Article 8: compliance with the requirements for high-risk AI systems
High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.
Paragraph 1 provides that high-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies.
Praxikon tracks Article 8: compliance with the requirements for high-risk AI systems under the EU AI Act, checked against the official source on 6 September 2026, citing the source for every statement.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 6 September 2026
Review status: placed against the official source (6 September 2026). Next check due by 5 March 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
From source to evidence
Why this obligation applies, what it asks of you, and what you show for it.
Applies
Upcoming · 2 December 2027
For whom
Provider of an AI system
What you do
Record the state of the art and the intended purpose per system
What you record
Justification of the state of the art
Official source
Who this is relevant to
When this applies
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1Applies to every AI system that qualifies as high-risk under Article 6, along both routes: the system that falls under the Union harmonisation legislation of Annex I as a safety component of a product or as a product in its own right, and the system that falls within one of the areas of Annex III. For the Annex I route there is a limit that this Article does not state itself: Article 2(2), as replaced by Article 1, point (2)(a), of Regulation (EU) 2026/1744, makes only Article 6(1), Article 60a and Articles 102 to 112 applicable to systems related to products covered by Section B of Annex I. Article 8 is not in that list, so for Section B products, machinery among them since 27 July 2026, this provision does not bear. In addition, Article 2(13), inserted by Article 1, point (3), can limit the application of the requirements in Articles 9 to 15 and 17 to 25 for Section A products, but only once the delegated act it prescribes exists. Article 8 sets no additional threshold of its own: what is high-risk is the subject of Article 6 and not of this provision.
- 2Compliance is not assessed in the abstract but against two measures at once: the intended purpose of the system, and the generally acknowledged state of the art on AI and AI-related technologies. The second measure lies outside the Regulation and has no fixed content, so what suffices changes without the text changing.
- 3Paragraph 2 only comes into play where a product contains an AI system to which both the requirements of this Regulation and those of the Union harmonisation legislation listed in Section A of Annex I apply. For a system that is high-risk through Annex III alone, paragraph 2 has no bearing.
What the official source establishes
Paragraph 1 provides that high-risk AI systems shall comply with the requirements laid down in this Section, taking into account their intended purpose as well as the generally acknowledged state of the art on AI and AI-related technologies. The risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements. Paragraph 2 provides that, where a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.
Our interpretation
The official source remains authoritative. This general interpretation is not legal advice.
Read Article 8 not as an eighth requirement alongside the seven of Articles 9 to 15, but as the provision that says how those seven are to be read. It does two things none of the seven does itself. The first is that it brings in a measure from outside the Regulation. Article 8 is the only article in Section 2 that names the generally acknowledged state of the art, and that means the bar moves. A file that sufficed at the first conformity assessment does not necessarily still suffice some years later, without a single word of the Regulation changing: what was the state of the art then is no longer the state of the art later. The Regulation provides no re-certification rhythm for this beyond the substantial modification of Article 43(4), so anyone who does not set a rhythm of their own has none. Note also what the measure is not. The state of the art is not a synonym for a harmonised standard: Article 40 gives a presumption of conformity to whoever applies such a standard, but Article 8 sets an open measure alongside it that does not stop applying once the standard has been ticked off. The second is that paragraph 1 designates the risk management system of Article 9 as the instrument through which compliance with the other requirements is assessed. Article 9 is therefore not one requirement beside the other six but the file in which you show that you have met the other six at the right level. An organisation that keeps its risk analysis as a separate document beside the technical documentation misses exactly that connection.
Paragraph 2 is the anti-duplication provision, and in practice it is rarely used. It concerns the product that contains an AI system and falls both under this Regulation and under the Union harmonisation legislation of Section A of Annex I: that is precisely the route of Article 6(1). Two different things are stated. The first is an allocation: the provider is responsible for his product being fully compliant with everything the sectoral legislation requires. It does not say that the AI Act replaces or lightens the sectoral requirements, nor that the sectoral assessment swallows the requirements of Section 2; it says that both stacks apply at once and that the provider of the product covers both. The second is a choice, not a duty: he may integrate the testing and reporting processes, the information and the documentation on the product into the documentation and procedures the sectoral legislation already prescribes. We see two mistakes there. The first is that the AI Act file is built beside the existing technical file, with two versions of the same risk analysis that drift apart after two releases; that is exactly the duplication paragraph 2 seeks to avoid. The second is that the integration happens but cannot be found. Whoever enters the sectoral conformity assessment of Article 43(3) must be able to point, per requirement of Articles 9 to 15, to where in the existing file the answer sits. Integrating is therefore not merging into invisibility; it is a cross-reference per requirement, and that is the form in which the choice of paragraph 2 actually saves work.
What you can do now
Record once, per high-risk system, what you regard as the generally acknowledged state of the art, with the sources: which harmonised standards or common specifications you apply, which of them you do not apply and why, and which evaluation method, benchmark or test set you use for this application area. Attach a fixed re-assessment moment to it, for instance annually and at every release, and hang that record on the risk management file of Article 9 rather than on a separate document; paragraph 1 designates that file as the instrument through which compliance is assessed. Note against which intended purpose each requirement of Articles 9 to 15 has been met, so that a change of intended purpose visibly touches the whole series. If your system sits in a product also covered by Section A of Annex I, make the choice of paragraph 2 explicit before you start and record who made it: one combined file or two files. If you combine, build a cross-reference table that points, per requirement of Section 2, to where in the existing technical file the answer sits, and let that table travel through the sectoral assessment. If you keep two files, record who keeps them in step and on which change both are updated.
- 01
Record the state of the art and the intended purpose per system
Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.
What to retain
Justification of the state of the art
Per system and per version: which intended purpose was taken, which standards, specifications, evaluation methods and test sets were treated as the state of the art, which were deliberately not applied and why, who established that, and on what date the record was reviewed again.
Control and reassessment
Review of the overlap with sectoral product documentation
The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.
Public tools
Full text of Article 8
The full legal text in the public AI Act Explorer.
Conditions and exceptions
- The integration in paragraph 2 is a choice and not a duty: providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist. Anyone who does not integrate breaches nothing. What the provision does not permit is doing less: the responsibility for full compliance with all applicable requirements under the sectoral harmonisation legislation stands undiminished.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 8(1)-(2)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 6(1); Article 9(1) and (2); Article 16, point (a); Article 40(1); Article 43(3) and (4); Annex I, Section A
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Article 8: compliance with the requirements for high-risk AI systems", praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-07-27T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z, sha256 4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f, https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-8-compliance-with-requirements&effective_at=2026-07-27&known_at=2026-09-06&lang=en, accessed 2026-09-15)
Short form
praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements@1.0.0 (sha256 4f3c944b)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-8-compliance-with-requirements-1-0-0,
author = {{Praxikon}},
title = {Article 8: compliance with the requirements for high-risk AI systems},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
note = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f},
url = {https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements},
urldate = {2026-09-15},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements@1.0.0",
"type": "dataset",
"title": "Article 8: compliance with the requirements for high-risk AI systems",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements",
"URL": "https://www.praxikon.com/en/verplichtingen/article-8-compliance-with-requirements",
"language": "en",
"issued": {
"date-parts": [
[
2026,
9,
6
]
]
},
"accessed": {
"date-parts": [
[
2026,
9,
15
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 4f3c944bd22b7f1e7152db7acbc5b5ff00963c180aee232371af34402e112e6f; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-8-compliance-with-requirements&effective_at=2026-07-27&known_at=2026-09-06&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Version history
v1.0.0
27 July 2026
Article 8: compliance with the requirements for high-risk AI systems
High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.
Corrections to this obligation
No substantive correction to this object has been recorded.
Open the correction logHelp with implementation
Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.
View AI governance at Embed AIFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.
