Article 16: Obligations of providers of high-risk AI systems
Praxikon tracks Article 16 (Obligations of providers of high-risk AI systems) under the EU AI Act, citing the source for every statement.
Article 16 requires providers to ensure their AI systems comply with requirements, implement a quality management system, maintain technical documentation, and affix the CE marking.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Cross-references
Annexes
Frequently asked questions
What obligations do providers of high-risk AI have under Article 16?+
Must a provider register under Article 16 AI Act?+
What documentation does Article 16 of the AI Act require?+
What must a provider do before placing a high-risk AI system on the market?+
What if I modify a third-party AI system and release it under my own name?+
Do I need to set up a quality management system as a provider?+
What Article 16 requires in practice
Connections
What connects to Article 16 AI Act
Themes where this returns
The counterpart in the other law
GDPR interpretation that also applies here6 of 11
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB) · via Security and robustness
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland · via Security and robustness
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB) · via Who is responsible: roles in both laws
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België) · via Who is responsible: roles in both laws
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak · via Who is responsible: roles in both laws
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB) · via Who is responsible: roles in both laws