Chapter 8 of 25
Standards, Conformity and Public Transparency
How does an operator demonstrate compliance, and what must people be told when AI shapes their experience? The recitals connect standards, conformity assessment, CE marking and registration with disclosures for synthetic content, deep fakes and human–AI interaction.
Recital (121): Standards as a Route to Conformity
Technical routes to compliance
Recital (121) says standardisation should provide technical solutions that help providers ensure compliance, in line with the state of the art.
Load-bearing wording
"Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity".
Participation in standards
Balanced representation of stakeholders should be encouraged, especially SMEs, consumer organisations, and environmental and social stakeholders.
Commission process
The Commission should issue standardisation requests without undue delay and should consult the advisory forum and the Board when preparing them.
Recitals (121)-(122): When Standards Are Missing or Context Matters
Exceptional fallback
Common specifications may be established by implementing acts after consultation of the advisory forum. Recital (121) calls them an exceptional fall back solution.
Why a fallback may be needed
Examples include an unaccepted request, inadequate treatment of fundamental rights, non-compliant standards, or delay in adopting an appropriate harmonised standard.
Data-setting presumption
Under Recital (122), a high-risk system trained and tested on data reflecting its intended setting should be presumed to comply with the relevant data-governance measure.
Cybersecurity presumption
A cybersecurity certificate or statement under Regulation (EU) 2019/881 supports a presumption only to the extent it covers this Regulation's cybersecurity requirement.
Recitals (123)-(127): Conformity Assessment and Third Parties
The timing rule
Recital (123): "those systems should be subject to a conformity assessment prior to their placing on the market or putting into service."
Avoiding duplicated assessment
For relevant product-related high-risk AI, Recital (124) says AI compliance should be assessed within the conformity assessment already provided under applicable Union product law.
Provider or notified body?
Recital (125) makes provider self-assessment the general rule for non-product high-risk systems, with the stated exception of systems intended for biometrics.
Notified bodies and international recognition
Notified bodies should meet independence, competence, conflict-of-interest, and cybersecurity conditions. Third-country recognition depends on compliance and a Union agreement.
Recitals (128)-(130): Modification, CE Marking, and Exceptional Access
Substantial modification
A compliance-affecting change, including a changed operating system, software architecture, or intended purpose, can turn the system into a new AI system.
Learning after deployment
Post-market learning does not constitute substantial modification where changes were pre-determined by the provider and assessed during conformity assessment.
CE marking
"High-risk AI systems should bear the CE marking to indicate their conformity with this Regulation". Embedded systems use physical marking; digital-only systems use digital marking.
Exceptional situations
Recital (130) describes tightly limited authorisation routes for systems without prior conformity assessment where urgent public interests are at stake.
Recital (131): Registration and the EU Database
Who should register?
Recital (131) identifies certain providers of high-risk systems and providers using a derogation, plus public-authority deployers before using an annex-listed high-risk system.
Public design
The public section should be free, navigable, understandable, machine-readable, and user-friendly, including search functionality such as keyword search.
Sensitive sectors
Law enforcement, migration, asylum, and border-control registrations belong in a secure non-public section. Critical-infrastructure systems are registered only nationally.
Database governance
The Commission should be the controller, consider cybersecurity risks, develop functional specifications, obtain an independent audit report, and meet accessibility requirements.
Checkpoint: Conformity and Registration
Choose the answer that most closely follows Recitals (123), (128), and (131).
A provider changes the software architecture of a high-risk AI system in a way that may affect compliance. According to the source text, what follows?
- The system should be considered a new AI system and should undergo a new conformity assessment.
- No further assessment is relevant if the system already bears a CE marking.
- Only a voluntary database entry is needed, regardless of the nature of the change.
- The modification is automatically exempt because software changes are not substantial.
Show Answer
Answer: A) The system should be considered a new AI system and should undergo a new conformity assessment.
Recital (128) says that where a change may affect compliance, including a change of operating system or software architecture, the system should be considered a new AI system and should undergo a new conformity assessment. It also says any substantial modification should be registered in the EU database.
Recital (132): Telling People They Are Interacting with AI
The basic notice
"natural persons should be notified that they are interacting with an AI system" when the system is within the recital's scope.
The obviousness exception
Notification is not needed where AI interaction is obvious to a person who is reasonably well-informed, observant, and circumspect in the circumstances and context.
Biometric uses
People should be notified when exposed to systems processing biometric data to identify or infer emotions or intentions, or to assign specific categories.
Accessible communication
Implementation should account for vulnerable groups due to age or disability, and information and notifications should be in accessible formats for persons with disabilities.
Recital (133): Machine-Readable Marking of Synthetic Content
The technical objective
Providers should embed technical solutions enabling machine-readable marking and detection that output was generated or manipulated by AI rather than a human.
Possible techniques
Recital (133) names watermarks, metadata identifications, cryptographic provenance methods, logs, fingerprints, and other appropriate techniques.
Technical feasibility and state of the art
Techniques should be reliable, interoperable, effective, and robust as far as technically feasible, while reflecting content limitations and the acknowledged state of the art.
Proportional limits
The marking obligation should not cover systems primarily performing standard editing assistance or systems not substantially altering input data or its semantics.
Recitals (134)-(137): Deep Fakes, Public-Interest Text, and Limits of Disclosure
Deep-fake disclosure
A deployer using qualifying deceptive image, audio, or video content "should also clearly and distinguishably disclose that the content has been artificially created or manipulated".
Creative and similar works
For evidently creative, satirical, artistic, fictional, or analogous works, disclosure is limited to an appropriate form that does not hamper display, enjoyment, or normal use.
Public-interest text
A similar disclosure is envisaged for AI-generated or manipulated public-interest text, unless there was human review or editorial control and an editor holds responsibility.
A label is not a legality finding
Recitals (136)-(137) say disclosure does not determine illegality or establish that an AI system or output is lawful under EU or Member State law.
Checkpoint: Transparency Boundaries
Apply the precise distinctions in Recitals (132)-(137).
Which statement best reflects Recital (137)?
- If deep-fake content is labelled, its use is automatically lawful under the Regulation.
- Compliance with transparency obligations does not establish that AI use or output is lawful under this Regulation or other Union and Member State law.
- Transparency duties apply only to systems classified as high-risk.
- A machine-readable watermark replaces every other disclosure duty under Union law.
Show Answer
Answer: B) Compliance with transparency obligations does not establish that AI use or output is lawful under this Regulation or other Union and Member State law.
Recital (137) expressly says that compliance with transparency obligations should not be interpreted as meaning that AI use or output is lawful. It also says those obligations are without prejudice to other transparency obligations under Union or national law.
Recall: Standards, Assessment, and Transparency
Flip each card. Focus on the exact distinction between a technical conformity route, a disclosure duty, and a conclusion about legality.
- Harmonised standards
- Recital (121): compliance with harmonised standards should be a means for providers to demonstrate conformity with the Regulation's requirements.
- Common specifications
- Recital (121): an exceptional fall back solution, established by the Commission through implementing acts after consultation of the advisory forum when specified standardisation problems arise.
- Pre-market assessment
- Recital (123): high-risk AI systems should be subject to a conformity assessment prior to their placing on the market or putting into service.
- Substantial modification
- Recital (128): a compliance-affecting change or a changed intended purpose can mean the system is considered a new AI system and should undergo a new conformity assessment.
- CE marking
- Recital (129): high-risk AI systems should bear CE marking to indicate conformity with the Regulation.
- AI interaction notice
- Recital (132): natural persons should be notified that they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant, and circumspect person in context.
- Synthetic-content marking
- Recital (133): providers should embed technical solutions enabling machine-readable marking and detection of AI-generated or AI-manipulated output.
- Deep-fake disclosure
- Recital (134): qualifying deep-fake content should be clearly and distinguishably disclosed as artificially created or manipulated.
- Transparency versus legality
- Recitals (136)-(137): a label does not determine whether content is illegal and does not establish that AI use or output is lawful.
Key Terms
- deep fake
- Image, audio, or video content generated or manipulated with AI that appreciably resembles existing persons, objects, places, entities, or events and would falsely appear authentic or truthful.
- CE marking
- A marking that high-risk AI systems should bear to indicate conformity with the Regulation, described in Recital (129).
- EU database
- The Commission-managed database described in Recital (131), containing specified registrations concerning high-risk AI systems and certain deployers.
- notified body
- A body notified by national competent authorities to conduct third-party conformity assessment where required, provided it meets conditions including independence, competence, absence of conflicts of interest, and suitable cybersecurity requirements.
- harmonised standards
- Standards referred to in Recital (121), defined by reference to Article 2, point (1)(c), of Regulation (EU) No 1025/2012, that are normally expected to reflect the state of the art and should be a means to demonstrate conformity.
- common specifications
- An exceptional fall back solution that the Commission should be able to establish through implementing acts, after consultation of the advisory forum, in the circumstances described in Recital (121).
- conformity assessment
- The assessment that high-risk AI systems should undergo before being placed on the market or put into service, as stated in Recital (123).
- editorial responsibility
- Responsibility held by a natural or legal person for publication of public-interest text after human review or editorial control, relevant to the exception described in Recital (134).
- machine-readable marking
- A technical marking that enables detection that output was generated or manipulated by AI, described in Recital (133).
- substantial modification
- A change that may affect a high-risk AI system's compliance, or a change in intended purpose, so that the system should be considered new and should undergo a new conformity assessment.