Article 3: Definitions
Praxikon tracks Article 3 (Definitions) under the EU AI Act, citing the source for every statement.
According to Article 3, an AI system is a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness, and infers from input how to generate outputs such as predictions, recommendations or decisions.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Official guidance on this article
7- Guidelines on transparency obligations for providers and deployers of certain AI systems under Article 50 of the AI ActSpecifies the concepts of provider, deployer and deepfake that determine who in a chain bears which transparency obligation.PublishedGuidelinesEuropean Commission20 Jul 2026
- Guidelines on the scope of obligations for providers of general-purpose AI models under the AI ActSpecifies the definition of a general-purpose AI model in Article 3, point 63, with an indicative threshold based on training compute.PublishedGuidelinesEuropean Commission18 Jul 2025
- AIB 2025-1 / MDCG 2025-6 Interplay between the Medical Devices Regulation (MDR) and In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)Specifies that the deployer under the AI Regulation does not coincide with the user under the Medical Devices Regulation and in vitro Diagnostic Medical Devices Regulation, which determines who bears which obligation.PublishedGuidelinesAI Board (AIB) and Medical Device Coordination Group (MDCG), European Commission
- Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act)Works through the definition of AI system in Article 3, paragraph 1, element by element so that organisations can classify their software portfolio as in scope or out of scope.PublishedGuidelinesEuropean Commission (DG CONNECT / AI Office)6 Feb 2025
- AI Literacy - Questions & AnswersClarifies who falls within the definition of staff, including contractors and third parties who work with AI on behalf of the organisationPublishedQ&AEuropean Commission, DG CONNECT27 Jul 2026
- Draft guidance and reporting template on serious AI incidents (Article 73)Clarifies the definition of serious incident from Article 3, paragraph 49, with examples of harm to health, property, environment and fundamental rightsConsultationTemplateEuropean Commission26 Sept 2025
- EU AI Act Compliance CheckerHelps determine what role an organisation has, provider or deployer, because the entire package of obligations depends on itDraftQ&AEuropean Commission (AI Act Service Desk)
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related blog posts
Related articles
Frequently asked questions
How does Article 3 AI Act define an AI system?+
What is a provider under the AI Act?+
What is a deployer under Article 3 of the AI Act?+
Connections
What connects to Article 3 AI Act
Themes where this returns
The counterpart in the other law
- Article 4 GDPR: Definitions
- Article 9 GDPR: Processing of special categories of personal data
- Article 24 GDPR: Responsibility of the controller
- Article 28 GDPR: Processor
- Article 33 GDPR: Notification of a personal data breach to the supervisory authority
- Article 34 GDPR: Communication of a personal data breach to the data subject
GDPR interpretation that also applies here6 of 15
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
2021-07-07 · final, European Data Protection Board (EDPB) · via Who is responsible: roles in both laws
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB) · via Reporting: data breaches and serious incidents
- IAB Europe: the TC String is personal data and the industry body is a joint controller
2024-03-07 · final, Hof van Justitie van de EU (Vierde kamer), IAB Europe tegen Gegevensbeschermingsautoriteit (België) · via Who is responsible: roles in both laws
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak · via Who is responsible: roles in both laws
- Guidelines 02/2026 on Anonymisation
2026-07-07 · under consultation, European Data Protection Board (EDPB) · via Who is responsible: roles in both laws
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB) · via Who is responsible: roles in both laws