The core of the regulation, product regulation on the model of CE marking. Classification, technical requirements, obligations along the chain, notified bodies and the route to market.
Section 1 · classification (Articles 6–7)
Art. 6 Classification rules for high-risk AI systems Two routes into high risk. The system is a safety component of a regulated product under Annex I with third-party conformity assessment (paragraph 1), or it falls into the areas of Annex III (paragraph 2), namely biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, the administration of justice. Paragraph 3 provides a filter for systems with only a preparatory or ancillary role without significant risk, but the exception has to be documented and the system registered. Profiling of natural persons is always high-risk. The step-by-step decision chart is on the AI Act card.
Art. 7 Amendments to Annex III The Commission may by delegated acts both add to and narrow the list of high-risk uses according to criteria of the severity and probability of harm. This is the mechanism by which Annex III will keep changing; tracking it is a continuing compliance obligation in itself.
Section 2 · requirements for the system (Articles 8–15)
Art. 8 Compliance with the requirements The system meets the requirements of the section having regard to its intended purpose and the generally acknowledged state of the art. For products under Annex I, compliance is integrated into the sectoral procedures so that nothing is assessed twice.
Art. 9 Risk management system A continuous, iterative process across the whole life cycle. Identifying foreseeable risks including reasonably foreseeable misuse, design measures, testing against metrics, and particular regard for persons under 18 and otherwise vulnerable groups.
Art. 10 Data and data governance Training, validation and testing sets must be relevant, sufficiently representative and, to the best extent possible, free of errors, with data-governance practices from collection through labelling to the detection and mitigation of bias. Processing special categories of personal data to detect bias is allowed only under strict cumulative conditions. In practice the most expensive article in the regulation.
Art. 11 Technical documentation Kept up to date before the system is placed on the market and thereafter, with content per Annex IV. Small and medium-sized enterprises may use the Commission’s simplified form.
Art. 12 Record-keeping The system automatically logs events across the whole life cycle so that a risky situation, a substantial modification and the basis for post-market monitoring can be traced back.
Art. 13 Transparency and provision of information to deployers Instructions for use setting out the system’s capabilities and limits, performance metrics, known risks, and the requirements for human oversight and maintenance. Without this article the deployer could not carry its own obligations under Article 26.
Art. 14 Human oversight Oversight must be effective: the overseeing person understands the capabilities and limits, can interpret the output correctly, resist automation bias, and intervene or stop the system. For remote biometric identification, no action may be taken on the basis of the output alone without verification by at least two competent natural persons.
Art. 15 Accuracy, robustness and cybersecurity Declared levels of accuracy in the instructions, robustness against errors and against attempts at misuse (data poisoning, adversarial inputs), and the handling of feedback loops in systems that learn in operation.
Section 3 · obligations along the chain (Articles 16–27)
Art. 16 Obligations of providers of high-risk AI systems A summary catalogue. Ensure compliance with Section 2, have a quality management system, keep documentation and logs, undergo conformity assessment, draw up the declaration, affix the CE marking, register, take corrective action, cooperate with the authorities, and meet accessibility requirements under Directives (EU) 2016/2102 and 2019/882.
Art. 17 Quality management system A written quality management system covering the compliance strategy, design and development, testing, data governance, risk management, post-market monitoring, incident reporting and communication with the authorities. The counterpart of the QMS from the world of medical devices.
Art. 18 Documentation keeping The technical documentation, the QMS documentation, the declaration of conformity and the certificates kept available to the authorities for ten years after the system is placed on the market.
Art. 23 Obligations of importers Before placing a system on the market, verify that conformity assessment has been carried out, that documentation exists, that the system bears the CE marking and that the provider has a representative. The importer puts its name on the packaging and must not place a system it knows to be non-conforming.
Art. 24 Obligations of distributors Verification of markings and documents, storage and transport that do not jeopardise conformity, and a duty to withdraw or report a system presenting a risk.
Art. 25 Responsibilities along the AI value chain The most underestimated article in the regulation. Anyone who puts their own name on a third party’s high-risk system, substantially modifies it, or turns a general-purpose system’s purpose into a high-risk one, becomes a provider with all the obligations. The original provider hands over the documentation, and component suppliers conclude written cooperation agreements. This is exactly the way integrators building on other people’s models slip into the regime.
Art. 26 Obligations of deployers of high-risk AI systems Use it in accordance with the instructions, entrust oversight to competent persons, ensure relevant input data, monitor operation, report incidents, keep logs for at least six months, inform workers and their representatives before deployment in the workplace, and inform the persons about whom the system helps to decide.
Art. 27 Fundamental rights impact assessment for high-risk AI systems Public-body deployers, private providers of public services, and deployers in credit scoring and life insurance describe, before first use, the processes, the groups affected, the risks of harm, human oversight and corrective measures, and notify this to the supervisory authority. It builds on the DPIA from the GDPR and, where one already exists, is added to it.
Section 4 · notifying authorities and notified bodies (Articles 28–39)
Art. 28 Notifying authorities Each State designates an authority to assess, notify and monitor conformity assessment bodies, with a guarantee of impartiality towards them.
Art. 30 Notification procedure Notification to the Commission and the States is done electronically, with windows for objections; only then may the body act as notified.
Art. 36 Changes to notifications The procedure on loss of competence, suspension or withdrawal, and the fate of certificates already issued, including the transfer of files to another body.
Section 5 · standards, conformity, certificates, registration (Articles 40–49)
Art. 41 Common specifications Where standards are missing or insufficient, the Commission may by implementing act issue its own specifications with the same presumption effect.
Art. 43 Conformity assessment For biometrics under Annex III, point 1, the provider chooses between internal control under Annex VI and assessment with a notified body under Annex VII only where it has used harmonised standards or common specifications. Where such standards do not exist or it did not apply them in full, it must go the Annex VII route with a notified body. For the other areas of Annex III, internal control under Annex VI is enough. Systems in products under Annex I run under the sectoral procedures. A substantial modification of the system means a new assessment.
Art. 44 Certificates Issued by notified bodies for a limited period, with the possibility of extension, suspension and withdrawal, against which an appeal procedure exists.
Art. 46 Derogation from conformity assessment procedure On exceptional grounds of public security, the protection of life and health, the environment or key assets, the supervisory authority may authorise placing on the market without a completed assessment, temporarily and under control.
Art. 48 CE marking Visibly, legibly and indelibly, digitally for digital systems, with the number of the notified body where one was involved.
Art. 49 Registration The provider registers in the EU database under Article 71 before placing the system on the market; systems exempted by the Article 6(3) filter and public-body deployers register too. Sensitive areas (law enforcement, migration) go into the non-public part.