
--- PAGE 1 ---
📜 AnimusLab Compliance Architecture | Statutory Interpretations Registry 
This repository resource maps the deterministic code invariants enforced by the Anchor Kernel 
(Articles 6–27) straight to the formal legal intent articulated by the European Commission's 
introductory frameworks (Recitals 38–73). 
If a rule triggers a runtime block or static code violation, look up the corresponding Article ID inside 
this ledger to view the exact legislative reasoning behind the system constraint. 
EU AI ACT 
Annex III 
High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:  
 
1)​ Biometrics, in so far as their use is permitted under relevant Union or national law: 
i)​
remote biometric identification systems.This shall not include AI systems intended to be u
biometric verification the sole purpose of which is to confirm that a specific natural person
person he or she claims to be; 
ii)​
AI systems intended to be used for biometric categorisation, according to sensitive or pr
attributes or characteristics based on the inference of those attributes or characteristics; 
iii)​
AI systems intended to be used for emotion recognition. 
 
2)​ Critical infrastructure: AI systems intended to be used as safety components in the manageme
operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or elec
3)​ Education and vocational training: 
i)​
AI systems intended to be used to determine access or admission or to assign natural per
educational and vocational training institutions at all levels; 
ii)​
AI systems intended to be used to evaluate learning outcomes, including when those outcom
used to steer the learning process of natural persons in educational and vocational 
institutions at all levels; 
iii)​
AI systems intended to be used for the purpose of assessing the appropriate level of educat
an individual will receive or will be able to access, in the context of or within education
vocational training institutions at all levels; 
iv)​
AI systems intended to be used for monitoring and detecting prohibited behaviour of students
tests in the context of or within educational and vocational training institutions at all levels.. 
 
4)​ Employment, workers’ management and access to self-employment: 
i)​
AI systems intended to be used for the recruitment or selection of natural persons, in parti
place targeted job advertisements, to analyse and filter job applications, and to evaluate cand
ii)​
AI systems intended to be used to make decisions affecting terms of work-related relationsh
promotion or termination of work-related contractual relationships, to allocate tasks ba

--- PAGE 2 ---
individual behaviour or personal traits or characteristics or to monitor and evaluate the perfo
and behaviour of persons in such relationships. 
 
5)​ Access to and enjoyment of essential private services and essential public services and benefits: 
i)​
AI systems intended to be used by public authorities or on behalf of public authorities to e
the eligibility of natural persons for essential public assistance benefits and services, in
healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and service
ii)​
AI systems intended to be used to evaluate the creditworthiness of natural persons or establi
credit score, with the exception of AI systems used for the purpose of detecting financial frau
iii)​
AI systems intended to be used for risk assessment and pricing in relation to natural person
case of life and health insurance; 
iv)​
AI systems intended to evaluate and classify emergency calls by natural persons or to be 
dispatch, or to establish priority in the dispatching of, emergency first response services, in
by police, firefighters and medical aid, as well as of emergency healthcare patient triage syste
 
6)​ Law enforcement, in so far as their use is permitted under relevant Union or national law: 
i)​
AI systems intended to be used by or on behalf of law enforcement authorities, or by
institutions, bodies, offices or agencies in support of law enforcement authorities or on thei
to assess the risk of a natural person becoming the victim of criminal offences; 
ii)​
AI systems intended to be used by or on behalf of law enforcement authorities or by
institutions, bodies, offices or agencies in support of law enforcement authorities as polygr
similar tools; 
iii)​
AI systems intended to be used by or on behalf of law enforcement authorities, or by
institutions, bodies, offices or agencies, in support of law enforcement authorities to evalu
reliability of evidence in the course of the investigation or prosecution of criminal offences; 
iv)​
AI systems intended to be used by law enforcement authorities or on their behalf or by
institutions, bodies, offices or agencies in support of law enforcement authorities for assess
risk of a natural person offending or re-offending not solely on the basis of the profiling of 
persons as referred to in Article 3(4) of Directive (EU) 2016/680, or to assess personality tra
characteristics or past criminal behaviour of natural persons or groups; 
v)​
AI systems intended to be used by or on behalf of law enforcement authorities or by
institutions, bodies, offices or agencies in support of law enforcement authorities for the pro
natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 in the course
detection, investigation or prosecution of criminal offences. 
 
7)​ Migration, asylum and border control management, in so far as their use is permitted under re
Union or national law: 
i)​
AI systems intended to be used by or on behalf of competent public authorities or by
institutions, bodies, offices or agencies as polygraphs or similar tools; 

--- PAGE 3 ---
ii)​
AI systems intended to be used by or on behalf of competent public authorities or by
institutions, bodies, offices or agencies to assess a risk, including a security risk, a risk of ir
migration, or a health risk, posed by a natural person who intends to enter or who has ente
the territory of a Member State; 
iii)​
AI systems intended to be used by or on behalf of competent public authorities or by
institutions, bodies, offices or agencies to assist competent public authorities for the examin
applications for asylum, visa or residence permits and for associated complaints with regard
eligibility of the natural persons applying for a status, including related assessments of the re
of evidence; 
iv)​
AI systems intended to be used by or on behalf of competent public authorities, or by
institutions, bodies, offices or agencies, in the context of migration, asylum or border 
management, for the purpose of detecting, recognising or identifying natural persons, w
exception of the verification of travel documents. 
 
8)​ Administration of justice and democratic processes: 
i)​
AI systems intended to be used by a judicial authority or on their behalf to assist a judicial a
in researching and interpreting facts and the law and in applying the law to a concrete set o
or to be used in a similar way in alternative dispute resolution; 
ii)​
AI systems intended to be used for influencing the outcome of an election or referendum
voting behaviour of natural persons in the exercise of their vote in elections or referenda. Th
not include AI systems to the output of which natural persons are not directly exposed, such a
used to organise, optimise or structure political campaigns from an administrative or logistic
of view. 
Annex IV 
 
 
The technical documentation referred to in Article 11(1) shall contain at least the following informat
applicable to the relevant AI system:  
 
1.​ A general description of the AI system including: 
i.​
its intended purpose, the name of the provider and the version of the system reflecting its rel
previous versions; 
 
ii.​
how the AI system interacts with, or can be used to interact with, hardware or software, in
with other AI systems, that are not part of the AI system itself, where applicable; 
 
iii.​
the versions of relevant software or firmware, and any requirements related to version update
 

--- PAGE 4 ---
iv.​
the description of all the forms in which the AI system is placed on the market or put into s
such as software packages embedded into hardware, downloads, or APIs; 
 
v.​
the description of the hardware on which the AI system is intended to run; 
 
vi.​
where the AI system is a component of products, photographs or illustrations showing e
features, the marking and internal layout of those products; 
 
vii.​
a basic description of the user-interface provided to the deployer; 
 
viii.​
instructions for use for the deployer, and a basic description of the user-interface provided
deployer, where applicable; 
 
2.​ A detailed description of the elements of the AI system and of the process for its development, incl
i.​
the methods and steps performed for the development of the AI system, including, where re
recourse to pre-trained systems or tools provided by third parties and how those were
integrated or modified by the provider; 
 
ii.​
the design specifications of the system, namely the general logic of the AI system and
algorithms; the key design choices including the rationale and assumptions made, includi
regard to persons or groups of persons in respect of who, the system is intended to be us
main classification choices; what the system is designed to optimise for, and the relevance
different parameters; the description of the expected output and output quality of the syste
decisions about any possible trade-off made regarding the technical solutions adopted to 
with the requirements set out in Chapter III, Section 2; 
 
iii.​
the description of the system architecture explaining how software components build on or fe
each other and integrate into the overall processing; the computational resources used to d
train, test and validate the AI system; 
 
iv.​
where relevant, the data requirements in terms of datasheets describing the training method
and techniques and the training data sets used, including a general description of these da
information about their provenance, scope and main characteristics; how the data was obtain
selected; labelling procedures (e.g. for supervised learning), data cleaning methodologie
outliers detection); 
 
v.​
assessment of the human oversight measures needed in accordance with Article 14, inclu
assessment of the technical measures needed to facilitate the interpretation of the output
systems by the deployers, in accordance with Article 13(3), point (d); 

--- PAGE 5 ---
 
vi.​
where applicable, a detailed description of pre-determined changes to the AI system 
performance, together with all the relevant information related to the technical solutions ado
ensure continuous compliance of the AI system with the relevant requirements set out in Cha
Section 2; 
 
vii.​
the validation and testing procedures used, including information about the validation and 
data used and their main characteristics; metrics used to measure accuracy, robustne
compliance with other relevant requirements set out in Chapter III, Section 2, as well as pot
discriminatory impacts; test logs and all test reports dated and signed by the responsible p
including with regard to pre-determined changes as referred to under point (f); 
 
viii.​
cybersecurity measures put in place; 
 
 
 
 
 
3.​ Detailed information about the monitoring, functioning and control of the AI system, in particul
regard to: its capabilities and limitations in performance, including the degrees of accuracy for s
persons or groups of persons on which the system is intended to be used and the overall expecte
of accuracy in relation to its intended purpose; the foreseeable unintended outcomes and sour
risks to health and safety, fundamental rights and discrimination in view of the intended purpose of
system; the human oversight measures needed in accordance with Article 14, including the tec
measures put in place to facilitate the interpretation of the outputs of AI systems by the dep
specifications on input data, as appropriate; 
 
4.​ A description of the appropriateness of the performance metrics for the specific AI system; 
 
5.​ A detailed description of the risk management system in accordance with Article 9; 
 
6.​ A description of relevant changes made by the provider to the system through its lifecycle; 
 
7.​ A list of the harmonised standards applied in full or in part the references of which have been pub
in the Official Journal of the European Union; where no such harmonised standards have been app
detailed description of the solutions adopted to meet the requirements set out in Chapter III, Sec
including a list of other relevant standards and technical specifications applied; 
 
8.​ A copy of the EU declaration of conformity referred to in Article 47; 

--- PAGE 6 ---
 
9.​ A detailed description of the system in place to evaluate the AI system performance in the post-
phase in accordance with Article 72, including the post-market monitoring plan referred to in 
72(3). 
 
​
Chapter II: Prohibited AI Practices 
Article 5: Prohibited AI practices 
1.   The following AI practices shall be prohibited: 
(a) 
the placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques 
a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the e
materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to m
informed decision, thereby causing them to take a decision that they would not have otherwise taken in a mann
causes or is reasonably likely to cause that person, another person or group of persons significant harm; 
(b) 
the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilit
natural person or a specific group of persons due to their age, disability or a specific social or economic situatio
the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that gro
manner that causes or is reasonably likely to cause that person or another person significant harm; 
(c) 
the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of
persons or groups of persons over a certain period of time based on their social behaviour or known, infe
predicted personal or personality characteristics, with the social score leading to either or both of the following: 
(i) 
detrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts t
unrelated to the contexts in which the data was originally generated or collected; 
(ii) 
detrimental or unfavourable treatment of certain natural persons or groups of persons that is unjusti
disproportionate to their social behaviour or its gravity; 
(d) 
the placing on the market, the putting into service for this specific purpose, or the use of an AI system for mak
assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal o
based solely on the profiling of a natural person or on assessing their personality traits and characteristi
prohibition shall not apply to AI systems used to support the human assessment of the involvement of a pers
criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity; 
(e) 

--- PAGE 7 ---
the placing on the market, the putting into service for this specific purpose, or the use of AI systems that cr
expand facial recognition databases through the untargeted scraping of facial images from the internet or
footage; 
(f) 
the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emo
a natural person in the areas of workplace and education institutions, except where the use of the AI system is in
to be put in place or into the market for medical or safety reasons; 
(g) 
the placing on the market, the putting into service for this specific purpose, or the use of biometric catego
systems that categorise individually natural persons based on their biometric data to deduce or infer their race, 
opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; this prohibitio
not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric 
categorizing of biometric data in the area of law enforcement; 
(h) 
the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes
enforcement, unless and in so far as such use is strictly necessary for one of the following objectives: 
(i) 
the targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation of human 
as well as the search for missing persons; 
(ii) 
the prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a g
and present or genuine and foreseeable threat of a terrorist attack; 
(iii) 
the localisation or identification of a person suspected of having committed a criminal offence, for the purp
conducting a criminal investigation or prosecution or executing a criminal penalty for offences referred to in Anne
punishable in the Member State concerned by a custodial sentence or a detention order for a maximum perio
least four years. 
Point (h) of the first subparagraph is without prejudice to Article 9 of Regulation (EU) 2016/679 for 
the processing of biometric data for purposes other than law enforcement. 
2.   The use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for 
the purposes of law enforcement for any of the objectives referred to in paragraph 1, first 
subparagraph, point (h), shall be deployed for the purposes set out in that point only to confirm 
the identity of the specifically targeted individual, and it shall take into account the following 
elements: 
(a) 
the nature of the situation giving rise to the possible use, in particular the seriousness, probability and scale of th
that would be caused if the system were not used; 

--- PAGE 8 ---
(b) 
the consequences of the use of the system for the rights and freedoms of all persons concerned, in particu
seriousness, probability and scale of those consequences. 
In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible 
spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, 
first subparagraph, point (h), of this Article shall comply with necessary and proportionate 
safeguards and conditions in relation to the use in accordance with the national law authorising 
the use thereof, in particular as regards the temporal, geographic and personal limitations. The 
use of the ‘real-time’ remote biometric identification system in publicly accessible spaces shall be 
authorised only if the law enforcement authority has completed a fundamental rights impact 
assessment as provided for in Article 27 and has registered the system in the EU database 
according to Article 49. However, in duly justified cases of urgency, the use of such systems may 
be commenced without the registration in the EU database, provided that such registration is 
completed without undue delay. 
3.   For the purposes of paragraph 1, first subparagraph, point (h) and paragraph 2, each use for 
the purposes of law enforcement of a ‘real-time’ remote biometric identification system in publicly 
accessible spaces shall be subject to a prior authorisation granted by a judicial authority or an 
independent administrative authority whose decision is binding of the Member State in which the 
use is to take place, issued upon a reasoned request and in accordance with the detailed rules of 
national law referred to in paragraph 5. However, in a duly justified situation of urgency, the use of 
such system may be commenced without an authorisation provided that such authorisation is 
requested without undue delay, at the latest within 24 hours. If such authorisation is rejected, the 
use shall be stopped with immediate effect and all the data, as well as the results and outputs of 
that use shall be immediately discarded and deleted. 
The competent judicial authority or an independent administrative authority whose decision is 
binding shall grant the authorisation only where it is satisfied, on the basis of objective evidence 
or clear indications presented to it, that the use of the ‘real-time’ remote biometric identification 
system concerned is necessary for, and proportionate to, achieving one of the objectives specified 
in paragraph 1, first subparagraph, point (h), as identified in the request and, in particular, remains 
limited to what is strictly necessary concerning the period of time as well as the geographic and 
personal scope. In deciding on the request, that authority shall take into account the elements 

--- PAGE 9 ---
referred to in paragraph 2. No decision that produces an adverse legal effect on a person may be 
taken based solely on the output of the ‘real-time’ remote biometric identification system. 
4.   Without prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification 
system in publicly accessible spaces for law enforcement purposes shall be notified to the 
relevant market surveillance authority and the national data protection authority in accordance 
with the national rules referred to in paragraph 5. The notification shall, as a minimum, contain the 
information specified under paragraph 6 and shall not include sensitive operational data. 
5.   A Member State may decide to provide for the possibility to fully or partially authorise the use 
of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the 
purposes of law enforcement within the limits and under the conditions listed in paragraph 1, first 
subparagraph, point (h), and paragraphs 2 and 3. Member States concerned shall lay down in 
their national law the necessary detailed rules for the request, issuance and exercise of, as well 
as supervision and reporting relating to, the authorisations referred to in paragraph 3. Those rules 
shall also specify in respect of which of the objectives listed in paragraph 1, first subparagraph, 
point (h), including which of the criminal offences referred to in point (h)(iii) thereof, the competent 
authorities may be authorised to use those systems for the purposes of law enforcement. Member 
States shall notify those rules to the Commission at the latest 30 days following the adoption 
thereof. Member States may introduce, in accordance with Union law, more restrictive laws on the 
use of remote biometric identification systems. 
6.   
National market surveillance authorities and the national data protection authorities of 
Member States that have been notified of the use of ‘real-time’ remote biometric identification 
systems in publicly accessible spaces for law enforcement purposes pursuant to paragraph 4 
shall submit to the Commission annual reports on such use. For that purpose, the Commission 
shall provide Member States and national market surveillance and data protection authorities with 
a template, including information on the number of the decisions taken by competent judicial 
authorities or an independent administrative authority whose decision is binding upon requests for 
authorisations in accordance with paragraph 3 and their result. 
7.   
The Commission shall publish annual reports on the use of real-time remote biometric 
identification systems in publicly accessible spaces for law enforcement purposes, based on 
aggregated data in Member States on the basis of the annual reports referred to in paragraph 6. 

--- PAGE 10 ---
Those annual reports shall not include sensitive operational data of the related law enforcement 
activities. 
8.   This Article shall not affect the prohibitions that apply where an AI practice infringes other 
Union law. 
Relevant recitals 
​
Recital 3 | Recital 26 | Recital 28 | Recital 29 | Recital 30 | Recital 31 | Recital 32 | Recital 33 | 
Recital 34 | Recital 35 | Recital 36 | Recital 37 | Recital 38 | Recital 39 | Recital 40 | Recital 41 | 
Recital 42 | Recital 43 | Recital 44 | Recital 45 
​
 
​
Chapter III: High-Risk AI Systems 
​
Section 1: Classification of AI Systems as High-Risk 
​
Article 6: Classification rules for high-risk AI systems 
 Irrespective of whether an AI system is placed on the market or put into service independently of 
the products referred to in points (a) and (b), that AI system shall be considered to be high-risk 
where both of the following conditions are fulfilled: 
(a)​the AI system is intended to be used as a safety component of a product, or the AI system is itself a p
covered by the Union harmonisation legislation listed in Annex I; 
(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a pro
required to undergo a third-party conformity assessment, with a view to the placing on the market or the putt
service of that product pursuant to the Union harmonisation legislation listed in Annex I. 
 
2.   In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in 
Annex III shall be considered to be high-risk. 
3.   By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered 
to be high-risk where it does not pose a significant risk of harm to the health, safety or 
fundamental rights of natural persons, including by not materially influencing the outcome of 
decision making. 
The first subparagraph shall apply where any of the following conditions is fulfilled: 
(a)​the AI system is intended to perform a narrow procedural task; 
(b)​the AI system is intended to improve the result of a previously completed human activity; 
(c) the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns
not meant to replace or influence the previously completed human assessment, without proper human review; or 

--- PAGE 11 ---
(d)the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use
listed in Annex III. 
 
Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be 
considered to be high-risk where the AI system performs profiling of natural persons. 
4.   A provider who considers that an AI system referred to in Annex III is not high-risk shall 
document its assessment before that system is placed on the market or put into service. Such 
provider shall be subject to the registration obligation set out in Article 49(2). Upon request of 
national competent authorities, the provider shall provide the documentation of the assessment. 
5.   The Commission shall, after consulting the European Artificial Intelligence Board (the ‘Board’), 
and no later than 2 February 2026, provide guidelines specifying the practical implementation of 
this Article in line with Article 96 together with a comprehensive list of practical examples of use 
cases of AI systems that are high-risk and not high-risk. 
6.   The Commission is empowered to adopt delegated acts in accordance with Article 97 in order 
to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those 
laid down therein, or by modifying them, where there is concrete and reliable evidence of the 
existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of 
harm to the health, safety or fundamental rights of natural persons. 
7.   The Commission shall adopt delegated acts in accordance with Article 97 in order to amend 
paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down 
therein, where there is concrete and reliable evidence that this is necessary to maintain the level 
of protection of health, safety and fundamental rights provided for by this Regulation. 
8.   Any amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in 
accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of 
protection of health, safety and fundamental rights provided for by this Regulation and shall 
ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of 
market and technological developments. 
 
 
 
 

--- PAGE 12 ---
​
Chapter III: High-Risk AI Systems 
​
Section 1: Classification of AI Systems as High-Risk 
​
Article 7: Amendments to Annex III 
​
 
 The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend 
Annex III by adding or modifying use-cases of high-risk AI systems where both of the following 
conditions are fulfilled: 
(a) 
the AI systems are intended to be used in any of the areas listed in Annex III; 
(b) 
the AI systems pose a risk of harm to health and safety, or an adverse impact on fundamental rights, and tha
equivalent to, or greater than, the risk of harm or of adverse impact posed by the high-risk AI systems already refe
in Annex III. 
2.   When assessing the condition under paragraph 1, point (b), the Commission shall take into 
account the following criteria: 
(a) 
the intended purpose of the AI system; 
(b) 
the extent to which an AI system has been used or is likely to be used; 
(c) 
the nature and amount of the data processed and used by the AI system, in particular whether special categ
personal data are processed; 
(d) 
the extent to which the AI system acts autonomously and the possibility for a human to override a deci
recommendations that may lead to potential harm; 
(e) 
the extent to which the use of an AI system has already caused harm to health and safety, has had an adverse
on fundamental rights or has given rise to significant concerns in relation to the likelihood of such harm or a
impact, as demonstrated, for example, by reports or documented allegations submitted to national competent aut
or by other reports, as appropriate; 
(f) 
the potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability t
multiple persons or to disproportionately affect a particular group of persons; 
(g) 

--- PAGE 13 ---
the extent to which persons who are potentially harmed or suffer an adverse impact are dependent on the o
produced with an AI system, in particular because for practical or legal reasons it is not reasonably possible to 
from that outcome; 
(h) 
the extent to which there is an imbalance of power, or the persons who are potentially harmed or suffer an a
impact are in a vulnerable position in relation to the deployer of an AI system, in particular due to status, au
knowledge, economic or social circumstances, or age; 
(i) 
the extent to which the outcome produced involving an AI system is easily corrigible or reversible, taking into a
the technical solutions available to correct or reverse it, whereby outcomes having an adverse impact on health
or fundamental rights, shall not be considered to be easily corrigible or reversible; 
(j) 
the magnitude and likelihood of benefit of the deployment of the AI system for individuals, groups, or society a
including possible improvements in product safety; 
(k) 
the extent to which existing Union law provides for: 
(i) 
effective measures of redress in relation to the risks posed by an AI system, with the exclusion of claims for dama
(ii) 
effective measures to prevent or substantially minimise those risks. 
3.   The Commission is empowered to adopt delegated acts in accordance with Article 97 to 
amend the list in Annex III by removing high-risk AI systems where both of the following 
conditions are fulfilled: 
(a) 
the high-risk AI system concerned no longer poses any significant risks to fundamental rights, health or safety
into account the criteria listed in paragraph 2; 
(b) 
the deletion does not decrease the overall level of protection of health, safety and fundamental rights under Union
 
 
 
 
 
 
 
​
 
​
 
​
 

--- PAGE 14 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
​
Article 8: Compliance with the requirements 
​
 
1.   High-risk AI systems shall comply with the requirements laid down in this Section, taking into 
account their intended purpose as well as the generally acknowledged state of the art on AI and 
AI-related technologies. The risk management system referred to in Article 9 shall be taken into 
account when ensuring compliance with those requirements. 
2.   Where a product contains an AI system, to which the requirements of this Regulation as well 
as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, 
providers shall be responsible for ensuring that their product is fully compliant with all applicable 
requirements under applicable Union harmonisation legislation. In ensuring the compliance of 
high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and 
in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall 
have a choice of integrating, as appropriate, the necessary testing and reporting processes, 
information and documentation they provide with regard to their product into documentation and 
procedures that already exist and are required under the Union harmonisation legislation listed in 
Section A of Annex I. 
 
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
 
​
 
​
 
 

--- PAGE 15 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems  
​
Article 9: Risk management system 
​
 
1.   A risk management system shall be established, implemented, documented and maintained in 
relation to high-risk AI systems. 
2.   The risk management system shall be understood as a continuous iterative process planned 
and run throughout the entire lifecycle of a high-risk AI system, requiring regular systematic 
review and updating. It shall comprise the following steps: 
(a) 
the identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system ca
to health, safety or fundamental rights when the high-risk AI system is used in accordance with its intended purpo
(b) 
the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance
intended purpose, and under conditions of reasonably foreseeable misuse; 
(c) 
the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market mo
system referred to in Article 72; 
(d) 
the adoption of appropriate and targeted risk management measures designed to address the risks identified p
to point (a). 
3.   
The risks referred to in this Article shall concern only those which may be reasonably 
mitigated or eliminated through the development or design of the high-risk AI system, or the 
provision of adequate technical information. 
4.   
The risk management measures referred to in paragraph 2, point (d), shall give due 
consideration to the effects and possible interaction resulting from the combined application of the 
requirements set out in this Section, with a view to minimising risks more effectively while 
achieving an appropriate balance in implementing the measures to fulfil those requirements. 
5.   The risk management measures referred to in paragraph 2, point (d), shall be such that the 
relevant residual risk associated with each hazard, as well as the overall residual risk of the 
high-risk AI systems is judged to be acceptable. 
In identifying the most appropriate risk management measures, the following shall be ensured: 
(a) 

--- PAGE 16 ---
elimination or reduction of risks identified and evaluated pursuant to paragraph 2 in as far as technically feasible t
adequate design and development of the high-risk AI system; 
(b) 
where appropriate, implementation of adequate mitigation and control measures addressing risks that can
eliminated; 
(c) 
provision of information required pursuant to Article 13 and, where appropriate, training to deployers. 
With a view to eliminating or reducing risks related to the use of the high-risk AI system, due 
consideration shall be given to the technical knowledge, experience, education, the training to be 
expected by the deployer, and the presumable context in which the system is intended to be 
used. 
6.   High-risk AI systems shall be tested for the purpose of identifying the most appropriate and 
targeted risk management measures. Testing shall ensure that high-risk AI systems perform 
consistently for their intended purpose and that they are in compliance with the requirements set 
out in this Section. 
7.   Testing procedures may include testing in real-world conditions in accordance with Article 60. 
8.   The testing of high-risk AI systems shall be performed, as appropriate, at any time throughout 
the development process, and, in any event, prior to their being placed on the market or put into 
service. Testing shall be carried out against prior defined metrics and probabilistic thresholds that 
are appropriate to the intended purpose of the high-risk AI system. 
9.   When implementing the risk management system as provided for in paragraphs 1 to 7, 
providers shall give consideration to whether in view of its intended purpose the high-risk AI 
system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, 
other vulnerable groups. 
10.   For providers of high-risk AI systems that are subject to requirements regarding internal risk 
management processes under other relevant provisions of Union law, the aspects provided in 
paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established 
pursuant to that law. 
​
 
​
 
​
 
​
 
​
 

--- PAGE 17 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
​
Article 10: Data and data governance 
1.   High-risk AI systems which make use of techniques involving the training of AI models with 
data shall be developed on the basis of training, validation and testing data sets that meet the 
quality criteria referred to in paragraphs 2 to 5 whenever such data sets are used. 
2.   Training, validation and testing data sets shall be subject to data governance and 
management practices appropriate for the intended purpose of the high-risk AI system. Those 
practices shall concern in particular: 
(a) 
the relevant design choices; 
(b) 
data collection processes and the origin of data, and in the case of personal data, the original purpose of the 
data collection; 
(c) 
relevant data-preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment 
and aggregation; 
(d) 
the formulation of assumptions, in particular with respect to the information that the data are supposed to 
measure and represent; 
(e) 
an assessment of the availability, quantity and suitability of the data sets that are needed; 
(f) 
examination in view of possible biases that are likely to affect the health and safety of persons, have a 
negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where 
data outputs influence inputs for future operations; 
(g) 
appropriate measures to detect, prevent and mitigate possible biases identified according to point (f); 
(h) 
the identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how 
those gaps and shortcomings can be addressed. 
3.   Training, validation and testing data sets shall be relevant, sufficiently representative, and to 
the best extent possible, free of errors and complete in view of the intended purpose. They shall 
have the appropriate statistical properties, including, where applicable, as regards the persons or 
groups of persons in relation to whom the high-risk AI system is intended to be used. Those 

--- PAGE 18 ---
characteristics of the data sets may be met at the level of individual data sets or at the level of a 
combination thereof. 
4.   Data sets shall take into account, to the extent required by the intended purpose, the 
characteristics or elements that are particular to the specific geographical, contextual, behavioural 
or functional setting within which the high-risk AI system is intended to be used. 
5.   To the extent that it is strictly necessary for the purpose of ensuring bias detection and 
correction in relation to the high-risk AI systems in accordance with paragraph (2), points (f) and 
(g) of this Article, the providers of such systems may exceptionally process special categories of 
personal data, subject to appropriate safeguards for the fundamental rights and freedoms of 
natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 
2018/1725 and Directive (EU) 2016/680, all the following conditions must be met in order for such 
processing to occur: 
(a) 
the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or 
anonymised data; 
(b) 
the special categories of personal data are subject to technical limitations on the re-use of the personal data, 
and state-of-the-art security and privacy-preserving measures, including pseudonymisation; 
(c) 
the special categories of personal data are subject to measures to ensure that the personal data processed 
are secured, protected, subject to suitable safeguards, including strict controls and documentation of the 
access, to avoid misuse and ensure that only authorised persons have access to those personal data with 
appropriate confidentiality obligations; 
(d) 
the special categories of personal data are not to be transmitted, transferred or otherwise accessed by other 
parties; 
(e) 
the special categories of personal data are deleted once the bias has been corrected or the personal data has 
reached the end of its retention period, whichever comes first; 
(f) 
the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive 
(EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly 
necessary to detect and correct biases, and why that objective could not be achieved by processing other 
data. 

--- PAGE 19 ---
6.   For the development of high-risk AI systems not using techniques involving the training of AI 
models, paragraphs 2 to 5 apply only to the testing data sets. 
Relevant recitals 
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
Article 11: Technical documentation 
1.   The technical documentation of a high-risk AI system shall be drawn up before that system is 
placed on the market or put into service and shall be kept up-to date. 
The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk 
AI system complies with the requirements set out in this Section and to provide national 
competent authorities and notified bodies with the necessary information in a clear and 
comprehensive form to assess the compliance of the AI system with those requirements. It shall 
contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, may provide 
the elements of the technical documentation specified in Annex IV in a simplified manner. To that 
end, the Commission shall establish a simplified technical documentation form targeted at the 
needs of small and microenterprises. Where an SME, including a start-up, opts to provide the 
information required in Annex IV in a simplified manner, it shall use the form referred to in this 
paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment. 
2.   Where a high-risk AI system related to a product covered by the Union harmonisation 
legislation listed in Section A of Annex I is placed on the market or put into service, a single set of 
technical documentation shall be drawn up containing all the information set out in paragraph 1, 
as well as the information required under those legal acts. 
3.   The Commission is empowered to adopt delegated acts in accordance with Article 97 in order 
to amend Annex IV, where necessary, to ensure that, in light of technical progress, the technical 
documentation provides all the information necessary to assess the compliance of the system 
with the requirements set out in this Section. 
 
 
​
 
​
 

--- PAGE 20 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
Article 12: Record-keeping 
1.   High-risk AI systems shall technically allow for the automatic recording of events (logs) over 
the lifetime of the system. 
2.   In order to ensure a level of traceability of the functioning of a high-risk AI system that is 
appropriate to the intended purpose of the system, logging capabilities shall enable the recording 
of events relevant for: 
(a) 
identifying situations that may result in the high-risk AI system presenting a risk within the meaning of Article 
79(1) or in a substantial modification; 
(b) 
facilitating the post-market monitoring referred to in Article 72; and 
(c) 
monitoring the operation of high-risk AI systems referred to in Article 26(5). 
3.   For high-risk AI systems referred to in point 1 (a), of Annex III, the logging capabilities shall 
provide, at a minimum: 
(a) 
recording of the period of each use of the system (start date and time and end date and time of each use); 
(b) 
the reference database against which input data has been checked by the system; 
(c) 
the input data for which the search has led to a match; 
(d) 
the identification of the natural persons involved in the verification of the results, as referred to in Article 14(5). 
 
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 

--- PAGE 21 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
Article 13: Transparency and provision of information to deployers 
1.   High-risk AI systems shall be designed and developed in such a way as to ensure that their 
operation is sufficiently transparent to enable deployers to interpret a system’s output and use it 
appropriately. An appropriate type and degree of transparency shall be ensured with a view to 
achieving compliance with the relevant obligations of the provider and deployer set out in Section 
3. 
2.   High-risk AI systems shall be accompanied by instructions for use in an appropriate digital 
format or otherwise that include concise, complete, correct and clear information that is relevant, 
accessible and comprehensible to deployers. 
3.   The instructions for use shall contain at least the following information: 
(a) 
the identity and the contact details of the provider and, where applicable, of its authorised representative; 
(b) 
the characteristics, capabilities and limitations of performance of the high-risk AI system, including: 
(i) 
its intended purpose; 
(ii) 
the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which 
the high-risk AI system has been tested and validated and which can be expected, and any known and 
foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and 
cybersecurity; 
(iii) 
any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its 
intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health 
and safety or fundamental rights referred to in Article 9(2); 
(iv) 
where applicable, the technical capabilities and characteristics of the high-risk AI system to provide 
information that is relevant to explain its output; 
(v) 
when appropriate, its performance regarding specific persons or groups of persons on which the system is 
intended to be used; 
(vi) 

--- PAGE 22 ---
when appropriate, specifications for the input data, or any other relevant information in terms of the training, 
validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; 
(vii) 
where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it 
appropriately; 
(c) 
the changes to the high-risk AI system and its performance which have been pre-determined by the provider 
at the moment of the initial conformity assessment, if any; 
(d) 
the human oversight measures referred to in Article 14, including the technical measures put in place to 
facilitate the interpretation of the outputs of the high-risk AI systems by the deployers; 
(e) 
the computational and hardware resources needed, the expected lifetime of the high-risk AI system and any 
necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that 
AI system, including as regards software updates; 
(f) 
where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers 
to properly collect, store and interpret the logs in accordance with Article 12. 
 
 
 
 
 
 
 
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 

--- PAGE 23 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
Article 14: Human oversight 
1.   High-risk AI systems shall be designed and developed in such a way, including with 
appropriate human-machine interface tools, that they can be effectively overseen by natural 
persons during the period in which they are in use. 
2.   Human oversight shall aim to prevent or minimise the risks to health, safety or fundamental 
rights that may emerge when a high-risk AI system is used in accordance with its intended 
purpose or under conditions of reasonably foreseeable misuse, in particular where such risks 
persist despite the application of other requirements set out in this Section. 
3.   The oversight measures shall be commensurate with the risks, level of autonomy and context 
of use of the high-risk AI system, and shall be ensured through either one or both of the following 
types of measures: 
(a) 
measures identified and built, when technically feasible, into the high-risk AI system by the provider before it is 
placed on the market or put into service; 
(b) 
measures identified by the provider before placing the high-risk AI system on the market or putting it into 
service and that are appropriate to be implemented by the deployer. 
4.   For the purpose of implementing paragraphs 1, 2 and 3, the high-risk AI system shall be 
provided to the deployer in such a way that natural persons to whom human oversight is assigned 
are enabled, as appropriate and proportionate: 
(a) 
to properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly 
monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected 
performance; 
(b) 
to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a 
high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or 
recommendations for decisions to be taken by natural persons; 
(c) 

--- PAGE 24 ---
to correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools 
and methods available; 
(d) 
to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or 
reverse the output of the high-risk AI system; 
(e) 
to intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a 
similar procedure that allows the system to come to a halt in a safe state. 
5.   For high-risk AI systems referred to in point 1(a) of Annex III, the measures referred to in 
paragraph 3 of this Article shall be such as to ensure that, in addition, no action or decision is 
taken by the deployer on the basis of the identification resulting from the system unless that 
identification has been separately verified and confirmed by at least two natural persons with the 
necessary competence, training and authority. 
The requirement for a separate verification by at least two natural persons shall not apply to 
high-risk AI systems used for the purposes of law enforcement, migration, border control or 
asylum, where Union or national law considers the application of this requirement to be 
disproportionate. 
 
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
​
 
 
​
 
​
 
​
 
​
 

--- PAGE 25 ---
​
Chapter III: High-Risk AI Systems 
​
Section 2: Requirements for High-Risk AI Systems 
Article 15: Accuracy, robustness and cybersecurity 
1.   High-risk AI systems shall be designed and developed in such a way that they achieve an 
appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in 
those respects throughout their lifecycle. 
2.   To address the technical aspects of how to measure the appropriate levels of accuracy and 
robustness set out in paragraph 1 and any other relevant performance metrics, the Commission 
shall, in cooperation with relevant stakeholders and organisations such as metrology and 
benchmarking authorities, encourage, as appropriate, the development of benchmarks and 
measurement methodologies. 
3.   The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be 
declared in the accompanying instructions of use. 
4.   High-risk AI systems shall be as resilient as possible regarding errors, faults or 
inconsistencies that may occur within the system or the environment in which the system 
operates, in particular due to their interaction with natural persons or other systems. Technical 
and organisational measures shall be taken in this regard. 
The robustness of high-risk AI systems may be achieved through technical redundancy solutions, 
which may include backup or fail-safe plans. 
High-risk AI systems that continue to learn after being placed on the market or put into service 
shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly 
biased outputs influencing input for future operations (feedback loops), and as to ensure that any 
such feedback loops are duly addressed with appropriate mitigation measures. 
5.   High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter 
their use, outputs or performance by exploiting system vulnerabilities. 
The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be 
appropriate to the relevant circumstances and the risks. 

--- PAGE 26 ---
The technical solutions to address AI specific vulnerabilities shall include, where appropriate, 
measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the 
training data set (data poisoning), or pre-trained components used in training (model poisoning), 
inputs designed to cause the AI model to make a mistake (adversarial examples or model 
evasion), confidentiality attacks or model flaws. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 16: Obligations of providers of high-risk AI systems 
Providers of high-risk AI systems shall: 
(a) 
ensure that their high-risk AI systems are compliant with the requirements set out in Section 2; 
(b) 
indicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying 
documentation, as applicable, their name, registered trade name or registered trade mark, the address at 
which they can be contacted; 
(c) 
have a quality management system in place which complies with Article 17; 
(d) 
keep the documentation referred to in Article 18; 
(e) 
when under their control, keep the logs automatically generated by their high-risk AI systems as referred to in 
Article 19; 
(f) 
ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in 
Article 43, prior to its being placed on the market or put into service; 

--- PAGE 27 ---
(g) 
draw up an EU declaration of conformity in accordance with Article 47; 
(h) 
affix the CE marking to the high-risk AI system or, where that is not possible, on its packaging or its 
accompanying documentation, to indicate conformity with this Regulation, in accordance with Article 48; 
(i) 
comply with the registration obligations referred to in Article 49(1); 
(j) 
take the necessary corrective actions and provide information as required in Article 20; 
(k) 
upon a reasoned request of a national competent authority, demonstrate the conformity of the high-risk AI 
system with the requirements set out in Section 2; 
(l) 
ensure that the high-risk AI system complies with accessibility requirements in accordance with Directives 
(EU) 2016/2102 and (EU) 2019/882. 
 
 
 
 
 
 
 
 

--- PAGE 28 ---
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 17: Quality management system 
1.   Providers of high-risk AI systems shall put a quality management system in place that ensures 
compliance with this Regulation. That system shall be documented in a systematic and orderly 
manner in the form of written policies, procedures and instructions, and shall include at least the 
following aspects: 
(a) 
a strategy for regulatory compliance, including compliance with conformity assessment procedures and 
procedures for the management of modifications to the high-risk AI system; 
(b) 
techniques, procedures and systematic actions to be used for the design, design control and design 
verification of the high-risk AI system; 
(c) 
techniques, procedures and systematic actions to be used for the development, quality control and quality 
assurance of the high-risk AI system; 
(d) 
examination, test and validation procedures to be carried out before, during and after the development of the 
high-risk AI system, and the frequency with which they have to be carried out; 
(e) 
technical specifications, including standards, to be applied and, where the relevant harmonised standards are 
not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to 
ensure that the high-risk AI system complies with those requirements; 
(f) 
systems and procedures for data management, including data acquisition, data collection, data analysis, data 
labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation 
regarding the data that is performed before and for the purpose of the placing on the market or the putting into 
service of high-risk AI systems; 

--- PAGE 29 ---
(g) 
the risk management system referred to in Article 9; 
(h) 
the setting-up, implementation and maintenance of a post-market monitoring system, in accordance with 
Article 72; 
(i) 
procedures related to the reporting of a serious incident in accordance with Article 73; 
(j) 
the handling of communication with national competent authorities, other relevant authorities, including those 
providing or supporting the access to data, notified bodies, other operators, customers or other interested 
parties; 
(k) 
systems and procedures for record-keeping of all relevant documentation and information; 
(l) 
resource management, including security-of-supply related measures; 
(m) 
an accountability framework setting out the responsibilities of the management and other staff with regard to 
all the aspects listed in this paragraph. 
2.   The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size 
of the provider’s organisation. Providers shall, in any event, respect the degree of rigour and the 
level of protection required to ensure the compliance of their high-risk AI systems with this 
Regulation. 
3.   Providers of high-risk AI systems that are subject to obligations regarding quality management 
systems or an equivalent function under relevant sectoral Union law may include the aspects 
listed in paragraph 1 as part of the quality management systems pursuant to that law. 
4.   For providers that are financial institutions subject to requirements regarding their internal 
governance, arrangements or processes under Union financial services law, the obligation to put 

--- PAGE 30 ---
in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of 
this Article, shall be deemed to be fulfilled by complying with the rules on internal governance 
arrangements or processes pursuant to the relevant Union financial services law. To that end, any 
harmonised standards referred to in Article 40 shall be taken into account. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 18: Documentation keeping 
1.   The provider shall, for a period ending 10 years after the high-risk AI system has been placed 
on the market or put into service, keep at the disposal of the national competent authorities: 
(a) 
the technical documentation referred to in Article 11; 
(b) 
the documentation concerning the quality management system referred to in Article 17; 
(c) 
the documentation concerning the changes approved by notified bodies, where applicable; 
(d) 
the decisions and other documents issued by the notified bodies, where applicable; 
(e) 
the EU declaration of conformity referred to in Article 47. 
2.   Each Member State shall determine conditions under which the documentation referred to in 
paragraph 1 remains at the disposal of the national competent authorities for the period indicated 
in that paragraph for the cases when a provider or its authorised representative established on its 
territory goes bankrupt or ceases its activity prior to the end of that period. 
3.   Providers that are financial institutions subject to requirements regarding their internal 
governance, arrangements or processes under Union financial services law shall maintain the 

--- PAGE 31 ---
technical documentation as part of the documentation kept under the relevant Union financial 
services law. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 19: Automatically generated logs 
1.   Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically 
generated by their high-risk AI systems, to the extent such logs are under their control. Without 
prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the 
intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in 
the applicable Union or national law, in particular in Union law on the protection of personal data. 
2.   Providers that are financial institutions subject to requirements regarding their internal 
governance, arrangements or processes under Union financial services law shall maintain the 
logs automatically generated by their high-risk AI systems as part of the documentation kept 
under the relevant financial services law. 
 
 
 
 
 
 
 
 
 
 

--- PAGE 32 ---
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 20: Corrective actions and duty of information 
1.   Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI 
system that they have placed on the market or put into service is not in conformity with this 
Regulation shall immediately take the necessary corrective actions to bring that system into 
conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the 
distributors of the high-risk AI system concerned and, where applicable, the deployers, the 
authorised representative and importers accordingly. 
2.   Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the 
provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration 
with the reporting deployer, where applicable, and inform the market surveillance authorities 
competent for the high-risk AI system concerned and, where applicable, the notified body that 
issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the 
nature of the non-compliance and of any relevant corrective action taken. 
Relevant recitals 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 21: Cooperation with competent authorities 
1.   Providers of high-risk AI systems shall, upon a reasoned request by a competent authority, 
provide that authority all the information and documentation necessary to demonstrate the 
conformity of the high-risk AI system with the requirements set out in Section 2, in a language 
which can be easily understood by the authority in one of the official languages of the institutions 
of the Union as indicated by the Member State concerned. 
2.   Upon a reasoned request by a competent authority, providers shall also give the requesting 
competent authority, as applicable, access to the automatically generated logs of the high-risk AI 
system referred to in Article 12(1), to the extent such logs are under their control. 
3.   Any information obtained by a competent authority pursuant to this Article shall be treated in 
accordance with the confidentiality obligations set out in Article 78. 

--- PAGE 33 ---
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 22: Authorised representatives of providers of high-risk AI 
systems 
1.   Prior to making their high-risk AI systems available on the Union market, providers 
established in third countries shall, by written mandate, appoint an authorised representative 
which is established in the Union. 
2.   The provider shall enable its authorised representative to perform the tasks specified in the 
mandate received from the provider. 
3.   The authorised representative shall perform the tasks specified in the mandate received from 
the provider. It shall provide a copy of the mandate to the market surveillance authorities upon 
request, in one of the official languages of the institutions of the Union, as indicated by the 
competent authority. For the purposes of this Regulation, the mandate shall empower the 
authorised representative to carry out the following tasks: 
(a) 
verify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred 
to in Article 11 have been drawn up and that an appropriate conformity assessment procedure has been 
carried out by the provider; 
(b) 
keep at the disposal of the competent authorities and national authorities or bodies referred to in Article 
74(10), for a period of 10 years after the high-risk AI system has been placed on the market or put into 
service, the contact details of the provider that appointed the authorised representative, a copy of the EU 
declaration of conformity referred to in Article 47, the technical documentation and, if applicable, the certificate 
issued by the notified body; 
(c) 
provide a competent authority, upon a reasoned request, with all the information and documentation, including 
that referred to in point (b) of this subparagraph, necessary to demonstrate the conformity of a high-risk AI 
system with the requirements set out in Section 2, including access to the logs, as referred to in Article 12(1), 
automatically generated by the high-risk AI system, to the extent such logs are under the control of the 
provider; 

--- PAGE 34 ---
(d) 
cooperate with competent authorities, upon a reasoned request, in any action the latter take in relation to the 
high-risk AI system, in particular to reduce and mitigate the risks posed by the high-risk AI system; 
(e) 
where applicable, comply with the registration obligations referred to in Article 49(1), or, if the registration is 
carried out by the provider itself, ensure that the information referred to in point 3 of Section A of Annex VIII is 
correct. 
The mandate shall empower the authorised representative to be addressed, in addition to or 
instead of the provider, by the competent authorities, on all issues related to ensuring compliance 
with this Regulation. 
4.   The authorised representative shall terminate the mandate if it considers or has reason to 
consider the provider to be acting contrary to its obligations pursuant to this Regulation. In such a 
case, it shall immediately inform the relevant market surveillance authority, as well as, where 
applicable, the relevant notified body, about the termination of the mandate and the reasons 
therefor. 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

--- PAGE 35 ---
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 23: Obligations of importers 
1.   Before placing a high-risk AI system on the market, importers shall ensure that the system is 
in conformity with this Regulation by verifying that: 
(a) 
the relevant conformity assessment procedure referred to in Article 43 has been carried out by the provider of 
the high-risk AI system; 
(b) 
the provider has drawn up the technical documentation in accordance with Article 11 and Annex IV; 
(c) 
the system bears the required CE marking and is accompanied by the EU declaration of conformity referred to 
in Article 47 and instructions for use; 
(d) 
the provider has appointed an authorised representative in accordance with Article 22(1). 
2.   Where an importer has sufficient reason to consider that a high-risk AI system is not in 
conformity with this Regulation, or is falsified, or accompanied by falsified documentation, it shall 
not place the system on the market until it has been brought into conformity. Where the high-risk 
AI system presents a risk within the meaning of Article 79(1), the importer shall inform the 
provider of the system, the authorised representative and the market surveillance authorities to 
that effect. 
3.   Importers shall indicate their name, registered trade name or registered trade mark, and the 
address at which they can be contacted on the high-risk AI system and on its packaging or its 
accompanying documentation, where applicable. 
4.   Importers shall ensure that, while a high-risk AI system is under their responsibility, storage or 
transport conditions, where applicable, do not jeopardise its compliance with the requirements set 
out in Section 2. 
5.   Importers shall keep, for a period of 10 years after the high-risk AI system has been placed on 
the market or put into service, a copy of the certificate issued by the notified body, where 
applicable, of the instructions for use, and of the EU declaration of conformity referred to in Article 
47. 

--- PAGE 36 ---
6.   Importers shall provide the relevant competent authorities, upon a reasoned request, with all 
the necessary information and documentation, including that referred to in paragraph 5, to 
demonstrate the conformity of a high-risk AI system with the requirements set out in Section 2 in a 
language which can be easily understood by them. For this purpose, they shall also ensure that 
the technical documentation can be made available to those authorities. 
7.   Importers shall cooperate with the relevant competent authorities in any action those 
authorities take in relation to a high-risk AI system placed on the market by the importers, in 
particular to reduce and mitigate the risks posed by it. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 24: Obligations of distributors 
1.   Before making a high-risk AI system available on the market, distributors shall verify that it 
bears the required CE marking, that it is accompanied by a copy of the EU declaration of 
conformity referred to in Article 47 and instructions for use, and that the provider and the importer 
of that system, as applicable, have complied with their respective obligations as laid down in 
Article 16, points (b) and (c) and Article 23(3). 
2.   Where a distributor considers or has reason to consider, on the basis of the information in its 
possession, that a high-risk AI system is not in conformity with the requirements set out in Section 
2, it shall not make the high-risk AI system available on the market until the system has been 
brought into conformity with those requirements. Furthermore, where the high-risk AI system 
presents a risk within the meaning of Article 79(1), the distributor shall inform the provider or the 
importer of the system, as applicable, to that effect. 
3.   Distributors shall ensure that, while a high-risk AI system is under their responsibility, storage 
or transport conditions, where applicable, do not jeopardise the compliance of the system with the 
requirements set out in Section 2. 
4.   A distributor that considers or has reason to consider, on the basis of the information in its 
possession, a high-risk AI system which it has made available on the market not to be in 
conformity with the requirements set out in Section 2, shall take the corrective actions necessary 
to bring that system into conformity with those requirements, to withdraw it or recall it, or shall 
ensure that the provider, the importer or any relevant operator, as appropriate, takes those 

--- PAGE 37 ---
corrective actions. Where the high-risk AI system presents a risk within the meaning of Article 
79(1), the distributor shall immediately inform the provider or importer of the system and the 
authorities competent for the high-risk AI system concerned, giving details, in particular, of the 
non-compliance and of any corrective actions taken. 
5.   Upon a reasoned request from a relevant competent authority, distributors of a high-risk AI 
system shall provide that authority with all the information and documentation regarding their 
actions pursuant to paragraphs 1 to 4 necessary to demonstrate the conformity of that system 
with the requirements set out in Section 2. 
6.   Distributors shall cooperate with the relevant competent authorities in any action those 
authorities take in relation to a high-risk AI system made available on the market by the 
distributors, in particular to reduce or mitigate the risk posed by it. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 25: Responsibilities along the AI value chain 
1.   Any distributor, importer, deployer or other third-party shall be considered to be a provider of a 
high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of 
the provider under Article 16, in any of the following circumstances: 
(a) 
they put their name or trademark on a high-risk AI system already placed on the market or put into service, 
without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated; 
(b) 
they make a substantial modification to a high-risk AI system that has already been placed on the market or 
has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6; 
(c) 
they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been 
classified as high-risk and has already been placed on the market or put into service in such a way that the AI 
system concerned becomes a high-risk AI system in accordance with Article 6. 
2.   Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the 
AI system on the market or put it into service shall no longer be considered to be a provider of 
that specific AI system for the purposes of this Regulation. That initial provider shall closely 

--- PAGE 38 ---
cooperate with new providers and shall make available the necessary information and provide the 
reasonably expected technical access and other assistance that are required for the fulfilment of 
the obligations set out in this Regulation, in particular regarding the compliance with the 
conformity assessment of high-risk AI systems. This paragraph shall not apply in cases where the 
initial provider has clearly specified that its AI system is not to be changed into a high-risk AI 
system and therefore does not fall under the obligation to hand over the documentation. 
3.   In the case of high-risk AI systems that are safety components of products covered by the 
Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be 
considered to be the provider of the high-risk AI system, and shall be subject to the obligations 
under Article 16 under either of the following circumstances: 
(a) 
the high-risk AI system is placed on the market together with the product under the name or trademark of the 
product manufacturer; 
(b) 
the high-risk AI system is put into service under the name or trademark of the product manufacturer after the 
product has been placed on the market. 
4.   The provider of a high-risk AI system and the third party that supplies an AI system, tools, 
services, components, or processes that are used or integrated in a high-risk AI system shall, by 
written agreement, specify the necessary information, capabilities, technical access and other 
assistance based on the generally acknowledged state of the art, in order to enable the provider 
of the high-risk AI system to fully comply with the obligations set out in this Regulation. This 
paragraph shall not apply to third parties making accessible to the public tools, services, 
processes, or components, other than general-purpose AI models, under a free and open-source 
licence. 
The AI Office may develop and recommend voluntary model terms for contracts between 
providers of high-risk AI systems and third parties that supply tools, services, components or 
processes that are used for or integrated into high-risk AI systems. When developing those 
voluntary model terms, the AI Office shall take into account possible contractual requirements 
applicable in specific sectors or business cases. The voluntary model terms shall be published 
and be available free of charge in an easily usable electronic format. 

--- PAGE 39 ---
5.   Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual 
property rights, confidential business information and trade secrets in accordance with Union and 
national law. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 26: Obligations of deployers of high-risk AI systems 
1.   Deployers of high-risk AI systems shall take appropriate technical and organisational 
measures to ensure they use such systems in accordance with the instructions for use 
accompanying the systems, pursuant to paragraphs 3 and 6. 
2.   Deployers shall assign human oversight to natural persons who have the necessary 
competence, training and authority, as well as the necessary support. 
3.   The obligations set out in paragraphs 1 and 2, are without prejudice to other deployer 
obligations under Union or national law and to the deployer’s freedom to organise its own 
resources and activities for the purpose of implementing the human oversight measures indicated 
by the provider. 
4.   Without prejudice to paragraphs 1 and 2, to the extent the deployer exercises control over the 
input data, that deployer shall ensure that input data is relevant and sufficiently representative in 
view of the intended purpose of the high-risk AI system. 
5.   Deployers shall monitor the operation of the high-risk AI system on the basis of the 
instructions for use and, where relevant, inform providers in accordance with Article 72. Where 
deployers have reason to consider that the use of the high-risk AI system in accordance with the 
instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they 
shall, without undue delay, inform the provider or distributor and the relevant market surveillance 
authority, and shall suspend the use of that system. Where deployers have identified a serious 
incident, they shall also immediately inform first the provider, and then the importer or distributor 
and the relevant market surveillance authorities of that incident. If the deployer is not able to 
reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover 
sensitive operational data of deployers of AI systems which are law enforcement authorities. 

--- PAGE 40 ---
For deployers that are financial institutions subject to requirements regarding their internal 
governance, arrangements or processes under Union financial services law, the monitoring 
obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the 
rules on internal governance arrangements, processes and mechanisms pursuant to the relevant 
financial service law. 
6.   Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk 
AI system to the extent such logs are under their control, for a period appropriate to the intended 
purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable 
Union or national law, in particular in Union law on the protection of personal data. 
Deployers that are financial institutions subject to requirements regarding their internal 
governance, arrangements or processes under Union financial services law shall maintain the 
logs as part of the documentation kept pursuant to the relevant Union financial service law. 
7.   Before putting into service or using a high-risk AI system at the workplace, deployers who are 
employers shall inform workers’ representatives and the affected workers that they will be subject 
to the use of the high-risk AI system. This information shall be provided, where applicable, in 
accordance with the rules and procedures laid down in Union and national law and practice on 
information of workers and their representatives. 
8.   Deployers of high-risk AI systems that are public authorities, or Union institutions, bodies, 
offices or agencies shall comply with the registration obligations referred to in Article 49. When 
such deployers find that the high-risk AI system that they envisage using has not been registered 
in the EU database referred to in Article 71, they shall not use that system and shall inform the 
provider or the distributor. 
9.   Where applicable, deployers of high-risk AI systems shall use the information provided under 
Article 13 of this Regulation to comply with their obligation to carry out a data protection impact 
assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 
2016/680. 
10.   Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the 
targeted search of a person suspected or convicted of having committed a criminal offence, the 
deployer of a high-risk AI system for post-remote biometric identification shall request an 
authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or 
an administrative authority whose decision is binding and subject to judicial review, for the use of 

--- PAGE 41 ---
that system, except when it is used for the initial identification of a potential suspect based on 
objective and verifiable facts directly linked to the offence. Each use shall be limited to what is 
strictly necessary for the investigation of a specific criminal offence. 
If the authorisation requested pursuant to the first subparagraph is rejected, the use of the 
post-remote biometric identification system linked to that requested authorisation shall be stopped 
with immediate effect and the personal data linked to the use of the high-risk AI system for which 
the authorisation was requested shall be deleted. 
In no case shall such high-risk AI system for post-remote biometric identification be used for law 
enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal 
proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the 
search for a specific missing person. It shall be ensured that no decision that produces an 
adverse legal effect on a person may be taken by the law enforcement authorities based solely on 
the output of such post-remote biometric identification systems. 
This paragraph is without prejudice to Article 9 of Regulation (EU) 2016/679 and Article 10 of 
Directive (EU) 2016/680 for the processing of biometric data. 
Regardless of the purpose or deployer, each use of such high-risk AI systems shall be 
documented in the relevant police file and shall be made available to the relevant market 
surveillance authority and the national data protection authority upon request, excluding the 
disclosure of sensitive operational data related to law enforcement. This subparagraph shall be 
without prejudice to the powers conferred by Directive (EU) 2016/680 on supervisory authorities. 
Deployers shall submit annual reports to the relevant market surveillance and national data 
protection authorities on their use of post-remote biometric identification systems, excluding the 
disclosure of sensitive operational data related to law enforcement. The reports may be 
aggregated to cover more than one deployment. 
Member States may introduce, in accordance with Union law, more restrictive laws on the use of 
post-remote biometric identification systems. 
11.   Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred 
to in Annex III that make decisions or assist in making decisions related to natural persons shall 

--- PAGE 42 ---
inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk 
AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply. 
12.   Deployers shall cooperate with the relevant competent authorities in any action those 
authorities take in relation to the high-risk AI system in order to implement this Regulation. 
​
Chapter III: High-Risk AI Systems 
​
Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties 
Article 27: Fundamental rights impact assessment for high-risk AI 
systems 
1.   Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of 
high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that 
are bodies governed by public law, or are private entities providing public services, and deployers 
of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an 
assessment of the impact on fundamental rights that the use of such system may produce. For 
that purpose, deployers shall perform an assessment consisting of: 
(a) 
a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended 
purpose; 
(b) 
a description of the period of time within which, and the frequency with which, each high-risk AI system is 
intended to be used; 
(c) 
the categories of natural persons and groups likely to be affected by its use in the specific context; 
(d) 
the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons 
identified pursuant to point (c) of this paragraph, taking into account the information given by the provider 
pursuant to Article 13; 
(e) 
a description of the implementation of human oversight measures, according to the instructions for use; 
(f) 
the measures to be taken in the case of the materialisation of those risks, including the arrangements for 
internal governance and complaint mechanisms. 

--- PAGE 43 ---
2.   The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The 
deployer may, in similar cases, rely on previously conducted fundamental rights impact 
assessments or existing impact assessments carried out by provider. If, during the use of the 
high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has 
changed or is no longer up to date, the deployer shall take the necessary steps to update the 
information. 
3.   Once the assessment referred to in paragraph 1 of this Article has been performed, the 
deployer shall notify the market surveillance authority of its results, submitting the filled-out 
template referred to in paragraph 5 of this Article as part of the notification. In the case referred to 
in Article 46(1), deployers may be exempt from that obligation to notify. 
4.   If any of the obligations laid down in this Article is already met through the data protection 
impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of 
Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of 
this Article shall complement that data protection impact assessment. 
5.   The AI Office shall develop a template for a questionnaire, including through an automated 
tool, to facilitate deployers in complying with their obligations under this Article in a simplified 
manner. 
 
 
 
 
 
 
 
 
 
 
 
 
 

--- PAGE 44 ---
Recital 27 
While the risk-based approach is the basis for a proportionate and effective set of binding rules, it 
is important to recall the 2019 Ethics guidelines for trustworthy AI developed by the independent 
AI HLEG appointed by the Commission. In those guidelines, the AI HLEG developed seven 
non-binding ethical principles for AI which are intended to help ensure that AI is trustworthy and 
ethically sound. The seven principles include human agency and oversight; technical robustness 
and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; 
societal and environmental well-being and accountability. Without prejudice to the legally binding 
requirements of this Regulation and any other applicable Union law, those guidelines contribute to 
the design of coherent, trustworthy and human-centric AI, in line with the Charter and with the 
values on which the Union is founded. According to the guidelines of the AI HLEG, human agency 
and oversight means that AI systems are developed and used as a tool that serves people, 
respects human dignity and personal autonomy, and that is functioning in a way that can be 
appropriately controlled and overseen by humans. Technical robustness and safety means that AI 
systems are developed and used in a way that allows robustness in the case of problems and 
resilience against attempts to alter the use or performance of the AI system so as to allow 
unlawful use by third parties, and minimise unintended harm. Privacy and data governance 
means that AI systems are developed and used in accordance with privacy and data protection 
rules, while processing data that meets high standards in terms of quality and integrity. 
Transparency means that AI systems are developed and used in a way that allows appropriate 
traceability and explainability, while making humans aware that they communicate or interact with 
an AI system, as well as duly informing deployers of the capabilities and limitations of that AI 
system and affected persons about their rights. Diversity, non-discrimination and fairness means 
that AI systems are developed and used in a way that includes diverse actors and promotes equal 
access, gender equality and cultural diversity, while avoiding discriminatory impacts and unfair 
biases that are prohibited by Union or national law. Social and environmental well-being means 
that AI systems are developed and used in a sustainable and environmentally friendly manner as 
well as in a way to benefit all human beings, while monitoring and assessing the long-term 
impacts on the individual, society and democracy. The application of those principles should be 
translated, when possible, in the design and use of AI models. They should in any case serve as 
a basis for the drafting of codes of conduct under this Regulation. All stakeholders, including 

--- PAGE 45 ---
industry, academia, civil society and standardisation organisations, are encouraged to take into 
account, as appropriate, the ethical principles for the development of voluntary best practices and 
standards. 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
​
Article 14: Human oversight 
​
Article 15: Accuracy, robustness and cybersecurity 
Recital 28 
Aside from the many beneficial uses of AI, it can also be misused and provide novel and powerful 
tools for manipulative, exploitative and social control practices. Such practices are particularly 
harmful and abusive and should be prohibited because they contradict Union values of respect for 
human dignity, freedom, equality, democracy and the rule of law and fundamental rights enshrined 
in the Charter, including the right to non-discrimination, to data protection and to privacy and the 
rights of the child. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
Recital 29 
AI-enabled manipulative techniques can be used to persuade persons to engage in unwanted 
behaviours, or to deceive them by nudging them into decisions in a way that subverts and impairs 
their autonomy, decision-making and free choices. The placing on the market, the putting into 
service or the use of certain AI systems with the objective to or the effect of materially distorting 
human behaviour, whereby significant harms, in particular having sufficiently important adverse 
impacts on physical, psychological health or financial interests are likely to occur, are particularly 
dangerous and should therefore be prohibited. Such AI systems deploy subliminal components 
such as audio, image, video stimuli that persons cannot perceive, as those stimuli are beyond 
human perception, or other manipulative or deceptive techniques that subvert or impair person’s 

--- PAGE 46 ---
autonomy, decision-making or free choice in ways that people are not consciously aware of those 
techniques or, where they are aware of them, can still be deceived or are not able to control or 
resist them. This could be facilitated, for example, by machine-brain interfaces or virtual reality as 
they allow for a higher degree of control of what stimuli are presented to persons, insofar as they 
may materially distort their behaviour in a significantly harmful manner. In addition, AI systems 
may also otherwise exploit the vulnerabilities of a person or a specific group of persons due to 
their age, disability within the meaning of Directive (EU) 2019/882 of the European Parliament 
and of the Council, or a specific social or economic situation that is likely to make those persons 
more vulnerable to exploitation such as persons living in extreme poverty, ethnic or religious 
minorities. Such AI systems can be placed on the market, put into service or used with the 
objective to or the effect of materially distorting the behaviour of a person and in a manner that 
causes or is reasonably likely to cause significant harm to that or another person or groups of 
persons, including harms that may be accumulated over time and should therefore be prohibited. 
It may not be possible to assume that there is an intention to distort behaviour where the 
distortion results from factors external to the AI system which are outside the control of the 
provider or the deployer, namely factors that may not be reasonably foreseeable and therefore not 
possible for the provider or the deployer of the AI system to mitigate. In any case, it is not 
necessary for the provider or the deployer to have the intention to cause significant harm, 
provided that such harm results from the manipulative or exploitative AI-enabled practices. The 
prohibitions for such AI practices are complementary to the provisions contained in Directive 
2005/29/EC of the European Parliament and of the Council, in particular unfair commercial 
practices leading to economic or financial harms to consumers are prohibited under all 
circumstances, irrespective of whether they are put in place through AI systems or otherwise. The 
prohibitions of manipulative and exploitative practices in this Regulation should not affect lawful 
practices in the context of medical treatment such as psychological treatment of a mental disease 
or physical rehabilitation, when those practices are carried out in accordance with the applicable 
law and medical standards, for example explicit consent of the individuals or their legal 
representatives. In addition, common and legitimate commercial practices, for example in the field 
of advertising, that comply with the applicable law should not, in themselves, be regarded as 
constituting harmful manipulative AI-enabled practices. 
This Recital relates to 

--- PAGE 47 ---
​
Article 5: Prohibited AI practices 
Recital 30 
Biometric categorisation systems that are based on natural persons’ biometric data, such as an 
individual person’s face or fingerprint, to deduce or infer an individuals’ political opinions, trade 
union membership, religious or philosophical beliefs, race, sex life or sexual orientation should be 
prohibited. That prohibition should not cover the lawful labelling, filtering or categorisation of 
biometric data sets acquired in line with Union or national law according to biometric data, such 
as the sorting of images according to hair colour or eye colour, which can for example be used in 
the area of law enforcement. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
Recital 31 
AI systems providing social scoring of natural persons by public or private actors may lead to 
discriminatory outcomes and the exclusion of certain groups. They may violate the right to dignity 
and non-discrimination and the values of equality and justice. Such AI systems evaluate or 
classify natural persons or groups thereof on the basis of multiple data points related to their 
social behaviour in multiple contexts or known, inferred or predicted personal or personality 
characteristics over certain periods of time. The social score obtained from such AI systems may 
lead to the detrimental or unfavourable treatment of natural persons or whole groups thereof in 
social contexts, which are unrelated to the context in which the data was originally generated or 
collected or to a detrimental treatment that is disproportionate or unjustified to the gravity of their 
social behaviour. AI systems entailing such unacceptable scoring practices and leading to such 
detrimental or unfavourable outcomes should therefore be prohibited. That prohibition should not 
affect lawful evaluation practices of natural persons that are carried out for a specific purpose in 
accordance with Union and national law. 
This Recital relates to 
​
Article 5: Prohibited AI practices 

--- PAGE 48 ---
Recital 32 
The use of AI systems for ‘real-time’ remote biometric identification of natural persons in publicly 
accessible spaces for the purpose of law enforcement is particularly intrusive to the rights and 
freedoms of the concerned persons, to the extent that it may affect the private life of a large part 
of the population, evoke a feeling of constant surveillance and indirectly dissuade the exercise of 
the freedom of assembly and other fundamental rights. Technical inaccuracies of AI systems 
intended for the remote biometric identification of natural persons can lead to biased results and 
entail discriminatory effects. Such possible biased results and discriminatory effects are 
particularly relevant with regard to age, ethnicity, race, sex or disabilities. In addition, the 
immediacy of the impact and the limited opportunities for further checks or corrections in relation 
to the use of such systems operating in real-time carry heightened risks for the rights and 
freedoms of the persons concerned in the context of, or impacted by, law enforcement activities. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
Recital 33 
The use of those systems for the purpose of law enforcement should therefore be prohibited, 
except in exhaustively listed and narrowly defined situations, where the use is strictly necessary 
to achieve a substantial public interest, the importance of which outweighs the risks. Those 
situations involve the search for certain victims of crime including missing persons; certain threats 
to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or 
identification of perpetrators or suspects of the criminal offences listed in an annex to this 
Regulation, where those criminal offences are punishable in the Member State concerned by a 
custodial sentence or a detention order for a maximum period of at least four years and as they 
are defined in the law of that Member State. Such a threshold for the custodial sentence or 
detention order in accordance with national law contributes to ensuring that the offence should be 
serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. 
Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 
criminal offences listed in the Council Framework Decision 2002/584/JHA, taking into account that 
some of those offences are, in practice, likely to be more relevant than others, in that the recourse 

--- PAGE 49 ---
to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to 
highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator 
or suspect of the different criminal offences listed and having regard to the likely differences in the 
seriousness, probability and scale of the harm or possible negative consequences. An imminent 
threat to life or the physical safety of natural persons could also result from a serious disruption of 
critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European 
Parliament and of the Council, where the disruption or destruction of such critical infrastructure 
would result in an imminent threat to life or the physical safety of a person, including through 
serious harm to the provision of basic supplies to the population or to the exercise of the core 
function of the State. In addition, this Regulation should preserve the ability for law enforcement, 
border control, immigration or asylum authorities to carry out identity checks in the presence of 
the person concerned in accordance with the conditions set out in Union and national law for such 
checks. In particular, law enforcement, border control, immigration or asylum authorities should be 
able to use information systems, in accordance with Union or national law, to identify persons 
who, during an identity check, either refuse to be identified or are unable to state or prove their 
identity, without being required by this Regulation to obtain prior authorisation. This could be, for 
example, a person involved in a crime, being unwilling, or unable due to an accident or a medical 
condition, to disclose their identity to law enforcement authorities. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
Recital 34 
In order to ensure that those systems are used in a responsible and proportionate manner, it is 
also important to establish that, in each of those exhaustively listed and narrowly defined 
situations, certain elements should be taken into account, in particular as regards the nature of 
the situation giving rise to the request and the consequences of the use for the rights and 
freedoms of all persons concerned and the safeguards and conditions provided for with the use. 
In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible 

--- PAGE 50 ---
spaces for the purpose of law enforcement should be deployed only to confirm the specifically 
targeted individual’s identity and should be limited to what is strictly necessary concerning the 
period of time, as well as the geographic and personal scope, having regard in particular to the 
evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time 
remote biometric identification system in publicly accessible spaces should be authorised only if 
the relevant law enforcement authority has completed a fundamental rights impact assessment 
and, unless provided otherwise in this Regulation, has registered the system in the database as 
set out in this Regulation. The reference database of persons should be appropriate for each use 
case in each of the situations mentioned above. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
Recital 35 
Each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for 
the purpose of law enforcement should be subject to an express and specific authorisation by a 
judicial authority or by an independent administrative authority of a Member State whose decision 
is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system 
with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly 
justified situations on grounds of urgency, namely in situations where the need to use the systems 
concerned is such as to make it effectively and objectively impossible to obtain an authorisation 
before commencing the use of the AI system. In such situations of urgency, the use of the AI 
system should be restricted to the absolute minimum necessary and should be subject to 
appropriate safeguards and conditions, as determined in national law and specified in the context 
of each individual urgent use case by the law enforcement authority itself. In addition, the law 
enforcement authority should in such situations request such authorisation while providing the 
reasons for not having been able to request it earlier, without undue delay and at the latest within 
24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems 
linked to that authorisation should cease with immediate effect and all the data related to such 
use should be discarded and deleted. Such data includes input data directly acquired by an AI 
system in the course of the use of such system as well as the results and outputs of the use 

--- PAGE 51 ---
linked to that authorisation. It should not include input that is legally acquired in accordance with 
another Union or national law. In any case, no decision producing an adverse legal effect on a 
person should be taken based solely on the output of the remote biometric identification system. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
 
 
 
 
 
 
Recital 36 
In order to carry out their tasks in accordance with the requirements set out in this Regulation as 
well as in national rules, the relevant market surveillance authority and the national data 
protection authority should be notified of each use of the real-time biometric identification system. 
Market surveillance authorities and the national data protection authorities that have been notified 
should submit to the Commission an annual report on the use of real-time biometric identification 
systems. 
                                                        This Recital relates to 
                                                     Article 5: Prohibited AI practices 
      Article 74: Market surveillance and control of AI systems in the Union market 
 
 
Recital 37 
Furthermore, it is appropriate to provide, within the exhaustive framework set by this Regulation 
that such use in the territory of a Member State in accordance with this Regulation should only be 
possible where and in as far as the Member State concerned has decided to expressly provide for 
the possibility to authorise such use in its detailed rules of national law. Consequently, Member 

--- PAGE 52 ---
States remain free under this Regulation not to provide for such a possibility at all or to only 
provide for such a possibility in respect of some of the objectives capable of justifying authorised 
use identified in this Regulation. Such national rules should be notified to the Commission within 
30 days of their adoption. 
This Recital relates to 
Article 5: Prohibited AI practices 
 
 
 
 
 
Recital 38 
The use of AI systems for real-time remote biometric identification of natural persons in publicly 
accessible spaces for the purpose of law enforcement necessarily involves the processing of 
biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, 
which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the 
processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating 
such use and the processing of biometric data involved in an exhaustive manner. Therefore, such 
use and processing should be possible only in as far as it is compatible with the framework set by 
this Regulation, without there being scope, outside that framework, for the competent authorities, 
where they act for purpose of law enforcement, to use such systems and process such data in 
connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, 
this Regulation is not intended to provide the legal basis for the processing of personal data under 
Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification 
systems in publicly accessible spaces for purposes other than law enforcement, including by 
competent authorities, should not be covered by the specific framework regarding such use for 
the purpose of law enforcement set by this Regulation. Such use for purposes other than law 
enforcement should therefore not be subject to the requirement of an authorisation under this 

--- PAGE 53 ---
Regulation and the applicable detailed rules of national law that may give effect to that 
authorisation. 
This Recital relates to 
      Article 5: Prohibited AI practices 
 
 
 
 
 
 
 
 
Recital 39 
Any processing of biometric data and other personal data involved in the use of AI systems for 
biometric identification, other than in connection to the use of real-time remote biometric 
identification systems in publicly accessible spaces for the purpose of law enforcement as 
regulated by this Regulation, should continue to comply with all requirements resulting from 
Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of 
Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing 
of biometric data subject to limited exceptions as provided in those Articles. In the application of 
Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes 
other than law enforcement has already been subject to prohibition decisions by national data 
protection authorities. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
 

--- PAGE 54 ---
 
 
 
 
 
 
 
 
 
 
 
                                               Recital 40 
In accordance with Article 6a of Protocol No 21 on the position of the United Kingdom and Ireland 
in respect of the area of freedom, security and justice, as annexed to the TEU and to the TFEU, 
Ireland is not bound by the rules laid down in Article 5(1), first subparagraph, point (g), to the 
extent it applies to the use of biometric categorisation systems for activities in the field of police 
cooperation and judicial cooperation in criminal matters, Article 5(1), first subparagraph, point (d), 
to the extent it applies to the use of AI systems covered by that provision, Article 5(1), first 
subparagraph, point (h), Article 5(2) to (6) and Article 26(10) of this Regulation adopted on the 
basis of Article 16 TFEU which relate to the processing of personal data by the Member States 
when carrying out activities falling within the scope of Chapter 4 or Chapter 5 of Title V of Part 
Three of the TFEU, where Ireland is not bound by the rules governing the forms of judicial 
cooperation in criminal matters or police cooperation which require compliance with the provisions 
laid down on the basis of Article 16 TFEU. 
This Recital relates to 
​
                                                     Article 5: Prohibited AI practices 

--- PAGE 55 ---
Recital 41 
In accordance with Articles 2 and 2a of Protocol No 22 on the position of Denmark, annexed to 
the TEU and to the TFEU, Denmark is not bound by rules laid down in Article 5(1), first 
subparagraph, point (g), to the extent it applies to the use of biometric categorisation systems for 
activities in the field of police cooperation and judicial cooperation in criminal matters, Article 5(1), 
first subparagraph, point (d), to the extent it applies to the use of AI systems covered by that 
provision, Article 5(1), first subparagraph, point (h), (2) to (6) and Article 26(10) of this Regulation 
adopted on the basis of Article 16 TFEU, or subject to their application, which relate to the 
processing of personal data by the Member States when carrying out activities falling within the 
scope of Chapter 4 or Chapter 5 of Title V of Part Three of the TFEU. 
This Recital relates to 
​
                                                      Article 5: Prohibited AI practices 
 
Recital 42 
In line with the presumption of innocence, natural persons in the Union should always be judged 
on their actual behaviour. Natural persons should never be judged on AI-predicted behaviour 
based solely on their profiling, personality traits or characteristics, such as nationality, place of 
birth, place of residence, number of children, level of debt or type of car, without a reasonable 
suspicion of that person being involved in a criminal activity based on objective verifiable facts 
and without human assessment thereof. Therefore, risk assessments carried out with regard to 
natural persons in order to assess the likelihood of their offending or to predict the occurrence of 
an actual or potential criminal offence based solely on profiling them or on assessing their 
personality traits and characteristics should be prohibited. In any case, that prohibition does not 
refer to or touch upon risk analytics that are not based on the profiling of individuals or on the 
personality traits and characteristics of individuals, such as AI systems using risk analytics to 
assess the likelihood of financial fraud by undertakings on the basis of suspicious transactions or 
risk analytic tools to predict the likelihood of the localisation of narcotics or illicit goods by customs 
authorities, for example on the basis of known trafficking routes. 
This Recital relates to 

--- PAGE 56 ---
​
                                                   Article 5: Prohibited AI practices 
 
Recital 43 
The placing on the market, the putting into service for that specific purpose, or the use of AI 
systems that create or expand facial recognition databases through the untargeted scraping of 
facial images from the internet or CCTV footage, should be prohibited because that practice adds 
to the feeling of mass surveillance and can lead to gross violations of fundamental rights, 
including the right to privacy. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
Recital 44 
There are serious concerns about the scientific basis of AI systems aiming to identify or infer 
emotions, particularly as expression of emotions vary considerably across cultures and situations, 
and even within a single individual. Among the key shortcomings of such systems are the limited 
reliability, the lack of specificity and the limited generalisability. Therefore, AI systems identifying 
or inferring emotions or intentions of natural persons on the basis of their biometric data may lead 
to discriminatory outcomes and can be intrusive to the rights and freedoms of the concerned 
persons. Considering the imbalance of power in the context of work or education, combined with 
the intrusive nature of these systems, such systems could lead to detrimental or unfavourable 
treatment of certain natural persons or whole groups thereof. Therefore, the placing on the 
market, the putting into service, or the use of AI systems intended to be used to detect the 
emotional state of individuals in situations related to the workplace and education should be 
prohibited. That prohibition should not cover AI systems placed on the market strictly for medical 
or safety reasons, such as systems intended for therapeutical use. 
This Recital relates to 
​
Article 5: Prohibited AI practices 

--- PAGE 57 ---
 
Recital 45 
Practices that are prohibited by Union law, including data protection law, non-discrimination law, 
consumer protection law, and competition law, should not be affected by this Regulation. 
This Recital relates to 
​
Article 5: Prohibited AI practices 
 
 
 
 
 
 
 
 
Recital 46 
High-risk AI systems should only be placed on the Union market, put into service or used if they 
comply with certain mandatory requirements. Those requirements should ensure that high-risk AI 
systems available in the Union or whose output is otherwise used in the Union do not pose 
unacceptable risks to important Union public interests as recognised and protected by Union law. 
On the basis of the New Legislative Framework, as clarified in the Commission notice ‘The “Blue 
Guide” on the implementation of EU product rules 2022’(20), the general rule is that more than 
one legal act of Union harmonisation legislation, such as Regulations (EU) 2017/745(21)and (EU) 
2017/746(22)of the European Parliament and of the Council or Directive 2006/42/EC of the 
European Parliament and of the Council(23), may be applicable to one product, since the making 
available or putting into service can take place only when the product complies with all applicable 
Union harmonisation legislation. To ensure consistency and avoid unnecessary administrative 
burdens or costs, providers of a product that contains one or more high-risk AI systems, to which 
the requirements of this Regulation and of the Union harmonisation legislation listed in an annex 
to this Regulation apply, should have flexibility with regard to operational decisions on how to 
ensure compliance of a product that contains one or more AI systems with all applicable 
requirements of the Union harmonisation legislation in an optimal manner. AI systems identified 

--- PAGE 58 ---
as high-risk should be limited to those that have a significant harmful impact on the health, safety 
and fundamental rights of persons in the Union and such limitation should minimise any potential 
restriction to international trade. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 8: Compliance with the requirements 
 
 
 
 
 
 
 
 
 
 
Recital 47 
AI systems could have an adverse impact on the health and safety of persons, in particular when 
such systems operate as safety components of products. Consistent with the objectives of Union 
harmonisation legislation to facilitate the free movement of products in the internal market and to 
ensure that only safe and otherwise compliant products find their way into the market, it is 
important that the safety risks that may be generated by a product as a whole due to its digital 
components, including AI systems, are duly prevented and mitigated. For instance, increasingly 
autonomous robots, whether in the context of manufacturing or personal assistance and care 
should be able to safely operate and performs their functions in complex environments. Similarly, 
in the health sector where the stakes for life and health are particularly high, increasingly 
sophisticated diagnostics systems and systems supporting human decisions should be reliable 
and accurate. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 

--- PAGE 59 ---
Recital 48 
The extent of the adverse impact caused by the AI system on the fundamental rights protected by 
the Charter is of particular relevance when classifying an AI system as high risk. Those rights 
include the right to human dignity, respect for private and family life, protection of personal data, 
freedom of expression and information, freedom of assembly and of association, the right to 
non-discrimination, the right to education, consumer protection, workers’ rights, the rights of 
persons with disabilities, gender equality, intellectual property rights, the right to an effective 
remedy and to a fair trial, the right of defence and the presumption of innocence, and the right to 
good administration. In addition to those rights, it is important to highlight the fact that children 
have specific rights as enshrined in Article 24 of the Charter and in the United Nations Convention 
on the Rights of the Child, further developed in the UNCRC General Comment No 25 as regards 
the digital environment, both of which require consideration of the children’s vulnerabilities and 
provision of such protection and care as necessary for their well-being. The fundamental right to a 
high level of environmental protection enshrined in the Charter and implemented in Union policies 
should also be considered when assessing the severity of the harm that an AI system can cause, 
including in relation to the health and safety of persons. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 8: Compliance with the requirements 
 
Recital 49 
As regards high-risk AI systems that are safety components of products or systems, or which are 
themselves products or systems falling within the scope of Regulation (EC) No 300/2008 of the 
European Parliament and of the Council(24), Regulation (EU) No 167/2013 of the European 
Parliament and of the Council(25), Regulation (EU) No 168/2013 of the European Parliament and 
of the Council(26), Directive 2014/90/EU of the European Parliament and of the Council(27), 
Directive (EU) 2016/797 of the European Parliament and of the Council(28), Regulation (EU) 
2018/858 of the European Parliament and of the Council(29), Regulation (EU) 2018/1139 of the 
European Parliament and of the Council(30), and Regulation (EU) 2019/2144 of the European 
Parliament and of the Council(31), it is appropriate to amend those acts to ensure that the 

--- PAGE 60 ---
Commission takes into account, on the basis of the technical and regulatory specificities of each 
sector, and without interfering with existing governance, conformity assessment and enforcement 
mechanisms and authorities established therein, the mandatory requirements for high-risk AI 
systems laid down in this Regulation when adopting any relevant delegated or implementing acts 
on the basis of those acts. 
 
 
 
 
 
 
 
 
 
 
 
 
 
Recital 50 
As regards AI systems that are safety components of products, or which are themselves products, 
falling within the scope of certain Union harmonisation legislation listed in an annex to this 
Regulation, it is appropriate to classify them as high-risk under this Regulation if the product 
concerned undergoes the conformity assessment procedure with a third-party conformity 
assessment body pursuant to that relevant Union harmonisation legislation. In particular, such 
products are machinery, toys, lifts, equipment and protective systems intended for use in 
potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft 
equipment, cableway installations, appliances burning gaseous fuels, medical devices,in 
vitrodiagnostic medical devices, automotive and aviation. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 46: Derogation from conformity assessment procedure 
 

--- PAGE 61 ---
Recital 51 
The classification of an AI system as high-risk pursuant to this Regulation should not necessarily 
mean that the product whose safety component is the AI system, or the AI system itself as a 
product, is considered to be high-risk under the criteria established in the relevant Union 
harmonisation legislation that applies to the product. This is, in particular, the case for Regulations 
(EU) 2017/745 and (EU) 2017/746, where a third-party conformity assessment is provided for 
medium-risk and high-risk products. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 46: Derogation from conformity assessment procedure 
 
 
 
 
 
 
Recital 52 
As regards stand-alone AI systems, namely high-risk AI systems other than those that are safety 
components of products, or that are themselves products, it is appropriate to classify them as 
high-risk if, in light of their intended purpose, they pose a high risk of harm to the health and 
safety or the fundamental rights of persons, taking into account both the severity of the possible 
harm and its probability of occurrence and they are used in a number of specifically pre-defined 
areas specified in this Regulation. The identification of those systems is based on the same 
methodology and criteria envisaged also for any future amendments of the list of high-risk AI 
systems that the Commission should be empowered to adopt, via delegated acts, to take into 
account the rapid pace of technological development, as well as the potential changes in the use 
of AI systems. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 7: Amendments to Annex III 

--- PAGE 62 ---
Recital 53 
It is also important to clarify that there may be specific cases in which AI systems referred to in 
pre-defined areas specified in this Regulation do not lead to a significant risk of harm to the legal 
interests protected under those areas because they do not materially influence the 
decision-making or do not harm those interests substantially. For the purposes of this Regulation, 
an AI system that does not materially influence the outcome of decision-making should be 
understood to be an AI system that does not have an impact on the substance, and thereby the 
outcome, of decision-making, whether human or automated. An AI system that does not 
materially influence the outcome of decision-making could include situations in which one or more 
of the following conditions are fulfilled. The first such condition should be that the AI system is 
intended to perform a narrow procedural task, such as an AI system that transforms unstructured 
data into structured data, an AI system that classifies incoming documents into categories or an 
AI system that is used to detect duplicates among a large number of applications. Those tasks 
are of such narrow and limited nature that they pose only limited risks which are not increased 
through the use of an AI system in a context that is listed as a high-risk use in an annex to this 
Regulation. The second condition should be that the task performed by the AI system is intended 
to improve the result of a previously completed human activity that may be relevant for the 
purposes of the high-risk uses listed in an annex to this Regulation. Considering those 
characteristics, the AI system provides only an additional layer to a human activity with 
consequently lowered risk. That condition would, for example, apply to AI systems that are 
intended to improve the language used in previously drafted documents, for example in relation to 
professional tone, academic style of language or by aligning text to a certain brand messaging. 
The third condition should be that the AI system is intended to detect decision-making patterns or 
deviations from prior decision-making patterns. The risk would be lowered because the use of the 
AI system follows a previously completed human assessment which it is not meant to replace or 
influence, without proper human review. Such AI systems include for instance those that, given a 
certain grading pattern of a teacher, can be used to checkex postwhether the teacher may have 
deviated from the grading pattern so as to flag potential inconsistencies or anomalies. The fourth 
condition should be that the AI system is intended to perform a task that is only preparatory to an 
assessment relevant for the purposes of the AI systems listed in an annex to this Regulation, thus 

--- PAGE 63 ---
making the possible impact of the output of the system very low in terms of representing a risk for 
the assessment to follow. That condition covers, inter alia, smart solutions for file handling, which 
include various functions from indexing, searching, text and speech processing or linking data to 
other data sources, or AI systems used for translation of initial documents. In any case, AI 
systems used in high-risk use-cases listed in an annex to this Regulation should be considered to 
pose significant risks of harm to the health, safety or fundamental rights if the AI system implies 
profiling within the meaning of Article 4, point (4) of Regulation (EU) 2016/679 or Article 3, point 
(4) of Directive (EU) 2016/680 or Article 3, point (5) of Regulation (EU) 2018/1725. To ensure 
traceability and transparency, a provider who considers that an AI system is not high-risk on the 
basis of the conditions referred to above should draw up documentation of the assessment before 
that system is placed on the market or put into service and should provide that documentation to 
national competent authorities upon request. Such a provider should be obliged to register the AI 
system in the EU database established under this Regulation. With a view to providing further 
guidance for the practical implementation of the conditions under which the AI systems listed in 
an annex to this Regulation are, on an exceptional basis, non-high-risk, the Commission should, 
after consulting the Board, provide guidelines specifying that practical implementation, completed 
by a comprehensive list of practical examples of use cases of AI systems that are high-risk and 
use cases that are not. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 7: Amendments to Annex III 
Recital 54 
As biometric data constitutes a special category of personal data, it is appropriate to classify as 
high-risk several critical-use cases of biometric systems, insofar as their use is permitted under 
relevant Union and national law. Technical inaccuracies of AI systems intended for the remote 
biometric identification of natural persons can lead to biased results and entail discriminatory 
effects. The risk of such biased results and discriminatory effects is particularly relevant with 
regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should 

--- PAGE 64 ---
therefore be classified as high-risk in view of the risks that they pose. Such a classification 
excludes AI systems intended to be used for biometric verification, including authentication, the 
sole purpose of which is to confirm that a specific natural person is who that person claims to be 
and to confirm the identity of a natural person for the sole purpose of having access to a service, 
unlocking a device or having secure access to premises. In addition, AI systems intended to be 
used for biometric categorisation according to sensitive attributes or characteristics protected 
under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these 
are not prohibited under this Regulation, and emotion recognition systems that are not prohibited 
under this Regulation, should be classified as high-risk. Biometric systems which are intended to 
be used solely for the purpose of enabling cybersecurity and personal data protection measures 
should not be considered to be high-risk AI systems. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 55 
As regards the management and operation of critical infrastructure, it is appropriate to classify as 
high-risk the AI systems intended to be used as safety components in the management and 
operation of critical digital infrastructure as listed in point (8) of the Annex to Directive (EU) 
2022/2557, road traffic and the supply of water, gas, heating and electricity, since their failure or 
malfunctioning may put at risk the life and health of persons at large scale and lead to appreciable 
disruptions in the ordinary conduct of social and economic activities. Safety components of critical 
infrastructure, including critical digital infrastructure, are systems used to directly protect the 
physical integrity of critical infrastructure or the health and safety of persons and property but 
which are not necessary in order for the system to function. The failure or malfunctioning of such 
components might directly lead to risks to the physical integrity of critical infrastructure and thus to 
risks to health and safety of persons and property. Components intended to be used solely for 
cybersecurity purposes should not qualify as safety components. Examples of safety components 
of such critical infrastructure may include systems for monitoring water pressure or fire alarm 
controlling systems in cloud computing centres. 

--- PAGE 65 ---
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 56 
The deployment of AI systems in education is important to promote high-quality digital education 
and training and to allow all learners and teachers to acquire and share the necessary digital skills 
and competences, including media literacy, and critical thinking, to take an active part in the 
economy, society, and in democratic processes. However, AI systems used in education or 
vocational training, in particular for determining access or admission, for assigning persons to 
educational and vocational training institutions or programmes at all levels, for evaluating learning 
outcomes of persons, for assessing the appropriate level of education for an individual and 
materially influencing the level of education and training that individuals will receive or will be able 
to access or for monitoring and detecting prohibited behaviour of students during tests should be 
classified as high-risk AI systems, since they may determine the educational and professional 
course of a person’s life and therefore may affect that person’s ability to secure a livelihood. When 
improperly designed and used, such systems may be particularly intrusive and may violate the 
right to education and training as well as the right not to be discriminated against and perpetuate 
historical patterns of discrimination, for example against women, certain age groups, persons with 
disabilities, or persons of certain racial or ethnic origins or sexual orientation. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 57 
AI systems used in employment, workers management and access to self-employment, in 
particular for the recruitment and selection of persons, for making decisions affecting terms of the 
work-related relationship, promotion and termination of work-related contractual relationships, for 
allocating tasks on the basis of individual behaviour, personal traits or characteristics and for 
monitoring or evaluation of persons in work-related contractual relationships, should also be 

--- PAGE 66 ---
classified as high-risk, since those systems may have an appreciable impact on future career 
prospects, livelihoods of those persons and workers’ rights. Relevant work-related contractual 
relationships should, in a meaningful manner, involve employees and persons providing services 
through platforms as referred to in the Commission Work Programme 2021. Throughout the 
recruitment process and in the evaluation, promotion, or retention of persons in work-related 
contractual relationships, such systems may perpetuate historical patterns of discrimination, for 
example against women, certain age groups, persons with disabilities, or persons of certain racial 
or ethnic origins or sexual orientation. AI systems used to monitor the performance and behaviour 
of such persons may also undermine their fundamental rights to data protection and privacy. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
 
Recital 58 
Another area in which the use of AI systems deserves special consideration is the access to and 
enjoyment of certain essential private and public services and benefits necessary for people to 
fully participate in society or to improve one’s standard of living. In particular, natural persons 
applying for or receiving essential public assistance benefits and services from public authorities 
namely healthcare services, social security benefits, social services providing protection in cases 
such as maternity, illness, industrial accidents, dependency or old age and loss of employment 
and social and housing assistance, are typically dependent on those benefits and services and in 
a vulnerable position in relation to the responsible authorities. If AI systems are used for 
determining whether such benefits and services should be granted, denied, reduced, revoked or 
reclaimed by authorities, including whether beneficiaries are legitimately entitled to such benefits 
or services, those systems may have a significant impact on persons’ livelihood and may infringe 
their fundamental rights, such as the right to social protection, non-discrimination, human dignity 
or an effective remedy and should therefore be classified as high-risk. Nonetheless, this 
Regulation should not hamper the development and use of innovative approaches in the public 
administration, which would stand to benefit from a wider use of compliant and safe AI systems, 

--- PAGE 67 ---
provided that those systems do not entail a high risk to legal and natural persons. In addition, AI 
systems used to evaluate the credit score or creditworthiness of natural persons should be 
classified as high-risk AI systems, since they determine those persons’ access to financial 
resources or essential services such as housing, electricity, and telecommunication services. AI 
systems used for those purposes may lead to discrimination between persons or groups and may 
perpetuate historical patterns of discrimination, such as that based on racial or ethnic origins, 
gender, disabilities, age or sexual orientation, or may create new forms of discriminatory impacts. 
However, AI systems provided for by Union law for the purpose of detecting fraud in the offering 
of financial services and for prudential purposes to calculate credit institutions’ and insurance 
undertakings’ capital requirements should not be considered to be high-risk under this Regulation. 
Moreover, AI systems intended to be used for risk assessment and pricing in relation to natural 
persons for health and life insurance can also have a significant impact on persons’ livelihood and 
if not duly designed, developed and used, can infringe their fundamental rights and can lead to 
serious consequences for people’s life and health, including financial exclusion and 
discrimination. Finally, AI systems used to evaluate and classify emergency calls by natural 
persons or to dispatch or establish priority in the dispatching of emergency first response 
services, including by police, firefighters and medical aid, as well as of emergency healthcare 
patient triage systems, should also be classified as high-risk since they make decisions in very 
critical situations for the life and health of persons and their property. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 59 
Given their role and responsibility, actions by law enforcement authorities involving certain uses of 
AI systems are characterised by a significant degree of power imbalance and may lead to 
surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on 
fundamental rights guaranteed in the Charter. In particular, if the AI system is not trained with 
high-quality data, does not meet adequate requirements in terms of its performance, its accuracy 
or robustness, or is not properly designed and tested before being put on the market or otherwise 

--- PAGE 68 ---
put into service, it may single out people in a discriminatory or otherwise incorrect or unjust 
manner. Furthermore, the exercise of important procedural fundamental rights, such as the right 
to an effective remedy and to a fair trial as well as the right of defence and the presumption of 
innocence, could be hampered, in particular, where such AI systems are not sufficiently 
transparent, explainable and documented. It is therefore appropriate to classify as high-risk, 
insofar as their use is permitted under relevant Union and national law, a number of AI systems 
intended to be used in the law enforcement context where accuracy, reliability and transparency is 
particularly important to avoid adverse impacts, retain public trust and ensure accountability and 
effective redress. In view of the nature of the activities and the risks relating thereto, those 
high-risk AI systems should include in particular AI systems intended to be used by or on behalf of 
law enforcement authorities or by Union institutions, bodies, offices, or agencies in support of law 
enforcement authorities for assessing the risk of a natural person to become a victim of criminal 
offences, as polygraphs and similar tools, for the evaluation of the reliability of evidence in the 
course of investigation or prosecution of criminal offences, and, insofar as not prohibited under 
this Regulation, for assessing the risk of a natural person offending or reoffending not solely on 
the basis of the profiling of natural persons or the assessment of personality traits and 
characteristics or the past criminal behaviour of natural persons or groups, for profiling in the 
course of detection, investigation or prosecution of criminal offences. AI systems specifically 
intended to be used for administrative proceedings by tax and customs authorities as well as by 
financial intelligence units carrying out administrative tasks analysing information pursuant to 
Union anti-money laundering law should not be classified as high-risk AI systems used by law 
enforcement authorities for the purpose of prevention, detection, investigation and prosecution of 
criminal offences. The use of AI tools by law enforcement and other relevant authorities should 
not become a factor of inequality, or exclusion. The impact of the use of AI tools on the defence 
rights of suspects should not be ignored, in particular the difficulty in obtaining meaningful 
information on the functioning of those systems and the resulting difficulty in challenging their 
results in court, in particular by natural persons under investigation. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
​
Article 13: Transparency and provision of information to deployers 

--- PAGE 69 ---
Recital 60 
AI systems used in migration, asylum and border control management affect persons who are 
often in particularly vulnerable positions and who are dependent on the outcome of the actions of 
the competent public authorities. The accuracy, non-discriminatory nature and transparency of the 
AI systems used in those contexts are therefore particularly important to guarantee respect for the 
fundamental rights of the affected persons, in particular their rights to free movement, 
non-discrimination, protection of private life and personal data, international protection and good 
administration. It is therefore appropriate to classify as high-risk, insofar as their use is permitted 
under relevant Union and national law, AI systems intended to be used by or on behalf of 
competent public authorities or by Union institutions, bodies, offices or agencies charged with 
tasks in the fields of migration, asylum and border control management as polygraphs and similar 
tools, for assessing certain risks posed by natural persons entering the territory of a Member 
State or applying for visa or asylum, for assisting competent public authorities for the examination, 
including related assessment of the reliability of evidence, of applications for asylum, visa and 
residence permits and associated complaints with regard to the objective to establish the eligibility 
of the natural persons applying for a status, for the purpose of detecting, recognising or identifying 
natural persons in the context of migration, asylum and border control management, with the 
exception of verification of travel documents. AI systems in the area of migration, asylum and 
border control management covered by this Regulation should comply with the relevant 
procedural requirements set by the Regulation (EC) No 810/2009 of the European Parliament and 
of the Council(32), the Directive 2013/32/EU of the European Parliament and of the Council(33), 
and other relevant Union law. The use of AI systems in migration, asylum and border control 
management should, under no circumstances, be used by Member States or Union institutions, 
bodies, offices or agencies as a means to circumvent their international obligations under the UN 
Convention relating to the Status of Refugees established in Geneva on 28 July 1951 as 
amended by the Protocol of 31 January 1967. Nor should they be used to in any way infringe on 
the principle of non-refoulement, or to deny safe and effective legal avenues into the territory of 
the Union, including the right to international protection. 
This Recital relates to 

--- PAGE 70 ---
​
Article 6: Classification rules for high-risk AI systems 
​
Article 13: Transparency and provision of information to deployers 
Recital 61 
Certain AI systems intended for the administration of justice and democratic processes should be 
classified as high-risk, considering their potentially significant impact on democracy, the rule of 
law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, 
to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk 
AI systems intended to be used by a judicial authority or on its behalf to assist judicial authorities 
in researching and interpreting facts and the law and in applying the law to a concrete set of facts. 
AI systems intended to be used by alternative dispute resolution bodies for those purposes should 
also be considered to be high-risk when the outcomes of the alternative dispute resolution 
proceedings produce legal effects for the parties. The use of AI tools can support the 
decision-making power of judges or judicial independence, but should not replace it: the final 
decision-making must remain a human-driven activity. The classification of AI systems as 
high-risk should not, however, extend to AI systems intended for purely ancillary administrative 
activities that do not affect the actual administration of justice in individual cases, such as 
anonymisation or pseudonymisation of judicial decisions, documents or data, communication 
between personnel, administrative tasks. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 62 
Without prejudice to the rules provided for in Regulation (EU) 2024/900 of the European 
Parliament and of the Council(34), and in order to address the risks of undue external interference 
with the right to vote enshrined in Article 39 of the Charter, and of adverse effects on democracy 
and the rule of law, AI systems intended to be used to influence the outcome of an election or 
referendum or the voting behaviour of natural persons in the exercise of their vote in elections or 

--- PAGE 71 ---
referenda should be classified as high-risk AI systems with the exception of AI systems whose 
output natural persons are not directly exposed to, such as tools used to organise, optimise and 
structure political campaigns from an administrative and logistical point of view. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 63 
The fact that an AI system is classified as a high-risk AI system under this Regulation should not 
be interpreted as indicating that the use of the system is lawful under other acts of Union law or 
under national law compatible with Union law, such as on the protection of personal data, on the 
use of polygraphs and similar tools or other systems to detect the emotional state of natural 
persons. Any such use should continue to occur solely in accordance with the applicable 
requirements resulting from the Charter and from the applicable acts of secondary Union law and 
national law. This Regulation should not be understood as providing legal ground for processing 
of personal data, including special categories of personal data, where relevant, unless it is 
specifically otherwise provided for in this Regulation. 
This Recital relates to 
​
Article 6: Classification rules for high-risk AI systems 
Recital 64 
To mitigate the risks from high-risk AI systems placed on the market or put into service and to 
ensure a high level of trustworthiness, certain mandatory requirements should apply to high-risk 
AI systems, taking into account the intended purpose and the context of use of the AI system and 
according to the risk-management system to be established by the provider. The measures 
adopted by the providers to comply with the mandatory requirements of this Regulation should 
take into account the generally acknowledged state of the art on AI, be proportionate and effective 
to meet the objectives of this Regulation. Based on the New Legislative Framework, as clarified in 

--- PAGE 72 ---
Commission notice ‘The “Blue Guide” on the implementation of EU product rules 2022’, the 
general rule is that more than one legal act of Union harmonisation legislation may be applicable 
to one product, since the making available or putting into service can take place only when the 
product complies with all applicable Union harmonisation legislation. The hazards of AI systems 
covered by the requirements of this Regulation concern different aspects than the existing Union 
harmonisation legislation and therefore the requirements of this Regulation would complement the 
existing body of the Union harmonisation legislation. For example, machinery or medical devices 
products incorporating an AI system might present risks not addressed by the essential health 
and safety requirements set out in the relevant Union harmonised legislation, as that sectoral law 
does not deal with risks specific to AI systems. This calls for a simultaneous and complementary 
application of the various legislative acts. To ensure consistency and to avoid an unnecessary 
administrative burden and unnecessary costs, providers of a product that contains one or more 
high-risk AI systems, to which the requirements of this Regulation and of the Union harmonisation 
legislation based on the New Legislative Framework and listed in an annex to this Regulation 
apply, should have flexibility with regard to operational decisions on how to ensure compliance of 
a product that contains one or more AI systems with all the applicable requirements of that Union 
harmonised legislation in an optimal manner. That flexibility could mean, for example a decision 
by the provider to integrate a part of the necessary testing and reporting processes, information 
and documentation required under this Regulation into already existing documentation and 
procedures required under existing Union harmonisation legislation based on the New Legislative 
Framework and listed in an annex to this Regulation. This should not, in any way, undermine the 
obligation of the provider to comply with all the applicable requirements. 
This Recital relates to 
​
Article 9: Risk management system 
​
Article 34: Operational obligations of notified bodies 
Recital 65 
The risk-management system should consist of a continuous, iterative process that is planned 
and runs throughout the entire lifecycle of a high-risk AI system. That process should be aimed at 

--- PAGE 73 ---
identifying and mitigating the relevant risks of AI systems on health, safety and fundamental 
rights. The risk-management system should be regularly reviewed and updated to ensure its 
continuing effectiveness, as well as justification and documentation of any significant decisions 
and actions taken subject to this Regulation. This process should ensure that the provider 
identifies risks or adverse impacts and implements mitigation measures for the known and 
reasonably foreseeable risks of AI systems to the health, safety and fundamental rights in light of 
their intended purpose and reasonably foreseeable misuse, including the possible risks arising 
from the interaction between the AI system and the environment within which it operates. The 
risk-management system should adopt the most appropriate risk-management measures in light 
of the state of the art in AI. When identifying the most appropriate risk-management measures, 
the provider should document and explain the choices made and, when relevant, involve experts 
and external stakeholders. In identifying the reasonably foreseeable misuse of high-risk AI 
systems, the provider should cover uses of AI systems which, while not directly covered by the 
intended purpose and provided for in the instruction for use may nevertheless be reasonably 
expected to result from readily predictable human behaviour in the context of the specific 
characteristics and use of a particular AI system. Any known or foreseeable circumstances 
related to the use of the high-risk AI system in accordance with its intended purpose or under 
conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or 
fundamental rights should be included in the instructions for use that are provided by the provider. 
This is to ensure that the deployer is aware and takes them into account when using the high-risk 
AI system. Identifying and implementing risk mitigation measures for foreseeable misuse under 
this Regulation should not require specific additional training for the high-risk AI system by the 
provider to address foreseeable misuse. The providers however are encouraged to consider such 
additional training measures to mitigate reasonable foreseeable misuses as necessary and 
appropriate. 
This Recital relates to 
​
Article 9: Risk management system 
Recital 66 

--- PAGE 74 ---
Requirements should apply to high-risk AI systems as regards risk management, the quality and 
relevance of data sets used, technical documentation and record-keeping, transparency and the 
provision of information to deployers, human oversight, and robustness, accuracy and 
cybersecurity. Those requirements are necessary to effectively mitigate the risks for health, safety 
and fundamental rights. As no other less trade restrictive measures are reasonably available 
those requirements are not unjustified restrictions to trade. 
This Recital relates to 
​
Article 10: Data and data governance 
​
Article 11: Technical documentation 
​
Article 12: Record-keeping 
​
Article 13: Transparency and provision of information to deployers 
​
Article 14: Human oversight 
​
Article 15: Accuracy, robustness and cybersecurity 
​
Article 18: Documentation keeping 
 
Recital 67 
High-quality data and access to high-quality data plays a vital role in providing structure and in 
ensuring the performance of many AI systems, especially when techniques involving the training 
of models are used, with a view to ensure that the high-risk AI system performs as intended and 
safely and it does not become a source of discrimination prohibited by Union law. High-quality 
data sets for training, validation and testing require the implementation of appropriate data 
governance and management practices. Data sets for training, validation and testing, including 
the labels, should be relevant, sufficiently representative, and to the best extent possible free of 
errors and complete in view of the intended purpose of the system. In order to facilitate 
compliance with Union data protection law, such as Regulation (EU) 2016/679, data governance 

--- PAGE 75 ---
and management practices should include, in the case of personal data, transparency about the 
original purpose of the data collection. The data sets should also have the appropriate statistical 
properties, including as regards the persons or groups of persons in relation to whom the high-risk 
AI system is intended to be used, with specific attention to the mitigation of possible biases in the 
data sets, that are likely to affect the health and safety of persons, have a negative impact on 
fundamental rights or lead to discrimination prohibited under Union law, especially where data 
outputs influence inputs for future operations (feedback loops). Biases can for example be 
inherent in underlying data sets, especially when historical data is being used, or generated when 
the systems are implemented in real world settings. Results provided by AI systems could be 
influenced by such inherent biases that are inclined to gradually increase and thereby perpetuate 
and amplify existing discrimination, in particular for persons belonging to certain vulnerable 
groups, including racial or ethnic groups. The requirement for the data sets to be to the best 
extent possible complete and free of errors should not affect the use of privacy-preserving 
techniques in the context of the development and testing of AI systems. In particular, data sets 
should take into account, to the extent required by their intended purpose, the features, 
characteristics or elements that are particular to the specific geographical, contextual, behavioural 
or functional setting in which the AI system is intended to be used. The requirements related to 
data governance can be complied with by having recourse to third parties that offer certified 
compliance services including verification of data governance, data set integrity, and data training, 
validation and testing practices, as far as compliance with the data requirements of this 
Regulation are ensured. 
This Recital relates to 
​
Article 10: Data and data governance 
​
Article 13: Transparency and provision of information to deployers 
Recital 68 
For the development and assessment of high-risk AI systems, certain actors, such as providers, 
notified bodies and other relevant entities, such as European Digital Innovation Hubs, testing 
experimentation facilities and researchers, should be able to access and use high-quality data 

--- PAGE 76 ---
sets within the fields of activities of those actors which are related to this Regulation. European 
common data spaces established by the Commission and the facilitation of data sharing between 
businesses and with government in the public interest will be instrumental to provide trustful, 
accountable and non-discriminatory access to high-quality data for the training, validation and 
testing of AI systems. For example, in health, the European health data space will facilitate 
non-discriminatory access to health data and the training of AI algorithms on those data sets, in a 
privacy-preserving, secure, timely, transparent and trustworthy manner, and with an appropriate 
institutional governance. Relevant competent authorities, including sectoral ones, providing or 
supporting the access to data may also support the provision of high-quality data for the training, 
validation and testing of AI systems. 
This Recital relates to 
​
Article 10: Data and data governance 
​
Article 31: Requirements relating to notified bodies 
Recital 69 
The right to privacy and to protection of personal data must be guaranteed throughout the entire 
lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by 
design and by default, as set out in Union data protection law, are applicable when personal data 
are processed. Measures taken by providers to ensure compliance with those principles may 
include not only anonymisation and encryption, but also the use of technology that permits 
algorithms to be brought to the data and allows training of AI systems without the transmission 
between parties or copying of the raw or structured data themselves, without prejudice to the 
requirements on data governance provided for in this Regulation. 
This Recital relates to 
​
Article 10: Data and data governance 
Recital 70 

--- PAGE 77 ---
In order to protect the right of others from the discrimination that might result from the bias in AI 
systems, the providers should, exceptionally, to the extent that it is strictly necessary for the 
purpose of ensuring bias detection and correction in relation to the high-risk AI systems, subject 
to appropriate safeguards for the fundamental rights and freedoms of natural persons and 
following the application of all applicable conditions laid down under this Regulation in addition to 
the conditions laid down in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 
2016/680, be able to process also special categories of personal data, as a matter of substantial 
public interest within the meaning of Article 9(2), point (g) of Regulation (EU) 2016/679 and Article 
10(2), point (g) of Regulation (EU) 2018/1725. 
This Recital relates to 
​
Article 10: Data and data governance 
​
Article 77: Powers of authorities protecting fundamental rights 
Recital 71 
Having comprehensible information on how high-risk AI systems have been developed and how 
they perform throughout their lifetime is essential to enable traceability of those systems, verify 
compliance with the requirements under this Regulation, as well as monitoring of their operations 
and post market monitoring. This requires keeping records and the availability of technical 
documentation, containing information which is necessary to assess the compliance of the AI 
system with the relevant requirements and facilitate post market monitoring. Such information 
should include the general characteristics, capabilities and limitations of the system, algorithms, 
data, training, testing and validation processes used as well as documentation on the relevant 
risk-management system and drawn in a clear and comprehensive form. The technical 
documentation should be kept up to date, appropriately throughout the lifetime of the AI system. 
Furthermore, high-risk AI systems should technically allow for the automatic recording of events, 
by means of logs, over the duration of the lifetime of the system. 
This Recital relates to 

--- PAGE 78 ---
​
Article 9: Risk management system 
​
Article 11: Technical documentation 
​
Article 12: Record-keeping 
​
Article 13: Transparency and provision of information to deployers 
​
Article 19: Automatically generated logs 
​
Article 72: Post-market monitoring by providers and post-market monitoring plan for 
high-risk AI systems 
Recital 72 
To address concerns related to opacity and complexity of certain AI systems and help deployers 
to fulfil their obligations under this Regulation, transparency should be required for high-risk AI 
systems before they are placed on the market or put it into service. High-risk AI systems should 
be designed in a manner to enable deployers to understand how the AI system works, evaluate 
its functionality, and comprehend its strengths and limitations. High-risk AI systems should be 
accompanied by appropriate information in the form of instructions of use. Such information 
should include the characteristics, capabilities and limitations of performance of the AI system. 
Those would cover information on possible known and foreseeable circumstances related to the 
use of the high-risk AI system, including deployer action that may influence system behaviour and 
performance, under which the AI system can lead to risks to health, safety, and fundamental 
rights, on the changes that have been pre-determined and assessed for conformity by the 
provider and on the relevant human oversight measures, including the measures to facilitate the 
interpretation of the outputs of the AI system by the deployers. Transparency, including the 
accompanying instructions for use, should assist deployers in the use of the system and support 
informed decision making by them. Deployers should, inter alia, be in a better position to make 
the correct choice of the system that they intend to use in light of the obligations applicable to 
them, be educated about the intended and precluded uses, and use the AI system correctly and 
as appropriate. In order to enhance legibility and accessibility of the information included in the 
instructions of use, where appropriate, illustrative examples, for instance on the limitations and on 
the intended and precluded uses of the AI system, should be included. Providers should ensure 

--- PAGE 79 ---
that all documentation, including the instructions for use, contains meaningful, comprehensive, 
accessible and understandable information, taking into account the needs and foreseeable 
knowledge of the target deployers. Instructions for use should be made available in a language 
which can be easily understood by target deployers, as determined by the Member State 
concerned. 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
 
 
 
 
Recital 73 
High-risk AI systems should be designed and developed in such a way that natural persons can 
oversee their functioning, ensure that they are used as intended and that their impacts are 
addressed over the system’s lifecycle. To that end, appropriate human oversight measures should 
be identified by the provider of the system before its placing on the market or putting into service. 
In particular, where appropriate, such measures should guarantee that the system is subject to 
in-built operational constraints that cannot be overridden by the system itself and is responsive to 
the human operator, and that the natural persons to whom human oversight has been assigned 
have the necessary competence, training and authority to carry out that role. It is also essential, 
as appropriate, to ensure that high-risk AI systems include mechanisms to guide and inform a 
natural person to whom human oversight has been assigned to make informed decisions if, when 
and how to intervene in order to avoid negative consequences or risks or stop the system if it 
does not perform as intended. Considering the significant consequences for persons in the case 
of an incorrect match by certain biometric identification systems, it is appropriate to provide for an 
enhanced human oversight requirement for those systems so that no action or decision may be 
taken by the deployer on the basis of the identification resulting from the system unless this has 

--- PAGE 80 ---
been separately verified and confirmed by at least two natural persons. Those persons could be 
from one or more entities and include the person operating or using the system. This requirement 
should not pose unnecessary burden or delays, and it could be sufficient that the separate 
verifications by the different persons are automatically recorded in the logs generated by the 
system. Given the specificities of the areas of law enforcement, migration, border control and 
asylum, this requirement should not apply where Union or national law considers the application 
of that requirement to be disproportionate. 
This Recital relates to 
​
Article 14: Human oversight 
​
Article 19: Automatically generated logs 
 
 
Recital 74 
High-risk AI systems should perform consistently throughout their lifecycle and meet an 
appropriate level of accuracy, robustness and cybersecurity, in light of their intended purpose and 
in accordance with the generally acknowledged state of the art. The Commission and relevant 
organisations and stakeholders are encouraged to take due consideration of the mitigation of 
risks and the negative impacts of the AI system. The expected level of performance metrics 
should be declared in the accompanying instructions of use. Providers are urged to communicate 
that information to deployers in a clear and easily understandable way, free of misunderstandings 
or misleading statements. Union law on legal metrology, including Directives 2014/31/EU(35) and 
2014/32/EU(36) of the European Parliament and of the Council, aims to ensure the accuracy of 
measurements and to help the transparency and fairness of commercial transactions. In that 
context, in cooperation with relevant stakeholders and organisation, such as metrology and 
benchmarking authorities, the Commission should encourage, as appropriate, the development of 
benchmarks and measurement methodologies for AI systems. In doing so, the Commission 

--- PAGE 81 ---
should take note and collaborate with international partners working on metrology and relevant 
measurement indicators relating to AI. 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
​
Article 15: Accuracy, robustness and cybersecurity 
Recital 75 
Technical robustness is a key requirement for high-risk AI systems. They should be resilient in 
relation to harmful or otherwise undesirable behaviour that may result from limitations within the 
systems or the environment in which the systems operate (e.g. errors, faults, inconsistencies, 
unexpected situations). Therefore, technical and organisational measures should be taken to 
ensure robustness of high-risk AI systems, for example by designing and developing appropriate 
technical solutions to prevent or minimise harmful or otherwise undesirable behaviour. Those 
technical solution may include for instance mechanisms enabling the system to safely interrupt its 
operation (fail-safe plans) in the presence of certain anomalies or when operation takes place 
outside certain predetermined boundaries. Failure to protect against these risks could lead to 
safety impacts or negatively affect the fundamental rights, for example due to erroneous decisions 
or wrong or biased outputs generated by the AI system. 
This Recital relates to 
​
Article 15: Accuracy, robustness and cybersecurity 
Recital 76 
Cybersecurity plays a crucial role in ensuring that AI systems are resilient against attempts to 
alter their use, behaviour, performance or compromise their security properties by malicious third 
parties exploiting the system’s vulnerabilities. Cyberattacks against AI systems can leverage AI 
specific assets, such as training data sets (e.g. data poisoning) or trained models (e.g. adversarial 
attacks or membership inference), or exploit vulnerabilities in the AI system’s digital assets or the 

--- PAGE 82 ---
underlying ICT infrastructure. To ensure a level of cybersecurity appropriate to the risks, suitable 
measures, such as security controls, should therefore be taken by the providers of high-risk AI 
systems, also taking into account as appropriate the underlying ICT infrastructure. 
This Recital relates to 
​
Article 10: Data and data governance 
​
Article 15: Accuracy, robustness and cybersecurity 
Recital 77 
Without prejudice to the requirements related to robustness and accuracy set out in this 
Regulation, high-risk AI systems which fall within the scope of a regulation of the European 
Parliament and of the Council on horizontal cybersecurity requirements for products with digital 
elements, in accordance with that regulation may demonstrate compliance with the cybersecurity 
requirements of this Regulation by fulfilling the essential cybersecurity requirements set out in that 
regulation. When high-risk AI systems fulfil the essential requirements of a regulation of the 
European Parliament and of the Council on horizontal cybersecurity requirements for products 
with digital elements, they should be deemed compliant with the cybersecurity requirements set 
out in this Regulation in so far as the achievement of those requirements is demonstrated in the 
EU declaration of conformity or parts thereof issued under that regulation. To that end, the 
assessment of the cybersecurity risks, associated to a product with digital elements classified as 
high-risk AI system according to this Regulation, carried out under a regulation of the European 
Parliament and of the Council on horizontal cybersecurity requirements for products with digital 
elements, should consider risks to the cyber resilience of an AI system as regards attempts by 
unauthorised third parties to alter its use, behaviour or performance, including AI specific 
vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to 
fundamental rights as required by this Regulation. 
This Recital relates to 
​
Article 15: Accuracy, robustness and cybersecurity 

--- PAGE 83 ---
​
Article 42: Presumption of conformity with certain requirements 
Recital 78 
The conformity assessment procedure provided by this Regulation should apply in relation to the 
essential cybersecurity requirements of a product with digital elements covered by a regulation of 
the European Parliament and of the Council on horizontal cybersecurity requirements for products 
with digital elements and classified as a high-risk AI system under this Regulation. However, this 
rule should not result in reducing the necessary level of assurance for critical products with digital 
elements covered by a regulation of the European Parliament and of the Council on horizontal 
cybersecurity requirements for products with digital elements. Therefore, by way of derogation 
from this rule, high-risk AI systems that fall within the scope of this Regulation and are also 
qualified as important and critical products with digital elements pursuant to a regulation of the 
European Parliament and of the Council on horizontal cybersecurity requirements for products 
with digital elements and to which the conformity assessment procedure based on internal control 
set out in an annex to this Regulation applies, are subject to the conformity assessment 
provisions of a regulation of the European Parliament and of the Council on horizontal 
cybersecurity requirements for products with digital elements insofar as the essential 
cybersecurity requirements of that regulation are concerned. In this case, for all the other aspects 
covered by this Regulation the respective provisions on conformity assessment based on internal 
control set out in an annex to this Regulation should apply. Building on the knowledge and 
expertise of ENISA on the cybersecurity policy and tasks assigned to ENISA under the Regulation 
(EU) 2019/881 of the European Parliament and of the Council(37), the Commission should 
cooperate with ENISA on issues related to cybersecurity of AI systems. 
This Recital relates to 
​
Article 15: Accuracy, robustness and cybersecurity 
​
Article 42: Presumption of conformity with certain requirements 
​
Article 43: Conformity assessment 

--- PAGE 84 ---
Recital 79 
It is appropriate that a specific natural or legal person, defined as the provider, takes responsibility 
for the placing on the market or the putting into service of a high-risk AI system, regardless of 
whether that natural or legal person is the person who designed or developed the system. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
Recital 80 
As signatories to the United Nations Convention on the Rights of Persons with Disabilities, the 
Union and the Member States are legally obliged to protect persons with disabilities from 
discrimination and promote their equality, to ensure that persons with disabilities have access, on 
an equal basis with others, to information and communications technologies and systems, and to 
ensure respect for privacy for persons with disabilities. Given the growing importance and use of 
AI systems, the application of universal design principles to all new technologies and services 
should ensure full and equal access for everyone potentially affected by or using AI technologies, 
including persons with disabilities, in a way that takes full account of their inherent dignity and 
diversity. It is therefore essential that providers ensure full compliance with accessibility 
requirements, including Directive (EU) 2016/2102 of the European Parliament and of the Council 
(38) and Directive (EU) 2019/882. Providers should ensure compliance with these requirements 
by design. Therefore, the necessary measures should be integrated as much as possible into the 
design of the high-risk AI system. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
Recital 81 

--- PAGE 85 ---
The provider should establish a sound quality management system, ensure the accomplishment 
of the required conformity assessment procedure, draw up the relevant documentation and 
establish a robust post-market monitoring system. Providers of high-risk AI systems that are 
subject to obligations regarding quality management systems under relevant sectoral Union law 
should have the possibility to include the elements of the quality management system provided for 
in this Regulation as part of the existing quality management system provided for in that other 
sectoral Union law. The complementarity between this Regulation and existing sectoral Union law 
should also be taken into account in future standardisation activities or guidance adopted by the 
Commission. Public authorities which put into service high-risk AI systems for their own use may 
adopt and implement the rules for the quality management system as part of the quality 
management system adopted at a national or regional level, as appropriate, taking into account 
the specificities of the sector and the competences and organisation of the public authority 
concerned. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 17: Quality management system 
​
Article 18: Documentation keeping 
​
Article 19: Automatically generated logs 
​
Article 20: Corrective actions and duty of information 
​
Article 21: Cooperation with competent authorities 
Recital 82 
To enable enforcement of this Regulation and create a level playing field for operators, and, taking 
into account the different forms of making available of digital products, it is important to ensure 
that, under all circumstances, a person established in the Union can provide authorities with all 
the necessary information on the compliance of an AI system. Therefore, prior to making their AI 
systems available in the Union, providers established in third countries should, by written 

--- PAGE 86 ---
mandate, appoint an authorised representative established in the Union. This authorised 
representative plays a pivotal role in ensuring the compliance of the high-risk AI systems placed 
on the market or put into service in the Union by those providers who are not established in the 
Union and in serving as their contact person established in the Union. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 22: Authorised representatives of providers of high-risk AI systems 
​
Article 54: Authorised representatives of providers of general-purpose AI models 
 
 
 
 
 
 
Recital 83 
In light of the nature and complexity of the value chain for AI systems and in line with the New 
Legislative Framework, it is essential to ensure legal certainty and facilitate the compliance with 
this Regulation. Therefore, it is necessary to clarify the role and the specific obligations of relevant 
operators along that value chain, such as importers and distributors who may contribute to the 
development of AI systems. In certain situations those operators could act in more than one role 
at the same time and should therefore fulfil cumulatively all relevant obligations associated with 
those roles. For example, an operator could act as a distributor and an importer at the same time. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 

--- PAGE 87 ---
​
Article 22: Authorised representatives of providers of high-risk AI systems 
​
Article 23: Obligations of importers 
​
Article 24: Obligations of distributors 
​
Article 25: Responsibilities along the AI value chain 
Recital 84 
To ensure legal certainty, it is necessary to clarify that, under certain specific conditions, any 
distributor, importer, deployer or other third-party should be considered to be a provider of a 
high-risk AI system and therefore assume all the relevant obligations. This would be the case if 
that party puts its name or trademark on a high-risk AI system already placed on the market or put 
into service, without prejudice to contractual arrangements stipulating that the obligations are 
allocated otherwise. This would also be the case if that party makes a substantial modification to 
a high-risk AI system that has already been placed on the market or has already been put into 
service in a way that it remains a high-risk AI system in accordance with this Regulation, or if it 
modifies the intended purpose of an AI system, including a general-purpose AI system, which has 
not been classified as high-risk and has already been placed on the market or put into service, in 
a way that the AI system becomes a high-risk AI system in accordance with this Regulation. 
Those provisions should apply without prejudice to more specific provisions established in certain 
Union harmonisation legislation based on the New Legislative Framework, together with which 
this Regulation should apply. For example, Article 16(2) of Regulation (EU) 2017/745, establishing 
that certain changes should not be considered to be modifications of a device that could affect its 
compliance with the applicable requirements, should continue to apply to high-risk AI systems that 
are medical devices within the meaning of that Regulation. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 23: Obligations of importers 
​
Article 24: Obligations of distributors 

--- PAGE 88 ---
​
Article 25: Responsibilities along the AI value chain 
​
Article 26: Obligations of deployers of high-risk AI systems 
Recital 85 
General-purpose AI systems may be used as high-risk AI systems by themselves or be 
components of other high-risk AI systems. Therefore, due to their particular nature and in order to 
ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems 
should, irrespective of whether they may be used as high-risk AI systems as such by other 
providers or as components of high-risk AI systems and unless provided otherwise under this 
Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable 
their compliance with the relevant obligations under this Regulation and with the competent 
authorities established under this Regulation. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 25: Responsibilities along the AI value chain 
 
Recital 86 
Where, under the conditions laid down in this Regulation, the provider that initially placed the AI 
system on the market or put it into service should no longer be considered to be the provider for 
the purposes of this Regulation, and when that provider has not expressly excluded the change of 
the AI system into a high-risk AI system, the former provider should nonetheless closely 
cooperate and make available the necessary information and provide the reasonably expected 
technical access and other assistance that are required for the fulfilment of the obligations set out 
in this Regulation, in particular regarding the compliance with the conformity assessment of 
high-risk AI systems. 

--- PAGE 89 ---
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 25: Responsibilities along the AI value chain 
Recital 87 
In addition, where a high-risk AI system that is a safety component of a product which falls within 
the scope of Union harmonisation legislation based on the New Legislative Framework is not 
placed on the market or put into service independently from the product, the product manufacturer 
defined in that legislation should comply with the obligations of the provider established in this 
Regulation and should, in particular, ensure that the AI system embedded in the final product 
complies with the requirements of this Regulation. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 25: Responsibilities along the AI value chain 
 
 
Recital 88 
Along the AI value chain multiple parties often supply AI systems, tools and services but also 
components or processes that are incorporated by the provider into the AI system with various 
objectives, including the model training, model retraining, model testing and evaluation, 
integration into software, or other aspects of model development. Those parties have an 
important role to play in the value chain towards the provider of the high-risk AI system into which 
their AI systems, tools, services, components or processes are integrated, and should provide by 
written agreement this provider with the necessary information, capabilities, technical access and 
other assistance based on the generally acknowledged state of the art, in order to enable the 

--- PAGE 90 ---
provider to fully comply with the obligations set out in this Regulation, without compromising their 
own intellectual property rights or trade secrets. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 25: Responsibilities along the AI value chain 
Recital 89 
Third parties making accessible to the public tools, services, processes, or AI components other 
than general-purpose AI models, should not be mandated to comply with requirements targeting 
the responsibilities along the AI value chain, in particular towards the provider that has used or 
integrated them, when those tools, services, processes, or AI components are made accessible 
under a free and open-source licence. Developers of free and open-source tools, services, 
processes, or AI components other than general-purpose AI models should be encouraged to 
implement widely adopted documentation practices, such as model cards and data sheets, as a 
way to accelerate information sharing along the AI value chain, allowing the promotion of 
trustworthy AI systems in the Union. 
This Recital relates to 
​
Article 25: Responsibilities along the AI value chain 
Recital 90 
The Commission could develop and recommend voluntary model contractual terms between 
providers of high-risk AI systems and third parties that supply tools, services, components or 
processes that are used or integrated in high-risk AI systems, to facilitate the cooperation along 
the value chain. When developing voluntary model contractual terms, the Commission should 
also take into account possible contractual requirements applicable in specific sectors or business 
cases. 

--- PAGE 91 ---
This Recital relates to 
​
Article 25: Responsibilities along the AI value chain 
Recital 91 
Given the nature of AI systems and the risks to safety and fundamental rights possibly associated 
with their use, including as regards the need to ensure proper monitoring of the performance of an 
AI system in a real-life setting, it is appropriate to set specific responsibilities for deployers. 
Deployers should in particular take appropriate technical and organisational measures to ensure 
they use high-risk AI systems in accordance with the instructions of use and certain other 
obligations should be provided for with regard to monitoring of the functioning of the AI systems 
and with regard to record-keeping, as appropriate. Furthermore, deployers should ensure that the 
persons assigned to implement the instructions for use and human oversight as set out in this 
Regulation have the necessary competence, in particular an adequate level of AI literacy, training 
and authority to properly fulfil those tasks. Those obligations should be without prejudice to other 
deployer obligations in relation to high-risk AI systems under Union or national law. 
This Recital relates to 
​
Article 14: Human oversight 
​
Article 26: Obligations of deployers of high-risk AI systems 
 
Recital 92 
This Regulation is without prejudice to obligations for employers to inform or to inform and consult 
workers or their representatives under Union or national law and practice, including Directive 
2002/14/EC of the European Parliament and of the Council(39), on decisions to put into service or 
use AI systems. It remains necessary to ensure information of workers and their representatives 
on the planned deployment of high-risk AI systems at the workplace where the conditions for 
those information or information and consultation obligations in other legal instruments are not 

--- PAGE 92 ---
fulfilled. Moreover, such information right is ancillary and necessary to the objective of protecting 
fundamental rights that underlies this Regulation. Therefore, an information requirement to that 
effect should be laid down in this Regulation, without affecting any existing rights of workers. 
This Recital relates to 
​
Article 26: Obligations of deployers of high-risk AI syste 
Recital 93 
Whilst risks related to AI systems can result from the way such systems are designed, risks can 
as well stem from how such AI systems are used. Deployers of high-risk AI system therefore play 
a critical role in ensuring that fundamental rights are protected, complementing the obligations of 
the provider when developing the AI system. Deployers are best placed to understand how the 
high-risk AI system will be used concretely and can therefore identify potential significant risks 
that were not foreseen in the development phase, due to a more precise knowledge of the context 
of use, the persons or groups of persons likely to be affected, including vulnerable groups. 
Deployers of high-risk AI systems listed in an annex to this Regulation also play a critical role in 
informing natural persons and should, when they make decisions or assist in making decisions 
related to natural persons, where applicable, inform the natural persons that they are subject to 
the use of the high-risk AI system. This information should include the intended purpose and the 
type of decisions it makes. The deployer should also inform the natural persons about their right 
to an explanation provided under this Regulation. With regard to high-risk AI systems used for law 
enforcement purposes, that obligation should be implemented in accordance with Article 13 of 
Directive (EU) 2016/680. 
This Recital relates to 
​
Article 26: Obligations of deployers of high-risk AI systems 
​
Article 27: Fundamental rights impact assessment for high-risk AI systems 
Recital 94 

--- PAGE 93 ---
Any processing of biometric data involved in the use of AI systems for biometric identification for 
the purpose of law enforcement needs to comply with Article 10 of Directive (EU) 2016/680, that 
allows such processing only where strictly necessary, subject to appropriate safeguards for the 
rights and freedoms of the data subject, and where authorised by Union or Member State law. 
Such use, when authorised, also needs to respect the principles laid down in Article 4 (1) of 
Directive (EU) 2016/680 including lawfulness, fairness and transparency, purpose limitation, 
accuracy and storage limitation. 
Recital 95 
Without prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive 
(EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, 
the use of post-remote biometric identification systems should be subject to safeguards. 
Post-remote biometric identification systems should always be used in a way that is proportionate, 
legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the 
location, temporal scope and based on a closed data set of legally acquired video footage. In any 
case, post-remote biometric identification systems should not be used in the framework of law 
enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric 
identification should in any case not provide a basis to circumvent the conditions of the prohibition 
and strict exceptions for real time remote biometric identification. 
This Recital relates to 
​
Article 26: Obligations of deployers of high-risk AI systems 
Recital 96 
In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI 
systems that are bodies governed by public law, or private entities providing public services and 
deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or 
insurance entities, should carry out a fundamental rights impact assessment prior to putting it into 
use. Services important for individuals that are of public nature may also be provided by private 
entities. Private entities providing such public services are linked to tasks in the public interest 

--- PAGE 94 ---
such as in the areas of education, healthcare, social services, housing, administration of justice. 
The aim of the fundamental rights impact assessment is for the deployer to identify the specific 
risks to the rights of individuals or groups of individuals likely to be affected, identify measures to 
be taken in the case of a materialisation of those risks. The impact assessment should be 
performed prior to deploying the high-risk AI system, and should be updated when the deployer 
considers that any of the relevant factors have changed. The impact assessment should identify 
the deployer’s relevant processes in which the high-risk AI system will be used in line with its 
intended purpose, and should include a description of the period of time and frequency in which 
the system is intended to be used as well as of specific categories of natural persons and groups 
who are likely to be affected in the specific context of use. The assessment should also include 
the identification of specific risks of harm likely to have an impact on the fundamental rights of 
those persons or groups. While performing this assessment, the deployer should take into 
account information relevant to a proper assessment of the impact, including but not limited to the 
information given by the provider of the high-risk AI system in the instructions for use. In light of 
the risks identified, deployers should determine measures to be taken in the case of a 
materialisation of those risks, including for example governance arrangements in that specific 
context of use, such as arrangements for human oversight according to the instructions of use or, 
complaint handling and redress procedures, as they could be instrumental in mitigating risks to 
fundamental rights in concrete use-cases. After performing that impact assessment, the deployer 
should notify the relevant market surveillance authority. Where appropriate, to collect relevant 
information necessary to perform the impact assessment, deployers of high-risk AI system, in 
particular when AI systems are used in the public sector, could involve relevant stakeholders, 
including the representatives of groups of persons likely to be affected by the AI system, 
independent experts, and civil society organisations in conducting such impact assessments and 
designing measures to be taken in the case of materialisation of the risks. The European Artificial 
Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate 
compliance and reduce the administrative burden for deployers. 
This Recital relates to 
​
Article 26: Obligations of deployers of high-risk AI systems 
​
Article 27: Fundamental rights impact assessment for high-risk AI systems 

--- PAGE 95 ---
 
Recital 104 
The providers of general-purpose AI models that are released under a free and open-source 
licence, and whose parameters, including the weights, the information on the model architecture, 
and the information on model usage, are made publicly available should be subject to exceptions 
as regards the transparency-related requirements imposed on general-purpose AI models, unless 
they can be considered to present a systemic risk, in which case the circumstance that the model 
is transparent and accompanied by an open-source license should not be considered to be a 
sufficient reason to exclude compliance with the obligations under this Regulation. In any case, 
given that the release of general-purpose AI models under free and open-source licence does not 
necessarily reveal substantial information on the data set used for the training or fine-tuning of the 
model and on how compliance of copyright law was thereby ensured, the exception provided for 
general-purpose AI models from compliance with the transparency-related requirements should 
not concern the obligation to produce a summary about the content used for model training and 
the obligation to put in place a policy to comply with Union copyright law, in particular to identify 
and comply with the reservation of rights pursuant to Article 4(3) of Directive (EU) 2019/790 of the 
European Parliament and of the Council(40). 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 53: Obligations for providers of general-purpose AI models 
​
Article 79: Procedure at national level for dealing with AI systems presenting a risk 
Recital 106 
Providers that place general-purpose AI models on the Union market should ensure compliance 
with the relevant obligations in this Regulation. To that end, providers of general-purpose AI 

--- PAGE 96 ---
models should put in place a policy to comply with Union law on copyright and related rights, in 
particular to identify and comply with the reservation of rights expressed by rightsholders pursuant 
to Article 4(3) of Directive (EU) 2019/790. Any provider placing a general-purpose AI model on the 
Union market should comply with this obligation, regardless of the jurisdiction in which the 
copyright-relevant acts underpinning the training of those general-purpose AI models take place. 
This is necessary to ensure a level playing field among providers of general-purpose AI models 
where no provider should be able to gain a competitive advantage in the Union market by 
applying lower copyright standards than those provided in the Union. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 53: Obligations for providers of general-purpose AI models 
Recital 107 
In order to increase transparency on the data that is used in the pre-training and training of 
general-purpose AI models, including text and data protected by copyright law, it is adequate that 
providers of such models draw up and make publicly available a sufficiently detailed summary of 
the content used for training the general-purpose AI model. While taking into due account the 
need to protect trade secrets and confidential business information, this summary should be 
generally comprehensive in its scope instead of technically detailed to facilitate parties with 
legitimate interests, including copyright holders, to exercise and enforce their rights under Union 
law, for example by listing the main data collections or sets that went into training the model, such 
as large private or public databases or data archives, and by providing a narrative explanation 
about other data sources used. It is appropriate for the AI Office to provide a template for the 
summary, which should be simple, effective, and allow the provider to provide the required 
summary in narrative form. 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 

--- PAGE 97 ---
​
Article 53: Obligations for providers of general-purpose AI models 
Recital 109 
Compliance with the obligations applicable to the providers of general-purpose AI models should 
be commensurate and proportionate to the type of model provider, excluding the need for 
compliance for persons who develop or use models for non-professional or scientific research 
purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. 
Without prejudice to Union copyright law, compliance with those obligations should take due 
account of the size of the provider and allow simplified ways of compliance for SMEs, including 
start-ups, that should not represent an excessive cost and not discourage the use of such models. 
In the case of a modification or fine-tuning of a model, the obligations for providers of 
general-purpose AI models should be limited to that modification or fine-tuning, for example by 
complementing the already existing technical documentation with information on the 
modifications, including new training data sources, as a means to comply with the value chain 
obligations provided in this Regulation. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 53: Obligations for providers of general-purpose AI models 
​
Article 62: Measures for providers and deployers, in particular SMEs, including start-ups 
Recital 114 
The providers of general-purpose AI models presenting systemic risks should be subject, in 
addition to the obligations provided for providers of general-purpose AI models, to obligations 
aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity 
protection, regardless of whether it is provided as a standalone model or embedded in an AI 
system or a product. To achieve those objectives, this Regulation should require providers to 
perform the necessary model evaluations, in particular prior to its first placing on the market, 
including conducting and documenting adversarial testing of models, also, as appropriate, through 

--- PAGE 98 ---
internal or independent external testing. In addition, providers of general-purpose AI models with 
systemic risks should continuously assess and mitigate systemic risks, including for example by 
putting in place risk-management policies, such as accountability and governance processes, 
implementing post-market monitoring, taking appropriate measures along the entire model’s 
lifecycle and cooperating with relevant actors along the AI value chain. 
This Recital relates to 
​
Article 15: Accuracy, robustness and cybersecurity 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 55: Obligations of providers of general-purpose AI models with systemic risk 
Recital 115 
Providers of general-purpose AI models with systemic risks should assess and mitigate possible 
systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI 
model that may present systemic risks, the development or use of the model causes a serious 
incident, the general-purpose AI model provider should without undue delay keep track of the 
incident and report any relevant information and possible corrective measures to the Commission 
and national competent authorities. Furthermore, providers should ensure an adequate level of 
cybersecurity protection for the model and its physical infrastructure, if appropriate, along the 
entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious 
use or attacks should duly consider accidental model leakage, unauthorised releases, 
circumvention of safety measures, and defence against cyberattacks, unauthorised access or 
model theft. That protection could be facilitated by securing model weights, algorithms, servers, 
and data sets, such as through operational security measures for information security, specific 
cybersecurity policies, adequate technical and established solutions, and cyber and physical 
access controls, appropriate to the relevant circumstances and the risks involved. 
This Recital relates to 
​
Article 10: Data and data governance 

--- PAGE 99 ---
​
Article 15: Accuracy, robustness and cybersecurity 
​
Article 55: Obligations of providers of general-purpose AI models with systemic risk 
Recital 117 
The codes of practice should represent a central tool for the proper compliance with the 
obligations provided for under this Regulation for providers of general-purpose AI models. 
Providers should be able to rely on codes of practice to demonstrate compliance with the 
obligations. By means of implementing acts, the Commission may decide to approve a code of 
practice and give it a general validity within the Union, or, alternatively, to provide common rules 
for the implementation of the relevant obligations, if, by the time this Regulation becomes 
applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. 
Once a harmonised standard is published and assessed as suitable to cover the relevant 
obligations by the AI Office, compliance with a European harmonised standard should grant 
providers the presumption of conformity. Providers of general-purpose AI models should 
furthermore be able to demonstrate compliance using alternative adequate means, if codes of 
practice or harmonised standards are not available, or they choose not to rely on those. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 32: Presumption of conformity with requirements relating to notified bodies 
​
Article 40: Harmonised standards and standardisation deliverables 
​
Article 56: Codes of practice 
Recital 118 
This Regulation regulates AI systems and AI models by imposing certain requirements and 
obligations for relevant market actors that are placing them on the market, putting into service or 
use in the Union, thereby complementing obligations for providers of intermediary services that 
embed such systems or models into their services regulated by Regulation (EU) 2022/2065. To 

--- PAGE 100 ---
the extent that such systems or models are embedded into designated very large online platforms 
or very large online search engines, they are subject to the risk-management framework provided 
for in Regulation (EU) 2022/2065. Consequently, the corresponding obligations of this Regulation 
should be presumed to be fulfilled, unless significant systemic risks not covered by Regulation 
(EU) 2022/2065 emerge and are identified in such models. Within this framework, providers of 
very large online platforms and very large online search engines are obliged to assess potential 
systemic risks stemming from the design, functioning and use of their services, including how the 
design of algorithmic systems used in the service may contribute to such risks, as well as 
systemic risks stemming from potential misuses. Those providers are also obliged to take 
appropriate mitigating measures in observance of fundamental rights. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
Recital 119 
Considering the quick pace of innovation and the technological evolution of digital services in 
scope of different instruments of Union law in particular having in mind the usage and the 
perception of their recipients, the AI systems subject to this Regulation may be provided as 
intermediary services or parts thereof within the meaning of Regulation (EU) 2022/2065, which 
should be interpreted in a technology-neutral manner. For example, AI systems may be used to 
provide online search engines, in particular, to the extent that an AI system such as an online 
chatbot performs searches of, in principle, all websites, then incorporates the results into its 
existing knowledge and uses the updated knowledge to generate a single output that combines 
different sources of information. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
Recital 120 

--- PAGE 101 ---
Furthermore, obligations placed on providers and deployers of certain AI systems in this 
Regulation to enable the detection and disclosure that the outputs of those systems are artificially 
generated or manipulated are particularly relevant to facilitate the effective implementation of 
Regulation (EU) 2022/2065. This applies in particular as regards the obligations of providers of 
very large online platforms or very large online search engines to identify and mitigate systemic 
risks that may arise from the dissemination of content that has been artificially generated or 
manipulated, in particular risk of the actual or foreseeable negative effects on democratic 
processes, civic discourse and electoral processes, including through disinformation. 
Recital 131 
In order to facilitate the work of the Commission and the Member States in the AI field as well as 
to increase the transparency towards the public, providers of high-risk AI systems other than 
those related to products falling within the scope of relevant existing Union harmonisation 
legislation, as well as providers who consider that an AI system listed in the high-risk use cases in 
an annex to this Regulation is not high-risk on the basis of a derogation, should be required to 
register themselves and information about their AI system in an EU database, to be established 
and managed by the Commission. Before using an AI system listed in the high-risk use cases in 
an annex to this Regulation, deployers of high-risk AI systems that are public authorities, 
agencies or bodies, should register themselves in such database and select the system that they 
envisage to use. Other deployers should be entitled to do so voluntarily. This section of the EU 
database should be publicly accessible, free of charge, the information should be easily 
navigable, understandable and machine-readable. The EU database should also be user-friendly, 
for example by providing search functionalities, including through keywords, allowing the general 
public to find relevant information to be submitted upon the registration of high-risk AI systems 
and on the use case of high-risk AI systems, set out in an annex to this Regulation, to which the 
high-risk AI systems correspond. Any substantial modification of high-risk AI systems should also 
be registered in the EU database. For high-risk AI systems in the area of law enforcement, 
migration, asylum and border control management, the registration obligations should be fulfilled 
in a secure non-public section of the EU database. Access to the secure non-public section 
should be strictly limited to the Commission as well as to market surveillance authorities with 

--- PAGE 102 ---
regard to their national section of that database. High-risk AI systems in the area of critical 
infrastructure should only be registered at national level. The Commission should be the controller 
of the EU database, in accordance with Regulation (EU) 2018/1725. In order to ensure the full 
functionality of the EU database, when deployed, the procedure for setting the database should 
include the development of functional specifications by the Commission and an independent audit 
report. The Commission should take into account cybersecurity risks when carrying out its tasks 
as data controller on the EU database. In order to maximise the availability and use of the EU 
database by the public, the EU database, including the information made available through it, 
should comply with requirements under the Directive (EU) 2019/882. 
This Recital relates to 
​
Article 12: Record-keeping 
​
Article 13: Transparency and provision of information to deployers 
​
Article 49: Registration 
​
Article 71: EU database for high-risk AI systems listed in Annex III 
Recital 132 
Certain AI systems intended to interact with natural persons or to generate content may pose 
specific risks of impersonation or deception irrespective of whether they qualify as high-risk or not. 
In certain circumstances, the use of these systems should therefore be subject to specific 
transparency obligations without prejudice to the requirements and obligations for high-risk AI 
systems and subject to targeted exceptions to take into account the special need of law 
enforcement. In particular, natural persons should be notified that they are interacting with an AI 
system, unless this is obvious from the point of view of a natural person who is reasonably 
well-informed, observant and circumspect taking into account the circumstances and the context 
of use. When implementing that obligation, the characteristics of natural persons belonging to 
vulnerable groups due to their age or disability should be taken into account to the extent the AI 
system is intended to interact with those groups as well. Moreover, natural persons should be 
notified when they are exposed to AI systems that, by processing their biometric data, can identify 

--- PAGE 103 ---
or infer the emotions or intentions of those persons or assign them to specific categories. Such 
specific categories can relate to aspects such as sex, age, hair colour, eye colour, tattoos, 
personal traits, ethnic origin, personal preferences and interests. Such information and 
notifications should be provided in accessible formats for persons with disabilities. 
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
​
Article 50: Transparency obligations for providers and deployers of certain AI systems 
Recital 134 
Further to the technical solutions employed by the providers of the AI system, deployers who use 
an AI system to generate or manipulate image, audio or video content that appreciably resembles 
existing persons, objects, places, entities or events and would falsely appear to a person to be 
authentic or truthful (deep fakes), should also clearly and distinguishably disclose that the content 
has been artificially created or manipulated by labelling the AI output accordingly and disclosing 
its artificial origin. Compliance with this transparency obligation should not be interpreted as 
indicating that the use of the AI system or its output impedes the right to freedom of expression 
and the right to freedom of the arts and sciences guaranteed in the Charter, in particular where 
the content is part of an evidently creative, satirical, artistic, fictional or analogous work or 
programme, subject to appropriate safeguards for the rights and freedoms of third parties. In 
those cases, the transparency obligation for deep fakes set out in this Regulation is limited to 
disclosure of the existence of such generated or manipulated content in an appropriate manner 
that does not hamper the display or enjoyment of the work, including its normal exploitation and 
use, while maintaining the utility and quality of the work. In addition, it is also appropriate to 
envisage a similar disclosure obligation in relation to AI-generated or manipulated text to the 
extent it is published with the purpose of informing the public on matters of public interest unless 
the AI-generated content has undergone a process of human review or editorial control and a 
natural or legal person holds editorial responsibility for the publication of the content. 
This Recital relates to 

--- PAGE 104 ---
​
Article 26: Obligations of deployers of high-risk AI systems 
​
Article 50: Transparency obligations for providers and deployers of certain AI systems 
Recital 136 
The obligations placed on providers and deployers of certain AI systems in this Regulation to 
enable the detection and disclosure that the outputs of those systems are artificially generated or 
manipulated are particularly relevant to facilitate the effective implementation of Regulation (EU) 
2022/2065. This applies in particular as regards the obligations of providers of very large online 
platforms or very large online search engines to identify and mitigate systemic risks that may arise 
from the dissemination of content that has been artificially generated or manipulated, in particular 
the risk of the actual or foreseeable negative effects on democratic processes, civic discourse and 
electoral processes, including through disinformation. The requirement to label content generated 
by AI systems under this Regulation is without prejudice to the obligation in Article 16(6) of 
Regulation (EU) 2022/2065 for providers of hosting services to process notices on illegal content 
received pursuant to Article 16(1) of that Regulation and should not influence the assessment and 
the decision on the illegality of the specific content. That assessment should be performed solely 
with reference to the rules governing the legality of the content. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 26: Obligations of deployers of high-risk AI systems 
​
Article 50: Transparency obligations for providers and deployers of certain AI systems 
Recital 137 
Compliance with the transparency obligations for the AI systems covered by this Regulation 
should not be interpreted as indicating that the use of the AI system or its output is lawful under 
this Regulation or other Union and Member State law and should be without prejudice to other 
transparency obligations for deployers of AI systems laid down in Union or national law. 

--- PAGE 105 ---
This Recital relates to 
​
Article 13: Transparency and provision of information to deployers 
​
Article 50: Transparency obligations for providers and deployers of certain AI systems 
Recital 143 
In order to promote and protect innovation, it is important that the interests of SMEs, including 
start-ups, that are providers or deployers of AI systems are taken into particular account. To that 
end, Member States should develop initiatives, which are targeted at those operators, including 
on awareness raising and information communication. Member States should provide SMEs, 
including start-ups, that have a registered office or a branch in the Union, with priority access to 
the AI regulatory sandboxes provided that they fulfil the eligibility conditions and selection criteria 
and without precluding other providers and prospective providers to access the sandboxes 
provided the same conditions and criteria are fulfilled. Member States should utilise existing 
channels and where appropriate, establish new dedicated channels for communication with 
SMEs, including start-ups, deployers, other innovators and, as appropriate, local public 
authorities, to support SMEs throughout their development path by providing guidance and 
responding to queries about the implementation of this Regulation. Where appropriate, these 
channels should work together to create synergies and ensure homogeneity in their guidance to 
SMEs, including start-ups, and deployers. Additionally, Member States should facilitate the 
participation of SMEs and other relevant stakeholders in the standardisation development 
processes. Moreover, the specific interests and needs of providers that are SMEs, including 
start-ups, should be taken into account when notified bodies set conformity assessment fees. The 
Commission should regularly assess the certification and compliance costs for SMEs, including 
start-ups, through transparent consultations and should work with Member States to lower such 
costs. For example, translation costs related to mandatory documentation and communication 
with authorities may constitute a significant cost for providers and other operators, in particular 
those of a smaller scale. Member States should possibly ensure that one of the languages 
determined and accepted by them for relevant providers’ documentation and for communication 
with operators is one which is broadly understood by the largest possible number of cross-border 
deployers. In order to address the specific needs of SMEs, including start-ups, the Commission 

--- PAGE 106 ---
should provide standardised templates for the areas covered by this Regulation, upon request of 
the Board. Additionally, the Commission should complement Member States’ efforts by providing 
a single information platform with easy-to-use information with regards to this Regulation for all 
providers and deployers, by organising appropriate communication campaigns to raise awareness 
about the obligations arising from this Regulation, and by evaluating and promoting the 
convergence of best practices in public procurement procedures in relation to AI systems. 
Medium-sized enterprises which until recently qualified as small enterprises within the meaning of 
the Annex to Commission Recommendation 2003/361/EC(44)should have access to those 
support measures, as those new medium-sized enterprises may sometimes lack the legal 
resources and training necessary to ensure proper understanding of, and compliance with, this 
Regulation. 
This Recital relates to 
​
Article 26: Obligations of deployers of high-risk AI systems 
​
Article 57: AI regulatory sandboxes 
​
Article 58: Detailed arrangements for, and functioning of, AI regulatory sandboxes 
​
Article 59: Further processing of personal data for developing certain AI systems in the 
public interest in the AI regulatory sandbox 
​
Article 62: Measures for providers and deployers, in particular SMEs, including start-ups 
Recital 145 
In order to minimise the risks to implementation resulting from lack of knowledge and expertise in 
the market as well as to facilitate compliance of providers, in particular SMEs, including start-ups, 
and notified bodies with their obligations under this Regulation, the AI-on-demand platform, the 
European Digital Innovation Hubs and the testing and experimentation facilities established by the 
Commission and the Member States at Union or national level should contribute to the 
implementation of this Regulation. Within their respective mission and fields of competence, the 
AI-on-demand platform, the European Digital Innovation Hubs and the testing and 

--- PAGE 107 ---
experimentation Facilities are able to provide in particular technical and scientific support to 
providers and notified bodies. 
This Recital relates to 
​
Article 16: Obligations of providers of high-risk AI systems 
​
Article 57: AI regulatory sandboxes 
​
Article 58: Detailed arrangements for, and functioning of, AI regulatory sandboxes 
​
Article 59: Further processing of personal data for developing certain AI systems in the 
public interest in the AI regulatory sandbox 
​
Article 60: Testing of high-risk AI systems in real world conditions outside AI regulatory 
sandboxes 
​
Article 61: Informed consent to participate in testing in real world conditions outside AI 
regulatory sandboxes 
​
Article 62: Measures for providers and deployers, in particular SMEs, including start-ups 
​
Article 63: Derogations for specific operators 
 
 
Recital 146 
Moreover, in light of the very small size of some operators and in order to ensure proportionality 
regarding costs of innovation, it is appropriate to allow microenterprises to fulfil one of the most 
costly obligations, namely to establish a quality management system, in a simplified manner 
which would reduce the administrative burden and the costs for those enterprises without 
affecting the level of protection and the need for compliance with the requirements for high-risk AI 

--- PAGE 108 ---
systems. The Commission should develop guidelines to specify the elements of the quality 
management system to be fulfilled in this simplified manner by microenterprises. 
This Recital relates to 
​
Article 17: Quality management system 
​
Article 34: Operational obligations of notified bodies 
​
Article 63: Derogations for specific operators 
Recital 155 
In order to ensure that providers of high-risk AI systems can take into account the experience on 
the use of high-risk AI systems for improving their systems and the design and development 
process or can take any possible corrective action in a timely manner, all providers should have a 
post-market monitoring system in place. Where relevant, post-market monitoring should include 
an analysis of the interaction with other AI systems including other devices and software. 
Post-market monitoring should not cover sensitive operational data of deployers which are law 
enforcement authorities. This system is also key to ensure that the possible risks emerging from 
AI systems which continue to ‘learn’ after being placed on the market or put into service can be 
more efficiently and timely addressed. In this context, providers should also be required to have a 
system in place to report to the relevant authorities any serious incidents resulting from the use of 
their AI systems, meaning incident or malfunctioning leading to death or serious damage to 
health, serious and irreversible disruption of the management and operation of critical 
infrastructure, infringements of obligations under Union law intended to protect fundamental rights 
or serious damage to property or the environment. 
This Recital relates to 
​
Article 20: Corrective actions and duty of information 
​
Article 72: Post-market monitoring by providers and post-market monitoring plan for 
high-risk AI systems 

--- PAGE 109 ---
​
Article 73: Reporting of serious incidents 
Recital 159 
Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in 
an annex to this Regulation insofar as those systems are used for the purposes of law 
enforcement, migration, asylum and border control management, or the administration of justice 
and democratic processes, should have effective investigative and corrective powers, including at 
least the power to obtain access to all personal data that are being processed and to all 
information necessary for the performance of its tasks. The market surveillance authorities should 
be able to exercise their powers by acting with complete independence. Any limitations of their 
access to sensitive operational data under this Regulation should be without prejudice to the 
powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national 
data protection authorities under this Regulation should affect the current or future powers of 
those authorities beyond the scope of this Regulation. 
This Recital relates to 
​
Article 20: Corrective actions and duty of information 
 
 
Recital 176 
Since the objective of this Regulation, namely to improve the functioning of the internal market 
and to promote the uptake of human centric and trustworthy AI, while ensuring a high level of 
protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the 
rule of law and environmental protection against harmful effects of AI systems in the Union and 
supporting innovation, cannot be sufficiently achieved by the Member States and can rather, by 
reason of the scale or effects of the action, be better achieved at Union level, the Union may 

--- PAGE 110 ---
adopt measures in accordance with the principle of subsidiarity as set out in Article 5 TEU. In 
accordance with the principle of proportionality as set out in that Article, this Regulation does not 
go beyond what is necessary in order to achieve that objective. 
 
 
