Chapter 11 of 25
General Provisions and the Act’s Defined Vocabulary
The operative text begins by converting the recitals’ policy logic into binding subject-matter, scope and definitions. Articles 1–3 supply the vocabulary needed to interpret every later obligation, from operators and conformity to biometrics, incidents, testing and general-purpose AI.
Article 1: What the Regulation Is For
A dual purpose
Article 1(1) joins market integration and trustworthy AI. It seeks an effective internal market while protecting health, safety, Charter rights, democracy, the rule of law, and the environment.
The exact purpose
The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI).
Seven rule groups
Article 1(2) covers market access and use, prohibited practices, high-risk systems, transparency, general-purpose AI models, enforcement, and innovation support for SMEs and start-ups.
Interpretive takeaway
Article 1 is not a list of optional ambitions. It identifies the binding regulatory architecture that later Articles make operational through duties, definitions, procedures, and enforcement.
Article 2: Who and What Falls Within Scope
Providers and deployers
Article 2(1) applies to providers placing systems or general-purpose AI models on the Union market, and to deployers established or located in the Union.
Cross-border output rule
It also covers providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;
The whole supply chain
Scope also includes importers, distributors, product manufacturers using their own name or trademark, and authorised representatives of providers not established in the Union.
Affected persons
Article 2(1)(g) includes affected persons located in the Union. This reflects that the framework is concerned not only with sellers and users, but also people affected by AI.
Article 2: Limits, Exclusions, and Other Law
Section B product systems
Article 2(2) gives a limited-application rule for Article 6(1) high-risk systems related to products covered by Union harmonisation legislation listed in Annex I, Section B.
Military, defence, security
The exclusion applies only where the system is handled exclusively for military, defence, or national-security purposes. The word "exclusively" limits the exclusion.
Research is distinct from real-world testing
Scientific R&D systems and pre-market research activities are excluded, but Article 2(8) expressly says that testing in real-world conditions is not covered by that exclusion.
Open-source boundary
Free and open-source licensing does not automatically end the analysis. The exclusion does not apply when the system is high-risk or falls under Article 5 or Article 50.
Scope Sorting Exercise
Apply Article 2 before reading further
For each scenario, decide whether Article 2 clearly points toward inclusion, exclusion, or a need for more facts. Then check the reasoning.
- A company based outside the Union runs an AI resume-ranking service. The company sends rankings to an employer in Spain, which uses them in hiring decisions.
- Likely included: Article 2(1)(c) covers a third-country provider or deployer where the output produced by the AI system is used in the Union.
- A university develops a model solely for laboratory research and does not place it on the market or put it into service.
- Excluded on the stated facts: Article 2(6) covers systems or models, including output, specifically developed and put into service for the sole purpose of scientific research and development. Article 2(8) also addresses pre-market research, testing, and development.
- A defence contractor uses an AI system partly for military logistics and partly for civilian commercial shipping.
- More facts needed: Article 2(3) requires exclusive military, defence, or national-security purposes. Mixed civilian use may mean the exclusion does not cover all activity.
- A hobbyist uses an image generator only to make birthday invitations for family.
- Deployer obligations are excluded on the stated facts: Article 2(10) excludes obligations of deployers who are natural persons using AI systems in a purely personal non-professional activity.
- A free open-source model is incorporated into a high-risk AI system placed on the market.
- Not automatically excluded: Article 2(12) expressly withholds the open-source exclusion for high-risk AI systems and systems falling under Article 5 or 50.
The recurring lesson is that scope turns on role, location or Union-output connection, activity, purpose, and sometimes the system's classification.
Article 3: Roles and the AI Market Lifecycle
The Article 3(1) test
An AI system is machine-based, has varying autonomy, may adapt after deployment, infers how to generate outputs from inputs, and can influence physical or virtual environments.
Provider versus deployer
A provider develops, or has developed, and markets or puts a system into service under its own name or trademark. A deployer uses a system under its authority.
Market events differ
Placing on the market is the first Union-market availability. Making available is supply in commercial activity. Putting into service concerns first use by a deployer or own use.
Purpose and misuse
Intended purpose comes from provider-supplied information and documentation. Reasonably foreseeable misuse is not intended use, but can result from foreseeable human behavior or system interaction.
Article 3: Conformity, Modification, and Data
Conformity infrastructure
Conformity assessment demonstrates whether Chapter III, Section 2 high-risk requirements are fulfilled. Notifying authorities oversee assessment bodies; notified bodies are formally notified assessors.
Substantial modification
A change must be unplanned in the initial conformity assessment and must affect Chapter III, Section 2 compliance or change the assessed intended purpose.
Monitoring after release
A post-market monitoring system collects and reviews use experience so the provider can identify a need to apply necessary corrective or preventive action immediately.
Three data functions
Training data fits learnable parameters. Validation data evaluates and tunes the learning process. Testing data independently checks expected performance before market placement or service.
Article 3: Biometrics, Places, and Serious Incidents
Identification is not verification
Biometric identification establishes identity by comparison with a database of individuals. Biometric verification is one-to-one confirmation, including authentication, against previously provided data.
Remote biometric identification
The definition involves identifying people without active involvement, typically at a distance, through comparison with a reference database of biometric data.
A public place can be privately owned
A publicly accessible space can be public or private property if an undetermined number of people can access it, even where conditions or capacity limits apply.
Four serious-incident outcomes
Serious incidents include death or serious health harm, serious irreversible critical-infrastructure disruption, rights-protection breaches, and serious property or environmental harm.
Article 3: Sandboxes, Literacy, Deep Fakes, and General-Purpose AI
Sandbox versus market release
A regulatory sandbox is a controlled, supervised, time-limited framework under a sandbox plan. It can support development, training, validation, and testing, including appropriate real-world testing.
AI literacy
AI literacy concerns skills, knowledge, and understanding for informed deployment and awareness of AI opportunities, risks, and possible harm, considering each person's rights and obligations.
Deep fake
A deep fake is AI-generated or manipulated image, audio, or video that resembles existing people, objects, places, entities, or events and falsely appears authentic or truthful.
General-purpose AI
A general-purpose AI model has significant generality and can perform a wide range of distinct tasks. A downstream provider integrates a model into an AI system.
Worked Example: From Model Release to a Serious Incident
Map the chain
Northstar can be a provider; the company integrating its model can be a downstream provider; and a clinic using the completed system under its authority can be a deployer.
Map the data
Use purpose separates training, validation, and testing data. The same broad dataset is not automatically every type; the definition depends on the role the data performs.
Modification is conditional
A post-release threshold change is not automatically substantial. It must be unplanned in initial conformity assessment and affect compliance or modify the assessed intended purpose.
Incident threshold
A serious incident requires an incident or malfunction that directly or indirectly leads to one of Article 3(49)'s listed outcomes, such as death or serious health harm.
Quiz: Scope and Roles
Check your understanding
A provider is established in Canada. Its AI system produces fraud scores that are used by a bank in France. Which Article 2 provision most directly explains why the Regulation can apply to that provider?
Choose the best answer.
Which provision most directly applies?
- Article 2(1)(c), because a third-country provider's AI output is used in the Union.
- Article 2(6), because all systems developed outside the Union are research systems.
- Article 2(10), because providers are always personal non-professional deployers.
- Article 2(12), because any AI system made available without charge is open-source.
Show Answer
Answer: A) Article 2(1)(c), because a third-country provider's AI output is used in the Union.
Article 2(1)(c) applies to providers and deployers established or located in a third country where the output produced by the AI system is used in the Union. The facts say the scores are used by a bank in France.
Flashcards: Core Defined Vocabulary
Review the terms
Flip each card and say the definition aloud before checking it. Focus on the differences between closely related terms.
- AI system
- A machine-based system with varying autonomy that may adapt after deployment and, for explicit or implicit objectives, infers from inputs how to generate outputs that can influence physical or virtual environments.
- Risk
- The combination of the probability of an occurrence of harm and the severity of that harm.
- Provider
- A person or body that develops, or has developed, an AI system or general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether paid or free.
- Deployer
- A person or body using an AI system under its authority, except where it is used in a personal non-professional activity.
- Substantial modification
- An unplanned post-market or post-service change that affects Chapter III, Section 2 compliance or changes the intended purpose for which the system was assessed.
- Remote biometric identification system
- An AI system that identifies natural persons without their active involvement, typically at a distance, by comparing biometric data with a reference database.
- Serious incident
- An incident or malfunction directly or indirectly leading to death or serious health harm, serious irreversible critical-infrastructure disruption, a fundamental-rights protection breach, or serious property or environmental harm.
- Deep fake
- AI-generated or manipulated image, audio, or video resembling existing persons, objects, places, entities, or events and falsely appearing authentic or truthful.
Quiz: Modification and Exclusions
Final knowledge check
A free open-source AI system is placed on the market as a high-risk AI system. A team argues that Article 2(12) excludes it automatically because its licence is open-source.
Is that correct?
What does Article 2(12) say?
- Yes. Any free and open-source licence always excludes the AI system.
- No. The exclusion does not apply when the system is placed on the market or put into service as a high-risk AI system, or as a system falling under Article 5 or 50.
- Yes, but only if the provider is established in a third country.
- No, because Article 2 excludes all free software from the Union market.
Show Answer
Answer: B) No. The exclusion does not apply when the system is placed on the market or put into service as a high-risk AI system, or as a system falling under Article 5 or 50.
Article 2(12) states that the Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system falling under Article 5 or 50. The stated high-risk status triggers the exception to the exclusion.
Key Terms
- risk
- The combination of the probability of an occurrence of harm and the severity of that harm.
- deployer
- A person or body using an AI system under its authority, except personal non-professional use.
- operator
- A provider, product manufacturer, deployer, authorised representative, importer, or distributor.
- provider
- A person or body that develops, or has developed, an AI system or general-purpose AI model and markets it or puts it into service under its own name or trademark.
- AI system
- A machine-based system designed to operate with varying levels of autonomy that may exhibit adaptiveness after deployment and infers from inputs how to generate outputs capable of influencing physical or virtual environments.
- deep fake
- AI-generated or manipulated image, audio, or video that resembles existing people, objects, places, entities, or events and falsely appears authentic or truthful.
- AI literacy
- Skills, knowledge, and understanding enabling informed deployment and awareness of AI opportunities, risks, and possible harm.
- training data
- Data used for training an AI system through fitting its learnable parameters.
- intended purpose
- The use intended by the provider, including specified context and conditions of use in provider information, instructions, promotional or sales materials, statements, and technical documentation.
- serious incident
- An incident or malfunction leading directly or indirectly to one of the serious outcomes listed in Article 3(49).
- downstream provider
- A provider of an AI system, including a general-purpose AI system, that integrates an AI model whether supplied internally or by another entity.
- putting into service
- The first supply of an AI system directly to a deployer, or for own use in the Union, for its intended purpose.
- AI regulatory sandbox
- A controlled, time-limited, supervised framework that permits providers or prospective providers to develop, train, validate, and test an innovative AI system under a sandbox plan.
- placing on the market
- The first making available of an AI system or general-purpose AI model on the Union market.
- general-purpose AI model
- An AI model displaying significant generality, capable of competently performing a wide range of distinct tasks, and capable of integration into varied downstream systems or applications.
- substantial modification
- An unplanned post-market or post-service change that affects specified high-risk requirements or changes the assessed intended purpose.
- publicly accessible space
- A public or privately owned physical place accessible to an undetermined number of natural persons, despite possible access conditions or capacity limits.
- remote biometric identification system
- An AI system identifying people without active involvement, typically at a distance, by comparing biometric data with a reference database.