emendrix

AI Act

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on […]

32024R1689 · Digital · Atom feed · on EUR-Lex · reflects the consolidated version of 2026-07-27

32024R168902024R1689-20260727

in force 2026-07-27 · detected 2026-08-10

45 provisions touched — 45 substantive, 0 date-only, 0 disputed · 0 sentences quoted verbatim by the gate, 2 changes shipped without an explanation

MODIFIED Art. 1 — Subject matter' · applies from unchanged

In point (g) of Article 1(2), the description of the innovation-support measures now refers to a particular focus on small mid-cap enterprises (SMCs) and small and medium-sized enterprises (SMEs), including start-ups, whereas the earlier text referred only to a particular focus on SMEs, including start-ups. Art. 1, v1 Art. 1, v2

text before / after

32024R168902024R1689-20260727

Article 1Subject matter`1.The matter'1.The purpose of this Regulation is to improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation.2.This Regulation lays down:(a)harmonised rules for the placing on the market, the putting into service, and the use of AI systems in the Union;(b)prohibitions of certain AI practices;(c)specific requirements for high-risk AI systems and obligations for operators of such systems;(d)harmonised transparency rules for certain AI systems;(e)harmonised rules for the placing on the market of general-purpose AI models;(f)rules on market monitoring, market surveillance, governance and enforcement;(g)measures to support innovation, with a particular focus on SMEs, small mid-cap enterprises (SMCs) and small and medium-sized enterprises (SMEs), including start-ups.

MODIFIED Art. 2 — Scope · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Paragraph 2 now lists Article 60a among the provisions that apply to certain high-risk AI systems tied to Annex I Section B legislation, and it identifies Articles 57, 58 and 59 as the ones subject to the integration condition, whereas the earlier text named only Article 57 and referred to Articles 102 to 109 and Article 112 rather than Articles 102 to 112. Art. 2, v2 Art. 2, v1

Paragraph 7 now makes the statement about this Regulation not affecting the listed data-protection instruments subject to Articles 4a and 59, replacing the prior reference to Article 10(5) and Article 59. Art. 2, v2 Art. 2, v1

A new paragraph 13 has been added, describing conditions under which application of specific requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk AI systems under Article 6(1), and stating that the Commission shall adopt delegated acts under Article 97 by 2 August 2027 to specify the systems, requirements, conditions and scope of that limitation. Art. 2, v2

text before / after

32024R168902024R1689-20260727

Article 2Scope1.This Regulation applies to:(a)providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country;(b)deployers of AI systems that have their place of establishment or are located within the Union;(c)providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;(d)importers and distributors of AI systems;(e)product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark;(f)authorised representatives of providers, which are not established in the Union;(g)affected persons that are located in the Union.2.For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to 109 112 shall apply. Articles 57, 58 and Article 112 apply. Article 57 applies 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.3.This Regulation does not apply to areas outside the scope of Union law, and shall not, in any event, affect the competences of the Member States concerning national security, regardless of the type of entity entrusted by the Member States with carrying out tasks in relation to those competences.This Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.This Regulation does not apply to AI systems which are not placed on the market or put into service in the Union, where the output is used in the Union exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities.4.This Regulation applies neither to public authorities in a third country nor to international organisations falling within the scope of this Regulation pursuant to paragraph 1, where those authorities or organisations use AI systems in the framework of international cooperation or agreements for law enforcement and judicial cooperation with the Union or with one or more Member States, provided that such a third country or international organisation provides adequate safeguards with respect to the protection of fundamental rights and freedoms of individuals.5.This Regulation shall not affect the application of the provisions on the liability of providers of intermediary services as set out in Chapter II of Regulation (EU) 2022/2065.6.This Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development.7.Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 10(5) and Article 59 of this Regulation.8.This 2016/680.8.This Regulation does not apply to any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service. Such activities shall be conducted in accordance with applicable Union law. Testing in real world conditions shall not be covered by that exclusion.9.This Regulation is without prejudice to the rules laid down by other Union legal acts related to consumer protection and product safety.10.This Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity.11.This Regulation does not preclude the Union or Member States from maintaining or introducing laws, regulations or administrative provisions which are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or from encouraging or allowing the application of collective agreements which are more favourable to workers.12.This Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50. 50.13.For high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that:(a)Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned; and(b)such limitation does not reduce the overall level of protection provided for by this Regulation.By 2 August 2027, the Commission shall adopt delegated acts in accordance with Article 97 in order to supplement this Regulation by specifying the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.

MODIFIED Art. 3 — Definitions · applies from unchanged

The definition of safety component in point 14 now adds a clarifying sentence stating that a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property. Art. 3, v2

Two new definitions are inserted, point 14a defining micro, small and medium-sized enterprise or SME by reference to Article 2 of the Annex to Recommendation 2003/361/EC, and point 14b defining small mid-cap enterprise or SMC by reference to point (2) of the Annex to Recommendation (EU) 2025/1099. Art. 3, v2

These additions and the added clarifying text are not present in the earlier version of Article 3. Art. 3, v1

text before / after

32024R168902024R1689-20260727

Article 3DefinitionsFor the purposes of this Regulation, the following definitions apply:(1)AI system means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;(2)risk means the combination of the probability of an occurrence of harm and the severity of that harm;(3)provider means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;(4)deployer means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;(5)authorised representative means a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation;(6)importer means a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country;(7)distributor means a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market;(8)operator means a provider, product manufacturer, deployer, authorised representative, importer or distributor;(9)placing on the market means the first making available of an AI system or a general-purpose AI model on the Union market;(10)making available on the market means the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;(11)putting into service means the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose;(12)intended purpose means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;(13)reasonably foreseeable misuse means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems;(14)safety component means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property;(15)instructions property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property;(14a)micro, small and medium-sized enterprise or SME means a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Recommendation 2003/361/EC;(14b)small mid-cap enterprise or SMC means a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099;(15)instructions for use means the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use;(16)recall of an AI system means any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers;(17)withdrawal of an AI system means any measure aiming to prevent an AI system in the supply chain being made available on the market;(18)performance of an AI system means the ability of an AI system to achieve its intended purpose;(19)notifying authority means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;(20)conformity assessment means the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled;(21)conformity assessment body means a body that performs third-party conformity assessment activities, including testing, certification and inspection;(22)notified body means a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation;(23)substantial modification means a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed;(24)CE marking means a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing;(25)post-market monitoring system means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions;(26)market surveillance authority means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020;(27)harmonised standard means a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012;(28)common specification means a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation;(29)training data means data used for training an AI system through fitting its learnable parameters;(30)validation data means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting;(31)validation data set means a separate data set or part of the training data set, either as a fixed or variable split;(32)testing data means data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service;(33)input data means data provided to or directly acquired by an AI system on the basis of which the system produces an output;(34)biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data;(35)biometric identification means the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database;(36)biometric verification means the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data;(37)special categories of personal data means the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725;(38)sensitive operational data means operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings;(39)emotion recognition system means an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data;(40)biometric categorisation system means an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons;(41)remote biometric identification system means an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database;(42)real-time remote biometric identification system means a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention;(43)post-remote biometric identification system means a remote biometric identification system other than a real-time remote biometric identification system;(44)publicly accessible space means any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions;(45)law enforcement authority means:(a)any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or(b)any other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;(46)law enforcement means activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security;(47)AI Office means the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission;(48)national competent authority means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor;(49)serious incident means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following:(a)the death of a person, or serious harm to a person’s health;(b)a serious and irreversible disruption of the management or operation of critical infrastructure;(c)the infringement of obligations under Union law intended to protect fundamental rights;(d)serious harm to property or the environment;(50)personal data means personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;(51)non-personal data means data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;(52)profiling means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679;(53)real-world testing plan means a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions;(54)sandbox plan means a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox;(55)AI regulatory sandbox means a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision;(56)AI literacy means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause;(57)testing in real-world conditions means the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled;(58)subject, for the purpose of real-world testing, means a natural person who participates in testing in real-world conditions;(59)informed consent means a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate;(60)deep fake means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful;(61)widespread infringement means any act or omission contrary to Union law protecting the interest of individuals, which:(a)has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which:(i)the act or omission originated or took place;(ii)the provider concerned, or, where applicable, its authorised representative is located or established; or(iii)the deployer is established, when the infringement is committed by the deployer;(b)has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States;(62)critical infrastructure means critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557;(63)general-purpose AI model means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market;(64)high-impact capabilities means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models;(65)systemic risk means a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain;(66)general-purpose AI system means an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems;(67)floating-point operation means any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base;(68)downstream provider means a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.

MODIFIED Art. 4 — AI literacy · applies from unchanged

The provision is now split into three numbered paragraphs instead of a single unnumbered paragraph. Art. 4, v1 Art. 4, v2

The obligation on providers and deployers changed from taking measures to ensure a sufficient level of AI literacy to their best extent, to taking measures to support the development of AI literacy, and a new sentence states that this does not require guaranteeing any specific level of AI literacy of any individual. Art. 4, v2

Two new paragraphs were added: one requiring the Commission and Member States to support and facilitate providers' and deployers' efforts, particularly for SMEs, including publication of practical examples on the single information platform, and another requiring the Board to adopt recommendations, taking into account European competence frameworks, to support promotion of AI literacy including by setting common objectives. Art. 4, v2

text before / after

32024R168902024R1689-20260727

Article 4AI literacyProviders literacy1.Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.2.The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1 of this Article. For that purpose, the Commission shall publish practical examples of how to comply with that obligation on the single information platform referred to in Article 62(3), point (b).3.The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 1, including by setting out common objectives.

INSERTED Art. 4a — Processing of special categories of personal data for bias detection and correction · applies from unknown (an inserted provision states its own application date only in prose)

This is a newly inserted article that permits providers of high-risk AI systems to exceptionally process special categories of personal data where strictly necessary for bias detection and correction, subject to a specified list of conditions and safeguards. Art. 4a, v2

It also extends a similar, conditional permission to providers and deployers of other AI systems and models, and to deployers of high-risk AI systems, while stating that this does not create any obligation to carry out such bias detection and correction. Art. 4a, v2

text before / after

inserted text (02024R1689-20260727)

Article 4aProcessing of special categories of personal data for bias detection and correction1.To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:(a)the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;(b)the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;(c)the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;(d)the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties;(e)the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and(f)the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.2.Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:(a)such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and(b)all of the conditions and safeguards set out in paragraph 1 are applied.This paragraph does not create any obligation to conduct such bias detection and correction.

MODIFIED Art. 5 — Prohibited AI practices · applies from unchanged

The revised Article 5(1) adds two new prohibited practices, points (ba) and (bb), covering AI systems that generate or manipulate realistic intimate or sexually explicit depictions of an identifiable person without their consent, and AI systems that generate or manipulate material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, subject to a without-right defence under national law. Art. 5, v2

Two new paragraphs, 1a and 1b, are added to qualify these new prohibitions: paragraph 1a limits when placing on the market, putting into service, or use of such systems counts as prohibited, distinguishing intended-purpose generation from foreseeable-and-reproducible outcomes lacking adequate safeguards, and limiting deployer liability to purposeful generation or manipulation, while paragraph 1b excludes manipulations that do not increase exposure of intimate parts or alter the nature of depicted sexually explicit activity from counting as manipulation. Art. 5, v2

The remainder of Article 5, including the biometric identification and social scoring provisions, is unchanged between the two versions. Art. 5, v1 Art. 5, v2

text before / after

32024R168902024R1689-20260727

Article 5Prohibited AI practices1.The following AI practices shall be prohibited:(a)the placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm;(b)the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;(c)the harm;(ba)the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;(bb)the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a without right defence applies under national law;(c)the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following:(i)detrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts that are unrelated to the contexts in which the data was originally generated or collected;(ii)detrimental or unfavourable treatment of certain natural persons or groups of persons that is unjustified or disproportionate to their social behaviour or its gravity;(d)the placing on the market, the putting into service for this specific purpose, or the use of an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics; this prohibition shall not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity;(e)the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;(f)the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;(g)the placing on the market, the putting into service for this specific purpose, or the use of biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; this prohibition does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data or categorizing of biometric data in the area of law enforcement;(h)the use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of the following objectives:(i)the targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation of human beings, as well as the search for missing persons;(ii)the prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a genuine and present or genuine and foreseeable threat of a terrorist attack;(iii)the localisation or identification of a person suspected of having committed a criminal offence, for the purpose of conducting a criminal investigation or prosecution or executing a criminal penalty for offences referred to in Annex II and punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years.Point (h) of the first subparagraph is without prejudice to Article 9 of Regulation (EU) 2016/679 for the processing of biometric data for purposes other than law enforcement.2.The enforcement.1a.For the purposes of paragraph 1, first subparagraph, points (ba) and (bb):(a)the placing on the market or putting into service of an AI system that generates or manipulates the material or performance referred to in paragraph 1, first subparagraph, point (ba) or (bb) is only prohibited where:(i)that generation or manipulation is the intended purpose of the AI system; or(ii)the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse;(b)the use of an AI system that generates or manipulates the material or performance referred to in paragraph 1, first subparagraph, points (ba) and (bb) is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance.1b.For the purposes of paragraph 1, first subparagraph, point (ba), an AI system that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation.2.The use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), shall be deployed for the purposes set out in that point only to confirm the identity of the specifically targeted individual, and it shall take into account the following elements:(a)the nature of the situation giving rise to the possible use, in particular the seriousness, probability and scale of the harm that would be caused if the system were not used;(b)the consequences of the use of the system for the rights and freedoms of all persons concerned, in particular the seriousness, probability and scale of those consequences.In addition, the use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any of the objectives referred to in paragraph 1, first subparagraph, point (h), of this Article shall comply with necessary and proportionate safeguards and conditions in relation to the use in accordance with the national law authorising the use thereof, in particular as regards the temporal, geographic and personal limitations. The use of the real-time remote biometric identification system in publicly accessible spaces shall be authorised only if the law enforcement authority has completed a fundamental rights impact assessment as provided for in Article 27 and has registered the system in the EU database according to Article 49. However, in duly justified cases of urgency, the use of such systems may be commenced without the registration in the EU database, provided that such registration is completed without undue delay.3.For the purposes of paragraph 1, first subparagraph, point (h) and paragraph 2, each use for the purposes of law enforcement of a real-time remote biometric identification system in publicly accessible spaces shall be subject to a prior authorisation granted by a judicial authority or an independent administrative authority whose decision is binding of the Member State in which the use is to take place, issued upon a reasoned request and in accordance with the detailed rules of national law referred to in paragraph 5. However, in a duly justified situation of urgency, the use of such system may be commenced without an authorisation provided that such authorisation is requested without undue delay, at the latest within 24 hours. If such authorisation is rejected, the use shall be stopped with immediate effect and all the data, as well as the results and outputs of that use shall be immediately discarded and deleted.The competent judicial authority or an independent administrative authority whose decision is binding shall grant the authorisation only where it is satisfied, on the basis of objective evidence or clear indications presented to it, that the use of the real-time remote biometric identification system concerned is necessary for, and proportionate to, achieving one of the objectives specified in paragraph 1, first subparagraph, point (h), as identified in the request and, in particular, remains limited to what is strictly necessary concerning the period of time as well as the geographic and personal scope. In deciding on the request, that authority shall take into account the elements referred to in paragraph 2. No decision that produces an adverse legal effect on a person may be taken based solely on the output of the real-time remote biometric identification system.4.Without prejudice to paragraph 3, each use of a real-time remote biometric identification system in publicly accessible spaces for law enforcement purposes shall be notified to the relevant market surveillance authority and the national data protection authority in accordance with the national rules referred to in paragraph 5. The notification shall, as a minimum, contain the information specified under paragraph 6 and shall not include sensitive operational data.5.A Member State may decide to provide for the possibility to fully or partially authorise the use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement within the limits and under the conditions listed in paragraph 1, first subparagraph, point (h), and paragraphs 2 and 3. Member States concerned shall lay down in their national law the necessary detailed rules for the request, issuance and exercise of, as well as supervision and reporting relating to, the authorisations referred to in paragraph 3. Those rules shall also specify in respect of which of the objectives listed in paragraph 1, first subparagraph, point (h), including which of the criminal offences referred to in point (h)(iii) thereof, the competent authorities may be authorised to use those systems for the purposes of law enforcement. Member States shall notify those rules to the Commission at the latest 30 days following the adoption thereof. Member States may introduce, in accordance with Union law, more restrictive laws on the use of remote biometric identification systems.6.National market surveillance authorities and the national data protection authorities of Member States that have been notified of the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes pursuant to paragraph 4 shall submit to the Commission annual reports on such use. For that purpose, the Commission shall provide Member States and national market surveillance and data protection authorities with a template, including information on the number of the decisions taken by competent judicial authorities or an independent administrative authority whose decision is binding upon requests for authorisations in accordance with paragraph 3 and their result.7.The Commission shall publish annual reports on the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, based on aggregated data in Member States on the basis of the annual reports referred to in paragraph 6. Those annual reports shall not include sensitive operational data of the related law enforcement activities.8.This Article shall not affect the prohibitions that apply where an AI practice infringes other Union law.

MODIFIED Art. 6 — Classification rules for high-risk AI systems · applies from unchanged

Three new paragraphs, 1a, 1b and 1c, are inserted after paragraph 1, which are not present in the earlier version. Art. 6, v2

Paragraph 1a states that AI systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components, while paragraph 1b states that this does not apply to AI systems whose failure or malfunctioning would endanger health and safety, which still qualify as safety components. Art. 6, v2

Paragraph 1c adds that a product required to undergo third-party conformity assessment solely because of risks other than health and safety, such as risks relating to distribution of radio spectrum or electromagnetic interference that do not affect health and safety, is not considered to fulfil the condition in paragraph 1, point (b), a statement absent from the prior text. Art. 6, v2 Art. 6, v1

text before / after

32024R168902024R1689-20260727

Article 6Classification rules for high-risk AI systems1.Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:(a)the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;(b)the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.2.In I.1a.For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.1b.Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.1c.A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety, in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).2.In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.3.By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.The first subparagraph shall apply where any of the following conditions is fulfilled:(a)the AI system is intended to perform a narrow procedural task;(b)the AI system is intended to improve the result of a previously completed human activity;(c)the AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review; or(d)the AI system is intended to perform a preparatory task to an assessment relevant for the purposes of the use cases listed in Annex III.Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.4.A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Such provider shall be subject to the registration obligation set out in Article 49(2). Upon request of national competent authorities, the provider shall provide the documentation of the assessment.5.The Commission shall, after consulting the European Artificial Intelligence Board (the Board), and no later than 2 February 2026, provide guidelines specifying the practical implementation of this Article in line with Article 96 together with a comprehensive list of practical examples of use cases of AI systems that are high-risk and not high-risk.6.The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by adding new conditions to those laid down therein, or by modifying them, where there is concrete and reliable evidence of the existence of AI systems that fall under the scope of Annex III, but do not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.7.The Commission shall adopt delegated acts in accordance with Article 97 in order to amend paragraph 3, second subparagraph, of this Article by deleting any of the conditions laid down therein, where there is concrete and reliable evidence that this is necessary to maintain the level of protection of health, safety and fundamental rights provided for by this Regulation.8.Any amendment to the conditions laid down in paragraph 3, second subparagraph, adopted in accordance with paragraphs 6 and 7 of this Article shall not decrease the overall level of protection of health, safety and fundamental rights provided for by this Regulation and shall ensure consistency with the delegated acts adopted pursuant to Article 7(1), and take account of market and technological developments.

MODIFIED Art. 10 — Data and data governance · applies from unchanged

Paragraph 1 now points to the quality criteria in paragraphs 2, 3 and 4 of Article 10 together with Article 4a(1), replacing the earlier reference to paragraphs 2 to 5. Art. 10, v1 Art. 10, v2

Paragraph 6 similarly now states that paragraphs 2, 3 and 4 of Article 10 and Article 4a(1) apply only to testing data sets, instead of the earlier reference to paragraphs 2 to 5 applying only to testing data sets. Art. 10, v1 Art. 10, v2

text before / after

32024R168902024R1689-20260727

Article 10Data and data governance1.High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 2, 3 and 4 of this Article and in Article 4a(1) whenever such data sets are used.2.Training, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system. Those practices shall concern in particular:(a)the relevant design choices;(b)data collection processes and the origin of data, and in the case of personal data, the original purpose of the data collection;(c)relevant data-preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation;(d)the formulation of assumptions, in particular with respect to the information that the data are supposed to measure and represent;(e)an assessment of the availability, quantity and suitability of the data sets that are needed;(f)examination in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations;(g)appropriate measures to detect, prevent and mitigate possible biases identified according to point (f);(h)the identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.3.Training, validation and testing data sets shall be relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. Those characteristics of the data sets may be met at the level of individual data sets or at the level of a combination thereof.4.Data sets shall take into account, to the extent required by the intended purpose, the characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting within which the high-risk AI system is intended to be used.5.To the extent that it is strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems in accordance with paragraph (2), points (f) and (g) of this Article, the providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, all the following conditions must be met in order for such processing to occur:(a)the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;(b)the special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;(c)the special categories of personal data are subject to measures to ensure that the personal data processed are secured, protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;(d)the special categories of personal data are not to be transmitted, transferred or otherwise accessed by other parties;(e)the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first;(f)the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.6.For the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2 to 5 2, 3 and 4 of this Article and Article 4a(1) shall apply only to the testing data sets.

MODIFIED Art. 11 — Technical documentation · applies from unchanged

The provision now extends the option of providing a simplified form of technical documentation to small mid-cap companies (SMCs) in addition to SMEs and start-ups. Art. 11, v2

Correspondingly, the simplified technical documentation form that the Commission is to establish is described as targeted at the needs of SMEs, including start-ups, and SMCs, rather than only small and microenterprises as before. Art. 11, v1 Art. 11, v2

The wording also changes from referring to "The technical documentation" to "That technical documentation" at the start of the second sentence of paragraph 1. Art. 11, v2

text before / after

32024R168902024R1689-20260727

Article 11Technical documentation1.The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date.The date.That technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of small SMEs, including start-ups, and microenterprises. SMCs. Where an SME, including a start-up, or an SMC, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.2.Where a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section A of Annex I is placed on the market or put into service, a single set of technical documentation shall be drawn up containing all the information set out in paragraph 1, as well as the information required under those legal acts.3.The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex IV, where necessary, to ensure that, in light of technical progress, the technical documentation provides all the information necessary to assess the compliance of the system with the requirements set out in this Section.

MODIFIED Art. 17 — Quality management system · applies from unchanged

In paragraph 2, the proportionality standard for implementing the quality management system now adds a specific reference to cases where the provider is an SME, including a start-up, or an SMC. Art. 17, v2

The remainder of the provision, including the list of aspects in paragraph 1 and paragraphs 3 and 4, is unchanged between the two versions. Art. 17, v1 Art. 17, v2

text before / after

32024R168902024R1689-20260727

Article 17Quality management system1.Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions, and shall include at least the following aspects:(a)a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for the management of modifications to the high-risk AI system;(b)techniques, procedures and systematic actions to be used for the design, design control and design verification of the high-risk AI system;(c)techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the high-risk AI system;(d)examination, test and validation procedures to be carried out before, during and after the development of the high-risk AI system, and the frequency with which they have to be carried out;(e)technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all of the relevant requirements set out in Section 2, the means to be used to ensure that the high-risk AI system complies with those requirements;(f)systems and procedures for data management, including data acquisition, data collection, data analysis, data labelling, data storage, data filtration, data mining, data aggregation, data retention and any other operation regarding the data that is performed before and for the purpose of the placing on the market or the putting into service of high-risk AI systems;(g)the risk management system referred to in Article 9;(h)the setting-up, implementation and maintenance of a post-market monitoring system, in accordance with Article 72;(i)procedures related to the reporting of a serious incident in accordance with Article 73;(j)the handling of communication with national competent authorities, other relevant authorities, including those providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;(k)systems and procedures for record-keeping of all relevant documentation and information;(l)resource management, including security-of-supply related measures;(m)an accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph.2.The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation. organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.3.Providers of high-risk AI systems that are subject to obligations regarding quality management systems or an equivalent function under relevant sectoral Union law may include the aspects listed in paragraph 1 as part of the quality management systems pursuant to that law.4.For providers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the obligation to put in place a quality management system, with the exception of paragraph 1, points (g), (h) and (i) of this Article, shall be deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law. To that end, any harmonised standards referred to in Article 40 shall be taken into account.

MODIFIED Art. 25 — Responsibilities along the AI value chain · applies from unchanged

No explanation shipped — UnexpectedModelBehavior: Exceeded maximum output retries (1).

text before / after

32024R168902024R1689-20260727

Article 25Responsibilities along the AI value chain1.Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances:(a)they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;(b)they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;(c)they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.2.Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That Regulation.That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the with regard to compliance with the conformity assessment of high-risk AI systems. This systems.In particular, the obligation laid down in the second subparagraph shall include, where relevant for the purposes specified therein, the following:(a)making available of technical documentation sufficient to assess compliance with the requirements laid down in Article 16;(b)informing the new providers about known limitations and failure modes; and(c)providing the new providers with targeted technical access, including for testing and validation.This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.3.In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:(a)the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;(b)the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.4.The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used for or integrated into high-risk AI systems. When developing those voluntary model terms, the AI Office shall take into account possible contractual requirements applicable in specific sectors or business cases. The voluntary model terms shall be published and be available free of charge in an easily usable electronic format.5.Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law.

MODIFIED Art. 27 — Fundamental rights impact assessment for high-risk AI systems · applies from unchanged

Paragraph 4 no longer states that the fundamental rights impact assessment shall complement an existing data protection impact assessment, and instead permits the deployer to include cross-references to relevant sections of that data protection impact assessment, or to incorporate relevant parts of it, into the fundamental rights impact assessment. Art. 27, v1 Art. 27, v2

Paragraph 5 gains an added sentence requiring the AI Office's questionnaire template to give deployers, where relevant, the possibility to make such cross-references or incorporate such parts under paragraph 4. Art. 27, v2

text before / after

32024R168902024R1689-20260727

Article 27Fundamental rights impact assessment for high-risk AI systems1.Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:(a)a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;(b)a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;(c)the categories of natural persons and groups likely to be affected by its use in the specific context;(d)the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;(e)a description of the implementation of human oversight measures, according to the instructions for use;(f)the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.2.The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.3.Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.4.If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.5.The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.

MODIFIED Art. 28 — Notifying authorities · applies from unchanged

Two new paragraphs, 8 and 9, have been added to Article 28, where the earlier version ended after paragraph 7. Art. 28, v1 Art. 28, v2

Paragraph 8 sets out provisions on a single application and unified assessment procedure for conformity assessment bodies seeking designation under both this Regulation and the Union harmonisation legislation listed in Section A of Annex I, including cooperation between notifying authorities and rules on avoiding duplication. Art. 28, v2

Paragraph 9 states that a notifying authority already designated under the Union harmonisation legislation listed in Section A of Annex I also serves as the notifying authority for the single application and unified assessment procedure described in paragraph 8, unless the Member State designates a different notifying authority for this Regulation. Art. 28, v2

text before / after

32024R168902024R1689-20260727

Article 28Notifying authorities1.Each Member State shall designate or establish at least one notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States.2.Member States may decide that the assessment and monitoring referred to in paragraph 1 is to be carried out by a national accreditation body within the meaning of, and in accordance with, Regulation (EC) No 765/2008.3.Notifying authorities shall be established, organised and operated in such a way that no conflict of interest arises with conformity assessment bodies, and that the objectivity and impartiality of their activities are safeguarded.4.Notifying authorities shall be organised in such a way that decisions relating to the notification of conformity assessment bodies are taken by competent persons different from those who carried out the assessment of those bodies.5.Notifying authorities shall offer or provide neither any activities that conformity assessment bodies perform, nor any consultancy services on a commercial or competitive basis.6.Notifying authorities shall safeguard the confidentiality of the information that they obtain, in accordance with Article 78.7.Notifying authorities shall have an adequate number of competent personnel at their disposal for the proper performance of their tasks. Competent personnel shall have the necessary expertise, where applicable, for their function, in fields such as information technologies, AI and law, including the supervision of fundamental rights. rights.8.Notifying authorities designated pursuant to this Regulation that are responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both pursuant to this Regulation and the Union harmonisation legislation listed in Section A of Annex I is provided with the possibility to submit a single application and undergoes a unified assessment procedure to be designated pursuant to this Regulation and Union harmonisation legislation listed in Section A of Annex I, where the relevant Union harmonisation legislation provides for such single application and unified assessment procedure. To that end, notifying authorities designated pursuant to this Regulation and those designated pursuant to the Union harmonisation legislation listed in Section A of Annex I shall cooperate in their assessments.The single application and the unified assessment procedure referred to in this paragraph shall also be made available to notified bodies already designated pursuant to the Union harmonisation legislation listed in Section A of Annex I, when those notified bodies apply for designation pursuant to this Regulation, provided that the relevant Union harmonisation legislation provides for such a procedure.A conformity assessment body that is designated pursuant to more than one piece of Union harmonisation legislation listed in Section A of Annex I shall have to apply only once to be designated pursuant to this Regulation. A designation pursuant to this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which the conformity assessment body is designated.The single application and the unified assessment procedure shall avoid any unnecessary duplications, build on the existing procedures for designation in accordance with the Union harmonisation legislation listed in Section A of Annex I and ensure compliance with the requirements relating to notified bodies both in accordance with this Regulation and the relevant Union harmonisation legislation.9.A notifying authority that has been designated pursuant to the Union harmonisation legislation listed in Section A of Annex I is also the notifying authority for the application of the single application and unified assessment procedure referred to in paragraph 8, unless the Member State designates another notifying authority for this Regulation.

MODIFIED Art. 29 — Application of a conformity assessment body for notification · applies from unchanged

Paragraph 4 now refers to notified bodies designated 'pursuant to' other Union harmonisation legislation rather than 'under' it, and states that existing documents and certificates may be used to support and expedite the designation procedure, adding the word 'expedite' to the earlier wording. Art. 29, v1 Art. 29, v2

A new sentence has been inserted stating that notified bodies designated pursuant to Union harmonisation legislation listed in Section A of Annex I, which undergo the unified assessment procedure referred to in Article 28(8), shall submit a single application for assessment to the notifying authority designated under that legislation. Art. 29, v2

The remaining sentence on updating documentation under paragraphs 2 and 3 is unchanged in substance and now follows this new sentence. Art. 29, v1 Art. 29, v2

text before / after

32024R168902024R1689-20260727

Article 29Application of a conformity assessment body for notification1.Conformity assessment bodies shall submit an application for notification to the notifying authority of the Member State in which they are established.2.The application for notification shall be accompanied by a description of the conformity assessment activities, the conformity assessment module or modules and the types of AI systems for which the conformity assessment body claims to be competent, as well as by an accreditation certificate, where one exists, issued by a national accreditation body attesting that the conformity assessment body fulfils the requirements laid down in Article 31.Any valid document related to existing designations of the applicant notified body under any other Union harmonisation legislation shall be added.3.Where the conformity assessment body concerned cannot provide an accreditation certificate, it shall provide the notifying authority with all the documentary evidence necessary for the verification, recognition and regular monitoring of its compliance with the requirements laid down in Article 31.4.For notified bodies which are designated under pursuant to any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support and expedite their designation procedure under this Regulation, as appropriate. The appropriate.Notified bodies, which are designated pursuant to any of the Union harmonisation legislation listed in Section A of Annex I and which undergo the unified assessment procedure referred to in Article 28(8), shall submit the single application for assessment to the notifying authority designated pursuant to that Union harmonisation legislation.The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.

MODIFIED Art. 30 — Notification procedure · applies from unchanged

Paragraph 2 now specifies that notifying authorities' notifications to the Commission and other Member States must be based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, a reference absent from the earlier text. Art. 30, v1 Art. 30, v2

A new second subparagraph has been added to paragraph 2 empowering the Commission to adopt delegated acts under Article 97 to amend Annex XIV by adding, withdrawing, or moving codes, categories, or types of AI systems on that list. Art. 30, v2

text before / after

32024R168902024R1689-20260727

Article 30Notification procedure1.Notifying authorities may notify only conformity assessment bodies which have satisfied the requirements laid down in Article 31.2.Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.3.The 1.The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex XIV, in light of technical progress, advances in knowledge or new scientific evidence by adding to the list of codes, categories, and corresponding types of AI systems a new code, a category or a type of AI system, withdrawing an existing code, category or a type of AI system from that list or moving a code or type of AI system from one category to another.3.The notification referred to in paragraph 2 of this Article shall include full details of the conformity assessment activities, the conformity assessment module or modules, the types of AI systems concerned, and the relevant attestation of competence. Where a notification is not based on an accreditation certificate as referred to in Article 29(2), the notifying authority shall provide the Commission and the other Member States with documentary evidence which attests to the competence of the conformity assessment body and to the arrangements in place to ensure that that body will be monitored regularly and will continue to satisfy the requirements laid down in Article 31.4.The conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification by a notifying authority where it includes an accreditation certificate referred to in Article 29(2), or within two months of a notification by the notifying authority where it includes documentary evidence referred to in Article 29(3).5.Where objections are raised, the Commission shall, without delay, enter into consultations with the relevant Member States and the conformity assessment body. In view thereof, the Commission shall decide whether the authorisation is justified. The Commission shall address its decision to the Member State concerned and to the relevant conformity assessment body.

MODIFIED Art. 40 — Harmonised standards and standardisation deliverables · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

No explanation shipped — UnexpectedModelBehavior: Exceeded maximum output retries (1).

text before / after

32024R168902024R1689-20260727

Article 40Harmonised standards and standardisation deliverables1.High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations.2.In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation.The Commission shall request the European standardisation organisations to provide evidence of their best efforts to fulfil the objectives referred to in the first and the second subparagraph of this paragraph in accordance with Article 24 of Regulation (EU) No 1025/2012.3.The 1025/2012.The Commission shall request, in accordance with Regulation (EU) No 1025/2012 of the European Parliament and of the CouncilRegulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12, ELI: http://data.europa.eu/eli/reg/2012/1025/oj). and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation.3.The participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.

MODIFIED Art. 42 — Presumption of conformity with certain requirements · applies from unchanged

A new paragraph 3 has been added stating that where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems are deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation. Art. 42, v2

Paragraphs 1 and 2 remain unchanged from the earlier version of the provision. Art. 42, v1 Art. 42, v2

text before / after

32024R168902024R1689-20260727

Article 42Presumption of conformity with certain requirements1.High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).2.High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements. requirements.3.Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.

MODIFIED Art. 43 — Conformity assessment · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Paragraph 3 now requires that a quality management system assessment under Article 17 also be undertaken, and it references points 3, 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6, and point 5 of Annex VII, rather than only points 4.3, 4.4, 4.5 and the fifth paragraph of point 4.6. Art. 43, v1 Art. 43, v2

A new sentence states that notified bodies notified under the relevant Union harmonisation legislation shall apply for designation under Section 4 of the Chapter by 28 January 2028, and the text adds clauses on how classification as a high-risk AI system does not affect the choice of conformity assessment procedure for manufacturers under Section A of Annex I, and on the procedure to follow where a system is both covered by that legislation and falls within an Annex III category. Art. 43, v2

The wording describing the opt-out for third-party conformity assessment was rephrased, changing from a manufacturer having applied all harmonised standards covering all relevant requirements to a manufacturer having applied harmonised standards to ensure compliance with all relevant requirements. Art. 43, v1 Art. 43, v2

text before / after

32024R168902024R1689-20260727

Article 43Conformity assessment1.For high-risk AI systems listed in point 1 of Annex III, where, in demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider has applied harmonised standards referred to in Article 40, or, where applicable, common specifications referred to in Article 41, the provider shall opt for one of the following conformity assessment procedures based on:(a)the internal control referred to in Annex VI; or(b)the assessment of the quality management system and the assessment of the technical documentation, with the involvement of a notified body, referred to in Annex VII.In demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2, the provider shall follow the conformity assessment procedure set out in Annex VII where:(a)harmonised standards referred to in Article 40 do not exist, and common specifications referred to in Article 41 are not available;(b)the provider has not applied, or has applied only part of, the harmonised standard;(c)the common specifications referred to in point (a) exist, but the provider has not applied them;(d)one or more of the harmonised standards referred to in point (a) has been published with a restriction, and only on the part of the standard that was restricted.For the purposes of the conformity assessment procedure referred to in Annex VII, the provider may choose any of the notified bodies. However, where the high-risk AI system is intended to be put into service by law enforcement, immigration or asylum authorities or by Union institutions, bodies, offices or agencies, the market surveillance authority referred to in Article 74(8) or (9), as applicable, shall act as a notified body.2.For high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.3.For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required under those legal acts. in accordance with the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Points 4.3., 4.4., 4.5. Assessment of the quality management system set out in Article 17 shall also be undertaken, and points 3, 4.3, 4.4. and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII shall also apply.For the purposes of that conformity assessment, notified bodies which have been notified under those legal acts the Union harmonisation legislation listed in Section A of Annex I shall be entitled have the power to control assess the conformity of the high-risk AI systems with the requirements set out in Section 2, 2 of this Chapter, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure in accordance with the relevant Union harmonisation legislation, which is evidenced through the assessment as part of the existing notification. Without prejudice to Article 28, such notified bodies which have been notified under those legal acts.Where a legal act the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 of this Chapter by 28 January 2028.Where Union harmonisation legislation listed in Section A of Annex I enables provides the product manufacturer with an option to opt out from rely on a third-party conformity assessment, assessment that does not involve a third-party, provided that that manufacturer has applied all harmonised standards covering to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter.4.High-risk Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I, including, where applicable, an option to rely on harmonised standards. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by the Union harmonisation legislation listed in Section A of Annex I.Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of that system shall follow the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.4.High-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new conformity assessment procedure in the event of a substantial modification, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer.For high-risk AI systems that continue to learn after being placed on the market or put into service, changes to the high-risk AI system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment and are part of the information contained in the technical documentation referred to in point 2(f) of Annex IV, shall not constitute a substantial modification.5.The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annexes VI and VII by updating them in light of technical progress.6.The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend paragraphs 1 and 2 of this Article in order to subject high-risk AI systems referred to in points 2 to 8 of Annex III to the conformity assessment procedure referred to in Annex VII or parts thereof. The Commission shall adopt such delegated acts taking into account the effectiveness of the conformity assessment procedure based on internal control referred to in Annex VI in preventing or minimising the risks to health and safety and protection of fundamental rights posed by such systems, as well as the availability of adequate capacities and resources among notified bodies.

MODIFIED Art. 50 — Transparency obligations for providers and deployers of certain AI systems · applies from unchanged

The actor tasked with encouraging and facilitating codes of practice under paragraph 7 changes from the AI Office to the Commission, and the described scope of the obligations covered expands from detection and labelling to detection, marking and labelling. Art. 50, v1 Art. 50, v2

The process for approving codes of practice no longer refers to adopting an implementing act to approve them, but instead has the Commission assess, taking utmost account of the opinion of the Board, whether adherence to the codes is adequate to ensure compliance with the obligations in paragraphs 2 and 4, following the procedure in Article 56(6). Art. 50, v2

The wording describing an inadequate code changes from stating the code is not adequate to stating the code of practice is inadequate. Art. 50, v1 Art. 50, v2

text before / after

32024R168902024R1689-20260727

Article 50Transparency obligations for providers and deployers of certain AI systems1.Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.2.Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.3.Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.4.Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.5.The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.6.Paragraphs 1 to 4 shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.7.The AI Office Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection detection, marking and labelling of artificially generated or manipulated content. The Commission may adopt implementing acts Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to approve those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56 (6). 56(6). If it deems the code is not adequate, of practice to be inadequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).

MODIFIED Art. 56 — Codes of practice · applies from unchanged

In paragraph 6, the task of regularly monitoring and evaluating achievement of the codes of practice' objectives is now assigned to the Commission and the Board, rather than to the AI Office and the Board. Art. 56, v1 Art. 56, v2

The assessment of whether codes of practice cover the obligations in Articles 53 and 55 is now performed by the Commission, taking utmost account of the Board's opinion, rather than jointly by the AI Office and the Board, and the resulting adequacy assessment is now published by the Commission rather than by the AI Office and the Board together. Art. 56, v1 Art. 56, v2

The sentence in the earlier text authorising the Commission to approve a code of practice by implementing act and give it general validity within the Union, adopted under the examination procedure of Article 98(2), no longer appears in paragraph 6. Art. 56, v1 Art. 56, v2

text before / after

32024R168902024R1689-20260727

Article 56Codes of practice1.The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level in order to contribute to the proper application of this Regulation, taking into account international approaches.2.The AI Office and the Board shall aim to ensure that the codes of practice cover at least the obligations provided for in Articles 53 and 55, including the following issues:(a)the means to ensure that the information referred to in Article 53(1), points (a) and (b), is kept up to date in light of market and technological developments;(b)the adequate level of detail for the summary about the content used for training;(c)the identification of the type and nature of the systemic risks at Union level, including their sources, where appropriate;(d)the measures, procedures and modalities for the assessment and management of the systemic risks at Union level, including the documentation thereof, which shall be proportionate to the risks, take into consideration their severity and probability and take into account the specific challenges of tackling those risks in light of the possible ways in which such risks may emerge and materialise along the AI value chain.3.The AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in the drawing-up of codes of practice. Civil society organisations, industry, academia and other relevant stakeholders, such as downstream providers and independent experts, may support the process.4.The AI Office and the Board shall aim to ensure that the codes of practice clearly set out their specific objectives and contain commitments or measures, including key performance indicators as appropriate, to ensure the achievement of those objectives, and that they take due account of the needs and interests of all interested parties, including affected persons, at Union level.5.The AI Office shall aim to ensure that participants to the codes of practice report regularly to the AI Office on the implementation of the commitments and the measures taken and their outcomes, including as measured against the key performance indicators as appropriate. Key performance indicators and reporting commitments shall reflect differences in size and capacity between various participants.6.The AI Office Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The AI Office and Commission, taking utmost account of the Board opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. They The Commission shall publish their its assessment of the adequacy of the codes of practice.The Commission may, by way of an implementing act, approve a code of practice and give it a general validity within the Union. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).7.The practice.7.The AI Office may invite all providers of general-purpose AI models to adhere to the codes of practice. For providers of general-purpose AI models not presenting systemic risks this adherence may be limited to the obligations provided for in Article 53, unless they declare explicitly their interest to join the full code.8.The AI Office shall, as appropriate, also encourage and facilitate the review and adaptation of the codes of practice, in particular in light of emerging standards. The AI Office shall assist in the assessment of available standards.9.Codes of practice shall be ready at the latest by 2 May 2025. The AI Office shall take the necessary steps, including inviting providers pursuant to paragraph 7.If, by 2 August 2025, a code of practice cannot be finalised, or if the AI Office deems it is not adequate following its assessment under paragraph 6 of this Article, the Commission may provide, by means of implementing acts, common rules for the implementation of the obligations provided for in Articles 53 and 55, including the issues set out in paragraph 2 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).

MODIFIED Art. 57 — AI regulatory sandboxes · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

The operational deadline for the national AI regulatory sandbox was moved from 2 August 2026 to 2 August 2027. Art. 57, v1 Art. 57, v2

A new provision was added allowing the AI Office to establish an AI regulatory sandbox at Union level for certain AI systems, with references to national competent authorities in the Chapter to be read as references to the AI Office where relevant, alongside the existing option for the European Data Protection Supervisor to set up a sandbox for Union institutions. Art. 57, v2

The text also adds references to SMCs alongside SMEs and start-ups, ties the sandbox plan to real-world testing plans under Articles 60 and 60a, and expands the coordination duty in paragraph 14 to include the European Data Protection Supervisor and the AI Office alongside national competent authorities. Art. 57, v2

text before / after

32024R168902024R1689-20260727

Article 57AI regulatory sandboxes1.Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2026. 2027. That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.The obligation under the first subparagraph may also be fulfilled by participating in an existing sandbox in so far as that participation provides an equivalent level of national coverage for the participating Member States.2.Additional AI regulatory sandboxes at regional or local level, or established jointly with the competent authorities of other Member States may also be established.3.The European Data Protection Supervisor may also establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies, and may exercise the roles and the tasks of agencies. For this purpose, references to national competent authorities in accordance this Chapter shall be construed as references to the European Data Protection Supervisor.3a.The AI Office may establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). For this purpose, references to national competent authorities in this Chapter shall be construed, where relevant, as references to the AI Office. That AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular where compliance with Union legislation other than this Chapter.4.Member Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including start-ups, and SMCs.The establishment of a Union level AI regulatory sandbox by the AI Office shall be without prejudice to the competences of Member States to establish and supervise AI regulatory sandboxes for AI systems under their supervision.4.Member States shall ensure that the competent authorities referred to in paragraphs 1 and 2 allocate sufficient resources to comply with this Article effectively and in a timely manner. Where appropriate, national competent authorities shall cooperate with other relevant authorities, and may allow for the involvement of other actors within the AI ecosystem. This Article shall not affect other regulatory sandboxes established under Union or national law. Member States shall ensure an appropriate level of cooperation between the authorities supervising those other sandboxes and the national competent authorities.5.AI regulatory sandboxes established under paragraph 1 this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority. authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein.6.Competent therein. Where applicable, the sandbox plan shall incorporate the real-world testing plan referred to in Articles 60 and 60a.6.Competent authorities shall provide, as appropriate, guidance, supervision and support within the AI regulatory sandbox with a view to identifying risks, in particular to fundamental rights, health and safety, testing, mitigation measures, and their effectiveness in relation to the obligations and requirements of this Regulation and, where relevant, other Union and national law supervised within the sandbox.7.Competent authorities shall provide providers and prospective providers participating in the AI regulatory sandbox with guidance on regulatory expectations and how to fulfil the requirements and obligations set out in this Regulation.Upon request of the provider or prospective provider of the AI system, the competent authority shall provide a written proof of the activities successfully carried out in the sandbox. The competent authority shall also provide an exit report detailing the activities carried out in the sandbox and the related results and learning outcomes. Providers may use such documentation to demonstrate their compliance with this Regulation through the conformity assessment process or relevant market surveillance activities. In this regard, the exit reports and the written proof provided by the national competent authority shall be taken positively into account by market surveillance authorities and notified bodies, with a view to accelerating conformity assessment procedures to a reasonable extent.8.Subject to the confidentiality provisions in Article 78, and with the agreement of the provider or prospective provider, the Commission and the Board shall be authorised to access the exit reports and shall take them into account, as appropriate, when exercising their tasks under this Regulation. If both the provider or prospective provider and the national competent authority explicitly agree, the exit report may be made publicly available through the single information platform referred to in this Article.9.The establishment of AI regulatory sandboxes shall aim to contribute to the following objectives:(a)improving legal certainty to achieve regulatory compliance with this Regulation or, where relevant, other applicable Union and national law;(b)supporting the sharing of best practices through cooperation with the authorities involved in the AI regulatory sandbox;(c)fostering innovation and competitiveness and facilitating the development of an AI ecosystem;(d)contributing to evidence-based regulatory learning;(e)facilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups.10.National start-ups, and SMCs.10.National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the national competent data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.11.The AI regulatory sandboxes shall not affect the supervisory or corrective powers of the competent authorities supervising the sandboxes, including at regional or local level. Any significant risks to health and safety and fundamental rights identified during the development and testing of such AI systems shall result in an adequate mitigation. National competent authorities shall have the power to temporarily or permanently suspend the testing process, or the participation in the sandbox if no effective mitigation is possible, and shall inform the AI Office of such decision. National competent authorities shall exercise their supervisory powers within the limits of the relevant law, using their discretionary powers when implementing legal provisions in respect of a specific AI regulatory sandbox project, with the objective of supporting innovation in AI in the Union.12.Providers and prospective providers participating in the AI regulatory sandbox shall remain liable under applicable Union and national liability law for any damage inflicted on third parties as a result of the experimentation taking place in the sandbox. However, provided that the prospective providers observe the specific plan and the terms and conditions for their participation and follow in good faith the guidance given by the national competent authority, no administrative fines shall be imposed by the authorities for infringements of this Regulation. Where other competent authorities responsible for other Union and national law were actively involved in the supervision of the AI system in the sandbox and provided guidance for compliance, no administrative fines shall be imposed regarding that law.13.The AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.14.National competent authorities shall authorities, the European Data Protection Supervisor and the AI Office, shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board.15.National Board. They may support the joint establishment and operation of AI regulatory sandboxes, including in different sectors, and exchange best practices on related matters.15.National competent authorities shall inform the AI Office and the Board of the establishment of a sandbox, and may ask them for support and guidance. The AI Office shall make publicly available a list of planned and existing sandboxes and keep it up to date in order to encourage more interaction in the AI regulatory sandboxes and cross-border cooperation.16.National competent authorities shall submit annual reports to the AI Office and to the Board, from one year after the establishment of the AI regulatory sandbox and every year thereafter until its termination, and a final report. Those reports shall provide information on the progress and results of the implementation of those sandboxes, including best practices, incidents, lessons learnt and recommendations on their setup and, where relevant, on the application and possible revision of this Regulation, including its delegated and implementing acts, and on the application of other Union law supervised by the competent authorities within the sandbox. The national competent authorities shall make those annual reports or abstracts thereof available to the public, online. The Commission shall, where appropriate, take the annual reports into account when exercising its tasks under this Regulation.17.The Commission shall develop a single and dedicated interface containing all relevant information related to AI regulatory sandboxes to allow stakeholders to interact with AI regulatory sandboxes and to raise enquiries with competent authorities, and to seek non-binding guidance on the conformity of innovative products, services, business models embedding AI technologies, in accordance with Article 62(1), point (c). The Commission shall proactively coordinate with national competent authorities, where relevant.

MODIFIED Art. 58 — Detailed arrangements for, and functioning of, AI regulatory sandboxes · applies from unchanged

The list of matters covered by the Commission's implementing acts on AI regulatory sandboxes now also includes governance, alongside establishment, development, implementation and supervision, and the introductory phrase referring to 'the implementing acts' is changed to 'those implementing acts'. Art. 58, v1 Art. 58, v2

A new point (d) is added listing detailed rules applicable to the governance of AI regulatory sandboxes covered pursuant to Article 57, including the involvement of and supervision by competent data protection authorities where relevant, and coordination and cooperation at national and Union level. Art. 58, v2

Point (c), previously ending the list of common principles with a full stop, now ends with a semicolon to connect to the newly added point (d). Art. 58, v1 Art. 58, v2

text before / after

32024R168902024R1689-20260727

Article 58Detailed arrangements for, and functioning of, AI regulatory sandboxes1.In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation operation, governance, and supervision of the AI regulatory sandboxes. The Those implementing acts shall include common principles on the following issues:(a)eligibility and selection criteria for participation in the AI regulatory sandbox;(b)procedures for the application, participation, monitoring, exiting from and termination of the AI regulatory sandbox, including the sandbox plan and the exit report;(c)the terms and conditions applicable to the participants.Those participants;(d)the detailed rules applicable to the governance of AI regulatory sandboxes covered pursuant to Article 57, including as regards the involvement of and supervision by the competent data protection authorities, where relevant, and the coordination and cooperation at national and Union level.Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).2.The implementing acts referred to in paragraph 1 shall ensure:(a)that AI regulatory sandboxes are open to any applying provider or prospective provider of an AI system who fulfils eligibility and selection criteria, which shall be transparent and fair, and that national competent authorities inform applicants of their decision within three months of the application;(b)that AI regulatory sandboxes allow broad and equal access and keep up with demand for participation; providers and prospective providers may also submit applications in partnerships with deployers and other relevant third parties;(c)that the detailed arrangements for, and conditions concerning AI regulatory sandboxes support, to the best extent possible, flexibility for national competent authorities to establish and operate their AI regulatory sandboxes;(d)that access to the AI regulatory sandboxes is free of charge for SMEs, including start-ups, without prejudice to exceptional costs that national competent authorities may recover in a fair and proportionate manner;(e)that they facilitate providers and prospective providers, by means of the learning outcomes of the AI regulatory sandboxes, in complying with conformity assessment obligations under this Regulation and the voluntary application of the codes of conduct referred to in Article 95;(f)that AI regulatory sandboxes facilitate the involvement of other relevant actors within the AI ecosystem, such as notified bodies and standardisation organisations, SMEs, including start-ups, enterprises, innovators, testing and experimentation facilities, research and experimentation labs and European Digital Innovation Hubs, centres of excellence, individual researchers, in order to allow and facilitate cooperation with the public and private sectors;(g)that procedures, processes and administrative requirements for application, selection, participation and exiting the AI regulatory sandbox are simple, easily intelligible, and clearly communicated in order to facilitate the participation of SMEs, including start-ups, with limited legal and administrative capacities and are streamlined across the Union, in order to avoid fragmentation and that participation in an AI regulatory sandbox established by a Member State, or by the European Data Protection Supervisor is mutually and uniformly recognised and carries the same legal effects across the Union;(h)that participation in the AI regulatory sandbox is limited to a period that is appropriate to the complexity and scale of the project and that may be extended by the national competent authority;(i)that AI regulatory sandboxes facilitate the development of tools and infrastructure for testing, benchmarking, assessing and explaining dimensions of AI systems relevant for regulatory learning, such as accuracy, robustness and cybersecurity, as well as measures to mitigate risks to fundamental rights and society at large.3.Prospective providers in the AI regulatory sandboxes, in particular SMEs and start-ups, shall be directed, where relevant, to pre-deployment services such as guidance on the implementation of this Regulation, to other value-adding services such as help with standardisation documents and certification, testing and experimentation facilities, European Digital Innovation Hubs and centres of excellence.4.Where national competent authorities consider authorising testing in real world conditions supervised within the framework of an AI regulatory sandbox to be established under this Article, they shall specifically agree the terms and conditions of such testing and, in particular, the appropriate safeguards with the participants, with a view to protecting fundamental rights, health and safety. Where appropriate, they shall cooperate with other national competent authorities with a view to ensuring consistent practices across the Union.

MODIFIED Art. 60 — Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes · applies from unchanged

Paragraph 1 now extends the scope of permitted real-world testing to also cover high-risk AI systems covered by Union harmonisation legislation listed in Section A of Annex I, in addition to those listed in Annex III. Art. 60, v2

Paragraph 2 similarly now allows providers or prospective providers to conduct real-world testing of high-risk AI systems covered by Union harmonisation legislation listed in Section A of Annex I, alongside those referred to in Annex III, and refers to the 'high-risk AI system' rather than 'the AI system' when describing the timing of such testing before placing on the market or putting into service. Art. 60, v1 Art. 60, v2

text before / after

32024R168902024R1689-20260727

Article 60Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes1.Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, III or covered by Union harmonisation legislation listed in Section A of Annex I, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.The Commission shall, by means of implementing acts, specify the detailed elements of the real-world testing plan. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2).This paragraph shall be without prejudice to Union or national law on the testing in real world conditions of high-risk AI systems related to products covered by Union harmonisation legislation listed in Annex I.2.Providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the high-risk AI system on their own or in partnership with one or more deployers or prospective deployers.3.The testing of high-risk AI systems in real world conditions under this Article shall be without prejudice to any ethical review that is required by Union or national law.4.Providers or prospective providers may conduct the testing in real world conditions only where all of the following conditions are met:(a)the provider or prospective provider has drawn up a real-world testing plan and submitted it to the market surveillance authority in the Member State where the testing in real world conditions is to be conducted;(b)the market surveillance authority in the Member State where the testing in real world conditions is to be conducted has approved the testing in real world conditions and the real-world testing plan; where the market surveillance authority has not provided an answer within 30 days, the testing in real world conditions and the real-world testing plan shall be understood to have been approved; where national law does not provide for a tacit approval, the testing in real world conditions shall remain subject to an authorisation;(c)the provider or prospective provider, with the exception of providers or prospective providers of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, and high-risk AI systems referred to in point 2 of Annex III has registered the testing in real world conditions in accordance with Article 71(4) with a Union-wide unique single identification number and with the information specified in Annex IX; the provider or prospective provider of high-risk AI systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, has registered the testing in real-world conditions in the secure non-public section of the EU database according to Article 49(4), point (d), with a Union-wide unique single identification number and with the information specified therein; the provider or prospective provider of high-risk AI systems referred to in point 2 of Annex III has registered the testing in real-world conditions in accordance with Article 49(5);(d)the provider or prospective provider conducting the testing in real world conditions is established in the Union or has appointed a legal representative who is established in the Union;(e)data collected and processed for the purpose of the testing in real world conditions shall be transferred to third countries only provided that appropriate and applicable safeguards under Union law are implemented;(f)the testing in real world conditions does not last longer than necessary to achieve its objectives and in any case not longer than six months, which may be extended for an additional period of six months, subject to prior notification by the provider or prospective provider to the market surveillance authority, accompanied by an explanation of the need for such an extension;(g)the subjects of the testing in real world conditions who are persons belonging to vulnerable groups due to their age or disability, are appropriately protected;(h)where a provider or prospective provider organises the testing in real world conditions in cooperation with one or more deployers or prospective deployers, the latter have been informed of all aspects of the testing that are relevant to their decision to participate, and given the relevant instructions for use of the AI system referred to in Article 13; the provider or prospective provider and the deployer or prospective deployer shall conclude an agreement specifying their roles and responsibilities with a view to ensuring compliance with the provisions for testing in real world conditions under this Regulation and under other applicable Union and national law;(i)the subjects of the testing in real world conditions have given informed consent in accordance with Article 61, or in the case of law enforcement, where the seeking of informed consent would prevent the AI system from being tested, the testing itself and the outcome of the testing in the real world conditions shall not have any negative effect on the subjects, and their personal data shall be deleted after the test is performed;(j)the testing in real world conditions is effectively overseen by the provider or prospective provider, as well as by deployers or prospective deployers through persons who are suitably qualified in the relevant field and have the necessary capacity, training and authority to perform their tasks;(k)the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded.5.Any subjects of the testing in real world conditions, or their legally designated representative, as appropriate, may, without any resulting detriment and without having to provide any justification, withdraw from the testing at any time by revoking their informed consent and may request the immediate and permanent deletion of their personal data. The withdrawal of the informed consent shall not affect the activities already carried out.6.In accordance with Article 75, Member States shall confer on their market surveillance authorities the powers of requiring providers and prospective providers to provide information, of carrying out unannounced remote or on-site inspections, and of performing checks on the conduct of the testing in real world conditions and the related high-risk AI systems. Market surveillance authorities shall use those powers to ensure the safe development of testing in real world conditions.7.Any serious incident identified in the course of the testing in real world conditions shall be reported to the national market surveillance authority in accordance with Article 73. The provider or prospective provider shall adopt immediate mitigation measures or, failing that, shall suspend the testing in real world conditions until such mitigation takes place, or otherwise terminate it. The provider or prospective provider shall establish a procedure for the prompt recall of the AI system upon such termination of the testing in real world conditions.8.Providers or prospective providers shall notify the national market surveillance authority in the Member State where the testing in real world conditions is to be conducted of the suspension or termination of the testing in real world conditions and of the final outcomes.9.The provider or prospective provider shall be liable under applicable Union and national liability law for any damage caused in the course of their testing in real world conditions.

INSERTED Art. 60a — Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes · applies from unknown (an inserted provision states its own application date only in prose)

This is a newly inserted article allowing Member States to authorise testing of high-risk AI systems covered by Section B of Annex I Union harmonisation legislation in real-world conditions outside AI regulatory sandboxes, subject to adopted testing frameworks, notification to the Commission, cooperation duties among competent authorities, and specified requirements for those frameworks. Art. 60a, v2

It also specifies that such real-world testing must comply with the applicable provisions of that Union harmonisation legislation, with those provisions not affecting the application of this Article to the extent necessary to enable the testing described. Art. 60a, v2

text before / after

inserted text (02024R1689-20260727)

Article 60aTesting of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes1.Member States may allow, in accordance with this Article, the testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes by providers or prospective providers of AI enabled products covered by the Union harmonisation legislation listed in Section B of Annex I, with a view to assessing and verifying the conformity of those systems with the requirements laid down in Articles 8 to 15.2.Member States that choose to allow testing as referred to in paragraph 1 shall, individually or jointly, adopt frameworks for real-world testing.3.Each Member State shall notify the Commission of any real-world testing framework it adopts before implementing it. This shall not affect the competences of the Commission under the Union harmonisation legislation listed in Section B of Annex I.4.Member States that have adopted real-world testing frameworks shall ensure that the relevant national competent authorities, relevant authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I cooperate closely with each other in good faith and remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement those real-world testing frameworks and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex I.5.The frameworks for real-world testing shall lay down the requirements under which testing in real-world conditions shall occur. Those frameworks shall:(a)include the provision of a mandatory real-world testing plan to be agreed between the provider or prospective provider and the national competent authority or relevant authority in accordance with the Union harmonisation legislation listed in Section B of Annex I;(b)ensure compliance with the requirements laid down in Article 60(2), (3), (4)(d)-(j) and (5)-(9), where any reference to market surveillance authorities in those provisions shall be read as a reference to the national competent authority or relevant authority, as appropriate in accordance with the Union harmonisation legislation listed in Section B of Annex I;(c)include effective governance and accountability arrangements;(d)ensure a high level of protection of health safety and fundamental rights.6.The real-world testing shall comply with the applicable provisions laid down in the Union harmonisation legislation listed in Section B of Annex I. Any requirements laid down in those provisions shall not affect the application of this Article to the extent necessary to enable the testing referred to in paragraph 1.

MODIFIED Art. 63 — Derogations for specific operators · applies from unchanged

The scope of paragraph 1 changed from microenterprises to SMEs, including start-ups, expanding the category of operators to which the simplified compliance option applies. Art. 63, v1 Art. 63, v2

The condition regarding partner or linked enterprises within the meaning of Recommendation 2003/361/EC is retained but is now phrased as a proviso attached to SMEs rather than to microenterprises. Art. 63, v2

text before / after

32024R168902024R1689-20260727

Article 63Derogations for specific operators1.Microenterprises within the meaning of Recommendation 2003/361/EC operators1.SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 of this Regulation in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of that Recommendation. Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of microenterprises, SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.2.Paragraph 1 of this Article shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.

MODIFIED Art. 64 — AI Office · applies from unchanged

A new paragraph 3 has been added stating that, without prejudice to the budgetary procedure, the AI Office shall be allocated adequate resources to effectively perform its duties and exercise its powers in relation to the enforcement of the Regulation. Art. 64, v2

text before / after

32024R168902024R1689-20260727

Article 64AI Office1.The Commission shall develop Union expertise and capabilities in the field of AI through the AI Office.2.Member States shall facilitate the tasks entrusted to the AI Office, as reflected in this Regulation.3.Without prejudice to the budgetary procedure, the AI Office shall be allocated adequate resources to effectively perform its duties and exercise its powers in relation to the enforcement of this Regulation.

MODIFIED Art. 69 — Access to the pool of experts by the Member States · applies from unchanged

The provision on fees for advice and support from experts now ties the fee rate to the remuneration fees applicable to the Commission under the implementing act referred to in Article 68(1), replacing the earlier text that set out fee and cost structures with reference to objectives such as adequate implementation, cost-effectiveness and ensuring effective access for all Member States. Art. 69, v1 Art. 69, v2

text before / after

32024R168902024R1689-20260727

Article 69Access to the pool of experts by the Member States1.Member States may call upon experts of the scientific panel to support their enforcement activities under this Regulation.2.The Member States may be required to pay fees for the advice and support provided by the experts. The structure and experts at a rate equivalent to the level of remuneration fees as well as applicable to the scale and structure of recoverable costs shall be set out in Commission pursuant to the implementing act referred to in Article 68(1), taking into account the objectives of the adequate implementation of this Regulation, cost-effectiveness and the necessity of ensuring effective access to experts for all Member States.3.The 68(1).3.The Commission shall facilitate timely access to the experts by the Member States, as needed, and ensure that the combination of support activities carried out by Union AI testing support pursuant to Article 84 and experts pursuant to this Article is efficiently organised and provides the best possible added value.

MODIFIED Art. 70 — Designation of national competent authorities and single points of contact · applies from unchanged

In paragraph 8, the reference to entities that may receive guidance and advice, previously reading SMEs including start-ups, now reads SMEs, including start-ups, and SMCs. Art. 70, v1 Art. 70, v2

text before / after

32024R168902024R1689-20260727

Article 70Designation of national competent authorities and single points of contact1.Each Member State shall establish or designate as national competent authorities at least one notifying authority and at least one market surveillance authority for the purposes of this Regulation. Those national competent authorities shall exercise their powers independently, impartially and without bias so as to safeguard the objectivity of their activities and tasks, and to ensure the application and implementation of this Regulation. The members of those authorities shall refrain from any action incompatible with their duties. Provided that those principles are observed, such activities and tasks may be performed by one or more designated authorities, in accordance with the organisational needs of the Member State.2.Member States shall communicate to the Commission the identity of the notifying authorities and the market surveillance authorities and the tasks of those authorities, as well as any subsequent changes thereto. Member States shall make publicly available information on how competent authorities and single points of contact can be contacted, through electronic communication means by 2 August 2025. Member States shall designate a market surveillance authority to act as the single point of contact for this Regulation, and shall notify the Commission of the identity of the single point of contact. The Commission shall make a list of the single points of contact publicly available.3.Member States shall ensure that their national competent authorities are provided with adequate technical, financial and human resources, and with infrastructure to fulfil their tasks effectively under this Regulation. In particular, the national competent authorities shall have a sufficient number of personnel permanently available whose competences and expertise shall include an in-depth understanding of AI technologies, data and data computing, personal data protection, cybersecurity, fundamental rights, health and safety risks and knowledge of existing standards and legal requirements. Member States shall assess and, if necessary, update competence and resource requirements referred to in this paragraph on an annual basis.4.National competent authorities shall take appropriate measures to ensure an adequate level of cybersecurity.5.When performing their tasks, the national competent authorities shall act in accordance with the confidentiality obligations set out in Article 78.6.By 2 August 2025, and once every two years thereafter, Member States shall report to the Commission on the status of the financial and human resources of the national competent authorities, with an assessment of their adequacy. The Commission shall transmit that information to the Board for discussion and possible recommendations.7.The Commission shall facilitate the exchange of experience between national competent authorities.8.National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs SMEs, including start-ups, and SMCs, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.9.Where Union institutions, bodies, offices or agencies fall within the scope of this Regulation, the European Data Protection Supervisor shall act as the competent authority for their supervision.

MODIFIED Art. 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Paragraph 3 changes the Commission's action for the post-market monitoring plan from adopting an implementing act, under the examination procedure of Article 98(2), laying down a template and list of elements, to instead adopting guidance, including a template, after taking utmost account of the opinion of the Board. Art. 72, v1 Art. 72, v2

The deadline for this Commission action is changed from 2 February 2026 to 2 September 2027. Art. 72, v1 Art. 72, v2

text before / after

32024R168902024R1689-20260727

Article 72Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems1.Providers shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.2.The post-market monitoring system shall actively and systematically collect, document and analyse relevant data which may be provided by deployers or which may be collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of AI systems with the requirements set out in Chapter III, Section 2. Where relevant, post-market monitoring shall include an analysis of the interaction with other AI systems. This obligation shall not cover sensitive operational data of deployers which are law-enforcement authorities.3.The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission Commission, taking utmost account of the opinion of the Board, shall adopt an implementing act laying down detailed provisions establishing guidance, including a template for template, on the post-market monitoring plan and the list of elements to be included in the plan by 2 February 2026. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 98(2).4.For September 2027.4.For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, in order to ensure consistency, avoid duplications and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary elements described in paragraphs 1, 2 and 3 using the template referred in paragraph 3 into systems and plans already existing under that legislation, provided that it achieves an equivalent level of protection.The first subparagraph of this paragraph shall also apply to high-risk AI systems referred to in point 5 of Annex III placed on the market or put into service by financial institutions that are subject to requirements under Union financial services law regarding their internal governance, arrangements or processes.

MODIFIED Art. 75 — Market surveillance and control of AI systems and mutual assistance · applies from unchanged

The title of the article changed from referring to mutual assistance, market surveillance and control of general-purpose AI systems to referring to market surveillance and control of AI systems and mutual assistance. Art. 75, v1 Art. 75, v2

Paragraph 1 was expanded from a monitoring power over AI systems built on general-purpose AI models by the same provider into a list of AI systems for which the AI Office is stated to be exclusively competent for supervision and enforcement, including exceptions for certain Annex I, Annex III, law enforcement, and very large online platform or search engine systems, and provisions on when that exclusive competence extends to deployers. Art. 75, v2

New paragraphs 1a, 1b, 1c, 1d, 1e and 2a were added covering serious incident reporting to the AI Office, cooperation duties of national authorities, AI Office assistance from market surveillance authorities during investigations, notification before market restriction decisions, AI Office responsibility for certain conformity assessments and related fees, and a procedure for market surveillance authorities to request AI Office action, while the former paragraphs 2 and 3 remain present with paragraph 2 renumbered accordingly and paragraph 3 unchanged. Art. 75, v2 Art. 75, v1

text before / after

texts differ too much for an inline diff; shown separately

before (32024R1689)

Article 75Mutual assistance, market surveillance and control of general-purpose AI systems1.Where an AI system is based on a general-purpose AI model, and the model and the system are developed by the same provider, the AI Office shall have powers to monitor and supervise compliance of that AI system with obligations under this Regulation. To carry out its monitoring and supervision tasks, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and Regulation (EU) 2019/1020.2.Where the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk pursuant to this Regulation to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly.3.Where a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case, the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78 of this Regulation. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

after (02024R1689-20260727)

Article 75Market surveillance and control of AI systems and mutual assistance1.The AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to the following AI systems:(a)AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of:(i)AI systems related to products covered by the Union harmonisation legislation listed in Annex I;(ii)AI systems referred to in point 2 of Annex III;(iii)AI systems provided by law enforcement authorities, border management authorities and financial institutions, insofar as those AI systems fall under Article 74(6); and(iv)AI systems referred to in point 8 of Annex III as regards the administration of justice;(b)AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065.The exclusive competence referred to in the first subparagraph shall apply to the providers of those systems. It shall apply to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.1a.By way of derogation from Article 73, providers of high-risk AI systems subject to the competence of the AI Office pursuant to paragraph 1 of this Article shall report any serious incidents to the AI Office. Article 73 (2) to (9), shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in the territory of which the provider or its legal representative is situated.1b.The authorities involved in the application of this Regulation shall cooperate actively with the AI Office and provide the AI Office the necessary assistance for the exercise of its powers, including, where necessary, in connection with inspections or other enforcement measures carried out in the territory of a Member State. To that end, those authorities shall enjoy the powers provided for pursuant to this Regulation and Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks under this paragraph, in accordance with the applicable national procedures.1c.When taking investigatory or enforcement action in the territory of a Member State that involves access to a public authority’s data or AI system, the AI Office shall be assisted by the relevant market surveillance authority.1d.Before taking a decision that would have the effect of prohibiting or restricting the AI system being made available or put into service on a national market, or a decision to withdraw or recall the AI system from such market, the AI Office shall, without undue delay, notify the market surveillance authority competent for that market of its intention to take such a decision. The AI Office shall consult the authorities involved in the application of this Regulation, where appropriate, on any matter relating to the application and enforcement of this Regulation.1e.The AI Office shall be responsible for conformity assessments and tests of AI systems referred to in paragraph 1 of this Article that are classified as high-risk and subject to a third-party conformity assessment pursuant to Article 43 before such AI systems are placed on the market or put into service. Those tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission shall entrust the performance of those tests or assessments to notified bodies designated in accordance with this Regulation, in which case the notified body shall act on behalf of the Commission. If a notified body to which the Commission has delegated tasks under this paragraph does not perform those tasks adequately, the Commission may withdraw the delegation with immediate effect.The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for a third-party conformity assessment to the Commission. The provider shall pay the costs related to the services entrusted by the Commission to the notified bodies in accordance with this Article directly to the notified body.2.Where the relevant market surveillance authorities have sufficient reason to consider general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk pursuant to this Regulation to be non-compliant with the requirements laid down in this Regulation, they shall cooperate with the AI Office to carry out compliance evaluations, and shall inform the Board and other market surveillance authorities accordingly.2a.Where a market surveillance authority has well-founded and sufficient reasons to suspect that a provider or a deployer of an AI system referred to in paragraph 1 of this Article has infringed this Regulation, it may request, through the relevant single point of contact designated in accordance with Article 70(2), the AI Office to assess the matter in order to take the necessary supervisory and enforcement measures to ensure prompt compliance with this Regulation. Such a request shall be duly reasoned and shall include at least:(a)the name of the provider or the deployer concerned;(b)a description of the relevant facts, the provisions of this Regulation that have allegedly been infringed, and any well-founded and sufficient reasons for suspecting an infringement, including, where applicable, the description of the negative effects of the alleged infringement;(c)the market surveillance authority making the request.The AI Office shall take utmost account of the request and the market surveillance authority shall cooperate actively and provide the AI Office the necessary assistance for the exercise of its powers in accordance with paragraph 1a.The AI Office shall, without undue delay and in any event no later than four months following receipt of the request, inform the single point of contact of its intention to exercise its powers in accordance with Article 75a or of its reasons for not exercising its powers. If the AI Office decides to exercise its powers in accordance with Article 75a, it shall periodically inform that single point of contact about major developments in the proceedings and the outcome of such proceedings, without disclosing any confidential information.3.Where a market surveillance authority is unable to conclude its investigation of the high-risk AI system because of its inability to access certain information related to the general-purpose AI model despite having made all appropriate efforts to obtain that information, it may submit a reasoned request to the AI Office, by which access to that information shall be enforced. In that case, the AI Office shall supply to the applicant authority without delay, and in any event within 30 days, any information that the AI Office considers to be relevant in order to establish whether a high-risk AI system is non-compliant. Market surveillance authorities shall safeguard the confidentiality of the information that they obtain in accordance with Article 78 of this Regulation. The procedure provided for in Chapter VI of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

INSERTED Art. 75a — Supervisory and enforcement powers of the AI Office · applies from unknown (an inserted provision states its own application date only in prose)

A new Article 75a is added, granting the AI Office the powers of a market surveillance authority under this Regulation and under Articles 14(4), 15, 16(3) and 17 of Regulation (EU) 2019/1020, including cost recovery from operators for non-compliance-related supervision and enforcement activities. Art. 75a, v2

The article sets out procedures for opening investigations, issuing information requests by simple request or decision, conducting remote and on-site inspections with specified inspector powers, seeking judicial authorisation for inspections, delegating fact-finding to national market surveillance authorities, ordering access to AI systems and data retention, appointing external experts and auditors, and restricting use of collected information to the purposes of the Regulation. Art. 75a, v2

text before / after

inserted text (02024R1689-20260727)

Article 75aSupervisory and enforcement powers of the AI Office1.When exercising its tasks of supervision and enforcement laid down in Article 75(1) of this Regulation, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020. The AI Office shall be authorised to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance, including costs for human and technical resources, in accordance with Article 15 of Regulation (EU) 2019/1020. Article 17 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.2.Where the AI Office has reasonable grounds to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1) of this Regulation, it may adopt a decision to start an investigation into that non-compliance in accordance with Article 14(4), point (f) of Regulation (EU) 2019/1020. Upon starting such an investigation, the AI Office shall notify the operator of the AI system concerned. The AI Office may exercise the powers referred to in paragraph 1 of this Article on its own initiative or following a complaint received pursuant to Article 85 of this Regulation, even before starting an investigation pursuant to Article 14(4), point (f) of Regulation (EU) 2019/1020.Where a market surveillance authority has reason to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may send a request to the AI Office to assess the matter.3.The AI Office may exercise the powers listed in Article 14(4), points (a), (b) and (c) of Regulation (EU) 2019/1020 and Article 74(12) and (13) of this Regulation by simple request or by decision.When requesting information, the AI Office shall state the legal basis and the purpose of the request, specify what information is required, and set the period within which the information is to be provided. Where the request is a simple request, the AI Office shall additionally indicate that although there is no obligation to provide the information requested, in the case of a voluntary reply, the information must be correct and not misleading, and indicate the potential fines provided for in Article 99(5) for supplying incorrect or misleading information. Where the request is made by decision, the AI Office shall additionally indicate the fines provided for in Article 99(5) for supplying incorrect, incomplete or misleading information and indicate the right to have the decision reviewed by the Court of Justice of the European Union. The AI Office shall send a copy of the request to the market surveillance authority of the Member State in the territory of which the operator or its legal representative is situated.4.In order to carry out the tasks assigned to it under this Section, the AI Office may conduct all necessary remote or on-site inspections pursuant to the powers laid down in Article 14(4), points (d) and (e) of Regulation (EU) 2019/1020 and Article 74(5) of this Regulation. When conducting an inspection, the AI Office shall inform the provider concerned of the subject matter and purpose of the investigation, the relevant fines referred to in Article 99(5) of this Regulation, and the right to have the decision reviewed by the Court of Justice of the European Union. Prior to conducting an inspection, the AI Office shall inform the market surveillance authority of the Member State in the territory of which the operator or its legal representative is situated.During such an inspection, the officials of the AI Office shall be empowered to:(a)enter any of the business premises, land or property located in the Union of the operator concerned;(b)examine the books, data and other material relevant to the execution of their tasks, irrespective of the medium on which they are stored;(c)take or obtain in any form copies of or extracts from books, data and other records;(d)ask any of the persons subject to the inspection, or their representatives, or staff, for oral or written explanations on factors or documents relating to the subject matter and purpose of the inspection, and to record the answers;(e)seal any business premises and books or records for the duration of, and to the extent necessary for, the inspection.Where the AI Office finds that a natural or legal person opposes or obstructs an inspection, the national competent authority of the Member State concerned shall afford it the necessary assistance, requesting, where appropriate, the assistance of the police or an equivalent enforcement authority, to enable it to conduct its on-site inspection.Where an on-site inspection of business premises, land or property requires authorisation by a judicial authority in accordance with national law, the AI Office shall apply for such an authorisation. The AI Office may also apply for such authorisation as a precautionary measure. Where such an authorisation is applied for, the national judicial authority shall promptly verify that the coercive measures envisaged are neither arbitrary nor excessive having regard to the subject matter of the investigation or inspection and the documents provided by the AI Office with the decision. In its verification of the proportionality of coercive measures, the national judicial authority may ask the AI Office for detailed explanations, in particular relating to the grounds the AI Office has for suspecting that an infringement of this Regulation has taken place and the seriousness of the suspected infringement and, where relevant, the nature of the involvement of the person subject to the coercive measures. The national judicial authority shall not review the necessity of the investigation or inspection nor demand information from the case file of the AI Office. In accordance with the Treaties, the legality of the decision of the AI Office is subject to review only by the Court of Justice of the European Union.5.At the request of the AI Office, the competent market surveillance authority of a Member State may in its own territory carry out any investigation, inspection or other fact-finding measure on behalf and for the account of the AI Office in order to establish whether there has been an infringement of this Regulation. The officials of the competent authorities of the Member States who are responsible for conducting such investigations, inspections, or fact-finding measures, as well as those authorised or appointed by them, shall exercise their powers in accordance with their national law.6.In addition to the powers set out in paragraph 1 of this Article, the AI Office, in the exercise of its competences referred to in Article 75(1), may:(a)order operators to provide access to, and explanations relating to, their AI systems;(b)impose an obligation on an operator to retain all data and documents deemed to be necessary to assess the implementation of and compliance with the obligations under this Regulation.7.To assist it in monitoring the effective implementation and compliance with the relevant provisions of this Regulation and to provide it with specific expertise or knowledge in the exercise of its competences under Article 75(1), the AI Office may appoint independent external experts and auditors, as well as experts, investigative teams and auditors from the Member State’s competent authorities with the agreement of the authority concerned. Information obtained as a result of such monitoring actions shall be shared with the relevant competent authorities of the Member States.8.Information collected pursuant to this Article shall be used only for the purpose of this Regulation.

INSERTED Art. 75b — Commitments · applies from unknown (an inserted provision states its own application date only in prose)

A new Article 75b is added, allowing the AI Office to make binding, by decision, commitments offered by an operator during Article 75a(2) proceedings and to declare that there are no further grounds for action. Art. 75b, v2

It also allows the AI Office, on request or on its own initiative, to reopen those proceedings if the underlying facts materially change, the operator acts contrary to its commitments, or the original decision relied on incomplete, incorrect or misleading information from the operator. Art. 75b, v2

The new article further provides that where the AI Office considers the offered commitments unable to ensure effective compliance with the relevant provisions of the Regulation, it must reject them in a reasoned decision when concluding the proceedings. Art. 75b, v2

text before / after

inserted text (02024R1689-20260727)

Article 75bCommitmentsIf, during proceedings under Article 75a(2), the operator concerned offers commitments to ensure compliance with the relevant provisions of this Regulation, the AI Office may, by decision, make those commitments binding on the operator concerned and declare that there are no further grounds for action. The AI Office may, upon request or on its own initiative, reopen the proceedings where:(a)there has been a material change in any of the facts on which the decision was based;(b)the operator acts contrary to its commitments; or(c)the decision was based on incomplete, incorrect or misleading information provided by the operator concerned.Where the AI Office considers that the commitments offered by the operator concerned are unable to ensure effective compliance with the relevant provisions of this Regulation, it shall reject those commitments in a reasoned decision when concluding the proceedings.

INSERTED Art. 75c — Non-compliance, fines and periodic penalty payments · applies from unknown (an inserted provision states its own application date only in prose)

This new article establishes a procedure for the AI Office to formally find non-compliance by operators under Article 75(1), including issuing preliminary findings and, where relevant, ordering corrective measures within a specified period. Art. 75c, v2

It sets out powers for the AI Office to impose administrative fines under Article 99(3) to (7) for various infringements, and periodic penalty payments capped at 5% of average daily income or worldwide annual turnover, to compel compliance with investigations, information requests, inspections, corrective actions, or binding commitments. Art. 75c, v2

The article also grants the Court of Justice of the European Union unlimited jurisdiction to review such fines or penalty payments, directs collected funds to the general Union budget, and sets a five-year limitation period for both imposing and enforcing these measures. Art. 75c, v2

text before / after

inserted text (02024R1689-20260727)

Article 75cNon-compliance, fines and periodic penalty payments1.Where the AI Office finds that an operator falling within the scope of Article 75(1) does not comply with the relevant provisions of this Regulation or with commitments made binding pursuant to Article 75b, it shall adopt a decision establishing such non-compliance.2.Before adopting a decision pursuant to paragraph 1, the AI Office shall communicate its preliminary findings to the operator concerned. In the preliminary findings, the AI Office shall explain the measures that it is considering taking, or that it considers that the operator concerned should take, in order to effectively address the preliminary findings.3.In the decision pursuant to paragraph 1 of this Article, the AI Office shall, where relevant, order the operator concerned to take the necessary measures to ensure compliance with the relevant provisions of this Regulation within a reasonable period specified therein and to provide information on the measures that that operator intends to take to comply with the decision. The operator concerned shall provide the AI Office with a description of the measures it has taken to ensure compliance with the decision upon their implementation. Prior to requesting any measure, the AI Office may engage in a structured dialogue with the operator of the AI system in question. During this dialogue, the operator may propose commitments in accordance with Article 75b.4.A decision adopted pursuant to paragraph 1 of this Article may be accompanied by the imposition of penalties in accordance with Article 99(3) to (7), which provisions shall apply mutatis mutandis to the AI Office in the execution of its supervision and enforcement tasks referred to in Article 75(1).In particular, the following shall be subject to administrative fines as referred to in Article 99(4):(a)infringement of any applicable provision of this Regulation, including those not listed in Article 99(4);(b)failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020, as well as those specified in Article 75a of this Regulation;(c)failure to comply with a commitment made binding by a decision pursuant to Article 75b.The supply of incorrect, incomplete or misleading information to the AI Office in reply to a request shall be subject to administrative fines as referred to in Article 99(5).5.The AI Office may adopt a decision imposing periodic penalty payments to compel the operators subject to its competence pursuant to Article 75(1) to the following:(a)to submit to an investigation;(b)to comply with an information request ordered by a decision adopted under Article 75a(3);(c)to submit to an inspection ordered by a decision pursuant to Article 75a(4);(d)to provide correct or complete answers or explanations in the context of an inspection ordered by a decision pursuant to Article 75a(4);(e)to comply with corrective actions ordered pursuant to the power listed in Article 16 of Regulation (EU) 2019/1020;(f)to comply with commitments made legally binding by a decision pursuant to Article 75b; or(g)to comply with a decision pursuant to the paragraph (1) of this Article.Those penalty payments shall be effective and proportionate, and, where applicable, shall not exceed 5 % of the average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date appointed by the decision.6.The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the AI Office fixing a fine or periodic penalty payment pursuant to this Article. It may cancel, reduce or increase the fine or periodic penalty payment imposed.7.Funds collected through the imposition of fines or periodic penalty payments pursuant to this Article shall contribute to the general budget of the Union.8.The powers conferred on the AI Office by this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the infringement is committed. However, in the case of continuing or repeated infringements, the limitation period shall begin to run on the day on which the infringement ceases.The power of the AI Office to enforce decisions taken pursuant to this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the decision becomes final.The implementing act referred to in Article 75d(3) shall specify the first and second subparagraphs of this paragraph, including the circumstances in which the limitation periods shall be interrupted.9.Where the AI Office determines that there are no grounds to adopt a decision of non-compliance, it shall close the proceeding by a decision. That decision shall apply with immediate effect.

INSERTED Art. 75d — Safeguards and further specification · applies from unknown (an inserted provision states its own application date only in prose)

This entirely new Article 75d sets out procedural safeguards for operators subject to the AI Office's competence, including mutatis mutandis application of Article 18 of Regulation (EU) 2019/1020, rights of defence and access to the file subject to negotiated disclosure terms, and possible implementing acts on practical arrangements for such access. Art. 75d, v2

It also newly requires the AI Office to publish decisions adopted under Articles 75b and 75c, stating the parties' names and the main content of the decision including any penalties, while having regard to confidentiality interests. Art. 75d, v2

text before / after

inserted text (02024R1689-20260727)

Article 75dSafeguards and further specification1.Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to operators subject to the AI Office’s competence pursuant to Article 75(1) of this Regulation, without prejudice to more specific procedural rights provided for in this Regulation.2.The rights of defence and of access to the file of operators falling within the scope of Article 75(1) shall be fully respected in proceedings. In view of the possible adoption of decisions on the basis of Article 75c(1), those operators shall be entitled to have access to the AI Office file under the terms of a negotiated disclosure, subject to the legitimate interest of the operator or other person concerned in the protection of their business secrets. The AI Office shall have the power to adopt decisions setting out such terms of disclosure in the case of disagreement between the parties. The right of access to the file shall not extend to confidential information and internal documents of the AI Office, the Board, competent market surveillance authorities or other public authorities of the Member States. In particular, the right of access shall not extend to correspondence between the AI Office and those authorities. Nothing in this paragraph shall prevent the AI Office from disclosing and using information necessary to prove an infringement.3.The Commission may adopt implementing acts concerning the practical arrangements for access to the file and the negotiated disclosure of information provided for in paragraph 2.4.The AI Office shall publish the decisions it adopts pursuant to Articles 75b and 75c. Such publication shall state the names of the parties and the main content of the decision, including any penalties imposed. The publication shall have regard to the rights and legitimate interests of any person concerned in the protection of their confidential information.

MODIFIED Art. 76 — Supervision of testing in real world conditions by market surveillance authorities · applies from unchanged

Paragraph 1 gains a new sentence stating that where testing in real world conditions is based on Article 60a, any reference in Article 76 to a market surveillance authority is to be read as a reference to the national competent authority or the appropriate authority under the Union harmonisation legislation listed in Section B of Annex I, and references to Article 60 are to be read as references to Article 60a, as appropriate. Art. 76, v2

Paragraphs 2 through 5 remain textually unchanged between the two versions. Art. 76, v1 Art. 76, v2

text before / after

32024R168902024R1689-20260727

Article 76Supervision of testing in real world conditions by market surveillance authorities1.Market surveillance authorities shall have competences and powers to ensure that testing in real world conditions is in accordance with this Regulation.2.Where Regulation.Where testing in real world conditions is based on Article 60a, any reference to a market surveillance authority in this Article shall be construed as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I, and references to Article 60 shall be construed as references to Article 60a, as appropriate.2.Where testing in real world conditions is conducted for AI systems that are supervised within an AI regulatory sandbox under Article 58, the market surveillance authorities shall verify the compliance with Article 60 as part of their supervisory role for the AI regulatory sandbox. Those authorities may, as appropriate, allow the testing in real world conditions to be conducted by the provider or prospective provider, in derogation from the conditions set out in Article 60(4), points (f) and (g).3.Where a market surveillance authority has been informed by the prospective provider, the provider or any third party of a serious incident or has other grounds for considering that the conditions set out in Articles 60 and 61 are not met, it may take either of the following decisions on its territory, as appropriate:(a)to suspend or terminate the testing in real world conditions;(b)to require the provider or prospective provider and the deployer or prospective deployer to modify any aspect of the testing in real world conditions.4.Where a market surveillance authority has taken a decision referred to in paragraph 3 of this Article, or has issued an objection within the meaning of Article 60(4), point (b), the decision or the objection shall indicate the grounds therefor and how the provider or prospective provider can challenge the decision or objection.5.Where applicable, where a market surveillance authority has taken a decision referred to in paragraph 3, it shall communicate the grounds therefor to the market surveillance authorities of other Member States in which the AI system has been tested in accordance with the testing plan.

MODIFIED Art. 77 — Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities · applies from unchanged

The article heading now adds cooperation with market surveillance authorities, and paragraph 1 no longer limits the covered requests to high-risk AI systems referred to in Annex III, instead directing requests to the relevant market surveillance authority and specifying accessible language and machine-readable format delivered by electronic means, while adding a sentence preserving the competences, tasks, powers and independence of the relevant national public authorities or bodies. Art. 77, v1 Art. 77, v2

Two new paragraphs, 1a and 1b, are inserted: paragraph 1a requires the market surveillance authority to grant the public authority or body access to information or documentation, including by requesting it from the provider or deployer, where necessary and without undue delay, and paragraph 1b requires close cooperation and mutual assistance between market surveillance authorities and the public authorities or bodies referred to in paragraph 1, including exchange of information where necessary, while respecting their respective competences, tasks, powers and independence. Art. 77, v2

Paragraphs 2, 3 and 4 remain textually unchanged between the two versions. Art. 77, v1 Art. 77, v2

text before / after

32024R168902024R1689-20260727

Article 77Powers of authorities protecting fundamental rights1.National rights and cooperation with market surveillance authorities1.National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, in relation to the use of high-risk AI systems referred to in Annex III shall have the power to request and access any information or documentation created or maintained under from the relevant market surveillance authority pursuant to this Regulation in accessible language and machine-readable format when by electronic means where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. The This Article is without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates.1a.Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary and without undue delay.1b.Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall inform cooperate closely and provide each other with the market surveillance authority mutual assistance necessary to fulfil their respective mandates, with a view to ensuring the coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures, while respecting their respective competences, tasks, powers and independence. This shall include, in particular, exchange of information where necessary for the Member State concerned effective supervision or enforcement of any such request.2.By this Regulation and the respective other Union legislation.2.By 2 November 2024, each Member State shall identify the public authorities or bodies referred to in paragraph 1 and make a list of them publicly available. Member States shall notify the list to the Commission and to the other Member States, and shall keep the list up to date.3.Where the documentation referred to in paragraph 1 is insufficient to ascertain whether an infringement of obligations under Union law protecting fundamental rights has occurred, the public authority or body referred to in paragraph 1 may make a reasoned request to the market surveillance authority, to organise testing of the high-risk AI system through technical means. The market surveillance authority shall organise the testing with the close involvement of the requesting public authority or body within a reasonable time following the request.4.Any information or documentation obtained by the national public authorities or bodies referred to in paragraph 1 of this Article pursuant to this Article shall be treated in accordance with the confidentiality obligations set out in Article 78.

MODIFIED Art. 95 — Codes of conduct for voluntary application of specific requirements · applies from unchanged

Paragraph 4 now also refers to SMCs alongside SMEs and start-ups as an interest and need to be taken into account when encouraging and facilitating the drawing up of codes of conduct. Art. 95, v2

text before / after

32024R168902024R1689-20260727

Article 95Codes of conduct for voluntary application of specific requirements1.The AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems, other than high-risk AI systems, of some or all of the requirements set out in Chapter III, Section 2 taking into account the available technical solutions and industry best practices allowing for the application of such requirements.2.The AI Office and the Member States shall facilitate the drawing up of codes of conduct concerning the voluntary application, including by deployers, of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators to measure the achievement of those objectives, including elements such as, but not limited to:(a)applicable elements provided for in Union ethical guidelines for trustworthy AI;(b)assessing and minimising the impact of AI systems on environmental sustainability, including as regards energy-efficient programming and techniques for the efficient design, training and use of AI;(c)promoting AI literacy, in particular that of persons dealing with the development, operation and use of AI;(d)facilitating an inclusive and diverse design of AI systems, including through the establishment of inclusive and diverse development teams and the promotion of stakeholders’ participation in that process;(e)assessing and preventing the negative impact of AI systems on vulnerable persons or groups of vulnerable persons, including as regards accessibility for persons with a disability, as well as on gender equality.3.Codes of conduct may be drawn up by individual providers or deployers of AI systems or by organisations representing them or by both, including with the involvement of any interested stakeholders and their representative organisations, including civil society organisations and academia. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems.4.The AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and SMCs, when encouraging and facilitating the drawing up of codes of conduct.

MODIFIED Art. 96 — Guidelines from the Commission on the implementation of this Regulation · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Point (a) now refers to Article 26 in addition to Article 25 when listing the requirements and obligations covered by the guidelines. Art. 96, v1

A new point (g) is added covering the practical implementation of Article 8(2), Article 9(10) and Article 17(3) in light of complementarity and proportionality with the Union harmonisation legislation in Section A of Annex I, stating that such guidelines shall be published by 1 August 2027. Art. 96, v1

The paragraph on issuing guidelines now states that the Commission shall involve the Board and adds SMCs alongside SMEs and start-ups among the groups whose needs receive particular attention. Art. 96, v1

text before / after

32024R168902024R1689-20260727

Article 96Guidelines from the Commission on the implementation of this Regulation1.The Commission shall develop guidelines on the practical implementation of this Regulation, and in particular on:(a)the application of the requirements and obligations referred to in Articles 8 to 15 and in Article 25;(b)the Articles 25 and 26;(b)the prohibited practices referred to in Article 5;(c)the practical implementation of the provisions related to substantial modification;(d)the practical implementation of transparency obligations laid down in Article 50;(e)detailed information on the relationship of this Regulation with the Union harmonisation legislation listed in Annex I, as well as with other relevant Union law, including as regards consistency in their enforcement;(f)the application of the definition of an AI system as set out in Article 3, point (1).When (1);(g)the practical implementation of Article 8(2), Article 9(10) and Article 17(3) in accordance with the principle of complementarity and proportionality, with a view to ensuring consistency, avoiding duplication and minimising additional burdens when complying with the requirements of this Regulation and the requirements of the Union harmonisation legislation listed in Section A of Annex I; such guidelines shall be published by 1 August 2027.When issuing such guidelines, the Commission shall involve the Board and pay particular attention to the needs of SMEs SMEs, including start-ups, and SMCs, of local public authorities and of the sectors most likely to be affected by this Regulation.The guidelines referred to in the first subparagraph of this paragraph shall take due account of the generally acknowledged state of the art on AI, as well as of relevant harmonised standards and common specifications that are referred to in Articles 40 and 41, or of those harmonised standards or technical specifications that are set out pursuant to Union harmonisation law.2.At the request of the Member States or the AI Office, or on its own initiative, the Commission shall update guidelines previously adopted when deemed necessary.

MODIFIED Art. 97 — Exercise of the delegation · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

The list of provisions covered by the delegation of power in paragraphs 2, 3 and 6 now also includes Article 2(13) and Article 30(2), alongside the previously listed articles. Art. 97, v2

Paragraph 2 also adds a new sentence stating that the power to adopt delegated acts under Article 2(13) and Article 30(2) is conferred on the Commission for a period of five years starting from 27 July 2026, separate from the existing five-year period running from 1 August 2024. Art. 97, v2

The phrase describing when the European Parliament or Council may oppose the tacit extension changed from "not later than" to "no later than" three months before the end of each period. Art. 97, v1 Art. 97, v2

text before / after

32024R168902024R1689-20260727

Article 97Exercise of the delegation1.The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.2.The power to adopt delegated acts referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) shall be conferred on the Commission for a period of five years from 1 August 2024. The power to adopt delegated acts referred to in Article 2(13) and Article 30(2) shall be conferred on the Commission for a period of five years from 27 July 2026. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not no later than three months before the end of each period.3.The delegation of power referred to in Article 2(13), Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 30(2), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.4.Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.5.As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.6.Any delegated act adopted pursuant to Article 2(13), Article 6(6) or (7), Article 7(1) or (3), Article 11(3), Article 30(2), Article 43(5) or (6), Article 47(5), Article 51(3), Article 52(4) or Article 53(5) or (6) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.

MODIFIED Art. 99 — Penalties · applies from unchanged

Paragraph 1 now lists administrative fines among the enforcement measures Member States may adopt, refers to any infringement of the Regulation rather than infringements generally, and adds SMCs alongside SMEs and start-ups as entities whose interests and economic viability Member States must take into account when imposing penalties. Art. 99, v2 Art. 99, v1

Paragraph 4 adds a new point (da) covering non-compliance with obligations of providers and operators under Article 25(2) and (4) as a basis for the administrative fines described in that paragraph. Art. 99, v2

A new paragraph 6a is added stating that for SMCs each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred to therein, whichever is lower. Art. 99, v2

text before / after

32024R168902024R1689-20260727

Article 99Penalties1.In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to infringements any infringement of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. They The Member States shall take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability.2.The viability when imposing penalties.2.The Member States shall, without delay and at the latest by the date of entry into application, notify the Commission of the rules on penalties and of other enforcement measures referred to in paragraph 1, and shall notify it, without delay, of any subsequent amendment to them.3.Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35000000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.4.Non-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15000000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher:(a)obligations of providers pursuant to Article 16;(b)obligations of authorised representatives pursuant to Article 22;(c)obligations of importers pursuant to Article 23;(d)obligations of distributors pursuant to Article 24;(e)obligations 24;(da)obligations of providers and operators pursuant to Article 25(2) and (4);(e)obligations of deployers pursuant to Article 26;(f)requirements and obligations of notified bodies pursuant to Article 31, Article 33(1), (3) and (4) or Article 34;(g)transparency obligations for providers and deployers pursuant to Article 50.5.The supply of incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request shall be subject to administrative fines of up to EUR 7500000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.6.In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.6a.In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower.7.When deciding whether to impose an administrative fine and when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and, as appropriate, regard shall be given to the following:(a)the nature, gravity and duration of the infringement and of its consequences, taking into account the purpose of the AI system, as well as, where appropriate, the number of affected persons and the level of damage suffered by them;(b)whether administrative fines have already been applied by other market surveillance authorities to the same operator for the same infringement;(c)whether administrative fines have already been applied by other authorities to the same operator for infringements of other Union or national law, when such infringements result from the same activity or omission constituting a relevant infringement of this Regulation;(d)the size, the annual turnover and market share of the operator committing the infringement;(e)any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement;(f)the degree of cooperation with the national competent authorities, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;(g)the degree of responsibility of the operator taking into account the technical and organisational measures implemented by it;(h)the manner in which the infringement became known to the national competent authorities, in particular whether, and if so to what extent, the operator notified the infringement;(i)the intentional or negligent character of the infringement;(j)any action taken by the operator to mitigate the harm suffered by the affected persons.8.Each Member State shall lay down rules on to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.9.Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or by other bodies, as applicable in those Member States. The application of such rules in those Member States shall have an equivalent effect.10.The exercise of powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and national law, including effective judicial remedies and due process.11.Member States shall, on an annual basis, report to the Commission about the administrative fines they have issued during that year, in accordance with this Article, and about any related litigation or judicial proceedings.

MODIFIED Art. 111 — AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Paragraph 2 changes its cross-reference from Article 113(3), point (a), to Article 113, third paragraph, point (a), and replaces the fixed date of 2 August 2026 with a reference to the date of application of Chapter III as referred to in Article 113. Art. 111, v1 Art. 111, v2

A new paragraph 4 is added requiring providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content and that were placed on the market before 2 August 2026 to take the necessary steps to comply with Article 50(2) by 2 December 2026. Art. 111, v2

text before / after

32024R168902024R1689-20260727

Article 111AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked1.Without prejudice to the application of Article 5 as referred to in Article 113(3), point (a), AI systems which are components of the large-scale IT systems established by the legal acts listed in Annex X that have been placed on the market or put into service before 2 August 2027 shall be brought into compliance with this Regulation by 31 December 2030.The requirements laid down in this Regulation shall be taken into account in the evaluation of each large-scale IT system established by the legal acts listed in Annex X to be undertaken as provided for in those legal acts and where those legal acts are replaced or amended.2.Without prejudice to the application of Article 5 as referred to in Article 113(3), 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before 2 August 2026, the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of laid down in this Regulation by 2 August 2030.3.Providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027. 2027.4.Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.

MODIFIED Art. 113 — Entry into force and application · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

Point (a) now adds an exception for Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which are stated to apply from 2 December 2026 instead of the earlier date given for Chapters I and II. Art. 113, v2

Point (c) is rewritten: instead of applying only Article 6(1) and its corresponding obligations from 2 August 2027, it now covers Chapter III, Sections 1, 2 and 3 (excluding Article 6(5)) and splits the application into two dates, 2 December 2027 for high-risk systems under Article 6(2) and Annex III, and 2 August 2028 for high-risk systems under Article 6(1) and Annex I. Art. 113, v1 Art. 113, v2

A new point (d) is added stating that Articles 102 to 110 shall apply from 27 July 2026. Art. 113, v2

text before / after

32024R168902024R1689-20260727

Article 113Entry into force and applicationThis Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.It shall apply from 2 August 2026.However:(a)Chapters I and II shall apply from 2 February 2025;(b)Chapter 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026;(b)Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101;(c)Article 101;(c)Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:(i)2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and(ii)2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and the corresponding obligations in this Regulation Annex I;(d)Articles 102 to 110 shall apply from 2 August 2027. 27 July 2026.

MODIFIED Annex I — List of Union harmonisation legislation · applies from unknown (the text changed beyond its dates; the applicability binding is prose)

A new entry, numbered 21, has been added to Section B listing Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery, which repeals Directive 2006/42/EC and Council Directive 73/361/EEC. Annex I, v2

The previous final entry, item 20 concerning Regulation (EU) 2018/1139 on civil aviation, is unchanged in wording between the two versions and now has a following entry after it. Annex I, v1 Annex I, v2

text before / after

32024R168902024R1689-20260727

ANNEX IList of Union harmonisation legislationSection A. List of Union harmonisation legislation based on the New Legislative Framework1.Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);2.Directive 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1);3.Directive 2013/53/EU of the European Parliament and of the Council of 20 November 2013 on recreational craft and personal watercraft and repealing Directive 94/25/EC (OJ L 354, 28.12.2013, p. 90);4.Directive 2014/33/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to lifts and safety components for lifts (OJ L 96, 29.3.2014, p. 251);5.Directive 2014/34/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to equipment and protective systems intended for use in potentially explosive atmospheres (OJ L 96, 29.3.2014, p. 309);6.Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62);7.Directive 2014/68/EU of the European Parliament and of the Council of 15 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of pressure equipment (OJ L 189, 27.6.2014, p. 164);8.Regulation (EU) 2016/424 of the European Parliament and of the Council of 9 March 2016 on cableway installations and repealing Directive 2000/9/EC (OJ L 81, 31.3.2016, p. 1);9.Regulation (EU) 2016/425 of the European Parliament and of the Council of 9 March 2016 on personal protective equipment and repealing Council Directive 89/686/EEC (OJ L 81, 31.3.2016, p. 51);10.Regulation (EU) 2016/426 of the European Parliament and of the Council of 9 March 2016 on appliances burning gaseous fuels and repealing Directive 2009/142/EC (OJ L 81, 31.3.2016, p. 99);11.Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1);12.Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).Section B. List of other Union harmonisation legislation13.Regulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72);14.Regulation (EU) No 168/2013 of the European Parliament and of the Council of 15 January 2013 on the approval and market surveillance of two- or three-wheel vehicles and quadricycles (OJ L 60, 2.3.2013, p. 52);15.Regulation (EU) No 167/2013 of the European Parliament and of the Council of 5 February 2013 on the approval and market surveillance of agricultural and forestry vehicles (OJ L 60, 2.3.2013, p. 1);16.Directive 2014/90/EU of the European Parliament and of the Council of 23 July 2014 on marine equipment and repealing Council Directive 96/98/EC (OJ L 257, 28.8.2014, p. 146);17.Directive (EU) 2016/797 of the European Parliament and of the Council of 11 May 2016 on the interoperability of the rail system within the European Union (OJ L 138, 26.5.2016, p. 44);18.Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC (OJ L 151, 14.6.2018, p. 1);19.Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011, (EU) No 109/2011, (EU) No 458/2011, (EU) No 65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166 (OJ L 325, 16.12.2019, p. 1);20.Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1), in so far as the design, production and placing on the market of aircrafts referred to in Article 2(1), points (a) and (b) thereof, where it concerns unmanned aircraft and their engines, propellers, parts and equipment to control them remotely, are concerned. concerned;21.Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC (OJ L 165, 29.6.2023, p. 1, ELI: http://data.europa.eu/eli/reg/2023/1230/oj).

MODIFIED Annex VIII — Information to be submitted upon the registration of high-risk AI systems in accordance with Article 49 · applies from unchanged

In Section B, point 8 now ends with a full stop instead of a semicolon. Annex VIII, v2

This is a purely formal punctuation change with no alteration to the wording or substance of the listed information requirements. Annex VIII, v1 Annex VIII, v2

text before / after

32024R168902024R1689-20260727

ANNEX VIIIInformation to be submitted upon the registration of high-risk AI systems in accordance with Article 49Section A — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(1)The following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(1):1.The name, address and contact details of the provider;2.Where submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;3.The name, address and contact details of the authorised representative, where applicable;4.The AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;5.A description of the intended purpose of the AI system and of the components and functions supported through this AI system;6.A basic and concise description of the information used by the system (data, inputs) and its operating logic;7.The status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);8.The type, number and expiry date of the certificate issued by the notified body and the name or identification number of that notified body, where applicable;9.A scanned copy of the certificate referred to in point 8, where applicable;10.Any Member States in which the AI system has been placed on the market, put into service or made available in the Union;11.A copy of the EU declaration of conformity referred to in Article 47;12.Electronic instructions for use; this information shall not be provided for high-risk AI systems in the areas of law enforcement or migration, asylum and border control management referred to in Annex III, points 1, 6 and 7;13.A URL for additional information (optional).Section B — Information to be submitted by providers of high-risk AI systems in accordance with Article 49(2)The following information shall be provided and thereafter kept up to date with regard to AI systems to be registered in accordance with Article 49(2):1.The name, address and contact details of the provider;2.Where submission of information is carried out by another person on behalf of the provider, the name, address and contact details of that person;3.The name, address and contact details of the authorised representative, where applicable;4.The AI system trade name and any additional unambiguous reference allowing the identification and traceability of the AI system;5.A description of the intended purpose of the AI system;6.The condition or conditions under Article 6(3)based on which the AI system is considered to be not-high-risk;7.A short summary of the grounds on which the AI system is considered to be not-high-risk in application of the procedure under Article 6(3);8.The status of the AI system (on the market, or in service; no longer placed on the market/in service, recalled);9.Any recalled).9.Any Member States in which the AI system has been placed on the market, put into service or made available in the Union.Section C — Information to be submitted by deployers of high-risk AI systems in accordance with Article 49(3)The following information shall be provided and thereafter kept up to date with regard to high-risk AI systems to be registered in accordance with Article 49(3):1.The name, address and contact details of the deployer;2.The name, address and contact details of the person submitting information on behalf of the deployer;3.The URL of the entry of the AI system in the EU database by its provider;4.A summary of the findings of the fundamental rights impact assessment conducted in accordance with Article 27;5.A summary of the data protection impact assessment carried out in accordance with Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680 as specified in Article 26(8) of this Regulation, where applicable.

INSERTED Annex XIV — ANNEX XIV · applies from unknown (an inserted provision states its own application date only in prose)

Annex XIV is a new addition setting out a list of codes, categories and corresponding types of AI systems used for the notification procedure under Article 30, which defines the scope of designation for notified bodies. Annex XIV, v2

The annex introduces sections covering AI systems subject to Annex I and Annex III, technology-specific codes for symbolic AI and expert systems, machine learning, general-purpose or generative AI, and emerging AI technologies, and states that conformity assessment bodies must use these codes when specifying AI system types in applications for designation referred to in Article 29. Annex XIV, v2

text before / after

inserted text (02024R1689-20260727)

ANNEX XIVThe list of codes, categories and corresponding types of AI systems for the purpose of the notification procedure referred to in Article 30 specifying the scope of the designation as notified bodies1.IntroductionConformity assessment of high-risk AI systems pursuant to this Regulation may require the involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated in accordance with this Regulation may carry out conformity assessments and only for the activities related to the types of AI systems concerned. The list of codes, categories, and corresponding types of AI systems sets the scope of the designation of conformity assessment bodies notified under Article 30.2.List of Codes, categories, and corresponding AI systemsa.AI systems subject to Annex IAIA CodeAIP 0102AI systems subject to point 2 of Section A of Annex IAIP 0103AI systems subject to point 3 of Section A of Annex IAIP 0104AI systems subject to point 4 of Section A of Annex IAIP 0105AI systems subject to point 5 of Section A of Annex IAIP 0106AI systems subject to point 6 of Section A of Annex IAIP 0107AI systems subject to point 7 of Section A of Annex IAIP 0108AI systems subject to point 8 of Section A of Annex IAIP 0109AI systems subject to point 9 of Section A of Annex IAIP 0110AI systems subject to point 10 of Section A of Annex IAIP 0111AI systems subject to point 11 of Section A of Annex IAIP 0112AI systems subject to point 12 of Section A of Annex Ib.AI systems subject to point 1 of Annex IIIAIA CodeAIB 0201Remote biometric identification systemsAIB 0202Biometric categorisation AI systemsAIB 0203Emotion recognition AI systems3.AI technology-specific codesa.Symbolic AI and expert systemsAIA CodeAIH 0101AI systems based on symbolic AI, expert and knowledge-based systems, and AI systems based on search and optimisationb.Machine learning, excluding generative AI and general-purpose AI systemsAIA CodeAIH 0201AI systems that process structured dataAIH 0202AI systems that process signal and audio dataAIH 0203AI systems that process text dataAIH 0204AI systems that process image and videoAIH 0205AI systems that learn from their environment, excluding AI systems covered under AIH 0401c.AI systems based on general-purpose AI models or generative AIAIA CodeAIH 0301generative AI systems, including AI systems based on general-purpose AI modelsd.Emerging AI technologiesAIA CodeAIH 0401AI systems based on other emerging AI technologies not covered by other codes, including Agentic AI4.Application for designationConformity assessment bodies shall use the lists of codes, categories and corresponding types of AI systems set out in this Annex when specifying the types of AI systems in the application for designation referred to in Article 29.

The full entry, with the citation mapping v1 = 32024R1689, v2 = 02024R1689-20260727, is committed at eu/32024R1689/CHANGELOG.md.