Skip to main content
Praxikon
Comparisons

Comparison

Article 16 versus Article 23: provider or importer

The difference

Article 16 places the full set of duties on the party that puts the system on the market under its own name or trademark, up to and including the risk management system and the technical documentation. Article 23 places a verification duty on the importer: they have to establish that the provider went through those steps, not redesign or reassess the system themselves.

The official source remains authoritative. This is general interpretation and not legal advice about your situation.

The fields side by side

Every row comes from the objects themselves. Where a field is empty, it says so; we do not fill in an assumption where the source is silent.

Status

Article 16, provider
Upcoming
Article 23, importer
Upcoming

Applies from

Article 16, provider
2 December 2027
Article 23, importer
2 December 2027

Who carries the duty

Article 16, provider
Provider of an AI system
Article 23, importer
Importer

Who is affected

Article 16, provider
Not recorded
Article 23, importer
Not recorded

Who supervises

Article 16, provider
Not recorded
Article 23, importer
Market surveillance authority

When this applies

Article 16, provider
Applies to providers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027. For systems embedded as a safety component in products covered by the Annex I harmonisation legislation (Article 6(1)) the date is 2 August 2028.
Article 23, importer
Applies to importers of high-risk AI systems. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028.

Exceptions

Article 16, provider
A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
Article 23, importer
If you put your own name or trade mark on the system, substantially modify it, or change the intended purpose so that it becomes high-risk, Article 25(1) treats you as a provider and the duties of Article 16 apply instead of those of Article 23.

First actions

Article 16, provider
Assign an internal owner and a date to each point of Article 16
Article 23, importer
Run the four verifications of Article 23(1) before importing

Evidence that belongs with it

Article 16, provider
Provider dossier per high-risk AI system
Article 23, importer
Importer dossier with ten-year retention

Control

Article 16, provider
Release gate before placing on the market
Article 23, importer
Stop rule and notification route on doubts about conformity

Version and review status

Article 16, provider
v1.0.0, placed against the official source
Article 23, importer
v1.0.0, placed against the official source

Official sources and locators

Per side, the provisions the statements above rest on.

Article 16, provider

Article 23, importer

Referring to these two objects

Each side has its own stable identifier, version and hash. Take them separately; you cite a comparison by citing the two objects.

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 16: the twelve duties of a provider of a high-risk AI system",
praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275,
https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0 (sha256 69744054)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-16-provider-obligations-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 16: the twelve duties of a provider of a high-risk AI system},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-16-provider-obligations},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275},
  url          = {https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-16-provider-obligations@1.0.0",
    "type": "dataset",
    "title": "Article 16: the twelve duties of a provider of a high-risk AI system",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-16-provider-obligations",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-16-provider-obligations",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 69744054b2105841ae2447d2d83216af48b1ea7983b7bbeeb9330a5d40469275; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-16-provider-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 23: obligations of importers",
praxikon:eu:ai-act:obligation:article-23-importer-obligations@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0),
effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 1a3e0958b87d5b96c66eb024898d343fb1a7f570e3fcffbfe56521278f17b278,
https://www.praxikon.com/en/verplichtingen/article-23-importer-obligations
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-23-importer-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-24)

Short form

praxikon:eu:ai-act:obligation:article-23-importer-obligations@1.0.0 (sha256 1a3e0958)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-23-importer-obligations-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 23: obligations of importers},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-23-importer-obligations},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
  note         = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 1a3e0958b87d5b96c66eb024898d343fb1a7f570e3fcffbfe56521278f17b278},
  url          = {https://www.praxikon.com/en/verplichtingen/article-23-importer-obligations},
  urldate      = {2026-08-24},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-23-importer-obligations@1.0.0",
    "type": "dataset",
    "title": "Article 23: obligations of importers",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-23-importer-obligations",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-23-importer-obligations",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          8,
          24
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 1a3e0958b87d5b96c66eb024898d343fb1a7f570e3fcffbfe56521278f17b278; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-23-importer-obligations&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Execution

Get from your supplier what you have to be able to show yourself

When the duty sits with another party in the chain, you need information from that party that you cannot produce yourself. Praxikon does not carry that out; Embed AI translates it into what belongs in the contract and in the supplier documentation.

See the Embed AI approach

Unsure about your role itself rather than the duties that come with it? Work out whether you are a provider or a deployer