SkarpSkarp
The EU Artificial Intelligence Act: A Section-by-Section Deep Dive into Regulation (EU) 2024/1689
💻 TechnologyAdvanced9h 32m25 modules

The EU Artificial Intelligence Act: A Section-by-Section Deep Dive into Regulation (EU) 2024/1689

This advanced course walks through Regulation (EU) 2024/1689 in document order, from its legal foundations and recitals to its operative rules, enforcement regime, amendments, footnotes and annexes. Learners will be able to navigate the AI Act’s risk-based architecture, determine how its principal obligations apply, and connect its detailed compliance mechanisms to the Regulation’s policy rationale.

by Skarp_officialen

Course Content

25 modules · 9h 32m total

1

The AI Act as a Union Legislative Instrument

The course opens by situating Regulation (EU) 2024/1689 as a binding act of the European Parliament and Council and tracing the policy ambitions announced in its opening recitals. Its internal-market foundation is paired from the outset with human-centric AI, fundamental rights and continuity with existing Union law.

16 min
2

Core Concepts, Reach and the Risk-Based Framework

What counts as AI, where does the Act reach, and which activities remain outside it? This module follows the recitals as they establish technical and biometric concepts, territorial connections, exclusions, AI literacy and the ethical background to the risk-based framework.

21 min
3

The Boundary of Unacceptable AI

The Act draws its hardest line around practices considered incompatible with Union values. This module examines the rationales for banning manipulation, exploitation, social scoring and other practices while permitting only tightly controlled law-enforcement biometric exceptions.

20 min
4

How the Act Identifies High-Risk AI

High-risk status turns on both a general classification logic and a detailed set of sensitive use areas. The recitals show how product components, stand-alone systems, profiling and decision influence determine whether demanding obligations attach.

24 min
5

The Compliance Design of High-Risk Systems

The recitals turn high-risk status into a lifecycle engineering and governance discipline. Risk management, data quality, logging, human oversight and resilience are treated as mutually supporting controls rather than isolated paperwork duties.

22 min
6

Responsibility Across the AI Value Chain

AI compliance rarely rests with a single organisation. This module follows responsibility from providers and component suppliers through importers, distributors, product manufacturers and deployers, including circumstances that transfer provider status.

20 min
7

General-Purpose AI Models and Systemic Risk

The recitals introduce a regulatory layer for models capable of serving many downstream purposes, including the most powerful and widely deployed models. Documentation, copyright, evaluations, incident reporting and codes of practice form a proportionate regime that changes when systemic risk emerges.

27 min
8

Standards, Conformity and Public Transparency

How does an operator demonstrate compliance, and what must people be told when AI shapes their experience? The recitals connect standards, conformity assessment, CE marking and registration with disclosures for synthetic content, deep fakes and human–AI interaction.

21 min
9

Innovation Support and the Governance Architecture

The Act pairs strict controls with supervised routes for experimentation and institutional support. Its recitals establish sandboxes for innovators while building a multilevel network of Union bodies, national authorities, experts and testing structures.

29 min
10

Supervision, Remedies and the Recitals’ Closing Framework

The final recitals allocate supervision among financial, biometric, national and Union authorities before turning to remedies, penalties, review and staged application. They reveal how the Act intends to move from legislative design to phased, revisable enforcement.

20 min
11

General Provisions and the Act’s Defined Vocabulary

The operative text begins by converting the recitals’ policy logic into binding subject-matter, scope and definitions. Articles 1–3 supply the vocabulary needed to interpret every later obligation, from operators and conformity to biometrics, incidents, testing and general-purpose AI.

27 min
12

AI Literacy, Prohibitions and Binding High-Risk Classification

The first substantive operative duties move rapidly from workforce competence to categorical prohibitions and high-risk classification. Articles 4–10 show how the Act translates its risk hierarchy into literacy measures, bans, classification records and continuous controls over risks and data.

25 min
13

High-Risk System Evidence and Provider Controls

Compliance must be built into the system and preserved as evidence. Articles 11–21 connect documentation, automatic logs, instructions, oversight and resilience with the provider’s quality system, retention, corrective action and regulatory cooperation.

27 min
14

Operators, Deployers and Fundamental-Rights Impact Assessments

Once a high-risk system moves through distribution and into use, responsibility shifts but does not disappear. Articles 22–27 allocate verification, contractual support, monitoring, worker notice and impact-assessment duties across the full chain.

27 min
15

Notifying Authorities and Notified Bodies

Independent conformity assessment depends on a regulated institutional chain of its own. Articles 28–39 govern who may assess systems, how competence is demonstrated, how subcontracting and certificates are controlled, and what happens when confidence in a notified body fails.

23 min
16

Proving Conformity and Entering the Union Market

Articles 40–49 turn technical standards into concrete routes to market. This module follows presumptions of conformity through assessment routes, certificates, emergency derogations, declarations, CE marking and database registration.

23 min
17

Transparency and General-Purpose AI Obligations

The Act regulates what people must be told and what downstream developers must receive. Article 50’s public-facing disclosures sit alongside the classification, documentation, copyright and systemic-risk duties imposed on general-purpose AI model providers.

27 min
18

Sandboxes and Testing in Real-World Conditions

Innovation moves from principle to supervised procedure in Chapter VI. Articles 57–61 establish sandbox access, protected personal-data processing and tightly controlled real-world testing, including plans, consent, incident response and continuing liability.

18 min
19

SME Support and the Institutions of AI Governance

The Act’s governance system combines practical support for smaller operators with coordination at Union and national levels. Articles 62–70 establish reduced burdens, expert institutions and independent authorities expected to make implementation consistent and technically credible.

21 min
20

Registration, Monitoring and Market Surveillance

After market entry, the Act relies on information flows: database records, monitoring plans, incident reports and supervisory access. Articles 71–78 show how those flows support sectoral surveillance while protecting rights, confidential information and cybersecurity.

24 min
21

Risk Procedures, Remedies and General-Purpose AI Enforcement

The enforcement chapters address systems that are risky, misclassified, formally defective or compliant on paper but dangerous in practice. They also give the Commission and AI Office specialised powers over general-purpose AI models while preserving complaint, explanation and whistleblower channels.

20 min
22

Soft-Law Guidance, Penalties and Legislative Integration

The Act combines voluntary guidance with formidable sanctions and targeted amendments to existing Union legislation. Articles 95–110 show how responsible practices can extend beyond high-risk systems, how infringements are fined and how AI safety is integrated into sectoral regimes.

21 min
23

Transition, Application and the Act’s Legal Reference Network

The operative text closes with transition rules, evaluation duties and a staged timetable rather than a single compliance date. The accompanying footnotes reveal the dense legal network—from data protection and product safety to copyright and whistleblower law—on which the Act relies.

24 min
24

Annexes I–VI: Classification and Core Compliance Evidence

The annexes turn abstract legal duties into lists, templates and technical specifications. This module connects product legislation and serious-offence exceptions to Annex III use cases, Annex IV documentation and the formal evidence required for declarations and internal-control assessment.

23 min
25

Annexes VII–XIII: Operational Compliance and the Act as a Whole

The final annexes supply the operational detail for notified-body assessment, registration, real-world testing, transitional IT systems and general-purpose AI documentation. Together they consolidate the Act as a complete chain from classification and evidence to market access, deployment, monitoring and enforcement.

22 min

Read the Textbook

Read every chapter for free, right here in your browser.

The AI Act as a Union Legislative Instrument

This module examines the opening material of Regulation (EU) 2024/1689, the Artificial Intelligence Act. It was adopted by the European Parliament and the Council on 13 June 2024 and published in the Official Journal on 12 July 2024.

The assigned text begins with the Regulation's formal identity, its Treaty bases, the legislative procedure, and Recitals (1) to (11). These recitals explain why the Union adopted the instrument and how it is intended to relate to other areas of Union law.

Study Flashcards

Key concepts from this course as flashcard pairs.

The AI Act as a Union Legislative Instrument

Recital (1): Core purpose

The purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework.

Recital (1): Cross-border movement

This Regulation ensures the free movement, cross-border, of AI-based goods and services.

Recital (3): Main concern

Diverging national rules may fragment the internal market and decrease legal certainty for operators.

Recital (5): Types of possible harm

Harm might be material or immaterial, including physical, psychological, societal, or economic harm.

Recital (6): Human-centric AI

As a prerequisite, AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being.

Recital (9): Existing rights

Rights and remedies under relevant Union law remain unaffected and fully applicable.

+1 more flashcards

Core Concepts, Reach and the Risk-Based Framework

Inference

A core AI characteristic. It concerns obtaining outputs such as predictions, content, recommendations or decisions, and can include deriving models or algorithms from inputs or data.

Deployer

Any natural or legal person, including a public authority, agency or other body, using an AI system under its authority, except personal non-professional use.

Biometric identification

Automated recognition to establish identity by comparing a person's biometric data with stored biometric data in a reference database.

Biometric verification

Authentication whose sole purpose is confirming that a specific person is who they claim to be for access to a service, device or premises.

Real-time remote biometric identification

Capture, comparison and identification occur instantaneously, near-instantaneously or without significant delay using live or near-live material.

Post remote biometric identification

Biometric data was captured earlier; comparison and identification occur only after a significant delay.

+2 more flashcards

The Boundary of Unacceptable AI

What is the central concern in Recital (29)?

Material distortion of behaviour through subliminal, manipulative, deceptive, or exploitative AI-enabled practices, causing or reasonably likely to cause significant harm.

Does Recital (29) require intent to cause significant harm?

No. It says intent to cause significant harm is not necessary, provided harm results from the manipulative or exploitative AI-enabled practice.

What makes social scoring unacceptable in Recital (31)?

A score leading to detrimental or unfavourable treatment in unrelated social contexts, or treatment disproportionate or unjustified to the gravity of social behaviour.

What is the criminal-offence threshold for the Recital (33) biometric-identification exception?

The offence must be punishable by "a custodial sentence or a detention order for a maximum period of at least four years" in the Member State concerned.

What is the urgent authorisation deadline in Recital (35)?

The authority should request authorisation "without undue delay and at the latest within 24 hours."

What facial-database practice does Recital (43) identify?

Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

How the Act Identifies High-Risk AI

Product-related high-risk trigger

Under Recital (50), classification is appropriate where the relevant product undergoes a conformity-assessment procedure with a third-party conformity assessment body under the relevant Union harmonisation legislation.

Stand-alone AI route

Under Recital (52), intended purpose must pose a high risk of harm to health and safety or fundamental rights, considering severity and probability, and the system must be used in specifically pre-defined areas.

Material influence

An AI system does not materially influence a decision where it does not affect the substance, and thereby the outcome, of human or automated decision-making.

Profiling qualifier

In high-risk use-cases listed in an annex, Recital (53) says a system should be considered to pose significant risks if it implies profiling under the referenced data-protection definitions.

Biometric verification exclusion

Biometric verification, including authentication, is excluded where its sole purpose is confirming a specific person is who they claim to be and confirming identity solely for access to a service, device, or premises.

Critical-infrastructure safety component

A component used directly to protect physical integrity of critical infrastructure or health and safety of persons and property, but not necessary for the system to function. Cybersecurity-only components do not qualify.

+2 more flashcards

The Compliance Design of High-Risk Systems

Continuous, iterative risk management

A process planned and run throughout the entire lifecycle of a high-risk AI system, regularly reviewed and updated for continuing effectiveness.

Reasonably foreseeable misuse

Use outside the intended purpose or instructions that may nevertheless be reasonably expected from readily predictable human behaviour in the system's particular context.

Data quality standard

Training, validation, and testing data sets, including labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete for the intended purpose.

Feedback loop

A situation in which AI outputs influence inputs for future operations, allowing bias to gradually increase, perpetuate, or amplify discrimination.

Technical documentation

Clear and comprehensive, up-to-date information on characteristics, capabilities, limitations, algorithms, data, training, testing, validation, and the risk-management system.

Automatic logs

High-risk AI systems should technically allow automatic recording of events by logs over the system's lifetime.

+4 more flashcards

Responsibility Across the AI Value Chain

Provider responsibility

Recital (79): "a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system" regardless of whether that person designed or developed it.

Third-country representative

Recital (82): "providers established in third countries should, by written mandate, appoint an authorised representative established in the Union."

Overlapping operator roles

An operator acting in more than one role should fulfil cumulatively all relevant obligations associated with those roles; Recital (83) gives importer and distributor as an example.

Provider reassignment

Recital (84): "any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations" under its stated conditions.

Supplier assistance

Recital (88): suppliers "should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance" while not compromising IP rights or trade secrets.

Deployer use measures

Recital (91): "Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use".

+1 more flashcards

General-Purpose AI Models and Systemic Risk

General-purpose model characteristics

Recital (97): "the generality and the capability to competently perform a wide range of distinct tasks."

One-billion-parameter indicator

Recital (98): "models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality".

Open-source licence formulation

Recital (102): "allows users to run, copy, distribute, study, change and improve software and data, including models".

Open-source systemic-risk limit

Recital (104): transparency-related exceptions apply "unless they can be considered to present a systemic risk".

Copyright policy

Recital (106): "providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights".

Public training-content summary

Recital (107): providers should "draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model."

+6 more flashcards

Standards, Conformity and Public Transparency

Harmonised standards

Recital (121): compliance with harmonised standards should be a means for providers to demonstrate conformity with the Regulation's requirements.

Common specifications

Recital (121): an exceptional fall back solution, established by the Commission through implementing acts after consultation of the advisory forum when specified standardisation problems arise.

Pre-market assessment

Recital (123): high-risk AI systems should be subject to a conformity assessment prior to their placing on the market or putting into service.

Substantial modification

Recital (128): a compliance-affecting change or a changed intended purpose can mean the system is considered a new AI system and should undergo a new conformity assessment.

CE marking

Recital (129): high-risk AI systems should bear CE marking to indicate conformity with the Regulation.

AI interaction notice

Recital (132): natural persons should be notified that they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant, and circumspect person in context.

+3 more flashcards

Innovation Support and the Governance Architecture

AI regulatory sandbox

A controlled setting for development and testing under strict regulatory oversight before an innovative AI system is placed on the market or put into service.

Priority access for SMEs

SMEs, including start-ups, with a registered office or branch in the Union should receive priority access to sandboxes if they fulfil eligibility conditions and selection criteria.

Microenterprise simplification

Microenterprises may fulfil the quality-management-system obligation in a simplified manner; this does not remove high-risk compliance requirements or reduce the intended protection level.

AI Office mission

To develop Union expertise and capabilities in AI and contribute to implementation of Union law on AI.

National competent authorities

Each Member State should designate at least one notifying authority and at least one market surveillance authority.

Single point of contact

Each Member State should designate a market surveillance authority to act as a single point of contact.

+2 more flashcards

Supervision, Remedies and the Recitals’ Closing Framework

Financial-sector oversight

Recital (158): existing financial competent authorities should generally supervise AI systems of regulated financial institutions within their competences, unless a Member State designates another market-surveillance authority.

Biometric authority access

Recital (159): authorities should have effective investigative and corrective powers, including access to all personal data being processed and all information necessary for their tasks.

Same provider: model plus system

Recital (161): supervision should take place at Union level through the AI Office.

General-purpose model provider enforcement

Recital (162): supervision and enforcement powers over provider obligations should be a competence of the Commission.

Complaint route

Recital (170): a natural or legal person with grounds to consider that the Regulation was infringed should be entitled to complain to the relevant market-surveillance authority.

First general review

Recital (174): the Commission should evaluate and review the Regulation by 2 August 2029 and every four years thereafter.

+1 more flashcards

General Provisions and the Act’s Defined Vocabulary

AI system

A machine-based system with varying autonomy that may adapt after deployment and, for explicit or implicit objectives, infers from inputs how to generate outputs that can influence physical or virtual environments.

Risk

The combination of the probability of an occurrence of harm and the severity of that harm.

Provider

A person or body that develops, or has developed, an AI system or general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether paid or free.

Deployer

A person or body using an AI system under its authority, except where it is used in a personal non-professional activity.

Substantial modification

An unplanned post-market or post-service change that affects Chapter III, Section 2 compliance or changes the intended purpose for which the system was assessed.

Remote biometric identification system

An AI system that identifies natural persons without their active involvement, typically at a distance, by comparing biometric data with a reference database.

+2 more flashcards

AI Literacy, Prohibitions and Binding High-Risk Classification

Article 4: Who must take AI-literacy measures?

Providers and deployers of AI systems shall take measures for a sufficient level of AI literacy among relevant staff and other persons dealing with operation and use on their behalf.

Article 5(1)(e): What facial-recognition practice is prohibited?

Creating or expanding facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.

Article 5(3): What is the urgent authorisation deadline?

Authorisation must be requested without undue delay, at the latest within 24 hours.

Article 5(3): Can adverse legal effect rest solely on real-time biometric output?

No. No decision producing an adverse legal effect may be taken based solely on that output.

Article 6(1): What two conditions create product-related high-risk status?

Annex I product or safety-component coverage, and a required third-party conformity assessment under that Annex I legislation.

Article 6(3): What defeats the Annex III non-high-risk derogation?

An Annex III system shall always be high-risk where it performs profiling of natural persons.

+2 more flashcards

High-Risk System Evidence and Provider Controls

Article 11 timing rule

"The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date."

Article 12 core obligation

The system shall technically allow automatic recording of events, or logs, over its lifetime.

Article 13 transparency outcome

Deployers must be able to interpret the output and use the system appropriately.

Article 14 automation bias

The possible tendency to automatically rely or over-rely on AI output, especially where it supplies information or recommendations for human decisions.

Article 15 lifecycle requirement

Appropriate accuracy, robustness, and cybersecurity must be achieved and performed consistently throughout the lifecycle.

Article 18 retention period

Specified documentation must be available to national competent authorities for a period ending 10 years after market placement or putting into service.

+2 more flashcards

Operators, Deployers and Fundamental-Rights Impact Assessments

Third-country provider: Article 22 entry condition?

Before making a high-risk system available on the Union market, it shall appoint, by written mandate, an authorised representative established in the Union.

How long must Article 22 materials be kept available?

For 10 years after the high-risk AI system has been placed on the market or put into service.

Importer: four Article 23 verification areas?

Conformity assessment; technical documentation; CE marking, declaration and instructions; and appointment of an authorised representative.

Distributor: response to suspected Section 2 non-conformity?

It shall not make the system available on the market until the system has been brought into conformity with those requirements.

Article 25: three ways another actor can become provider?

Putting its name or trademark on the system; substantial modification while it remains high-risk; or changing intended purpose so it becomes high-risk.

Deployer log-retention minimum?

A period appropriate to intended purpose, of at least six months, unless applicable Union or national law provides otherwise.

+2 more flashcards

Notifying Authorities and Notified Bodies

What must every Member State do under Article 28(1)?

Each Member State shall designate or establish at least one notifying authority.

Where does a conformity assessment body apply for notification?

To the notifying authority of the Member State in which it is established.

What are Article 30(4)'s objection periods?

Two weeks where the notification includes an Article 29(2) accreditation certificate; two months where it includes Article 29(3) documentary evidence.

What must notified bodies be independent of under Article 31(4)?

The provider of the high-risk AI system assessed, other operators with an economic interest in assessed systems, and competitors of the provider.

What does Article 31(11) require for external work?

Notified bodies shall have sufficient internal competences to be able effectively to evaluate tasks conducted by external parties on their behalf.

How long must Article 33(4) subcontracting records remain available?

Five years from the termination date of the subcontracting.

+2 more flashcards

Proving Conformity and Entering the Union Market

Harmonised-standard presumption

Article 40(1): conformity gives a presumption only where the standard reference is published in the Official Journal and only to the extent the standard covers the relevant requirements or obligations.

Common specifications

Article 41: Commission implementing acts available only when the listed standardisation and Official Journal conditions are fulfilled.

Annex III points 2-8

Article 43(2): providers shall follow Annex VI internal control; it does not provide for notified-body involvement.

Substantial modification

Article 43(4): a previously assessed system shall undergo a new conformity assessment procedure in the event of a substantial modification.

Certificate maximum

Article 44(2): five years for Annex I systems; four years for Annex III systems.

EU declaration retention

Article 47(1): keep it available to national competent authorities for 10 years after market placement or putting into service.

+2 more flashcards

Transparency and General-Purpose AI Obligations

Article 50(1): What must directly interactive AI systems communicate?

Providers shall ensure that **the natural persons concerned are informed that they are interacting with an AI system**, unless that is obvious from the specified reasonably informed person's perspective.

Article 50(2): What is the synthetic-output rule?

Providers shall ensure **the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated**.

Article 50(5): When is Article 50 information due?

In a clear and distinguishable manner **at the latest at the time of the first interaction or exposure**, and conforming to applicable accessibility requirements.

Article 51(2): What is the computation presumption?

A model is presumed to have high-impact capabilities when **the cumulative amount of computation used for its training measured in floating point operations is greater than 1025**.

Article 52(1): What is the notification deadline?

The provider must notify **without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met**.

Article 53: What four baseline items are required?

Up-to-date technical documentation; downstream information and documentation; a copyright-and-related-rights compliance policy; and a publicly available sufficiently detailed training-content summary.

+2 more flashcards

Sandboxes and Testing in Real-World Conditions

Sandbox plan

The specific plan agreed between the provider or prospective provider and the competent authority for the limited-time sandbox activity.

Exit report

A report the competent authority shall provide, detailing sandbox activities and related results and learning outcomes.

Written proof

On request, proof from the competent authority of activities successfully carried out in the sandbox.

SME access

Access is free of charge for SMEs, including start-ups, except fair and proportionate recovery of exceptional costs.

Annual reporting

National competent authorities submit annual reports to the AI Office and Board from one year after sandbox establishment, every year until termination, plus a final report.

SME Support and the Institutions of AI Governance

Article 62 sandbox rule

Member States shall provide eligible SMEs and start-ups with a registered office or branch in the Union priority access to AI regulatory sandboxes. Priority does not exclude other eligible SMEs or start-ups.

Article 62 fee rule

Conformity-assessment fees under Article 43 shall take account of SME provider interests and needs, including reducing fees proportionately to size, market size, and other relevant indicators.

Article 63 simplification

Eligible microenterprises without partner or linked enterprises may comply with certain Article 17 quality-management elements in a simplified manner. This is not a general exemption.

Article 64 AI Office

The Commission shall develop Union expertise and capabilities in AI through the AI Office.

Article 65 Board composition

The Board has one representative per Member State. The EDPS is an observer, and the AI Office attends without voting.

Article 66 Board purpose

The Board shall advise and assist the Commission and Member States to facilitate consistent and effective application of the Regulation.

+4 more flashcards

Registration, Monitoring and Market Surveillance

Who shall set up and maintain the EU database?

Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database."

Who enters Annex VIII Sections A and B data?

The provider or, where applicable, the authorised representative.

What is the ordinary outer reporting deadline for a serious incident?

Not later than 15 days after the provider or, where applicable, deployer becomes aware of the serious incident.

What deadline applies to a widespread infringement or Article 3, point (49)(b) incident?

Immediately, and not later than two days after the provider or, where applicable, deployer becomes aware of that incident.

What is the death-related outer deadline?

Not later than 10 days after the date on which the provider or, where applicable, deployer becomes aware of the serious incident.

When may source code be accessed under Article 74(13)?

Only upon a reasoned request, where access is necessary for conformity assessment and data/documentation-based testing, auditing and verification have been exhausted or proved insufficient.

+1 more flashcards

Risk Procedures, Remedies and General-Purpose AI Enforcement

Article 79 risk definition

AI systems presenting a risk are understood as a product presenting a risk under Article 3(19) of Regulation (EU) 2019/1020, insofar as they risk health, safety, or fundamental rights.

Article 79 corrective-action limit

The authority may prescribe the period, but action is required in any event within the shorter of 15 working days, or the period under relevant Union harmonisation legislation.

Article 80 misclassification consequence

If a provider misclassified a system as non-high-risk to circumvent Chapter III, Section 2, the provider is subject to Article 99 fines.

Article 82 key insight

A high-risk AI system may require corrective measures even though it complies with the Regulation, if it nevertheless presents a specified risk.

Article 85 complaint holder

Any natural or legal person with grounds to consider an infringement may submit a complaint to the relevant market surveillance authority.

Article 88 enforcement allocation

The Commission has exclusive powers to supervise and enforce Chapter V and entrusts implementation tasks to the AI Office.

+1 more flashcards

Soft-Law Guidance, Penalties and Legislative Integration

Article 95(1): What is the purpose of voluntary codes?

They are "intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2".

Article 95(2): What makes a voluntary code measurable?

It is based on clear objectives and key performance indicators to measure achievement of those objectives.

Article 96: Who must receive particular attention?

SMEs including start-ups, local public authorities, and sectors most likely to be affected by the Regulation.

Article 97: How long is the initial delegation?

Five years from 1 August 2024, with possible tacit extension for identical periods unless Parliament or Council objects in time.

Article 99(3): Prohibited-practice maximum

Up to EUR 35,000,000 or, for an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Article 99(6): SME fine rule

For SMEs, including start-ups, each fine is up to the percentage or amount in paragraphs 3, 4, and 5, whichever is lower.

+2 more flashcards

Transition, Application and the Act’s Legal Reference Network

Article 111(1): deadline for covered Annex X large-scale IT system AI components

They **"shall be brought into compliance with this Regulation by 31 December 2030"**, if placed on the market or put into service before 2 August 2027.

Article 111(2): condition for many pre-2 August 2026 high-risk systems

The Regulation applies only if, from 2 August 2026, those systems are subject to **significant changes in their designs**.

Article 111(2): public-authority high-risk systems

Providers and deployers **shall take the necessary steps** to comply by 2 August 2030.

Article 111(3): older general-purpose AI models

Providers of models placed on the market before 2 August 2025 shall take necessary steps to comply by 2 August 2027.

Article 112: first general evaluation-and-review report

By 2 August 2029, and every four years thereafter; it includes enforcement structure and possible need for a Union agency.

Article 113: general application date

**"It shall apply from 2 August 2026."**

+2 more flashcards

Annexes I–VI: Classification and Core Compliance Evidence

What are the two headings in Annex I?

"Section A. List of Union harmonisation legislation based on the New Legislative Framework" and "Section B. List of other Union harmonisation legislation".

What is the limited civil-aviation wording in Annex I?

"where it concerns unmanned aircraft and their engines, propellers, parts and equipment to control them remotely".

Name three Annex II offences using the source wording.

"terrorism"; "trafficking in human beings"; and "sexual exploitation of children, and child pornography".

What Annex III wording covers applicant filtering and candidate evaluation?

"AI systems intended to be used for the recruitment or selection of natural persons".

What does Annex IV require at minimum?

"The technical documentation referred to in Article 11(1) shall contain at least the following information, as applicable to the relevant AI system".

What must Annex VI point 2 verify?

"The provider verifies that the established quality management system is in compliance with the requirements of Article 17."

Annexes VII–XIII: Operational Compliance and the Act as a Whole

Annex VII conformity procedure

It is based on assessment of the quality management system and assessment of technical documentation under points 2 to 5.

Notified-body data access

Where relevant and necessary, the notified body shall be granted full access to training, validation, and testing data sets used, with appropriate security safeguards.

Model access under Annex VII

After other reasonable verification means are exhausted and insufficient, and upon a reasoned request, access to training and trained models, including relevant parameters, shall also be granted.

Training-data non-compliance

Re-training of the AI system will be needed prior to applying for a new conformity assessment.

Annex VIII Section C

Deployers provide the provider's EU-database entry URL and summaries of fundamental-rights and, where applicable, data-protection impact assessments.

Annex IX identifier

A Union-wide unique single identification number of the testing in real world conditions.

+2 more flashcards