Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Active filters
Objects
150 of 315 shown. Pick a type below or narrow with a filter to see the rest.
- ActionUpcomingv1.0.02 relations
Justify the Article 6(3) exception against each individual condition
praxikon:eu:ai-act:action:annex-iii-article-6-3-justification
Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- Actionv1.0.05 relations
Classify the use case and document the outcome
praxikon:eu:ai-act:action:annex-iii-classify
Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- ActionUpcomingv1.0.02 relations
Run the profiling test before invoking the Article 6(3) exception
praxikon:eu:ai-act:action:annex-iii-profiling-test
Establish as the first question whether the system performs profiling of natural persons; if yes, the Article 6(3) route falls away and the system remains high-risk, regardless of the four conditions.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- Actionv1.0.04 relations
Set up data governance per dataset
praxikon:eu:ai-act:action:article-10-data-governance-act
Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
Hangs off: Article 10: data and data governance
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Build the technical file per Annex IV
praxikon:eu:ai-act:action:article-11-technical-documentation-act
Document system description, development process, data, oversight measures, performance and risk management before market placement.
Hangs off: Article 11: technical documentation
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design logging into the system
praxikon:eu:ai-act:action:article-12-logging-act
Ensure the system automatically records events relevant to risk identification and post-market monitoring.
Hangs off: Article 12: logging and traceability
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Provide complete instructions for use
praxikon:eu:ai-act:action:article-13-instructions-act
Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design and assign effective human oversight
praxikon:eu:ai-act:action:article-14-human-oversight-act
Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.
Hangs off: Article 14: human oversight
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set and test performance and security levels
praxikon:eu:ai-act:action:article-15-accuracy-robustness-act
Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set up an AI quality management system
praxikon:eu:ai-act:action:article-17-quality-management-act
Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.
Hangs off: Article 17: quality management system
Editorially reviewed | high-risk-requirements
- Actionv1.0.05 relations
Take role- and context-specific AI literacy measures
praxikon:eu:ai-act:action:article-4-measures
Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- ActionApplicablev1.0.03 relations
Determine per role which knowledge is needed to use the specific system responsibly
praxikon:eu:ai-act:action:article-4-role-needs-matrix
Map roles against the AI systems they use and record per combination what a person must be able to judge: what the system does, where it fails, who it is applied to, and when to intervene or escalate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- ActionApplicablev1.0.03 relations
Deliver instruction at the moment a new tool or a new employee arrives
praxikon:eu:ai-act:action:article-4-tool-and-onboarding-instruction
Attach the literacy measure to two fixed moments in existing processes: the rollout of a new AI tool and the onboarding of anyone gaining access to an existing tool.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Actionv1.0.04 relations
Screen every use case against Article 5 first
praxikon:eu:ai-act:action:article-5-screen
Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
Hangs off: Article 5: prohibited practices
Editorially reviewed | prohibited-practices
- Actionv1.0.05 relations
Implement the applicable disclosure, marking or label
praxikon:eu:ai-act:action:article-50-disclosure
First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- ActionApplicablev1.0.03 relations
Test every system in your AI register against the five Article 50 scenarios
praxikon:eu:ai-act:action:article-50-scenario-triage
For each AI system, walk through the distinct Article 50 scenarios (direct interaction, synthetic output, emotion recognition or biometric categorisation, deep fake, published text on matters of public interest) and record per paragraph whether it applies, does not apply or falls under an exception, with the reason.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- ActionApplicablev1.0.04 relations
Apply to a sandbox and agree the sandbox plan
praxikon:eu:ai-act:action:article-57-sandbox-application-and-plan
Apply to the competent authority, agree a specific sandbox plan, and record which uncertainty about the Regulation you want resolved inside the sandbox.
Hangs off: Article 57: AI regulatory sandboxes
Editorially reviewed | innovation
- ActionApplicablev1.0.05 relations
Submit the testing plan, obtain approval and register the test
praxikon:eu:ai-act:action:article-60-testing-plan-and-authorisation
Draw up a real-world testing plan, submit it to the market surveillance authority, obtain approval, register the test with a Union-wide unique single identification number, and record the division of roles with your deployer.
Hangs off: Article 60: testing in real world conditions outside a sandbox
Editorially reviewed | innovation
- Actionv1.0.04 relations
Draw up a post-market monitoring plan
praxikon:eu:ai-act:action:article-72-post-market-monitoring-act
Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | post-market
- Actionv1.0.04 relations
Set up an incident process with reporting routes
praxikon:eu:ai-act:action:article-73-incident-reporting-act
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | post-market
- Actionv1.0.03 relations
Set up an iterative risk management process
praxikon:eu:ai-act:action:article-9-risk-management-act
Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.
Hangs off: Article 9: risk management system
Editorially reviewed | high-risk-requirements
- ActionUpcomingv1.0.03 relations
Assign an internal owner and a date to each point of Article 16
praxikon:eu:ai-act:action:assign-article-16-provider-duties
Translate the twelve points (a) to (l) into twelve named owners with a start date, so that no point falls between product management, quality and legal.
Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Complete the conformity route before market placement
praxikon:eu:ai-act:action:conformity-ce-registration-act
Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity
- Actionv1.0.04 relations
Assess the value-chain role per system and change
praxikon:eu:ai-act:action:value-chain-representative-act
On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | value-chain
A party that develops or has an AI system developed and places it on the market under its own name.
Editorially reviewed | governance
- ChangeApplicablev1.0.04 relations
The AI Act enters into force
praxikon:eu:ai-act:change:2024-08-01-entry-into-force
The regulation entered into force on 1 August 2024, after which the obligations followed in phases.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | timeline
- ChangeApplicablev1.0.04 relations
Prohibited practices and AI literacy apply
praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable
Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | ai-literacy, timeline
- ChangeGuidancev1.0.04 relations
Guidelines on the definition of an AI system
praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines
The Commission draws the line between software that does and does not fall under the regulation.
Hangs off: Annex III: high-risk AI, Article 4: AI literacy
Placed against the official source | scope
- ChangeGuidancev1.0.03 relations
Guidelines on prohibited AI practices
praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines
Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited
- ChangeGuidancev1.0.04 relations
Draft guidelines on high-risk classification
praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines
The Commission explains in consultation when a system falls under Annex I or Annex III.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk
- ChangeGuidancev1.0.03 relations
Transparency Code of Practice published
praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice
A voluntary route to comply with parts of Article 50, in two separately signable sections.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeGuidancev1.0.02 relations
First European AI Act standard approved
praxikon:eu:ai-act:change:2026-07-12-en-18286-approved
EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.
Hangs off: Article 17: quality management system
Placed against the official source | standards
- ChangeGuidancev1.0.03 relations
Final guidelines on Article 50
praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines
The Commission works out the transparency duties and confirms they apply from 2 August 2026.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeIn forcev1.0.05 relations
Annex III core rules moved to 2 December 2027
praxikon:eu:ai-act:change:2026-07-27-annex-iii-date
The amended application date has been binding law since 27 July 2026.
Hangs off: Annex III: high-risk AI
Placed against the official source | high-risk
- ChangeIn forcev1.0.05 relations
Article 4 amended to a duty to take measures
praxikon:eu:ai-act:change:2026-07-27-article-4-amended
Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.
Hangs off: Article 4: AI literacy
Placed against the official source | ai-literacy
- ChangeApplicablev1.0.05 relations
Article 50 is applicable
praxikon:eu:ai-act:change:2026-08-02-article-50-applicable
The transparency duties apply since 2 August 2026.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeUpcomingv1.0.02 relations
Grace period for machine-readable marking ends
praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends
Systems placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.
Hangs off: Article 50: transparency
Placed against the official source | timeline, transparency
- ChangeUpcomingv1.0.02 relations
New prohibitions require technical safeguards
praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards
The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited, timeline
- ChangeUpcomingv1.0.03 relations
High-risk AI embedded in regulated products
praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable
AI as a safety component of products under Annex I follows on 2 August 2028.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk, timeline
- Controlv1.0.04 relations
Reclassification on purpose or context change
praxikon:eu:ai-act:control:annex-iii-change-trigger
Reopen classification when intended purpose, use context or system functionality changes materially.
Hangs off: Annex III: high-risk AI
Editorially reviewed | control, high-risk
- ControlUpcomingv1.0.03 relations
Procurement gate: no signature without a completed classification answer
praxikon:eu:ai-act:control:annex-iii-procurement-gate
Block signature of an AI contract until the supplier has answered in writing which Annex III point the intended purpose falls under, whether it relies on Article 6(3), and whether the system profiles natural persons.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- Controlv1.0.04 relations
Data check before retraining
praxikon:eu:ai-act:control:article-10-data-governance-control
Repeat the data quality assessment before every retraining or dataset change.
Hangs off: Article 10: data and data governance
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Documentation update on every release
praxikon:eu:ai-act:control:article-11-technical-documentation-control
Update the file before every release and retain earlier versions traceably.
Hangs off: Article 11: technical documentation
Editorially reviewed | control, high-risk-requirements
Periodically verify that logging works, is complete and is retained according to the regime.
Hangs off: Article 12: logging and traceability
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Instructions check at deployment
praxikon:eu:ai-act:control:article-13-instructions-control
At every deployment and update, verify instructions are present, current and internally translated.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Oversight test before go-live
praxikon:eu:ai-act:control:article-14-human-oversight-control
Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.
Hangs off: Article 14: human oversight
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Performance monitoring in use
praxikon:eu:ai-act:control:article-15-accuracy-robustness-control
Monitor whether the system stays within declared levels in production and escalate on deviation.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | control, high-risk-requirements
- ControlUpcomingv1.0.03 relations
Release gate before placing on the market
praxikon:eu:ai-act:control:article-16-pre-market-release-gate
A hard block in your release or delivery process: no delivery without a completed conformity assessment, a signed EU declaration of conformity, an affixed CE marking and a completed registration.
Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system
Editorially reviewed | high-risk-requirements
- Controlv1.0.03 relations
Internal audit cycle
praxikon:eu:ai-act:control:article-17-quality-management-control
Periodically audit whether practice follows the described system and record deviations and improvements.
Hangs off: Article 17: quality management system
Editorially reviewed | control, high-risk-requirements
- ControlApplicablev1.0.03 relations
Coverage reconciliation: every person with AI access appears in the register
praxikon:eu:ai-act:control:article-4-coverage-reconciliation
Periodically reconcile the list of accounts and licences with access to AI systems against the participation and instruction register, and clear the gap list with an owner and a deadline.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Controlv1.0.04 relations
Periodic role and context review
praxikon:eu:ai-act:control:article-4-periodic-review
Check when systems, roles or risks change whether the selected measures remain appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, control
- Controlv1.0.04 relations
Article 5 gate at intake and change
praxikon:eu:ai-act:control:article-5-intake-gate
Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.
Hangs off: Article 5: prohibited practices
Editorially reviewed | control, prohibited-practices
- ControlApplicablev1.0.03 relations
Quarterly sampling of live disclosures and markings in production
praxikon:eu:ai-act:control:article-50-production-sampling
Each quarter, sample the systems carrying an Article 50 scenario and verify in the production environment that the disclosure still appears and the marking is still present in the actual output, recording finding, owner and remediation deadline.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- Controlv1.0.04 relations
Pre-release transparency check
praxikon:eu:ai-act:control:article-50-release-check
Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.
Hangs off: Article 50: transparency
Editorially reviewed | control, transparency
- ControlApplicablev1.0.03 relations
Supervision inside the sandbox and the conditional fine shield
praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield
The authority retains its supervisory and corrective powers and can suspend your testing or participation. If you stay within the plan and follow the guidance in good faith, authorities impose no administrative fines for infringements of this Regulation.
Hangs off: Article 57: AI regulatory sandboxes
Editorially reviewed | innovation
- ControlApplicablev1.0.04 relations
Oversight during the test, incident reporting and recall procedure
praxikon:eu:ai-act:control:article-60-oversight-and-incident-response
The market surveillance authority may inspect unannounced. On a serious incident you report, take immediate mitigation or suspend, and you must have a procedure in place in advance for prompt recall of the system.
Hangs off: Article 60: testing in real world conditions outside a sandbox
Editorially reviewed | innovation
- Controlv1.0.04 relations
Signal-to-action loop
praxikon:eu:ai-act:control:article-72-post-market-monitoring-control
Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | control, post-market
- Controlv1.0.04 relations
Incident drill and deadline watch
praxikon:eu:ai-act:control:article-73-incident-reporting-control
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | control, post-market
- Controlv1.0.03 relations
Reassessment on every material change
praxikon:eu:ai-act:control:article-9-risk-management-control
Reopen the risk management process on changes in purpose, data, model or use context and before every release.
Hangs off: Article 9: risk management system
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Reassessment on substantial modification
praxikon:eu:ai-act:control:conformity-ce-registration-control
Rerun the conformity route whenever the system is substantially modified.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, control
- Controlv1.0.04 relations
Role reassessment on every change
praxikon:eu:ai-act:control:value-chain-representative-control
Repeat the role assessment on every rebranding, modification or new use of an existing system.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | control, value-chain
The role carrying the heaviest obligations, and the role organisations most often end up in by accident.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Notified body
praxikon:eu:ai-act:definition:definitie-aangemelde-instantie
A conformity assessment body notified in accordance with this regulation and other relevant Union harmonisation legislation. Only notified bodies may carry out the external assessments under the AI Act.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Notifying authority
praxikon:eu:ai-act:definition:definitie-aanmeldende-autoriteit
The national authority responsible for setting up and carrying out the procedures for assessing, designating and notifying conformity assessment bodies, and for monitoring them.
Placed against the official source | definitions
Not a standalone authority but a function within the European Commission. For general-purpose AI models the AI Office is your supervisor; for ordinary AI systems it is not.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
AI literacy
praxikon:eu:ai-act:definition:definitie-ai-geletterdheid
Skills, knowledge and understanding that enable providers, deployers and affected persons to deploy AI systems in an informed way and to become aware of the opportunities, risks and possible harm of AI.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
General-purpose AI model (GPAI model)
praxikon:eu:ai-act:definition:definitie-ai-model-voor-algemene-doeleinden
The model is not the system, and that distinction determines which chapter of obligations applies to you.
Placed against the official source | definitions
The gateway definition of the Regulation's system track: if your application falls outside it, the obligations for AI systems do not apply. General-purpose AI models run on a separate track under Article 3(63), with their own obligations in Article 53.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
AI regulatory sandbox
praxikon:eu:ai-act:definition:definitie-ai-testomgeving-voor-regelgeving
A controlled framework set up by a competent authority in which you may temporarily develop, train, validate and test an innovative AI system under regulatory supervision, following a sandbox plan.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Intended purpose
praxikon:eu:ai-act:definition:definitie-beoogd-doel
The use set by the provider on which the entire risk classification and assessment rest.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Special categories of personal data
praxikon:eu:ai-act:definition:definitie-bijzondere-categorieen-persoonsgegevens
The sensitive data categories from the GDPR and related European rules, imported here because the AI Act attaches both a prohibition and a narrow exception to them.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Biometric data
praxikon:eu:ai-act:definition:definitie-biometrische-gegevens
The AI Act uses its own, broader wording than the GDPR, and that difference decides whether you land in Annex III or Article 5.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
Biometric identification
praxikon:eu:ai-act:definition:definitie-biometrische-identificatie
A one-to-many comparison against a database, to be distinguished from the one-to-one verification of point 36.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Post-remote biometric identification system
praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-achteraf
The residual category: any remote identification that is not real-time. Not prohibited, but high-risk, and subject to its own authorisation regime in law enforcement.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Real-time remote biometric identification system
praxikon:eu:ai-act:definition:definitie-biometrische-identificatie-op-afstand-in-real-time
Remote identification where capture, comparison and identification happen without significant delay. The legislator explicitly closed the escape route of an artificial delay.
Placed against the official source | definitions
The marking by which a provider indicates that an AI system conforms to the requirements of Chapter III, Section 2 and to other applicable Union harmonisation legislation providing for its affixing.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Conformity assessment
praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordeling
The process of demonstrating that a high-risk AI system meets the requirements of Chapter III, Section 2. It is the evidence step for high-risk systems, not for all AI.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Conformity assessment body
praxikon:eu:ai-act:definition:definitie-conformiteitsbeoordelingsinstantie
A body that performs third-party conformity assessment activities, including testing, certification and inspection.
Placed against the official source | definitions
Far broader than fake videos of famous people: objects, places, entities and events are covered too.
Placed against the official source | definitions
Any link in the supply chain that makes an AI system available on the Union market and is neither provider nor importer.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Downstream provider
praxikon:eu:ai-act:definition:definitie-downstreamaanbieder
A provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether that model is provided by themselves and vertically integrated or obtained from another entity on a contractual basis.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Emotion recognition system
praxikon:eu:ai-act:definition:definitie-emotieherkenningssysteem
Prohibited in the workplace and in education since 2 February 2025; elsewhere an information duty under Article 50 applies since 2 August 2026.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Serious incident
praxikon:eu:ai-act:definition:definitie-ernstig-incident
Four categories of consequence, one of which is an infringement of fundamental rights protection. No physical harm is needed before a notification duty arises.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Instructions for use
praxikon:eu:ai-act:definition:definitie-gebruiksinstructies
The information the provider supplies to inform the deployer about, in particular, the intended purpose and proper use of an AI system. It is the hinge between the provider's obligations and the deployer's.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Harmonised standard
praxikon:eu:ai-act:definition:definitie-geharmoniseerde-norm
A European standard published in the Official Journal which, if you apply it, produces a presumption of conformity. This is the fastest route to demonstrability, but the AI Act standards are not finished yet.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Informed consent
praxikon:eu:ai-act:definition:definitie-geinformeerde-toestemming
A subject's freely given, specific, unambiguous and voluntary expression of willingness to take part in a particular real-world test, after having been informed of all aspects relevant to that decision.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
Authorised representative
praxikon:eu:ai-act:definition:definitie-gemachtigde
The European point of contact for a provider from outside the Union, valid only on the basis of a written mandate.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Common specification
praxikon:eu:ai-act:definition:definitie-gemeenschappelijke-specificatie
Technical specifications the Commission can adopt itself when harmonised standards are missing or fall short. The fallback that prevents the AI Act from stalling because standardisation is delayed.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Sensitive operational data
praxikon:eu:ai-act:definition:definitie-gevoelige-operationele-gegevens
Operational data around detection and prosecution whose disclosure could harm criminal proceedings. The concept on which the law enforcement exceptions to transparency rest.
Placed against the official source | definitions
Whoever places on the Union market a system bearing the name or trademark of a party established in a third country.
Placed against the official source | definitions
- DefinitionIn forcev1.0.04 relations
Placing on the market
praxikon:eu:ai-act:definition:definitie-in-de-handel-brengen
The first moment a system or model is made available on the Union market, and therefore the trigger for many obligations.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Putting into service
praxikon:eu:ai-act:definition:definitie-in-gebruik-stellen
The concept that brings internally built systems which are never sold within the scope of the Regulation.
Placed against the official source | definitions
The data entering the system or acquired by it, on the basis of which it produces its output. This is the data definition that touches the deployer, not just the provider.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Critical infrastructure
praxikon:eu:ai-act:definition:definitie-kritieke-infrastructuur
Critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557, the CER Directive. The AI Act gives no definition of its own here but aligns with that framework.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Market surveillance authority
praxikon:eu:ai-act:definition:definitie-markttoezichtautoriteit
The national supervisor that enforces the AI Act on the market, with the powers from the general market surveillance regulation. This is the party that comes knocking and requests your documentation.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
National competent authority
praxikon:eu:ai-act:definition:definitie-nationale-bevoegde-autoriteit
An umbrella term for two very different roles: the notifying authority and the market surveillance authority. For EU institutions the European Data Protection Supervisor takes their place.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Non-personal data
praxikon:eu:ai-act:definition:definitie-niet-persoonsgebonden-gegevens
Everything that is not personal data. The category exists to make clear that the AI Act applies even when no personal data is involved.
Placed against the official source | definitions
The umbrella term for all six roles in the chain, and not the person operating the controls.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Personal data
praxikon:eu:ai-act:definition:definitie-persoonsgegevens
The AI Act deliberately creates no separate concept here and refers to the GDPR. Your GDPR records and your AI Act file must therefore cover the same data.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Real-world testing plan
praxikon:eu:ai-act:definition:definitie-plan-voor-testen-onder-reele-omstandigheden
The document in which you set out in advance how you will test an AI system outside the lab: objective, methodology, scope, who takes part, for how long and how you monitor it. Without this plan, testing in real-world conditions is not permitted.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Performance of an AI system
praxikon:eu:ai-act:definition:definitie-prestaties-ai-systeem
The ability of an AI system to achieve its intended purpose. Performance is therefore measured against the intended purpose, not against a standalone technical score.
Placed against the official source | definitions
For the purpose of real-world testing, a subject is a natural person who participates in such a test. The term comes from the testing regime, not from data protection law.
Placed against the official source | definitions
Taken from the GDPR, but decisive in the AI Act: an Annex III system that profiles always remains high-risk.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Law enforcement
praxikon:eu:ai-act:definition:definitie-rechtshandhaving
The activity, not the authority. Work carried out on behalf of a law enforcement authority is covered as well, including where a private party performs it.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Reasonably foreseeable misuse
praxikon:eu:ai-act:definition:definitie-redelijkerwijs-te-voorzien-misbruik
Use outside the intended purpose that the provider could have seen coming, and must therefore anticipate.
Placed against the official source | definitions
Risk is the combination of the probability of harm occurring and the severity of that harm. It is the unit of measurement underpinning the entire regulation, from prohibited practices to the Article 9 risk management system.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Substantial modification
praxikon:eu:ai-act:definition:definitie-substantiele-wijziging
A change to an AI system after it has been placed on the market or put into service that the provider did not foresee in the initial conformity assessment, and that affects compliance with Chapter III, Section 2 or changes the intended purpose.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Biometric categorisation system
praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-categorisering
An AI system that assigns people to categories on the basis of their biometric data. The carve-out for functions ancillary to another commercial service is narrow and is routinely read far too broadly in practice.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Remote biometric identification system
praxikon:eu:ai-act:definition:definitie-systeem-voor-biometrische-identificatie-op-afstand
An AI system that identifies people without their active involvement, typically at a distance, by comparing them against a reference database. The decisive words are "active involvement".
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Post-market monitoring system
praxikon:eu:ai-act:definition:definitie-systeem-voor-monitoring-na-in-de-handel-brengen
The set of activities through which a provider keeps following how its AI system behaves in practice after launch, so it can intervene in time. Conformity is a starting point, not an end point.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
Systemic risk
praxikon:eu:ai-act:definition:definitie-systeemrisico
A concept that applies exclusively to GPAI models, and that is unrelated to the high-risk classification of AI systems.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Recall of an AI system
praxikon:eu:ai-act:definition:definitie-terugroepen-ai-systeem
A measure aimed at returning an AI system to the provider, taking it out of service, or disabling its use, where that system has already been made available to deployers. A recall reaches systems already in use.
Placed against the official source | definitions
Data for an independent evaluation confirming expected performance, which must take place beforehand: before the system is placed on the market or put into service.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Testing in real-world conditions
praxikon:eu:ai-act:definition:definitie-testen-onder-reele-omstandigheden
Temporarily testing an AI system for its intended purpose outside the lab, in order to gather reliable data and assess conformity. It does not count as placing on the market or putting into service, provided you meet all conditions of Article 57 or 60.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Sandbox plan
praxikon:eu:ai-act:definition:definitie-testomgevingsplan
The agreement between you and the supervisory authority about what you will do in an AI regulatory sandbox: objectives, conditions, timeframe, methodology and requirements. It is a two-sided document, not an internal plan.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Training data
praxikon:eu:ai-act:definition:definitie-trainingsdata
Data used to fit the learnable parameters of an AI system. Narrowly defined, and precisely for that reason decisive for who carries which data governance obligation.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
Withdrawal of an AI system
praxikon:eu:ai-act:definition:definitie-uit-de-handel-nemen
A measure aimed at preventing an AI system that is in the supply chain from being made available on the market. It stops distribution, not use by existing customers.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Validation data
praxikon:eu:ai-act:definition:definitie-validatiedata
Data with which you evaluate and tune the trained system, including its non-learnable parameters, to prevent underfitting and overfitting. Meant for tuning, not for producing the final score.
Placed against the official source | definitions
- DefinitionIn forcev1.0.01 relations
Validation data set
praxikon:eu:ai-act:definition:definitie-validatiedataset
The form validation data may take: a separate data set or part of the training data set, as a fixed or variable split. The law leaves the method open, but not the explainability.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Safety component
praxikon:eu:ai-act:definition:definitie-veiligheidscomponent
One of the two routes into the high-risk classification of Article 6(1), and often overlooked outside manufacturing.
Placed against the official source | definitions
- DefinitionIn forcev1.0.03 relations
Widespread infringement
praxikon:eu:ai-act:definition:definitie-wijdverbreide-inbreuk
An act or omission contrary to Union law protecting the interests of individuals that harms the collective interests of persons in at least two other Member States, or that, with common features, occurs concurrently and is committed by the same operator in at least three Member States.
Placed against the official source | definitions
- DefinitionIn forcev1.0.02 relations
Floating-point operation (FLOP)
praxikon:eu:ai-act:definition:definitie-zwevendekommabewerking-flop
Any mathematical operation or assignment involving floating-point numbers. This is the unit of computation with which the Regulation measures the scale of training of a general-purpose AI model.
Placed against the official source | definitions
- EvidenceUpcomingv1.0.02 relations
Article 49(2) registration record for the system assessed as not high-risk
praxikon:eu:ai-act:evidence:annex-iii-article-49-2-registration-record
Proof that the system for which you invoke the Article 6(3) exception is registered as Article 49(2) requires, with the registration number linked to the underlying assessment.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- EvidenceUpcomingv1.0.02 relations
Dated Article 6(3) assessment made before market placement
praxikon:eu:ai-act:evidence:annex-iii-article-6-3-dated-assessment
The written assessment with date, author and rationale, drawn up before the system is placed on the market or put into service, ready to be provided to the national competent authority on request.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- Evidencev1.0.05 relations
Article 6 and Annex III classification record
praxikon:eu:ai-act:evidence:annex-iii-classification-record
Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.
Hangs off: Annex III: high-risk AI
Editorially reviewed | evidence, high-risk
- Evidencev1.0.04 relations
Data governance file
praxikon:eu:ai-act:evidence:article-10-data-governance-record
Record per dataset of origin, choices, assumptions, bias examination and mitigations.
Hangs off: Article 10: data and data governance
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Technical file (Annex IV)
praxikon:eu:ai-act:evidence:article-11-technical-documentation-record
Technical documentation kept current per system version, ready for a supervisor’s request.
Hangs off: Article 11: technical documentation
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Logs and retention regime
praxikon:eu:ai-act:evidence:article-12-logging-record
Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).
Hangs off: Article 12: logging and traceability
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Instructions and interpretation file
praxikon:eu:ai-act:evidence:article-13-instructions-record
The received instructions for use plus their internal translation into work instructions per role.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Oversight file per system
praxikon:eu:ai-act:evidence:article-14-human-oversight-record
Record of oversight measures, appointed persons, their training and the moments of intervention.
Hangs off: Article 14: human oversight
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Performance and security file
praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record
Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | evidence, high-risk-requirements
- EvidenceUpcomingv1.0.03 relations
Provider dossier per high-risk AI system
praxikon:eu:ai-act:evidence:article-16-provider-dossier
One dossier per system holding the documentation, the logs, the EU declaration of conformity and the registration record, in the version that applied at the moment of placing on the market.
Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system
Editorially reviewed | high-risk-requirements
- Evidencev1.0.03 relations
QMS documentation
praxikon:eu:ai-act:evidence:article-17-quality-management-record
The documented quality system with procedures, role assignment and references to the underlying files.
Hangs off: Article 17: quality management system
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.05 relations
AI literacy measures record
praxikon:eu:ai-act:evidence:article-4-measures-record
Versioned record of roles, context, measures, participation or instruction and review moments.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, evidence
- EvidenceApplicablev1.0.03 relations
Register of participation and instruction per person, system and date
praxikon:eu:ai-act:evidence:article-4-participation-register
Internal register showing who received which instruction, working session, training or guidance, for which system, on which date and on what basis, including new joiners, contractors and external staff.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- EvidenceApplicablev1.0.03 relations
Role-system matrix with the established literacy need
praxikon:eu:ai-act:evidence:article-4-role-system-matrix-record
The recorded matrix of roles against AI systems, with the context of use, affected persons, risk and selected measure per combination, dated and with an owner per row.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Evidencev1.0.04 relations
Article 5 screening record
praxikon:eu:ai-act:evidence:article-5-screening-record
A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.
Hangs off: Article 5: prohibited practices
Editorially reviewed | evidence, prohibited-practices
- EvidenceApplicablev1.0.03 relations
Test report per touchpoint: disclosure visible, timely and accessible
praxikon:eu:ai-act:evidence:article-50-disclosure-test-report
Dated record per interface and channel showing that the disclosure appears at the latest at first interaction or exposure, is clear and distinguishable, and passed the accessibility check, with screenshot, version number and tester identity.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- Evidencev1.0.05 relations
Transparency implementation record
praxikon:eu:ai-act:evidence:article-50-implementation-record
Record of scenario, actor, disclosure or marking, technical implementation, test and owner.
Hangs off: Article 50: transparency
Editorially reviewed | evidence, transparency
- EvidenceApplicablev1.0.03 relations
Supplier statement on machine-readable marking of output
praxikon:eu:ai-act:evidence:article-50-supplier-marking-statement
Written statement from the supplier describing which marking is applied to the output, in which machine-readable format, how robust and interoperable the solution is, and whether the marking survives editing or export.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- EvidenceApplicablev1.0.03 relations
Written proof of participation and the exit report
praxikon:eu:ai-act:evidence:article-57-written-proof-and-exit-report
On request, the competent authority provides written proof of the activities successfully carried out, plus an exit report with results and learning outcomes. You can use that documentation in conformity assessment and in market surveillance.
Hangs off: Article 57: AI regulatory sandboxes
Editorially reviewed | innovation
- EvidenceApplicablev1.0.04 relations
Dated and documented informed consent of test subjects
praxikon:eu:ai-act:evidence:article-61-informed-consent-record
For every test subject you record freely given informed consent, covering five prescribed information elements, dated, documented, with a copy provided to the subject.
Hangs off: Article 60: testing in real world conditions outside a sandbox
Editorially reviewed | innovation
- Evidencev1.0.04 relations
Monitoring plan and reports
praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record
The plan as part of the technical documentation plus the periodic analyses and follow-up actions.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | evidence, post-market
- Evidencev1.0.04 relations
Incident register and reports
praxikon:eu:ai-act:evidence:article-73-incident-reporting-record
Record of incidents, analyses, reports to supervisors and corrective measures.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | evidence, post-market
- Evidencev1.0.03 relations
Risk management file
praxikon:eu:ai-act:evidence:article-9-risk-management-record
Versioned record of risk analyses, chosen measures, residual risks and test results per system version.
Hangs off: Article 9: risk management system
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Conformity file
praxikon:eu:ai-act:evidence:conformity-ce-registration-record
The assessment, EU declaration of conformity, CE marking and registration proof, per system version.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, evidence
- Evidencev1.0.04 relations
Value-chain file
praxikon:eu:ai-act:evidence:value-chain-representative-record
Record per system of role, contractual arrangements on information and cooperation, and the appointment of a representative where required.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | evidence, value-chain
- ExampleGuidancev1.0.03 relations
Candidate recommendation that automatically becomes a decision
praxikon:eu:ai-act:example:example-aanbeveling-wordt-besluit-werving
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Hangs off: Annex III: high-risk AI
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
AI toy rewards children for dangerous challenges
praxikon:eu:ai-act:example:example-ai-speelgoed-riskante-challenges
A manufacturer markets an AI-powered toy that keeps children engaged by encouraging increasingly risky challenges, such as climbing furniture, exploring high shelves or handling sharp objects, in exchange for digital rewards and virtual praise.
Hangs off: Article 5: prohibited practices
Placed against the official source | examples
- ExampleEditorialv1.0.03 relations
Facial recognition at access control: the guard behind the camera counts too
praxikon:eu:ai-act:example:example-artikel-4-gezichtsherkenning-toegangscontrole
An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.
Hangs off: Article 4: AI literacy
Placed against the official source | examples
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.