Skip to main content
Praxikon
All obligations
Applicablev1.0.0

Article 49: registration in the EU database before the system reaches the market

The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.

Paragraph 1 provides that, before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71.

Praxikon tracks Article 49: registration in the EU database before the system reaches the market under the EU AI Act, checked against the official source on 6 September 2026, citing the source for every statement.

Status
Applicable
Application date
2 August 2026
Version
1.0.0
Last reviewed
6 September 2026

Review status: placed against the official source (6 September 2026). Next check due by 5 March 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Applicable · 2 August 2026

For whom

  • Authorised representative
  • Deployer
  • Distributor
  • and 2 more

What you do

Register yourself and the system before it reaches the market or is put into service

What you record

Article 49 registration dossier

Official source

Article 49(1)-(5)

Who this is relevant to

When this applies

  • Authorised representative

    The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Distributor

    You are a distributor if you make an AI system available on the Union market without being the provider or the importer. This catches resellers, systems integrators and managed service providers that pass on someone else's AI.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  • Body governed by public law

    A deployer that is a body governed by public law.

  1. 1Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it.
  2. 2Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3).
  3. 3Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III.
  4. 4Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used.

What the official source establishes

Paragraph 4 provides that, for high-risk AI systems referred to in points 1, 6 and 7 of Annex III, in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 of this Article shall be in a secure non-public section of the EU database referred to in Article 71 and shall include only the following information, as applicable, referred to in: (a) Section A, points 1 to 10, of Annex VIII, with the exception of points 6, 8 and 9; (b) Section B, points 1 to 5, and points 8 and 9 of Annex VIII; (c) Section C, points 1 to 3, of Annex VIII; (d) points 1, 2, 3 and 5, of Annex IX. Only the Commission and national authorities referred to in Article 74(8) shall have access to the respective restricted sections of the EU database listed in the first subparagraph of this paragraph. Paragraph 5 provides that high-risk AI systems referred to in point 2 of Annex III shall be registered at national level.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

Two readings existed of the date on this object, and Chef chose between them on 6 September 2026. Article 49 sits in Section 5 of Chapter III, and the third paragraph of Article 113 names a Section of Chapter III twice: point (b) names Section 4 and sets it at 2 August 2025, and point (c) names Sections 1, 2 and 3, with the exception of Article 6(5). Section 5 appears in neither point, nor in point (a) or point (d). Article 49 therefore falls under the general date in the second paragraph, and that is the date this object carries: 2 August 2026. Whoever places an Annex III system on the market today without registering is late, not early. The practical reading is not written away but sits alongside it: the duty only acquires an object once a high-risk AI system exists, and that status arises through Article 6(2) and Annex III on 2 December 2027, the date named in point (c) of the third paragraph as replaced by Article 1, point (40)(b), of Regulation (EU) 2026/1744. That date sits in high_risk_regime_from and the ground of the chosen date in timing_basis. The decision is recorded in data/ai-act/review/decision-d1-application-dates.json.

Paragraph 2 is the most expensive sentence in this article and it is missed systematically. Anyone invoking the Article 6(3) exception for an Annex III system believes they have stepped out of the high-risk regime. That is true for the requirements on the system, but not for the registration: it is precisely that provider that registers itself and that system in the EU database, and does so before it is placed on the market or put into service. The exception is therefore not free. It is paid for in visibility: your name, your system and the Article 6(3) condition you rely on end up in a publicly searchable register, exactly where you thought you would stay out of sight. The mistake that follows is predictable and expensive. An organisation carries out the Article 6(3) assessment properly, documents it, and skips the registration because in its mind that belongs to the high-risk regime. The result is that the database holds no trace of a choice it did in fact make deliberately, and that a regulator meets it as a party that simply failed to register the system. The matching piece of evidence already exists in this knowledge base as the registration record for the Article 6(3) route and hangs off the Annex III obligation; the object below covers registration under paragraphs 1, 3, 4 and 5. Note the sequence, finally. Registration is a precondition, not a notification afterwards. Delivering first and registering later repairs nothing: the moment the duty is breached is the placing on the market itself.

Read Article 49 together with Article 71 and with Article 26(8), because those three form a chain that in practice stalls at its weakest point. Article 71 describes the database and says who fills in which fields; Article 49 says when that must happen and by whom; Article 26(8) turns the result into a procurement condition. That last one is the sharpest: a deployer with the status of a public authority that establishes that the system it intends to use is not registered in the EU database shall not use that system and shall inform the provider or the distributor. For a supplier that means a missing registration is not an administrative backlog but a block on the public market, and the party raising it with you is your own customer. For a public sector organisation it means the check belongs in the procurement process and not at the moment of deployment. Two routes deviate and are forgotten for exactly that reason. The first is paragraph 4: for the areas of law enforcement, migration, asylum and border control management the registration moves into a secure non-public section with a shorter list of fields, and only the Commission and the national authorities referred to in Article 74(8) can look into it. That is not an exemption but a different counter, and whoever reads it as an exemption registers nothing. The second is paragraph 5: the systems in point 2 of Annex III, critical infrastructure, are registered at national level. The Regulation does not say which national register that is, so you answer that question in national law and not here. For a grid operator or a water utility that is the difference between an existing counter and a search that only starts once the system is already running.

What you can do now

Make registration a hard gate in the release process, before the moment of placing on the market or putting into service, not after. Work through three questions per system. First: does the intended purpose fall under a point of Annex III, and if so, under which point. Second: are you relying on Article 6(3). If you are, the registration in paragraph 2 is your duty and not your choice, and you register yourself and that system, together with the condition you rely on. Third: if it concerns point 2 of Annex III, the registration does not go to the EU database but to national level, and you locate that counter before you need the system. If you are a public sector organisation, do not only register yourself but also select the system and register its use, and build the Article 26(8) check into your procurement process: no deployment as long as the provider entry is not in the database, with a written notification to the provider or the distributor where it is missing. If you supply into the areas of law enforcement, migration, asylum or border control management, record that your registration runs through the secure non-public section and which limited fields go into it. Keep, per system, the registration number, the date of registration and the name of the person who submitted it, together with the system version the entry relates to, and update that entry as soon as the intended purpose, the status or the conformity documentation changes.

  1. 01

    Register yourself and the system before it reaches the market or is put into service

    Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used.

What to retain

Article 49 registration dossier

Per system: which Article 49 route was followed, the registration number, the date of registration, the name of the person who submitted it, the system version the entry relates to, and, for the secure section, a statement of which limited fields from Annex VIII and Annex IX were completed.

Control and reassessment

  • Release gate: no market entry without registration

    The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.

Public tools

Conditions and exceptions

  • This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 49(1)-(5)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 6(2)-(4), Article 49 and Annex III

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 26(1)-(12)

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 49: registration in the EU database before the system reaches the market",
praxikon:eu:ai-act:obligation:article-49-registration@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-08-02T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z,
sha256 95cd9f806f657817dbdc6e5aa1c1b74b37239b8513edc6ad054fd87eaf7b858f,
https://www.praxikon.com/en/verplichtingen/article-49-registration
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-49-registration&effective_at=2026-08-02&known_at=2026-09-06&lang=en, accessed 2026-09-15)

Short form

praxikon:eu:ai-act:obligation:article-49-registration@1.0.0 (sha256 95cd9f80)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-49-registration-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 49: registration in the EU database before the system reaches the market},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-49-registration},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-08-02T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 95cd9f806f657817dbdc6e5aa1c1b74b37239b8513edc6ad054fd87eaf7b858f},
  url          = {https://www.praxikon.com/en/verplichtingen/article-49-registration},
  urldate      = {2026-09-15},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-49-registration@1.0.0",
    "type": "dataset",
    "title": "Article 49: registration in the EU database before the system reaches the market",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-49-registration",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-49-registration",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          9,
          6
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          15
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-02T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 95cd9f806f657817dbdc6e5aa1c1b74b37239b8513edc6ad054fd87eaf7b858f; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-49-registration&effective_at=2026-08-02&known_at=2026-09-06&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v1.0.0

    2 August 2026

    Article 49: registration in the EU database before the system reaches the market

    The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist

Help with implementation

Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.

View AI governance at Embed AI

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.