The core of the regulation, product regulation on the model of CE marking. Classification, technical requirements, obligations along the chain, notified bodies and the route to market.
Section 1 · classification (Articles 6–7)
Art. 6 Two routes into high risk. The system is a safety component of a regulated product under Annex I with third-party conformity assessment (paragraph 1), or it falls into the areas of Annex III (paragraph 2), namely biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, the administration of justice. Paragraph 3 provides a filter for systems with only a preparatory or ancillary role without significant risk, but the exception has to be documented and the system registered. Profiling of natural persons is always high-risk. The step-by-step decision chart is on the AI Act card.
Art. 7 The Commission may by delegated acts both add to and narrow the list of high-risk uses according to criteria of the severity and probability of harm. This is the mechanism by which Annex III will keep changing; tracking it is a continuing compliance obligation in itself.
Section 2 · requirements for the system (Articles 8–15)
Art. 8 The system meets the requirements of the section having regard to its intended purpose and the generally acknowledged state of the art. For products under Annex I, compliance is integrated into the sectoral procedures so that nothing is assessed twice.
Art. 9 A continuous, iterative process across the whole life cycle. Identifying foreseeable risks including reasonably foreseeable misuse, design measures, testing against metrics, and particular regard for persons under 18 and otherwise vulnerable groups.
Art. 10 Training, validation and testing sets must be relevant, sufficiently representative and, to the best extent possible, free of errors, with data-governance practices from collection through labelling to the detection and mitigation of bias. Processing special categories of personal data to detect bias is allowed only under strict cumulative conditions. In practice the most expensive article in the regulation.
Art. 11 Kept up to date before the system is placed on the market and thereafter, with content per Annex IV. Small and medium-sized enterprises may use the Commission’s simplified form.
Art. 12 The system automatically logs events across the whole life cycle so that a risky situation, a substantial modification and the basis for post-market monitoring can be traced back.
Art. 13 Instructions for use setting out the system’s capabilities and limits, performance metrics, known risks, and the requirements for human oversight and maintenance. Without this article the deployer could not carry its own obligations under Article 26.
Art. 14 Oversight must be effective: the overseeing person understands the capabilities and limits, can interpret the output correctly, resist automation bias, and intervene or stop the system. For remote biometric identification, no action may be taken on the basis of the output alone without verification by at least two competent natural persons.
Art. 15 Declared levels of accuracy in the instructions, robustness against errors and against attempts at misuse (data poisoning, adversarial inputs), and the handling of feedback loops in systems that learn in operation.
Section 3 · obligations along the chain (Articles 16–27)
Art. 16 A summary catalogue. Ensure compliance with Section 2, have a quality management system, keep documentation and logs, undergo conformity assessment, draw up the declaration, affix the CE marking, register, take corrective action, cooperate with the authorities, and meet accessibility requirements under Directives (EU) 2016/2102 and 2019/882.
Art. 17 A written quality management system covering the compliance strategy, design and development, testing, data governance, risk management, post-market monitoring, incident reporting and communication with the authorities. The counterpart of the QMS from the world of medical devices.
Art. 18 The technical documentation, the QMS documentation, the declaration of conformity and the certificates kept available to the authorities for ten years after the system is placed on the market.
Art. 19 Logs under the provider’s control are kept for a period appropriate to the purpose, at least six months.
Art. 20 Bring a non-conforming system into compliance, withdraw it from the market, disable it or recall it, and inform distributors, deployers, the authorised representative and importers.
Art. 21 On a reasoned request, demonstrate compliance and make the documentation and logs available in a language the authority understands.
Art. 22 A provider from a third country must have a written-mandated representative established in the EU who holds the documentation and is the authorities’ point of contact. The same logic as Article 27 GDPR.
Art. 23 Before placing a system on the market, verify that conformity assessment has been carried out, that documentation exists, that the system bears the CE marking and that the provider has a representative. The importer puts its name on the packaging and must not place a system it knows to be non-conforming.
Art. 24 Verification of markings and documents, storage and transport that do not jeopardise conformity, and a duty to withdraw or report a system presenting a risk.
Art. 25 The most underestimated article in the regulation. Anyone who puts their own name on a third party’s high-risk system, substantially modifies it, or turns a general-purpose system’s purpose into a high-risk one, becomes a provider with all the obligations. The original provider hands over the documentation, and component suppliers conclude written cooperation agreements. This is exactly the way integrators building on other people’s models slip into the regime.
Art. 26 Use it in accordance with the instructions, entrust oversight to competent persons, ensure relevant input data, monitor operation, report incidents, keep logs for at least six months, inform workers and their representatives before deployment in the workplace, and inform the persons about whom the system helps to decide.
Art. 27 Public-body deployers, private providers of public services, and deployers in credit scoring and life insurance describe, before first use, the processes, the groups affected, the risks of harm, human oversight and corrective measures, and notify this to the supervisory authority. It builds on the DPIA from the GDPR and, where one already exists, is added to it.
Section 4 · notifying authorities and notified bodies (Articles 28–39)
Art. 28 Each State designates an authority to assess, notify and monitor conformity assessment bodies, with a guarantee of impartiality towards them.
Art. 29 A conformity assessment body demonstrates its competence by accreditation or, where appropriate, other documentation.
Art. 30 Notification to the Commission and the States is done electronically, with windows for objections; only then may the body act as notified.
Art. 31 Independence from providers and competitors, confidentiality, expert staff, liability insurance, and internal processes proportionate to the size of the client.
Art. 32 Accreditation under harmonised standards raises a presumption that the requirements of Article 31 are met.
Art. 33 Subcontracting of assessment only with the client’s consent and with the notified body retaining full responsibility.
Art. 34 Assess proportionately, do not burden small providers needlessly, and keep the documentation available to the notifying authority.
Art. 35 The Commission assigns numbers and maintains a public list of notified bodies.
Art. 36 The procedure on loss of competence, suspension or withdrawal, and the fate of certificates already issued, including the transfer of files to another body.
Art. 37 The Commission may investigate competence and require the State to take remedial action, including withdrawing the notification.
Art. 38 Sectoral groups for sharing practice, so that assessment does not diverge between States.
Art. 39 On equivalent conditions and on the basis of agreements, bodies established outside the EU may also carry out the activity.
Section 5 · standards, conformity, certificates, registration (Articles 40–49)
Art. 40 Conformity with a harmonised standard raises a presumption of conformity with the requirements the standard covers. The practical route to compliance; standards for the AI Act are being drawn up in CEN/CENELEC at the Commission’s request.
Art. 41 Where standards are missing or insufficient, the Commission may by implementing act issue its own specifications with the same presumption effect.
Art. 42 Two special presumptions. Training on data reflecting the deployment setting, for representativeness, and cybersecurity certification, for Article 15.
Art. 43 For biometrics under Annex III, point 1, the provider chooses between internal control under Annex VI and assessment with a notified body under Annex VII only where it has used harmonised standards or common specifications. Where such standards do not exist or it did not apply them in full, it must go the Annex VII route with a notified body. For the other areas of Annex III, internal control under Annex VI is enough. Systems in products under Annex I run under the sectoral procedures. A substantial modification of the system means a new assessment.
Art. 44 Issued by notified bodies for a limited period, with the possibility of extension, suspension and withdrawal, against which an appeal procedure exists.
Art. 45 Reporting of certificates issued, refused, suspended and withdrawn to the notifying authority and sharing with the other bodies.
Art. 46 On exceptional grounds of public security, the protection of life and health, the environment or key assets, the supervisory authority may authorise placing on the market without a completed assessment, temporarily and under control.
Art. 47 Through it the provider assumes responsibility for conformity for ten years, with content per Annex V.
Art. 48 Visibly, legibly and indelibly, digitally for digital systems, with the number of the notified body where one was involved.
Art. 49 The provider registers in the EU database under Article 71 before placing the system on the market; systems exempted by the Article 6(3) filter and public-body deployers register too. Sensitive areas (law enforcement, migration) go into the non-public part.