EU-AI-Act
Regulation (EU) 2024/1689 — Artificial Intelligence Act
- I. General Provisions
- Art. 1. Subject matter ref
- Art. 2. Scope ref
- Art. 3. Definitions ref
- Art. 4. AI literacy ref
- II. Prohibited AI Practices
- Art. 5. Prohibited artificial intelligence practices ref
- III. High-Risk AI Systems
- Ch. 1 — Classification of AI Systems as High-Risk
- Art. 6. Classification rules for high-risk AI systems (7)
- Art. 7. Amendments to Annex III (12)
- Ch. 2 — Requirements for High-Risk AI Systems
- Art. 8. Compliance with the requirements (5)
- Art. 9. Risk management system (15)
- Art. 10. Data and data governance (20)
- Art. 11. Technical documentation (7)
- Art. 12. Record-keeping (8)
- Art. 13. Transparency and provision of information to deployers (14)
- Art. 14. Human oversight (11)
- Art. 15. Accuracy, robustness and cybersecurity (9)
- Ch. 3 — Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties
- Art. 16. Obligations of providers of high-risk AI systems (12)
- Art. 17. Quality management system (16)
- Art. 18. Documentation keeping (6)
- Art. 19. Automatically generated logs (2)
- Art. 20. Corrective actions and duty of information (5)
- Art. 21. Cooperation with competent authorities (3)
- Art. 22. Duty of providers of high-risk AI systems to inform (2)
- Art. 23. Obligations of importers (12)
- Art. 24. Obligations of distributors (10)
- Art. 25. Responsibilities along the AI value chain (9)
- Ch. 4 — Obligations of Deployers of High-Risk AI Systems
- Art. 26. Obligations of deployers of high-risk AI systems (17)
- Art. 27. Fundamental rights impact assessment for high-risk AI systems (10)
- Ch. 5 — Notifying Authorities and Notified Bodies
- Art. 28. Notifying authorities (8)
- IV. Transparency Obligations for Providers and Deployers of Certain AI Systems
- Art. 50. Transparency obligations for providers and deployers of certain AI systems (9)
- V. General-Purpose AI Models
- Ch. 1 — Classification Rules
- Art. 51. Classification of general-purpose AI models as general-purpose AI models with systemic risk (4)
- Ch. 2 — Obligations for Providers of General-Purpose AI Models
- Art. 53. Obligations for providers of general-purpose AI models (6)
- Art. 54. Authorised representatives of providers of general-purpose AI models (11)
- Art. 55. Obligations for providers of general-purpose AI models with systemic risk (6)
- Art. 56. Codes of practice (8)
- VIII. Post-Market Monitoring, Information Sharing and Market Surveillance
- Ch. 1 — Post-Market Monitoring
- Art. 72. Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems (7)
- Ch. 2 — Sharing of Information on Serious Incidents
- Art. 73. Reporting of serious incidents (12)
- X. Codes of Conduct and Guidelines
- Art. 95. Codes of conduct for voluntary application of specific requirements (6)
- XII. Penalties
- Art. 99. Penalties (8)
- Art. 100. Administrative fines on Union institutions, bodies, offices and agencies (7)
- Art. 101. Penalties for providers of general-purpose AI models (4)
- Annex I. Union Harmonisation Legislation Listed in Article 6(1)
- Annex III. High-Risk AI Systems Referred to in Article 6(2)
- Annex IV. Technical Documentation Referred to in Article 11(1)
Risk Management Obligations
23Title I — General Provisions
Title II — Prohibited AI Practices
Title III — High-Risk AI Systems
Chapter 1 — Classification of AI Systems as High-Risk
Chapter 2 — Requirements for High-Risk AI Systems
Article 9. Risk management system
12 obligations
EU-AIA-9-01
Risk Management
Establish risk management system for high-risk AI systems
A risk management system must be established, implemented, documented and maintained in relation to high-risk AI systems
EU-AIA-9-02
Risk Management
Implement continuous iterative risk management process
The risk management system must be understood as a continuous iterative process planned and run throughout the entire li
EU-AIA-9-03
Risk Management
Identify and analyze known and reasonably foreseeable risks
Providers must identify and analyze the known and the reasonably foreseeable risks that the high-risk AI system can pose
EU-AIA-9-04
Risk Management
Estimate and evaluate risks under intended use and foreseeable misuse
Providers must estimate and evaluate the risks that may emerge when the high-risk AI system is used in accordance with i
EU-AIA-9-05
Risk Management
Evaluate risks from post-market monitoring data
Providers must evaluate other risks possibly arising, based on the analysis of data gathered from the post-market monito
EU-AIA-9-06
Risk Management
Adopt appropriate and targeted risk management measures
Providers must adopt appropriate and targeted risk management measures designed to address the risks identified through
EU-AIA-9-07
Risk Management
Consider combined effects of requirements in risk management
Risk management measures must give due consideration to the effects and possible interactions resulting from the combine
EU-AIA-9-08
Risk Management
Ensure acceptable residual risk levels
Risk management measures must ensure that the relevant residual risk associated with each hazard, as well as the overall
EU-AIA-9-09
Risk Management
Eliminate or reduce risks through adequate design and development
Providers must ensure elimination or reduction of identified and evaluated risks as far as technically feasible through
EU-AIA-9-10
Risk Management
Implement mitigation and control measures for non-eliminable risks
Where appropriate, providers must implement adequate mitigation and control measures addressing risks that cannot be eli
EU-AIA-9-12
Risk Management
Test high-risk AI systems for risk management purposes
High-risk AI systems must be tested for the purpose of identifying the most appropriate and targeted risk management mea
EU-AIA-9-15
Risk Management
Consider impact on minors and vulnerable groups in risk management
When implementing the risk management system, providers must give consideration to whether, in light of its intended pur
Article 10. Data and data governance
2 obligations
EU-AIA-10-08
Risk Management
Examine data for possible biases
Data governance practices must include examination for possible biases that are likely to affect health and safety, nega
EU-AIA-10-09
Risk Management
Implement bias detection, prevention and mitigation measures
Data governance practices must include appropriate measures to detect, prevent and mitigate possible biases identified i
Chapter 3 — Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties
Article 16. Obligations of providers of high-risk AI systems
1 obligation
Article 17. Quality management system
1 obligation
Article 20. Corrective actions and duty of information
1 obligation
Chapter 4 — Obligations of Deployers of High-Risk AI Systems
Article 27. Fundamental rights impact assessment for high-risk AI systems
4 obligations
EU-AIA-27-01
Risk Management
Perform fundamental rights impact assessment before deployment
Prior to deploying a high-risk AI system, specified deployers must perform an assessment of the impact on fundamental ri
EU-AIA-27-04
Risk Management
Identify categories of persons affected by AI system use
As part of the fundamental rights impact assessment, deployers must identify the categories of natural persons and group
EU-AIA-27-05
Risk Management
Assess specific risks of harm to affected persons
As part of the fundamental rights impact assessment, deployers must assess the specific risks of harm likely to impact t
EU-AIA-27-07
Risk Management
Define measures for when risks materialize
As part of the fundamental rights impact assessment, deployers must define the measures to be taken when identified risk
Chapter 5 — Notifying Authorities and Notified Bodies
Title IV — Transparency Obligations for Providers and Deployers of Certain AI Systems
Title V — General-Purpose AI Models
Chapter 1 — Classification Rules
Chapter 2 — Obligations for Providers of General-Purpose AI Models
Article 55. Obligations for providers of general-purpose AI models with systemic risk
1 obligation
Title VIII — Post-Market Monitoring, Information Sharing and Market Surveillance
Chapter 1 — Post-Market Monitoring
Chapter 2 — Sharing of Information on Serious Incidents
Article 73. Reporting of serious incidents
1 obligation