressly only for paragraphs 4 and 5, so the Article 5 band is not reversed for them. Paragraph 8 leaves it to each Member State to determine to what extent administrative fines may be imposed on public authorities and bodies established in that Member State, so the ceiling for a public organisation does not follow from the Regulation. Paragraph 9 allows the fine to be imposed by the competent national courts or by other bodies rather than by the authority in some Member States."}],"statements":[{"kind":"official_fact","text":"Paragraph 1, as replaced by Regulation (EU) 2026/1744, requires Member States to lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, provides that those penalties shall be effective, proportionate and dissuasive, and requires Member States to take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties. Paragraph 2 requires Member States to notify those rules to the Commission without delay and at the latest by the date of entry into application, and to notify any subsequent amendment without delay. Paragraph 3 sets, for non-compliance with the prohibition of the AI practices referred to in Article 5, administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. Paragraph 4 sets, for non-compliance with provisions related to operators or notified bodies other than those laid down in Article 5, fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of that same turnover, whichever is higher, and enumerates: obligations of providers pursuant to Article 16, of authorised representatives pursuant to Article 22, of importers pursuant to Article 23, of distributors pursuant to Article 24, point (da) inserted by Regulation (EU) 2026/1744, obligations of providers and operators pursuant to Article 25(2) and (4), obligations of deployers pursuant to Article 26, requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34, and transparency obligations for providers and deployers pursuant to Article 50. Paragraph 5 sets, for the supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request, fines of up to EUR 7 500 000 or, if the offender is an undertaking, up to 1 % of that same turnover, whichever is higher. Paragraph 6 provides that in the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. The paragraph 6a inserted by Regulation (EU) 2026/1744 provides that in the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower. Paragraph 7 enumerates what is taken into account when deciding whether to impose a fine and when deciding on the amount: the nature, gravity and duration of the infringement and of its consequences, whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement, whether other authorities have already fined that operator for infringements of other Union or national law resulting from the same activity or omission, the size, annual turnover and market share of the operator, any other aggravating or mitigating factor such as financial benefits gained or losses avoided, the degree of cooperation with the national competent authorities, the degree of responsibility of the operator taking into account the technical and organisational measures it implemented, the manner in which the infringement became known to the authorities and whether the operator notified it, the intentional or negligent character of the infringement, and any action taken by the operator to mitigate the harm suffered by the affected persons. Paragraph 8 provides that each Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Paragraph 9 provides that, depending on the legal system of the Member State, the rules may be applied in such a manner that fines are imposed by competent national courts or by other bodies, with equivalent effect. Paragraph 10 subjects the exercise of these powers to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process. Paragraph 11 requires Member States to report annually to the Commission on the administrative fines they issued and on any related litigation or judicial proceedings. Chapter XII, which contains Article 99, has applied since 2 August 2025, with the exception of Article 101; the amendments to Article 99 have applied since 27 July 2026.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (38)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (40)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 101(1) provides that the Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, where it finds that the provider intentionally or negligently infringed the relevant provisions of this Regulation, failed to comply with a request for a document or for information pursuant to Article 91 or supplied incorrect, incomplete or misleading information, failed to comply with a measure requested under Article 93, or failed to make available access to the model with a view to conducting an evaluation pursuant to Article 92. In fixing the amount of the fine or periodic penalty payment, regard shall be had to the nature, gravity and duration of the infringement, taking due account of the principles of proportionality and appropriateness, and the Commission shall also take into account commitments made in accordance with Article 93(3) or made in relevant codes of practice in accordance with Article 56. Paragraph 2 requires the Commission to communicate its preliminary findings to the provider and give it an opportunity to be heard before adopting the decision. Paragraph 3 provides that fines imposed shall be effective, proportionate and dissuasive. Paragraph 4 provides that information on fines imposed shall also be communicated to the Board as appropriate. Paragraph 5 gives the Court of Justice of the European Union unlimited jurisdiction to review decisions of the Commission fixing a fine and provides that it may cancel, reduce or increase the fine. Paragraph 6 requires the Commission to adopt implementing acts containing detailed arrangements and procedural safeguards for proceedings that may lead to a decision under paragraph 1. Article 101 is excluded from the earlier application of Chapter XII and has therefore applied since 2 August 2026. Alongside this regime, Article 100 carries its own scheme for Union institutions, bodies, offices and agencies: the European Data Protection Supervisor may impose administrative fines on them of up to EUR 1 500 000 for non-compliance with the prohibition in Article 5 and up to EUR 750 000 for non-compliance with other requirements or obligations under this Regulation. Regulation (EU) 2026/1744 did not amend Articles 100 and 101.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 100(1)-(3)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Article 75c(4), inserted by Regulation (EU) 2026/1744, provides that a decision of the AI Office may be accompanied by the imposition of penalties in accordance with Article 99(3) to (7), which provisions apply mutatis mutandis to the Office in the execution of its supervision and enforcement tasks referred to in Article 75(1). In particular, the following are subject to administrative fines as referred to in Article 99(4): infringement of any applicable provision of this Regulation, including those not listed in Article 99(4); failure to comply with decisions or measures adopted pursuant to Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020 and the powers specified in Article 75a; and failure to comply with a commitment made binding pursuant to Article 75b. The supply of incorrect, incomplete or misleading information to the Office is subject to the fines of Article 99(5). Paragraph 5 additionally allows the Office to impose periodic penalty payments to compel, among other things, submission to an investigation, compliance with an information request, submission to an inspection or compliance with a binding commitment; those payments shall not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day. Paragraph 6 gives the Court of Justice unlimited jurisdiction over decisions of the Office fixing a fine or periodic penalty payment, and paragraph 8 subjects the powers of the Office to a limitation period of five years, with the same period for the power to enforce decisions taken. Note: the two authentic language editions of Regulation (EU) 2026/1744 diverge here. The English edition states five years in both subparagraphs of Article 75c(8); the Dutch edition states three years in both subparagraphs of Article 75 quater(8). This statement renders in each language what the edition in that language says and makes no silent choice. The implementing act under Article 75d(3) is to specify both subparagraphs, including the circumstances in which the limitation periods are interrupted; until it exists, the divergence remains an open question of interpretation.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The ceiling follows the provision, not the harm. That is the point routinely missed in boardrooms: a single amount gets budgeted for \"the AI Act fine\", while operators face three bands in Article 99 and there are separate regimes on top for Union institutions and for providers of general-purpose AI models. The highest band, EUR 35 million or 7 percent, belongs to Article 5 alone. Until recently that was a list of practices you either engage in or do not, but since the amendment of Article 5 that is no longer true: for the new prohibitions on sexual imagery, placing on the market is also prohibited where such generation is a reasonably foreseeable and reproducible outcome and the system lacks reasonable and adequate technical safety measures and safeguards. That is a duty to take measures inside the highest band, and it applies from 2 December 2026. The middle band, EUR 15 million or 3 percent, belongs to the enumeration in paragraph 4: the role duties of the provider, the authorised representative, the importer, the distributor and the deployer, since 27 July 2026 also Article 25(2) and (4), plus Article 50. What is not named there is at least as interesting: Article 4 and Article 27 do not appear, and the requirements of Chapter III reach the ceiling at most through Article 16 and Article 26. Note that Article 72 and Article 73 do come within reach for the deployer, because Article 26(5) obliges it to inform in accordance with Article 72 and declares Article 73 applicable mutatis mutandis, and Article 26 is named in paragraph 4. Two further things. Paragraph 5 turns answering an information request badly into its own fine category at 1 percent, independently of the underlying infringement. And paragraph 7 is not a discount scheme: it works both ways, because its opening words concern the decision whether or not to impose a fine and point (e) expressly names aggravating factors such as financial benefits gained. What you can steer are the factors you can evidence: your technical and organisational measures, your notification behaviour, your cooperation, and what you did after an incident to mitigate the harm suffered by affected persons. Two dates that matter in practice: the prohibition in Article 5 has applied since 2 February 2025 but Chapter XII only since 2 August 2025, so for conduct in between there is no administrative fine under Article 99(3). That gap does not return for the new Article 5 prohibitions of 2 December 2026: Chapter XII will by then have applied for well over a year, so the penalty regime exists on the day those prohibitions start to apply. And whoever falls within the competence of the AI Office must drop the idea that the enumeration in paragraph 4 is closed: Article 75c(4) places infringement of any applicable provision in the EUR 15 million or 3 percent band there, expressly including provisions not listed in paragraph 4.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (7)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 113, third paragraph, point (b)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Add a column to your obligations register carrying the ceiling that belongs to each entry, with three values: Article 99(3), Article 99(4), or national law under Article 99(1). Determine per general-purpose AI model that you provide yourself whether the Commission's Article 101 regime is added on top, and determine whether you fall under Article 75(1), because the Article 75c regime with periodic penalty payments then applies as well. Also record, per obligation, which of the factors in Article 99(7) you could actually show, in particular the technical and organisational measures implemented, your notification behaviour, your cooperation with the authority and the steps you take to mitigate harm to affected persons, because that is the part of the amount you can influence yourself. This is our recommendation and not a duty under the Regulation: Article 99 addresses the Member States and imposes no deadline whatsoever on an operator.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 99(1)-(11)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_locator":"Article 101(1)-(6)"},{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_locator":"Regulation (EU) 2026/1744, Article 1, point (32)"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"applicable","deadline_at":null,"timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-99-101-penalties","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 99, 100 and 101 on EUR-Lex"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Regulation (EU) 2026/1744, the amendment of Article 99"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":50},{"id":"praxikon:eu:ai-act:obligation:annex-iii-eight-areas","legacy_id":"raip:obligation:annex-iii-eight-areas","type":"obligation","slug":"annex-iii-eight-areas","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"fefd34d9142cbbda7f5ba59c3a3ec858bd9f1101363c0e874cf8b071780790e6","label":"Annex III: the eight areas separately","summary":"Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":"preliminary","interpretation_note":"What is open here is not the text but the boundary and the form. The eight points are reproduced verbatim, but whether a concrete application falls inside a lettered subpoint depends on the intended purpose, and the Commission guidelines working that out point by point are still in draft at our knowledge date. Publishing the points as separate objects is also our choice; the Regulation gives a list and not eight self-standing norms. A defensible alternative reading is that only the Article 6(2) route deserves an object of its own. It also remains unclear how Article 6(3) works out per area: the exception is drafted in general terms, but the profiling proviso bites in almost every case in one area and rarely in another. Finally, we have checked that Regulation (EU) 2026/1744 inserts Article 6(1a) to (1c) without renumbering or amending paragraphs 2 and 3; if that changes, the route in this object changes with it.","obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:map-system-to-annex-iii-area"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-eight-areas-legal-text"],"conditions":[{"id":"annex-iii-eight-areas-intended-purpose","operator":"any","description":"Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes."},{"id":"annex-iii-eight-areas-route","operator":"all","description":"Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order."},{"id":"annex-iii-eight-areas-article-25-role-shift","operator":"any","description":"The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself."}],"exceptions":[{"id":"annex-iii-eight-areas-article-6-3-derogation","operator":"not","description":"Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk."},{"id":"annex-iii-eight-areas-article-6-4-documentation","operator":"all","description":"The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request."}],"statements":[{"kind":"official_fact","text":"The introductory sentence of Annex III reads: High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas. Eight numbered areas follow. 1. Biometrics, in so far as their use is permitted under relevant Union or national law. 2. Critical infrastructure. 3. Education and vocational training. 4. Employment, workers’ management and access to self-employment. 5. Access to and enjoyment of essential private services and essential public services and benefits. 6. Law enforcement, in so far as their use is permitted under relevant Union or national law. 7. Migration, asylum and border control management, in so far as their use is permitted under relevant Union or national law. 8. Administration of justice and democratic processes. The full text of each point, with its lettered subpoints, sits on the object for that area.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"Annex III is not fixed. Article 7(1) empowers the Commission to add or amend use cases in Annex III by delegated act, and Article 7(3) to remove them. Article 7(1)(a) requires the system to be intended for use in one of the areas listed in Annex III. The eight areas are therefore the stable layer; the lettered subpoints inside them can change without the Regulation itself being revised.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 7(1) and (3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Seven of the eight areas are subdivided into lettered subpoints in the text: point 1 into (a) to (c), point 3 into (a) to (d), point 4 into (a) and (b), point 5 into (a) to (d), point 6 into (a) to (e), point 7 into (a) to (d) and point 8 into (a) and (b). Point 2 has no lettered subpoints. We therefore count twenty-four lettered subpoints across seven areas. That number appears nowhere in the Regulation: it is our count of the text as it stands at our knowledge date, and a delegated act under Article 7 can silently make it stale.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Annex III, points 1 to 8","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"editorial_interpretation","text":"Reading Annex III as one block leads to the wrong question. The question is not whether your organisation works in one of the eight areas, because nearly everyone does: a hospital touches point 5, a school point 3, and every employer point 4. The question is whether the intended purpose of this one system coincides with the description of a lettered subpoint. A CV parser that only deduplicates repeat applications does something other than a system that evaluates candidates, and yet both get filed under recruitment in practice. Note the order too. Points 1, 6 and 7 carry the condition that the use must be permitted, and that is where Article 5 comes first. Emotion recognition in the workplace and in education is prohibited under Article 5(1)(f), except where the system is placed on the market or put into service for medical or safety reasons; whoever reverses that builds a conformity file for something that is not allowed. Finally, the area also determines which duties then weigh heavily. Article 86 gives a right to an explanation for decisions based on any system listed in Annex III other than point 2, and Article 27 requires bodies governed by public law and private providers of public services to carry out a fundamental rights impact assessment on every Annex III route other than point 2, with point 5(b) and (c) extending that duty to any deployer. For systems already on the market before the application date, the separate transitional rule of Article 111(2) applies as well.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"For every AI system, record in your register not that it falls under Annex III but which point and which lettered subpoint it touches, with the intended purpose in your own words alongside. The eight area objects sit in the graph under the slugs annex-iii-area-1-biometrics through annex-iii-area-8-justice-and-democratic-processes; refer to those rather than to Annex III as a whole. Add four fields: is the use permitted, and if not, why is Article 5 not engaged; has the Article 6(3) test been carried out, which of the four conditions was met, and has the assessment been documented and the system registered under Article 6(4) and Article 49(2); does the system perform profiling, because the exception then falls away; and who carries the provider role after Article 25. Repeat that record on every change to the intended purpose.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-eight-areas","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Annex III on EUR-Lex"},{"relation":"public_page","href":"https://www.praxikon.com/nl/ai-act/bijlage/3","label":"Annex III in the AI Act Explorer"},{"relation":"related","href":"https://www.praxikon.com/nl/annex-iii","label":"The eight areas on praxikon.com"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-14T00:00:00.000Z","next_review_due_at":"2027-02-10T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:annex-iii-high-risk","legacy_id":"raip:obligation:annex-iii-high-risk","type":"obligation","slug":"annex-iii-high-risk","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"c0afd1789ed393ba3f9ce04205bd74b4831ff0fd58146108fdd8dd08d2f4f6c9","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","topics":["high-risk"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:annex-iii-classify"],"evidence_ids":["praxikon:eu:ai-act:evidence:annex-iii-classification-record"],"control_ids":["praxikon:eu:ai-act:control:annex-iii-change-trigger"],"template_ids":["praxikon:eu:ai-act:template:annex-iii-classifier"],"conditions":[{"id":"annex-iii-listed-purpose","operator":"all","description":"The intended purpose falls within a use case listed in Annex III."},{"id":"article-6-2-route","operator":"all","description":"Classification follows Article 6(2)."}],"exceptions":[{"id":"article-6-3-exception","operator":"not","description":"A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented."}],"statements":[{"kind":"official_fact","text":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","label":"Binding amended application calendar"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:article-10-data-governance","legacy_id":"raip:obligation:article-10-data-governance","type":"obligation","slug":"article-10-data-governance","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"1b6992c5a6d684dd828c8b00a7239e768eee9d4a5cb4fdbc4fbaee3dbf561d91","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-10-data-governance-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-10-data-governance-record"],"control_ids":["praxikon:eu:ai-act:control:article-10-data-governance-control"],"template_ids":["praxikon:eu:ai-act:template:article-10-data-governance-legal-text"],"conditions":[{"id":"article-10-data-governance-scope","operator":"all","description":"The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data."}],"exceptions":[{"id":"article-10-data-governance-exception","operator":"not","description":"For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions)."}],"statements":[{"kind":"official_fact","text":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 10 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:article-11-technical-documentation","legacy_id":"raip:obligation:article-11-technical-documentation","type":"obligation","slug":"article-11-technical-documentation","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"15571dc37c23ef11a79a3b7b9b7d5674ee4fc7161cc4a9bb8f62321f66294a2c","label":"Article 11: technical documentation","summary":"The technical file demonstrating before market placement that a high-risk system meets the requirements.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":[],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-11-technical-documentation-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-11-technical-documentation-record"],"control_ids":["praxikon:eu:ai-act:control:article-11-technical-documentation-control"],"template_ids":["praxikon:eu:ai-act:template:article-11-technical-documentation-legal-text"],"conditions":[{"id":"article-11-technical-documentation-scope","operator":"all","description":"The provider places a high-risk AI system on the market or puts it into service."}],"exceptions":[{"id":"article-11-technical-documentation-exception","operator":"not","description":"Small providers (SMEs) may provide the documentation in the simplified form established by the Commission."}],"statements":[{"kind":"official_fact","text":"Article 11 requires technical documentation drawn up before market placement, kept up to date and containing the Annex IV elements, so that compliance with Section 2 is demonstrable to supervisors.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"For buying organisations, Annex IV is the checklist of what you must be able to request contractually from your supplier; without that file you cannot meet your own Article 26 duties.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include the right to access the technical documentation in AI procurement and supplier contracts now.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 11(1)-(3) and Annex IV","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-11-technical-documentation","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 11 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:article-12-logging","legacy_id":"raip:obligation:article-12-logging","type":"obligation","slug":"article-12-logging","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"92daf8448d3471e5014ea66a2dc2731909f2689e5e3bdb243f49a75572002f20","label":"Article 12: logging and traceability","summary":"Automatic recording of events over the lifetime of a high-risk AI system.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-12-logging-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-12-logging-record"],"control_ids":["praxikon:eu:ai-act:control:article-12-logging-control"],"template_ids":["praxikon:eu:ai-act:template:article-12-logging-legal-text"],"conditions":[{"id":"article-12-logging-scope","operator":"all","description":"The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control."}],"exceptions":[{"id":"article-12-logging-exception","operator":"not","description":"The retention period may be limited by Union or national law, including data protection."}],"statements":[{"kind":"official_fact","text":"Article 12 requires high-risk AI systems to be technically capable of automatically recording events over their lifetime, for traceability, risk signalling and post-market monitoring; Article 19 and Article 26(6) govern log retention.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Logging is the backbone of all other evidence: without logs an incident cannot be reconstructed and a monitoring duty cannot be fulfilled. Buyers should already test whether a system is technically capable of this.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Include logging capability and log access as a requirement in every AI purchase and assign the retention regime (who, where, how long) per system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 12, Article 19 and Article 26(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-12-logging","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 12 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:article-13-instructions","legacy_id":"raip:obligation:article-13-instructions","type":"obligation","slug":"article-13-instructions","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"818266e8912de0d2c95a38a4a16c67b1aad02d10359b3571710fd757c678819b","label":"Article 13: transparency towards deployers","summary":"Comprehensible instructions for use and system information so deployers can operate the system correctly.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":[],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-13-instructions-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-13-instructions-record"],"control_ids":["praxikon:eu:ai-act:control:article-13-instructions-control"],"template_ids":["praxikon:eu:ai-act:template:article-13-instructions-legal-text"],"conditions":[{"id":"article-13-instructions-scope","operator":"all","description":"The provider supplies a high-risk system; the deployer uses it according to the instructions."}],"exceptions":[{"id":"article-13-instructions-exception","operator":"not","description":"The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed."}],"statements":[{"kind":"official_fact","text":"Article 13 requires high-risk systems to be designed transparently enough for deployers to interpret and use the output, with instructions covering purpose, accuracy, limitations, human oversight and maintenance.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"The instructions are the hinge between provider and deployer duties: what the provider fails to supply here, the deployer cannot deliver under Article 26. Ask for it explicitly at procurement.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Translate received instructions per system into internal work instructions per role and record who received them.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 13(1)-(3)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-13-instructions","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 13 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40},{"id":"praxikon:eu:ai-act:obligation:article-14-human-oversight","legacy_id":"raip:obligation:article-14-human-oversight","type":"obligation","slug":"article-14-human-oversight","version":"1.0.0","effective_at":"2026-07-27T00:00:00.000Z","known_at":"2026-08-08T00:00:00.000Z","valid_until":null,"payload_hash_sha256":"02da6ce26c5036d2cdea0842564e14a1227cd8f8e5fe5e67e15b52cd5332f98b","label":"Article 14: human oversight","summary":"High-risk AI must be designed so that humans can effectively oversee it and intervene.","topics":["high-risk-requirements"],"actor_ids":["praxikon:eu:ai-act:actor:deployer","praxikon:eu:ai-act:actor:provider"],"duty_holder_ids":["praxikon:eu:ai-act:actor:provider"],"affected_actor_ids":["praxikon:eu:ai-act:actor:deployer"],"oversight_actor_ids":[],"evidence_owner_ids":["praxikon:eu:ai-act:actor:provider"],"duty_holder_uncertainty_status":null,"interpretation_status":null,"interpretation_note":null,"obligation_ids":[],"change_ids":[],"action_ids":["praxikon:eu:ai-act:action:article-14-human-oversight-act"],"evidence_ids":["praxikon:eu:ai-act:evidence:article-14-human-oversight-record"],"control_ids":["praxikon:eu:ai-act:control:article-14-human-oversight-control"],"template_ids":["praxikon:eu:ai-act:template:article-14-human-oversight-legal-text"],"conditions":[{"id":"article-14-human-oversight-scope","operator":"all","description":"The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons."}],"exceptions":[{"id":"article-14-human-oversight-exception","operator":"not","description":"For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there."}],"statements":[{"kind":"official_fact","text":"Article 14 requires high-risk systems to be effectively overseeable by natural persons, with measures enabling them to understand the system, correctly interpret output, remain aware of automation bias, and decide not to use, to disregard or to stop the system.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"official_fact","text":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"}},{"kind":"editorial_interpretation","text":"Oversight on paper is not oversight: the law names automation bias explicitly, so a human who may only click through does not count. Effective oversight requires understanding, time and mandate, which ties directly into the Article 4 literacy measures.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}},{"kind":"recommended_action","text":"Appoint the overseeing persons per (upcoming) high-risk system now, train them specifically and record their mandate to intervene in writing.","citations":[{"source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 14(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"editorial"}}],"legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","timing_basis":null,"high_risk_regime_from":null,"links":[{"relation":"public_page","href":"https://www.praxikon.com/en/verplichtingen/article-14-human-oversight","label":"Open the human explanation"},{"relation":"official_source","href":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","label":"Article 14 on EUR-Lex"}],"review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"source_review":{"level":"source_verified","last_checked_at":"2026-08-08T00:00:00.000Z","next_review_due_at":"2027-02-04T00:00:00.000Z","date_basis":"first_publication"},"score":40}],"included":{"sources":[{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":{"nl":"Richtsnoeren over Artikel 50","en":"Guidelines on Article 50"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"3c3d066f0294692b398f096861adb89198f3d6062939237a97b35fa9ced4d39d","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-article-50-guidelines"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":{"nl":"Richtsnoeren voor GPAI-modelaanbieders","en":"Guidelines for GPAI model providers"},"publisher":{"nl":"Europese Commissie","en":"European Commission"},"canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"b3691c417d2ea106c7767e1b78bf30f045b0172a4292cb44ba76ff45109de497","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:commission-gpai-guidelines"},{"id":"praxikon:eu:ai-act:source:dir-eu-2019-1937","title":{"nl":"Richtlijn (EU) 2019/1937 inzake de bescherming van personen die inbreuken op het Unierecht melden","en":"Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/dir/2019/1937/oj","eli":"http://data.europa.eu/eli/dir/2019/1937/oj","source_version":"original-oj-2019-11-26","verified_at":"2026-09-06T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"2c76f0ccbfefa16c95ca202883ed31d30dfa21498f4895b621abab2fb9dbb706","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:dir-eu-2019-1937"},{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":{"nl":"EU AI-verordening 2024/1689","en":"EU Artificial Intelligence Act 2024/1689"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"bf0fca3e1fb47ce58924f6e736d572bb5db3812c3276c0b2891fbf328c42a5c6","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2024-1689"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":{"nl":"Digital Omnibus over AI 2026/1744","en":"Digital Omnibus on AI 2026/1744"},"publisher":{"nl":"Europees Parlement en Raad","en":"European Parliament and Council"},"canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z","fingerprint_basis":"canonical_url|source_version|verified_at","source_record_hash_sha256":"17f108dc4eb93b8ff3abf091ab8a6a6e3095ae112229f27ca9a59ded886c7864","review":{"reviewed_at":"2026-08-08T00:00:00.000Z","reviewer":"Praxikon release validation","review_method":"source_link_and_rule_validation","legal_status":"source_checked"},"legacy_id":"raip:source:reg-eu-2026-1744"}]},"links":{"self":"https://www.praxikon.com/api/v1/search?q=article+50&lang=en","alternate":"https://www.praxikon.com/api/v1/search?q=article+50&lang=en&format=jsonld","licence":"https://www.praxikon.com/nl/legal/terms"}}