Skip to main content
Praxikon
All answers

Direct answer

What obligations does the deployer, the provider of a GPAI model and the provider of an AI system have under Article 4a of the AI Act?

Your question is about Article 4a: legal basis for bias testing with special categories of personal data. That obligation applies today. Whether your system actually falls under it depends on conditions you assess yourself.

You determine this yourself

  • Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2.
  • Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it.
  • The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data.
  • Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all.

First step: Justify and record your reliance on Article 4a.

Article 4a of the AI Act covers legal basis for bias testing with special categories of personal data. Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5). The duty sits with the deployer, the provider of a GPAI model and the provider of an AI system. This obligation applies today.

The conclusion and your first steps

This applies now

Your first actions

  1. Justify and record your reliance on Article 4a. Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)
    • Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)
    • Article 1, point 2(b), replacing Article 2(7)
    • Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Execution

Where relevant, connect the FRIA to the DPIA, register and decision-making

Whether a FRIA is required depends on your role and the use case. Where it applies, you record the assessment and measures and, where relevant, connect them to the AI register, a DPIA and decision-making. Embed AI guides this connected assessment with your team. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the FRIA and DPIA approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist