EU AI Act

Jurisdiction:
European Union
phased enforcement
Effective:
Aug 2, 2026
Full enforcement:
Aug 2, 2027
Authority:
European Parliament and Council of the European Union
Official text
Amendments:
  • — Digital Omnibus political agreement (European Parliament final vote 2026-06-16). Treated as binding from 2026-06-18 onward pending publication; superseded by the 2026-07-27 entry below, which records the amendment as enacted.
  • — Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026, entered into force 27 July 2026. Timeline: Annex III high-risk obligations deferred 2026-08-02 to 2027-12-02 (Art. 113 third para. point (c)); Annex I product-safety high-risk to 2028-08-02; new Art. 5 prohibitions (NCIM, CSAM generation) apply 2026-12-02; Arts. 102-110 apply from 2026-07-27 (new Art. 113 third para. point (d)); pre-existing generative systems have until 2026-12-02 to meet Art. 50(2) marking (new Art. 111(4)); legacy high-risk systems used by public authorities have until 2030-08-02 (amended Art. 111(2)). Substantive: Art. 4 AI literacy replaced with a softer support-measures duty; new Art. 4a legal basis for processing special categories of personal data for bias detection and correction (former Art. 10(5) deleted); 'safety component' narrowed in Art. 3(14) and new Art. 6(1a)-(1c); SME/SMC proportionality in Arts. 11(1) and 17(2); Art. 43(3) rewritten so embedding a high-risk AI safety component does not itself force third-party conformity assessment; Art. 27(4)-(5) allow FRIA cross-references to a DPIA and mandate an AI Office questionnaire template; Art. 50(7) codes of practice for content marking with an implementing-act fallback; Art. 99 penalties extended to Art. 25(2) and (4) and capped at the lower of percentage or amount for SMCs; new Arts. 75a-77 give the AI Office direct market-surveillance powers under Regulation (EU) 2019/1020; Annex I Section A point 1 (Machinery Directive 2006/42/EC) deleted and Section B point 21 added. The new Art. 5 NCIM/CSAM prohibitions are tracked as context only and are out of scope for a provision per exclusions.md E1/E2 (criminal-style prohibition, no new ongoing-compliance obligation). GPAI Chapter V rules and the 2027-08-02 Art. 6(1)/pre-existing-GPAI dates unchanged.

Obligations Covered

AI Literacy & Training Human Oversight Transparency & Disclosure Risk Assessment Conformity Assessment Record-Keeping & Documentation Bias & Discrimination Prevention

Timeline

MilestoneDateNotes
AdoptedMar 13, 2024European Parliament
Signed into lawJun 13, 2024Signature by Parliament + Council presidents; ELI date of the act (enacted)
Entered into forceAug 1, 202420 days after publication
AI literacy + prohibited practicesFeb 2, 2025Articles 4 and 5
GPAI model rulesAug 2, 2025National authorities designated
High-risk classification guidelinesFeb 2, 2026Commission guidelines published
Digital Omnibus on AI in forceJul 27, 2026Regulation (EU) 2026/1744 (OJ 2026-07-24); Articles 102-110 apply from this date (Art. 113 third para. point (d))
General application + Article 50 transparencyAug 2, 2026Default application date under Article 113; limited-risk transparency obligations apply
New Art. 5 prohibitions (NCIM/CSAM)Dec 2, 2026Added by Digital Omnibus
Article 50(2) marking, pre-existing generative systemsDec 2, 2026Four-month transitional period under new Article 111(4)
Article 6(1) + pre-existing GPAIAug 2, 2027Unchanged by Omnibus
National regulatory sandboxes operationalAug 2, 2027Amended Article 57(1); deferred from 2026-08-02
Full high-risk obligations (Annex III)Dec 2, 2027Deferred from 2026-08-02 by Digital Omnibus — human oversight, risk management, conformity assessment, logging
Notified-body designation under Section A of Annex IJan 28, 2028Amended Article 43(3) second subparagraph
Annex I product-safety high-riskAug 2, 2028Deferred from 2027-08-02 by Digital Omnibus
Legacy high-risk systems used by public authoritiesAug 2, 2030Amended Article 111(2)

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

AI Literacy (Article 4)

Copy link to this provision

Obligation:
Ai Literacy
enforcing
Effective:
Feb 2, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Support AI literacyProviders and deployers must take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf (Article 4(1), as replaced by Regulation (EU) 2026/1744 from 2026-07-27)
Context-specificMeasures must take account of technical knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used (Article 4(1))
No guaranteed levelThe obligation expressly does not require providers or deployers to guarantee any specific level of AI literacy of any individual (Article 4(1), second sentence — added by the Digital Omnibus)
Commission supportThe Commission and Member States must support providers and deployers, in particular SMEs, and the Commission must publish practical compliance examples on the single information platform (Article 4(2), Article 62(3)(b))
Board recommendationsThe AI Board must adopt recommendations, taking account of European competence frameworks, including common objectives (Article 4(3))

Penalties

ViolationFine
Article 4 non-compliancePenalties and other enforcement measures depend on applicable national rules under Article 99(1). Article 99(4) does not establish a uniform Article 4 fine. For operators within the AI Office's Article 75(1) competence, Article 75c(4)(a) separately applies Article 99(4) ceilings, subject to Article 99(6) and (6a).

Human Oversight (Article 14)

Copy link to this provision

Obligation:
Human Oversight
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers and deployers of high-risk AI systems within Article 2 scope; Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.

Requirements

RequirementDetails
Effective oversightHigh-risk AI must enable oversight by natural persons (Article 14(1))
Proportionate enablementOversight measures must be commensurate with the risks, autonomy, and context of use; the system must be provided so assigned natural persons are enabled, as appropriate and proportionate, to perform the Article 14(4)(a)-(e) functions below (Article 14(3)-(4))
Understand capabilitiesEnable assigned persons to properly understand relevant system capacities and limitations (Article 14(4)(a))
Monitor for anomaliesEnable assigned persons to duly monitor operation, including detecting and addressing unexpected performance, anomalies, and dysfunctions (Article 14(4)(a))
Address automation biasEnable assigned persons to remain aware of automation-bias risk in oversight (Article 14(4)(b))
Interpret outputEnable assigned persons to correctly interpret output, taking account of available interpretation tools and methods (Article 14(4)(c))
Override/reverseEnable assigned persons to decide not to use the system or to disregard, override, or reverse its output (Article 14(4)(d))
Intervene or haltEnable assigned persons to intervene or interrupt system operation via a stop button or similar procedure that allows a halt in a safe state (Article 14(4)(e))
Competent personnelDeployers must assign persons with necessary competence, training, authority, and support (Article 26(2))
Dual verification (biometric)For Annex III point 1(a) systems (remote biometric ID), oversight measures must ensure that the deployer takes no action or decision on the basis of the resulting identification unless that identification is separately verified and confirmed by at least two natural persons with necessary competence, training, and authority. The two-person verification requirement does not apply to systems used for law enforcement, migration, border control, or asylum where Union or national law considers that requirement disproportionate (Article 14(5))

Penalties

ViolationFine
Provider non-compliance through Article 16(a), or deployer non-compliance with Article 26Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.

Transparency Disclosure (Article 50)

Copy link to this provision

Obligation:
Transparency
phased enforcement
Effective:
Aug 2, 2026
Risk tier:
limited-risk
Scope:
Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems, systems producing deepfakes, and systems generating or manipulating text published to inform the public on matters of public interest (Article 50(3)-(4))
high-impactcross-domain
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02. The Commission published Article 50 scope guidelines on July 20, 2026. The final Code of Practice on Transparency of AI-generated Content was published on June 10, 2026; the Commission concluded its adequacy assessment on July 8. The code is voluntary and supports implementation of Article 50(2), (4) and (5). It does not replace the Act or the guidelines, and adherence is not conclusive evidence of compliance. These implementation materials do not postpone the statutory application date or remove the Article 111(4) transitional condition.

Requirements

RequirementDetails
Interaction disclosureProviders must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1))
Synthetic content markingProviders of systems, including general-purpose AI systems, generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking into account content-specific limitations, implementation costs and the generally acknowledged state of the art (Article 50(2))
Emotion recognition and biometric categorisation noticeDeployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3))
Deepfake disclosureDeployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4))
Public-interest text disclosureDeployers of systems generating or manipulating text published to inform the public on matters of public interest must disclose its artificial generation or manipulation. This does not apply where the use is authorised for specified criminal-law purposes, or where human review or editorial control occurs and a natural or legal person holds editorial responsibility (Article 50(4))
Disclosure timing and accessibilityInformation under Article 50(1)-(4) must be clear and distinguishable, provided by the first interaction or exposure, and conform to applicable accessibility requirements (Article 50(5))
Disclosure exceptionsArticle 50(1) excepts certain law-authorised criminal-law systems unless available for public crime reporting; Article 50(2) excepts limited assistive editing or insubstantial changes and certain law-authorised criminal-law uses; Article 50(3) excepts certain permitted criminal-law uses. Article 50(4) excepts law-authorised criminal-law uses; for deepfakes forming part of an evidently artistic, creative, satirical, fictional or analogous work or programme, disclosure remains required but is limited to an appropriate statement of the existence of generated or manipulated content that does not hamper the work's display or enjoyment (Article 50(1)-(4))
Generative AI grace periodProviders of systems, including general-purpose AI systems, generating synthetic audio, image, video or text that were placed on the market before 2026-08-02 must take the necessary steps to comply with Article 50(2) by 2026-12-02. This transition concerns Article 50(2), not the other disclosure duties (Article 111(4), inserted by Regulation (EU) 2026/1744)
Marking codes of practiceThe Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)

Penalties

ViolationFine
Transparency non-compliance (Article 50)Up to EUR 15M or, for an undertaking, 3% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(4)(g))
Incorrect, incomplete or misleading information in response to a request from a notified body or national competent authorityUp to EUR 7.5M or, for an undertaking, 1% of its preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC ceilings (Article 99(5))
SME ceilingFor SMEs, including start-ups, each fine under Article 99(3)-(5) is capped at the lower of the percentage or fixed amount (Article 99(6))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)

High-Risk Transparency and Instructions for Use (Article 13)

Copy link to this provision

Obligation:
Transparency
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users. Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
upcominghigh-impact
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.

Requirements

RequirementDetails
Operational transparencyHigh-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1))
Instructions for useHigh-risk systems must be accompanied by instructions for use in an appropriate digital format or otherwise, containing concise, complete, correct and clear information relevant, accessible and comprehensible to deployers (Article 13(2))
Provider identityInstructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a))
Capabilities and limitationsInstructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b))
Explainability informationWhere applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv))
Group performance and input dataWhere appropriate, instructions must state performance regarding specific persons or groups, and input-data specifications or relevant information about training, validation and testing datasets (Article 13(3)(b)(v)-(vi))
Output interpretationWhere applicable, instructions must provide information enabling deployers to interpret the system's output and use it appropriately (Article 13(3)(b)(vii))
Human oversight measuresInstructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d))
Pre-determined changesWhere applicable, instructions must describe the changes to the system and its performance which the provider pre-determined at the moment of the initial conformity assessment (Article 13(3)(c))
Resources, lifetime and maintenanceInstructions must state computational and hardware resources needed, expected lifetime, and any necessary maintenance and care measures, including their frequency and software updates (Article 13(3)(e))
Logging mechanismsWhere relevant, instructions must describe mechanisms enabling deployers to collect, store and interpret logs under Article 12 (Article 13(3)(f))

Penalties

ViolationFine
Provider non-compliance through Article 16(a)Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.
Incorrect, incomplete or misleading information supplied to notified bodies or national competent authorities in reply to a requestUp to EUR 7.5 million; for undertakings, up to 1% of total worldwide annual turnover for the preceding financial year or EUR 7.5 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(5), (6), and (6a))

Risk Management (Article 9)

Copy link to this provision

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems within Article 2 scope; Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.

Requirements

RequirementDetails
Risk management systemEstablish, implement, document, and maintain a risk management system (Article 9(1))
Identify and analyzeIdentify known and reasonably foreseeable risks to health, safety, and fundamental rights during intended use (Article 9(2)(a))
Estimate and evaluateEstimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse conditions (Article 9(2)(b))
Post-market evaluationEvaluate risks based on data from post-market monitoring (Article 9(2)(c))
Risk mitigationAdopt appropriate and targeted measures addressing the risks identified under Article 9(2)(a) (Article 9(2)(d))
Risk boundaryArticle 9 concerns only risks reasonably mitigated or eliminated through system development or design, or provision of adequate technical information (Article 9(3))
Design-based reductionEliminate or reduce risks through adequate design and development where technically feasible (Article 9(5)(a))
Residual riskEnsure residual risk associated with each hazard and overall residual risk is judged acceptable (Article 9(5))
TestingTest to identify appropriate risk management measures and ensure consistent performance and compliance; tested against prior defined metrics and probabilistic thresholds (Article 9(6)-(8))
Iterative reviewPlan and run the risk management system as a continuous iterative process throughout the entire lifecycle, with regular systematic review and updating (Article 9(2))
Children and vulnerable groupsWhen implementing the risk management system, providers must consider whether the system is likely to adversely affect persons under 18 and, as appropriate, other vulnerable groups (Article 9(9))
Other Union-law risk processesProviders subject to internal risk-management requirements under other Union law may include or combine Article 9(1)-(9) aspects in those procedures (Article 9(10))

Penalties

ViolationFine
Provider non-compliance through Article 16(a)Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.

Conformity Assessment

Copy link to this provision

Obligation:
Conformity Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems subject to Article 16(f)-(h), within Article 2 scope, before placing them on the market or putting them into service; Article 43(3) governs Annex I Section A products, while Article 2(2) limits direct application for Article 6(1) systems related to Annex I Section B products
The Article 16(f)-(h) provider duties to ensure conformity assessment, draw up the declaration, and affix CE marking are in Chapter III Section 3: they apply on 2027-12-02 to Article 6(2)/Annex III systems and on 2028-08-02 to covered Article 6(1)/Annex I systems under amended Article 113(c), subject to Article 111 transitions. The `Effective` field carries the earlier date for those duties. Articles 40-49 are in Section 5 and are not themselves included in that Sections 1-3 deferral; Article 113 retains the general 2026-08-02 application date for provisions not otherwise excepted.

Requirements

RequirementDetails
Conformity assessmentMust undergo before placing on market or putting into service (Article 43)
Annex III assessment routeFor Annex III point 1 systems, application of harmonised standards or common specifications permits a choice between Annex VI internal control and Annex VII assessment with a notified body; Article 43(1) requires Annex VII in its listed cases where standards or specifications are unavailable or unapplied, harmonised standards are applied only in part, or a published restriction affects the relevant part. Annex III points 2-8 follow Annex VI internal control without notified-body involvement (Article 43(1)-(2))
CE markingRequired for high-risk AI systems once assessment complete (Article 48)
Quality managementMust establish quality management system (Article 17); implementation must be proportionate to the size of the provider's organisation, in particular for SMEs, start-ups, and small mid-cap enterprises, without lowering the rigour needed for compliance (Article 17(2), as replaced by Regulation (EU) 2026/1744)
DocumentationKeep the technical documentation, quality-management-system documentation, approved changes, and notified-body decisions and certificates at national-authority disposal for 10 years after the high-risk system is placed on the market or put into service (Article 18). SMEs, start-ups, and SMCs may provide the Annex IV elements in simplified form using the Commission-issued form (Article 11(1), as amended)
Conditional route without a third partyWhere Annex I Section A legislation permits a route without third-party assessment on application of harmonised standards ensuring all relevant sectoral requirements, that option additionally requires application of harmonised standards or applicable Article 41 common specifications covering all Chapter III Section 2 requirements. Subject to those conditions, high-risk classification or inclusion of a high-risk AI safety component does not by itself force third-party assessment (Article 43(3), as replaced)
Annex III phasingAnnex III high-risk systems: 2027-12-02 (deferred from 2026-08-02 by Regulation (EU) 2026/1744). Covered Annex I Section A high-risk systems (including product-safety systems such as medical devices): 2028-08-02 (deferred from 2027-08-02). Notified bodies already notified under Annex I Section A legislation must apply for designation under the AI Act by 2028-01-28

Penalties

ViolationFine
Provider non-compliance with Article 16, including conformity dutiesUp to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.

Record-Keeping & Automatic Logging (Article 12)

Copy link to this provision

Obligation:
Record Keeping
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
providers, deployers
high-impactupcoming
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two.

Requirements

RequirementDetails
Automatic logging capabilityHigh-risk AI systems must technically allow automatic recording of events over the system's lifetime (Article 12(1))
TraceabilityLogs must enable risk identification and post-market monitoring
Deployer monitoringLogs must support operational monitoring by deployers (Article 26(5))
Log retentionProviders and deployers must keep automatically generated logs under their control for a period appropriate to the system's intended purpose, of at least six months unless applicable Union or national law provides otherwise, particularly data-protection law (Articles 19(1), 26(6)); financial institutions keep logs under the relevant Union financial-services rules (Articles 19(2), 26(6))
Tamper-evident storageEditorial best practice, not a statutory requirement. Articles 12, 19 and 26 do not use "immutable" or "tamper-evident", and no specific provision requiring log integrity controls has been identified
Biometric ID specificsRemote biometric systems (Annex III point 1(a)) must log period of use, reference database, input data for which the search led to a match, and verifying personnel (Article 12(3))

Penalties

ViolationFine
Provider non-compliance through Article 16(a) and 16(e) log keeping, or deployer non-compliance with Article 26(5)-(6)Up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher. For SMEs (including start-ups) and SMCs, the lower of the amount or percentage applies (Article 99(4), (6), and (6a)). Applicability depends on the relevant duty and its application date.

Fundamental Rights Impact Assessment (Article 27)

Copy link to this provision

Obligation:
Risk Assessment
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Deployers that are bodies governed by public law or private entities providing public services, and any deployer of Annex III point 5(b)-(c) systems (creditworthiness assessment, life and health insurance risk assessment and pricing); Annex III point 2 (critical infrastructure) systems are excluded
upcominghigh-impact
The deployer-side counterpart to the provider's Article 9 risk management system. Deferred with the rest of the Annex III high-risk regime, but the Digital Omnibus made it materially cheaper to run: relevant parts of a GDPR or LED data protection impact assessment may be cross-referenced where they already meet particular FRIA obligations; the remaining FRIA duties still apply, and the AI Office must ship a questionnaire template.

Requirements

RequirementDetails
Pre-deployment assessmentAssess the impact on fundamental rights before putting the high-risk system into use (Article 27(1))
Process descriptionDescribe the deployer processes in which the system will be used, in line with its intended purpose (Article 27(1)(a))
Period and frequencyDescribe the period and frequency of intended use (Article 27(1)(b))
Affected personsIdentify the categories of natural persons and groups likely to be affected in the specific context (Article 27(1)(c))
Specific harmsIdentify specific risks of harm to those categories, using the provider information supplied under Article 13 (Article 27(1)(d))
Human oversightDescribe implementation of human oversight measures per the instructions for use (Article 27(1)(e))
Response measuresSet out measures if risks materialise, including internal governance arrangements and complaint mechanisms (Article 27(1)(f))
First use and updatesApplies to first use; earlier assessments (including a provider's) may be relied on in similar cases, and the assessment must be updated when elements change (Article 27(2))
Notify authorityNotify the market surveillance authority of the results with the filled-out template; deployers may be exempt from notification in Article 46(1) cases (Article 27(3))
DPIA cross-referenceWhere an obligation is already met by a GDPR Article 35 or LED Article 27 data protection impact assessment, the deployer may cross-reference the relevant sections or incorporate parts of it (Article 27(4), as replaced by Regulation (EU) 2026/1744)
AI Office templateThe AI Office must develop a questionnaire template, including an automated tool, allowing DPIA cross-references (Article 27(5), as replaced)

Penalties

ViolationFine
Article 27 non-compliance under national enforcementMember State penalties and enforcement measures under Article 99(1). Article 27 is not expressly listed in Article 99(4); there is no uniform Article 99(4) FRIA maximum established by that list. National rules determine the extent of fines on public authorities and bodies under Article 99(8)
Article 27 non-compliance within AI Office competenceArticle 75c(4)(a) extends the Article 99(4) tier to applicable provisions otherwise unlisted: up to EUR 15M or, for an undertaking, 3% of preceding financial year worldwide turnover, whichever is higher, subject to the SME/SMC lower-cap rules in Article 99(6)/(6a). This route applies only within Article 75(1): specified same-undertaking GPAI-based systems (with listed exclusions), or systems constituting or integrated into designated very large online platforms/search engines; deployers must also be the provider or belong to the same undertaking

Bias Detection Data Basis (Article 4a)

Copy link to this provision

Obligation:
Bias Prevention
enforcing
Effective:
Jul 27, 2026
Risk tier:
all
Scope:
Providers of high-risk AI systems (Article 4a(1)); providers and deployers of other AI systems and models, and deployers of high-risk AI systems (Article 4a(2))
cross-domain
A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It supplies an express AI Act route to processing special-category personal data for covered bias work, with six cumulative safeguards for anyone who uses it; other potential data-protection-law bases require their own analysis. Replaces the former Article 10(5), which was limited to high-risk training data.

Requirements

RequirementDetails
Strict necessityProcessing is permitted only to the extent strictly necessary for bias detection and correction under Article 10(2)(f)-(g) (Article 4a(1))
No alternative dataBias detection and correction must be impossible to achieve effectively with other data, including synthetic or anonymised data (Article 4a(1)(a))
Technical limitsRe-use must be technically limited, with state-of-the-art security and privacy-preserving measures including pseudonymisation (Article 4a(1)(b))
Access controlStrict, documented access controls, confidentiality obligations, and authorised-person-only access (Article 4a(1)(c))
No onward transferThe special-category data must not be transmitted, transferred, or otherwise accessed by other parties (Article 4a(1)(d))
DeletionDelete once the bias is corrected or the retention period ends, whichever is first (Article 4a(1)(e))
Documented justificationGDPR/EUDPR/LED records of processing must state why the processing was strictly necessary and why other data would not achieve the objective (Article 4a(1)(f))
Extension beyond high-riskProviders and deployers of other AI systems and models, and deployers of high-risk systems, may rely on the same basis where strictly necessary to address biases affecting health, safety, fundamental rights, or prohibited discrimination — subject to all Article 4a(1) safeguards (Article 4a(2))
No duty createdArticle 4a(2) expressly creates no obligation to carry out bias detection and correction

Penalties

ViolationFine
Processing outside the permissionProcessing that does not meet Article 4a conditions cannot rely on this permission; applicable data-protection requirements and enforcement remain separate. This is not a conclusion on every alternative legal basis (Article 4a(1)-(2)).
AI Act enforcementArticle 4a is not enumerated in Article 99(4), but amended Article 99(1) covers national penalties for any operator infringement. For operators within the AI Office competence defined in Article 75(1), Article 75c(4)(a) separately reaches any applicable provision, including unlisted provisions, through the Article 99(4) tier. This does not establish a universal Article 4a fine or immunity.
Scoped Article 75c routeWhere that route applies, up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher, with the lower-of rule for SMEs and SMCs (Article 99(4), (6), and (6a)). Article 75(1) system categories and exclusions apply; deployers fall within that competence only if they are also the provider or part of the same undertaking.
Cite this regulation

Permalink: https://everyailaw.com/regulation/eu-ai-act/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “EU AI Act”, EveryAILaw.com, Sep 1, 2026. https://everyailaw.com/regulation/eu-ai-act/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.