Skip to main content
Praxikon
All answers

Direct answer

When are you a provider under the AI Act?

18 obligations under the AI Act bear on this, of which 4 apply today.

First step: Justify the Article 6(3) exception against each individual condition.

Whether you are a provider is not a matter of what you call yourself but of what you do with the system. Across the 18 obligations there are 39 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: provider of an ai system.

The conclusion and your first steps

This applies now

Coming up

What decides whether this is about you

Annex III: high-risk AI
  • Applies when: The intended purpose falls within a use case listed in Annex III.
  • Applies when: Classification follows Article 6(2).
  • Unless: A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
Article 10: data and data governance
  • Applies when: The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data.
  • Unless: For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions).
Article 11: technical documentation
  • Applies when: The provider places a high-risk AI system on the market or puts it into service.
  • Unless: Small providers (SMEs) may provide the documentation in the simplified form established by the Commission.
Article 12: logging and traceability
  • Applies when: The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control.
  • Unless: The retention period may be limited by Union or national law, including data protection.
Article 13: transparency towards deployers
  • Applies when: The provider supplies a high-risk system; the deployer uses it according to the instructions.
  • Unless: The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed.
Article 14: human oversight
  • Applies when: The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons.
  • Unless: For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there.
Article 15: accuracy, robustness and cybersecurity
  • Applies when: The provider places a high-risk AI system on the market or puts it into service.
  • Unless: Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.
Article 16: the twelve duties of a provider of a high-risk AI system
  • Applies when: Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
  • Unless: A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
Article 17: quality management system
  • Applies when: The provider places high-risk AI systems on the market or puts them into service.
  • Unless: Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form.
Article 4: AI literacy
  • Applies when: The organisation is a provider or deployer of an AI system within scope.
  • Unless: The provision does not require a specific individual level to be guaranteed.
Article 5: prohibited practices
  • Applies when: Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
  • Unless: The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
Article 50: transparency
  • Applies when: An AI system is intended to interact directly with natural persons.
  • Applies when: The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario.
  • Unless: The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context.
  • Unless: Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026.
Article 60: testing in real world conditions outside a sandbox
  • Applies when: Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22.
  • Unless: Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level.
Article 72: post-market monitoring
  • Applies when: The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals.
  • Unless: The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes.
Article 73: serious incident reporting
  • Applies when: A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
  • Unless: For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
Article 9: risk management system
  • Applies when: The system is high-risk under Article 6 and the provider places it on the market or puts it into service.
  • Unless: Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
Articles 43-49: conformity assessment, CE and registration
  • Applies when: The provider places a high-risk system on the market; public deployers also register their use.
  • Unless: For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.
Articles 22-25: value chain and authorised representative
  • Applies when: A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU.
  • Unless: Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties.

These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.

Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

4 now · 14 later

To record: Article 49(2) registration record for the system assessed as not high-risk · Data governance file · Technical file (Annex IV)

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 6 and Annex III
    • Article 6(2)-(4), Article 49 and Annex III
    • Article 10(1)-(6)
    • Article 11(1)-(3) and Annex IV
    • Article 12, Article 19 and Article 26(6)
    • Article 13(1)-(3)
    • Article 14(1)-(5)
    • Article 15(1)-(5)
    • Article 16(a)-(l)
    • Article 17(1)-(3)
    • Article 5, Article 99(3) and Article 113(a)
    • Article 5(1)(a)-(h)
    • Article 5 read with Article 6 classification order
    • Article 50(1)-(5) and Article 113
    • Article 60(1)-(4), Article 60(9), Article 113
    • Article 72(1)-(4)
    • Article 73(1)-(11)
    • Article 9(1)-(10)
    • Articles 43, 47, 48 and 49
    • Articles 22 and 25
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended Article 113, Article 6(2) and Annex III application date
    • Amended Article 113 application dates
    • Amendment of Article 4; entry into force 27 July 2026
    • Amendment to Article 5 and transition to 2 December 2026
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance
  • Guidelines on Article 50

    European Commission, version final-2026-07-20, checked on

    Locators in this source

    • Final guidelines, scope by Article 50 paragraph
    • Implementation guidance for providers and deployers

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0, schema 1.4.0.

Execution

Record role and classification for each AI system

The boundary is set out in the rules above. The outcome becomes demonstrable when the facts, role, classification, owner and reassessment are recorded for each system. Embed AI guides that inventory and sets up the AI register. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the AI register approach
Does this answer your question?
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist