Skip to main content
Praxikon
All answers

Direct answer

When are you a provider under the AI Act?

33 obligations under the AI Act bear on this, of which 14 apply today.

First step: Map every system to a point of Annex III.

Whether you are a provider is not a matter of what you call yourself but of what you do with the system. Across the 33 obligations there are 96 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: provider of an ai system.

The conclusion and your first steps

This applies now

Coming up

What decides whether this is about you

Annex III: the eight areas separately
  • Applies when: Applies where the intended purpose of the AI system falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers management, access to essential private and public services, law enforcement, migration and border control management, or administration of justice and democratic processes.
  • Applies when: Classification follows Article 6(2). For points 1, 6 and 7 the text adds the condition that the use is permitted under relevant Union or national law. We read that condition as meaning that a prohibition under Article 5 comes before the question whether the system is high-risk; that is our reading and not the literal text, which states the condition without naming the order.
  • Applies when: The duty rests on the provider, but the role can shift. Under Article 25(1) a distributor, importer, deployer or third party becomes a provider itself where it puts its name or trademark on the system, makes a substantial modification, or changes the intended purpose such that the system becomes high-risk under Article 6. From that moment it carries the mapping to a point of Annex III itself.
  • Unless: Article 6(3) takes a system listed in Annex III back outside high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four conditions is met: the system performs a narrow procedural task, it improves the result of a previously completed human activity, it detects decision making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment without proper human review, or it performs a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III. A system that performs profiling of natural persons is always high-risk.
  • Unless: The derogation is not free. Article 6(4) requires a provider who considers that a system referred to in Annex III is not high-risk to document its assessment before the system is placed on the market or put into service, subjects that provider to the registration obligation in Article 49(2), and requires it to provide the documentation to national competent authorities on request.
Annex III: high-risk AI
  • Applies when: The intended purpose falls within a use case listed in Annex III.
  • Applies when: Classification follows Article 6(2).
  • Unless: A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
Article 10: data and data governance
  • Applies when: The high-risk system is trained with data; the provider composes the datasets, the deployer controls relevant input data.
  • Unless: For special categories of personal data the strict exception of Article 10(5) applies (bias detection and correction under conditions).
Article 11: technical documentation
  • Applies when: The provider places a high-risk AI system on the market or puts it into service.
  • Unless: Small providers (SMEs) may provide the documentation in the simplified form established by the Commission.
Article 111(2): legacy high-risk systems and the 2 August 2030 date
  • Applies when: The transitional rule is without prejudice to the application of Article 5, as referred to in Article 113, third paragraph, point (a). A prohibited practice remains prohibited, regardless of when the system was placed on the market or put into service and regardless of whether the design has changed.
  • Applies when: The transitional rule concerns the high-risk requirements of Chapter III and is not an exemption from the whole Regulation. Article 4 has applied since 2 February 2025 irrespective of when a system reached the market, and Article 50 has applied to all systems in scope since 2 August 2026. The paragraph 4 added by the Digital Omnibus confirms this: it gives legacy generative systems a short extra period for Article 50(2), which would make no sense if Article 50 did not reach them.
  • Applies when: Applies to operators of high-risk AI systems placed on the market or put into service before the date of application of Chapter III referred to in Article 113, other than the systems referred to in paragraph 1 that are components of the large-scale IT systems listed in Annex X. That date is 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. For that group the high-risk requirements bite only once the systems are subject to significant changes in their designs as from that date.
  • Applies when: The grace period runs per type and model, not per unit. If at least one individual unit of the type and model was lawfully placed on the market or put into service before the cut off date, other units of the same type and model are covered too and may be offered without additional obligations, requirements or additional certification, as long as the design remains unchanged. The decisive date is the one on which the first unit of that type and model was placed on the market or put into service in the Union.
  • Applies when: Applies independently to providers and deployers of high-risk AI systems intended to be used by public authorities. They must in any case take the necessary steps to comply with the requirements and obligations of the Regulation by 2 August 2030, even where the design remains unchanged.
  • Unless: Systems that are components of the large-scale IT systems established by the legal acts listed in Annex X fall not under paragraph 2 but under paragraph 1. Paragraph 1 was not amended by the Digital Omnibus and keeps its own cut off: placed on the market or put into service before 2 August 2027, with compliance by 31 December 2030.
Article 12: logging and traceability
  • Applies when: The system is high-risk; the provider designs the logging, provider and deployer retain the logs under their control.
  • Unless: The retention period may be limited by Union or national law, including data protection.
Article 13: transparency towards deployers
  • Applies when: The provider supplies a high-risk system; the deployer uses it according to the instructions.
  • Unless: The level of detail may match the intended deployer’s knowledge; trade secrets need not be disclosed.
Article 14: human oversight
  • Applies when: The system is high-risk; the provider builds in oversight measures, the deployer assigns oversight to competent persons.
  • Unless: For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there.
Article 15: accuracy, robustness and cybersecurity
  • Applies when: The provider places a high-risk AI system on the market or puts it into service.
  • Unless: Systems that continue learning after deployment carry additional requirements to control feedback loops and drift.
Article 16: the twelve duties of a provider of a high-risk AI system
  • Applies when: Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
  • Unless: A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
Article 17: quality management system
  • Applies when: The provider places high-risk AI systems on the market or puts them into service.
  • Unless: Providers already under sectoral quality regimes may integrate the AI elements into that existing system; SMEs may implement elements in simplified form.
Article 18: documentation keeping
  • Applies when: Applies to the provider of a high-risk AI system. The period ends ten years after the system has been placed on the market or put into service.
  • Applies when: Where the provider is a financial institution subject to requirements regarding internal governance, arrangements or processes under Union financial services law, it maintains the technical documentation of point (a) as part of the documentation it already keeps under that law. That is not an exemption from the retention duty but an indication of the regime in which it is carried out for that one component. Paragraph 3 does not mention points (b) to (e).
Article 20: corrective actions and duty of information
  • Applies when: Applies to providers of high-risk AI systems as soon as they consider, or have reason to consider, that a system they have placed on the market or put into service is not in conformity with this Regulation. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
  • Applies when: The second layer in paragraph 2 is added only where the system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk. The investigation of causes and the duty to inform the market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44, then come on top of the corrective actions under paragraph 1.
  • Applies when: The distributor, the importer and the deployer appear here as affected parties, but that is not their only possible position. Anyone who puts their name or trade mark on a high-risk system already placed on the market, who substantially modifies such a system, or who changes the intended purpose of a system not classified as high-risk so that it becomes high-risk, is considered a provider under Article 25(1) and is subject to the obligations of Article 16. Point (j) of that Article routes straight to Article 20, so this provision then becomes a duty of their own rather than a notification arriving from someone else. In the trade mark case this applies without prejudice to contractual arrangements allocating the obligations otherwise.
  • Unless: Article 20 is by definition about systems already placed on the market or put into service, and that is exactly the group covered by the transitional rule of Article 111(2). That provision was replaced by Article 1, point (39)(a), of Regulation (EU) 2026/1744 and now reads: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation applies to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of that Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The cut-off is therefore no longer a fixed date in paragraph 2: the date of 2 August 2026 that stood there until that amendment has been removed, and the amended paragraph names no date of its own. The carve-out in paragraph 1 covers systems that are components of the large-scale IT systems listed in Annex X; paragraph 1 was not amended and keeps a cut-off of its own. For systems intended to be used by public authorities the reprieve in paragraph 2 does not hold: there, compliance with the requirements and obligations is due by 2 August 2030 in any event. Which date of application of Chapter III is the cut-off is an open point: the object on Article 111 reads it as route dependent, so 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route, and marks that reading expressly as preliminary. That question is carried there, not here.
Article 21: cooperation with competent authorities
  • Applies when: Applies to providers of high-risk AI systems as soon as a competent authority makes a reasoned request. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems that are high-risk under Article 6(1) and relate to products covered by Annex I, Section A, the date is 2 August 2028. For products covered by Annex I, Section B, Article 21 does not apply at all: amended Article 2(2) makes only Article 6(1), Article 60a and Articles 102 to 112 applicable there, and Article 21 is not on that list. That is not a corner case, because the Machinery Regulation (EU) 2023/1230 has been moved from Section A to Section B. Note also the new Article 2(13): for systems under Annex I, Section A, the Commission may limit the application of Articles 17 to 25, and therefore of Article 21, by delegated act.
  • Applies when: For systems already running, the amended Article 111(2) applies: without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), the Regulation applies to operators of high-risk AI systems, other than those referred to in Article 111(1), placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. The reference date is therefore no longer 2 August 2026 but whichever date applies to the system: 2 December 2027 for the Annex III route and 2 August 2028 for the Annex I route. For systems intended to be used by public authorities the date of 2 August 2030 applies in any case.
  • Applies when: What the authority obtains pursuant to this Article is treated in accordance with the confidentiality obligations of Article 78. That is not a limit on the duty to supply and therefore not an exception: it is how what you supplied is handled on the receiving side.
  • Unless: Paragraph 2 carries two limits, not one. Access to the automatically generated logs applies "as applicable", and it applies "to the extent such logs are under their control". Logs held solely by the deployer therefore fall outside what the provider can supply under this Article; the deployer keeps those logs itself under Article 26(6).
Article 4: AI literacy
  • Applies when: The organisation is a provider or deployer of an AI system within scope.
  • Unless: The provision does not require a specific individual level to be guaranteed.
Articles 40 to 42: standards, common specifications and presumption of conformity
  • Applies when: The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal.
  • Applies when: The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route.
  • Unless: A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements.
  • Unless: Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis.
Article 49: registration in the EU database before the system reaches the market
  • Applies when: Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it.
  • Applies when: Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3).
  • Applies when: Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III.
  • Applies when: Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used.
  • Unless: This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database.
Article 4a: legal basis for bias testing with special categories of personal data
  • Applies when: Paragraph 1 is open only to the provider of a high-risk AI system, and only to the extent that the processing is strictly necessary to detect and correct bias in accordance with Article 10(2), points (f) and (g). The deployer cannot rely on this paragraph, not even for a high-risk system; for the deployer the route runs through paragraph 2.
  • Applies when: Paragraph 2 is open to providers and deployers of other AI systems and models and to deployers of high-risk AI systems, but carries its own substantive threshold: the processing must be strictly necessary in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations. Bias without one of those consequences falls outside it.
  • Applies when: The six conditions in paragraph 1 are cumulative and, through paragraph 2, point (b), apply to the wider circle as well: (a) other data, including synthetic or anonymised data, demonstrably do not suffice; (b) technical limitations on re-use apply plus state of the art security and privacy preserving measures, including pseudonymisation; (c) there is strict access control with documentation and confidentiality; (d) the data are not transmitted, transferred or otherwise accessed by other parties; (e) they are deleted once the bias has been corrected or the retention period ends, whichever comes first; (f) the record of processing activities states why the processing was strictly necessary and why the objective could not be achieved with other data.
  • Unless: Paragraph 2 closes by providing that it creates no obligation to carry out bias detection and correction. Article 4a is therefore a basis and not an instruction: without carrying out such processing there is nothing to comply with under this article, there is no date by which anything must be done, and outside the purpose of bias detection and correction it grants no room at all.
Article 5: prohibited practices
  • Applies when: Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
  • Unless: The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
Article 50: transparency
  • Applies when: An AI system is intended to interact directly with natural persons.
  • Applies when: The system generates or manipulates synthetic audio, image, video or text, or the use concerns a specifically listed deployer scenario.
  • Unless: The direct-interaction disclosure is not required where this is obvious to a reasonably well-informed, observant and circumspect person, considering circumstances and context.
  • Unless: Only Article 50(2) has a transition until 2 December 2026 for systems placed on the market before 2 August 2026.
Article 6(1): the product route to high risk
  • Applies when: The AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I. Whether the system is placed on the market independently of that product is irrelevant.
  • Applies when: That product, or the AI system as a product itself, is required under that same harmonisation legislation to undergo a third-party conformity assessment with a view to its placing on the market or putting into service. Both conditions must be fulfilled together.
  • Unless: Article 6(1a), inserted by Regulation (EU) 2026/1744, provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back as soon as failure or malfunctioning would endanger health and safety.
  • Unless: Article 6(1c), as inserted, provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b).
Article 6(1a) to (1c): the tightened classification route
  • Applies when: Applies where it must be determined whether an AI system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and whether that product is required to undergo a third-party conformity assessment. Because paragraph 1a writes itself for the purposes of this Regulation, the delimitation also bears on Annex III, point 2, where the notion of safety component is used for critical digital infrastructure, road traffic and the supply of water, gas, heating or electricity.
  • Applies when: For the consequences under Chapter III only Annex I, Section A, counts. For products under Section B, including machinery since Regulation (EU) 2023/1230 was moved there, the amended Article 2(2) means that only Article 6(1), Article 60a and Articles 102 to 112 apply.
  • Unless: Paragraph 1a provides that AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components. Paragraph 1b takes that exclusion back: AI systems the failure or malfunctioning of which would endanger health and safety do qualify as safety components.
  • Unless: Paragraph 1c provides that a product required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered as fulfilling the condition in paragraph 1, point (b).
Article 60: testing in real world conditions outside a sandbox
  • Applies when: Applies where you are a provider or prospective provider of an Annex III high-risk AI system and you want to test it in real world conditions outside an AI regulatory sandbox, before placing it on the market or putting it into service. If you are established outside the Union, Article 60(4), point (d), requires you to appoint a legal representative established in the Union; that is a different figure from the authorised representative under Article 22.
  • Unless: Article 60(1), third subparagraph, leaves Union and national law on real-world testing of high-risk systems related to products under the Annex I harmonisation legislation unaffected. Article 60(4), point (i), contains a law enforcement carve-out: where seeking informed consent would prevent the system from being tested, testing may proceed without consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test. For the systems referred to in Annex III, points 1, 6 and 7, in law enforcement, migration, asylum and border control, registration runs through the secure non-public section of the EU database under Article 49(4), point (d). For the systems referred to in Annex III, point 2, Article 49(5) requires registration at national level.
Article 61: informed consent of test subjects for testing in real world conditions
  • Applies when: Applies for the purpose of testing in real world conditions under Article 60, that is where you are a provider or prospective provider of a high-risk AI system listed in Annex III and you test that system in real world conditions outside an AI regulatory sandbox. Article 60(4), point (i), makes informed consent in accordance with Article 61 one of the cumulative conditions under which such testing is allowed. Consent is obtained per subject prior to their participation. Article 61 sits in Chapter VI, which is named in none of the three exceptions in the third paragraph of Article 113; the general date of application in the second paragraph therefore governs, 2 August 2026.
  • Applies when: If under Article 60(2) you test in partnership with one or more deployers or prospective deployers, the condition stays with you as the provider, even where that party is the one in contact with the subject. Article 60(4), point (h), requires you and that party to conclude an agreement specifying your tasks and responsibilities; that is where you record who informs, who obtains the consent and who keeps the file.
  • Unless: The only exception sits not in Article 61 but in Article 60(4), point (i): in the case of law enforcement, where seeking informed consent would prevent the AI system from being tested in real world conditions, testing may proceed without that consent, provided the testing and its outcome have no negative effect on the subjects and their personal data are deleted after the test is performed. Outside that context there is no exception to consent; Article 61 contains none of its own.
Article 71: EU database for high-risk AI systems listed in Annex III
  • Applies when: Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use.
  • Unless: Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database.
  • Unless: Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there.
  • Unless: Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5).
Article 72: post-market monitoring
  • Applies when: The provider has a high-risk system on the market; deployers supply the real-world data via monitoring and signals.
  • Unless: The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes.
Article 73: serious incident reporting
  • Applies when: A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
  • Unless: For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
Article 75(1a) and (1e): reporting to and assessment by the AI Office
  • Applies when: Applies to providers of AI systems that fall under the competence of the AI Office pursuant to Article 75(1) and that are classified as high-risk. The replaced paragraph 1 carries two independent routes, and the four carve-outs at (i) to (iv) sit inside point (a) alone. Along point (a) Annex I systems fall outside the competence, as do point 2 of Annex III and point 8 as regards the administration of justice; point 8(b), on influencing elections and referenda, is not carved out. Point (b) is a route of its own: a system that constitutes, or is integrated into, a designated very large online platform or very large online search engine falls under the competence of the AI Office even where one of the carve-outs in point (a) applies. Anyone testing point (a) alone places such a system outside this obligation wrongly. Those duties start to apply when Chapter III, Sections 1 to 3, becomes applicable, and that date depends on the route: 2 December 2027 for the route of Article 6(2) and Annex III, and 2 August 2028 for the route of Article 6(1) and Annex I, which point (b) can bring into view. The deadline_at field carries the earlier of the two.
Article 75: market surveillance, mutual assistance and the powers of the AI Office
  • Applies when: Applies to AI systems based on a general-purpose AI model where the model and the system are developed by the same provider or by providers forming part of the same undertaking, and to AI systems that constitute or are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065. The exclusive competence applies to the providers of those systems, and to deployers only where they are also the provider or form part of the same undertaking as the provider.
  • Applies when: The allocation of competence itself operates from 2 August 2026, because Article 75 sits in Chapter IX. It covers the obligations that apply at that moment, such as the prohibition in Article 5, the transparency duties of Article 50 and the obligations for general-purpose AI models. The two literal duties the amending regulation places on the provider, the reporting route of paragraph 1a and the fees of paragraph 1e, attach to high-risk status and therefore follow 2 December 2027; they sit in the separate object article-75-ai-office-high-risk-duties.
  • Unless: Paragraph 1, point (a) carves four groups out of the exclusive competence of the AI Office: AI systems related to products covered by the Union harmonisation legislation listed in Annex I, systems referred to in point 2 of Annex III, systems provided by law enforcement authorities, border management authorities and financial institutions insofar as they fall under Article 74(6), and systems referred to in point 8 of Annex III as regards the administration of justice. Who is competent instead differs per group and is not always "the market surveillance authority": for financial institutions Article 74(6) points to the national authority responsible for their financial supervision, and for law enforcement, border management and the administration of justice Article 74(8) has the Member State designate either the data protection supervisory authority or another authority under the same conditions. Which body that is per Member State does not follow from the Regulation.
Article 8: compliance with the requirements for high-risk AI systems
  • Applies when: Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision.
  • Applies when: Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing.
  • Applies when: Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing.
  • Unless: The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished.
Article 9: risk management system
  • Applies when: The system is high-risk under Article 6 and the provider places it on the market or puts it into service.
  • Unless: Risks arising only from misuse beyond any reasonably foreseeable use fall outside the mandatory scope.
Articles 43-49: conformity assessment, CE and registration
  • Applies when: The provider places a high-risk system on the market; public deployers also register their use.
  • Unless: For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.
Articles 22-25: value chain and authorised representative
  • Applies when: A high-risk system is supplied, modified, rebranded or placed on the Union market from outside the EU.
  • Unless: Those acting solely as distributor or importer without the Article 25 triggers remain in that lighter role, with their own verification duties.

These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.

Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

14 now · 19 later

Your situation

Whether you are a provider is not a matter of what you call yourself but of what you do with the system. Across the 33 obligations there are 96 conditions and exceptions that decide it. Below they are listed per provision, with the official source.

Role

provider of an AI system

To record: Record of the mapping to a point of Annex III · Article 49(2) registration record for the system assessed as not high-risk · Data governance file

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Annex III, points 1 to 8
    • Article 7(1) and (3)
    • Article 5(1)(f), Article 27(1), Article 86(1), Article 111(2) and Annex III
    • Article 6(2)-(4), Article 25(1), Article 49(2) and Annex III
    • Article 6 and Annex III
    • Article 6(2)-(4), Article 49 and Annex III
    • Article 10(1)-(6)
    • Article 11(1)-(3) and Annex IV
    • Article 12, Article 19 and Article 26(6)
    • Article 13(1)-(3)
    • Article 14(1)-(5)
    • Article 15(1)-(5)
    • Article 16(a)-(l)
    • Article 17(1)-(3)
    • Article 18(1)-(3)
    • Article 20(1)-(2)
    • Article 20(2), Article 73(1)-(2) and Article 79(1)
    • Article 21(1)-(3)
    • Article 12(1); Article 19(1); Article 21(1)-(3); Article 22(3); Article 26(6); Article 74(1); Article 78; Article 99(5)
    • Article 40(1) to (3)
    • Article 41(1) to (3)
    • Article 41(4), (5) and (6)
    • Article 42(1) and (2)
    • Article 10(4); Article 15; Article 43(1); Chapter III, Section 5, and Article 113, second paragraph
    • Article 49(1)-(5)
    • Article 26(1)-(12)
    • Article 5, Article 99(3) and Article 113(a)
    • Article 5(1)(a)-(h)
    • Article 5 read with Article 6 classification order
    • Article 50(1)-(5) and Article 113
    • Article 6(1) and Annex I
    • Article 2(1), point (e), and Article 25(3)
    • Article 113, third paragraph, point (c)
    • Article 6(1)
    • Article 60(1)-(4), Article 60(9), Article 113
    • Article 61(1) and (2)
    • Article 60(2); Article 60(4), points (c), (h) and (i); Article 60(5); Article 113, second paragraph
    • Article 71(1)-(6)
    • Annex VIII, Sections A and C
    • Annex VIII, Section B
    • Article 49(4) and Annex IX
    • Article 60(4), point (c), Article 49(4) and (5)
    • Recital 131
    • Article 72(1)-(4)
    • Article 113, second paragraph
    • Article 73(1)-(11)
    • Article 75(2)-(3)
    • Article 8(1)-(2)
    • Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A
    • Article 9(1)-(10)
    • Articles 43, 47, 48 and 49
    • Articles 22 and 25
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended Article 113, Article 6(2) and Annex III application date
    • Amended Article 113 application dates
    • Amended Article 111(2)
    • New Article 111(4)
    • Recital 39 of Regulation (EU) 2026/1744
    • Article 1, point (40)(b), of Regulation (EU) 2026/1744, replacing Article 113, third paragraph, point (c), of Regulation (EU) 2024/1689
    • Article 1, point (34), amending Article 77; Article 1, point (38)(b), inserting point (da) into Article 99(4)
    • Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)
    • Article 1, point (39)(a), replacing Article 111(2)
    • Article 1, point (2)(a), replacing Article 2(2); Article 1, point (41), amending Annex I
    • Amendment of Article 4; entry into force 27 July 2026
    • Article 1, points (17) and (18), amending Article 40(2) and Article 42
    • Article 1, point 6, inserting Article 4a: Article 4a(1), points (a) to (f), and Article 4a(2), points (a) and (b)
    • Article 1, point 6 (insertion) and point 9 (Article 10 amended, paragraph 5 deleted)
    • Article 1, point 2(b), replacing Article 2(7)
    • Recital 9, Article 4 (entry into force) and Article 1, point 40(a), replacing Article 113, third paragraph, point (a)
    • Amendment to Article 5 and transition to 2 December 2026
    • Article 1, point (19), replacing Article 43(3), third subparagraph
    • Article 1, point (2)(a), replacing Article 2(2)
    • Article 1, point (41), and Article 3, point (1), amending Article 8 of Regulation (EU) 2023/1230
    • Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)
    • Article 1, point (3), inserting Article 2(13)
    • Inserted Article 6(1a)-(1c)
    • Amended Article 3(14)
    • Amended Article 2(2), Article 43(3) and Annex I
    • Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9
    • Recital 22 of Regulation (EU) 2026/1744
    • Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a
    • Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1a) and (1e)
    • Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1)
    • Regulation (EU) 2026/1744, Article 1, point (31), Article 75(1b) to (1d) and (2a)
    • Regulation (EU) 2026/1744, Article 1, point (32), Article 75a
    • Regulation (EU) 2026/1744, Article 1, point (32), Articles 75b, 75c and 75d
    • Regulation (EU) 2026/1744, Article 1, points (31) and (32)
    • Regulation (EU) 2026/1744, Article 1, point (32), Articles 75a and 75c
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance
  • Guidelines on Article 50

    European Commission, version final-2026-07-20, checked on

    Locators in this source

    • Final guidelines, scope by Article 50 paragraph
    • Implementation guidance for providers and deployers
  • CEN-CENELEC JTC 21: European standards under standardisation request M/613

    CEN-CENELEC JTC 21, version work-programme-checked-2026-08-08, checked on

    Locators in this source

    • EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613
    • prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Execution

Record role and classification for each AI system

The boundary is set out in the rules above. The outcome becomes demonstrable when the facts, role, classification, owner and reassessment are recorded for each system. Embed AI guides that inventory and sets up the AI register. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the AI register approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist