Sittings · Compare

What changed

From · agreement provisional · 2026-05-13 CJ40-AG-789081 Proposal for a regulation Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
To · opinion parliamentary committee draft · 2026-02-02 JURI-PA-784179 on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
+366 added · −409 removed · 4 modified paragraphs

13.5.2026

PA_Legam

PROVISIONAL AGREEMENT RESULTING FROM INTERINSTITUTIONAL NEGOTIATIONS

AMENDMENTS

Subject: Proposal for a regulation Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

The Committee on Legal Affairs submits the following to the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs, as the committees responsible:

(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

Amendment 1

The interinstitutional negotiations on the aforementioned proposal for a regulation have led to a compromise. In accordance with Rule 75(4) of the Rules of Procedure, the provisional agreement reproduced below is submitted to the Committee on the Internal Market and Consumer Protection Committee on Civil Liberties, Justice and Home Affairs for decision by way of a single vote.

Proposal for a regulation

2025/0359 (COD)

Recital 4 a (new)

Proposal for a

Text proposed by the Commission

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Amendment

amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

(4a) AI agents should constitute a new category of artificial intelligence applications that can execute sophisticated real-world operations rapidly and with reduced human oversight. While conventional AI systems deliver outputs like forecasts, generated content, suggestions or judgments, AI agents distinguish themselves through their capacity to carry out concrete actions autonomously. To address this potential regulatory gap and provide legal clarity, it would be advisable to amend the definition to expressly include systems that execute autonomous actions under the jurisdiction of Regulation (EU) 2024/1689.

(Text with EEA relevance)

Or. en

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Amendment 2

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Proposal for a regulation

Having regard to the proposal from the European Commission,

Recital 5

After transmission of the draft legislative act to the national parliaments,

Text proposed by the Commission

Having regard to the opinion of the European Economic and Social Committee,

Amendment

Having regard to the opinion of the Committee of the Regions,

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

Acting in accordance with the ordinary legislative procedure,

deleted

Whereas:

Or. en

(1) Regulation (EU) 2024/1689 of the European Parliament and of the Council lays down harmonised rules on artificial intelligence (AI) and aims to improve the functioning of the internal market, to promote the uptake of human-centric and trustworthy artificial intelligence, while ensuring a high level of protection of health, safety and fundamental rights, and supporting innovation. Regulation (EU) 2024/1689 entered into force on 1 August 2024. Its provisions enter into application in a staggered manner, with all rules entering into application by 2 August 2027.

Amendment 3

(2) The experience gathered in implementing the parts of Regulation (EU) 2024/1689 that have already entered into application can inform the implementation of those parts that are yet to apply. In this context, the delayed preparation of standards, which should provide technical solutions for providers of high-risk AI systems to ensure compliance with their obligations under that regulation, and the delayed establishment of the governance and the conformity assessment frameworks at national level result in a compliance burden that is heavier than expected. In addition, consultations of stakeholders have revealed the need for additional measures that facilitate and provide clarification on the implementation and compliance, without reducing the level of protection for health, safety and fundamental rights from AI-related risks that the rules of Regulation (EU) 2024/1689 seek to achieve.

Proposal for a regulation

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective, simple and uniform application of the relevant rules.

Recital 6

(3a) Additionally, it is important that the Commission and Member States’ competent authorities ensure that supervision, enforcement and monitoring of sectorial and national laws do not create overlaps, inconsistent interpretations or divergent enforcement in order to enable AI innovation in the private and public sector.

Text proposed by the Commission

(3b) Regulation (EU) 2024/1689 lays down horizontal rules for AI systems in order to ensure a consistent and high level of protection of public interests as regards health, safety and fundamental rights. For high-risk AI systems referred to in Article 6(1), that Regulation applies in conjunction with the Union harmonisation legislation listed in Section A of Annex I. In certain cases, the Union harmonisation legislation may lay down requirements that achieve the same or a higher level of protection of the relevant public interests as specific requirements or obligations laid down in Regulation (EU) 2024/1689. Where this is the case, it should be possible to limit the application of specific requirements or obligations laid down in Regulation (EU) 2024/1689 in order to facilitate compliance, minimise administrative burden and duplications, while preserving the level of protection ensured by that Regulation. Such limitation should be possible where, and to the extent that, the Union harmonisation legislation listed in Section A of Annex I lays down requirements providing for an equivalent level of protection of health, safety or fundamental rights as the requirement or obligation concerned. The Commission should be empowered to adopt delegated acts to identify such cases, specifying the products concerned, the requirements or obligations that may be limited, and the conditions and scope of any limitation, ensuring that the level of protection provided by Regulation (EU) 2024/1689 is not reduced.

Amendment

(4) Most of the Union companies are small and medium-sized enterprises, the majority of which are micro and small enterprises. Therefore, enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs where appropriate while safeguarding the overarching objectives and level of protection afforded under Regulation (EU) 2024/1689. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC1 and Annex to Commission Recommendation 2025/3500/EC2.

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. Discrimination might result from the bias in AI models and AI systems other than high-risk AI systems for which of Regulation (EU) 2024/1689 already provides a legal basis authorising the processing of special categories of personal data under Article 9(2), point (g), of Regulation (EU) 2016/679 of the European Parliament and of the Council6 . Given that discrimination might result also from those other AI systems and models, it is therefore appropriate that Regulation (EU) 2024/1689 should provide for a legal basis for the processing of special categories of personal data also by providers and deployers of other AI systems and AI models as well as deployers of high-risk AI systems. The legal basis is established in compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council7 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council8 provides a legal basis allowing, where necessary for the detection and removal of bias, the processing of special categories of personal data by providers and deployers of all AI systems and models, subject to appropriate safeguards that complement Regulations (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.

(4a) The notion of ‘safety component’ is decisive for the classification of certain AI systems as high-risk according to Regulation (EU) 2024/1689. Thus, it should be targeted to capture only AI systems which could have an adverse impact on the health and safety of persons or property, in line with the risk-based approach of Regulation (EU) 2024/1689. The definition set out in Article 3(14) of Regulation (EU) 2024/1689 does not provide the necessary clarity to allow providers of AI systems to determine whether an AI system qualifies as a safety component and, as a result, risks leading to a disproportionate scope. It is therefore necessary to amend that definition. First, It is necessary to provide clarity on the concept of safety function. The safety function must be an intended purpose of the system, which is determined by the provider of the system. An AI system fulfils a safety function where its intended purpose, as determined by the provider, is to prevent or mitigate risks to health and safety of persons. In particular, this does not include AI systems which are intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or quality control operations of non-safety related aspects. The mere fact that an AI system is integrated into or operates within a product that is subject to safety regulation does not, in itself, mean that it fulfils a safety function.

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 provides a legal basis authorising providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. That legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects might also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. In each of those further cases, a substantial public interest exists to permit, exceptionally and where strictly necessary, the processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it applies to the providers and deployers of other AI systems and AI models. That legal basis should be subject to the same limitations, conditions and safeguards as set out in the existing Article 10(5) of Regulation (EU) 2024/1689, thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council7 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council8. Furthermore, to enable providers of high-risk AI systems to lawfully undertake bias detection and mitigation activities in preparation for compliance with the high-risk requirements, including Article 10(2), points (f) and (g) of Regulation (EU) 2024/1689, the legal basis established by Article 4a of that Regulation should apply from the entry into application of this Regulation.

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary skills to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a solution imposing stringent obligations to ensure a sufficient level of AI literacy is not suitable for all types of providers and deployers in relation to the promotion of AI literacy. Moreover, data indicates that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require providers and deployers to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The Commission and Member States should support and facilitate those efforts of providers and deployers of AI systems, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other initiatives. European competence frameworks, for example the Digital Competence Framework for Citizens (DigComp) and the AI Literacy Framework for Primary and Secondary Education, could be taken into account in the compliance of the Commission and Member States with this obligation. The European Artificial Intelligence Board (‘Board’) should support the Commission and Member States by adopting recommendations setting out common objectives to be achieved in order to meet their obligation and will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community.

__________________

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 provides a legal basis authorising the providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. This legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects might also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. For example, biases in eligibility or risk-scoring tools used to assess applications for various types of public permits or licences can restrict rights or effectively bar certain groups from access to public services. Accordingly, a substantial public interest exists to permit, exceptionally and where strictly necessary, the processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it also applies to the providers and deployers of other AI systems and AI models. That legal basis should be subject to the same limitations, conditions and safeguards as apply under the existing Article 10(5), thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council2 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council3. Furthermore, to enable providers of high-risk AI systems to lawfully undertake bias detection and mitigation activities in preparation for compliance with the high-risk requirements, including Article 10(2), points (f) and (g), of Regulation (EU) 2024/1689, the legal basis established by Article 4a should apply from entry into application of this Regulation.

__________________

(6a) Article 5 of Regulation (EU) 2024/1689 prohibits certain practices of AI systems that are particularly harmful and abusive, contradict certain Union values and violate certain fundamental rights. Article 5 is to be kept under review, as notably shown by Article 112(1) of that Regulation. In light of technological and societal developments since the adoption of that Regulation, including the deployment and widespread use of AI systems generating non-consensual intimate images, videos, audio and similar material (‘non-consensual intimate material’) and child sexual abuse material, it is necessary to amend that list. Non-consensual intimate material constitutes sexual violence and abuse against individuals, especially women. AI systems that generate or manipulate such material pose a severe risk to health, safety and fundamental rights, including victims’ human dignity, personal autonomy, integrity and private life, with potentially serious lasting psychological and other harms and abuse at scale. The proliferation of such technologies, often described as ‘nudification’ applications, has created an urgent need for explicit regulatory prohibition. Child sexual abuse material, including wholly or partially synthetic material, constitutes a grave threat to the safety and fundamental rights of children. AI systems generating or manipulating such material pose a grave risk to human dignity and the rights of the child, and risk normalising, amplifying and perpetuating sexual violence against children. Accordingly, an amendment to Article 5 of Regulation (EU) 2024/1689 is necessary both to protect women, children, other individuals and society from seriously harmful practices, thereby pursuing the objectives of that Regulation itself, and to bring clarity to providers and deployers as to the scope of their obligations, thereby addressing implementation challenges.

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(6b) It is necessary to define clearly the scope of the prohibition, including in particular the extent of providers’ and deployers’ obligations. This prohibition should not prevent providers from developing technical capabilities of AI systems to generate or manipulate images, videos, audio or similar material. The prohibition should be limited to AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material in two cases concerning providers. First, it should cover systems intended to generate or manipulate such material. Second, it should cover systems where such generation or manipulation is a reasonably foreseeable and reproducible outcome and there are no reasonable and adequate technical safety measures and other safeguards in place, taking into account reasonably foreseeable misuse to reliably prevent, and where necessary correct, that outcome and correct observed or reported misuse, including circumvention of such measures. Technical measures and other safeguards to prevent the generation of such material could include data cleaning, refusal training, prompts safe design and output controls, runtime prompt guardrails, content classification and filtering mechanisms, usage restrictions, abuse detection mechanisms, and notice and action mechanisms. Such preventive measures should be reasonable for the specific AI system, and are considered adequate if they align with the state of the art and demonstrably prevent or sufficiently reduce in each specific case the likelihood of generating or manipulating such material, taking into account known and reasonably foreseeable misuse, including reasonably foreseeable circumvention of the preventive measures without significant technical modification. For providers retaining effective control over the provision of AI systems, for instance through a platform or a web interface, that could include following and reporting methods for misuse cases in full compliance with EU privacy and data protection law. In cases of observed or reported circumvention of the preventive measures or other safeguards, adequate corrective measures must also be taken to the extent that such measures are reasonable, taking into account the specific AI system, including its release and distribution strategy (such as open-source releases). The use of an AI system should be prohibited only where the deployer uses an AI system for the purpose of generating or manipulating non-consensual intimate material or child sexual abuse material, thereby violating the prohibition. This includes cases when a deployer uses or misuses for such purposes AI systems placed on the market or put into service that lack reasonable and adequate preventive measures or when the deployer circumvents the preventive measures mentioned above, or uses for such purposes lawful AI systems not intended to generate or manipulate such material. The prohibition on use therefore does not cover the use of an AI system for other lawful purposes, such as the generation or manipulation of material other than non-consensual intimate material or child sexual abuse material, even in cases where the AI system lacks reasonable and adequate safeguards that should have been put in place by the provider, nor does it cover accidental generation of manipulation of such content. Concerning the prohibition regarding non-consensual intimate material, where an AI system is intended for generation or manipulation of material falling under this prohibition, those measures and other safeguards should include means appropriate for the distribution of the system aimed at enabling the reliable collection and demonstration of consent of the depicted person to such generation or manipulation, in compliance with Regulation (EU) 2016/679. The prohibition regarding non-consensual intimate material should be limited to realistic depictions of intimate parts, notably the genitals, pubic area, anus, exposed buttocks or exposed female breasts, nipples or areolae or of sexually explicit activity. This ‘realism’ refers to the depiction of the person’s face, voice or their body in a credible real-life manner, regardless of the realism of the context of that depiction and of whether it fully corresponds to the actual voice or appearance of the depicted person. Conversely, it excludes cartoonish or physically impossible depictions of a person’s body. The prohibition of non-consensual intimate material does not affect the generation or manipulation of other forms of nude material, such as material that does not depict identifiable natural persons, realistic partially nude depictions where intimate parts are not revealed and sexually explicit activities are not depicted, non-realistic artistic nude works that do not realistically depict identifiable natural persons engaged in sexually explicit activity or depict their intimate parts. It also does not cover generative AI applications where intimate parts are not exposed or, if exposed, this is subject to the freely given, specific, informed, unambiguous and explicit consent of the depicted person (for example try-on applications), medical applications, such as medical anatomical simulations and mammograms).; this prohibition does not preclude he exceptional use of AI systems generating or manipulating nude depictions of the intimate parts of an identifiable person , in accordance with fundamental rights law, including data protection law, and applicable medical law, for the purpose of medical diagnosis and treatment by medical professionals where the person concerned is incapable of consent (for instance in an emergency situation). Finally, the prohibition on ‘manipulating’ non-consensual intimate material excludes cases where pre-existing intimate material is manipulated in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities, for instance the mere enhancement of an existing image depicting intimate parts or video depicting sexually explicit activities, such as changing the background, adding a text heading or enhancing the contrast or the brightness. Conversely, any manipulation of material, including material that already depicts intimate parts or sexually explicit activity, that increases the level of exposure or any depicted intimate parts or alters the nature of any depicted sexually explicit activities falls within this prohibition. The prohibition on child sexual abuse material should not prevent the placing on the market, putting into service or use of an AI system where a ‘without right’ defence applies under national law, as referred to in Article 5(1) of Directive 2011/93/EU. This includes activities carried out under domestic legal powers, such as the legitimate generation, or manipulation of child sexual abuse material by the authorities in order to conduct criminal proceedings or to prevent, detect or investigate crime, as well as the legitimate use of the AI system in the context of red-teaming and evaluation activities for the purpose of assessing the system’s compliance with the prohibition laid down in this Regulation.

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(6c) These prohibitions constitute justified interferences with the freedom of expression and information and the freedom to conduct a business. They pursue weighty objectives of general interest and protect the rights and freedoms of others, including under Articles 1, 3(1), 4, 7, 8, 21, 23 and 24 of the Charter of Fundamental Rights. They are closely tailored. In the case of intimate material, they are limited to realistic depictions of identifiable natural persons; are limited to cases where the AI system is used to increase the level of nudity or explicitness; and exclude generation or manipulation with the person’s consent. Moreover, they are limited to requiring providers to implement ‘reasonable and adequate’ measures and safeguards in the case of systems not intended to generate or manipulate the prohibited material. They are also aligned with existing Union law, including Directive (EU) 2011/93/EU and Directive (EU) 2024/1385. The interferences respect the essence of Articles 11 and 16 of the Charter, are prescribed by law, and are proportionate. The conduct covered by these prohibitions may also violate other law, including criminal law. The prohibitions do not preclude prosecution under that law. However, insofar as an infringement of the prohibitions may result in the imposition of penalties of a criminal nature, which may be laid down pursuant to Article 99(1) of Regulation (EU) 2024/1689, and to the extent that the same conduct is sanctioned under criminal law, including criminal law falling within the scope of Directive 2011/93/EU and Directive (EU) 2024/1385, Member States are required to ensure respect for the ne bis in idem principle in accordance with the Charter of Fundamental Rights.

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(6d) The prohibitions are without prejudice to remedies available under national laws for individuals to protect their fundamental rights, including rights to their image, privacy and human dignity.

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(7) In order to ensure consistency, avoid duplication and minimise administrative burdens in relation to the procedure for designating notified bodies under Regulation (EU) 2024/1689, while maintaining the same level of scrutiny, a single application and a unified assessment procedure should be available for new conformity assessment bodies and notified bodies which are designated under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, such as under Regulations (EU) 2017/745 and (EU) 2017/746 of the European Parliament and of the Council, where such a procedure is established under that Union harmonisation legislation. The single application and unified assessment procedure aims at facilitating, supporting and expediting the designation procedure under Regulation (EU) 2024/1689, while ensuring compliance with the requirements applicable to notified bodies under that Regulation and the Union harmonisation legislation listed in Section A of Annex I thereto. The unified assessment procedure has to be carried out with respect to the tasks and responsibilities of the authorities involved. Moreover, it should be clarified that a conformity assessment body that is designated under more than one Union harmonisation legislation listed in Section A of Annex I should have to apply only once to be designated under this Regulation.

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(8) With a view to ensuring the smooth application and consistency of Regulation (EU) 2024/1689, amendments should be made to it. A technical correction to Article 43(3), first subparagraph, of Regulation (EU) 2024/1689 should be added to align the conformity assessment requirements with the requirements of providers of high-risk AI systems in Article 16 of that Regulation. Moreover, it should be clarified that where a provider of a high-risk AI system is subject to the conformity assessment procedure under Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, and the conformity assessment extends to compliance of the quality management system of that Regulation and of such Union harmonisation legislation, the provider should be able to include aspects related to quality management systems under that Regulation as part of the quality management systems under such Union harmonisation legislation, in line with Article 17(3) of Regulation (EU) 2024/1689. Article 43(3), second subparagraph, should be amended to clarify that notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and which aim to assess high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I to that Regulation, should have the power to assess conformity of high-risk AI systems under certain conditions for 18 months from [the entry into application of this Regulation]. This amendment is without prejudice to Article 28 of Regulation (EU) 2024/1689, thus conformity assessment bodies that wish to be designated and notified under that Regulation can submit an application at any time during and after these 18 months. Moreover, Regulation (EU) 2024/1689 should be amended to clarify that where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and falls within one of the use-cases listed in Annex III to that Regulation, the provider should follow the relevant conformity assessment procedure as required under that relevant harmonisation legislation.

Or. en

(8a) Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847 complement each other so that the safety and cybersecurity of products with digital elements is ensured. Article 12 of Regulation (EU) 2024/2847 lays down that where high-risk AI systems fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847. In order to improve the visibility of the interplay of Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847, the rule of Article 12 of Regulation (EU) 2024/2847 should also be reflected in Regulation (EU) 2024/1689. The interplay between the two instruments should thereby not be affected.

Amendment 4

(8b) In accordance with Article 6(1) of Regulation (EU) 2024/1689, AI systems are classified as high-risk where an AI system that is a component of a product covered by Union harmonisation legislation listed in Section A of Annex I to that Regulation is a safety component and that product requires a third-party conformity assessment. The requirement that such product must require a third-party conformity assessment, however, does not affect the choice of the manufacturer regarding the conformity assessment procedure for such product. Where Union harmonisation legislation listed in Section A of Annex I allows to choose a conformity assessment procedure based on harmonised standards amongst alternative conformity assessment procedures, this possibility remains applicable also to products in which a high-risk AI system is embedded. Article 6(1) of Regulation (EU) 2024/1689 should not be understood to require products in which a high-risk AI system is embedded automatically to undergo a third-party conformity assessment involving a notified body. Where this possibility is provided under Union harmonisation legislation, the provider of the product in which a high-risk AI system is embedded could continue to rely on harmonised standards to comply with the requirements of the Union harmonisation legislation and Regulation (EU) 2024/1689 as a conformity assessment procedure.

Proposal for a regulation

(8d) In order to enhance competitiveness and innovation, it is essential to support economic operators that are required to comply simultaneously with the requirements or obligations set out in Chapter III, Sections 2 and 3, and with relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I. To support and simplify the regulatory compliance pathways of such economic operators, the Commission should request, without undue delay, the European standardisation organisations, to develop standardisation deliverables, including, where appropriate, harmonised standards. Those standardisation deliverables should be based on the harmonised standards published in the Official Journal that give presumption of conformity with the requirements or obligations of this Regulation as well as any relevant harmonised standards published in the Official Journal that give presumption of conformity with the relevant requirements or obligations under the Union harmonisation legislation listed in Annex I. Such standardisation deliverables should help reduce legal uncertainty, avoid unnecessary duplication of conformity assessment activities, testing, documentation and reporting obligations, and lower compliance costs, in particular for small and medium-sized enterprises and start-ups. Timely development of such deliverables is essential in order to provide economic operators with practical and reliable technical solutions, strengthen legal certainty and facilitate the placing on the market, putting into service and use of AI systems in accordance with this Regulation and the Union harmonisation legislation listed in Annex I.

Recital 6 a (new)

(9) To streamline compliance and reduce the associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the required content in Section B of Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate. This simplification will strike a better balance without undermining the protection laid down by Regulation 2024/1689. Such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons. Furthermore, a provider applying Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

Text proposed by the Commission

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document.

Amendment

(10a) In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. To ensure coherence, legal certainty and an efficient allocation of supervisory responsibilities between Union and national levels, the scope of the Union-level AI regulatory sandbox should be clearly defined in order to avoid any overlapping with national AI regulatory sandboxes established pursuant to that Regulation. In order to foster innovation and facilitate the uptake of AI, SMEs, including startups, and SMCs should be provided with priority access to the AI regulatory sandboxes established by the AI Office.

(6a) Recent developments have demonstrated the incompatibility of certain AI practices with the Union's fundamental rights framework. The nudification of women, manipulation of intimate images without consent and generation of child sexual abuse material constitute clear breaches of fundamental rights and Union law. However, significant legal uncertainty remains as to whether AI-powered nudity applications fall within the scope of the AI practices prohibited by Article 5 of Regulation (EU) 2024/1689. Article 112 of that Regulation obliges the Commission to assess, on an annual basis, the necessity of amendments to the list of prohibited practices laid down in Article 5 and the list set out in Annex III, and to submit the findings of that assessment to the European Parliament and the Council. The Commission has failed to meet the deadline for the previous assessment period. For this reason, it seems adequate to specify that prohibited practices under Article 5 include the placing on the market, the putting into service or the use of an AI system that can generate or manipulate sexualised audio, images and videos of individuals, thereby facilitating non-consensual sharing of intimate or manipulated material as defined in Directive (EU) 2024/1385.

(10b) Moreover, the provisions on cooperation between relevant competent authorities for the operation of an AI regulatory sandbox should be clarified in order to ensure their effective functioning. For that reason, the empowerment of the Commission to adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of the AI regulatory sandboxes should be extended to also cover governance aspects of such sandboxes. In addition, where AI regulatory sandboxes involve innovative AI systems that process personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the relevant national supervisory authorities should be associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.

Or. en

(11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions, subject to sufficient safeguards. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation.

Amendment 5

(11a) It is also appropriate to ensure that real-world testing of high-risk AI systems covered by the Union harmonisation legislation listed in Section B of Annex I to that Regulation is possible. Those systems are subject to the requirements and procedures of the relevant sectoral legislation and are, for most purposes, not directly subject to Regulation (EU) 2024/1689. Those sectoral acts will, in due course, incorporate requirements corresponding to the requirements laid down by Articles 8 to15 of that Regulation. Therefore, it is appropriate to ensure that Member States can allow real-world testing of these AI systems with a view to assessing and verifying the conformity of those systems with the requirements of Articles 8 to 15 of the Regulation. If Member States decide to allow such testing, the Regulation should require Member States to adopt frameworks laying down the detailed requirements for such testing. The Regulation should provide for essential elements to be contained in such frameworks. When designing such frameworks, Member States should ensure a high level of protection of health, safety and fundamental rights of natural persons. Before implementing a framework, Member States should notify it to the Commission. The real-world testing should comply with the relevant Union harmonisation legislation listed in Section B of Annex I, including any applicable provisions regarding testing. However, this should not affect the application of the new article regarding real-world testing.

Proposal for a regulation

(12) Article 63 of Regulation (EU) 2024/1689 offers microenterprises who are providers of high-risk AI systems the possibility to benefit from a simplified way to comply with the obligation to establish a quality management system. With a view to facilitating compliance for more innovators, that possibility should be extended to all SMEs, including start-ups.

Recital 9

(12a) In light of the important role of the AI Office for the effective and coordinated governance of Regulation (EU) 2024/1689, as further reinforced by this Regulation, and without prejudice to the next Multiannual Financial Framework and to the budgetary procedure, the Commission should allocate adequate human, financial and technical resources to the AI Office to ensure that it can effectively and within reasonable timeframes perform its tasks in respect of Regulation (EU) 2024/1689, including a sufficient number of permanent personnel with in-depth competences and technical expertise.

Text proposed by the Commission

Amendment

(9) To streamline compliance and reduce the associated costs, providers of AI systems should not be required to register AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation. Given that such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons, imposing registration requirements would constitute a disproportionate compliance burden. Nevertheless, a provider who considers that an AI system falls under Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

deleted

Or. en

Amendment 6

Proposal for a regulation

Recital 10

Text proposed by the Commission

Amendment

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In addition, it is appropriate that the AI Office establishes an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

Or. en

Amendment 7

Proposal for a regulation

Recital 11

Text proposed by the Commission

Amendment

(11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation. To address the specific situation of high-risk AI systems covered the Union harmonisation legislation listed in Section B of Annex I to that Regulation, it is necessary to allow the conclusion of voluntary agreements between the Commission and Member States to enable testing of such high-risk AI systems in real-world conditions.

deleted

Or. en

Amendment 8

Proposal for a regulation

Recital 13

Text proposed by the Commission

Amendment

(13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances. Furthermore, to reduce the procedural complexity, Member States should be able to consult the experts of the scientific panel directly, without involvement of the Commission.

(13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances.

(14) In order to strengthen the governance system for AI systems, it is necessary to clarify the role of the AI Office in monitoring and supervising compliance of such AI systems with Regulation (EU) 2024/1689. The Commission has exclusive competence as regards general-purpose AI models under Article 88 of that Regulation. To increase coherence, clarity and effectiveness, and in light of the reach and impacts of AI systems linked to those competences, the scope of the AI Office’s exclusive competence to supervise systems should be refined. In particular, the AI Office should have exclusive competence over AI systems built on general-purpose AI models not only where both the system and the model are developed by the same provider, but also where they are developed by providers that form part of the same undertaking. However, in certain cases, notably where there is specific sectoral supervision, responsibility should remain with the relevant national competent authority. Accordingly, certain exceptions should be laid down. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. Other deployers should remain subject to national supervision and enforcement. Moreover, this does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689.

Or. en

(15) Additionally, considering the existing supervisory and enforcement system under Regulation (EU) 2022/2065 of the European Parliament and of the Council1, it is appropriate to grant the Commission the powers of a competent market surveillance authority under Regulation (EU) 2024/1689 where an AI system qualifies as a very large online platform or a very large online search engine within the meaning of Regulation (EU) 2022/2065, or where it is embedded in such a platform or search engine. This should contribute to ensuring that the exercise of the Commission’s supervision and enforcement powers under Regulation (EU) 2024/1689 and Regulation (EU) 2022/2065, as well as those applicable to general-purpose AI models integrated into such platforms or search engines, are carried out in a coherent and effective manner. This is also appropriate in light of the importance of such platforms and search engines, in view of their reach, impact and potential to cause complex and large societal harms. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. In the case of AI systems embedded in or qualifying as a very large online platform or search engine, the first point of entry for the assessment of the AI systems are the risk assessment, mitigating measures and audit obligations prescribed by Articles 34, 35 and 37 of Regulation (EU) 2022/2065, without prejudice to the AI Office’s powers to investigate and enforce ex post non-compliance with the rules of this Regulation. In the context of the analysis of this risk assessment, mitigating measures and audits, the Commission services responsible for the enforcement of Regulation (EU) 2022/2065 may seek the opinion of the AI Office on the outcome of a potential earlier or parallel risk assessment carried out under this Regulation and the applicability of prohibitions under this Regulation. In addition, the AI Office and the competent national authorities under (EU) 2024/1689 should coordinate their enforcement efforts with the authorities competent for the supervision and enforcement of Regulation (EU) 2022/2065, including the Commission, in order to ensure that the principles of loyal cooperation, proportionality and non bis in idem are respected, while information obtained under the respective other Regulation would be used for the purposes of supervision and enforcement of the other only provided the undertaking agrees. In particular, those authorities should exchange views regularly and take into account, in their respective areas of competence, any fines and penalties imposed on the same provider for the same conduct through a final decision in proceedings relating to an infringement of other Union or national rules, so as to ensure that the overall fines and penalties imposed are proportionate and correspond to the seriousness of the infringements committed.

Amendment 9

(16) When supervising and enforcing those AI systems, the AI Office has the same role and responsibility as a market surveillance authority under Regulation (EU) 2024/1689. Consequently, it is necessary for the AI Office to have all of the powers and responsibilities that market surveillance authorities have under that Regulation and under Regulation (EU) 2019/1020 (“the general powers”). These must ensure the appropriate and effective enforcement of the requirements and obligations set out by Regulation (EU) 2024/1689. However, it is necessary to specify, complement, and frame certain essential elements and other aspects of the general powers, as well as their safeguards (“the specifying provisions”) . In particular, it is necessary to lay down provisions governing the relationship between the AI Office and national authorities; provisions specifying, complementing, and constraining the powers to request information and conduct on-site inspections; provisions governing investigations, including the possibility for binding commitments; and provisions specifying and constraining power to find non-compliance, impose fines and impose periodic penalties. Where a type of general power has been so specified, the AI Office may not circumvent the conditions and limits of those powers by relying on a related general power. Conversely, types of general power that are not specified and framed in respect of the AI Office – such as the power to adopt measures referred to in Article 16(3) of Regulation (EU) 2019/1020 – may be relied on by the AI Office. As necessary for the good implementation of Regulation (EU) 2024/1689 the Commission may adopt implementing acts further defining the rules and the procedures concerning the application of limitation periods and, the access to the file and the negotiated disclosure of information. In exercising all of these powers, AI Office must comply with the Charter of Fundamental Rights. Additionally, the AI Office is subject to the safeguards and protection for fundamental rights laid down in the specifying provisions.

Proposal for a regulation

(17) In addition to those procedural and fundamental rights safeguards the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020 should apply mutatis mutandis to providers of AI systems, without prejudice to more specific procedural rights provided for in Regulation (EU) 2024/1689. When national market surveillance authorities, through the single point of contact, request that the AI Office takes supervisory and enforcement measures with regards to AI systems under its exclusive supervision, the AI Office shall no later than four months following receipt, inform the single point of contact of its intention to exercise its supervisory and enforcement powers or of its reasons for not exercising its powers. If the AI Office decides to exercise its supervisory and enforcement powers, it shall also inform market surveillance authorities, when suitable through the single point of contact, about the final outcome of such proceedings and of intermediate developments that the AI Officer considers as having a major impact in the investigation, including the decision to open proceedings, to impose a fine pursuant to Article 75d (1c), and to withdraw or recall the AI system from the market.

Recital 22

(18) To enable access to Union market for AI systems which are under the supervision by the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to third party conformity assessment, the Commission should be responsible for pre-market conformity assessments of those systems.

Text proposed by the Commission

(19) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing the cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests without undue delay, and that the involved authorities or bodies should have a mutual obligation to cooperate. It should be clarified that these provisions are without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates. In particular, these provisions do not limit any powers that those authorities and bodies have to request information pursuant to other Union or national law. Accordingly, those authorities and bodies retain any power they have to directly request information from operators pursuant to their mandate or other law.

Amendment

(19a) The requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 address specific risks inherent to AI systems, including bias, unpredictable model behaviour, poor robustness or accuracy, vulnerabilities to attacks by third parties, lack of transparency of AI system. By addressing AI specific risks, that Regulation complements the requirements laid down in Union harmonisation legislation listed in its Annex I, without duplicating them. Regulation (EU) 2024/1689 provides mechanisms for economic operators to minimise the compliance burden. In particular, Articles 8(2) on the interplay with the sectoral legislation, 9(10) on risk management and 17(3) on quality management allow economic operators to integrate, when necessary and appropriate, an assessment of AI specific risks into existing risk and quality management systems. Article 40 further requires the Commission to specify that AI Act harmonised standards must be consistent with standards developed under the Union harmonisation legislation listed in Annex I. The Commission should provide guidelines to assist economic operators of high-risk AI systems covered in Annex I in complying with this Regulation, including by providing guidance on application of Articles 8(2), 9(10) and 17(3) as mechanisms to minimise the compliance burden, in line with principles of complementary and proportionality. These guidelines should be published at the latest on 1 August 2027.

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. Building on experience, it is appropriate to put in place a mechanism that links the entry into application to the availability of measures in support of compliance with Chapter III, which may include harmonised standards, common specifications, and Commission guidelines. This should be confirmed by the Commission by decision, following which the rules obligations for high-risk AI systems should apply after 6 months as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and after 12 months as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to Regulation (EU) 2024/1689. However, this flexibility should only be extended until 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and until 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to that Regulation, by which dates those rules should enter into application in any case. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations.

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 4 months for providers who have already placed their systems on the market before the 2 August 2026.

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. Against thats background, it is appropriate to align the implementation timeline and set the date for the application of Section 1,2 and 3 of Chapter III to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations.

(21) To provide sufficient time for providers of high-risk AI systems and to clarify applicable rules to the AI systems already placed on the market or put into service before the entry into application of relevant provisions of the Regulation (EU) 2024/1689, it is appropriate to clarify the application of a grace period provided in Article 111(2) of that Regulation. The grace period, for the purpose of Article 111(2), should apply to a type and model of AI systems already placed in the market. This means that if at least one individual unit of the high-risk AI system has been lawfully placed on the market or put into service before the date specified in Article 111(2), other individual units of the same type and model of high-risk AI system are subject to the grace period provided in Article 111(2) and thus may continue to be placed on the market, made available or put into service on the Union market without any additional obligations, requirements or the need for additional certification, as long as the design of that high-risk AI system remains unchanged. For the purposes of application of the grace period provided in Article 111(2), the decisive factor is the date on which the first unit of that type and model of high-risk AI system was placed on the market or put into service on the Union market for the first time. Any significant change to the design of that AI system after the date specified in Article 111(2) should trigger the obligation of the provider to comply fully with all relevant provisions of this Regulation applicable to high-risk AI systems, including the conformity assessment requirements.

Or. en

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026.Against this background, it is appropriate that the date for the application of Sections 1, 2 and 3 of Chapter III is set to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations. The timely availability of support instruments, including guidance, relevant standards, common specifications and codes of practice is important in order to facilitate compliance and reduce the risk of divergent interpretation and uneven application of the rules across Member States. In order to ensure legal certainty and to avoid further delays in application of this Regulation, the Commission should ensure that measures in support of compliance with regard to Chapter III, Sections 1, 2, and 3 are in place in due time to ensure timely and effective implementation of the necessary provisions.

Amendment 10

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. Given that the codes of practice referred to in Article 50(7) and 56(6) have limited legal effect, and in particular do not grant a presumption of conformity, it is not strictly necessary for these codes to be approved by an implementing act. Providers should be able to rely, under Article 53(4) and 54(2), on codes of practice assessed as adequate pursuant to Article 56(6). The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply with their obligation under Article 72(1) of Regulation (EU) 2024/1689, the Commission should be required to publish guidance, including a voluntary template, on the post-market monitoring plan by 2 September 2027.

Proposal for a regulation

(23a) The use of artificial intelligence in machinery can help foster innovation and improve the efficiency of those machines. The application of Regulation (EU) 2023/1230 and Regulation (EU) 2024/1689 might lead to overlaps. At the same time, it is important to ensure a level of protection from risks related to the use of artificial intelligence in machinery that is consistent with the level of protection from high-risk AI systems ensured by Regulation (EU) 2024/1689. Given the specific nature of machinery and the machinery sector, and in order to address the need to simplify the regulatory framework for artificial intelligence-enabled machinery, it is appropriate to move to a sectoral approach by moving Regulation (EU) 2023/1230 from section A to section B of the Regulation (EU) 2024/1689. Accordingly, first, the application of Regulation (EU) 2024/1689 to those machines should be limited to the provisions referred to in Article 2(2) of that Regulation. The references to Directive 2006/42/EC in Annex I to Regulation (EU) 2024/1689 should also be moved from Section A to Section B and updated so as to refer to Regulation (EU) 2023/1230. Second, it is crucial to ensure that Regulation (EU) 2023/1230 incorporates essential health and safety requirements for high-risk AI systems classified under Article 6(1) of (EU) Regulation 2024/1689 used as a safety component in machinery or themselves constituting machinery that ensure a level of protection consistent with Regulation (EU) 2024/1689. To that end, the Commission should be required to adopt delegated acts amending Annex III of Regulation (EU) 2023/1230 in order to reflect relevant requirements from Regulation (EU) 2024/1689. The delegated acts should ensure that the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 are reflected. To avoid a legal gap and ensure alignment with the entry into application of the high-risk AI system rules under Regulation (EU) 2024/1689, those delegated acts should apply by 2 August 2028. For those same reasons, manufacturers should be free to rely on harmonised standards or common specifications referenced or adopted under Regulation (EU) 2024/1689 that cover the relevant essential requirements for the presumption of conformity within the meaning of Article 20 Regulation (EU) 2023/1230 until harmonised standards or common specifications regarding AI are referenced or adopted under Regulation (EU) 2023/1230.

Recital 22 a (new)

(24) Conformity assessment of high-risk AI systems under Regulation (EU) 2024/1689 may require involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated under that Regulation may carry out conformity assessments and only for the activities related to the categories and types of AI systems concerned. To enable the specification of the scope of the designation of conformity assessment bodies notified under Article 30 of Regulation (EU) 2024/1689, it is necessary to draw up a list of codes, categories, and corresponding types of AI systems. The list of codes should take into account whether the AI system is a component of a product or itself a product covered by the Union harmonisation legislation listed in Annex I (referred to as ‘AIP codes’, for AI systems covered by product legislation) or a system referred in Annex III of Regulation (EU) 2024/1689, which currently concerns only biometric AI systems referred to in point (1) of Annex III (referred to as ‘AIB codes’, for biometric AI systems). Both AIP codes and AIB codes are vertical codes. The AIP codes are reference codes to provide a link to the Union harmonisation legislation listed in Section A of Annex I of Regulation (EU) 2024/1689. The AIB codes are new codes specific to Regulation (EU) 2024/1689 to identify biometric AI systems referred in paragraph 1 of Annex III of that Regulation. The list of codes should also take into account specific types and underlying technologies of AI systems (referred to as ‘AIH codes’, for horizontal AI system codes). The AIH codes are new AI technology-specific codes and can be applied in conjunction with AIP or AIB vertical codes. The AIH codes cover AI systems’ underlying types and technologies. The list of codes, including three categories, should provide for a multi-dimensional typology of AI systems which ensures that conformity assessment bodies designated as notified bodies are fully competent for the AI systems they are required to assess.

Text proposed by the Commission

(25) Regulation (EU) 2018/1139 of the European Parliament and the Council1 lays down common rules in the field of civil aviation. Article 108 of Regulation (EU) 2024/1689 sets out amendments to Regulation (EU) 2018/1139 to ensure that the Commission takes into account, on the basis of the technical and regulatory specificities of the civil aviation sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 when adopting any relevant delegated or implementing acts on the basis of that act. A technical correction extending specific articles of Regulation (EU) 2018/1139 is necessary to ensure that those mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 are fully covered when adopting relevant delegated or implementing acts on the basis of Regulation (EU) 2018/1139.

Amendment

(26) In order to ensure legal certainty as soon as possible, with a view to the imminent general application of Regulation (EU) 2024/1689, this Regulation should enter into force as a matter of urgency.

(22a) To ensure a sufficient degree of legal clarity in the event of continued delays in the availability of harmonised standards, it is necessary to mitigate potential legal uncertainty resulting from their absence. To that end, the Commission should be required to adopt common specifications by 2 December 2027. This deadline aligns with the deferred application date of Sections 1, 2, and 3 of Chapter III of Regulation (EU) 2024/1689 for AI systems classified as high-risk under Article 6(1) and Annex I of that Regulation, which has also been postponed to 2 December 2027. Additionally, the Commission should be required to issue standardisation requests covering the obligations set forth in Chapter V, Sections 2 and 3, of that Regulation by 2 December 2027, as it has not proceeded without undue delay.

(26a) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 20 January 2026,

Or. en

HAVE ADOPTED THIS REGULATION:

Amendment 11

Article 1 Amendments to Regulation (EU) 2024/1689

Proposal for a regulation

Regulation (EU) 2024/1689 is amended as follows:

Recital 23

(1) in Article 1(2), point (g) is replaced by the following:

Text proposed by the Commission

’(g) measures to support innovation, with a particular focus on small mid-cap enterprises (SMCs) and small and medium-sized enterprises (SMEs), including start-ups.;’

Amendment

(2) Article 2 is amended as follows:

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

‘2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a, Articles 102 to 112 shall apply. Articles 57 to 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.;’’

deleted

(2b) paragraph 7 is replaced by the following:

Or. en

‘7. Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 4a and Article 59 of this Regulation.’

Amendment 12

(2c) In Article 2, the following paragraph 13 is added:

Proposal for a regulation

“13. For high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9-15 and 17-25 of this Regulation may be limited, where and to the extent that:

Article 1 – paragraph 1 – point 2 a (new)

(a) Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing for an equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned; and (b) such limitation does not reduce the overall level of protection provided for by this Regulation.

Regulation (EU) 2024/1689

By 2 August 2027 the Commission shall adopt delegated acts in accordance with Article 97 to specify the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.”

Article 3 – point 1

(3) Article 3 is amended as follows:

Text proposed by the Commission

Point (14) is amended as follows: (14) ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property;

Amendment

‘(a) the following points (14a) and (14b) are inserted:

(2a) In article 3, point 1 is replaced by the following:

(14a) micro, small and medium-sized enterprise (‘SME’) means a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC;

(1) ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;

(14b) small mid-cap enterprise (‘SMC’) means a small mid-cap enterprise as defined in point (2) of the Annex to Commission Recommendation (EU) 2025/1099;’

(1) ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, decisions, or actions that can influence physical or virtual environments;

Or. en

Amendment 13

Proposal for a regulation

Article 1 – paragraph 1 – point 4

Regulation (EU) 2024/1689

Article 4

Text proposed by the Commission

Amendment

(4) Article 4 is replaced by the following:

‘Article 4

deleted

Article 4

AI literacy

1.‘The ProvidersCommission and Member States shall encourage providers and deployers of AI systems shallto take measures to supportensure thea developmentsufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation shall not be understood as requiring providers or deployers to guarantee any specific level of AI literacy of any individual.used.;

2. The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1. For that purpose, the Commission shall publish practical examples for compliance with that obligation on the single information platform referred to in point (d) of Article 62(3).

Or. en

3. The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 2, including by setting out common objectives.’;’

Amendment 14

(5) the following Article 4a is inserted in Chapter I:

Proposal for a regulation

‘Article 4a

Article 1 – paragraph 1 – point 5

Processing of special categories of personal data for bias detection and mitigation

Regulation (EU) 2024/1689

1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Article 4a – paragraph 1 – introductory part

(a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;

Text proposed by the Commission

Amendment

1. To the extent necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate provisions on fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Or. en

Amendment 15

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4a – paragraph 1 – point b

Text proposed by the Commission

Amendment

(b) the special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;

(c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured, protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;

(b) the special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures;

(d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties;

Or. en

(e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first;

Amendment 16

(f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.

Proposal for a regulation

2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:

Article 1 – paragraph 1 – point 5

(a) processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations; and

Regulation (EU) 2024/1689

(b) all of the conditions and safeguards set out in paragraph 1 are applied.

Article 4 a – paragraph 2

2b. This paragraph does not create any obligation to conduct such bias detection and correction.’

Text proposed by the Commission

(5a) Article 5 is amended as follows:

Amendment

(a) the following points are added to paragraph 1, first subparagraph:

2. Paragraph 1 may apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where necessary and proportionate if the processing occurs for the purposes set out therein and provided that the conditions set out under the safeguards set out in this paragraph.;

(ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;

2. Providers and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:

(bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, save where a ‘without right’ defence applies under national law;

(a) such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations; and

(b) The following paragraph is inserted:

(b) all the conditions and safeguards set out in paragraph 1 are applied.

1a. For the purposes of paragraph 1, first subparagraph, points (ba) and (bb):

This paragraph does not create any obligation to conduct such bias detection and correction with special categories of personal data.

(a) the placing on the market or putting into service of an AI system that generates or manipulates the material or performance referred to in points (ba) or (bb) above is only prohibited where:

Or. en

(i) that generation or manipulation is the intended purpose of the AI system; or

Amendment 17

(ii) the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse.

Proposal for a regulation

(b) the use of an AI system that generates or manipulates the material or performance referred to in points (ba) and (bb) above is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance.

Article 1 – paragraph 1 – point 5 a (new)

1b. For the purposes of paragraph 1, first subparagraph, point (ba), an AI system that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation.’

Regulation (EU) 2024/1689

(5b) Article 6 is amended as follows:

Article 5 – paragraph 1 – subparagraph 1 – point h a (new)

1a. For the purposes of this Regulation including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components. 1b. AI systems whose failure or malfunctioning would endanger health and safety shall qualify as safety components notwithstanding paragraph 1a. 1c. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety in particular risks relating to distribution of radio spectrum or electromagnetic interference that do not affect health and safety shall not be considered as fulfilling the condition in paragraph 1, point (b).

Text proposed by the Commission

(7) Article 10 is amended as follows:

Amendment

(a) paragraph 1 is replaced by the following:

(5a) In Article 5(1), first subparagraph, the following point is added

‘1. High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2, 3 and 4 of this Article and in Article 4a(1) whenever such data sets are used.;’

‘(ha) The placing on the market, the putting into service or the use of an AI system that can generate or manipulate sexualised audio, images and videos of individuals, thereby facilitating non-consensual sharing of intimate or manipulated material as defined in Directive (EU) 2024/1385*’.

(b) paragraph 5 is deleted;

__________________

(c) paragraph 6 is replaced by the following:

* Directive (EU) 2024/1385 of the European Parliament and of the Council of 14 May 2024 on combating violence against women and domestic violence, OJ L, 2024/1385, 24.5.2024, ELI: http://data.europa.eu/eli/dir/2024/1385/oj.

‘6. For the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2, 3 and 4 of this Article and Article 4a(1) shall apply only to the testing data sets.;’

Or. en

(8) in Article 11(1), the second subparagraph is replaced by the following:

Amendment 18

‘That technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of SMEs, including start-ups, and SMCs. Where an SME, including a start-up, or an SMC, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.;’

Proposal for a regulation

(9) in Article 17, paragraph 2 is replaced by the following:

Article 1 – paragraph 1 – point 6

‘2. The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.;’

Regulation (EU) 2024/1689

(9a) Article 25(2) is replaced by the following:

Article 6 – paragraph 4

2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. In particular, this obligation shall include, as long as it is relevant for the purposes specified in the previous subparagraph, the following:

Text proposed by the Commission

(a) making available technical documentation sufficient to assess compliance with Article 16 requirements;

Amendment

(b) informing the new provider about known limitations and failure modes; and

(6) in Article 6(4), paragraph 4 is replaced by the following:

(c) providing the new provider with targeted technical access, including for testing and validation. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.

deleted

(9ab) Article 25(4) first subparagraph is replaced by the following:

4. A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service. Upon request of national competent authorities, the provider shall provide the documentation of the assessment.;

4. The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.

Or. en

(9b) in Article 27, paragraph 4 is replaced by the following:

Amendment 19

‘4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article include cross references to the relevant sections of that data protection impact assessment or include relevant parts of that data protection impact assessment into the fundamental rights impact assessment.’;

Proposal for a regulation

(9c) In Article 27, paragraph 5 is replaced by the following:

Article 1 – paragraph 1 – point 12 a (new)

‘5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross references to the relevant sections of the data protection impact assessment or include relevant parts of that data protection impact assessment into the fundamental rights impact assessment pursuant to paragraph 4 of this Article.’;

Regulation (EU) 2024/1689

(10) in Article 28 the following paragraphs are added:

Article 40 – paragraph 2 – subparagraph 1

‘8. Notifying authorities designated under this Regulation responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both under this Regulation and the Union harmonisation legislation listed in Section A of Annex I shall be provided with the possibility to submit a single application and undergo a unified assessment procedure to be designated under this Regulation and Union harmonisation legislation listed in Section A of Annex I, where the relevant Union harmonisation legislation provides for such single application and unified assessment procedure. To that end, notifying authorities designated under this Regulation and under any other Union harmonisation legislation listed in Section A of Annex I shall cooperate in their assessments.

Text proposed by the Commission

The single application and unified assessment procedure referred to in this paragraph shall also be made available to notified bodies already designated under the Union harmonisation legislation listed in Section A of Annex I, when those notified bodies apply for designation under this Regulation, provided that the relevant Union harmonisation legislation provides for such a procedure.

Amendment

A conformity assessment body that is designated under more than one Union harmonisation legislation listed in Section A of Annex I shall have to apply only once to be designated under this Regulation. A designation under this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which the conformity assessment body is designated.

(12a) In Article 40, paragraph 2, first subparagraph is replaced by the following:

The single application and unified assessment procedure shall avoid any unnecessary duplications, build on the existing procedures for designation under the Union harmonisation legislation listed in Section A of Annex I and ensure compliance with the requirements both relating to notified bodies under this Regulation and the relevant Union harmonisation legislation.’;

In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.

A notifying authority that has been designated under the Union harmonisation legislation listed in Section A of Annex I is also the notifying authority for the application of the single application and unified assessment procedure referred to in paragraph 8, unless the Member State designates another notifying authority for this Regulation.’;’

‘In accordance with Article 10 of Regulation (EU) (No) 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, by 2 December 2027, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.

(11) in Article 29, paragraph 4 is replaced by the following:

Or. en

‘4. For notified bodies which are designated under any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support and expedite their designation procedure under this Regulation, as appropriate.

Amendment 20

Notified bodies, which are designated under any of the Union harmonisation legislation listed in Section A of Annex I and which apply for the unified assessment referred to in Article 28(8), shall submit the single application for assessment to the notifying authority designated in accordance with that Union harmonisation legislation.

Proposal for a regulation

The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.;’

Article 1 – paragraph 1 – point 12 b (new)

(12) in Article 30, paragraph 2 is replaced by the following:

Regulation (EU) 2024/1689

‘2. Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.

Article 41 – paragraph 1 – introductory part

The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend Annex XIV, in the light of technical progress, advances in knowledge or new scientific evidence by adding to the list of codes, categories, and corresponding types of AI systems a new code, a category or a type of AI system, withdrawing an existing code, category or a type of AI system from that list or moving a code or type of AI system from one category to another.;’

Text proposed by the Commission

(12a) In Article 40, the following subparagraph is added in paragraph 2:

Amendment

‘The Commission shall request, in accordance with the Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I.;’

(12b) In Article 41, the introductory wording is replaced by the following:

(12b) In Article 42, the following paragraph is inserted:

1. The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:

‘ 2a. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 , and where the conditions laid down in Article 12(1) of that Regulation (EU) 2024/2847 are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.;’

‘1. The Commission shall adopt, implementing acts by 2 December 2027 establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:’

(13) in Article 43, paragraph 3 is replaced by the following:

Or. en

‘For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 shall also apply, as well as points 3, 4.3, 4.4., 4.5, the fifth paragraph of point 4.6 and 5 of Annex VII.

Amendment 21

For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in Section 2, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under the relevant Union harmonisation legislation and as is evidenced through the assessment as part of the existing notification. Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 at the latest [18 months from the entry into application of this Regulation].

Proposal for a regulation

Where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment not involving a third-party, provided that that manufacturer has applied harmonised standards to show the compliance covering all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system under Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I, including, where applicable, an option to rely on harmonised standards. The manufacturers of such products are not obligated to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by the Union harmonisation legislation.

Article 1 – paragraph 1 – point 12 c (new)

Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation listed in Section A of Annex I.;’

Regulation (EU) 2024/1689

Article 41 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(12c) in Article 41, the following paragraph is inserted

‘1a. When there is no harmonised standard that enable compliance with the essential requirements set out in Section 2 of this Chapter and no reference in the Official Journal of the European Union is expected to be published within a reasonable period, the Commission shall by means of implementing acts adopt common specifications in order to address an urgent concern with regard to non-compliant AI systems, which cannot be adequately mitigated by alternative measures. A situation shall be considered to constitute an urgent concern when the suspension of cooperation with international standardisation organisations impedes the development of relevant harmonised standards by European standardisation organisations. In such a situation the Commission shall adopt common specifications only after prior authorisation of the Council. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). When preparing those implementing acts, the Commission shall be assisted by an expert group that includes relevant stakeholder representatives.

Or. en

Amendment 22

Proposal for a regulation

Article 1 – paragraph 1 – point 12 d (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 b (new)

Text proposed by the Commission

Amendment

(12d) in Article 41, the following paragraph 1b is inserted

‘1b. The Commission shall provide the European Parliament, in a timely manner, with all relevant information concerning the implementing acts referred to in paragraph 1. That shall include, in particular, details on the drafting process of the implementing act, details on the composition of the expert groups supporting the process, details on the timeline and, where the drafting of an implementing act is outsourced, information on the main contractual aspects of such outsourcing, including the name of the entity responsible for the drafting, the total value of the contract and its duration.’

Or. en

Amendment 23

Proposal for a regulation

Article 1 – paragraph 1 – point 12 e (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 6

Text proposed by the Commission

Amendment

(12e) in Article 41, paragraph 6 is replaced by the following:

6. Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.

‘6. Where the European Parliament or a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.’

Or. en

Amendment 24

Proposal for a regulation

Article 1 – paragraph 1 – point 12 f (new)

Regulation (EU) 2024/1689

Article 42 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(12f) In Article 42, the following paragraph is added

‘2a. Where an AI system is subject to the requirements of Regulation (EU) 2024/2847 as well as requirements set out in Article 15 of this Regulation, and where those high-risk AI systems fulfil the essential cybersecurity requirements set out in the Regulation (EU) 2024/2847, they shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under Regulation (EU) 2024/2847.’

Or. en

Amendment 25

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2024/1689

Article 49 – paragraph 2

Text proposed by the Commission

Amendment

(14) in Article 49, paragraph 2 is deleted;

deleted

Or. en

Amendment 26

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2024/1689

Article 50 – paragraph 7

Text proposed by the Commission

Amendment

(15) in Article 50, paragraph 7 is replaced by the following:

‘7. The Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56(6). If it deems the code of practice is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).’;’

deleted

(16) in Article 56, paragraph 6 is replaced by the following:

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).;

‘6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;’

Or. en

(17) Article 57 is amended as follows:

Amendment 27

‘(-a) paragraph 1, first subparagraph, is replaced by the following:

Proposal for a regulation

‘1. Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2nd August 2027 . That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.;’

Article 1 – paragraph 1 – point 16

(-b) paragraph 3 is replaced by:

Regulation (EU) 2024/1689

‘3. The European Data Protection Supervisor may also establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose references to national competent authorities in this Chapter shall be construed as references to the European Data Protection Supervisor.;’

Article 56 – paragraph 6

(a) the following paragraphs are inserted:

Text proposed by the Commission

‘3a. The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). For this purpose references to national competent authorities in this Chapter shall be construed, where relevant, as references to the AI Office. Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when compliance with Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including start-ups, and SMCs.

Amendment

3b. The establishment of a Union level AI regulatory sandbox by the AI Office shall be without prejudice to the competences of Member States to establish and supervise AI regulatory sandboxes for AI systems under their supervision.’;’

(16) in Article 56(6), the first subparagraph is replaced by the following:

(b) paragraph 5 is replaced by the following:

deleted

‘5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;’

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;

(c) paragraph 9, point (e) is replaced by the following:

Or. en

‘(e) facilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups, and SMCs.;’

Amendment 28

(ca) paragraph 10 is replaced by the following:

Proposal for a regulation

’10. National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the competent data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.;’

Article 1 – paragraph 1 – point 17 – point a

(d) paragraph 13 is replaced by the following:

Regulation (EU) 2024/1689

’13. The AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.; ’

Article 57 – paragraph 3a

(e) paragraph 14 is replaced by the following:

Text proposed by the Commission

’14. National competent authorities, the EDPS and the AI Office shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board. They may support the joint establishment and operation of AI regulatory sandboxes, including in different sectors and exchange best practices on related matters.;’

Amendment

(18) Article 58, paragraph 1, is replaced by the following:

The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.;

‘1. In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation, governance, and supervision of the AI regulatory sandboxes. The implementing acts shall include common principles on the following issues:

‘The AI Office shall also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.’;

(a) eligibility and selection criteria for participation in the AI regulatory sandbox;

Or. en

(b) procedures for the application, participation, monitoring, exiting from and termination of the AI regulatory sandbox, including the sandbox plan and the exit report;

Amendment 29

(c) the terms and conditions applicable to the participants;

Proposal for a regulation

(d) the detailed rules applicable to the governance of AI regulatory sandboxes covered under Article 57, including as regards the involvement and supervision by the competent data protection authorities, where relevant, and the coordination and cooperation at national and EU level.;’

Article 1 – paragraph 1 – point 17 – point b

(19) Article 60 is amended as follows:

Regulation (EU) 2024/1689

(a) in paragraph 1, the first subparagraph is replaced by the following:

Article 57 – paragraph 5

‘Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.;’

Text proposed by the Commission

(b) paragraph 2 is replaced by the following:

Amendment

‘2. Providers or5. prospectiveAI providersregulatory maysandboxes conductestablished testingunder ofthis high-riskArticle AIshall systemsprovide referredfor toa incontrolled Annexenvironment IIIthat orfosters coveredinnovation byand Unionfacilitates harmonisationthe legislationdevelopment, listedtraining, intesting Sectionand Avalidation of Annex I ininnovative realAI worldsystems conditionsfor ata anylimited time before thetheir placingbeing placed on the market or the puttingput into service ofpursuant theto AIa systemspecific onsandbox theirplan ownagreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in partnershipplace. withSuch onesandboxes ormay moreinclude deployerstesting orin prospectivereal deployers.;’world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;

5. 'AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place.’

Or. en

Amendment 30

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e

Regulation (EU) 2024/1689

Article 57 – paragraph 14

Text proposed by the Commission

Amendment

14. National competent authorities shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.;

14. ’National competent authorities, the European Data Protection Supervisor, and the AI Office shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.’

Or. en

Amendment 31

Proposal for a regulation

Article 1 – paragraph 1 – point 20

Regulation (EU) 2024/1689

Article 60a

Text proposed by the Commission

Amendment

(20) the following Article 60a is inserted:

‘Article 60a

deleted

Article 60a

Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes

1. Member States may permit the testingTesting of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of AI enabled products covered by Union harmonisation legislation listed in Section B of Annex I, within aaccordance viewwith tothis assessingArticle and verifying the conformity of those systemsa withvoluntary thereal-world requirementstesting ofagreement, Articleswithout 8prejudice to 15 of this Regulation, inthe accordanceprohibitions withunder thisArticle Article.5.

2a. Member States which choose to permit testing as referred to in paragraph 1 shall, individually or jointly, adopt frameworks for real-world testing.

2. The voluntary real-world testing agreement referred to in paragraph 1 shall be concluded in writing between interested Member States and the Commission. It shall set the requirements for the testing of those AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions.

2b. Each Member State shall notify the Commission of any real-world testing framework it adopts before implementing that framework. This shall not affect the competences of the Commission under the Union harmonisation legislation listed in Section B of Annex I.

3. Member States, the Commission, market surveillance authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I shall cooperate closely with each other and in good faith, and shall remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement the voluntary real-world testing agreement and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex.

3. Member States that have adopted real-world testing frameworks shall ensure that the relevant national competent authorities, appropriate authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I cooperate closely with each other and in good faith, and remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement those real-world testing frameworks and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex I.

4. The signatories of the voluntary real-world testing agreement, shall specify conditions of the testing in real world conditions and establish detailed elements of the real-world testing plan for AI systems covered by Union harmonisation legislation listed in Section B of Annex I.

4. The frameworks for real-world testing shall lay down the requirements by which testing in real-world conditions shall occur. Those frameworks shall:

5. Article 60(2), (5) and (9) shall apply.;

(a) include provision of a mandatory real-world testing plan to be agreed between the provider or prospective provider and the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I;

Or. en

(b) ensure compliance with the requirements laid down in Article 60(2), (3), (4)(d)-(j) and (5)-(9), save that any reference to market surveillance authorities in those provisions shall be read as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I;

Amendment 32

(c) include effective governance and accountability arrangements.

Proposal for a regulation

(d) ensure a high level of protection of health, safety and fundamental rights.

Article 1 – paragraph 1 – point 22 – point b

4a. The real-world testing shall comply with any applicable provisions laid down in the Union harmonisation legislation listed in Section B of Annex I. Any requirements laid down in those provisions shall not affect the application of this Article to the extent necessary to enable the testing referred to in paragraph 1.’

Regulation (EU) 2024/1689

(21) Article 63(1) is replaced by the following:

Article 69 – point 3

‘1. SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.’;’

Text proposed by the Commission

(21a) In Article 64, paragraph 2a is added:

Amendment

‘(2a) Without prejudice to the budgetary procedure, the AI Office shall be allocated with adequate resources to effectively perform its duties and exercise its powers in respect of the enforcement of Regulation (EU) 2024/1689.’

(b) paragraph 3 is deleted.

(22) Article 69 is amended as follows:

deleted

(a) paragraph 2 is replaced by the following:

Or. en

‘2. The Member States may be required to pay fees for the advice and support provided by the experts at a rate equivalent to the remuneration fees applicable to the Commission pursuant to the implementing act referred to in Article 68(1).;’

Amendment 33

(23) in Article 70, paragraph 8 is replaced by the following:

Proposal for a regulation

‘8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs, including start-ups, and SMCs, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.;’

Article 1 – paragraph 1 – point 30 – point a

(24) in Article 72, paragraph 3 is replaced by the following:

Regulation (EU) 2024/1689

‘3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.’;’

Article 111 – paragraph 2

(25) Article 75 is amended as follows:

Text proposed by the Commission

(a) the heading of Article 75 is replaced by the following:

Amendment

‘Market surveillance and control of AI systems and mutual assistance;’

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.;

(b) paragraph 1 is replaced by the following:

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to providers and deployers of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, they shall be brought into compliance with this Regulation by 31 December 2030.’

‘1. 1. The AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to the following AI systems:

Or. en

(a) AI systems based on general-purpose AI models where that model and that system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of:

Amendment 34

(i) AI systems related to products covered by the Union harmonisation listed in Annex I;

Proposal for a regulation

(ii) AI systems referred to in Annex III, point (2);

Article 1 – paragraph 1 – point 31 – point a

(iii) AI systems provided by law enforcement authorities, border management authorities, and financial institutions insofar as those AI systems fall under Article 74(6); and

Regulation (EU) 2024/1689

(iv) AI systems referred to in Annex III, point (8) as regards the administration of justice.

Article 113 – paragraph 3 – point d

(b) AI systems that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.

Text proposed by the Commission

The exclusive competence referred to in the first subparagraph shall apply to the providers of those systems. It shall also apply to the deployers of those systems, but only when they are also the provider or part of the same undertaking as the provider.

Amendment

(c) the following paragraphs are inserted:

(a) in the third paragraph, point (d) is added:

‘1ab. By way of derogation from Article 73, providers of high-risk AI systems subject to the AI Office’s competence under paragraph 1 of this Article shall report any serious incidents to the AI Office. Article 73(2)-(9) shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated.

(a) in the third paragraph, point (d) is added:

1a. The authorities involved in the application of this Regulation shall cooperate actively and afford the AI Office the necessary assistance for the exercise of its powers, including, where necessary, in connection with inspections or other enforcement measures carried out in the territory of a Member State. To this end, those authorities shall enjoy the powers provided for under this Regulation and Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks under this paragraph, in accordance with the applicable national procedures.

‘Chapter III, Sections 1, 2, and 3, shall apply following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available, from the following dates:

1ba. When taking investigatory or enforcement action in the territory of a Member State that involves access to a public authority’s data or AI system, the AI Office shall be assisted by the relevant market surveillance authority.

‘Chapter III, Sections 1, 2, and 3, shall apply:

1c. Before taking a decision that would have the effect of prohibiting or restricting the AI system being made available or put into service on a national market, or a decision to withdraw or recall the AI system from the market, the AI Office shall, without undue delay, notify the market surveillance authority competent for that market of the intention to take such a decision. The AI Office shall consult the authorities involved in the application of this Regulation, where appropriate, on any matter relating to the application and enforcement of this Regulation.

(i) 6 months after the adoption of that decision as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

1d. The AI Office shall be responsible for pre-market conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to third-party conformity assessment under Article 43 before such AI systems are placed on the market or put into service. These tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission shall entrust the performance of these tests or assessments to notified bodies designated under this Regulation, in which case the notified body shall act on behalf of the Commission. If a notified body to which the Commission has delegated tasks under this paragraph does not perform those tasks adequately, the Commission may withdraw the delegation with immediate effect.’

(ii) 12 months after the adoption of the decision as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

1e. The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for third-party conformity assessment to the Commission. The costs related to the services entrusted by the Commission to the notified bodies in accordance with this Article shall be directly paid by the provider to the notified body.;

In the absence of the adoption of the decision within the meaning of subparagraph 1, or where the dates below are earlier than those that follow the adoption of that decision, Chapter III, Sections 1, 2, and 3, shall apply:

2a. Where a market surveillance authority has well-founded and sufficient reasons to suspect that a provider or a deployer of an AI system referred to in paragraph 1 has infringed this Regulation, it may request, through the relevant single point of contact foreseen in Article 70(2) of this Regulation, the AI Office to assess the matter in order to take the necessary supervisory and enforcement measures to ensure prompt compliance with this Regulation. Such a request shall be duly reasoned and shall include at least:

(a) the name of the provider or the deployer concerned;

(b) a description of the relevant facts, the provisions of this Regulation that have allegedly been infringed, and the well-founded and sufficient reasons for suspecting an infringement, including, where applicable, the description of the negative effects of the alleged infringement;

(c) the market surveillance authority making the request.

The AI Office shall take utmost account of the request and the market surveillance shall cooperate actively and afford the AI office the necessary assistance for the exercise of its powers in line with paragraph 1a of this Article. The AI Office shall, without undue delay and in any event no later than four months following receipt of the request, inform the single point of contact of its intention to exercise its powers under Article 75a or of its reasons for not exercising its powers. If the AI Office decides to exercise its powers under Article 75a, it shall periodically inform that single point of contact about major developments in the proceedings and the outcome of such proceedings, without disclosing any confidential information.

(25a) The following articles are inserted after Article 75:

‘Article 75a

Supervisory and enforcement powers of the AI Office

1. When exercising its tasks of supervision and enforcement outlined in Article 75(1), the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020. The AI Office shall also be authorised to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance, including costs for human and technical resources, in accordance with Article 15 of Regulation (EU) 2019/1020. Article 17 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

2. Where the AI Office has reasonable grounds to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may adopt a decision initiating an investigation into that non-compliance in accordance with Article 14(4)(f) of Regulation 2019/1020. Upon the initiation of such an investigation, the AI Office shall notify the operator of the AI system concerned. The AI Office may exercise the powers listed in paragraph 1 on its own initiative or following a complaint received pursuant to Article 85 of this Regulation, even before initiating an investigation pursuant to Article 14(4)(f) of Regulation 2019/1020. Where a market surveillance authority has reason to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may send a request to the AI Office to assess the matter.

3. The AI Office may exercise the powers listed in Article 14(4)(a) to (c) of Regulation 2019/1020 and Article 74(12-13) of this Regulation by simple request or by decision. When requesting information, the AI Office shall state the legal basis and the purpose of the request, specify what information is required, set the period within which the information is to be provided. Where the request is a simple request, the AI Office shall additionally indicate that although there is no obligation to provide the information requested, in the case of a voluntary reply, the information must be correct and not misleading, and indicate the potential fines provided for in Article 99(5) for supplying incorrect or misleading information. Where the request is made by decision, the AI Office shall additionally indicate the fines provided for in Article 99(5) for supplying incorrect, incomplete and misleading information and indicate the right to have the decision reviewed by the Court of Justice of the European Union. The AI Office shall send a copy of the request to the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated.

4. In order to carry out the tasks assigned to it under this Section, the AI Office may conduct all necessary remote or on-site inspections pursuant to the powers laid down in Article 14(4)(d) and (e) of Regulation (EU) 2019/1020 and Article 74(5) of this Regulation. When ordering inspections , the AI Office shall inform the provider concerned of the subject matter and purpose of the investigation, the relevant penalties referred to in Article 99(5), and the right to have the decision reviewed by the Court of Justice of the European Union. Prior to conducting an inspection, the Commission shall inform the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated. During such an inspection, the officials of the AI Office shall be empowered to: (a) enter any of the business premises, land or property located in the Union of the operator concerned; (b) examine the books, data and other material relevant to the execution of their tasks, irrespective of the medium on which they are stored; (c) take or obtain in any form copies of or extracts from such books, data and other records; (d) ask any of the persons subject to the inspection, or their representatives, or staff, for oral or written explanations on factors or documents relating to the subject matter and purpose of the inspection, and to record the answers. (e ) seal any business premises and books or records for the duration of, and to the extent necessary for, the inspection; Where the AI Office finds that a natural or legal person opposes or obstructs such an inspection, the national competent authority of the Member State concerned shall afford it the necessary assistance, requesting, where appropriate, the assistance of the police or an equivalent enforcement authority, to enable it to conduct its on-site inspection. Where an on-site inspection of business premises, land or property requires authorisation by a judicial authority in accordance with national law, the AI Office shall apply for such an authorisation. The AI Office may also apply for such authorisation as a precautionary measure. Where such an authorisation is applied for, the national judicial authority shall promptly verify that the coercive measures envisaged are neither arbitrary nor excessive having regard to the subject matter of the investigation or inspection and the documents provided by the AI Office with the decision. In its verification of the proportionality of coercive measures, the national judicial authority may ask the AI Office for detailed explanations, in particular relating to the grounds the AI Office has for suspecting that an infringement of this Regulation has taken place and the seriousness of the suspected infringement and, where relevant, the nature of the involvement of the person subject to the coercive measures. However, the national judicial authority shall not review the necessity of the investigation or inspection nor demand information from the case file of the Commission. In accordance with the Treaties, the legality of the Commission’s decision is subject to review only by the Court of Justice of the European Union.

5. At the request of the AI Office, the competent market surveillance authority of a Member State may in its own territory carry out any investigation, inspection or other fact-finding measure on behalf and for the account of the AI Office in order to establish whether there has been an infringement of this Regulation. The officials of the competent authorities of the Member States who are responsible for conducting these investigations, inspections, or fact-finding measures as well as those authorised or appointed by them shall exercise their powers in accordance with their national law.

6. In addition to the powers set out in paragraph 1, the AI Office, in the exercise of its competences listed in Article 75(1), may: (a) order operators to provide access to, and explanations relating to, their AI systems; (b) impose an obligation on an operator to retain all data and documents deemed to be necessary to assess the implementation of and compliance with the obligations under this Regulation.

7. To assist it in monitoring the effective implementation and compliance with the relevant provisions of this Regulation and to provide it with specific expertise or knowledge in the exercise of its competences under Article 75(1), the AI Office may appoint independent external experts and auditors, as well as experts, investigative teams and auditors from the Member State’s competent authorities with the agreement of the authority concerned,. Information obtained as a result of such monitoring actions shall be shared with the relevant competent authorities of the Member States.

8. Information collected pursuant to this provision shall be used only for the purpose of this Regulation.

Article 75c

Commitments

If, during proceedings under Article 75a(2), the operator concerned offers commitments to ensure compliance with the relevant provisions of this Regulation, the AI Office may, by decision, make those commitments binding on the operator concerned and declare that there are no further grounds for action. The AI Office may, upon request or on its own initiative, reopen the proceedings:

(a) where there has been a material change in any of the facts on which the decision was based;

(b) where the operator acts contrary to its commitments; or

(c) where the decision was based on incomplete, incorrect or misleading information provided by the operator concerned.

Where the AI Office considers that the commitments offered by the operator concerned are unable to ensure effective compliance with the relevant provisions of this Regulation, it shall reject those commitments in a reasoned decision when concluding the proceedings.

Article 75d

Non-compliance, fines and periodic penalties

1. Where the Commission finds that an operator of an AI system falling within the scope of Article 75(1) does not comply with the relevant provisions of this Regulation or with commitments made binding pursuant to Article 75c, it shall adopt a decision establishing such non-compliance.

2. Before adopting a decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the operator concerned. In the preliminary findings, the Commission shall explain the measures that it considers taking, or that it considers that the operator concerned should take, in order to effectively address the preliminary findings.

3. In the decision pursuant to the paragraph 1, the AI Office shall, where relevant, order the operator concerned to take the necessary measures to ensure compliance with the decision within a reasonable period specified therein and to provide information on the measures that that operator intends to take to comply with the decision. The operator concerned shall provide the AI Office with a description of the measures it has taken to ensure compliance with the decision upon their implementation. Prior to requesting any measure, the AI Office may engage in a structured dialogue with the operator of the AI system in question. During this dialogue, the operator may propose commitments in accordance with paragraph Article 75c.

4. A decision adopted pursuant to paragraph 1 may be accompanied by the imposition of penalties in accordance with Article 99 (3)-(7), which provisions shall apply mutatis mutandis to the AI Office in the execution of its supervision and enforcement tasks laid out in Article 75(1) of this Regulation.

In particular, the following shall be subject to administrative fines as referred to in Article 99(4):

(a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4);

(b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or 16(3) of Regulation (EU) 2019/1020, as well as those specified in Article 75b;

(c) failure to comply with a commitment made binding by a decision pursuant to Article 75c.

The supply of incorrect, incomplete or misleading information to the Commission in reply to a request shall be subject to administrative fines as referred to in Article 99(5).

5. The Commission may adopt a decision imposing periodic penalty payments to compel the operators subject to its competence pursuant to Article 75(1) to submit to an investigation, to comply with an information request ordered by a decision adopted under paragraph Article 75a(3), to submit to an inspection ordered by a decision pursuant to Article 75a(4), to provide correct or complete answers or explanations in the context of such an inspection, to comply with corrective actions ordered pursuant to the power listed in Article 16 of Regulation (EU) 2019/1020, to comply with commitments made legally binding by a decision pursuant to Article 75c, or to comply with a decision pursuant to the first paragraph of this Article. Those penalty payments shall be effective and proportionate, and where applicable shall not exceed 5% of the average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date appointed by the decision.

6. The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine or periodic penalty payment under this Article. It may cancel, reduce or increase the fine or periodic penalty payment imposed.

7. Funds collected through the imposition of fines or periodic penalty payments under this Article shall contribute to the general budget of the Union.

7a. The powers conferred on the Commission by this Article shall be subject to a limitation period of five years. Time shall begin to run on the day on which the infringement is committed. However, the case of continuing or repeated infringements, time shall begin to run on the day on which the infringement ceases.

The power of the Commission to enforce decisions taken pursuant to this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the decision becomes final.

The implementing act referred to in Article 75e(3) shall specify the first and second subparagraphs of this paragraph, including the circumstances in which the limitation periods shall be interrupted.

8. Where the Commission determines that there are no grounds to adopt a decision of non-compliance, it shall close the proceeding by a decision. That decision shall apply with immediate effect.

Article 75e

Safeguards and further specification

1. Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to operators subject to the AI Office’s competence pursuant to Article 75(1), without prejudice to more specific procedural rights provided for in this Regulation.

2. The rights of defence and of access to the file of operators of AI systems falling within the scope of Article 75(1) shall be fully respect in proceedings. In view of the possible adoption of decisions on the basis of Article 75d(1), those operators shall be entitled to have access to the Commission's file under the terms of a negotiated disclosure, subject to the legitimate interest of the operator or other person concerned in the protection of their business secrets. The AI Office shall have the power to adopt decisions setting out such terms of disclosure in case of disagreement between the parties. The right of access to the file shall not extend to confidential information and internal documents of the AI Office, the Board, competent market surveillance authorities or other public authorities of the Member States. In particular, the right of access shall not extend to correspondence between the Commission and those authorities. Nothing in this paragraph shall prevent the Commission from disclosing and using information necessary to prove an infringement.

3. The Commission may adopt implementing acts concerning the practical arrangements for access to the file and the negotiated disclosure of information provided for in paragraph 2.

4. The Commission shall publish the decisions it adopts pursuant to Articles75c and 75d. Such publication shall state the names of the parties and the main content of the decision, including any penalties imposed. The publication shall have regard to the rights and legitimate interests of any person concerned in the protection of their confidential information.’

(25b) In Article 76(1), the following subparagraph is added:

‘Where testing in real world conditions is based on Article 60a, any reference to a market surveillance authority in this Article shall be construed as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I, and references to Article 60 shall be construed as references to Article 60a as appropriate.’;’.

(26) Article 77 is amended as follows:

(a) the heading is replaced by the following:

‘Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities’

(b) paragraph 1 is replaced by the following:

‘1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and machine-readable format by electronic means where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. This article is without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates.’;’

(c) the following paragraph 1a and 1b are inserted:

‘1a. Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary and without undue delay.

1b. Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall cooperate closely and provide each other with mutual assistance necessary for fulfilling their respective mandates, with a view to ensuring coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures while respecting their respective competences, tasks, powers and independence. This shall include, in particular, exchange of information where necessary for the effective supervision or enforcement of this Regulation and the respective other Union legislation.;’

(27) Article 95, paragraph 4 is replaced by the following:

‘4. The AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and SMCs, when encouraging and facilitating the drawing up of codes of conduct.;

(28) Article 96 is amended as follows:

(a) in paragraph 1, the following point (g) is added:

‘(g) the practical implementation of Articles 8(2), 9(10), and 17(3) in line with the principle of complementarity and proportionality, with a view to ensuring consistency, avoiding duplication and minimising additional burdens when complying with the requirements of this Regulation and the requirements of the Union harmonisation legislation listed in Section A of Annex I. These guidelines shall be published at the latest on 1 August 2027.”;’

(b) paragraph 1, the second subparagraph is replaced by the following:

‘the application of the requirements and obligations referred to in Articles 8 to 15 and in Articles 25 and 26;

‘When issuing such guidelines, the Commission shall involve the AI Board and pay particular attention to the needs of SMEs, including start-ups, and SMCs, of local public authorities and of the sectors most likely to be affected by this Regulation.’;’’

(29) Article 99 is amended as follows:

(a) paragraph 1 is replaced by the following:

‘1. In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. The Member States shall take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties.’;’

(aa) in paragraph 4 the following point (da) is inserted:

(da) 'obligations of providers and operators pursuant to Article 25(2) and (4); ’

(b) paragraph 6 is replaced by the following:

‘6. In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.;’

(29a) In Article 99, paragraph 6a is inserted:

‘In the case of SMCs each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred to in paragraph 4 or 5, whichever thereof is lower.’

(30) Article 111 is amended as follows:

(a) paragraph 2 is replaced by the following:

‘2. Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.;’

(b) the following paragraph 4 is added:

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.’

(31) Article 113 is amended as follows:

(-a) in the third paragraph, point (a) is replaced by the following:

(a) Chapters I and II shall apply from 2 February 2025, except for Article 5(1), first subparagraph, points (ba) and (bb), Article 5(1a) and Article 5(1b) which shall apply from 2 December 2026 ;’

(a) in the third paragraph, point (c) is replaced by the following:

‘Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply

(i) on 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

(ii)(i) on 2 AugustDecember 20282027 as regards AI systems classified as high-risk pursuant to Article 6(1)6(2) and Annex I.;’III, and

(b) in the third paragraph, point (d) is added:

(ii) on 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.’

‘(d) Articles 102 to 110 shall apply from [the date of entry into force of this amending Regulation].’;’

(ii) on 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.’

(31a) Annex I is amended as follows:

Or. en

(a) in Section A, point 1 is deleted. (b) in Section B, the following point 21 is added: ‘21. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC.’

ANNEX: DECLARATION OF INPUT

(32) in Annex VIII, section B, points 7 and 9 are deleted;

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that he included in his draft opinion input on matters pertaining to the subject of the file that he received, in the preparation of the draft opinion, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

(33) the following Annex XIV is added:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

‘Annex XIV

Volkswagen

The list of codes, categories and corresponding types of AI systems for the purpose of the notification procedure referred to in Article 30 specifying the scope of the designation as notified bodies

Logitech

1. Introduction

DKB

Conformity assessment of high-risk AI systems under this Regulation may require involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated in accordance with this Regulation may carry out conformity assessments and only for the activities related to the types of AI systems concerned. The list of codes, categories, and corresponding types of AI systems sets the scope of the designation of conformity assessment bodies notified under Article 30 of this Regulation.

Indeed

2. List of Codes, categories, and corresponding AI systems

Adobe

1. AI systems subject to Annex I of the AI Act

Vzbv

AIA Code

Mozilla Foundation

AIP 0101

Bitkom

AI systems subject to Annex I.A.1. of the AI Act.

Cocir

AIP 0102

E-on

AI systems subject to Annex I.A.2. of the AI Act.

Milestones Systems

AIP 0103

Volkswagen

AI systems subject to Annex I.A.3. of the AI Act.

German Chamber of Commerce

AIP 0104

German Association of Local Public Utilities

AI systems subject to Annex I.A.4. of the AI Act.

Philips

AIP 0105

OpenAI

AI systems subject to Annex I.A.5. of the AI Act.

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies

AIP 0106

The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.

AI systems subject to Annex I.A.6. of the AI Act.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that he has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

AIP 0107

AI systems subject to Annex I.A.7. of the AI Act.

AIP 0108

AI systems subject to Annex I.A.8. of the AI Act.

AIP 0109

AI systems subject to Annex I.A.9. of the AI Act.

AIP 0110

AI systems subject to Annex I.A.10. of the AI Act.

AIP 0111

AI systems subject to Annex I.A.11. of the AI Act.

AIP 0112

AI systems subject to Annex I.A.12. of the AI Act.

2. AI systems subject to Annex III.1 of the AI Act

AIA Code

AIB 0201

Remote biometric identification systems

AIB 0202

Biometric categorisation AI systems

AIB 0203

Emotion recognition AI systems

3. AI technology-specific codes

a. Symbolic AI and expert systems

AIA Code

AIH 0101

AI systems based on symbolic AI, expert and knowledge-based systems, and AI systems based on search and optimisation

b. Machine learning, excluding generative AI and GPAI

AIA Code

AIH 0201

AI systems that process structured data

AIH 0202

AI systems that process signal and audio data

AIH 0203

AI systems that process text data

AIH 0204

AI systems that process image and video

AIH 0205

AI systems that learn from their environment, excluding AI systems covered under AIH 0401

c. AI systems based on GPAI or generative AI

AIA Code

AIH 0301

generative AI systems, including AI systems based on GPAI models

d. Emerging AI technologies

AIA Code

AIH 0401

AI systems based on other emerging AI technologies not covered by other codes, including Agentic AI

3. Application for designation

Conformity assessment bodies shall use the lists of codes, categories and corresponding types of AI systems set out in this Annex when specifying the types of AI systems in the application for designation referred to in Article 29 of this Regulation.’.

Article 2 Amendments to Regulation (EU) 2018/1139

Regulation (EU) 2018/1139 is amended as follows:

(1) in Article 27, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council1, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;

_____________

1 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).’

(2) in Article 31, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

(3) in Article 32, the following paragraph is added:

‘3. When adopting delegated acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

(4) in Article 36, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

(5) in Article 39 the following paragraph is added:

‘3. When adopting delegated acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

(6) in Article 50, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

(7) in Article 53, the following paragraph is added:

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’

Article 2a Amendments to Regulation (EU) 2023/1230

Regulation (EU) 2023/1230 is amended as follows:

(1) in Article 8, the following subparagraphs are added:

‘The Commission shall adopt delegated acts in accordance with Article 47 to amend Annex III by adding health and safety requirements in respect of AI-systems that are classified as high-risk pursuant to Article 6(1) of Regulation (EU) 2024/1689 because they are a safety component in a product covered by this Regulation, or because they are themselves a product covered by this Regulation. Those requirements shall ensure that the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 are reflected.

When adopting the delegated acts referred to in the third paragraph, the Commission shall take into account the objectives of Regulation (EU) 2024/1689 and ensure a level of protection consistent with that Regulation.

Such delegated acts shall apply by 2 August 2028.’;

(2) in Article 20, the following paragraph is added:

‘10. Until harmonised standards or common specifications are referenced or adopted under this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards or common specifications referenced or adopted under Articles 40 and 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III as regards high-risk AI systems.’.

Article 3 Entry into force and application

This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels,

For the European Parliament For the Council

The President The President