Does EU AI Act require Bias & Discrimination Prevention?

European Union • phased enforcement

Yes — 1 provision

Requirements at a glance

This regulation imposes 9 specific requirements for Bias & Discrimination Prevention across 1 provision:

Bias Detection Data Basis (Article 4a)

Copy link to this provision

Obligation:
Bias Prevention
enforcing
Effective:
Jul 27, 2026
Risk tier:
all
Scope:
Providers of high-risk AI systems (Article 4a(1)); providers and deployers of other AI systems and models, and deployers of high-risk AI systems (Article 4a(2))
cross-domain
A permission, not a mandate — Article 4a(2) states expressly that it creates no obligation to conduct bias detection. It supplies an express AI Act route to processing special-category personal data for covered bias work, with six cumulative safeguards for anyone who uses it; other potential data-protection-law bases require their own analysis. Replaces the former Article 10(5), which was limited to high-risk training data.

Requirements

RequirementDetails
Strict necessityProcessing is permitted only to the extent strictly necessary for bias detection and correction under Article 10(2)(f)-(g) (Article 4a(1))
No alternative dataBias detection and correction must be impossible to achieve effectively with other data, including synthetic or anonymised data (Article 4a(1)(a))
Technical limitsRe-use must be technically limited, with state-of-the-art security and privacy-preserving measures including pseudonymisation (Article 4a(1)(b))
Access controlStrict, documented access controls, confidentiality obligations, and authorised-person-only access (Article 4a(1)(c))
No onward transferThe special-category data must not be transmitted, transferred, or otherwise accessed by other parties (Article 4a(1)(d))
DeletionDelete once the bias is corrected or the retention period ends, whichever is first (Article 4a(1)(e))
Documented justificationGDPR/EUDPR/LED records of processing must state why the processing was strictly necessary and why other data would not achieve the objective (Article 4a(1)(f))
Extension beyond high-riskProviders and deployers of other AI systems and models, and deployers of high-risk systems, may rely on the same basis where strictly necessary to address biases affecting health, safety, fundamental rights, or prohibited discrimination — subject to all Article 4a(1) safeguards (Article 4a(2))
No duty createdArticle 4a(2) expressly creates no obligation to carry out bias detection and correction

Penalties

ViolationFine
Processing outside the permissionProcessing that does not meet Article 4a conditions cannot rely on this permission; applicable data-protection requirements and enforcement remain separate. This is not a conclusion on every alternative legal basis (Article 4a(1)-(2)).
AI Act enforcementArticle 4a is not enumerated in Article 99(4), but amended Article 99(1) covers national penalties for any operator infringement. For operators within the AI Office competence defined in Article 75(1), Article 75c(4)(a) separately reaches any applicable provision, including unlisted provisions, through the Article 99(4) tier. This does not establish a universal Article 4a fine or immunity.
Scoped Article 75c routeWhere that route applies, up to EUR 15 million; for undertakings, up to 3% of total worldwide annual turnover for the preceding financial year or EUR 15 million, whichever is higher, with the lower-of rule for SMEs and SMCs (Article 99(4), (6), and (6a)). Article 75(1) system categories and exclusions apply; deployers fall within that competence only if they are also the provider or part of the same undertaking.
View full regulation View obligation Obligation matrix