
The EU Artificial Intelligence Act: A Section-by-Section Deep Dive into Regulation (EU) 2024/1689
This advanced course walks through Regulation (EU) 2024/1689 in document order, from its legal foundations and recitals to its operative rules, enforcement regime, amendments, footnotes and annexes. Learners will be able to navigate the AI Act’s risk-based architecture, determine how its principal obligations apply, and connect its detailed compliance mechanisms to the Regulation’s policy rationale.
Course Content
25 modules · 9h 32m total
The AI Act as a Union Legislative Instrument
The course opens by situating Regulation (EU) 2024/1689 as a binding act of the European Parliament and Council and tracing the policy ambitions announced in its opening recitals. Its internal-market foundation is paired from the outset with human-centric AI, fundamental rights and continuity with existing Union law.
Core Concepts, Reach and the Risk-Based Framework
What counts as AI, where does the Act reach, and which activities remain outside it? This module follows the recitals as they establish technical and biometric concepts, territorial connections, exclusions, AI literacy and the ethical background to the risk-based framework.
The Boundary of Unacceptable AI
The Act draws its hardest line around practices considered incompatible with Union values. This module examines the rationales for banning manipulation, exploitation, social scoring and other practices while permitting only tightly controlled law-enforcement biometric exceptions.
How the Act Identifies High-Risk AI
High-risk status turns on both a general classification logic and a detailed set of sensitive use areas. The recitals show how product components, stand-alone systems, profiling and decision influence determine whether demanding obligations attach.
The Compliance Design of High-Risk Systems
The recitals turn high-risk status into a lifecycle engineering and governance discipline. Risk management, data quality, logging, human oversight and resilience are treated as mutually supporting controls rather than isolated paperwork duties.
Responsibility Across the AI Value Chain
AI compliance rarely rests with a single organisation. This module follows responsibility from providers and component suppliers through importers, distributors, product manufacturers and deployers, including circumstances that transfer provider status.
General-Purpose AI Models and Systemic Risk
The recitals introduce a regulatory layer for models capable of serving many downstream purposes, including the most powerful and widely deployed models. Documentation, copyright, evaluations, incident reporting and codes of practice form a proportionate regime that changes when systemic risk emerges.
Standards, Conformity and Public Transparency
How does an operator demonstrate compliance, and what must people be told when AI shapes their experience? The recitals connect standards, conformity assessment, CE marking and registration with disclosures for synthetic content, deep fakes and human–AI interaction.
Innovation Support and the Governance Architecture
The Act pairs strict controls with supervised routes for experimentation and institutional support. Its recitals establish sandboxes for innovators while building a multilevel network of Union bodies, national authorities, experts and testing structures.
Supervision, Remedies and the Recitals’ Closing Framework
The final recitals allocate supervision among financial, biometric, national and Union authorities before turning to remedies, penalties, review and staged application. They reveal how the Act intends to move from legislative design to phased, revisable enforcement.
General Provisions and the Act’s Defined Vocabulary
The operative text begins by converting the recitals’ policy logic into binding subject-matter, scope and definitions. Articles 1–3 supply the vocabulary needed to interpret every later obligation, from operators and conformity to biometrics, incidents, testing and general-purpose AI.
AI Literacy, Prohibitions and Binding High-Risk Classification
The first substantive operative duties move rapidly from workforce competence to categorical prohibitions and high-risk classification. Articles 4–10 show how the Act translates its risk hierarchy into literacy measures, bans, classification records and continuous controls over risks and data.
High-Risk System Evidence and Provider Controls
Compliance must be built into the system and preserved as evidence. Articles 11–21 connect documentation, automatic logs, instructions, oversight and resilience with the provider’s quality system, retention, corrective action and regulatory cooperation.
Operators, Deployers and Fundamental-Rights Impact Assessments
Once a high-risk system moves through distribution and into use, responsibility shifts but does not disappear. Articles 22–27 allocate verification, contractual support, monitoring, worker notice and impact-assessment duties across the full chain.
Notifying Authorities and Notified Bodies
Independent conformity assessment depends on a regulated institutional chain of its own. Articles 28–39 govern who may assess systems, how competence is demonstrated, how subcontracting and certificates are controlled, and what happens when confidence in a notified body fails.
Proving Conformity and Entering the Union Market
Articles 40–49 turn technical standards into concrete routes to market. This module follows presumptions of conformity through assessment routes, certificates, emergency derogations, declarations, CE marking and database registration.
Transparency and General-Purpose AI Obligations
The Act regulates what people must be told and what downstream developers must receive. Article 50’s public-facing disclosures sit alongside the classification, documentation, copyright and systemic-risk duties imposed on general-purpose AI model providers.
Sandboxes and Testing in Real-World Conditions
Innovation moves from principle to supervised procedure in Chapter VI. Articles 57–61 establish sandbox access, protected personal-data processing and tightly controlled real-world testing, including plans, consent, incident response and continuing liability.
SME Support and the Institutions of AI Governance
The Act’s governance system combines practical support for smaller operators with coordination at Union and national levels. Articles 62–70 establish reduced burdens, expert institutions and independent authorities expected to make implementation consistent and technically credible.
Registration, Monitoring and Market Surveillance
After market entry, the Act relies on information flows: database records, monitoring plans, incident reports and supervisory access. Articles 71–78 show how those flows support sectoral surveillance while protecting rights, confidential information and cybersecurity.
Risk Procedures, Remedies and General-Purpose AI Enforcement
The enforcement chapters address systems that are risky, misclassified, formally defective or compliant on paper but dangerous in practice. They also give the Commission and AI Office specialised powers over general-purpose AI models while preserving complaint, explanation and whistleblower channels.
Soft-Law Guidance, Penalties and Legislative Integration
The Act combines voluntary guidance with formidable sanctions and targeted amendments to existing Union legislation. Articles 95–110 show how responsible practices can extend beyond high-risk systems, how infringements are fined and how AI safety is integrated into sectoral regimes.
Transition, Application and the Act’s Legal Reference Network
The operative text closes with transition rules, evaluation duties and a staged timetable rather than a single compliance date. The accompanying footnotes reveal the dense legal network—from data protection and product safety to copyright and whistleblower law—on which the Act relies.
Annexes I–VI: Classification and Core Compliance Evidence
The annexes turn abstract legal duties into lists, templates and technical specifications. This module connects product legislation and serious-offence exceptions to Annex III use cases, Annex IV documentation and the formal evidence required for declarations and internal-control assessment.
Annexes VII–XIII: Operational Compliance and the Act as a Whole
The final annexes supply the operational detail for notified-body assessment, registration, real-world testing, transitional IT systems and general-purpose AI documentation. Together they consolidate the Act as a complete chain from classification and evidence to market access, deployment, monitoring and enforcement.
Read the Textbook
Read every chapter for free, right here in your browser.
The AI Act as a Union Legislative Instrument
This module examines the opening material of Regulation (EU) 2024/1689, the Artificial Intelligence Act. It was adopted by the European Parliament and the Council on 13 June 2024 and published in the Official Journal on 12 July 2024.
The assigned text begins with the Regulation's formal identity, its Treaty bases, the legislative procedure, and Recitals (1) to (11). These recitals explain why the Union adopted the instrument and how it is intended to relate to other areas of Union law.
Study Flashcards
Key concepts from this course as flashcard pairs.
The AI Act as a Union Legislative Instrument
Recital (1): Core purpose
The purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework.
Recital (1): Cross-border movement
This Regulation ensures the free movement, cross-border, of AI-based goods and services.
Recital (3): Main concern
Diverging national rules may fragment the internal market and decrease legal certainty for operators.
Recital (5): Types of possible harm
Harm might be material or immaterial, including physical, psychological, societal, or economic harm.
Recital (6): Human-centric AI
As a prerequisite, AI should be a human-centric technology. It should serve as a tool for people, with the ultimate aim of increasing human well-being.
Recital (9): Existing rights
Rights and remedies under relevant Union law remain unaffected and fully applicable.
+1 more flashcards
Core Concepts, Reach and the Risk-Based Framework
Inference
A core AI characteristic. It concerns obtaining outputs such as predictions, content, recommendations or decisions, and can include deriving models or algorithms from inputs or data.
Deployer
Any natural or legal person, including a public authority, agency or other body, using an AI system under its authority, except personal non-professional use.
Biometric identification
Automated recognition to establish identity by comparing a person's biometric data with stored biometric data in a reference database.
Biometric verification
Authentication whose sole purpose is confirming that a specific person is who they claim to be for access to a service, device or premises.
Real-time remote biometric identification
Capture, comparison and identification occur instantaneously, near-instantaneously or without significant delay using live or near-live material.
Post remote biometric identification
Biometric data was captured earlier; comparison and identification occur only after a significant delay.
+2 more flashcards
The Boundary of Unacceptable AI
What is the central concern in Recital (29)?
Material distortion of behaviour through subliminal, manipulative, deceptive, or exploitative AI-enabled practices, causing or reasonably likely to cause significant harm.
Does Recital (29) require intent to cause significant harm?
No. It says intent to cause significant harm is not necessary, provided harm results from the manipulative or exploitative AI-enabled practice.
What makes social scoring unacceptable in Recital (31)?
A score leading to detrimental or unfavourable treatment in unrelated social contexts, or treatment disproportionate or unjustified to the gravity of social behaviour.
What is the criminal-offence threshold for the Recital (33) biometric-identification exception?
The offence must be punishable by "a custodial sentence or a detention order for a maximum period of at least four years" in the Member State concerned.
What is the urgent authorisation deadline in Recital (35)?
The authority should request authorisation "without undue delay and at the latest within 24 hours."
What facial-database practice does Recital (43) identify?
Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
How the Act Identifies High-Risk AI
Product-related high-risk trigger
Under Recital (50), classification is appropriate where the relevant product undergoes a conformity-assessment procedure with a third-party conformity assessment body under the relevant Union harmonisation legislation.
Stand-alone AI route
Under Recital (52), intended purpose must pose a high risk of harm to health and safety or fundamental rights, considering severity and probability, and the system must be used in specifically pre-defined areas.
Material influence
An AI system does not materially influence a decision where it does not affect the substance, and thereby the outcome, of human or automated decision-making.
Profiling qualifier
In high-risk use-cases listed in an annex, Recital (53) says a system should be considered to pose significant risks if it implies profiling under the referenced data-protection definitions.
Biometric verification exclusion
Biometric verification, including authentication, is excluded where its sole purpose is confirming a specific person is who they claim to be and confirming identity solely for access to a service, device, or premises.
Critical-infrastructure safety component
A component used directly to protect physical integrity of critical infrastructure or health and safety of persons and property, but not necessary for the system to function. Cybersecurity-only components do not qualify.
+2 more flashcards
The Compliance Design of High-Risk Systems
Continuous, iterative risk management
A process planned and run throughout the entire lifecycle of a high-risk AI system, regularly reviewed and updated for continuing effectiveness.
Reasonably foreseeable misuse
Use outside the intended purpose or instructions that may nevertheless be reasonably expected from readily predictable human behaviour in the system's particular context.
Data quality standard
Training, validation, and testing data sets, including labels, should be relevant, sufficiently representative, and to the best extent possible free of errors and complete for the intended purpose.
Feedback loop
A situation in which AI outputs influence inputs for future operations, allowing bias to gradually increase, perpetuate, or amplify discrimination.
Technical documentation
Clear and comprehensive, up-to-date information on characteristics, capabilities, limitations, algorithms, data, training, testing, validation, and the risk-management system.
Automatic logs
High-risk AI systems should technically allow automatic recording of events by logs over the system's lifetime.
+4 more flashcards
Responsibility Across the AI Value Chain
Provider responsibility
Recital (79): "a specific natural or legal person, defined as the provider, takes responsibility for the placing on the market or the putting into service of a high-risk AI system" regardless of whether that person designed or developed it.
Third-country representative
Recital (82): "providers established in third countries should, by written mandate, appoint an authorised representative established in the Union."
Overlapping operator roles
An operator acting in more than one role should fulfil cumulatively all relevant obligations associated with those roles; Recital (83) gives importer and distributor as an example.
Provider reassignment
Recital (84): "any distributor, importer, deployer or other third-party should be considered to be a provider of a high-risk AI system and therefore assume all the relevant obligations" under its stated conditions.
Supplier assistance
Recital (88): suppliers "should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance" while not compromising IP rights or trade secrets.
Deployer use measures
Recital (91): "Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use".
+1 more flashcards
General-Purpose AI Models and Systemic Risk
General-purpose model characteristics
Recital (97): "the generality and the capability to competently perform a wide range of distinct tasks."
One-billion-parameter indicator
Recital (98): "models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality".
Open-source licence formulation
Recital (102): "allows users to run, copy, distribute, study, change and improve software and data, including models".
Open-source systemic-risk limit
Recital (104): transparency-related exceptions apply "unless they can be considered to present a systemic risk".
Copyright policy
Recital (106): "providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights".
Public training-content summary
Recital (107): providers should "draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model."
+6 more flashcards
Standards, Conformity and Public Transparency
Harmonised standards
Recital (121): compliance with harmonised standards should be a means for providers to demonstrate conformity with the Regulation's requirements.
Common specifications
Recital (121): an exceptional fall back solution, established by the Commission through implementing acts after consultation of the advisory forum when specified standardisation problems arise.
Pre-market assessment
Recital (123): high-risk AI systems should be subject to a conformity assessment prior to their placing on the market or putting into service.
Substantial modification
Recital (128): a compliance-affecting change or a changed intended purpose can mean the system is considered a new AI system and should undergo a new conformity assessment.
CE marking
Recital (129): high-risk AI systems should bear CE marking to indicate conformity with the Regulation.
AI interaction notice
Recital (132): natural persons should be notified that they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant, and circumspect person in context.
+3 more flashcards
Innovation Support and the Governance Architecture
AI regulatory sandbox
A controlled setting for development and testing under strict regulatory oversight before an innovative AI system is placed on the market or put into service.
Priority access for SMEs
SMEs, including start-ups, with a registered office or branch in the Union should receive priority access to sandboxes if they fulfil eligibility conditions and selection criteria.
Microenterprise simplification
Microenterprises may fulfil the quality-management-system obligation in a simplified manner; this does not remove high-risk compliance requirements or reduce the intended protection level.
AI Office mission
To develop Union expertise and capabilities in AI and contribute to implementation of Union law on AI.
National competent authorities
Each Member State should designate at least one notifying authority and at least one market surveillance authority.
Single point of contact
Each Member State should designate a market surveillance authority to act as a single point of contact.
+2 more flashcards
Supervision, Remedies and the Recitals’ Closing Framework
Financial-sector oversight
Recital (158): existing financial competent authorities should generally supervise AI systems of regulated financial institutions within their competences, unless a Member State designates another market-surveillance authority.
Biometric authority access
Recital (159): authorities should have effective investigative and corrective powers, including access to all personal data being processed and all information necessary for their tasks.
Same provider: model plus system
Recital (161): supervision should take place at Union level through the AI Office.
General-purpose model provider enforcement
Recital (162): supervision and enforcement powers over provider obligations should be a competence of the Commission.
Complaint route
Recital (170): a natural or legal person with grounds to consider that the Regulation was infringed should be entitled to complain to the relevant market-surveillance authority.
First general review
Recital (174): the Commission should evaluate and review the Regulation by 2 August 2029 and every four years thereafter.
+1 more flashcards
General Provisions and the Act’s Defined Vocabulary
AI system
A machine-based system with varying autonomy that may adapt after deployment and, for explicit or implicit objectives, infers from inputs how to generate outputs that can influence physical or virtual environments.
Risk
The combination of the probability of an occurrence of harm and the severity of that harm.
Provider
A person or body that develops, or has developed, an AI system or general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether paid or free.
Deployer
A person or body using an AI system under its authority, except where it is used in a personal non-professional activity.
Substantial modification
An unplanned post-market or post-service change that affects Chapter III, Section 2 compliance or changes the intended purpose for which the system was assessed.
Remote biometric identification system
An AI system that identifies natural persons without their active involvement, typically at a distance, by comparing biometric data with a reference database.
+2 more flashcards
AI Literacy, Prohibitions and Binding High-Risk Classification
Article 4: Who must take AI-literacy measures?
Providers and deployers of AI systems shall take measures for a sufficient level of AI literacy among relevant staff and other persons dealing with operation and use on their behalf.
Article 5(1)(e): What facial-recognition practice is prohibited?
Creating or expanding facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.
Article 5(3): What is the urgent authorisation deadline?
Authorisation must be requested without undue delay, at the latest within 24 hours.
Article 5(3): Can adverse legal effect rest solely on real-time biometric output?
No. No decision producing an adverse legal effect may be taken based solely on that output.
Article 6(1): What two conditions create product-related high-risk status?
Annex I product or safety-component coverage, and a required third-party conformity assessment under that Annex I legislation.
Article 6(3): What defeats the Annex III non-high-risk derogation?
An Annex III system shall always be high-risk where it performs profiling of natural persons.
+2 more flashcards
High-Risk System Evidence and Provider Controls
Article 11 timing rule
"The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date."
Article 12 core obligation
The system shall technically allow automatic recording of events, or logs, over its lifetime.
Article 13 transparency outcome
Deployers must be able to interpret the output and use the system appropriately.
Article 14 automation bias
The possible tendency to automatically rely or over-rely on AI output, especially where it supplies information or recommendations for human decisions.
Article 15 lifecycle requirement
Appropriate accuracy, robustness, and cybersecurity must be achieved and performed consistently throughout the lifecycle.
Article 18 retention period
Specified documentation must be available to national competent authorities for a period ending 10 years after market placement or putting into service.
+2 more flashcards
Operators, Deployers and Fundamental-Rights Impact Assessments
Third-country provider: Article 22 entry condition?
Before making a high-risk system available on the Union market, it shall appoint, by written mandate, an authorised representative established in the Union.
How long must Article 22 materials be kept available?
For 10 years after the high-risk AI system has been placed on the market or put into service.
Importer: four Article 23 verification areas?
Conformity assessment; technical documentation; CE marking, declaration and instructions; and appointment of an authorised representative.
Distributor: response to suspected Section 2 non-conformity?
It shall not make the system available on the market until the system has been brought into conformity with those requirements.
Article 25: three ways another actor can become provider?
Putting its name or trademark on the system; substantial modification while it remains high-risk; or changing intended purpose so it becomes high-risk.
Deployer log-retention minimum?
A period appropriate to intended purpose, of at least six months, unless applicable Union or national law provides otherwise.
+2 more flashcards
Notifying Authorities and Notified Bodies
What must every Member State do under Article 28(1)?
Each Member State shall designate or establish at least one notifying authority.
Where does a conformity assessment body apply for notification?
To the notifying authority of the Member State in which it is established.
What are Article 30(4)'s objection periods?
Two weeks where the notification includes an Article 29(2) accreditation certificate; two months where it includes Article 29(3) documentary evidence.
What must notified bodies be independent of under Article 31(4)?
The provider of the high-risk AI system assessed, other operators with an economic interest in assessed systems, and competitors of the provider.
What does Article 31(11) require for external work?
Notified bodies shall have sufficient internal competences to be able effectively to evaluate tasks conducted by external parties on their behalf.
How long must Article 33(4) subcontracting records remain available?
Five years from the termination date of the subcontracting.
+2 more flashcards
Proving Conformity and Entering the Union Market
Harmonised-standard presumption
Article 40(1): conformity gives a presumption only where the standard reference is published in the Official Journal and only to the extent the standard covers the relevant requirements or obligations.
Common specifications
Article 41: Commission implementing acts available only when the listed standardisation and Official Journal conditions are fulfilled.
Annex III points 2-8
Article 43(2): providers shall follow Annex VI internal control; it does not provide for notified-body involvement.
Substantial modification
Article 43(4): a previously assessed system shall undergo a new conformity assessment procedure in the event of a substantial modification.
Certificate maximum
Article 44(2): five years for Annex I systems; four years for Annex III systems.
EU declaration retention
Article 47(1): keep it available to national competent authorities for 10 years after market placement or putting into service.
+2 more flashcards
Transparency and General-Purpose AI Obligations
Article 50(1): What must directly interactive AI systems communicate?
Providers shall ensure that **the natural persons concerned are informed that they are interacting with an AI system**, unless that is obvious from the specified reasonably informed person's perspective.
Article 50(2): What is the synthetic-output rule?
Providers shall ensure **the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated**.
Article 50(5): When is Article 50 information due?
In a clear and distinguishable manner **at the latest at the time of the first interaction or exposure**, and conforming to applicable accessibility requirements.
Article 51(2): What is the computation presumption?
A model is presumed to have high-impact capabilities when **the cumulative amount of computation used for its training measured in floating point operations is greater than 1025**.
Article 52(1): What is the notification deadline?
The provider must notify **without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met**.
Article 53: What four baseline items are required?
Up-to-date technical documentation; downstream information and documentation; a copyright-and-related-rights compliance policy; and a publicly available sufficiently detailed training-content summary.
+2 more flashcards
Sandboxes and Testing in Real-World Conditions
Sandbox plan
The specific plan agreed between the provider or prospective provider and the competent authority for the limited-time sandbox activity.
Exit report
A report the competent authority shall provide, detailing sandbox activities and related results and learning outcomes.
Written proof
On request, proof from the competent authority of activities successfully carried out in the sandbox.
SME access
Access is free of charge for SMEs, including start-ups, except fair and proportionate recovery of exceptional costs.
Annual reporting
National competent authorities submit annual reports to the AI Office and Board from one year after sandbox establishment, every year until termination, plus a final report.
SME Support and the Institutions of AI Governance
Article 62 sandbox rule
Member States shall provide eligible SMEs and start-ups with a registered office or branch in the Union priority access to AI regulatory sandboxes. Priority does not exclude other eligible SMEs or start-ups.
Article 62 fee rule
Conformity-assessment fees under Article 43 shall take account of SME provider interests and needs, including reducing fees proportionately to size, market size, and other relevant indicators.
Article 63 simplification
Eligible microenterprises without partner or linked enterprises may comply with certain Article 17 quality-management elements in a simplified manner. This is not a general exemption.
Article 64 AI Office
The Commission shall develop Union expertise and capabilities in AI through the AI Office.
Article 65 Board composition
The Board has one representative per Member State. The EDPS is an observer, and the AI Office attends without voting.
Article 66 Board purpose
The Board shall advise and assist the Commission and Member States to facilitate consistent and effective application of the Regulation.
+4 more flashcards
Registration, Monitoring and Market Surveillance
Who shall set up and maintain the EU database?
Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database."
Who enters Annex VIII Sections A and B data?
The provider or, where applicable, the authorised representative.
What is the ordinary outer reporting deadline for a serious incident?
Not later than 15 days after the provider or, where applicable, deployer becomes aware of the serious incident.
What deadline applies to a widespread infringement or Article 3, point (49)(b) incident?
Immediately, and not later than two days after the provider or, where applicable, deployer becomes aware of that incident.
What is the death-related outer deadline?
Not later than 10 days after the date on which the provider or, where applicable, deployer becomes aware of the serious incident.
When may source code be accessed under Article 74(13)?
Only upon a reasoned request, where access is necessary for conformity assessment and data/documentation-based testing, auditing and verification have been exhausted or proved insufficient.
+1 more flashcards
Risk Procedures, Remedies and General-Purpose AI Enforcement
Article 79 risk definition
AI systems presenting a risk are understood as a product presenting a risk under Article 3(19) of Regulation (EU) 2019/1020, insofar as they risk health, safety, or fundamental rights.
Article 79 corrective-action limit
The authority may prescribe the period, but action is required in any event within the shorter of 15 working days, or the period under relevant Union harmonisation legislation.
Article 80 misclassification consequence
If a provider misclassified a system as non-high-risk to circumvent Chapter III, Section 2, the provider is subject to Article 99 fines.
Article 82 key insight
A high-risk AI system may require corrective measures even though it complies with the Regulation, if it nevertheless presents a specified risk.
Article 85 complaint holder
Any natural or legal person with grounds to consider an infringement may submit a complaint to the relevant market surveillance authority.
Article 88 enforcement allocation
The Commission has exclusive powers to supervise and enforce Chapter V and entrusts implementation tasks to the AI Office.
+1 more flashcards
Soft-Law Guidance, Penalties and Legislative Integration
Article 95(1): What is the purpose of voluntary codes?
They are "intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2".
Article 95(2): What makes a voluntary code measurable?
It is based on clear objectives and key performance indicators to measure achievement of those objectives.
Article 96: Who must receive particular attention?
SMEs including start-ups, local public authorities, and sectors most likely to be affected by the Regulation.
Article 97: How long is the initial delegation?
Five years from 1 August 2024, with possible tacit extension for identical periods unless Parliament or Council objects in time.
Article 99(3): Prohibited-practice maximum
Up to EUR 35,000,000 or, for an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Article 99(6): SME fine rule
For SMEs, including start-ups, each fine is up to the percentage or amount in paragraphs 3, 4, and 5, whichever is lower.
+2 more flashcards
Transition, Application and the Act’s Legal Reference Network
Article 111(1): deadline for covered Annex X large-scale IT system AI components
They **"shall be brought into compliance with this Regulation by 31 December 2030"**, if placed on the market or put into service before 2 August 2027.
Article 111(2): condition for many pre-2 August 2026 high-risk systems
The Regulation applies only if, from 2 August 2026, those systems are subject to **significant changes in their designs**.
Article 111(2): public-authority high-risk systems
Providers and deployers **shall take the necessary steps** to comply by 2 August 2030.
Article 111(3): older general-purpose AI models
Providers of models placed on the market before 2 August 2025 shall take necessary steps to comply by 2 August 2027.
Article 112: first general evaluation-and-review report
By 2 August 2029, and every four years thereafter; it includes enforcement structure and possible need for a Union agency.
Article 113: general application date
**"It shall apply from 2 August 2026."**
+2 more flashcards
Annexes I–VI: Classification and Core Compliance Evidence
What are the two headings in Annex I?
"Section A. List of Union harmonisation legislation based on the New Legislative Framework" and "Section B. List of other Union harmonisation legislation".
What is the limited civil-aviation wording in Annex I?
"where it concerns unmanned aircraft and their engines, propellers, parts and equipment to control them remotely".
Name three Annex II offences using the source wording.
"terrorism"; "trafficking in human beings"; and "sexual exploitation of children, and child pornography".
What Annex III wording covers applicant filtering and candidate evaluation?
"AI systems intended to be used for the recruitment or selection of natural persons".
What does Annex IV require at minimum?
"The technical documentation referred to in Article 11(1) shall contain at least the following information, as applicable to the relevant AI system".
What must Annex VI point 2 verify?
"The provider verifies that the established quality management system is in compliance with the requirements of Article 17."
Annexes VII–XIII: Operational Compliance and the Act as a Whole
Annex VII conformity procedure
It is based on assessment of the quality management system and assessment of technical documentation under points 2 to 5.
Notified-body data access
Where relevant and necessary, the notified body shall be granted full access to training, validation, and testing data sets used, with appropriate security safeguards.
Model access under Annex VII
After other reasonable verification means are exhausted and insufficient, and upon a reasoned request, access to training and trained models, including relevant parameters, shall also be granted.
Training-data non-compliance
Re-training of the AI system will be needed prior to applying for a new conformity assessment.
Annex VIII Section C
Deployers provide the provider's EU-database entry URL and summaries of fundamental-rights and, where applicable, data-protection impact assessments.
Annex IX identifier
A Union-wide unique single identification number of the testing in real world conditions.
+2 more flashcards