Sittings · Compare

What changed

From · Plenary report · 2026-03-19 A-10-2026-0073 on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
To · Adopted text · 2026-06-16 TA-10-2026-0198 Simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
+482 added · −1887 removed · 4 modified paragraphs

PR_COD_1amCom

P10_TA(2026)0198

Symbols for procedures

Simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

* Consultation procedure

Committee on the Internal Market and Consumer Protection, Committee on Civil Liberties, Justice and Home Affairs

*** Consent procedure

PE782.530

***I Ordinary legislative procedure (first reading)

European Parliament legislative resolution of 16 June 2026 on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (COM(2025)0836 – C10-0304/2025 – 2025/0359(COD))

***II Ordinary legislative procedure (second reading)

***III Ordinary legislative procedure (third reading)

(The type of procedure depends on the legal basis proposed by the draft act.)

Amendments to a draft act

Amendments by Parliament set out in two columns

Deletions are indicated in bold italics in the left-hand column. Replacements are indicated in bold italics in both columns. New text is indicated in bold italics in the right-hand column.

The first and second lines of the header of each amendment identify the relevant part of the draft act under consideration. If an amendment pertains to an existing act that the draft act is seeking to amend, the amendment heading includes a third line identifying the existing act and a fourth line identifying the provision in that act that Parliament wishes to amend.

Amendments by Parliament in the form of a consolidated text

New text is highlighted in bold italics. Deletions are indicated using either the ▌symbol or strikeout. Replacements are indicated by highlighting the new text in bold italics and by deleting or striking out the text that has been replaced.

By way of exception, purely technical changes made by the drafting departments in preparing the final text are not highlighted.

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

(Ordinary legislative procedure: first reading)

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to the opinion of the European Central Bank of 15 April 2026,

– having regard to the opinion of the European Economic and Social Committee of 18 March 2026,

– having regard to the opinion of the Committee of the Regions of 7 May 2026,

– having regard to the provisional agreement approved by the committees responsible under Rule 75(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 13 May 2026 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,

– having regard to Rule 60 of its Rules of Procedure,

– having regard to the joint deliberations of the Committee on Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs under Rule 5859 of the Rules of Procedure,

– having regard to the opinions of the Committee on Transport and Tourism, Committee on Culture and Education and the Committee on Legal Affairs,

– having regard to the report of the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs (A10-0073/2026),

3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Amendment 1

P10_TC1-COD(2025)0359

Proposal for a regulation

Position of the European Parliament adopted at first reading on 16 June 2026 with a view to the adoption of Regulation (EU) 2026/… of the European Parliament and of the Council amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

Recital 3

(Text with EEA relevance)

Text proposed by the Commission

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Amendment

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective application of the relevant rules.

Having regard to the proposal from the European Commission,

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective, simple and uniform application of the relevant rules.

After transmission of the draft legislative act to the national parliaments,

Amendment 2

Having regard to the opinion of the European Central Bank,

Proposal for a regulation

Having regard to the opinion of the European Economic and Social Committee,

Recital 3 a (new)

Having regard to the opinion of the Committee of the Regions,

Text proposed by the Commission

Acting in accordance with the ordinary legislative procedure,

Amendment

Whereas:

(3a) Additionally, the Commission, the AI Office and Member States’ competent authorities should ensure that supervision, enforcement and monitoring of sectorial and national laws do not create overlaps, inconsistent interpretations or divergent enforcement in order to enable AI innovation in the private and public sector.

(1) Regulation (EU) 2024/1689 of the European Parliament and of the Council lays down harmonised rules on artificial intelligence (AI) and aims to improve the functioning of the internal market, to promote the uptake of human-centric and trustworthy AI, while ensuring a high level of protection of health, safety and fundamental rights and supporting innovation. Regulation (EU) 2024/1689 entered into force on 1 August 2024. The entry into application of its provisions is staggered, with all rules entering into application by 2 August 2027.

Amendment 3

(2) The experience gathered from the implementation of the parts of Regulation (EU) 2024/1689 that already apply can inform the implementation of those parts that are yet to apply. In this context, the delayed preparation of standards, which provide technical solutions for providers of high-risk AI systems to ensure compliance with their obligations under that Regulation, and the delayed establishment of the governance and the conformity assessment frameworks at national level has resulted in a compliance burden that is heavier than expected. In addition, consultations of stakeholders have revealed the need for additional measures to facilitate and provide clarification on implementation and compliance, without reducing the level of protection for health, safety and fundamental rights from AI-related risks that the provisions of Regulation (EU) 2024/1689 seek to achieve.

Proposal for a regulation

(3) Targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective, simple and uniform application of the relevant rules ▌.

Recital 4

(4) In order to enable AI innovation in the private and public sectors, it is important that the Commission and Member States’ competent authorities ensure that the supervision, enforcement and monitoring of sectoral and national laws do not create overlaps, inconsistent interpretations or divergent enforcement.

Text proposed by the Commission

(5) Regulation (EU) 2024/1689 lays down horizontal rules for AI systems to ensure a consistent and high level of protection of public interests as regards health safety and fundamental rights. For high-risk AI systems referred to in Article 6(1), that Regulation applies in conjunction with the Union harmonisation legislation listed in Section A of Annex I. In certain cases, it is possible for such Union harmonisation legislation to lay down requirements that achieve the same or a higher level of protection of relevant public interests as achieved by the specific requirements or obligations laid down in Regulation (EU) 2024/1689. In that case, it should be possible to limit the application of specific requirements or obligations laid down in Regulation (EU) 2024/1689 in order to facilitate compliance, minimise administrative burden and duplications, while preserving the level of protection ensured by that Regulation. Such limitation should be possible where, and to the extent that, the Union harmonisation legislation listed in Section A of Annex I lays down requirements providing for an equivalent level of protection of health, safety or fundamental rights as the requirement or obligation concerned. The Commission should be empowered to adopt delegated acts to supplement that Regulation by identifying such cases and specifying the products concerned, the requirements or obligations that may be limited, and the conditions and scope of any limitation, ensuring that the level of protection provided by Regulation (EU) 2024/1689 is not reduced.

Amendment

(6) Most Union companies are small and medium-sized enterprises, the majority of which are micro and small enterprises. Enterprises outgrowing the micro, small and medium-sized enterprises (SMEs) definition, namely the ‘small mid-cap enterprises’ (SMCs), play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a faster pace of growth, and a higher level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs to SMCs, it is important to address in a coherent manner the effect that Regulation may have on their activity once those enterprises become SMCs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale operators, which should be extended to SMCs where appropriate while safeguarding the overarching objectives and level of protection afforded under Regulation (EU) 2024/1689. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC and Annex to Commission Recommendation (EU) 2025/1099, respectively.

(4) Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4 and Annex to Commission Recommendation 2025/3500/EC5 .

(7) The notion of a ‘safety component’ is crucial for the classification of certain AI systems as high-risk according to Regulation (EU) 2024/1689. Thus, the notion should be targeted to include only the AI systems which could have an adverse impact on the health and safety of persons or property, in line with the risk-based approach of that Regulation. The definition set out in Article 3, point (14) of Regulation (EU) 2024/1689 does not provide the necessary clarity to allow providers of AI systems to determine whether an AI system qualifies as a safety component and, as a result, risks extending the high-risk classification of AI systems beyond what is justified by the risk-based approach of that Regulation. It is therefore necessary to amend that definition. First, it is necessary to provide clarity on the concept of a ‘safety function’. The safety function should be an intended purpose of the system, which is determined by the provider of the system. An AI system fulfils a safety function where its intended purpose, as determined by the provider, is to prevent or mitigate risks to the health and safety of persons or property. In particular, this does not include AI systems which are intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or non-safety related aspects for quality control operations. The mere fact that an AI system is integrated into or operates within a product that is subject to Union harmonisation legislation does not, in itself, mean that it fulfils a safety function.

(4) 99,8% of all Union companies are small and medium-sized enterprises, the majority of which are micro and small enterprises.3a Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs where appropriate while safeguarding the overarching objectives and level of protection afforded under Regulation (EU) 2024/16893b. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4 and Annex to Commission Recommendation 2025/3500/EC5 .

(8) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. Development of AI literacy starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary skills to make informed decisions regarding the deployment of AI systems. However, experience shared by stakeholders reveals that a ▌ solution imposing stringent obligations to ensure a sufficient level of AI literacy would not be suitable for all types of providers and deployers in relation to the promotion of AI literacy ▌. Moreover, data indicates that imposing such obligations creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that information, Article 4 of Regulation (EU) 2024/1689 should be amended to require ▌ providers and deployers to take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. The Commission and Member States should support and facilitate the efforts of providers and deployers of AI systems, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other ▌ initiatives. When complying with this obligation, the Commission and the Member States could take into account the European competence frameworks, for example the Digital Competence Framework for Citizens (DigComp) and the AI Literacy Framework for Primary and Secondary Education. The European Artificial Intelligence Board (the Board) should support the Commission and Member States by adopting recommendations setting out common objectives to be achieved in order to meet their obligation and ensure regular exchange between the Commission and Member States on the topic, while the Apply AI Alliance should allow discussion with the wider community. ▌

__________________

__________________

(9) Bias detection and correction constitute a substantial public interest because they protect natural persons from the adverse effects of biases, including discrimination. For that reason, Regulation (EU) 2024/1689 ▌ provides a legal basis authorising providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. This legal basis is linked to the obligation on those providers to establish practices concerning the detection, prevention and correction of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects could also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. For example, biases in eligibility or risk-scoring tools used to assess applications for various types of public permits or licences can restrict rights or effectively prevent certain groups from accessing public services. Accordingly, a substantial public interest exists to allow, exceptionally and where strictly necessary, the processing of special ▌categories of personal data for the purposes of bias detection and correction to providers and deployers of other AI systems and models and deployers of high-risk AI systems. It is therefore necessary to extend the legal basis, established pursuant to Regulation (EU) 2024/1689, to those providers and deployers. That legal basis should be subject to the same limitations, conditions and safeguards that apply in accordance with the existing Article 10(5) of that Regulation, thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 of the European Parliament and of the Council, Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council. Furthermore, to enable providers of high-risk AI systems to lawfully undertake bias detection and correction activities in preparation for compliance with the requirements for high-risk AI systems, including Article 10(2), points (f) and (g), of Regulation (EU) 2024/1689, the legal basis established by Article 4a of Regulation (EU) 2024/1689 should apply from the date of entry into application of that Regulation.

3a https://single-market-economy.ec.europa.eu/system/files/2023-08/Annual%20Report%20on%20European%20SMEs%202023_FINAL.pdf

(10) Article 5 of Regulation (EU) 2024/1689 prohibits certain practices of AI systems that are particularly harmful and abusive, contradict certain Union values and violate certain fundamental rights. Article 5 is to be kept under review, as laid down in Article 112(1) of that Regulation. In light of technological and societal developments since the adoption of that Regulation, including the deployment and widespread use of AI systems generating non-consensual intimate images, videos, audio and similar material (‘non-consensual intimate material’) and child sexual abuse material, it is necessary to amend Article 5 of that Regulation.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, pp. 36–41, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

(11) Non-consensual intimate material constitutes sexual violence and abuse against individuals, in particular women. AI systems that generate or manipulate such material pose a severe risk to health safety and fundamental rights, including victims’ human dignity, personal autonomy, integrity and private life, with potentially serious lasting psychological and other harms, and enable abuse at scale. The proliferation of such technologies, often described as ‘nudification’ applications, has created an urgent need for an explicit regulatory prohibition. Child sexual abuse material, including wholly or partially synthetic material, constitutes a grave threat to the safety and fundamental rights of children. AI systems generating or manipulating such material pose a grave risk to human dignity and the rights of the child, and risk normalising, amplifying and perpetuating sexual violence against children. Accordingly, an amendment to Article 5 of Regulation (EU) 2024/1689 is necessary both to protect women, children, other individuals and society from seriously harmful practices, thereby pursuing the objectives of that Regulation, and to bring clarity to providers and deployers as to the scope of their obligations, thereby addressing implementation challenges.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, pp. 36–41, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

(12) It is necessary to define clearly the scope of the prohibition, including in particular the extent of providers’ and deployers’ obligations. This prohibition should not prevent providers from developing the technical capabilities of AI systems to generate or manipulate images, videos, audio or similar material. As concerns providers, the prohibition should be limited to the placing on the market or the putting into service of AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material in two cases. First, it should cover systems intended to generate or manipulate such material. Second, it should cover systems where such generation or manipulation is a reasonably foreseeable and reproducible outcome and there are no reasonable and adequate technical safety measures and other safeguards in place, taking into account reasonably foreseeable misuse, to reliably prevent, and where necessary correct, that outcome and correct observed or reported misuse, including circumvention of such measures. Technical measures and other safeguards to prevent the generation of such material could include data cleaning, refusal training, safe prompt design and output controls, runtime prompt guardrails, content classification and filtering mechanisms, usage restrictions, abuse detection mechanisms, and notice and action mechanisms. Such preventive measures should be reasonable for the specific AI system, and are considered adequate if they align with the state-of-the-art measures and demonstrably prevent or sufficiently reduce in each specific case the likelihood of generating or manipulating such material, taking into account known and reasonably foreseeable misuse, including reasonably foreseeable circumvention of the preventive measures without significant technical modification. For providers retaining effective control over AI systems, for instance through a platform or a web interface, that could include following and reporting methods for misuse cases in full compliance with Union privacy and data protection law. In cases of observed or reported circumvention of the preventive measures or other safeguards, adequate corrective measures should be taken provided that such measures are reasonable, taking into account the specific AI system, including its release and distribution strategy (such as open-source releases). As concerns deployers, the use of an AI system should be prohibited only where the deployer uses an AI system for the purpose of generating or manipulating non-consensual intimate material or child sexual abuse material. This includes cases where a deployer uses or misuses AI systems placed on the market or put into service that lack reasonable and adequate preventive measures or where a deployer circumvents the preventive measures or uses for such purposes lawful AI systems not intended to generate or manipulate such material. The prohibition on use therefore does not cover the use of an AI system for lawful purposes, such as the generation or manipulation of material other than non-consensual intimate material or child sexual abuse material, even in cases where the AI system lacks reasonable and adequate safeguards that should have been put in place by the provider, nor does it cover accidental generation or manipulation of such content. Concerning the prohibition regarding non-consensual intimate material, where an AI system is intended for generation or manipulation of material falling under this prohibition, measures and other safeguards should include appropriate means for the distribution of the AI system aimed at enabling the reliable collection and demonstration of consent of the depicted person to such generation or manipulation, in compliance with Regulation (EU) 2016/679. The prohibition regarding non-consensual intimate material should be limited to realistic depictions of intimate parts, notably the genitals, pubic area, anus, exposed buttocks or exposed female breasts, nipples or areolae, or of sexually explicit activity. This ‘realism’ refers to the depiction of the person’s face, voice or their body in a credible real-life manner, regardless of the realism of the context of that depiction or whether it fully corresponds to the actual voice or appearance of the depicted person. Conversely, it excludes cartoonish or physically impossible depictions of a person’s body. The prohibition of non-consensual intimate material does not affect the generation or manipulation of other forms of nude material, such as material that does not depict identifiable natural persons, realistic partially nude depictions where intimate parts are not revealed and sexually explicit activities are not depicted, or non-realistic artistic nude works that do not realistically depict identifiable natural persons engaged in sexually explicit activity or depict their intimate parts. It also does not cover generative AI applications where intimate parts are not exposed or, if exposed, this is subject to the freely given, specific, informed, unambiguous and explicit consent of the depicted person (for example, try-on applications and medical applications, such as medical anatomical simulations and mammograms); this prohibition does not preclude the exceptional use of AI systems generating or manipulating nude depictions of the intimate parts of an identifiable person, in accordance with fundamental rights law, including data protection law, and applicable medical law, for the purpose of medical diagnosis and treatment by medical professionals where the person concerned is incapable of consent (for instance in an emergency situation). Finally, the prohibition on ‘manipulating’ non-consensual intimate material excludes cases where pre-existing intimate material is manipulated in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities, for instance the mere enhancement of an existing image depicting intimate parts or video depicting sexually explicit activities, such as changing the background, adding a text heading or enhancing the contrast or the brightness. Conversely, any manipulation of material, including material that already depicts intimate parts or sexually explicit activity, that increases the level of exposure of any depicted intimate parts or alters the nature of any depicted sexually explicit activities, falls under the scope of this prohibition.

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

(13) The prohibition on child sexual abuse material should not prevent the placing on the market, putting into service or use of an AI system where a ‘without right’ defence applies under national law, as referred to in Article 5(1) of Directive 2011/93/EU of the European Parliament and of the Council. This includes activities carried out under domestic legal powers, such as the legitimate generation, or manipulation of child sexual abuse material by the authorities in order to conduct criminal proceedings or to prevent, detect or investigate crime, as well as the legitimate use of the AI system in the context of red-teaming and evaluation activities for the purpose of assessing the system’s compliance with the prohibition laid down in this Regulation.

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

(14) These prohibitions constitute justified interferences with the freedom of expression and information and the freedom to conduct a business. They pursue objectives of general interest and protect the rights and freedoms of others, including those set out in Article 1, Article 3(1) and Articles 4, 7, 8, 21, 23 and 24 of the Charter of Fundamental Rights of the European Union (the Charter). They are closely tailored. In the case of intimate material, they are limited to realistic depictions of identifiable natural persons and to cases where the AI system is used to increase the level of nudity or explicitness; and exclude generation or manipulation with the person’s consent. Moreover, they are limited to requiring providers to implement ‘reasonable and adequate’ measures and safeguards in the case of systems not intended to generate or manipulate the prohibited material. They are also aligned with existing Union law, including Directive (EU) 2011/93/EU and Directive (EU) 2024/1385 of the European Parliament and of the Council. The interferences respect the essence of Articles 11 and 16 of the Charter, are prescribed by law, and are proportionate.

Amendment 4

(15) The conduct covered by these prohibitions may also violate other law, including criminal law. The prohibitions do not preclude prosecution under such law. However, insofar as an infringement of the prohibitions may result in the imposition of penalties of a criminal nature, which may be laid down pursuant to Article 99(1) of Regulation (EU) 2024/1689, and to the extent that the same conduct is sanctioned under criminal law, including criminal law falling within the scope of Directives 2011/93/EU and (EU) 2024/1385, Member States are required to ensure respect for the ne bis in idem principle in accordance with the Charter.

Proposal for a regulation

(16) The prohibitions are without prejudice to remedies available under national laws for individuals to protect their fundamental rights, including rights to their image, privacy and human dignity.

Recital 5

(17) In order to ensure consistency, avoid duplication and minimise administrative burdens in relation to the procedure for the designation of notified bodies pursuant to Regulation (EU) 2024/1689, while maintaining the same level of scrutiny, a single application and a unified assessment procedure should be available for new conformity assessment bodies and notified bodies which are designated pursuant to the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, such as Regulations (EU) 2017/745 and (EU) 2017/746 of the European Parliament and of the Council, where such an application and procedure is established pursuant to that Union harmonisation legislation. The single application and unified assessment procedure aims to facilitate, support and expedite the designation procedure in accordance with Regulation (EU) 2024/1689, while ensuring compliance with the requirements applicable to notified bodies in accordance with that Regulation and the Union harmonisation legislation listed in Section A of Annex I thereto. The unified assessment procedure should be carried out with respect to the tasks and responsibilities of the authorities involved. Moreover, it should be clarified that a conformity assessment body that is designated pursuant to more than one piece of Union harmonisation legislation listed in Section A of Annex I should have to apply only once to be designated pursuant to this Regulation.

Text proposed by the Commission

(18) With a view to ensuring the smooth application and consistency of Regulation (EU) 2024/1689, amendments should be made to it. A technical correction to Article 43(3), first subparagraph, of Regulation (EU) 2024/1689 should be made to align the conformity assessment requirements with the requirements of providers of high-risk AI systems in Article 16 of that Regulation. Moreover, it should be clarified that where a provider of a high-risk AI system is subject to the conformity assessment procedure under Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, and the conformity assessment extends to the compliance of the quality management system of that Regulation and of such Union harmonisation legislation, the provider should be able to include aspects related to quality management systems pursuant to that Regulation as part of the quality management systems pursuant to such Union harmonisation legislation, in accordance with Article 17(3) of Regulation (EU) 2024/1689. Article 43(3), second subparagraph, of that Regulation should be amended to clarify that notified bodies which have been notified pursuant to the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and which aim to assess high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I to that Regulation, should have the power to assess the conformity of high-risk AI systems under certain conditions for 18 months from … [the entry into force of this Regulation]. This amendment is without prejudice to Article 28 of Regulation (EU) 2024/1689, thus conformity assessment bodies that wish to be designated and notified pursuant to that Regulation can submit an application at any time during and after these 18 months. Moreover, Regulation (EU) 2024/1689 should be amended to clarify that where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and falls within one of the use-cases listed in Annex III to that Regulation, the provider should follow the relevant conformity assessment procedure as required under that relevant harmonisation legislation.

Amendment

(19) Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847 of the European Parliament and of the Council complement each other so that the safety and cybersecurity of products with digital elements is ensured. Article 12 of Regulation (EU) 2024/2847 states that where high-risk AI systems and processes put in place by manufacturers fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847. In order to improve the visibility of the interplay of Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847, the rule of Article 12 of Regulation (EU) 2024/2847 should also be reflected in Regulation (EU) 2024/1689. The interplay between the two instruments should not be affected.

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

(20) In accordance with Article 6(1) of Regulation (EU) 2024/1689, AI systems are classified as high-risk where an AI system that is a component of a product covered by Union harmonisation legislation listed in Section A of Annex I to that Regulation is a safety component and that product requires a third-party conformity assessment. The requirement that such product must require a third-party conformity assessment, however, does not affect the choice of the manufacturer regarding the conformity assessment procedure for such product. Where Union harmonisation legislation listed in Section A of Annex I allows to choose a conformity assessment procedure based on harmonised standards amongst conformity assessment procedures, this possibility remains applicable also to products in which a high-risk AI system is embedded. Article 6(1) of Regulation (EU) 2024/1689 should not be understood to require products in which a high-risk AI system is embedded to automatically undergo a third-party conformity assessment involving a notified body. Where this possibility is provided for in Union harmonisation legislation, the provider of the product in which the high-risk AI system is embedded could continue to rely on harmonised standards to comply with the requirements of the Union harmonisation legislation and Regulation (EU) 2024/1689 as a conformity assessment procedure.

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary skills to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a solution imposing stringent obligations to ensure a sufficient level of AI literacy is not suitable for all types of providers and deployers in relation to the promotion of AI literacy. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require providers and deployers of AI systems to support AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The European Commission should promote AI literacy and competences for the wider population, and in order to support, facilitate and complement the efforts of providers, should be tasked to issue guidance on the practical implementation regarding the obligation on providers and deployers of AI systems, and should, together with the Member States, encourage and support AI literacy in society. This should include facilitating and complementing the efforts of providers and deployers of AI systems, in particular SMEs, as the implementation of the relevant obligations poses particular challenges for them. One possibility to facilitate AI literacy in the Union could be the creation of Public Private Partnerships (PPPs).

Amendment 5

(21) In order to enhance competitiveness and innovation, it is essential to support economic operators that are required to comply simultaneously with the requirements or obligations set out in Chapter III, Sections 2 and 3 of Regulation (EU) 2024/1689, and with the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to that Regulation. To support and simplify the regulatory compliance pathways of such economic operators, the Commission should request that, without undue delay, the European standardisation organisations develop standardisation deliverables, including, where appropriate, harmonised standards. Those standardisation deliverables should be based on the harmonised standards published in the Official Journal of the European Union that give the presumption of conformity with the requirements or obligations of Regulation (EU) 2024/1689, as well as any relevant harmonised standards published in the Official Journal of the European Union that give the presumption of conformity with the relevant requirements or obligations set out in the Union harmonisation legislation listed in Annex I to that Regulation. Such standardisation deliverables should help reduce legal uncertainty, avoid unnecessary duplication of conformity assessment activities, testing, documentation and reporting obligations, and lower compliance costs, in particular for small and medium-sized enterprises and start-ups. Timely development of such deliverables is essential in order to provide economic operators with practical and reliable technical solutions, strengthen legal certainty and facilitate the placing on the market, putting into service and use of AI systems in accordance with this Regulation and the Union harmonisation legislation listed in Annex I to that Regulation.

Proposal for a regulation

(22) To streamline compliance and reduce associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the content required under Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate. This simplification would strike a better balance without undermining the protection laid down by Regulation (EU) 2024/1689. Such AI systems are not considered to be high risk under certain conditions where they do not pose a significant risk of harm to the health, safety or fundamental rights of persons. Furthermore, a provider applying Article 6(3) of Regulation (EU) 2024/1689 remains obligated to document its assessment before that AI system is placed on the market or put into service. National competent authorities should be able to request that assessment .

Recital 5 a (new)

(23) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that also include real-world testing, the real-world testing plan should be integrated into the sandbox plan agreed by the providers or prospective providers and the competent authority. ▌

Text proposed by the Commission

(24) In addition, it is appropriate to provide for the possibility of the European Artificial Intelligence Office (AI Office) to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. To ensure coherence, legal certainty and an efficient allocation of supervisory responsibilities between Union and national levels, the scope of the Union-level AI regulatory sandbox should be clearly defined in order to avoid any overlap with national AI regulatory sandboxes established pursuant to that Regulation. In order to foster innovation and facilitate the uptake of AI, SMEs, including startups, and SMCs should be provided with priority access to the AI regulatory sandboxes established by the AI Office.

Amendment

(25) Moreover, the provisions on the cooperation between relevant competent authorities for the operation of an AI regulatory sandbox should be clarified in order to ensure their effective functioning. For that reason, the empowerment of the Commission to adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of the AI regulatory sandboxes should be extended to also cover governance aspects of such sandboxes. In addition, where AI regulatory sandboxes involve innovative AI systems that process personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the relevant competent supervisory authorities should be associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.

(5a) AI systems that alter, manipulate or artificially generates realistic images or videos depicting sexually explicit activities, or the intimate parts of an identifiable natural person, without that person’s consent, cause harm to victims and violate fundamental rights to dignity and privacy. The proliferation of such technologies, often marketed as 'nudification’ applications, has created an urgent need for explicit regulatory prohibition. Regulation (EU) 2024/1689 establishes a framework for prohibited AI practices, which is to be kept under review. This is without prejudice towards the rights, freedoms and principles recognised by Article 6 TEU and the Charter of Fundamental Rights of the European Union, and the exercise of the rights guaranteed therein to freedom of expression and information and the freedom of the arts and sciences. This prohibition should not apply to providers or deployers of AI systems who have put in place effective safety measures, such as technical and organisational measures, to prevent the generation of such depictions and to avoid continuously misuse, after the system has been placed, on the market or put into service, despite the intention of the provider or deployer. Moreover, this prohibition should not prevent AI providers from developing their technical capabilities to alter, manipulate or artificially generate images or videos.

(26) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions, subject to sufficient safeguards. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation. ▌

Amendment 6

(27) It is also appropriate to ensure that real-world testing of high-risk AI systems covered by the Union harmonisation legislation listed in Section B of Annex I to Regulation (EU) 2024/1689 is possible. Those systems are subject to the requirements and procedures of the relevant sectoral legislation and are, for most purposes, not directly subject to that Regulation. Those sectoral acts will, in due course, incorporate requirements corresponding to the requirements set out in Articles 8 to15 of that Regulation. Therefore, it is appropriate to ensure that Member States can allow real-world testing of these AI systems with a view to assessing and verifying the conformity of those systems with the requirements set out in Articles 8 to 15 of that Regulation. If Member States decide to allow such testing, that Regulation should require them to adopt frameworks setting out the detailed requirements for such testing. That Regulation should provide for essential elements to be contained in such frameworks. When designing such frameworks, Member States should ensure a high level of protection of health safety and fundamental rights of natural persons. Before implementing the framework, Member States should notify it to the Commission. The real-world testing should comply with the relevant Union harmonisation legislation listed in Section B of Annex I to Regulation (EU) 2024/1689, including any applicable provisions regarding testing. However, this should not affect the application of the new article regarding real-world testing.

Proposal for a regulation

(28) Article 63 of Regulation (EU) 2024/1689 offers microenterprises who are providers of high-risk AI systems the possibility to benefit from a simplified way to comply with the obligation to establish a quality management system. With a view to facilitating compliance for more innovators, that possibility should be extended to all SMEs, including start-ups.

Recital 6

(29) In light of the important role of the AI Office for the effective and coordinated governance of Regulation (EU) 2024/1689, as further reinforced by this Regulation, and without prejudice to the next Multiannual Financial Framework and to the budgetary procedure, the Commission should allocate adequate human, financial and technical resources to the AI Office to ensure that it can effectively, and within reasonable timeframes, perform its tasks in relation to the enforcement of Regulation (EU) 2024/1689, including the allocation of a sufficient number of permanent personnel with in-depth competences and technical expertise.

Text proposed by the Commission

(30) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay to the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances. ▌

Amendment

(31) In order to strengthen the governance system for AI systems ▌ , it is necessary to clarify the role of the AI Office in monitoring and supervising the compliance of such AI systems with Regulation (EU) 2024/1689. The Commission has exclusive competence as regards general-purpose AI models under Article 88 of that Regulation. To increase coherence, clarity and effectiveness, and in light of the reach and impacts of AI systems linked to those competences, the scope of the AI Office’s exclusive competence to supervise systems should be refined. In particular, the AI Office should have exclusive competence over AI systems built on general-purpose AI models, not only where both the system and the model are developed by the same provider, but also where they are developed by providers that form part of the same undertaking. However, in certain cases, in particular where there is specific sectoral supervision, responsibility should remain with the relevant national competent authority. Accordingly, certain exceptions should be laid down. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. Other deployers should remain subject to national supervision and enforcement. Moreover, this does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689. ▌

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. Discrimination might result from the bias in AI models and AI systems other than high-risk AI systems for which of Regulation (EU) 2024/1689 already provides a legal basis authorising the processing of special categories of personal data under Article 9(2), point (g), of Regulation (EU) 2016/679 of the European Parliament and of the Council6 . Given that discrimination might result also from those other AI systems and models, it is therefore appropriate that Regulation (EU) 2024/1689 should provide for a legal basis for the processing of special categories of personal data also by providers and deployers of other AI systems and AI models as well as deployers of high-risk AI systems. The legal basis is established in compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council7 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council8 provides a legal basis allowing, where necessary for the detection and removal of bias, the processing of special categories of personal data by providers and deployers of all AI systems and models, subject to appropriate safeguards that complement Regulations (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 already provides a legal basis authorising the providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. This legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Accordingly, a substantial public interest exists to permit, where strictly necessary, the processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it also applies to the also by providers and deployers of other AI systems and AI models. That legal basis should be subject to the same conditions and safeguards as apply under the existing Article 10(5), thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council.

(32) Additionally, considering the existing supervisory and enforcement system under Regulation (EU) 2022/2065 of the European Parliament and of the Council, it is appropriate to grant the Commission the powers of a competent market surveillance authority pursuant to Regulation (EU) 2024/1689 where an AI system qualifies as a very large online platform or a very large online search engine in accordance with Regulation (EU) 2022/2065, or where it is embedded in such a platform or search engine. This should contribute to ensuring that the exercise of the Commission’s supervision and enforcement powers pursuant to Regulation (EU) 2024/1689 and Regulation (EU) 2022/2065, as well as those applicable to general-purpose AI models integrated into such platforms or search engines, is carried out in a coherent and effective manner. This is also appropriate in light of the importance of such platforms and search engines, in view of their reach, impact and potential to cause complex and large societal harms. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. In the case of AI systems embedded in or qualifying as a very large online platform or search engine, the first point of entry for the assessment of the AI systems are the risk assessment, mitigating measures and audit obligations prescribed by Articles 34, 35 and 37 of Regulation (EU) 2022/2065, without prejudice to the AI Office’s powers to investigate and enforce ex post non-compliance with the rules of Regulation (EU) 2024/1689. In the context of the analysis of this risk assessment, mitigating measures and audits, the Commission services responsible for the enforcement of Regulation (EU) 2022/2065 may seek the opinion of the AI Office on the outcome of a potential earlier or parallel risk assessment carried out in accordance with Regulation (EU) 2024/1689 and the applicability of prohibitions pursuant to Regulation (EU) 2024/1689. In addition, the AI Office and the competent national authorities should, in accordance with Regulation (EU) 2024/1689, coordinate their enforcement efforts with the authorities competent for the supervision and enforcement of Regulation (EU) 2022/2065, including the Commission, in order to ensure that the principles of loyal cooperation, proportionality and non bis in idem are respected, while information obtained pursuant to one Regulation is to be used for the purposes of supervision and enforcement of the other only provided the undertaking agrees. In particular, those authorities should exchange views regularly and take into account, in their respective areas of competence, any fines and penalties imposed on the same provider for the same conduct through a final decision in proceedings relating to an infringement of other Union or national rules, so as to ensure that the overall fines and penalties imposed are proportionate and correspond to the seriousness of the infringements committed.

__________________

(33) When supervising and enforcing obligations in relation to AI systems under its competence, the AI Office has the same role and responsibility as a market surveillance authority pursuant to Regulation (EU) 2024/1689. Consequently, it is necessary for the AI Office to have all of the powers and responsibilities that market surveillance authorities have pursuant to that Regulation and Regulation (EU) 2019/1020 of the European Parliament and of the Council (‘the general powers’). These should ensure the appropriate and effective enforcement of the requirements and obligations set out in Regulation (EU) 2024/1689. However, it is necessary to specify, complement, and frame certain essential elements and other aspects of the general powers, as well as their safeguards (‘the specifying provisions’). In particular, it is necessary to lay down provisions governing the relationship between the AI Office and national authorities; provisions specifying, complementing, and constraining the powers to request information and conduct on-site inspections; provisions governing investigations, including the possibility to make commitments binding; and provisions specifying and constraining power to find non-compliance, impose fines and impose periodic penalties. Where a type of general power has been so specified, the AI Office may not circumvent the conditions and limits of those powers by relying on a related general power. Conversely, types of general power that are not specified and framed in respect of the AI Office, such as the power to adopt measures referred to in Article 16(3) of Regulation (EU) 2019/1020, may be relied on by the AI Office. As necessary for the proper implementation of Regulation (EU) 2024/1689, the Commission should be able to adopt implementing acts further defining the rules and the procedures concerning the application of limitation periods and, the access to the file and the negotiated disclosure of information. In exercising all of these powers, the AI Office must comply with the Charter. Additionally, the AI Office is subject to the safeguards and protection for fundamental rights laid down in the specifying provisions.

__________________

(34) In addition to those procedural and fundamental rights safeguards ▌ the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020 should apply mutatis mutandis to providers of AI systems, without prejudice to more specific procedural rights provided for in Regulation (EU) 2024/1689. When national market surveillance authorities, through the single point of contact, request that the AI Office takes supervisory and enforcement measures with regards to AI systems under its exclusive supervision, the AI Office should no later than four months following the receipt of that request, inform the single point of contact of its intention to exercise its supervisory and enforcement powers or of its reasons for not exercising its powers. If the AI Office decides to exercise its supervisory and enforcement powers, it should also inform the single point of contact about the final outcome of such proceedings and of intermediate developments that the AI Office considers as having a major impact in the investigation, including the decision to open proceedings, to impose a fine, and to withdraw or recall the AI system from the market.

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(35) To enable access to the Union market for AI systems which are under the supervision of the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to a third party conformity assessment, the Commission should be responsible for the pre-market conformity assessments of those systems.

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(36) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests without undue delay, and that the authorities or bodies involved should have a mutual obligation to cooperate. It should be clarified that these provisions are without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates. In particular, those provisions do not limit any powers that those authorities and bodies have to request information pursuant to other Union or national law. Accordingly, those authorities and bodies retain any power they have to directly request information from operators pursuant to their mandate or Union or national law.

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(37) The requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 address specific risks inherent to AI systems, including bias, unpredictable model behaviour, poor robustness or accuracy, vulnerabilities to attacks by third parties, and a lack of transparency of the AI system. By addressing AI-specific risks, that Regulation complements the requirements laid down in Union harmonisation legislation listed in Annex I to that Regulation, without duplicating them. Regulation (EU) 2024/1689 provides mechanisms for economic operators to minimise the compliance burden. In particular, Article 8(2) on the interplay with the sectoral legislation, Article 9(10) on risk management and Article 17(3) on quality management, allow economic operators to integrate, when necessary and appropriate, an assessment of AI-specific risks into existing risk and quality management systems. Article 40 of Regulation (EU) 2024/1689 further requires the Commission to specify that harmonised standards developed pursuant to that Regulation are to be consistent with standards developed pursuant to the Union harmonisation legislation listed in Annex I to that Regulation. The Commission should provide guidelines to assist economic operators of high-risk AI systems covered in Annex I to Regulation (EU) 2024/1689 in complying with that Regulation, including by providing guidance on the application of Article 8(2), Article 9(10) and Article 17(3) of that Regulation as mechanisms to minimise the compliance burden, in line with principles of complementarity and proportionality. Those guidelines should be published, at the latest, by 1 August 2027.

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(38) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of four months for providers who have already placed their systems on the market before the 2 August 2026.

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(39) To provide sufficient time for providers of high-risk AI systems and to clarify rules applicable to the AI systems already placed on the market or put into service before the relevant provisions of Regulation (EU) 2024/1689 apply, it is appropriate to clarify the scope of the grace period provided in Article 111(2) of that Regulation. For the purpose of that Article 111(2), the grace period should apply where the type and model of AI system has already been placed on the market. This means that if at least one individual unit of the high-risk AI system has been lawfully placed on the market or put into service before the date specified in Article 111(2), other individual units of the same type and model of high-risk AI system are subject to the grace period provided in that Article 111(2) and thus may continue to be placed on the market, made available or put into service on the Union market without any additional obligations, requirements or the need for additional certification, as long as the design of that high-risk AI system remains unchanged. For the purposes of the application of the grace period provided in Article 111(2), the decisive factor is the date on which the first unit of that type and model of high-risk AI system was placed on the market or put into service on the Union market for the first time. Any significant change to the design of that AI system after the date specified in Article 111(2) should trigger the obligation of the provider to fully comply with all relevant provisions of that Regulation applicable to high-risk AI systems, including the conformity assessment requirements.

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(40) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, in particular that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations and that risk a significant increase in implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. Therefore, it is appropriate that the date of application of Sections 1, 2 and 3 of Chapter III is set to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I ▌. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations. The timely availability of support instruments, including guidance, relevant standards, common specifications and codes of practice is important in order to facilitate compliance and reduce the risk of divergent interpretation and uneven application of the rules across Member States. In order to ensure legal certainty and to avoid further delays in the application of Regulation (EU) 2024/1689, the Commission should ensure that measures in support of compliance with regard to Chapter III, Sections 1, 2, and 3 of that Regulation are in place in due time to ensure timely and effective implementation of the necessary provisions.

Amendment 7

Proposal for a regulation

(41) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where that is not the case. Article 50(7), Article 56(6), and Article 72(3) of Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission to adopt implementing acts. Given that the codes of practice referred to in Article 50(7) and Article 56(6) have limited legal effect, and in particular do not grant a presumption of conformity, it is not strictly necessary for these codes to be approved by an implementing act. Providers should be able to rely, pursuant to Article 53(4) and Article 54(2) of Regulation (EU) 2024/1689, on codes of practice assessed as adequate pursuant to Article 56(6) thereof. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has the additional benefit of offering more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity regarding how providers of high-risk AI systems are required to comply with their obligation set out in Article 72(1) of Regulation (EU) 2024/1689, the Commission should be required to publish guidance, including a voluntary template, on the post-market monitoring plan by 2 September 2027.

Recital 7

(42) The use of artificial intelligence in machinery can help foster innovation and improve the efficiency of those machines. The application of Regulation (EU) 2023/1230 of the European Parliament and of the Council and Regulation (EU) 2024/1689 might lead to overlaps. At the same time, it is important to ensure a level of protection with regard to risks related to the use of artificial intelligence in machinery that is consistent with the level of protection provided in Regulation (EU) 2024/1689 with regard to high-risk AI systems. Given the specific nature of machinery and the machinery sector, and in order to address the need to simplify the regulatory framework for AI-enabled machinery, it is appropriate to move to a sectoral approach by moving Regulation (EU) 2023/1230 from Section A to Section B of Annex I to Regulation (EU) 2024/1689. Accordingly, first, the application of Regulation (EU) 2024/1689 to those machines should be limited to the provisions referred to in Article 2(2) of that Regulation. The reference to Directive 2006/42/EC should be moved from Section A to Section B of Annex I to Regulation (EU) 2024/1689 and updated so as to refer to Regulation (EU) 2023/1230. Second, it is crucial to ensure that Regulation (EU) 2023/1230 incorporates essential health and safety requirements for high-risk AI systems classified pursuant to Article 6(1) of Regulation (EU) 2024/1689 and used as a safety component in machinery or high-risk AI systems constituting machinery that ensure a level of protection consistent with Regulation (EU) 2024/1689. To that end, the Commission should be required to adopt delegated acts amending Annex III to Regulation (EU) 2023/1230 in order to reflect the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 . To avoid a legal gap and ensure alignment with the entry into application of the relevant high-risk AI system rules set out in Regulation (EU) 2024/1689, those delegated acts should apply by 2 August 2028. For the same reasons, manufacturers should be free to rely on harmonised standards or common specifications referenced or adopted pursuant to Regulation (EU) 2024/1689 that cover the relevant essential requirements for the presumption of conformity within the meaning of Article 20 of Regulation (EU) 2023/1230 until harmonised standards or common specifications regarding AI are referenced or adopted pursuant to Regulation (EU) 2023/1230.

Text proposed by the Commission

Amendment

(43) Conformity assessments of high-risk AI systems pursuant to Regulation (EU) 2024/1689 can require the involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated pursuant to that Regulation are able to carry out conformity assessments, and only for the activities related to the categories and types of AI systems concerned. To enable the specification of the scope of the designation of conformity assessment bodies notified pursuant to Article 30 of Regulation (EU) 2024/1689, it is necessary to draw up a list of codes, categories, and corresponding types of AI systems. The list of codes should take into account whether the AI system is a component of a product or itself a product covered by the Union harmonisation legislation listed in Annex I to Regulation (EU) 2024/1689 (referred to as ‘AIP codes’, for AI systems covered by product legislation), or a system listed in Annex III to that Regulation, which currently concerns only biometric AI systems referred to in point (1) of Annex III (referred to as ‘AIB codes’, for biometric AI systems). Both AIP codes and AIB codes are vertical codes. The AIP codes are reference codes that provide a link to the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689. The AIB codes are new codes specific to Regulation (EU) 2024/1689 that identify biometric AI systems referred to in point (1) of Annex III to that Regulation. The list of codes should also take into account specific types and underlying technologies of AI systems (referred to as ‘AIH codes’, for horizontal AI system codes). The AIH codes are new AI technology-specific codes and can be applied in conjunction with AIP or AIB vertical codes. The AIH codes cover the underlying types and technologies of AI systems. The list of codes, comprising three categories, should provide for a multi-dimensional typology of AI systems which ensures that conformity assessment bodies designated as notified bodies are fully competent in regard to the AI systems they are required to assess.

(7) In order to ensure consistency, avoid duplication and minimise administrative burdens in relation to the procedure for designating notified bodies under Regulation (EU) 2024/1689, while maintaining the same level of scrutiny, a single application and a single assessment procedure should be available for new conformity assessment bodies and notified bodies which are designated under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, such as under Regulations (EU) 2017/7459 and (EU) 2017/74610 of the European Parliament and of the Council, where such a procedure is established under that Union harmonisation legislation. The single application and assessment procedure aims at facilitating, supporting and expediting the designation procedure under Regulation (EU) 2024/1689, while ensuring compliance with the requirements applicable to notified bodies under that Regulation and the Union harmonisation legislation listed in Section A of Annex I thereto.

(44) Regulation (EU) 2018/1139 of the European Parliament and the Council lays down common rules in the field of civil aviation. Article 108 of Regulation (EU) 2024/1689 amends Regulation (EU) 2018/1139 to ensure that the Commission, when adopting any relevant delegated or implementing acts pursuant to Regulation (EU) 2018/1139, takes into account, on the basis of the technical and regulatory specificities of the civil aviation sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689. A technical correction to amend additional Articles of Regulation (EU) 2018/1139 is necessary to ensure that the mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 are fully covered when adopting relevant delegated or implementing acts pursuant to Regulation (EU) 2018/1139.

deleted

__________________

(45) In order to amend certain non-essential elements of Regulations (EU) 2024/1689 and (EU) 2023/1230, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of:

9 Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1, ELI: http://data.europa.eu/eli/reg/2017/745/oj).

- limiting the application of specific requirements or obligations laid down in Regulation (EU) 2024/1689 where Union harmonisation legislation listed in Section A of Annex I of that Regulation lays down requirements providing for an equivalent level of protection,

10 Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176, ELI: http://data.europa.eu/eli/reg/2017/746/oj).

- amending the list of codes, categories, and corresponding types of AI systems in Annex XIV of Regulation (EU) 2024/1689, and

Amendment 8

- amending Annex III of Regulation (EU) 2023/1230 to reflect the relevant requirements of Regulation (EU) 2024/1689.

Proposal for a regulation

It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

Recital 8

(46) In order to ensure legal certainty without delay, with a view to the imminent general application of Regulation (EU) 2024/1689, this Regulation should enter into force as a matter of urgency on the third day following that of its publication in the Official Journal of the European Union.

Text proposed by the Commission

(47) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 20 January 2026,

Amendment

HAVE ADOPTED THIS REGULATION:

(8) With a view to ensuring the smooth application and consistency of Regulation (EU) 2024/1689, amendments should be made to it. A technical correction to Article 43(3), first subparagraph, of Regulation (EU) 2024/1689 should be added to align the conformity assessment requirements with the requirements of providers of high-risk AI systems in Article 16 of that Regulation. Moreover, it should be clarified that where a provider of a high-risk AI system is subject to the conformity assessment procedure under Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, and the conformity assessment extends to compliance of the quality management system of that Regulation and of such Union harmonisation legislation, the provider should be able to include aspects related to quality management systems under that Regulation as part of the quality management systems under such Union harmonisation legislation, in line with Article 17(3) of Regulation (EU) 2024/1689. Article 43(3), second subparagraph, should be amended to clarify that notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and which aim to assess high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I to that Regulation, should apply for the designation as a notified body under that Regulation within 18 months from [the entry into application of this Regulation]. This amendment is without prejudice to Article 28 of Regulation (EU) 2024/1689. Moreover, Regulation (EU) 2024/1689 should be amended to clarify that where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and falls within one of the use-cases listed in Annex III to that Regulation, the provider should follow the relevant conformity assessment procedure as required under that relevant harmonisation legislation.

Article 1 Amendments to Regulation (EU) 2024/1689

(8) deleted

Regulation (EU) 2024/1689 is amended as follows:

Amendment 9

(1) in Article 1(2), point (g) is replaced by the following:

Proposal for a regulation

’(g) measures to support innovation, with a particular focus on small mid-cap enterprises (SMCs) and small and medium-sized enterprises (SMEs), including start-ups.’;

Recital 8 a (new)

(2) ▌ Article 2 is amended as follows:

Text proposed by the Commission

(a) paragraph 2 is replaced by the following:

Amendment

‘2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a and Articles 102 to ▌ 112 shall apply. Articles 57, 58 and 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.’;

(8a) Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847 complement each other so that the safety and cybersecurity of products with digital elements is ensured. It is necessary to ensure the alignment of Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847, to allow for their smooth implementation. Where high-risk AI systems fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847.

(b) paragraph 7 is replaced by the following:

Amendment 10

‘7. Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680.’;

Proposal for a regulation

(3) in Article 2, the following paragraph is added:

Recital 8 b (new)

‘13. For high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9 to 15 and 17 to 25 may be limited, where and to the extent that:

Text proposed by the Commission

(a) Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing an equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned; and

Amendment

(b) such limitation does not reduce the overall level of protection provided for by this Regulation.

(8b) For the purposes of this Regulation, the fact that an AI system is integrated into, or operates within, a product subject to Union harmonisation legislation on product safety should not, in itself, imply that the AI system performs a safety function. An AI system should be regarded as performing a safety function only where its functioning is necessary to ensure that the product or the AI system complies with applicable Union safety requirements. By contrast, functionalities intended solely for user assistance, performance optimisation, service efficiency, automation, convenience, or quality control of non-safety-related aspects should not be regarded as safety functions under this Regulation, where their failure would not directly create risks to health or safety.

By 2 August 2027, the Commission shall adopt delegated acts in accordance with Article 97 in order to supplement this Regulation by specifying the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.’;

Amendment 11

(4) Article 3 is amended as follows:

Proposal for a regulation

(a) point (14) is amended as follows:

Recital 9

‘(14) ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property;’;

Text proposed by the Commission

(b) the following points are inserted:

Amendment

‘(14a) ‘micro, small and medium-sized enterprise’ or ‘SME’ means a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Recommendation 2003/361/EC;

(9) To streamline compliance and reduce the associated costs, providers of AI systems should not be required to register AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation. Given that such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons, imposing registration requirements would constitute a disproportionate compliance burden. Nevertheless, a provider who considers that an AI system falls under Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

(14b) ‘small mid-cap enterprise’ or ‘SMC’ means a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099;▌’;

(9) To streamline compliance and reduce the associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the required content in Section B of Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate. This simplification will strike a better balance without undermining the protection laid down by Regulation 2024/1689. Such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons. Furthermore, a provider applying Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

(5) Article 4 is replaced by the following:

Amendment 12

Proposal for a regulation

Recital 10

Text proposed by the Commission

Amendment

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. When discussions are held within the framework of the Board, the European Data Protection Supervisor and the AI Office, as part of their roles within the board, should provide feedback and exchange best practices on matters related to the establishment and operation of AI regulatory sandboxes that were established under their respective competences. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be streamlined and resources optimally utilised. In order to foster innovation and facilitate the uptake of AI, SMEs, including startups, and SMCs should be provided with priority access to the AI regulatory sandboxes established by the AI Office.

Where AI regulatory sandboxes, including the controlled environment to foster innovation, involve innovative AI systems that process personal data, the relevant national supervisory authorities should be involved in accordance with their tasks and powers.

Amendment 13

Proposal for a regulation

Recital 11

Text proposed by the Commission

Amendment

(11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation. To address the specific situation of high-risk AI systems covered the Union harmonisation legislation listed in Section B of Annex I to that Regulation, it is necessary to allow the conclusion of voluntary agreements between the Commission and Member States to enable testing of such high-risk AI systems in real-world conditions.

(11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation. To address the specific situation of high-risk AI systems covered the Union harmonisation legislation listed in Section B of Annex I to that Regulation, it is necessary to allow the conclusion of voluntary agreements between the Commission and Member States to enable testing of such high-risk AI systems in real-world conditions, subject to sufficient safeguards.

Amendment 14

Proposal for a regulation

Recital 12 a (new)

Text proposed by the Commission

Amendment

(12a) In order to allow the AI Office to effectively exercise its duties under Regulation (EU) 2024/1689 and in light of the new powers conferred on it by this Regulation, adequate human, financial and technical resources should be provided, without prejudice to the budgetary procedure and existing financial instruments. In particular, the AI Office should have a sufficient number of personnel whose expertise include an in-depth understanding of AI technologies.

Amendment 15

Proposal for a regulation

Recital 13

Text proposed by the Commission

Amendment

(13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances. Furthermore, to reduce the procedural complexity, Member States should be able to consult the experts of the scientific panel directly, without involvement of the Commission.

(13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances.

Amendment 16

Proposal for a regulation

Recital 14

Text proposed by the Commission

Amendment

(14) In order to strengthen the governance system for AI systems based on general-purpose AI models, it is necessary to clarify the role of the AI Office in monitoring and supervising compliance of such AI systems with Regulation (EU) 2024/1689, while excluding AI systems related to products covered by the Union harmonisation legislation listed in Annex I to that Regulation. While sectoral authorities continue to remain responsible for the supervision of AI systems related to products covered by that Union harmonisation legislation, Article 75(1) Regulation (EU) 2024/1689 should be modified to bring all AI systems based on general-purpose AI models developed by the same provider within the scope of the AI Office's supervision. This does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689. To ensure effective supervision for those AI systems in accordance with the tasks and responsibilities assigned to market surveillance authorities under Regulation (EU) 2024/1689, the AI Office should be empowered to take the appropriate measures and decisions to adequately exercise its powers provided for in that Section and Regulation (EU) 2019/1020 of the European Parliament and of the Council11 . Article 14 of Regulation (EU) 2019/1020 should apply mutatis mutandis. Furthermore, to ensure effective enforcement, the authorities involved in the application of Regulation (EU) 2024/1689 should cooperate actively in the exercise of those powers, in particular where enforcement actions need to be taken in the territory of a Member State.

(14) In order to strengthen the governance system for AI systems based on general-purpose AI models, it is necessary to clarify the role of the AI Office in monitoring and supervising compliance of such AI systems with Regulation (EU) 2024/1689, while excluding AI systems related to products covered by the Union harmonisation legislation listed in Annex I and AI systems referred to in Annex III, point 2 to that Regulation. While sectoral authorities continue to remain responsible for the supervision of AI systems related to products covered by that Union harmonisation legislation, Article 75(1) Regulation (EU) 2024/1689 should be modified to bring all AI systems based on general-purpose AI models developed by the same provider within the scope of the AI Office's supervision. This does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689. To ensure effective supervision for those AI systems in accordance with the tasks and responsibilities assigned to market surveillance authorities under Regulation (EU) 2024/1689, the AI Office should take the appropriate measures and decisions to adequately exercise its powers provided for in that Section and Regulation (EU) 2019/1020 of the European Parliament and of the Council11. Article 14 of Regulation (EU) 2019/1020 should apply mutatis mutandis. Furthermore, to ensure effective enforcement, the authorities involved in the application of Regulation (EU) 2024/1689 should cooperate actively in the exercise of those powers, in particular where enforcement actions need to be taken in the territory of a Member State.

__________________

__________________

11 Regulation (EU) 2019/1020 of the European Parliament and of the Council of 20 June 2019 on market surveillance and compliance of products and amending Directive 2004/42/EC and Regulations (EC) No 765/2008 and (EU) No 305/2011 (OJ L 169, 25.6.2019, p. 1, ELI: http://data.europa.eu/eli/reg/2019/1020/oj).

11 Regulation (EU) 2019/1020 of the European Parliament and of the Council of 20 June 2019 on market surveillance and compliance of products and amending Directive 2004/42/EC and Regulations (EC) No 765/2008 and (EU) No 305/2011 (OJ L 169, 25.6.2019, p. 1, ELI: http://data.europa.eu/eli/reg/2019/1020/oj).

Amendment 17

Proposal for a regulation

Recital 16

Text proposed by the Commission

Amendment

(16) To further operationalise the AI Office’s supervision and enforcement set out in Article 75(1) of Regulation (EU) 2024/1689, it is necessary to further define the which of the powers listed in Article 14 of Regulation (EU) 2019/1020 should be conferred upon the AI Office. The Commission should therefore be empowered to adopt implementing acts to specify those powers, including the ability to impose penalties, such as fines or other administrative sanctions, in accordance with the conditions and ceilings referred to in Article 99, and applicable procedures. This should ensure that the AI Office has the necessary tools to effectively monitor and supervise compliance with Regulation (EU) 2024/1689.

(16) To further operationalise the AI Office’s supervision and enforcement set out in Article 75(1) of Regulation (EU) 2024/1689, it is necessary to further define which of the powers listed in Article 14 of Regulation (EU) 2019/1020 should be conferred upon the AI Office. The Commission should therefore be empowered to adopt implementing acts to specify those powers, including the ability to impose penalties, such as fines or other administrative sanctions, in accordance with the conditions and ceilings referred to in Article 99, and applicable procedures. This should ensure that the AI Office has the necessary tools to effectively monitor and supervise compliance with Regulation (EU) 2024/1689.

Amendment 18

Proposal for a regulation

Recital 18

Text proposed by the Commission

Amendment

(18) To enable access to Union market for AI systems which are under the supervision by the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to third party conformity assessment, the Commission should be enabled to carry out pre-market conformity assessments of those systems.

(18) To enable access to Union market for AI systems which are under the supervision by the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to third party conformity assessment, the Commission should ensure that pre-market conformity assessments are carried out for those systems. Furthermore, the AI Office should maintain organised records of communications with providers and deployers of general-purpose AI models with systemic risk. Such records should be documented in a consistent manner.

Amendment 19

Proposal for a regulation

Recital 19

Text proposed by the Commission

Amendment

(19) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing the cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests, and that the involved authorities or bodies should have a mutual obligation to cooperate.

(19) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing the cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests without undue delay, and that the involved authorities or bodies should have a mutual obligation to cooperate. It should be clarified that these provisions are without prejudice to the tasks, powers and independence of the relevant national public authorities or bodies under their mandates. In particular, those provisions do not limit any powers that those authorities and bodies have to request information pursuant to other Union or national law. Accordingly, those authorities and bodies retain any power they have to directly request information from operators pursuant to their mandate or other law.

Amendment 20

Proposal for a regulation

Recital 20

Text proposed by the Commission

Amendment

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 6 months for providers who have already placed their systems on the market before the 2 August 2026.

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 3 months for providers who have already placed their systems on the market before the 2 August 2026.

Amendment 21

Proposal for a regulation

Recital 22

Text proposed by the Commission

Amendment

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. Building on experience, it is appropriate to put in place a mechanism that links the entry into application to the availability of measures in support of compliance with Chapter III, which may include harmonised standards, common specifications, and Commission guidelines. This should be confirmed by the Commission by decision, following which the rules obligations for high-risk AI systems should apply after 6 months as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and after 12 months as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to Regulation (EU) 2024/1689. However, this flexibility should only be extended until 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and until 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to that Regulation, by which dates those rules should enter into application in any case. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations.

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. It is appropriate that the date of application of obligations on AI systems classified as high-risk pursuant to Article 6(2) and Annex III and on AI systems classified as high-risk pursuant to Article 6(1) and Annex I to Regulation (EU) 2024/1689 is postponed until 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and until 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to that Regulation. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations.

Amendment 22

Proposal for a regulation

Recital 22 a (new)

Text proposed by the Commission

Amendment

(22a) In order to ensure legal certainty and to avoid further delays in application of this Regulation, the Commission should ensure that measures in support of compliance with regard to Chapter III, Sections 1, 2, and 3 are in place in due time to ensure timely and effective implementation of the necessary provisions.

Amendment 23

Proposal for a regulation

Recital 23

Text proposed by the Commission

Amendment

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply with their monitoring obligations, the Commission should be required to publish guidance on the post-market monitoring plan, including a template with elements to be included therein, by 2 February 2027.

Amendment 24

Proposal for a regulation

Recital 23 a (new)

Text proposed by the Commission

Amendment

(23a) The parallel application of sectoral Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 of the European Parliament and of the Council and the requirements set out in that Regulation for high-risk artificial intelligence systems may lead to overlaps of requirements and unnecessary administrative burden for economic operators. Such overlaps could create legal uncertainty, increase compliance costs and potentially lead to competitive disadvantages, without providing additional benefits for the protection of health, safety or fundamental rights. In order to ensure a more coherent and proportionate regulatory framework and to simplify the application of requirements for artificial intelligence systems embedded in products regulated under Union harmonisation legislation, the references to the Union harmonisation legislation currently listed in Section A of Annex I to Regulation (EU) 2024/1689 should therefore be moved to Section B of that Annex. This approach clarifies that artificial intelligence systems integrated into products covered by those sectoral acts are subject to the requirements of this Regulation where relevant, while allowing the conformity assessment procedures and product safety requirements under the respective sectoral legislation to remain the primary framework. Any remaining gaps relating to artificial intelligence systems integrated into such products should be addressed within the relevant sectoral legislation.

Amendment 25

Proposal for a regulation

Recital 23 b (new)

Text proposed by the Commission

Amendment

(23b) In order to safeguard the horizontal nature of this Regulation and ensure the proper functioning of the internal market, the relevant requirements laid down in Chapter III, Section 2 of this Regulation should be deemed to constitute essential health and safety requirements for high-risk AI systems covered by Union harmonisation legislation listed in Annex I and should be applied in a consistent and coherent manner across those sectoral frameworks. For this purpose, the Commission should be entitled to adopt delegated acts taking into account the requirements set out in Chapter III, Section 2 of this Regulation as regards their application to AI systems falling within its scope as well as relevant harmonised standards. In doing so, the Commission should not go beyond the requirements laid down in Regulation (EU) 2024/1689 for this purpose and should take into account the specific context of sectorial legislation. Before adopting the acts referred to in the first subparagraph, the Commission should conduct open and transparent consultations with relevant stakeholders, including competent authorities, notified bodies, civil society and industry.

Amendment 26

Proposal for a regulation

Recital 25 a (new)

Text proposed by the Commission

Amendment

(25a) When implementing and enforcing this Regulation, national competent authorities, the AI office and the Commission should take into account the objectives set out in Article 1(1) of Regulation (EU) 2024/1689 and follow the principles of necessity, proportionality, legal certainty and technological neutrality, while at the same time ensuring that unnecessary administrative and compliance burdens are minimised.

Amendment 27

Proposal for a regulation

Article 1 – paragraph 1 – point 2

Regulation (EU) 2024/1689

Article 2 – paragraph 2

Text proposed by the Commission

Amendment

2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a, Articles 102 to 109 and Articles 111 and 112 shall apply. Article 57 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.;

2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Annex I, only Article 6(1), Article 60a, Articles 102 to 109, Articles 110a-110l and Articles 111 and 112 shall apply. Article 57 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.;

Amendment 28

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4 – paragraph 1

Text proposed by the Commission

Amendment

‘The Commission and Member States shall encourage providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.;

1. ‘Providers and deployers of AI systems shall take measures to support the improvement of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not cover any guarantee of a specific level of AI literacy of any individual.;

Amendment 29

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4 – paragraph 1a (new)

Text proposed by the Commission

Amendment

(1a) The Commission shall issue guidance on the practical implementation of the obligation on providers and deployers of AI systems under paragraph 1.

Amendment 30

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4 – paragraph 1b (new)

Text proposed by the Commission

Amendment

(1b) The Commission and the Member States shall encourage and support AI literacy in society and among the general population and support, facilitate and complement the efforts of providers and deployers of AI systems, in particular SMEs, for example via the creation of Public Private Partnerships in fulfilling their obligation under paragraph 1.;

Amendment 31

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4 a (new) – paragraph 1

Text proposed by the Commission

Amendment

1. To the extent necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Amendment 32

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4 a (new) – paragraph 2

Text proposed by the Commission

Amendment

2. Paragraph 1 may apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where necessary and proportionate if the processing occurs for the purposes set out therein and provided that the conditions set out under the safeguards set out in this paragraph.;

2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:

(a) processing is necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations; and

(b) all of the conditions and safeguards set out in paragraph 1 are applied.

This paragraph does not create any obligation to conduct such bias detection and correction.’

Amendment 33

Proposal for a regulation

Article 1 – paragraph 1 – point 5 a (new)

Regulation (EU) 2024/1689

Article 5 – paragraph 1 – subparagraph 1 – point ha (new)

Text proposed by the Commission

Amendment

(5a) in Article 5, paragraph 1, subparagraph 1 the following point is added:

(ha) the placing on the market, the putting into service or the use of an AI system that alters, manipulates or artificially generates realistic images or videos so as to depict sexually explicit activities or the intimate parts of an identifiable natural person, without that person’s consent.

This prohibition does not apply to providers or deployers of AI systems who have put in place effective safety measures to prevent the generation of such depictions and to avoid misuse continuously, after the system has been placed, on the market or put into service despite the intention of the provider or deployer.

This prohibition shall not prevent AI providers from developing any capabilities referred to in the first subparagraph.

Amendment 34

Proposal for a regulation

Article 1 – paragraph 1 – point 5 b (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 1

Present text

Amendment

(5b) Article 6(1) is amended as follows:

1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

"1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(a) the AI system is intended to be used as a safety component of a product and whose functioning is necessary to ensure that the product or AI system complies with applicable Union safety requirements, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

"

(Regulation (EU) 2024/1689)

Amendment 35

Proposal for a regulation

Article 1 – paragraph 1 – point 5 c (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(5c) In Article 6, paragraph 1a is added:

‘1a. For the purposes of this Regulation, functionalities intended solely for user assistance, performance optimisation, service efficiency, automation, convenience, or quality control of non-safety-related aspects shall not be regarded as safety functions under this Regulation, where their failure would not directly create risks to health or safety.’

Amendment 36

Proposal for a regulation

Article 1 – paragraph 1 – point 6

Regulation (EU) 2024/1689

Article 6 – paragraph 4

Text proposed by the Commission

Amendment

(6) in Article 6, paragraph 4 is replaced by the following:

deleted

4. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Upon request of national competent authorities, the provider shall provide the documentation of the assessment.;

Amendment 37

Proposal for a regulation

Article 1 – paragraph 1 – point 9 a (new)

Regulation (EU) 2024/1689

Article 25 – paragraph 2

Present text

Amendment

(9a) Article 25(2) is replaced by the following:

2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.

"2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation.

That initial provider, as well as providers of general-purpose AI models whose models are integrated into high-risk AI systems, shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems.

This obligation shall include:

(a) the provision of technical documentation sufficient to assess compliance with Article 16 requirements;

(b) the disclosure of known limitations and failure modes that could affect high-risk applications;

(c) the provision of reasonable technical access for testing and validation purposes.

This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.’

"

(Regulation (EU) 2024/1689)

Amendment 38

Proposal for a regulation

Article 1 – paragraph 1 – point 9 b (new)

Regulation (EU) 2024/1689

Article 27 – paragraph 4

Present text

Amendment

(9b) in Article 27, paragraph 4 is replaced by the following:

4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment. to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.

"4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer shall, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article include cross references to the relevant sections of that data protection impact assessment or include relevant parts of that data protection impact assessment into the fundamental rights impact assessment.

"

(Regulation 2024/1689)

Amendment 39

Proposal for a regulation

Article 1 – paragraph 1 – point 10

Regulation (EU) 2024/1689

Article 28 – paragraph 8 (new)

Text proposed by the Commission

Amendment

(10) in Article 28, the following paragraph 8 is added:

Notifying authorities designated under this Regulation responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall be established, organised and operated in such a way that ensures that the conformity assessment body that applies for designation both under this Regulation and the Union harmonisation legislation listed in Section A of Annex I shall be provided with the possibility to submit a single application and undergo a single assessment procedure to be designated under this Regulation and Union harmonisation legislation listed in Section A of Annex I, where the relevant Union harmonisation legislation provides for such single application and single assessment procedure.

deleted

Amendment 40

Proposal for a regulation

Article 1 – paragraph 1 – point 10

Regulation (EU) 2024/1689

Article 28 – paragraph 8 (new) – subparagraph 1

Text proposed by the Commission

Amendment

The single application and single assessment procedure referred to in this paragraph shall also be made available to notified bodies already designated under the Union harmonisation legislation listed in Section A of Annex I, when those notified bodies apply for designation under this Regulation, provided that the relevant Union harmonisation legislation provides for such a procedure.

deleted

Amendment 41

Proposal for a regulation

Article 1 – paragraph 1 – point 10

Regulation (EU) 2024/1689

Article 28 – paragraph 8 (new) – subparagraph 2

Text proposed by the Commission

Amendment

The single application and single assessment procedure shall avoid any unnecessary duplications, build on the existing procedures for designation under the Union harmonisation legislation listed in Section A of Annex I and ensure compliance with the requirements both relating to notified bodies under this Regulation and the relevant Union harmonisation legislation.;

deleted

Amendment 42

Proposal for a regulation

Article 1 – paragraph 1 – point 11

Regulation (EU) 2024/1689

Article 29 – paragraph 4 – second subparagraph

Text proposed by the Commission

Amendment

Notified bodies, which are designated under any of the Union harmonisation legislation listed in Section A of Annex I and which apply for the single assessment referred to in Article 28(8), shall submit the single application for assessment to the notifying authority designated in accordance with that Union harmonisation legislation.

deleted

Amendment 43

Proposal for a regulation

Article 1 – paragraph 1 – point 12 a (new)

Regulation (EU) 2024/1689

Article 42 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(12a) In Article 42, the following paragraph is inserted:

'2a. Where an AI system is subject to the requirements of Regulation (EU) 2024/2847 as well as requirements set out in Article 15, and where those high-risk AI systems fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they shall be presumed to comply with the cybersecurity requirements set out in Article 15 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847.';

Amendment 44

Proposal for a regulation

Article 1 – paragraph 1 – point 13

Regulation (EU) 2024/1689

Article 43 – paragraph 3

Text proposed by the Commission

Amendment

(13) in Article 43, paragraph 3 is replaced by the following:

deleted

For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 and Annex VII shall also apply.

For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in Section 2, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under the relevant Union harmonisation legislation. Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 at the latest [18 months from the entry into application of this Regulation].

Where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to opt out from a third-party conformity assessment, provided that that manufacturer has applied harmonised standards covering all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter.

Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation listed in Section A of Annex I.;

Amendment 45

Proposal for a regulation

Article 1 – paragraph 1 – point 13

Regulation (EU) 2024/1689

Article 43 – paragraph 4 – subparagraph 3

Text proposed by the Commission

Amendment

Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation listed in Section A of Annex I.;

deleted

Amendment 46

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2024/1689

Article 49 – paragraph 2

Text proposed by the Commission

Amendment

(14) in Article 49, paragraph 2 is deleted;

deleted

Amendment 47

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2024/1689

Article 50 – paragraph 7

Text proposed by the Commission

Amendment

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).;

7. The Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).;

Amendment 48

Proposal for a regulation

Article 1 – paragraph 1 – point 16

Regulation (EU) 2024/1689

Article 56 – paragraph 6

Text proposed by the Commission

Amendment

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board and other relevant competent authorities, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;

Amendment 49

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point a

Regulation (EU) 2024/1689

Article 57 – paragraph 3 a (new)

Text proposed by the Commission

Amendment

The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.;

(3a) The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including startups.;

The AI Office shall ensure that, to the extent innovative AI systems referred to in paragraph 5 involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the national data protection authorities, the EDPB and those other national or competent authorities are associated with the operation of the AI regulatory sandbox established at Union level and involved in the supervision of those aspects to the extent that they relate to their respective tasks and powers, in accordance with Regulation (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU)2018/680.;

Amendment 50

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point b

Regulation (EU) 2024/1689

Article 57 – paragraph 5

Text proposed by the Commission

Amendment

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;

Amendment 51

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e

Regulation (EU) 2024/1689

Article 57 – paragraph 14

Text proposed by the Commission

Amendment

14. National competent authorities shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.;

14. National competent authorities shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.;

When discussions are held within the framework of the Board, the European Data Protection Supervisor and the AI office shall, as part of their roles within the Board, also provide their feedback and exchange best practices on matters related to the establishment and operation of AI regulatory sandboxes established under their respective competences.;

Amendment 52

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU) 2024/1689

Article 58 – paragraph 1 – point d (new)

Text proposed by the Commission

Amendment

(d) the detailed rules applicable to the governance of AI regulatory sandboxes covered under Article 57, including as regards the exercise of the tasks of the competent authorities and the coordination and cooperation at national and EU level.;

(d) the detailed rules applicable to the governance of AI regulatory sandboxes covered under Article 57, including as regards the exercise of the tasks of the competent authorities, the involvement and supervision by the competent data protection authorities and the coordination and cooperation at national and EU level.;

Amendment 53

Proposal for a regulation

Article 1 – paragraph 1 – point 19 – point a

Regulation (EU) 2024/1689

Article 60 – paragraph 1

Text proposed by the Commission

Amendment

Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.;

1. Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.;

Amendment 54

Proposal for a regulation

Article 1 – paragraph 1 – point 19 – point b

Regulation (EU) 2024/1689

Article 60 – paragraph 2

Text proposed by the Commission

Amendment

2. Providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the AI system on their own or in partnership with one or more deployers or prospective deployers.;

2. Providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III in real world conditions at any time before the placing on the market or the putting into service of the AI system on their own or in partnership with one or more deployers or prospective deployers.;

Amendment 55

Proposal for a regulation

Article 1 – paragraph 1 – point 20

Regulation (EU) 2024/1689

Article 60 a (new) – paragraph 3

Text proposed by the Commission

Amendment

3. Member States, the Commission, market surveillance authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I shall cooperate closely with each other and in good faith, and shall remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement the voluntary real-world testing agreement and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex.

3. Member States, the Commission, and national competent authorities such as market surveillance authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I shall cooperate closely with each other and in good faith, and shall remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement the voluntary real-world testing agreement and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex.

Amendment 56

Proposal for a regulation

Article 1 – paragraph 1 – point 21

Regulation (EU) 2024/1689

Article 63 – paragraph 1

Text proposed by the Commission

Amendment

1. SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.;

1. SMEs, including start-ups, and micro enterprises may comply with certain elements of the quality management system required by Article 17 in a simplified manner. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs and micro enterprises, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.;

Amendment 57

Proposal for a regulation

Article 1 – paragraph 1 – point 21 a (new)

Regulation (EU) 2024/1689

Article 64 – paragraph 2a (new)

Text proposed by the Commission

Amendment

(21a) In Article 64, paragraph 2a is added:

‘(2a) Without prejudice to the budgetary procedure and through existing financial instruments, the AI Office shall be allocated with adequate human, financial and technical resources, and with infrastructure to fulfil their tasks, to effectively perform its duties and exercise its powers in respect of the enforcement of Regulation (EU) 2024/1689. In particular, the AI Office shall have a sufficient number of personnel permanently available with in-depth competences and technical expertise. The AI Board shall assess competence and resource requirements.’

Amendment 58

Proposal for a regulation

Article 1 – paragraph 1 – point 22 – point b

Regulation (EU) 2024/1689

Article 69 – paragraph 3

Text proposed by the Commission

Amendment

(b) paragraph 3 is deleted.

deleted

Amendment 59

Proposal for a regulation

Article 1 – paragraph 1 – point 24

Regulation (EU) 2024/1689

Article 72 – paragraph 3

Text proposed by the Commission

Amendment

3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt guidance on the post-market monitoring plan.;

3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt guidance on the post-market monitoring plan, including a template with elements to be included by 2 February 2027.;

Amendment 60

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point b

Regulation (EU) 2024/1689

Article 75 – paragraph 1

Text proposed by the Commission

Amendment

Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I, and that model and that system are developed by the same provider, the AI Office shall be exclusively competent for the supervision and enforcement of that system with the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to AI system that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.

1. Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I and AI systems referred to in Annex III, point 2, and that model and that system are developed by the same provider or by providers belonging to the same group of undertakings, the AI Office shall have powers to supervise and enforce the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also have powers to supervise and enforce the obligations under this Regulation in relation to AI systems that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065. Where the Commission has not initiated proceedings for the same infringement, the competent authority of a Member State in which the main establishment of the provider of very large online platform or of very large online search engine is located, or where their legal representative is established, may have the powers to supervise and enforce the obligations under this Regulation.

Notwithstanding the first subparagraph, the supervision and enforcement powers of the AI Office, do not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of this Regulation.

Amendment 61

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point b

Regulation (EU) 2024/1689

Article 75 – paragraph 1 – subparagraph 2

Text proposed by the Commission

Amendment

When exercising its tasks of supervision and enforcement under the first subparagraph, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Regulation (EU) 2019/1020. The AI Office shall be empowered to take appropriate measures and decisions to adequately exercise its supervisory and enforcement powers. Article 14 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

When exercising its tasks of supervision and enforcement under the first subparagraph, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Regulation (EU) 2019/1020. The AI Office shall take appropriate measures and decisions to adequately exercise its supervisory and enforcement powers. Article 14 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

Amendment 62

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point b a (new)

Regulation (EU) 2024/1689

Article 75 – paragraph –1a (new)

Text proposed by the Commission

Amendment

(ba) in Article 75, paragraph -1a is inserted:

‘-1a. In the implementation and enforcement of this Regulation, the AI Office shall promote innovation, competitiveness and the protection of fundamental rights, taking them into consideration in the exercise of their functions. The AI Office shall coordinate closely with the competent data protection authorities designated pursuant to Regulation (EU) 2016/1679 in matters involving the processing of personal data falling within the scope of that Regulation.’

Amendment 63

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point c

Regulation (EU) 2024/1689

Article 75 – paragraph – 1c

Text proposed by the Commission

Amendment

The Commission shall organise and carry out pre-market conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to third-party conformity assessment under Article 43 before such AI systems are placed on the market or put into service. These tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission may entrust the performance of these tests or assessments to notified bodies designated under this Regulation, in which case the notified body shall act on behalf of the Commission. Article 34(1) and (2) shall apply mutatis mutandis to the Commission when exercising its powers under this paragraph.

1c. The Commission shall, subject to Article 28(8), ensure that pre-market conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to third-party conformity assessment under Article 43 are carried out before such AI systems are placed on the market or put into service. These tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission shall entrust the performance of these tests or assessments to notified bodies designated under this Regulation, in which case the notified body shall act on behalf of the Commission. Article 34(1) and (2) shall apply mutatis mutandis to the Commission when exercising its powers under this paragraph.

Amendment 64

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point b

Regulation (EU) 2024/1689

Article 77 – paragraph 1 – point b

Text proposed by the Commission

Amendment

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and format where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction.;

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and machine-readable format by electronic means where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. This paragraph is without prejudice to the tasks, powers and independence of the relevant national public authorities or bodies under their mandates in accordance with Union and national law;

Amendment 65

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point c – introductory part

Regulation (EU) 2024/1689

Article 77 – paragraph 1a (new)

Text proposed by the Commission

Amendment

(c) the following paragraph 1a and 1b are inserted:

(c) the following paragraph 1a, 1b and 1ba are inserted:

Amendment 66

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point c

Regulation (EU) 2024/1689

Article 77 – paragraph 1a (new)

Text proposed by the Commission

Amendment

1a. Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary.

1a. Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary and without undue delay.

Amendment 67

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point c

Regulation (EU) 2024/1689

Article 77 – paragraph 1b (new)

Text proposed by the Commission

Amendment

1b. Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall cooperate closely and provide each other with mutual assistance necessary for fulfilling their respective mandates, with a view to ensuring coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures. This shall include, in particular, exchange of information where necessary for the effective supervision or enforcement of this Regulation and the respective other Union legislation.;

1b. Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall cooperate closely and provide each other with mutual assistance necessary for fulfilling their respective mandates, with a view to ensuring coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures while respecting their respective competences, tasks, powers and independence. This shall include, in particular, exchange of information where necessary for the effective supervision or enforcement of this Regulation and the respective other Union legislation.;

Amendment 68

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point c

Regulation (EU) 2024/1689

Article 77 – paragraph 1b a (new)

Text proposed by the Commission

Amendment

1ba. Requests for assistance shall contain all the necessary information, including the purpose of and reasons for the request.

Amendment 69

Proposal for a regulation

Article 1 – paragraph 1 – point 28 – introductory part

Regulation (EU) 2024/1689

Article 96 – paragraph 1

Text proposed by the Commission

Amendment

(28) in Article 96(1), the second subparagraph is replaced by the following:

(28) in Article 96(1), point (a) and the second subparagraph are replaced by the following:

Amendment 70

Proposal for a regulation

Article 1 – paragraph 1 – point 28

Regulation (EU) 2024/1689

Article 96 – paragraph 1 – point a

Text proposed by the Commission

Amendment

(a) the application of the requirements and obligations referred to in Articles 8 to 15 and in Article 25;

-1. (a) the application of the requirements and obligations referred to in Articles 8 to 15 and in Articles 25 and 26;

Amendment 71

Proposal for a regulation

Article 1 – paragraph 1 – point 28

Regulation (EU) 2024/1689

Article 96 – paragraph 1 – subparagraph 1

Text proposed by the Commission

Amendment

-1a. in Article 96, paragraph 1, subparagraph 1, the following point is inserted:

‘(fa) the application of the obligations referred to in Article 27, including the possibility to reference or include relevant sections or parts of the data protection impact assessment into the fundamental rights impact assessment pursuant to Article 27(4) of this Regulation, using, where relevant, standardised templates. ’

Amendment 72

Proposal for a regulation

Article 1 – paragraph 1 – point 29 – point a a (new)

Regulation (EU) 2024/1689

Article 99 – paragraph 4 – point da (new)

Text proposed by the Commission

Amendment

(aa) in paragraph 4 the following point (da) is inserted:

‘(da) obligations of providers and third parties, including providers of general purpose AI models, pursuant to Article 25(2), (3) and (4); ’

Amendment 73

Proposal for a regulation

Article 1 – paragraph 1 – point 29 – point b

Regulation (EU) 2024/1689

Article 99 – paragraph 6

Text proposed by the Commission

Amendment

6. In the case of SMCs and SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.;

6. In the case of and SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.;

Amendment 74

Proposal for a regulation

Article 1 – paragraph 1 – point 29 – point b

Regulation (EU) 2024/1689

Article 99 – paragraph 6 a (new)

Text proposed by the Commission

Amendment

6a. In Article 99, paragraph 6a is inserted:

‘In the case of SMCs, with the exception of providers of general-purpose AI models with systemic risk, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 4 and 5, whichever is lower.’

Amendment 75

Proposal for a regulation

Article 1 – paragraph 1 – point 29 a (new)

Regulation (EU) 2024/1689

Article 110 a (new)

Text proposed by the Commission

Amendment

(29a) The following articles: Article 110a – Article 110l are inserted:

Article 110a

Amendment to Regulation (EU) 2023/1230

In Article 8 of Regulation (EU) 2023/1230, the following paragraphs 2 and 3 are added:

‘2. The Commission is empowered to adopt delegated acts in accordance with Article 48 to amend the essential health and safety requirements set out in Annex III in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

3. When adopting delegated acts pursuant to paragraph 2 of this Article or Common Specifications pursuant to Article 20 of this Regulation concerning machinery and related products that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110b

Amendment to Regulation (EU) 2025/2509

In Article 5 of Regulation (EU) 2025/2509, the following paragraphs 4 and 5 are added:

‘4. The Commission is empowered to adopt delegated acts in accordance with Article 53 to amend the essential safety requirements set out in Annex II in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

5. When adopting delegated acts pursuant to paragraph 4 of this Article or Common Specifications pursuant to Article 16 of this Regulation concerning toys that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110c

Amendment to Directive 2013/53/EU

In Article 4 of Directive 2013/53/EU, the following paragraphs 3 and 4 are added:

‘3. The Commission is empowered to adopt delegated acts in accordance with Article 50 to amend the essential requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

4. When adopting delegated acts pursuant to paragraph 3 of this Article or Common Specifications pursuant to Article 14a of this Regulation concerning products that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110d

Amendment to Directive 2014/33/EU

In Article 5 of Directive 2014/33/EU, the following paragraphs 3 and 4 are added:

‘3. The Commission is empowered to adopt delegated acts in accordance with Article 42 to amend the essential health and safety requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

4. When adopting delegated acts pursuant to paragraph 3 of this Article or Common Specifications pursuant to Article 14a of this Regulation concerning lifts and safety components for lifts that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110e

Amendment to Directive 2014/34/EU

In Article 4 of Directive 2014/34/EU, the following paragraphs 2 and 3 are added:

‘2. The Commission is empowered to adopt delegated acts in accordance with Article 39 to amend the essential health and safety requirements set out in Annex II in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

3. When adopting delegated acts pursuant to paragraph 2 of this Article or Common Specifications pursuant to Article 12a of this Regulation concerning products that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110f

Amendment to Directive 2014/53/EU

In Article 3 of Directive 2014/53/EU, the following paragraphs 5 and 6 are added:

‘5. The Commission is empowered to adopt delegated acts in accordance with Article 45 to amend the essential requirements in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

6. When adopting delegated acts pursuant to paragraph 5 of this Article or Common Specifications pursuant to Article 16a of this Regulation concerning radio equipment that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110g

Amendment to Directive 2014/68/EU

In Article 4 of Directive 2014/68/EU, the following paragraphs 4 and 5 are added:

‘4. The Commission is empowered to adopt delegated acts in accordance with Article 44 to amend the general safety and performance essential safety requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

5. When adopting delegated acts pursuant to paragraph 4 of this Article or Common Specifications pursuant to Article 12a of this Regulation concerning products that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110h

Amendment to Regulation (EU) 2016/424

In Article 6 of Regulation (EU) 2016/424, the following paragraphs 2 and 3 are added:

‘2. The Commission is empowered to adopt delegated acts in accordance with Article 44 to amend the essential requirements set out in Annex II in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

3. When adopting delegated acts pursuant to paragraph 2 of this Article or Common Specifications pursuant to Article 12a of this Regulation concerning cableway installations, subsystems and safety components that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110i

Amendment to Regulation (EU) 2016/425

In Article 5 of Regulation (EU) 2016/425, the following paragraphs 2 and 3 are added:

‘2. The Commission is empowered to adopt delegated acts in accordance with Article 44 to amend the essential health and safety requirements set out in Annex II in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

3. When adopting delegated acts pursuant to paragraph 2 of this Article or Common Specifications pursuant to Article 14a of this Regulation concerning personal protective equipment that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110j

Amendment to Regulation (EU) 2016/426

In Article 5 of Regulation (EU) 2016/426, the following paragraphs 2 and 3 are added:

‘2. The Commission is empowered to adopt delegated acts in accordance with Article 41 to amend the essential requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

3. When adopting delegated acts pursuant to paragraph 2 of this Article or Common Specifications pursuant to Article 13a of this Regulation concerning appliances or fitting that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110k

Amendment to Regulation (EU) 2017/745

In Article 5 of Regulation (EU) 2017/745, the following paragraphs 7 and 8 are added:

‘7. The Commission is empowered to adopt delegated acts in accordance with Article 115 to amend the general safety and performance requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

8. When adopting implementing acts pursuant to paragraph 6 of this Article, delegated acts pursuant to paragraph 7 of this Article or Common Specifications pursuant to Article 9 of this Regulation concerning devices that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Article 110l

Amendment to Regulation (EU) 2017/746

In Article 5 of Regulation (EU) 2017/746, the following paragraphs 7 and 8 are added:

‘7. The Commission is empowered to adopt delegated acts in accordance with Article 107 to amend the general safety and performance requirements set out in Annex I in order to adapt them to scientific or technical progress or to international developments or to add requirements in relation to emerging risks or technologies. For high-risk AI systems referred to in Article 6(1) of Regulation (EU)2024/1689 the relevant requirements set out in Chapter III, Section 2 of (EU) Regulation 2024/1689 shall be deemed to constitute essential health and safety requirements for the purpose of this Regulation.

8. When adopting implementing acts pursuant to paragraph 6 of this Article, delegated acts pursuant to paragraph 7 of this Article or Common Specifications pursuant to Article 9 of this Regulation concerning devices that are high-risk AI systems as referred to in Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council, or that use high-risk AI systems as safety components, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation as well as relevant harmonised standards. With regard to high-risk AI systems, the Commission shall not go beyond the requirements laid down in Regulation (EU) 2024/1689.’

Amendment 76

Proposal for a regulation

Article 1 – paragraph 1 – point 30 – point b

Regulation (EU) 2024/1689

Article 111 – paragraph 4 (new)

Text proposed by the Commission

Amendment

4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 February 2027.;

4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 November 2026.;

Amendment 77

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 – paragraph 3 – point d (new)

Text proposed by the Commission

Amendment

Chapter III, Sections 1, 2, and 3, shall apply following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available, from the following dates:

Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply;

Amendment 78

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 – paragraph 3 – point d – point i (new)

Text proposed by the Commission

Amendment

(i) 6 months after the adoption of that decision as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

deleted

Amendment 79

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 – paragraph 3 – point d – point ii (new)

Text proposed by the Commission

Amendment

(ii) 12 months after the adoption of the decision as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

deleted

Amendment 80

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 – paragraph 3 – point d – subparagraph 1 – introductory part

Text proposed by the Commission

Amendment

In the absence of the adoption of the decision within the meaning of subparagraph 1, or where the dates below are earlier than those that follow the adoption of that decision, Chapter III, Sections 1, 2, and 3, shall apply:

deleted

Amendment 81

Proposal for a regulation

Article 1 – paragraph 1 – point 31 a (new)

Regulation (EU) 2024/1689

Annex I – Section A

Text proposed by the Commission

Amendment

(31 a) In Annex I, Section A is deleted

Amendment 82

Proposal for a regulation

Article 1 – paragraph 1 – point 31 b (new)

Regulation (EU) 2024/1689

Annex I – Section B – point 20 a (new)

Text proposed by the Commission

Amendment

(31b) In Annex I, Section B, the following points are added:

‘20a. Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);

20b. Directive 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1);

20c. Directive 2013/53/EU of the European Parliament and of the Council of 20 November 2013 on recreational craft and personal watercraft and repealing Directive 94/25/EC (OJ L 354, 28.12.2013, p. 90);

20d. Directive 2014/33/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to lifts and safety components for lifts (OJ L 96, 29.3.2014, p. 251);

20e. Directive 2014/34/EU of the European Parliament and of the Council of 26 February 2014 on the harmonisation of the laws of the Member States relating to equipment and protective systems intended for use in potentially explosive atmospheres (OJ L 96, 29.3.2014, p. 309);

20f. Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62);

20g. Directive 2014/68/EU of the European Parliament and of the Council of 15 May 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of pressure equipment (OJ L 189, 27.6.2014, p. 164);

20h. Regulation (EU) 2016/424 of the European Parliament and of the Council of 9 March 2016 on cableway installations and repealing Directive 2000/9/EC (OJ L 81, 31.3.2016, p. 1);

20i. Regulation (EU) 2016/425 of the European Parliament and of the Council of 9 March 2016 on personal protective equipment and repealing Council Directive 89/686/EEC (OJ L 81, 31.3.2016, p. 51);

20j. Regulation (EU) 2016/426 of the European Parliament and of the Council of 9 March 2016 on appliances burning gaseous fuels and repealing Directive 2009/142/EC (OJ L 81, 31.3.2016, p. 99);

20k. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1);

20l. Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).

20m. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council Directive 73/361/EEC.’

Amendment 83

Proposal for a regulation

Article 1 – paragraph 1 – point 32

Regulation (EU) 2024/1689

Annex VIII – section B

Text proposed by the Commission

Amendment

(32) in Annex VIII, section B is deleted;

(32) in Annex VIII, section B, points 7 and 9 are deleted;

EXPLANATORY STATEMENT

The digital omnibus on artificial intelligence is a welcome step to make the implementation and enforcement of Regulation (EU) 2024/1689 (AI Act) simpler, effective and uniform. The Co-Rapporteurs support the Commission’s ambitions to clarify and simplify certain provisions of the AI Act.

The Co-Rapporteurs consider that a postponement of the application date is necessary, considering the delayed preparation of standards, which are necessary to support compliance, as well as the delayed guidelines, governance and conformity assessment frameworks. This is a central part of the AI omnibus.

In order to ensure legal certainty and predictability, the report suggests to replace the Commission’s proposal of linking the date of application to a decision by the Commission with a set timeline of 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The report also states that the Commission should ensure that measures in support of compliance are in place in due time to avoid further application delays.

Besides the postponement, the Co-Rapporteurs have introduced some targeted adjustments to the Commission’s proposal related to AI literacy, processing of special categories of personal data for bias detection and mitigation, notified bodies, cybersecurity and sandboxes.

ANNEX: DECLARATIONS OF INPUT

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteurs declare that they included in their report input on matters pertaining to the subject of the file that they received, in the preparation of the draft report, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

AI Sweden

Allied for Startups

Applia (Home Appliance Europe)

Mistral

Coimisiún na Meán

Google Ireland

TIC Council

DOT Europe

TAM Ireland

Home Appliance Europe

Minister of Digitalisation and Public Governance – Norway

Ada Lovelace

Microsoft

The Future Society

Access Now

Orgalim

IBM

European Banking Federation

European Digital Rights (EDRi)

Black Forest Labs

Center for Countering Digital Hate

Confederation of Industry of Czech Republic

Confederation of Swedish Enterprise

Hetch

Mouvement des Entreprises de France

Orgalim (Europe’s Technology Industries)

Save the Children Europe

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies

The list above is drawn up under the exclusive responsibility of the rapporteurs.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteurs declare that they have submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

6.3.2026

OPINION OF THE COMMITTEE ON CULTURE AND EDUCATION

for the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs

on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

Rapporteur for opinion: Emma Rafowicz

AMENDMENTS

The Committee on Culture and Education submits the following to the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs, as the committees responsible:

Amendment 1

Proposal for a regulation

Recital 2 a (new)

Text proposed by the Commission

Amendment

(2a) Effective implementation of Regulation (EU) 2024/1689 requires that the adjustments introduced to facilitate its application in practice do not reduce the clarity and accessibility of the regulatory framework for those required to apply it. In particular, where the Regulation is applied in the fields of education, culture and media, a clear understanding of the obligations and safeguards related to the use of AI systems remains essential to ensure its effective and consistent application, with a particular attention given to rightholders from the cultural and creative sectors. The measures introduced to support timely and proportionate compliance with this Regulation should therefore continue to support clarity and accessibility of its requirements, thereby contributing to informed use of AI systems and trust in their deployment.

Amendment 2

Proposal for a regulation

Recital 3

Text proposed by the Commission

Amendment

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective application of the relevant rules.

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective application of the relevant rules. As AI systems are increasingly used in education and in the cultural and creative sectors, their deployment might raise specific considerations linked to learning processes, cultural expression and media pluralism. When applying this Regulation, particular attention should therefore be paid to these sectors in order to support informed use of AI and maintain trust in its deployment. In the field of education, this specifically requires safeguards to ensure that the deployment of AI systems preserves pedagogical autonomy, guarantees high standards of data privacy for learners, and prevents dependency on proprietary ecosystems (vendor lock-in).

Amendment 3

Proposal for a regulation

Recital 5

Text proposed by the Commission

Amendment

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

deleted

Amendment 4

Proposal for a regulation

Recital 5 a (new)

Text proposed by the Commission

Amendment

(5a) The promotion of AI literacy plays an important role in supporting citizens’ understanding of AI and its impact on society, including awareness of the opportunities and risks associated with AI, in particular the ability to identify and counter algorithmic bias, discrimination, and the amplification of disinformation, thereby contributing to its democratic governance and public oversight. In practice, such understanding is fostered through education, training, skilling and reskilling programmes, as well as through culture, media literacy and public awareness initiatives. These broader initiatives complement the organisational AI literacy measures taken by providers and deployers of AI systems for their staff and other persons acting on their behalf. Member States should therefore be encouraged, in the context of promoting AI literacy, to involve education providers, cultural institutions, media organisations and civil society actors, in order to ensure that AI literacy initiatives are accessible, inclusive and adapted to different audiences and age groups.

Amendment 5

Proposal for a regulation

Recital 5 b (new)

Text proposed by the Commission

Amendment

(5b) AI literacy, together with media and digital literacy, is especially important for children and young people, who are often exposed to AI systems from an early age without sufficient awareness of bias, inaccuracies, or misleading outputs, and of the effects such systems may have on trust in information, privacy, and the shaping of opinions and behaviour. Measures to promote these literacies should support critical thinking, digital autonomy, and informed decision-making, and should be tailored to different ages and learning contexts.

Amendment 6

Proposal for a regulation

Recital 5 c (new)

Text proposed by the Commission

Amendment

(5c) Artificial intelligence is increasingly present in the digital environments used by children and young people, including in education, social media, online gaming, and cultural and creative platforms. Regulation (EU) 2024/1689 should therefore be applied in a manner that reflects how children and young people interact with AI systems and their specific need for protection and age-appropriate information.

Amendment 7

Proposal for a regulation

Recital 6 a (new)

Text proposed by the Commission

Amendment

(6a) AI systems that alter, manipulate or artificially produce images or videos depicting natural persons engaged in sexually explicit activities, displaying their intimate body parts, or undresses a person without consent cause harm to victims and violate fundamental rights to dignity and privacy. Recent developments have demonstrated the incompatibility of certain AI practices with the Union's fundamental rights framework. The nudification of women, manipulation of intimate images and generation of child sexual abuse material constitute clear breaches of fundamental rights and Union law. However, significant legal uncertainty remains as to whether AI-powered nudity applications fall within the scope of the AI practices prohibited by Article 5 of Regulation (EU) 2024/1689. Article 112 of that Regulation obliges the Commission to assess, on an annual basis, the necessity of amendments to the list of prohibited practices laid down in Article 5 and the list set out in Annex III, and to submit the findings of that assessment to the European Parliament and the Council. The Commission has failed to meet the deadline for the previous assessment period. For this reason, it seems adequate to specify that prohibited practices under Article 5 include the placing on the market, the putting into service or the use of an AI system that can generate or manipulate sexualised audio, images and videos of individuals, thereby facilitating non-consensual sharing of intimate or manipulated material as defined in Directive (EU) 2024/1385.

Amendment 8

Proposal for a regulation

Recital 9

Text proposed by the Commission

Amendment

(9) To streamline compliance and reduce the associated costs, providers of AI systems should not be required to register AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation. Given that such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons, imposing registration requirements would constitute a disproportionate compliance burden. Nevertheless, a provider who considers that an AI system falls under Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

deleted

Amendment 9

Proposal for a regulation

Recital 11 a (new)

Text proposed by the Commission

Amendment

(11a) Extending opportunities for real-world testing can support innovation, but it should not result in vulnerable groups becoming default test populations. Where real-world testing involves AI systems intended for use in education and vocational training, or is carried out in environments where minors are likely to be affected, the real-world testing plan should set out safeguards that are specific to that setting, including clear information for affected persons and meaningful involvement of deployers such as schools and other public-interest organisations responsible for those environments.

Amendment 10

Proposal for a regulation

Recital 20

Text proposed by the Commission

Amendment

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 6 months for providers who have already placed their systems on the market before the 2 August 2026.

deleted

Amendment 11

Proposal for a regulation

Recital 21

Text proposed by the Commission

Amendment

(21) To provide sufficient time for providers of high-risk AI systems and to clarify applicable rules to the AI systems already placed on the market or put into service before the entry into application of relevant provisions of the Regulation (EU) 2024/1689, it is appropriate to clarify the application of a grace period provided in Article 111(2) of that Regulation. The grace period, for the purpose of Article 111(2), should apply to a type and model of AI systems already placed in the market. This means that if at least one individual unit of the high-risk AI system has been lawfully placed on the market or put into service before the date specified in Article 111(2), other individual units of the same type and model of high-risk AI system are subject to the grace period provided in Article 111(2) and thus may continue to be placed on the market, made available or put into service on the Union market without any additional obligations, requirements or the need for additional certification, as long as the design of that high-risk AI system remains unchanged. For the purposes of application of the grace period provided in Article 111(2), the decisive factor is the date on which the first unit of that type and model of high-risk AI system was placed on the market or put into service on the Union market for the first time. Any significant change to the design of that AI system after the date specified in Article 111(2) should trigger the obligation of the provider to comply fully with all relevant provisions of this Regulation applicable to high-risk AI systems, including the conformity assessment requirements.

deleted

Amendment 12

Proposal for a regulation

Recital 22

Text proposed by the Commission

Amendment

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. Building on experience, it is appropriate to put in place a mechanism that links the entry into application to the availability of measures in support of compliance with Chapter III, which may include harmonised standards, common specifications, and Commission guidelines. This should be confirmed by the Commission by decision, following which the rules obligations for high-risk AI systems should apply after 6 months as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and after 12 months as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to Regulation (EU) 2024/1689. However, this flexibility should only be extended until 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and until 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to that Regulation, by which dates those rules should enter into application in any case. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations.

deleted

Amendment 13

Proposal for a regulation

Recital 23

Text proposed by the Commission

Amendment

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance. In that context, codes of practice encouraged by the AI Office pursuant to Article 50(7) should, where relevant, provide guidance on how appropriate user information and awareness can be ensured in a proportionate manner, including in situations where AI systems present lower risks, in particular in education and training, media and information services, cultural and creative activities, or the provision of public services.

Amendment 14

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4

Text proposed by the Commission

Amendment

(4) Article 4 is replaced by the following:

deleted

‘Article 4

AI literacy

The Commission and Member States shall encourage1. providers▌Providers and deployers of AI systems toshall take measures to ensure asupport sufficientthe leveldevelopment of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.’;used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

Amendment 15

Proposal for a regulation

2. The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1 of this Article. For that purpose, the Commission shall publish practical examples of how to comply with that obligation on the single information platform referred to in Article 62(3), point (b).

Article 1 – paragraph 1 – point 5

3. The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 1, including by setting out common objectives.’;

Regulation (EU) 2024/1689

(6) the following Article is inserted:

Article 4a – paragraph 1 – point f a (new)

‘Article 4a

Text proposed by the Commission

Processing of special categories of personal data for bias detection and correction

Amendment

1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10(2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

(fa) for the sole purpose of detecting and mitigating algorithmic biases that may affect media pluralism and the diversity of information, providers of high-risk AI systems used in the media ecosystem may, in exceptional and strictly limited circumstances, process special categories of personal data, provided that:

(a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;

(i) such processing is strictly necessary and cannot be effectively achieved through the use of anonymised, aggregated or synthetic data;

(b) the special categories of personal data are subject to technical limitations on the re-use of personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;

(ii) the processing is limited in scope, duration and access, and does not lead to the identification, profiling or categorisation of individual users;

(c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured and protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and to ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;

(iii) no inferences are drawn regarding political opinions, religious beliefs or other protected characteristics of natural persons;

(d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties;

(iv) appropriate technical and organisational measures are implemented in accordance with Union data protection law to ensure confidentiality, security and accountability;

(e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first; and

(v) the personal data are deleted without undue delay once the bias has been detected and mitigated;

(f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.

(vi) users are informed in a clear and accessible manner that their personal data may be processed, in exceptional circumstances, for the sole purpose of detecting and mitigating algorithmic biases, and are provided with information on the scope, safeguards, and rights applicable to such processing.

2. ▌Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:

Amendment 16

(a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law, especially where data outputs influence inputs for future operations; and

Proposal for a regulation

(b) all of the conditions and safeguards set out in paragraph 1 are applied.

Article 1 – paragraph 1 – point 5

This paragraph does not create any obligation to conduct such bias detection and correction.’;

Regulation (EU) 2024/1689

Article 4a – paragraph 2 a (new)

(7) Article 5 is amended as follows:

Text proposed by the Commission

(a) in paragraph 1, the first subparagraph, the following points are inserted:

Amendment

‘(ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;

2a. Children's personal data is explicitly prohibited from being collected, processed or used any other way.

(bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a ‘without right’ defence applies under national law;’;

Amendment 17

(b) the following paragraphs are inserted:

Proposal for a regulation

‘1a. For the purposes of paragraph 1, first subparagraph, points (ba) and (bb):

Article 1 – paragraph 1 – point 5 a (new)

(a) the placing on the market or putting into service of an AI system that generates or manipulates the material or performance referred to in paragraph 1, first subparagraph, point (ba) or (bb) is only prohibited where:

Regulation (EU) 2024/1689

(i) that generation or manipulation is the intended purpose of the AI system; or

Article 5 – paragraph 1– point h a (new)

(ii) the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse;

Text proposed by the Commission

(b) the use of an AI system that generates or manipulates the material or performance referred to in paragraph 1, first subparagraph, points (ba) and (bb) is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance.

Amendment

1b. For the purposes of paragraph 1, first subparagraph, point (ba), an AI system that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation.’;

(5a)(8) Inin Article 5(1),6, the following pointparagraphs isare added:inserted:

'(ha) the placing on the market, the putting into service or the use of an AI system that can alter, manipulate or generate images or videos so as to depict sexually explicit activities or the intimate parts of a natural person, or that undresses that person, and can facilitate non-consensual sharing of intimate or manipulated material as defined in Article 5 of Directive 2024/1385 1a.

‘1a. For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.

_________________

1b. Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components. 1c. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety , in particular risks relating to the distribution of radio spectrum or electromagnetic interference that do not affect health and safety, shall not be considered as fulfilling the condition in paragraph 1, point (b).’;

1a Directive (EU) 2024/1385 of the European Parliament and of the Council of 14 May 2024 on combating violence against women and domestic violence (OJ L, 2024/1385, 24.5.2024, ELI: http://data.europa.eu/eli/dir/2024/1385/oj).’

(9) Article 10 is amended as follows:

Amendment 18

(a) paragraph 1 is replaced by the following:

Proposal for a regulation

‘1. High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2, 3 and 4 of this Article and in Article 4a(1) whenever such data sets are used.’;

Article 1 – paragraph 1 – point 6

Regulation (EU) 2024/1689

(b) paragraph 5 is deleted;

Article 6 – paragraph 4

(c) paragraph 6 is replaced by the following:

Text proposed by the Commission

‘6. For the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2, 3 and 4 of this Article and Article 4a(1) shall apply only to the testing data sets.’;

Amendment

(6)(10) in Article 6(4),11(1), paragraphthe 4second subparagraph is replaced by the following:

deleted

‘That technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. ▌ SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of ▌ SMEs, including start-ups, and SMCs. Where an ▌ SME, including a start-up, or an SMC, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.’;

‘4. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Upon request of national competent authorities, the provider shall provide the documentation of the assessment.’;

(11) in Article 17, paragraph 2 is replaced by the following:

Amendment 19

‘2. The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation, in particular, if the provider is ▌ an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.’;

Proposal for a regulation

(12) Article 25 is amended as follows:

Article 1 – paragraph 1 – point 14

(a) paragraph 2 is replaced by the following:

Regulation (EU) 2024/1689

‘2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation.

Article 49 – paragraph 2

That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular with regard to compliance with the conformity assessment of high-risk AI systems.

Text proposed by the Commission

In particular, the obligation laid down in the second subparagraph shall include, where relevant for the purposes specified therein, the following:

Amendment

(a) making available of technical documentation sufficient to assess compliance with the requirements laid down in Article 16;

(14) in Article 49, paragraph 2 is deleted;

(b) informing the new providers about known limitations and failure modes; and

deleted

(c) providing the new providers with targeted technical access, including for testing and validation.

Amendment 20

This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.’;

Proposal for a regulation

(b) in paragraph 4, the first subparagraph is replaced by the following:

Article 1 – paragraph 1 – point 15

‘4. The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.’;

Regulation (EU) 2024/1689

(13) Article 27 is amended as follows:

Article 50 – paragraph 7

(a) paragraph 4 is replaced by the following:

Text proposed by the Commission

‘4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.’;

Amendment

(b) paragraph 5 is replaced by the following:

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).

‘5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.’;

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may adopt implementing acts to approve those codes of practice in accordance with the procedure laid down in Article 56(6). If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2). Those codes of practice shall, where relevant, address how appropriate user information and awareness can be ensured in a proportionate manner, including in cases where AI systems are considered to present lower risks, in particular when used in education and training, media and information services, cultural and creative activities, or the provision of public services.

(14) in Article 28, ▌ the following paragraphs are added:

Amendment 21

‘8. Notifying authorities designated pursuant to this Regulation that are responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both pursuant to this Regulation and the Union harmonisation legislation listed in Section A of Annex I is provided with the possibility to submit a single application and undergoes a unified assessment procedure to be designated pursuant to this Regulation and Union harmonisation legislation listed in Section A of Annex I, where the relevant Union harmonisation legislation provides for such single application and unified assessment procedure. To that end, notifying authorities designated pursuant to this Regulation and those designated pursuant to the Union harmonisation legislation listed in Section A of Annex I shall cooperate in their assessments.

Proposal for a regulation

The single application and the unified assessment procedure referred to in this paragraph shall also be made available to notified bodies already designated pursuant to the Union harmonisation legislation listed in Section A of Annex I, when those notified bodies apply for designation pursuant to this Regulation, provided that the relevant Union harmonisation legislation provides for such a procedure.

Article 1 – paragraph 1 – point 16

A conformity assessment body that is designated pursuant to more than one piece of Union harmonisation legislation listed in Section A of Annex I shall have to apply only once to be designated pursuant to this Regulation. A designation pursuant to this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which the conformity assessment body is designated.

Regulation (EU) 2024/1689

The single application and the unified assessment procedure shall avoid any unnecessary duplications, build on the existing procedures for designation in accordance with the Union harmonisation legislation listed in Section A of Annex I and ensure compliance with the requirements relating to notified bodies both in accordance with this Regulation and the relevant Union harmonisation legislation.

Article 56 – paragraph 6 – subparagraph 1

9. A notifying authority that has been designated pursuant to the Union harmonisation legislation listed in Section A of Annex I is also the notifying authority for the application of the single application and unified assessment procedure referred to in paragraph 8, unless the Member State designates another notifying authority for this Regulation.’;

Text proposed by the Commission

(15) in Article 29, paragraph 4 is replaced by the following:

Amendment

‘4. For notified bodies which are designated pursuant to any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support and expedite their designation procedure under this Regulation, as appropriate.

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.

Notified bodies, which are designated pursuant to any of the Union harmonisation legislation listed in Section A of Annex I and which undergo the unified assessment procedure referred to in Article 28(8), shall submit the single application for assessment to the notifying authority designated pursuant to that Union harmonisation legislation.

6. The AI office and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The AI office and the Board, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. They shall publish their assessment of the adequacy of the codes of practice.

The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.’;

Justification

(16) in Article 30, paragraph 2 is replaced by the following:

This amendment seeks to ensure that the monitoring, evaluation and disclosure of the adequacy of codes of practice are fully consistent with the governance arrangements set out in this Regulation. Entrusting these responsibilities to the AI Office and the Board places oversight in the hands of the bodies specifically mandated for technical supervision. In addition, restoring this role to the Board is necessary to maintain an appropriate institutional balance.

‘2. Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.

Amendment 22

The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex XIV, in light of technical progress, advances in knowledge or new scientific evidence by adding to the list of codes, categories, and corresponding types of AI systems a new code, a category or a type of AI system, withdrawing an existing code, category or a type of AI system from that list or moving a code or type of AI system from one category to another.’;

Proposal for a regulation

(17) In Article 40(2), the following subparagraph is added:

Article 1 – paragraph 1 – point 23

‘The Commission shall request, in accordance with Regulation (EU) No 1025/2012 of the European Parliament and of the Council and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation.’;

Regulation (EU) 2024/1689

(18) In Article 42, the following paragraph is added:

Article 70 – paragraph 8

‘3. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.’;

Text proposed by the Commission

(19) in Article 43, paragraph 3 is replaced by the following:

Amendment

‘3. For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required in accordance with the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 ▌ shall also be undertaken, and points 3, 4.3, 4.4. and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII shall apply.

8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMCs and SMEs, including start-ups, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.

For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in Section 2 of this Chapter, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure in accordance with the relevant Union harmonisation legislation, which is evidenced through the assessment as part of the existing notification. Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 of this Chapter by … [18 months from the entry into force of this amending Regulation].

8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMCs and SMEs, including start-ups, and, where relevant, to public sector deployers, including local public authorities and publicly funded education, training and cultural institutions, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, including data protection, consumer protection and audiovisual media services, the national competent authorities under that Union law shall be consulted, as appropriate.

Where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third-party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I, including, where applicable, an option to rely on harmonised standards. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by the Union harmonisation legislation listed in Section A of Annex I.

Amendment 23

▌ Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of that system shall follow the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.’;

Proposal for a regulation

Article 1 – paragraph 1 – point 24

(20) in Article 50, paragraph 7 is replaced by the following:

Regulation (EU) 2024/1689

‘7. The Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56(6) ▌. If it deems the code of practice to be inadequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).’;

Article 72 – paragraph 3

(21) in Article 56, paragraph 6 is replaced by the following:

Text proposed by the Commission

‘6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice ▌.’;

Amendment

(22) Article 57 is amended as follows:

3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt guidance on the post-market monitoring plan.

(a) in paragraph 1, the first subparagraph is replaced by the following:

3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission shall adopt guidance on the post-market monitoring plan, including practical examples for high-risk AI systems deployed in education and vocational training and other public services, and on monitoring indicators that may signal adverse impacts on fundamental rights, including discriminatory outcomes.

‘1. Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2 August 2027. That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.’;

Amendment 24

(b) paragraph 3 is replaced by the following:

Proposal for a regulation

‘3. The European Data Protection Supervisor may establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose, references to national competent authorities in this Chapter shall be construed as references to the European Data Protection Supervisor.’;

Article 1 – paragraph 1 – point 27

(c) the following paragraph is inserted:

Regulation (EU) 2024/1689

‘3a. The AI Office may establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). For this purpose, references to national competent authorities in this Chapter shall be construed, where relevant, as references to the AI Office. That AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular where compliance with Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including start-ups, and SMCs. ▌

Article 95 – paragraph 4

The establishment of a Union level AI regulatory sandbox by the AI Office shall be without prejudice to the competences of Member States to establish and supervise AI regulatory sandboxes for AI systems under their supervision.’;

Text proposed by the Commission

(d) paragraph 5 is replaced by the following:

Amendment

‘5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. Where applicable, the sandbox plan shall incorporate the real-world testing plan referred to in Articles 60 and 60a.’;

4. The AI Office and the Member States shall take into account the specific interests and needs of SMCs and SMEs, including start-ups, when encouraging and facilitating the drawing up of codes of conduct.

(e) in paragraph 9, point (e) is replaced by the following:

4. The AI Office and the Member States shall take into account the specific interests and needs of SMCs and SMEs, including start-ups, as well as the operational needs of local public authorities and public-interest organisations, including education, training and cultural institutions, where they are expected to use or benefit from such codes, when encouraging and facilitating the drawing up of codes of conduct.

‘(e) facilitating and accelerating access to the Union market for AI systems, in particular when provided by ▌ SMEs, including start-ups, and SMCs.’;

Amendment 25

(f) paragraph 10 is replaced by the following:

Proposal for a regulation

‘10. National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the competent data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.’;

Article 1 – paragraph 1 – point 28

(g) paragraph 14 is replaced by the following:

Regulation (EU) 2024/1689

’14. National competent authorities, the European Data Protection Supervisor and the AI Office, shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board. They may support the joint establishment and operation of AI regulatory sandboxes, including in different sectors, and exchange best practices on related matters.’;

Article 96 – paragraph 1 – subparagraph 2

(23) in Article 58(1), the first subparagraph is amended as follows:

Text proposed by the Commission

(a) the introductory part is replaced by the following:

Amendment

‘1. In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation, governance, and supervision of the AI regulatory sandboxes. Those implementing acts shall include common principles on the following issues:’;

When issuing such guidelines, the Commission shall pay particular attention to the needs of SMCs and SMEs including start-ups, of local public authorities and of the sectors most likely to be affected by this Regulation.

(b) the following point is added:

When issuing such guidelines, the Commission shall pay particular attention to the needs of SMCs and SMEs including start-ups, of local public authorities and of the sectors most likely to be affected by this Regulation, including education and vocational training, cultural and creative activities, and media and information services.

‘(d) the detailed rules applicable to the governance of AI regulatory sandboxes covered pursuant to Article 57, including as regards the involvement of and supervision by the competent data protection authorities, where relevant, and the coordination and cooperation at national and Union level.’;

Amendment 26

(24) Article 60 is amended as follows:

Proposal for a regulation

(a) in paragraph 1, the first subparagraph is replaced by the following:

Article 1 – paragraph 1 – point 30 – point a

‘1. Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.’;

Regulation (EU) 2024/1689

(b) paragraph 2 is replaced by the following:

Article 111 – paragraph 2

‘2. Providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the high-risk AI system on their own or in partnership with one or more deployers or prospective deployers.’;

Text proposed by the Commission

(25) the following Article is inserted:

Amendment

‘Article 60a

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.

Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to deployers and providers of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.

1. Member States may allow, in accordance with this Article, the testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes ▌ by providers or prospective providers of AI enabled products covered by the Union harmonisation legislation listed in Section B of Annex I, with a view to assessing and verifying the conformity of those systems with the requirements laid down in Articles 8 to 15.

Amendment 27

Proposal for a regulation

2. Member States that choose to allow testing as referred to in paragraph 1 shall, individually or jointly, adopt frameworks for real-world testing.

Article 1 – paragraph 1 – point 30 – point b

3. Each Member State shall notify the Commission of any real-world testing framework it adopts before implementing it. This shall not affect the competences of the Commission under the Union harmonisation legislation listed in Section B of Annex I.

Regulation (EU) 2024/1689

4. Member States that have adopted real-world testing frameworks shall ensure that the relevant national competent authorities, relevant authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I ▌ cooperate closely with each other in good faith and ▌ remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement those real-world testing frameworks and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex I.

Article111 – paragraph 4

5. The frameworks for real-world testing ▌ shall lay down the requirements under which testing in real-world conditions shall occur. Those frameworks shall:

Text proposed by the Commission

(a) include the provision of a mandatory real-world testing plan to be agreed between the provider or prospective provider and the national competent authority or relevant authority in accordance with the Union harmonisation legislation listed in Section B of Annex I;

Amendment

(b) ensure compliance with the requirements laid down in Article 60(2), (3), (4)(d)-(j) and (5)-(9), where any reference to market surveillance authorities in those provisions shall be read as a reference to the national competent authority or relevant authority, as appropriate in accordance with the Union harmonisation legislation listed in Section B of Annex I;

(b) the following paragraph 4 is added:

(c) include effective governance and accountability arrangements;

deleted

(d) ensure a high level of protection of health safety and fundamental rights.

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 February 2027.

6. The real-world testing shall comply with the applicable provisions laid down in the Union harmonisation legislation listed in Section B of Annex I. Any requirements laid down in those provisions shall not affect the application of this Article to the extent necessary to enable the testing referred to in paragraph 1.

Amendment 28

▌ ’

Proposal for a regulation

(26) in Article 63, paragraph 1 is replaced by the following:

Article 1 – paragraph 1 – point 31

‘1. SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.’;

Regulation (EU) 2024/1689

(27) In Article 64, the following paragraph is added:

Article 113

‘3. Without prejudice to the budgetary procedure, the AI Office shall be allocated adequate resources to effectively perform its duties and exercise its powers in relation to the enforcement of this Regulation.’;

Text proposed by the Commission

(28) In Article 69, paragraph 2 is replaced by the following:

Amendment

‘2. The Member States may be required to pay fees for the advice and support provided by the experts at a rate equivalent to the remuneration fees applicable to the Commission pursuant to the implementing act referred to in Article 68(1).’;

(31) Article 113 is amended as follows:

deleted

(29) in Article 70, paragraph 8 is replaced by the following:

(a) in the third paragraph, point (d) is added:

‘8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to ▌ SMEs, including start-ups, and SMCs, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.’;

‘(d) Chapter III, Sections 1, 2, and 3, shall apply following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available, from the following dates:

(30) in Article 72, paragraph 3 is replaced by the following:

(i) 6 months after the adoption of that decision as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

‘3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.’;

(ii) 12 months after the adoption of the decision as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

(31) Article 75 is amended as follows:

In the absence of the adoption of the decision within the meaning of subparagraph 1, or where the dates below are earlier than those that follow the adoption of that decision, Chapter III, Sections 1, 2, and 3, shall apply:

(a) the heading is replaced by the following:

(i) on 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

‘Market surveillance and control of AI systems and mutual assistance’;

(ii) on 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.;’

(b) paragraph 1 is replaced by the following:

(b) in the third paragraph, point (e) is added:

‘1. The AI Office shall ▌ be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to the following AI systems:

‘(e) Articles 102 to 110 shall apply from [the date of entry into application of this Regulation].;’

(a) AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of:

Amendment 29

(i) AI systems related to products covered by the Union harmonisation legislation listed in Annex I;

Proposal for a regulation

(ii) AI systems referred to in point 2 of Annex III;

Article 1 – paragraph 1 – point 32

(iii) AI systems provided by law enforcement authorities, border management authorities and financial institutions, insofar as those AI systems fall under Article 74(6); and

Text proposed by the Commission

(iv) AI systems referred to in point 8 of Annex III as regards the administration of justice;

Amendment

(b) AI systems that constitute or that are integrated into a very large online platform or very large online search engine designated in accordance with Regulation (EU) 2022/2065.

(32) in Annex VIII, section B is deleted;

The exclusive competence referred to in the first subparagraph shall apply to the providers of those systems. It shall apply to the deployers of those systems only when they are also the provider or form part of the same undertaking as the provider.’;

deleted

(c) the following paragraphs are inserted:

ANNEX: DECLARATION OF INPUT

‘1a. By way of derogation from Article 73, providers of high-risk AI systems subject to the competence of the AI Office pursuant to paragraph 1 of this Article shall report any serious incidents to the AI Office. Article 73 (2) to (9), shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in the territory of which the provider or its legal representative is situated.

The rapporteur for opinion declares under her exclusive responsibility that she did not include in her opinion input from interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from representatives of public authorities of third countries, including their diplomatic missions and embassies, to be listed in this Annex pursuant to Article 8 of Annex I to the Rules of Procedure.

1b. The authorities involved in the application of this Regulation shall cooperate actively with the AI Office and provide the AI Office the necessary assistance for the exercise of its powers, including, where necessary, in connection with inspections or other enforcement measures carried out in the territory of a Member State. To that end, those authorities shall enjoy the powers provided for pursuant to this Regulation and Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks under this paragraph, in accordance with the applicable national procedures.

PROCEDURE – COMMITTEE ASKED FOR OPINION

1c. When taking investigatory or enforcement action in the territory of a Member State that involves access to a public authority’s data or AI system, the AI Office shall be assisted by the relevant market surveillance authority.

Title

1d. Before taking a decision that would have the effect of prohibiting or restricting the AI system being made available or put into service on a national market, or a decision to withdraw or recall the AI system from such market, the AI Office shall, without undue delay, notify the market surveillance authority competent for that market of its intention to take such a decision. The AI Office shall consult the authorities involved in the application of this Regulation, where appropriate, on any matter relating to the application and enforcement of this Regulation.

Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

1e. The AI Office shall be responsible for conformity assessments and tests of AI systems referred to in paragraph 1 of this Article that are classified as high-risk and subject to a third-party conformity assessment pursuant to Article 43 before such AI systems are placed on the market or put into service. Those tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission shall entrust the performance of those tests or assessments to notified bodies designated in accordance with this Regulation, in which case the notified body shall act on behalf of the Commission. If a notified body to which the Commission has delegated tasks under this paragraph does not perform those tasks adequately, the Commission may withdraw the delegation with immediate effect.

References

The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for a third-party conformity assessment to the Commission. The provider shall pay the costs related to the services entrusted by the Commission to the notified bodies in accordance with this Article directly to the notified body.’;

COM(2025)0836 – C10-0304/2025 – 2025/0359(COD)

(d) the following paragraph is inserted:

Committee(s) responsible

2a. Where a market surveillance authority has well-founded and sufficient reasons to suspect that a provider or a deployer of an AI system referred to in paragraph 1 of this Article has infringed this Regulation, it may request, through the relevant single point of contact designated in accordance with Article 70(2), the AI Office to assess the matter in order to take the necessary supervisory and enforcement measures to ensure prompt compliance with this Regulation. Such a request shall be duly reasoned and shall include at least:

Date announced in plenary

(a) the name of the provider or the deployer concerned;

IMCO

(b) a description of the relevant facts, the provisions of this Regulation that have allegedly been infringed, and any well-founded and sufficient reasons for suspecting an infringement, including, where applicable, the description of the negative effects of the alleged infringement;

19.1.2026

(c) the market surveillance authority making the request.

LIBE

The AI Office shall take utmost account of the request and the market surveillance authority shall cooperate actively and provide the AI Office the necessary assistance for the exercise of its powers in accordance with paragraph 1a.

19.1.2026

The AI Office shall, without undue delay and in any event no later than four months following receipt of the request, inform the single point of contact of its intention to exercise its powers in accordance with Article 75a or of its reasons for not exercising its powers. If the AI Office decides to exercise its powers in accordance with Article 75a, it shall periodically inform that single point of contact about major developments in the proceedings and the outcome of such proceedings, without disclosing any confidential information.’;

Opinion by

(32) the following articles are inserted:

Date announced in plenary

‘Article 75a

CULT

Supervisory and enforcement powers of the AI Office

19.1.2026

1. When exercising its tasks of supervision and enforcement laid down in Article 75(1) of this Regulation, the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020. The AI Office shall be authorised to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance, including costs for human and technical resources, in accordance with Article 15 of Regulation (EU) 2019/1020. Article 17 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

Rapporteur for the opinion

2. Where the AI Office has reasonable grounds to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1) of this Regulation, it may adopt a decision to start an investigation into that non-compliance in accordance with Article 14(4), point (f) of Regulation (EU) 2019/1020. Upon starting such an investigation, the AI Office shall notify the operator of the AI system concerned. The AI Office may exercise the powers referred to in paragraph 1 of this Article on its own initiative or following a complaint received pursuant to Article 85 of this Regulation, even before starting an investigation pursuant to Article 14(4), point (f) of Regulation (EU) 2019/1020.

Date appointed

Where a market surveillance authority has reason to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may send a request to the AI Office to assess the matter.

Emma Rafowicz

3. The AI Office may exercise the powers listed in Article 14(4), points (a), (b) and (c) of Regulation (EU) 2019/1020 and Article 74(12) and (13) of this Regulation by simple request or by decision.

20.1.2026

When requesting information, the AI Office shall state the legal basis and the purpose of the request, specify what information is required, and set the period within which the information is to be provided. Where the request is a simple request, the AI Office shall additionally indicate that although there is no obligation to provide the information requested, in the case of a voluntary reply, the information must be correct and not misleading, and indicate the potential fines provided for in Article 99(5) for supplying incorrect or misleading information. Where the request is made by decision, the AI Office shall additionally indicate the fines provided for in Article 99(5) for supplying incorrect, incomplete or misleading information and indicate the right to have the decision reviewed by the Court of Justice of the European Union. The AI Office shall send a copy of the request to the market surveillance authority of the Member State in the territory of which the operator or its legal representative is situated.

Rule 59 – Joint committee procedure

4. In order to carry out the tasks assigned to it under this Section, the AI Office may conduct all necessary remote or on-site inspections pursuant to the powers laid down in Article 14(4), points (d) and (e) of Regulation (EU) 2019/1020 and Article 74(5) of this Regulation. When conducting an inspection, the AI Office shall inform the provider concerned of the subject matter and purpose of the investigation, the relevant fines referred to in Article 99(5) of this Regulation, and the right to have the decision reviewed by the Court of Justice of the European Union. Prior to conducting an inspection, the AI Office shall inform the market surveillance authority of the Member State in the territory of which the operator or its legal representative is situated.

Date announced in plenary

During such an inspection, the officials of the AI Office shall be empowered to:

19.1.2026

(a) enter any of the business premises, land or property located in the Union of the operator concerned;

Discussed in committee

(b) examine the books, data and other material relevant to the execution of their tasks, irrespective of the medium on which they are stored;

9.2.2026

(c) take or obtain in any form copies of or extracts from books, data and other records;

Date adopted

(d) ask any of the persons subject to the inspection, or their representatives, or staff, for oral or written explanations on factors or documents relating to the subject matter and purpose of the inspection, and to record the answers;

5.3.2026

(e) seal any business premises and books or records for the duration of, and to the extent necessary for, the inspection.

Result of final vote

Where the AI Office finds that a natural or legal person opposes or obstructs an inspection, the national competent authority of the Member State concerned shall afford it the necessary assistance, requesting, where appropriate, the assistance of the police or an equivalent enforcement authority, to enable it to conduct its on-site inspection.

+:

Where an on-site inspection of business premises, land or property requires authorisation by a judicial authority in accordance with national law, the AI Office shall apply for such an authorisation. The AI Office may also apply for such authorisation as a precautionary measure. Where such an authorisation is applied for, the national judicial authority shall promptly verify that the coercive measures envisaged are neither arbitrary nor excessive having regard to the subject matter of the investigation or inspection and the documents provided by the AI Office with the decision. In its verification of the proportionality of coercive measures, the national judicial authority may ask the AI Office for detailed explanations, in particular relating to the grounds the AI Office has for suspecting that an infringement of this Regulation has taken place and the seriousness of the suspected infringement and, where relevant, the nature of the involvement of the person subject to the coercive measures. The national judicial authority shall not review the necessity of the investigation or inspection nor demand information from the case file of the AI Office. In accordance with the Treaties, the legality of the decision of the AI Office is subject to review only by the Court of Justice of the European Union.

–:

5. At the request of the AI Office, the competent market surveillance authority of a Member State may in its own territory carry out any investigation, inspection or other fact-finding measure on behalf and for the account of the AI Office in order to establish whether there has been an infringement of this Regulation. The officials of the competent authorities of the Member States who are responsible for conducting such investigations, inspections, or fact-finding measures, as well as those authorised or appointed by them, shall exercise their powers in accordance with their national law.

0:

6. In addition to the powers set out in paragraph 1 of this Article, the AI Office, in the exercise of its competences referred to in Article 75(1), may:

18

(a) order operators to provide access to, and explanations relating to, their AI systems;

0

(b) impose an obligation on an operator to retain all data and documents deemed to be necessary to assess the implementation of and compliance with the obligations under this Regulation.

3

7. To assist it in monitoring the effective implementation and compliance with the relevant provisions of this Regulation and to provide it with specific expertise or knowledge in the exercise of its competences under Article 75(1), the AI Office may appoint independent external experts and auditors, as well as experts, investigative teams and auditors from the Member State’s competent authorities with the agreement of the authority concerned,. Information obtained as a result of such monitoring actions shall be shared with the relevant competent authorities of the Member States.

FINAL VOTE BY ROLL CALL BY THE COMMITTEE ASKED FOR OPINION

8. Information collected pursuant to this Article shall be used only for the purpose of this Regulation.

Key to symbols:

Article 75b Commitments

25.2.2026

If, during proceedings under Article 75a(2), the operator concerned offers commitments to ensure compliance with the relevant provisions of this Regulation, the AI Office may, by decision, make those commitments binding on the operator concerned and declare that there are no further grounds for action. The AI Office may, upon request or on its own initiative, reopen the proceedings where:

OPINION OF THE COMMITTEE ON LEGAL AFFAIRS

(a) there has been a material change in any of the facts on which the decision was based;

for the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs

(b) the operator acts contrary to its commitments; or

on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

(c) the decision was based on incomplete, incorrect or misleading information provided by the operator concerned.

(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

Where the AI Office considers that the commitments offered by the operator concerned are unable to ensure effective compliance with the relevant provisions of this Regulation, it shall reject those commitments in a reasoned decision when concluding the proceedings.

Rapporteur for opinion: Sergey Lagodinsky

Article 75c Non-compliance, fines and periodic penalty payments

AMENDMENTS

1. Where the AI Office finds that an operator falling within the scope of Article 75(1) does not comply with the relevant provisions of this Regulation or with commitments made binding pursuant to Article 75b, it shall adopt a decision establishing such non-compliance.

The Committee on Legal Affairs submits the following to the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs, as the committees responsible:

2. Before adopting a decision pursuant to paragraph 1, the AI Office shall communicate its preliminary findings to the operator concerned. In the preliminary findings, the AI Office shall explain the measures that it is considering taking, or that it considers that the operator concerned should take, in order to effectively address the preliminary findings.

Amendment 1

3. In the decision pursuant to paragraph 1 of this Article, the AI Office shall, where relevant, order the operator concerned to take the necessary measures to ensure compliance with the relevant provisions of this Regulation within a reasonable period specified therein and to provide information on the measures that that operator intends to take to comply with the decision. The operator concerned shall provide the AI Office with a description of the measures it has taken to ensure compliance with the decision upon their implementation. Prior to requesting any measure, the AI Office may engage in a structured dialogue with the operator of the AI system in question. During this dialogue, the operator may propose commitments in accordance with Article 75b.

Proposal for a regulation

4. A decision adopted pursuant to paragraph 1 of this Article may be accompanied by the imposition of penalties in accordance with Article 99(3) to (7), which provisions shall apply mutatis mutandis to the AI Office in the execution of its supervision and enforcement tasks referred to in Article 75(1).

Recital 1 a (new)

In particular, the following shall be subject to administrative fines as referred to in Article 99(4):

Text proposed by the Commission

(a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4);

Amendment

(b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or Article 16(3) of Regulation (EU) 2019/1020, as well as those specified in Article 75a of this Regulation;

(1a) Obligations under this Regulation shall be implemented in a proportionate manner, taking into account the nature, scale and complexity of the activities concerned.

(c) failure to comply with a commitment made binding by a decision pursuant to Article 75b.

Amendment 2

The supply of incorrect, incomplete or misleading information to the AI Office in reply to a request shall be subject to administrative fines as referred to in Article 99(5).

Proposal for a regulation

5. The AI Office may adopt a decision imposing periodic penalty payments to compel the operators subject to its competence pursuant to Article 75(1) to the following:

Recital 2 a (new)

(a) to submit to an investigation;

Text proposed by the Commission

(b) to comply with an information request ordered by a decision adopted under Article 75a(3);

Amendment

(c) to submit to an inspection ordered by a decision pursuant to Article 75a(4);

(2a) This Regulation aims to simplify the implementation of Regulation (EU) 2024/1689 and to reduce unnecessary administrative burden without altering its scope. It does not introduce new legal categories of artificial intelligence systems, nor does it prejudge any future policy choices regarding systems exhibiting higher degrees of autonomy. Any such assessment should take place in the context of a dedicated legislative review.

(d) to provide correct or complete answers or explanations in the context of an inspection ordered by a decision pursuant to Article 75a(4);

Amendment 3

(e) to comply with corrective actions ordered pursuant to the power listed in Article 16 of Regulation (EU) 2019/1020;

Proposal for a regulation

(f) to comply with commitments made legally binding by a decision pursuant to Article 75b; or

Recital 4

(g) to comply with a decision pursuant to the paragraph (1) of this Article.

Text proposed by the Commission

Those penalty payments shall be effective and proportionate, and, where applicable, shall not exceed 5% of the average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date appointed by the decision.

Amendment

6. The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the AI Office fixing a fine or periodic penalty payment pursuant to this Article. It may cancel, reduce or increase the fine or periodic penalty payment imposed.

(4) Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4and Annex to Commission Recommendation 2025/3500/EC5.

7. Funds collected through the imposition of fines or periodic penalty payments pursuant to this Article shall contribute to the general budget of the Union.

(4) Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Though SMCs and SMEs have different operational and financial capabilities, the challenges they face in relation to administrative burden are in some cases similar, leading to a need for a number of adjustments concerning the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs. In all cases, such an extension must follow a strictly proportionate approach, seeing as SMEs and SMCs are two different categories of enterprises; this approach precludes any blanket uniform treatment and, on the contrary, requires that the differences between SMEs and SMCs be emphasized in the definition of model standards, guidelines or terms for contracts for the purposes of this Regulation. For the purposes of legal certainty and in order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4 and Annex to Commission Recommendation 2025/3500/EC5.

8. The powers conferred on the AI Office by this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the infringement is committed. However, in the case of continuing or repeated infringements, the limitation period shall begin to run on the day on which the infringement ceases.

_________________

The power of the AI Office to enforce decisions taken pursuant to this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the decision becomes final.

_________________

The implementing act referred to in Article 75d(3) shall specify the first and second subparagraphs of this paragraph, including the circumstances in which the limitation periods shall be interrupted.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, pp. 36–41, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

9. Where the AI Office determines that there are no grounds to adopt a decision of non-compliance, it shall close the proceeding by a decision. That decision shall apply with immediate effect.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

Article 75d

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

Safeguards and further specification

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

1. Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to operators subject to the AI Office’s competence pursuant to Article 75(1) of this Regulation, without prejudice to more specific procedural rights provided for in this Regulation.

Justification

2. The rights of defence and of access to the file of operators falling within the scope of Article 75(1) shall be fully respected in proceedings. In view of the possible adoption of decisions on the basis of Article 75c(1), those operators shall be entitled to have access to the AI Office file under the terms of a negotiated disclosure, subject to the legitimate interest of the operator or other person concerned in the protection of their business secrets. The AI Office shall have the power to adopt decisions setting out such terms of disclosure in the case of disagreement between the parties. The right of access to the file shall not extend to confidential information and internal documents of the AI Office, the Board, competent market surveillance authorities or other public authorities of the Member States. In particular, the right of access shall not extend to correspondence between the AI Office and those authorities. Nothing in this paragraph shall prevent the AI Office from disclosing and using information necessary to prove an infringement.

Extending SME-specific regulations to SMCs should not be the norm; rather, it is fundamental that such harmonisation be exceptional and implemented solely in relation to specific provisions outlined by the AI Act. Treating SMCs and SMEs in the same way entails the inevitable risk of creating a number of competition- and competitiveness-related imbalances that will harm the undertakings that are genuinely the smallest, especially micro-enterprises.

3. The Commission may adopt implementing acts concerning the practical arrangements for access to the file and the negotiated disclosure of information provided for in paragraph 2.

Amendment 4

4. The AI Office shall publish the decisions it adopts pursuant to Articles 75b and 75c. Such publication shall state the names of the parties and the main content of the decision, including any penalties imposed. The publication shall have regard to the rights and legitimate interests of any person concerned in the protection of their confidential information.’;

Proposal for a regulation

(33) in Article 76(1), the following subparagraph is added:

Recital 4 a (new)

‘Where testing in real world conditions is based on Article 60a, any reference to a market surveillance authority in this Article shall be construed as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I, and references to Article 60 shall be construed as references to Article 60a, as appropriate.’;

Text proposed by the Commission

(34) Article 77 is amended as follows:

Amendment

(4a) AI agents should constitute a new category of artificial intelligence applications that can execute sophisticated real-world operations rapidly and with reduced human oversight, including those of dual-use nature covered by Article 2(3) of Regulation (EU) 2024/1689. While conventional AI systems deliver outputs like forecasts, generated content, suggestions or judgments, AI agents distinguish themselves through their capacity to carry out concrete actions autonomously. These features can exacerbate associated risks for consumers stemming from the placing on the market, the putting into service or the use of AI agents. To enhance legal clarity, it is important to clarify that AI agents fall within the definition of AI systems in Article 3, point (1), of Regulation (EU) 2024/1689, while keeping in place a risk-based and future-proof regulatory approach.

(a) the heading is replaced by the following:

Amendment 5

‘Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities’;

Proposal for a regulation

(b) paragraph 1 is replaced by the following:

Recital 4 b (new)

‘1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to request and access any information or documentation created or maintained from the relevant market surveillance authority pursuant to this Regulation in accessible language and machine-readable format by electronic means where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. This Article is without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates.’;

Text proposed by the Commission

(c) the following paragraphs are inserted:

Amendment

‘1a. Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary and without undue delay.

(4b) To ensure that SMEs and startups can get an early understanding of their risk classification, the Commission and Member States should provide information assistance in a comprehensible manner, including through initiatives such as the AI Act Service Desk.

1b. Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall cooperate closely and provide each other with the mutual assistance necessary to fulfil their respective mandates, with a view to ensuring the coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures, while respecting their respective competences, tasks, powers and independence. This shall include, in particular, exchange of information where necessary for the effective supervision or enforcement of this Regulation and the respective other Union legislation.

Amendment 6

▌ ’;

Proposal for a regulation

(35) in Article 95, paragraph 4 is replaced by the following:

Recital 5

‘4. The AI Office and the Member States shall take into account the specific interests and needs of ▌ SMEs, including start-ups, and SMCs, when encouraging and facilitating the drawing up of codes of conduct.’;

Text proposed by the Commission

(36) in Article 96, paragraph 1 is amended as follows:

Amendment

(a) in the first subparagraph, point (a) is replaced by the following:

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

‘(a) the application of the requirements and obligations referred to in Articles 8 to 15 and in Articles 25 and 26;’;

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives, without, however, completely eliminating the obligation of providers and implementers of AI systems to take, likewise, the necessary measures to ensure a sufficient level of knowledge in the field of AI of their staff in order to play responsible roles. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

(b) in the first subparagraph, the following point is added:

Amendment 7

‘(g) the practical implementation of Article 8(2), Article 9(10) and Article 17(3) in accordance with the principle of complementarity and proportionality, with a view to ensuring consistency, avoiding duplication and minimising additional burdens when complying with the requirements of this Regulation and the requirements of the Union harmonisation legislation listed in Section A of Annex I; such guidelines shall be published by 1 August 2027.’;

Proposal for a regulation

(c) the second subparagraph is replaced by the following:

Recital 5 a (new)

‘When issuing such guidelines, the Commission shall involve the Board and pay particular attention to the needs of ▌ SMEs, including start-ups, and SMCs, of local public authorities and of the sectors most likely to be affected by this Regulation.’;

Text proposed by the Commission

(37) Article 97 is amended as follows:

Amendment

(a) paragraphs 2 and 3 are replaced by the following:

(5a) Recent developments have demonstrated the incompatibility of certain AI practices with the Union's fundamental rights framework while increasing legal uncertainty regarding them. AI systems that alter, manipulate or artificially produce images or videos depicting natural persons engaged in sexually explicit activities, displaying their intimate body parts or undresses a person without consent cause harm to victims and violate fundamental rights to dignity and privacy. While Regulation (EU) 2024/1689 establishes a framework for prohibited AI practices, the effective protection of persons, particularly women and minors who are disproportionately targeted, requires the explicit prohibition of such AI systems. Whereas Article 112 of Regulation (EU) 2024/1689 obliges the Commission to assess, on an annual basis, the necessity of amendments to the list of prohibited practices laid down in Article 5 of that Regulation and the list set out in Annex III of that Regulation, and to submit the findings of that assessment to the European Parliament and the Council, the proliferation of technologies, marketed as 'nudification' applications, has created an urgent need for explicit regulatory prohibition. This is without prejudice towards the rights, freedoms and principles recognised by Article 6 TEU and the Charter of Fundamental Rights of the European Union, and the exercise of the rights guaranteed therein to freedom of expression and information and the freedom of the arts and sciences.

‘2. The power to adopt delegated acts referred to in Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) shall be conferred on the Commission for a period of five years from 1 August 2024. The power to adopt delegated acts referred to in Article 2(13) and Article 30(2) shall be conferred on the Commission for a period of five years from … [the date of entry into force of this amending Regulation]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension no later than three months before the end of each period.

Amendment 8

3. The delegation of power referred to in Article 2(13), Article 6(6) and (7), Article 7(1) and (3), Article 11(3), Article 30(2), Article 43(5) and (6), Article 47(5), Article 51(3), Article 52(4) and Article 53(5) and (6) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of power specified in that decision. It shall take effect the day following that of its publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.’;

Proposal for a regulation

(b) paragraph 6 is replaced by the following:

Recital 6

‘6. Any delegated act adopted pursuant to Article 2(13), Article 6(6) or (7), Article 7(1) or (3), Article 11(3), Article 30(2), Article 43(5) or (6), Article 47(5), Article 51(3), Article 52(4) or Article 53(5) or (6) shall enter into force only if no objection has been expressed by either the European Parliament or the Council within a period of three months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by three months at the initiative of the European Parliament or of the Council.’;

Text proposed by the Commission

(38) Article 99 is amended as follows:

Amendment

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. Discrimination might result from the bias in AI models and AI systems other than high-risk AI systems for which of Regulation (EU) 2024/1689 already provides a legal basis authorising the processing of special categories of personal data under Article 9(2), point (g), of Regulation (EU) 2016/679 of the European Parliament and of the Council6 . Given that discrimination might result also from those other AI systems and models, it is therefore appropriate that Regulation (EU) 2024/1689 should provide for a legal basis for the processing of special categories of personal data also by providers and deployers of other AI systems and AI models as well as deployers of high-risk AI systems. The legal basis is established in compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council7 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council8 provides a legal basis allowing, where necessary for the detection and removal of bias, the processing of special categories of personal data by providers and deployers of all AI systems and models, subject to appropriate safeguards that complement Regulations (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.

(a) paragraph 1 is replaced by the following:

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 already provides a legal basis authorising providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. That legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects might also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. In each of those further cases, a substantial public interest exists to permit processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it applies to the providers and deployers of other AI systems and AI models. That legal basis should be subject to the same limitations, conditions and safeguards as set out in the existing Article 10(5) of Regulation (EU) 2024/1689, thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council[2]. Furthermore, to enable providers of high risk AI systems to lawfully undertake bias detection and mitigation activities in preparation for compliance with the high-risk requirements, including Article 10(2), points (f) and (g) of Regulation (EU) 2024 /1689 , the legal basis established by Article 4a of that Regulation should apply from the entry into application of this Regulation.

‘1. In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. The Member States shall take into account the interests of ▌ SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties.’;

(b) in paragraph 4, the following point is inserted:

‘(da) obligations of providers and operators pursuant to Article 25(2) and (4)’;

(c) the following paragraph is inserted:

‘6a. In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower.’;

(39) Article 111 is amended as follows:

(a) paragraph 2 is replaced by the following:

‘2. Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.’;

(b) the following paragraph is added:

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026. ▌’;

(40) in Article 113, the third paragraph is amended as follows:

(a) point (a) is replaced by the following:

‘(a) Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026;’;

(b) point (c) is replaced by the following:

‘(c) Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from:

(i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and

(ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;’;

(c) the following point is added:

‘(d) Articles 102 to 110 shall apply from … [the date of entry into force of this amending Regulation].’;

(41) Annex I is amended as follows:

(a) in Section A, point 1 is deleted;

(b) in Section B, the following point is added:

‘21. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC (OJ L 165, 29.6.2023, p. 1).’;

(42) in Annex VIII, section B, points 7 and 9 are deleted;

(43) the following Annex is added:

‘Annex XIV

The list of codes, categories and corresponding types of AI systems for the purpose of the notification procedure referred to in Article 30 specifying the scope of the designation as notified bodies

1. Introduction

Conformity assessment of high-risk AI systems pursuant to this Regulation may require the involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated in accordance with this Regulation may carry out conformity assessments and only for the activities related to the types of AI systems concerned. The list of codes, categories, and corresponding types of AI systems sets the scope of the designation of conformity assessment bodies notified under Article 30.

2. List of Codes, categories, and corresponding AI systems

a. AI systems subject to Annex I

AIA Code

AIP 0102

AI systems subject to point 2 of Section A of Annex I

AIP 0103

AI systems subject to point 3 of Section A of Annex I

AIP 0104

AI systems subject to point 4 of Section A of Annex I

AIP 0105

AI systems subject to point 5 of Section A of Annex I

AIP 0106

AI systems subject to point 6 of Section A of Annex I

AIP 0107

AI systems subject to point 7 of Section A of Annex I

AIP 0108

AI systems subject to point 8 of Section A of Annex I

AIP 0109

AI systems subject to point 9 of Section A of Annex I

AIP 0110

AI systems subject to point 10 of Section A of Annex I

AIP 0111

AI systems subject to point 11 of Section A of Annex I

AIP 0112

AI systems subject to point 12 of Section A of Annex I

b. AI systems subject to point 1 of Annex III

AIA Code

AIB 0201

Remote biometric identification systems

AIB 0202

Biometric categorisation AI systems

AIB 0203

Emotion recognition AI systems

3. AI technology-specific codes

a. Symbolic AI and expert systems

AIA Code

AIH 0101

AI systems based on symbolic AI, expert and knowledge-based systems, and AI systems based on search and optimisation

b. Machine learning, excluding generative AI and general-purpose AI systems

AIA Code

AIH 0201

AI systems that process structured data

AIH 0202

AI systems that process signal and audio data

AIH 0203

AI systems that process text data

AIH 0204

AI systems that process image and video

AIH 0205

AI systems that learn from their environment, excluding AI systems covered under AIH 0401

c. AI systems based on general-purpose AI models or generative AI

AIA Code

AIH 0301

generative AI systems, including AI systems based on general-purpose AI models

d. Emerging AI technologies

AIA Code

AIH 0401

AI systems based on other emerging AI technologies not covered by other codes, including Agentic AI

3. Application for designation

Conformity assessment bodies shall use the lists of codes, categories and corresponding types of AI systems set out in this Annex when specifying the types of AI systems in the application for designation referred to in Article 29. ▌’

Article 2 Amendments to Regulation (EU) 2018/1139

Regulation (EU) 2018/1139 is amended as follows:

(1) in Article 27, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence (AI) systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council* , the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

__________________

* Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).’;

(2) in Article 31, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’;

(3) in Article 32, the following paragraph is added:

‘3. When adopting delegated acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’;

(4) in Article 36, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’;

(5) in Article 39 the following paragraph is added:

‘3. When adopting delegated acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’;

(6) in Article 50, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’;

(7) in Article 53, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning AI systems which are safety components within the meaning of Regulation (EU) 2024/1689, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account. ▌’

Article 3 Amendments to Regulation (EU) 2023/1230

Regulation (EU) 2023/1230 is amended as follows:

(1) in Article 8, the following paragraphs are added:

‘The Commission shall adopt delegated acts in accordance with Article 47 of this Regulation to amend Annex III to this Regulation by adding health and safety requirements in respect of Artificial Intelligence (AI) systems that are classified as high-risk pursuant to Article 6(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council* due to the fact that they are a safety component in a product covered by this Regulation, or they are themselves a product covered by this Regulation. Those requirements shall ensure that the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 are reflected.

When adopting the delegated acts referred to in the third paragraph, the Commission shall take into account the objectives of Regulation (EU) 2024/1689 and ensure a level of protection consistent with that Regulation. Those delegated acts shall apply by 2 August 2028.

__________________

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

* Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).’;

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(2) in Article 20, the following paragraph is added:

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

‘10. Until harmonised standards or common specifications are referenced or adopted pursuant to this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards referenced, or common specifications adopted pursuant to Articles 40 and, respectively, 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III to this Regulation as regards high-risk AI systems.’;

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(3) Article 47 is amended as follows:

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(a) paragraphs 2 and 3 are replaced by the following:

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

‘2. The power to adopt delegated acts referred to in Article 6(2) and (11) and Article 7(2) , shall be conferred on the Commission for a period of five years from 19 July 2023. The power to adopt delegated acts referred to in Article 8, third paragraph, shall be conferred on the Commission for a period of five years from … [the date of entry into force of this amending Regulation]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension no later than three months before the end of each period.

Amendment 9

3. The delegation of power referred to in Article 6(2) and (11), Article 7(2) and Article 8, third paragraph, may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.’;

Proposal for a regulation

(b) paragraph 6 is replaced by the following:

Recital 6 a (new)

‘6. A delegated act adopted pursuant to Article 6(2) and (11), Article 7(2) or Article 8, third paragraph, shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.’;

Text proposed by the Commission

Article 4 Entry into force and application

Amendment

This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union.

(6a) To encourage the use of new technologies for safer products and to avoid duplicative requirements in the New Legislative Framework and Regulation (EU) 2024/1689, the safety component aspect of the high risk-classification should be clarified. Additional layers of safety, where a product is already deemed safe and compliant according to product-specific rules and where the AI embedded system does not serve a safety function to the product, should not automatically lead to designation of the AI system as high-risk.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Amendment 10

Done at …,

Proposal for a regulation

For the European Parliament For the Council

Recital 8 a (new)

The President The President

Text proposed by the Commission

Amendment

(8a) Regulations (EU) 2024/1689 and (EU) 2024/2847 are complementary laws that ensure the safety and cybersecurity of products with digital elements. It is necessary to ensure alignment of those Regulations to allow for their smooth interplay. Where those high-risk AI systems fulfil the essential cybersecurity requirements set out in this Regulation, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under this Regulation.

Amendment 11

Proposal for a regulation

Recital 9

Text proposed by the Commission

Amendment

(9) To streamline compliance and reduce the associated costs, providers of AI systems should not be required to register AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation. Given that such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons, imposing registration requirements would constitute a disproportionate compliance burden. Nevertheless, a provider who considers that an AI system falls under Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

deleted

Amendment 12

Proposal for a regulation

Recital 10

Text proposed by the Commission

Amendment

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In addition, it is appropriate that the AI Office establishes an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

Amendment 13

Proposal for a regulation

Recital 20

Text proposed by the Commission

Amendment

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 6 months for providers who have already placed their systems on the market before the 2 August 2026.

deleted

Amendment 14

Proposal for a regulation

Recital 22 a (new)

Text proposed by the Commission

Amendment

(22a) To ensure a sufficient degree of legal clarity in the event of continued delays in the availability of harmonised standards, it is necessary to mitigate potential legal uncertainty resulting from their absence. To that end, the Commission should be required to adopt common specifications by 2 December 2027. This deadline aligns with the deferred application date of Chapter III, Sections 1, 2, and 3, of Regulation (EU) 2024/1689 for AI systems classified as high-risk under Article 6(1) and Annex I of that Regulation, which has also been postponed to 2 December 2027. Additionally, the Commission should be required to issue standardisation requests covering the obligations set forth in Chapter V, Sections 2 and 3, of that Regulation by 2 December 2027, as it has not proceeded without undue delay.

Amendment 15

Proposal for a regulation

Recital 23

Text proposed by the Commission

Amendment

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity on how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

Amendment 16

Proposal for a regulation

Recital 23 a (new)

Text proposed by the Commission

Amendment

(23a) This Regulation shall not alter Regulation (EU) 2024/1689 as regards the scope, classification or compliance timelines applicable to AI systems.

Amendment 17

Proposal for a regulation

Article 1 – paragraph 1 – point 2 a (new)

Regulation (EU) 2024/1689

Article 2 – paragraph 10 a (new)

Text proposed by the Commission

Amendment

(2a) in Article 2, the following paragraph is inserted:

10a. This Regulation does not apply to AI systems or AI models that are only used intra-group and not consumer-facing with no impact on end-users or natural persons. Such activities shall be conducted in accordance with applicable Union law. The prohibited practices as outlined in Article 5 shall not be covered by that exclusion.

Amendment 18

Proposal for a regulation

Article 1 – paragraph 1 – point 2 b (new)

Regulation (EU) 2024/1689

Article 2 a (new)

Text proposed by the Commission

Amendment

(2b) the following article is inserted:

'Article 2a

Proportionality and Technological Neutrality

Without prejudice to explicit prohibitions laid down in Article 5 of this Regulation and to the protection of fundamental rights, the national competent authorities, the AI Office and the Commission shall interpret, implement, apply and enforce this Regulation in a manner that:

a) ensure proportionality, legal certainty and technological neutrality; and

b) minimise administrative and compliance burdens on economic operators

while ensuring that the requirements of this Regulation, including any secondary legislation resulting from this Regulation, do not exceed what is strictly necessary to achieve the objectives of this Regulation.'

Amendment 19

Proposal for a regulation

Article 1 – paragraph 1 – point 2 c (new)

Regulation (EU) 2024/1689

Article 3 – point 1 a (new)

Text proposed by the Commission

Amendment

(2c) in Article 3, the following point is inserted:

(1a) ''autonomy' means the ability of the artificial intelligence system to operate, within constraints, without human guidance or intervention;'

Amendment 20

Proposal for a regulation

Article 1 – paragraph 1 – point 2 d (new)

Regulation (EU) 2024/1689

Article 3 – point 3

Present text

Amendment

(2d) Article 3, point (3) is replaced by the following:

(3) ‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;

(3) 'provider' means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge, excluding those that perform fine-tuning, personalisation and technical adaptation operations on AI systems on behalf of third-party clients by using data provided by the latter, unless those operations result in substantial modifications to, or changes in the intended purpose of, the AI systems in question;

Justification

The current Regulation considers small enterprises that perform fine-tuning operations locally (i.e. on client servers) to be providers, thereby imposing totally disproportionate legal responsibilities and certification burdens on them. Among other things, this state of affairs prompts enterprises to forego local fine-tuning and instead perform this operation by means of application programming interfaces (APIs) supplied by (generally non-EU-based) large providers of general-purpose models with a view to retaining their status as deployers.

Amendment 21

Proposal for a regulation

Article 1 – paragraph 1 – point 2 e (new)

Regulation (EU) 2024/1689

Article 3 – point 14

Present text

Amendment

(2e) in Article 3, point (14) is replaced by the following:

(14) ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property;

(14) '‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, and the failure or malfunctioning of which endangers the health and safety of persons or property;'

Amendment 22

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4 – paragraph 1

Text proposed by the Commission

Amendment

‘The Commission and Member States shall encourage providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.;

‘The Commission and Member States shall support providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.'

Amendment 23

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4a – paragraph 1 – introductory part

Text proposed by the Commission

Amendment

1. To the extent necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

1. To the extent that is strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Amendment 24

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4a – paragraph 2

Text proposed by the Commission

Amendment

2. Paragraph 1 may apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where necessary and proportionate if the processing occurs for the purposes set out therein and provided that the conditions set out under the safeguards set out in this paragraph.;

2. Paragraph 1 may also apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where strictly necessary and proportionate for bias detection and correction, subject to all the safeguards set out in this Article and applicable Union data protection law.

This paragraph does not create any obligation to conduct such bias detection and correction with special categories of personal data.

Amendment 25

Proposal for a regulation

Article 1 – paragraph 1 – point 5 a (new)

Regulation (EU) 2024/1689

Article 5 – paragraph 1

Text proposed by the Commission

Amendment

(5 a) In Article 5(1), first subparagraph, the following points are added:

‘(ha) the placing on the market, the putting into service or the use of an AI system that can generate, alter or reproduce sexually or nude content in violation of the dignity, sexual integrity or consent of natural persons, including through the use of deep fake or other synthetic media techniques;

(hb) the placing on the market, the putting into service or the use of an AI system that generates child sexual abuse material, regardless of the nature or origin of the underlying content.’

Amendment 26

Proposal for a regulation

Article 1 – paragraph 1 – point 5 b (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 1

Present text

Amendment

(5b) in Article 6, paragraph 1 is replaced by the following:

1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

'1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(a) the AI system is intended to be used as a safety component of a product and the AI functionality has an impact on the safety of the overall system, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

A lack of harmonised standards or part thereof, the references of which have been published in the Official Journal of the European Union, leading to third-party conformity assessment according to the applicable Union harmonisation legislation in Annex I, can in itself not lead to a product or AI system being classified as high-risk.'

Amendment 27

Proposal for a regulation

Article 1 – paragraph 1 – point 5 c (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 3 – subparagraph 1

Present text

Amendment

(5c) In Article 6, paragraph 3, the first subparagraph is replaced by the following:

By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.

'By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making or by ensuring meaningful human intervention or review. '

Amendment 28

Proposal for a regulation

Article 1 – paragraph 1 – point 6 a (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 5 a (new)

Text proposed by the Commission

Amendment

(6a) In Article 6, the following paragraph is inserted:

5a. By way of derogation from the previous paragraphs, a high-risk AI system that is developed for internal use and is employed accordingly by a micro-enterprise to optimise its company processes shall not be subject to the obligations set out in Chapter III, Sections 2 and 3, provided that:

(a) the system is neither put on the market nor made available to third parties;

(b) the system does not process the personal data of external subjects;

(c) the system does not fall under the categories set out in Annex III, points 1,2,6 and 8;

(d) the system is only used by members of staff operating devices owned or controlled by the enterprise;

(e) the system does not implement any of the prohibited practices set out in Article 5.

Micro-enterprises making use of the derogation set out in the first subparagraph shall maintain simplified documentation in accordance with the template set out in Annex IV and shall make it available to the competent authorities upon request.

Justification

Micro-enterprises (companies with fewer than 10 employees and an annual turnover that does not exceed EUR 2 million, see Commission Recommendation 2003/361/EC of 6 May 2003) often use AI tools for simple international automation processes (stock management, sales projections, shift optimisation). Making these undertakings subject to the same obligations as multinational corporations or SMCs is disproportionate and discourages digital uptake. The internal use exemption, combined with proportionate guarantees, drastically reduces red tape while maintaining essential protections.

Amendment 29

Proposal for a regulation

Article 1 – paragraph 1 – point 6 b (new)

Regulation (EU) 2024/1689

Article 9 – paragraph 2 – point b

Present text

Amendment

(6a) in Article 9(2), point b is replaced by the following:

(b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;

'(b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse, including cybersecurity specific threat modelling;'

Amendment 30

Proposal for a regulation

Article 1 – paragraph 1 – point 8 a (new)

Regulation (EU) 2024/1689

Article 11 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(8a) in Article 11, the following paragraph is inserted:

'1a. The Commission’s simplified form shall be digital-by-default, machine-readable, interoperable (so the same info can be reused for other reporting/authority requests), and enable pre-filling /re-use of previously submitted information.'

Amendment 31

Proposal for a regulation

Article 1 – paragraph 1 – point 9 a (new)

Regulation (EU) 2024/1689

Article 17 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(9a) In Article 17, the following paragraph is added:

'2a. If the provider is an SMC or an SME, including start-ups, the national authorities shall provide appropriate guidance and advice, so that the necessary technical documentation and quality management system requirements are tailored to the organisational size and capacity of these categories of providers;'

Amendment 32

Proposal for a regulation

Article 1 – paragraph 1 – point 12 a (new)

Regulation (EU) 2024/1689

Article 40 – paragraph 2 – subparagraph 1

Present text

Amendment

(12a) In Article 40, paragraph 2, the first subparagraph is replaced by the following:

In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.

‘In accordance with Article 10 of Regulation (EU) (No) 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, by 2 December 2027, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3 of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.'

Amendment 33

Proposal for a regulation

Article 1 – paragraph 1 – point 12 b (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 – introductory part

Text proposed by the Commission

Amendment

(12b) In Article 41, the introductory wording is replaced by the following:

1. The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:

‘1. The Commission shall adopt implementing acts by 2 December 2027 establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:’

Amendment 34

Proposal for a regulation

Article 1 – paragraph 1 – point 12 c (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(12c) in Article 41, the following paragraph is inserted:

‘1a. When there is no harmonised standard that enable compliance with the essential requirements set out in Section 2 of this Chapter, and no reference in the Official Journal of the European Union is expected to be published within a reasonable period, the Commission shall by means of implementing acts adopt common specifications in order to address an urgent concern with regard to non-compliant AI systems which cannot be adequately mitigated by alternative measures. A situation shall be considered to constitute an urgent concern when the suspension of cooperation with international standardisation organisations impedes the development of relevant harmonised standards by European standardisation organisations. In such a situation the Commission shall adopt common specifications only after prior authorisation of the Council. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). When preparing those implementing acts, the Commission shall be assisted by an expert group that includes relevant stakeholder representatives.

Amendment 35

Proposal for a regulation

Article 1 – paragraph 1 – point 12 d (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 b (new)

Text proposed by the Commission

Amendment

(12d) in Article 41, the following paragraph is inserted:

‘1b. The Commission shall provide the European Parliament, in a timely manner, with all relevant information concerning the implementing acts referred to in paragraph 1. That shall include, in particular, details on the drafting process of the implementing act, details on the composition of the expert groups supporting the process, details on the timeline and, where the drafting of an implementing act is outsourced, information on the main contractual aspects of such outsourcing, including the name of the entity responsible for the drafting, the total value of the contract and its duration.’

Amendment 36

Proposal for a regulation

Article 1 – paragraph 1 – point 12 e (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 6

Text proposed by the Commission

Amendment

(12e) in Article 41, paragraph 6 is replaced by the following:

6. Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.

‘6. Where the European Parliament or a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.’

Amendment 37

Proposal for a regulation

Article 1 – paragraph 1 – point 12 f (new)

Regulation (EU) 2024/1689

Article 42 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(12f) In Article 42, the following paragraph is added:

'2a. Where an AI system is subject to the requirements of Regulation (EU) 2024/2847 as well as requirements set out in Article 15 of this Regulation, and where those high-risk AI systems fulfil the essential cybersecurity requirements set out in the Regulation (EU) 2024/2847, they shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under Regulation (EU) 2024/2847.'

Amendment 38

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2024/1689

Article 49 – paragraph 2

Text proposed by the Commission

Amendment

(14) in Article 49, paragraph 2 is deleted;

deleted

Amendment 39

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2024/1689

Article 50 – paragraph 7

Text proposed by the Commission

Amendment

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).;

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).; The Commission shall ensure that any implementing act adopted pursuant to this paragraph is limited to what is strictly necessary to ensure interoperability and effective implementation of the marking obligations.

Amendment 40

Proposal for a regulation

Article 1 – paragraph 1 – point 15 a (new)

Regulation (EU) 2024/1689

Article 50 – paragraph 7 a (new)

Text proposed by the Commission

Amendment

(15a) in Article 50, the following paragraph is added:

'7a. The AI Office, in cooperation with the European Union Agency for Cybersecurity (ENISA), shall develop non-binding technical guidance on emerging AI-specific cybersecurity threats, risks including from autonomous operational capabilities and secure-by-design AI development practices in accordance with the NIS2 and Cyber Resilience Act frameworks.'

Amendment 41

Proposal for a regulation

Article 1 – paragraph 1 – point 16

Regulation (EU) 2024/1689

Article 56 – paragraph 6

Text proposed by the Commission

Amendment

(16) in Article 56(6), the first subparagraph is replaced by the following:

deleted

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;

Amendment 42

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point a

Regulation (EU) 2024/1689

Article 57 – paragraph 3a

Text proposed by the Commission

Amendment

The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.;

‘The AI Office shall also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.’;

Amendment 43

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point b

Regulation (EU) 2024/1689

Article 57 – paragraph 5

Text proposed by the Commission

Amendment

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place.;

Amendment 44

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e

Regulation (EU)2024/1689

Article 57 – paragraph 14

Text proposed by the Commission

Amendment

14. National competent authorities shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.;

14. National competent authorities, the European Commission, the European Data Protection Supervisor and the AI Office shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.

Amendment 45

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e a (new)

Regulation (EU)2024/1689

Article 57 – paragraph 14 a (new)

Text proposed by the Commission

Amendment

(ea) in Article 57 the following paragraph is inserted:

'(14a) The Commission and the AI Office shall ensure transparent and non-discriminatory criteria for accessing the EU-level sandbox and shall support the participation of SMEs and the public administrations of Member States with developing administrative capacity and innovation ecosystems, including by providing technical assistance and procedural guidance.'

Amendment 46

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU)2024/1689

Article 58 – paragraph 1 – point c

Text proposed by the Commission

Amendment

(c) the terms and conditions applicable to the participants;

(c) the terms and conditions applicable to the participants, in particular those concerning SMEs and SMCs;

Amendment 47

Proposal for a regulation

Article 1 – paragraph 1 – point 20 a (new) – point a (new)

Regulation (EU) 2024/1689

Article 62 – paragraph 1 – point d

Present text

Amendment

(20a) Article 62 is amended as follows:

(a) in paragraph 1, point (d) is replaced by the following:

(d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process.

(d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process, including through appropriate dedicated financial support mechanisms to reimburse the cost of SME experts participating in European bodies;

Justification

Compliance with the regulation will depend on the appropriate tools being made available to small businesses for regulatory compliance. In this regard, it is essential to step up support for SMEs in the process of setting authorised standards. As it stands, participation in technical committees is sustainable only for large companies. What is more, it will be essential to relieve SMEs from overly complex audits on open-source components developed by third parties. In this regard, a 'safe harbour' linked to an EU repository must be established.

Amendment 48

Proposal for a regulation

Article 1 – paragraph 1 – point 20 a (new) – point b (new)

Regulation (EU) 2024/1689

Article 62 – paragraph 3 – point d a (new)

Text proposed by the Commission

Amendment

(b) in paragraph 3, the following point is added:

(da) establish and maintain a public repository of certified open-source AI components; also for the purposes of the obligations referred to in Article 16, the use of these components shall be presumed to be consistent with the requirements laid down in Section 2.

Justification

Compliance with the regulation will depend on the appropriate tools being made available to small businesses for regulatory compliance. In this regard, it is essential to step up support for SMEs in the process of setting authorised standards. As it stands, participation in technical committees is sustainable only for large companies. What is more, it will be essential to relieve SMEs from overly complex audits on open-source components developed by third parties. In this regard, a 'safe harbour' linked to an EU repository must be established.

Amendment 49

Proposal for a regulation

Article 1 – paragraph 1 – point 22 – point b

Regulation (EU) 2024/1689

Article 69 – paragraph 3

Text proposed by the Commission

Amendment

(b) paragraph 3 is deleted.

deleted

Amendment 50

Proposal for a regulation

Article 1 – paragraph 1 – point 25 – point b

Regulation (EU)2024/1689

Article 75 – paragraph 1 – subparagraph 1

Text proposed by the Commission

Amendment

Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I, and that model and that system are developed by the same provider, the AI Office shall be exclusively competent for the supervision and enforcement of that system with the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to AI system that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.

Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I, and that model and that system are developed by the same provider, the AI Office shall be exclusively competent for the supervision and enforcement of that system with the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to AI system that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065. The competent national authorities may refer signs of non-compliance or systemic risks that have arisen in their country to the AI Office and the AI Office shall, within a reasonable time, inform the referring authority about follow-up measures. The AI Office shall, in exercising its duties, work with the competent national authorities and with the relevant authorities under Regulation (EU) 2022/2065, in accordance with the principles of proportionality and ne bis in idem.

Justification

While centralised supervision by the AI Office enhances consistency, national competent authorities must retain an effective right to notify potential non-compliance or systemic risks identified on their territory. The amendment strengthens cooperative enforcement without creating duplication of competences or additional administrative burden.

Amendment 51

Proposal for a regulation

Article 1 – paragraph 1 – point 26 – point b

Regulation(EU)2024/1689

Article 77 – paragraph 1

Text proposed by the Commission

Amendment

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and format where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction.;

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have direct access to the technical documentation necessary for the exercise of their duties and shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and format where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction.;

Amendment 52

Proposal for a regulation

Article 1 – paragraph 1 – point 30 – point a

Regulation (EU) 2024/1689

Article 111 – paragraph 2

Text proposed by the Commission

Amendment

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.;

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to providers and deployers of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, they shall be brought into compliance with this Regulation by 31 August 2029.'

Amendment 53

Proposal for a regulation

Article 1 – paragraph 1 – point 30 – point b

Regulation (EU) 2024/1689

Article 111 – paragraph 4

Text proposed by the Commission

Amendment

(b) the following paragraph 4 is added:

deleted

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 February 2027.;’

Amendment 54

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 –paragraph 3 – point d – subparagraph 1 – introductory part

Text proposed by the Commission

Amendment

(d) Chapter III, Sections 1, 2, and 3, shall apply following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available, from the following dates:

(d) Chapter III, Sections 1, 2, and 3, shall apply:

Amendment 55

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 –paragraph 3 – point d – subparagraph 1 –point i

Text proposed by the Commission

Amendment

(i) 6 months after the adoption of that decision as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

deleted

Amendment 56

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 – paragraph 3 – point d – subparagraph 1 – point ii

Text proposed by the Commission

Amendment

(ii) 12 months after the adoption of the decision as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

deleted

Amendment 57

Proposal for a regulation

Article 1 – paragraph 1 – point 31 – point a

Regulation (EU) 2024/1689

Article 113 –paragraph 3 – point d –subparagraph 2 – introductory part

Text proposed by the Commission

Amendment

In the absence of the adoption of the decision within the meaning of subparagraph 1, or where the dates below are earlier than those that follow the adoption of that decision, Chapter III, Sections 1, 2, and 3, shall apply:

deleted

Amendment 58

Proposal for a regulation

Article 1 – paragraph 1 – point 31 a (new)

Regulation (EU) 2024/1689

Article 113 – paragraph 3 –subparagraph 2 a (new)

Text proposed by the Commission

Amendment

(31a) in Article 11 , the following paragraph is added:

By way of derogation from the deadlines referred to in the the third paragraph, micro-enterprises established in the Union shall benefit from an additional transition period of 24 months for the application of the provisions of Chapter II, Sections 1, 2 and 3. During this additional period:

(a) the placing on the market of high-risk AI systems by those undertakings shall continue to be permitted, provided that the supplier demonstrates that it has taken proportionate risk self-assessment measures based on harmonised standards or recognised good practices;

(b) national supervisory authorities shall adopt a non-sanctioning monitoring regime, giving priority to technical assistance and guided correction of non-compliance, without prejudice to provisions on public safety and the protection of fundamental rights;

(c) the Commission shall, within ... [36 months of the date of entry into force of this amending regulation], submit a report on the compliance capacity of micro-enterprises, assessing the need for further support measures or an adjustment of the requirements in accordance with the principle of proportionality;

Justification

Micro-enterprises and smaller enterprises (often made up of one to three individuals) do not have dedicated compliance resources. Often, the owner accumulates technical, commercial and administrative roles. The standard timelines are unrealistic. The extension requested is in line with the precedent set with GDPR: many Member States granted up to 36 months in an effort to provide soft enforcement for SMEs. A 2024 study by the Commission notes that micro-enterprises need 3.5 times longer than large certified companies. A gradual, assisted approach reduces business failures.

Amendment 59

Proposal for a regulation

Article 1 – paragraph 1 – point 31 b (new)

Regulation (EU) 2024/1689

Annex 1: List of Union Harmonisation Legislation

Present text

Amendment

(31b) The Machinery Regulation (EU) 2023/1230 is moved from Annex I Section A to Section B

Annex I

"Annex I

Section A. List of Union harmonisation legislation based on the New Legislative Framework as amended as follows:

(2) Section B, the following points are added from section A:

1. Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);

13. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC"

(32024R1689)

Justification

Particularly in the area of self-learning machines and software, the AI Act contains a number of safety requirements that are already included in the Machinery Regulation. To avoid double regulation, the Machinery Regulation contained in Annex I Section A is to be moved to Section B.

ANNEX: DECLARATION OF INPUT

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that he included in his opinion input on matters pertaining to the subject of the file that he received, in the preparation of the opinion, prior to the adoption thereof in committee, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

Volkswagen

Logitech

DKB

Indeed

Adobe

Vzbv

Mozilla Foundation

Bitkom

Cocir

E-on

Milestones Systems

Volkswagen

German Chamber of Commerce

German Association of Local Public Utilities

Philips

OpenAI

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies

The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that he has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

PROCEDURE – COMMITTEE ASKED FOR OPINION

Title

Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

References

COM(2025)0836 – C10-0304/2025 – 2025/0359(COD)

Committee(s) responsible

Date announced in plenary

IMCO

19.1.2026

LIBE

19.1.2026

Opinion by

Date announced in plenary

JURI

19.1.2026

Rapporteur for the opinion

Date appointed

Sergey Lagodinsky

3.12.2025

Rule 59 – Joint committee procedure

Date announced in plenary

19.1.2026

Discussed in committee

12.2.2026

Date adopted

24.2.2026

Result of final vote

+:

–:

0:

18

6

0

FINAL VOTE BY ROLL CALL BY THE COMMITTEE ASKED FOR OPINION

Key to symbols:

18.3.2026

LETTER OF THE COMMITTEE ON TRANSPORT AND TOURISM

Ms Anna Cavazzini

Chair

Committee on the Internal Market and Consumer Protection

BRUSSELS

Mr Javier Zarzalejos

Chair

Committee on Civil Liberties, Justice and Home Affairs

BRUSSELS

Subject: Opinion on Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (COM(2025)0836 – C10-0304/2025– 2025/0359(COD))

Dear Chairs,

Under the procedure referred to above, the Committee on Transport and Tourism (TRAN) has been asked to submit an opinion to the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs. At their meeting of 11 February 2026, TRAN Coordinators decided to send the opinion in the form of a letter. TRAN adopted the following opinion at its meeting of 18 March 2026.

General Remarks

1. The Committee on Transport and Tourism (TRAN) welcomes the objective of simplification under the Digital Omnibus on artificial intelligence (AI), hereafter ‘AI Omnibus’, and recognises the need to support a risk-based EU regulatory framework that is operational and innovation-friendly, while maintaining effective safeguards to ensure that AI systems are safe, transparent, accountable and respectful of fundamental rights.

2. Technological innovation in the EU transport sector is essential to strengthen its global competitiveness, to deliver safe, efficient, and sustainable transport systems for citizens and businesses, and to contribute to improved working conditions for the millions of workers who underpin the European mobility system.

3. AI is emerging as an important enabling technology to support EU transport policy objectives. AI is not a new phenomenon in the transport sector as it has been embedded in driver assistance systems, traffic management and operational optimisation tools for many years now. Examples of safety relevant systems already in use or in project phases include predictive maintenance systems in all transport modes, risk prediction and foreign object detection on runways in aviation, on track obstacle detection and train positioning in rail, autonomous vessels and collision detection systems in the maritime sector as well as advanced driver assistance systems and automated driving in road transport. Its role is expected to expand further, where it demonstrably contributes to improvements in safety and efficiency. In tourism, AI is reshaping the interaction between consumers, intermediaries and businesses.

Impact of the AI Omnibus on transport

4. The AI Omnibus introduces amendments to two key pieces of legislation: the AI Act (Regulation (EU) 2024/1689), which sets the regulatory framework for the use of AI across the EU, and the EASA Basic Regulation (Regulation (EU) 2018/1139) to ensure that AI integration in aviation maintains the highest standards of safety, efficiency, and accountability.

5. The extension of regulatory privileges from small and medium-sized enterprises (SMEs) to small-mid cap companies (SMCs) helps smaller and innovative EU companies active in AI-enabled transport systems, to scale up beyond the start-up phase without facing increased compliance burdens.

6. The extension of real-world testing possibilities to AI systems covered by Annex I, Section B, has a direct operational impact on transport. For technologies such as automated vehicles, exposure to complex traffic environments is essential to achieve technological maturity and for validating safety performance under real-world conditions. Facilitating these controlled operational scenarios is a decisive step toward accelerating the innovation cycle and the subsequent deployment of AI across European transport networks. They complement regulatory sandboxes by enabling a progression from controlled testing environments to real-world conditions once safety has been demonstrated. This approach strengthens public and consumer confidence and supports the rapid development and market uptake of innovative AI applications.

7. The Committee welcomes the amendments proposed by the AI Omnibus to the EASA Basic Regulation. These amendments would ensure that the existing safeguards for the use of high-risk AI systems, as set out in Chapter III, Section 2 of Regulation 2024/1689, also apply to delegated or implementing acts provided for in seven additional articles of the EASA Regulation (Articles 27, 31, 32, 36, 39, 50 and 53). Despite the recent adoption of the AI Act , this update is necessary in light of the accelerating evolution of AI technologies and their potential deployment in additional civil aviation domains, including, for example, the medical assessment of air traffic controllers, ground-handling services and training.

8. Considering these points, the Committee stresses that swift adoption of the updated legal framework is essential to ensure legal certainty and a simplified regulatory environment.

9. TRAN notes that, given that most transport systems already fall under sectoral Union harmonization legislation, the effective implementation of AI safeguards will largely depend on how these requirements interact with and are integrated into existing regulatory frameworks and supervisory practices. It underlines that differences in regulatory structures and capacities across transport modes and Member States may result in uneven application of AI-related safeguards.

AI’s potential for the transport and tourism sectors

10. AI’s success as a key technology for the future of the transport and tourism sectors, contributing to important safety and efficiency gains must also go hand in hand with careful consideration of its social and environmental impacts. In particular, the use of natural resources and the outsourcing of skills and jobs outside Europe are important factors that should be taken into account when evaluating the overall cost–benefit of AI deployment in the sector.

Risks and safeguards

11. The contribution of AI to safety and sustainability will depend on responsible deployment, effective oversight and alignment with broader transport and tourism policy objectives. While AI can support efficiency gains in transport operations, its overall environmental impact must be carefully assessed.

12. The increasing integration of AI systems into transport and tourism operations represents not only technological innovation but also changes in the organisation of work, including the potential to optimise workflows and reduce routine or repetitive tasks. Automated driving systems and remote supervision models may significantly reshape the roles of drivers, dispatchers and operational staff, including through the emergence of remote monitoring, operation or control functions that can be performed from anywhere in the world.

13. As AI deployment progresses, it is important to consider its implications for work organisation, workforce skills and job profiles. Any organisational changes, including new operational and outsourcing models involving third countries, should ensure that the development of AI in the sector does not lead to the relocation of skills and jobs outside the Union and should contribute to upholding high working conditions and standards. Maintaining and developing a strong EU-based jobs and skills ecosystem within the EU is essential to supporting the Union’s strategic autonomy and competitiveness.

Access to funding, capital and scale-up capabilities to support EU AI innovation

14. While the Committee notes that several initiatives exist at EU level that aim to stimulate and accelerate AI innovation in key industrial sectors, particularly in terms of autonomous driving, such as the European Connected and Autonomous Vehicle Alliance and the Autonomous Drive Ambition Cities initiative announced in the Apply AI strategy to accelerate autonomous vehicle deployment, important barriers in accessing capital may hinder European companies from scaling up their businesses to compete on a par with other global companies.

15. While Europe has strong industrial players and innovative technology firms, many companies in AI and transport automation remain in the start-up, early scale-up phase or leave the EU at an early stage. TRAN therefore calls on the Commission and the Member States to examine instruments and mechanisms allowing public-private partnerships and incentivising venture capital to bridge the gap between the start-up and SME phase, while ensuring that public and private investment promotes energy-efficient, safe, interoperable and open AI solutions that strengthen sustainability, resilience and Europe’s technological sovereignty.

Strategic autonomy

16. Given that the AI Act, notably its rules on high-risk systems, affects transport, TRAN calls for coherence with EU transport objectives and digital sovereignty. As AI increasingly becomes integral to critical transport infrastructure, safeguards are needed to protect data sovereignty, avoid strategic dependencies and ensure enforceability of EU law.

17. In procurement for critical infrastructure, authorities should be able to require interoperable solutions, effective cyber security and operational control within the Union to ensure strategic security of supply and resilience.

National fragmentation

18. The Committee emphasises that the EU type-approval framework (Regulation (EU) 2018/858) and the General Safety Regulation (Regulation (EU) 2019/2144) provide a strong harmonised safety regime for the deployment of automated driving and other AI-enabled transport systems.

19. The extension of real-world testing in the AI Omnibus is a welcome step that creates greater opportunities for innovation. Well-designed safeguards help uphold safety standards while reinforcing trust in new AI technologies. Divergent national or regional testing and operational regimes may continue to hinder large-scale testing and deployment. Further harmonisation and convergence would strengthen legal certainty and the functioning of the internal market. Supporting the EU transport sector in fully benefiting from Europe’s increasing digital competitiveness and more integrated data ecosystems is a priority.

Yours sincerely,

Elissavet VozembergVrionidi

ANNEX: DECLARATION OF INPUT

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that she included in her opinion input on matters pertaining to the subject of the file that she received, in the preparation of the opinion, prior to the adoption thereof in committee, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

Bitkom e.V.

Bureau Européen des Unions de Consommateurs

Einride AB

European Transport Safety Council

Robert Bosch GmbH

TUI AG

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies

None

The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that she has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

PROCEDURE – COMMITTEE RESPONSIBLE

Title

Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

References

COM(2025)0836 – C10-0304/2025 – 2025/0359(COD)

Date submitted to Parliament

19.11.2025

Committee(s) responsible

Date announced in plenary

IMCO

19.1.2026

LIBE

19.1.2026

Committees asked for opinions

Date announced in plenary

BUDG

19.1.2026

ITRE

19.1.2026

TRAN

19.1.2026

CULT

19.1.2026

JURI

19.1.2026

Not delivering opinions

Date of decision

BUDG

11.12.2025

ITRE

28.1.2026

Rapporteurs

Date appointed

Arba Kokalari

21.1.2026

Michael McNamara

21.1.2026

Rule 59 – Joint committee procedure

Date announced in plenary

19.1.2026

Date adopted

18.3.2026

Result of final vote

+:

–:

0:

101

9

8

Date tabled

19.3.2026

FINAL VOTE BY ROLL CALL BY THE COMMITTEE RESPONSIBLE

Key to symbols: