Direct answers
Recognise your situation, see what applies
Every question below is a real-world situation. The answer shows what applies now, your first actions and the evidence to retain, assembled from the same versioned information model as the rest of the platform.
Frequently asked right now
Go directly to common questions about what already applies, which role you have and what to arrange now.
- What exactly does Article 50 of the AI Act regulate?
- Our chatbot talks to customers. Does it have to say it is AI?
- We publish AI-generated content. Does it need labelling?
- What does Article 4 AI literacy concretely require from us?
- Where do we start with AI Act compliance? A step-by-step approach
- Are we a provider or a deployer under the AI Act?
- What counts as high risk, and is our system one of them?
- How do we set up an AI register and classify our systems?
- Do we need to perform a FRIA and how do we approach it?
- We want to draft an AI policy. Where do we start?
- We are a public-sector organisation using AI. What needs to be in place?
- We use AI for creditworthiness or insurance pricing. What applies?
- We train or publish our own AI model. Which GPAI rules apply?
- Our employees use ChatGPT or Copilot. What do we need to arrange?
- Does our AI use case fall under the prohibited practices?
- What did the Digital Omnibus shift and what still applies as planned?
Start from your role
The same knowledge base, ordered by who you are instead of by which article holds the answer.
As a provider of an AI system5
As a deployer5
As a public-law body5
- Which AI Act obligations apply to a public-law body?
- What does a public-law body actually have to do under the AI Act?
- What evidence does a public-law body have to be able to show under the AI Act?
- When do the AI Act obligations start to apply to a public-law body?
- When are you a public-law body under the AI Act?
As a provider of a GPAI model5
- Which AI Act obligations apply to a provider of a GPAI model?
- What does a provider of a GPAI model actually have to do under the AI Act?
- What evidence does a provider of a GPAI model have to be able to show under the AI Act?
- When do the AI Act obligations start to apply to a provider of a GPAI model?
- When are you a provider of a GPAI model under the AI Act?
For high-risk AI systems4
Prohibited practices and enforcement4
- We are considering facial recognition or other biometrics. Is that allowed?Biometric identification or categorisation of people, such as facial recognition for access or in public spaces.
- Does our AI use case fall under the prohibited practices?You want to be sure an existing or planned AI use case does not fall under the Article 5 prohibition, such as manipulation, social scoring or certain biometrics.
- What fines and enforcement does the AI Act have and who supervises?You want to know what can happen in case of non-compliance: which supervisors exist, what the fine ceilings are and which rules are already enforced.
- What does Article 99, 100 and 101 of the AI Act say about the penalty structure per obligation?The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.
Transparency, chatbots and content4
- Our chatbot talks to customers. Does it have to say it is AI?An AI system interacting directly with people, such as a chatbot or voicebot in customer contact.
- We publish AI-generated content. Does it need labelling?Text, image, audio or video (partly) created with generative AI and published publicly.
- We create or use deepfakes or synthetic media. What is required?Image, audio or video of existing people, places or events generated or manipulated with AI.
- What exactly does Article 50 of the AI Act regulate?You want the overview of the transparency obligations: which disclosure, marking or label applies to which AI scenario.
AI literacy and organisation8
- Our employees use ChatGPT or Copilot. What do we need to arrange?Employees use generative AI tools at work, with or without a formal policy.
- We want to draft an AI policy. Where do we start?Your organisation wants ground rules for responsible AI use: what is allowed, what is not, and who decides.
- What does Article 4 AI literacy concretely require from us?You want to know what the AI literacy duty entails and how to fulfil it demonstrably for your teams.
- Are we a provider or a deployer under the AI Act?You want to determine your organisation’s role per AI use case, because the role determines the duty list.
- Do we need to appoint an AI officer or AI compliance officer?You wonder whether the AI Act, like the GDPR with the DPO, requires a mandatory officer and how to assign AI responsibility if not.
- Is the ALTAI / trustworthy AI assessment mandatory under the AI Act?You know the Assessment List for Trustworthy AI and wonder how it relates to the legal duties.
- Who can help us implement the AI Act?You are looking for guidance: a workshop, training or a partner who executes the implementation with you rather than only advising.
- Does the AI Act also apply to small organisations?You are an SME, start-up or small institution and wonder whether this regulation applies to you or only to large technology companies.
Fundamental rights and the public sector8
- We are a public-sector organisation using AI. What needs to be in place?A municipality, executive agency or other public body using AI towards citizens, for example in benefits, enforcement or services.
- Do we need to perform a FRIA and how do we approach it?A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system.
- How do the GDPR and the AI Act relate to each other?Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet.
- What obligations does the deployer, the provider of a GPAI model and the provider of an AI system have under Article 4a of the AI Act?Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).
- What obligations does the provider of an AI system have under Article 61 of the AI Act?If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.
- What obligations does the deployer have under Article 85 of the AI Act?Anyone with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority. For an organisation that means your own staff, customers and candidates have a route to the regulator that does not run through you.
- What obligations does the deployer have under Article 86 of the AI Act?A person affected by a decision that a deployer takes on the basis of the output of a high-risk AI system listed in Annex III may request an explanation of the role of that system in the decision-making procedure and of the main elements of the decision taken.
- What does Article 87 of the AI Act say about reporting of infringements and protection of reporting persons?The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.
High risk and classification14
- We use AI in recruitment and selection. Is that high risk?AI screening CVs, ranking candidates, targeting vacancies or analysing job interviews.
- We use AI for creditworthiness or insurance pricing. What applies?AI determining creditworthiness or credit scores, or risk and premium setting for life or health insurance.
- We use AI in education or assessment. Is that high risk?AI for admission, evaluation, level determination or exam proctoring in education or vocational training.
- How do we set up an AI register and classify our systems?You want oversight: which AI systems run, who owns them, and which risk category applies per system.
- What did the Digital Omnibus shift and what still applies as planned?You want the current timeline: which obligations were postponed and which deadlines stand.
- Does our system fall under the definition of an AI system (Article 3)?You are unsure whether software, a computational model or a rule-based system legally qualifies as an AI system and thus falls under the regulation.
- Where do we start with AI Act compliance? A step-by-step approachYour organisation wants to become AI Act compliant but has no approach yet: you are looking for the logical order and a starting checklist.
- What counts as high risk, and is our system one of them?You want to know whether your application falls into the regulation’s heaviest category, because nearly every further obligation depends on it.
- What obligations does the provider of an AI system have under Annex III of the AI Act?Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.
- What obligations does the deployer and the provider of an AI system have under Article 111(2) of the AI Act?High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.
- What obligations does the authorised representative, the provider of an AI system and the body governed by public law have under Article 49 of the AI Act?The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.
- What obligations does the provider of an AI system have under Article 6(1) of the AI Act?An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.
- What obligations does the provider of an AI system have under Article 6(1a) to (1c) of the AI Act?The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.
- What obligations does the authorised representative, the provider of an AI system and the body governed by public law have under Article 71 of the AI Act?The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.
Requirements for high-risk systems19
- We build an AI product for customers. What are a provider’s duties?Your organisation develops an AI system (or has it developed) and places it on the market under its own name.
- We use AI to monitor or evaluate employees. What applies?AI for task allocation, performance evaluation, promotion or termination decisions, or monitoring employee behaviour.
- We use AI in healthcare. Which AI Act rules apply there?AI in a healthcare context, from triage and administrative support to AI in or around medical devices.
- How do we set up human oversight of AI?You want to know what the AI Act expects of human control over AI decisions: human in, on or over the loop, and who needs to be competent for it.
- What is automation bias and what should our organisation do about it?Employees blindly trust AI output. You want to know what the AI Act says about this and how to counter it demonstrably.
- What are a deployer’s obligations under Article 26?Your organisation uses (or will use) a supplier’s high-risk AI system and you want to know your own duties as deployer.
- What data requirements does the AI Act set for high-risk AI (Article 10)?You want to know which requirements apply to training, validation and test data and what you must be able to demonstrate about them.
- What technical documentation does the AI Act require (Article 11)?You want to know which file a high-risk AI provider must build and what you can request as a customer.
- What does "reasonably foreseeable misuse" mean in the AI Act?You encounter the term in requirements and documentation and want to know what to do with it concretely in design and management.
- What does the Article 9 risk management system require from us?You are the provider of a high-risk AI system and must show that you structurally identify, mitigate and keep tracking risks to health, safety and fundamental rights.
- Do we have to keep logs of our AI system?You want to know which events your high-risk AI system must record automatically, and how long you keep that record.
- Do we need a quality management system?You are the provider of a high-risk AI system and want to know whether you must set up a documented quality system, and what belongs in it.
- What instructions for use must we supply with our AI system?You supply a high-risk AI system to another organisation. They must be able to use it as you intended, which is only possible if you supply what the system can and cannot do.
- How accurate and robust does our AI system have to be?You want to know what performance level the regulation demands of a high-risk system, and how to demonstrate it when no statutory minimum percentage exists.
- What obligations does the provider of an AI system have under Article 20 of the AI Act?A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.
- What obligations does the provider of an AI system have under Article 21 of the AI Act?Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.
- What does Article 63 of the AI Act say about derogations for SMEs in the quality management system?SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Until 27 July 2026 this read microenterprises; Article 1, point (26), of Regulation (EU) 2026/1744 replaced paragraph 1 and widened the circle to SMEs. Which elements those are is for the Commission to set out in guidelines, considering the needs of SMEs and without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 rules out any wider reading: the provision shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.
- What obligations does the provider of an AI system have under Article 75(1a) and (1e) of the AI Act?If you are the provider of a high-risk AI system subject to the competence of the AI Office, you report serious incidents to the Office rather than to your national authority, with the machinery and the deadlines of Article 73(2) to (9) applying in full, and the Office still transmits the information to your national market surveillance authority. Where that system is subject to a third-party conformity assessment under Article 43, the Office is responsible for it, the notified body acts on behalf of the Commission, and you pay the costs directly to that body.
- What obligations does the provider of an AI system have under Article 8 of the AI Act?High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.
Conformity, CE and registration6
- Do we need to register our AI system in the EU database?You want to know who must register in the EU database for high-risk AI and when that duty starts to apply.
- How do conformity assessment and CE marking work for AI?You want to know when an AI system needs a conformity assessment and CE marking and who performs it.
- What does Articles 28 to 39 of the AI Act say about notifying authorities and notified bodies?Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.
- What obligations does the provider of a GPAI model and the provider of an AI system have under Articles 40 to 42 of the AI Act?A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.
- What does Article 44 of the AI Act say about certificates of notified bodies?A certificate issued by a notified body is valid for at most five years for AI systems covered by Annex I and at most four years for AI systems covered by Annex III, and may be extended at the request of the provider after a re-assessment. Where the system no longer meets the requirements of Section 2, the body shall, taking account of the principle of proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes corrective action within an appropriate deadline it sets so as to ensure compliance with those requirements. An appeal procedure against that decision is available.
- What does Article 46 of the AI Act say about derogation from conformity assessment procedure?By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.
Value chain: procurement, import and distribution4
- We source AI from outside the EU. What do we need to arrange?You import, distribute or use an AI system from a provider established outside the Union, and want to know which duties land with you.
- What obligations does the importer have under Article 23 of the AI Act?Before placing a system on the market the importer verifies four things about the provider, and afterwards carries its own retention, information and notification package with a ten-year term.
- What obligations does the distributor have under Article 24 of the AI Act?Before making a system available on the market the distributor verifies the marking, the declaration and the instructions for use plus compliance by provider and importer, and must afterwards be able to correct, withdraw or recall.
- What obligations does the authorised representative and the provider of a GPAI model have under Article 54 of the AI Act?A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.
After go-live: monitoring and incidents2
- Do we have to report serious incidents with our AI system?Something goes wrong with a high-risk AI system and you need to know whether that is a reportable incident, who to report it to and within what deadline.
- How do we monitor our AI system after it goes live?Your high-risk system runs in production. You must keep tracking how it behaves in practice and act as soon as that behaviour deviates from what you established at assessment time.
GPAI models3
- We train or publish our own AI model. Which GPAI rules apply?A general-purpose AI model (foundation model, LLM) placed on the Union market, including open source.
- What does Article 56 of the AI Act say about codes of practice for general-purpose AI models?The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.
- What obligations does the provider of an AI system have under Article 75 of the AI Act?For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.
GPAI models with systemic risk2
- When does a GPAI model have systemic risk (the 10^25 FLOPs threshold)?You want to know when an AI model qualifies as GPAI with systemic risk and which additional duties then apply.
- What obligations does the provider of a GPAI model have under Article 52 of the AI Act?The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.
Testing and sandboxes4
- Can we test our AI system before it goes to market?You want to develop, train and validate an AI system before placing it on the market, in a supervised sandbox or under real world conditions outside the laboratory.
- What does Article 57 of the AI Act say about AI regulatory sandboxes?Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.
- What does Article 62 of the AI Act say about measures for providers and deployers that are SMEs or start-ups?Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.
- What does Article 95 of the AI Act say about codes of conduct for voluntary application of specific requirements?The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.
Situation not listed? Ask your question in the knowledge base or use the implementation map.