Sittings · Compare

What changed

From · opinion parliamentary committee · 2026-02-26 JURI-AD-784179 on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
To · agreement provisional · 2026-05-13 CJ40-AG-789081 Proposal for a regulation Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)
+416 added · −614 removed · 3 modified paragraphs

PA_Legam

13.5.2026

AMENDMENTS

PROVISIONAL AGREEMENT RESULTING FROM INTERINSTITUTIONAL NEGOTIATIONS

The Committee on Legal Affairs submits the following to the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs, as the committees responsible:

Subject: Proposal for a regulation Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

Amendment 1

(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

Proposal for a regulation

The interinstitutional negotiations on the aforementioned proposal for a regulation have led to a compromise. In accordance with Rule 75(4) of the Rules of Procedure, the provisional agreement reproduced below is submitted to the Committee on the Internal Market and Consumer Protection Committee on Civil Liberties, Justice and Home Affairs for decision by way of a single vote.

Recital 1 a (new)

2025/0359 (COD)

Text proposed by the Commission

Proposal for a

Amendment

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

(1a) Obligations under this Regulation shall be implemented in a proportionate manner, taking into account the nature, scale and complexity of the activities concerned.

amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

Amendment 2

(Text with EEA relevance)

Proposal for a regulation

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Recital 2 a (new)

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Text proposed by the Commission

Having regard to the proposal from the European Commission,

Amendment

After transmission of the draft legislative act to the national parliaments,

(2a) This Regulation aims to simplify the implementation of Regulation (EU) 2024/1689 and to reduce unnecessary administrative burden without altering its scope. It does not introduce new legal categories of artificial intelligence systems, nor does it prejudge any future policy choices regarding systems exhibiting higher degrees of autonomy. Any such assessment should take place in the context of a dedicated legislative review.

Having regard to the opinion of the European Economic and Social Committee,

Amendment 3

Having regard to the opinion of the Committee of the Regions,

Proposal for a regulation

Acting in accordance with the ordinary legislative procedure,

Recital 4

Whereas:

Text proposed by the Commission

(1) Regulation (EU) 2024/1689 of the European Parliament and of the Council lays down harmonised rules on artificial intelligence (AI) and aims to improve the functioning of the internal market, to promote the uptake of human-centric and trustworthy artificial intelligence, while ensuring a high level of protection of health, safety and fundamental rights, and supporting innovation. Regulation (EU) 2024/1689 entered into force on 1 August 2024. Its provisions enter into application in a staggered manner, with all rules entering into application by 2 August 2027.

Amendment

(2) The experience gathered in implementing the parts of Regulation (EU) 2024/1689 that have already entered into application can inform the implementation of those parts that are yet to apply. In this context, the delayed preparation of standards, which should provide technical solutions for providers of high-risk AI systems to ensure compliance with their obligations under that regulation, and the delayed establishment of the governance and the conformity assessment frameworks at national level result in a compliance burden that is heavier than expected. In addition, consultations of stakeholders have revealed the need for additional measures that facilitate and provide clarification on the implementation and compliance, without reducing the level of protection for health, safety and fundamental rights from AI-related risks that the rules of Regulation (EU) 2024/1689 seek to achieve.

(4) Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4and Annex to Commission Recommendation 2025/3500/EC5.

(3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective, simple and uniform application of the relevant rules.

(4) Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Though SMCs and SMEs have different operational and financial capabilities, the challenges they face in relation to administrative burden are in some cases similar, leading to a need for a number of adjustments concerning the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs. In all cases, such an extension must follow a strictly proportionate approach, seeing as SMEs and SMCs are two different categories of enterprises; this approach precludes any blanket uniform treatment and, on the contrary, requires that the differences between SMEs and SMCs be emphasized in the definition of model standards, guidelines or terms for contracts for the purposes of this Regulation. For the purposes of legal certainty and in order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4 and Annex to Commission Recommendation 2025/3500/EC5.

(3a) Additionally, it is important that the Commission and Member States’ competent authorities ensure that supervision, enforcement and monitoring of sectorial and national laws do not create overlaps, inconsistent interpretations or divergent enforcement in order to enable AI innovation in the private and public sector.

_________________

(3b) Regulation (EU) 2024/1689 lays down horizontal rules for AI systems in order to ensure a consistent and high level of protection of public interests as regards health, safety and fundamental rights. For high-risk AI systems referred to in Article 6(1), that Regulation applies in conjunction with the Union harmonisation legislation listed in Section A of Annex I. In certain cases, the Union harmonisation legislation may lay down requirements that achieve the same or a higher level of protection of the relevant public interests as specific requirements or obligations laid down in Regulation (EU) 2024/1689. Where this is the case, it should be possible to limit the application of specific requirements or obligations laid down in Regulation (EU) 2024/1689 in order to facilitate compliance, minimise administrative burden and duplications, while preserving the level of protection ensured by that Regulation. Such limitation should be possible where, and to the extent that, the Union harmonisation legislation listed in Section A of Annex I lays down requirements providing for an equivalent level of protection of health, safety or fundamental rights as the requirement or obligation concerned. The Commission should be empowered to adopt delegated acts to identify such cases, specifying the products concerned, the requirements or obligations that may be limited, and the conditions and scope of any limitation, ensuring that the level of protection provided by Regulation (EU) 2024/1689 is not reduced.

_________________

(4) Most of the Union companies are small and medium-sized enterprises, the majority of which are micro and small enterprises. Therefore, enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs where appropriate while safeguarding the overarching objectives and level of protection afforded under Regulation (EU) 2024/1689. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC1 and Annex to Commission Recommendation 2025/3500/EC2.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, pp. 36–41, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

(4a) The notion of ‘safety component’ is decisive for the classification of certain AI systems as high-risk according to Regulation (EU) 2024/1689. Thus, it should be targeted to capture only AI systems which could have an adverse impact on the health and safety of persons or property, in line with the risk-based approach of Regulation (EU) 2024/1689. The definition set out in Article 3(14) of Regulation (EU) 2024/1689 does not provide the necessary clarity to allow providers of AI systems to determine whether an AI system qualifies as a safety component and, as a result, risks leading to a disproportionate scope. It is therefore necessary to amend that definition. First, It is necessary to provide clarity on the concept of safety function. The safety function must be an intended purpose of the system, which is determined by the provider of the system. An AI system fulfils a safety function where its intended purpose, as determined by the provider, is to prevent or mitigate risks to health and safety of persons. In particular, this does not include AI systems which are intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or quality control operations of non-safety related aspects. The mere fact that an AI system is integrated into or operates within a product that is subject to safety regulation does not, in itself, mean that it fulfils a safety function.

4 Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (OJ L 124, 20.5.2003, p. 36, ELI: http://data.europa.eu/eli/reco/2003/361/oj).

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary skills to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a solution imposing stringent obligations to ensure a sufficient level of AI literacy is not suitable for all types of providers and deployers in relation to the promotion of AI literacy. Moreover, data indicates that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require providers and deployers to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The Commission and Member States should support and facilitate those efforts of providers and deployers of AI systems, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other initiatives. European competence frameworks, for example the Digital Competence Framework for Citizens (DigComp) and the AI Literacy Framework for Primary and Secondary Education, could be taken into account in the compliance of the Commission and Member States with this obligation. The European Artificial Intelligence Board (‘Board’) should support the Commission and Member States by adopting recommendations setting out common objectives to be achieved in order to meet their obligation and will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community.

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 provides a legal basis authorising the providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. This legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects might also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. For example, biases in eligibility or risk-scoring tools used to assess applications for various types of public permits or licences can restrict rights or effectively bar certain groups from access to public services. Accordingly, a substantial public interest exists to permit, exceptionally and where strictly necessary, the processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it also applies to the providers and deployers of other AI systems and AI models. That legal basis should be subject to the same limitations, conditions and safeguards as apply under the existing Article 10(5), thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council2 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council3. Furthermore, to enable providers of high-risk AI systems to lawfully undertake bias detection and mitigation activities in preparation for compliance with the high-risk requirements, including Article 10(2), points (f) and (g), of Regulation (EU) 2024/1689, the legal basis established by Article 4a should apply from entry into application of this Regulation.

5 Commission Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises (OJ L, 2025/1099, 28.5.2025, ELI: http://data.europa.eu/eli/reco/2025/1099/oj).

(6a) Article 5 of Regulation (EU) 2024/1689 prohibits certain practices of AI systems that are particularly harmful and abusive, contradict certain Union values and violate certain fundamental rights. Article 5 is to be kept under review, as notably shown by Article 112(1) of that Regulation. In light of technological and societal developments since the adoption of that Regulation, including the deployment and widespread use of AI systems generating non-consensual intimate images, videos, audio and similar material (‘non-consensual intimate material’) and child sexual abuse material, it is necessary to amend that list. Non-consensual intimate material constitutes sexual violence and abuse against individuals, especially women. AI systems that generate or manipulate such material pose a severe risk to health, safety and fundamental rights, including victims’ human dignity, personal autonomy, integrity and private life, with potentially serious lasting psychological and other harms and abuse at scale. The proliferation of such technologies, often described as ‘nudification’ applications, has created an urgent need for explicit regulatory prohibition. Child sexual abuse material, including wholly or partially synthetic material, constitutes a grave threat to the safety and fundamental rights of children. AI systems generating or manipulating such material pose a grave risk to human dignity and the rights of the child, and risk normalising, amplifying and perpetuating sexual violence against children. Accordingly, an amendment to Article 5 of Regulation (EU) 2024/1689 is necessary both to protect women, children, other individuals and society from seriously harmful practices, thereby pursuing the objectives of that Regulation itself, and to bring clarity to providers and deployers as to the scope of their obligations, thereby addressing implementation challenges.

Justification

(6b) It is necessary to define clearly the scope of the prohibition, including in particular the extent of providers’ and deployers’ obligations. This prohibition should not prevent providers from developing technical capabilities of AI systems to generate or manipulate images, videos, audio or similar material. The prohibition should be limited to AI systems that generate or manipulate non-consensual intimate material or child sexual abuse material in two cases concerning providers. First, it should cover systems intended to generate or manipulate such material. Second, it should cover systems where such generation or manipulation is a reasonably foreseeable and reproducible outcome and there are no reasonable and adequate technical safety measures and other safeguards in place, taking into account reasonably foreseeable misuse to reliably prevent, and where necessary correct, that outcome and correct observed or reported misuse, including circumvention of such measures. Technical measures and other safeguards to prevent the generation of such material could include data cleaning, refusal training, prompts safe design and output controls, runtime prompt guardrails, content classification and filtering mechanisms, usage restrictions, abuse detection mechanisms, and notice and action mechanisms. Such preventive measures should be reasonable for the specific AI system, and are considered adequate if they align with the state of the art and demonstrably prevent or sufficiently reduce in each specific case the likelihood of generating or manipulating such material, taking into account known and reasonably foreseeable misuse, including reasonably foreseeable circumvention of the preventive measures without significant technical modification. For providers retaining effective control over the provision of AI systems, for instance through a platform or a web interface, that could include following and reporting methods for misuse cases in full compliance with EU privacy and data protection law. In cases of observed or reported circumvention of the preventive measures or other safeguards, adequate corrective measures must also be taken to the extent that such measures are reasonable, taking into account the specific AI system, including its release and distribution strategy (such as open-source releases). The use of an AI system should be prohibited only where the deployer uses an AI system for the purpose of generating or manipulating non-consensual intimate material or child sexual abuse material, thereby violating the prohibition. This includes cases when a deployer uses or misuses for such purposes AI systems placed on the market or put into service that lack reasonable and adequate preventive measures or when the deployer circumvents the preventive measures mentioned above, or uses for such purposes lawful AI systems not intended to generate or manipulate such material. The prohibition on use therefore does not cover the use of an AI system for other lawful purposes, such as the generation or manipulation of material other than non-consensual intimate material or child sexual abuse material, even in cases where the AI system lacks reasonable and adequate safeguards that should have been put in place by the provider, nor does it cover accidental generation of manipulation of such content. Concerning the prohibition regarding non-consensual intimate material, where an AI system is intended for generation or manipulation of material falling under this prohibition, those measures and other safeguards should include means appropriate for the distribution of the system aimed at enabling the reliable collection and demonstration of consent of the depicted person to such generation or manipulation, in compliance with Regulation (EU) 2016/679. The prohibition regarding non-consensual intimate material should be limited to realistic depictions of intimate parts, notably the genitals, pubic area, anus, exposed buttocks or exposed female breasts, nipples or areolae or of sexually explicit activity. This ‘realism’ refers to the depiction of the person’s face, voice or their body in a credible real-life manner, regardless of the realism of the context of that depiction and of whether it fully corresponds to the actual voice or appearance of the depicted person. Conversely, it excludes cartoonish or physically impossible depictions of a person’s body. The prohibition of non-consensual intimate material does not affect the generation or manipulation of other forms of nude material, such as material that does not depict identifiable natural persons, realistic partially nude depictions where intimate parts are not revealed and sexually explicit activities are not depicted, non-realistic artistic nude works that do not realistically depict identifiable natural persons engaged in sexually explicit activity or depict their intimate parts. It also does not cover generative AI applications where intimate parts are not exposed or, if exposed, this is subject to the freely given, specific, informed, unambiguous and explicit consent of the depicted person (for example try-on applications), medical applications, such as medical anatomical simulations and mammograms).; this prohibition does not preclude he exceptional use of AI systems generating or manipulating nude depictions of the intimate parts of an identifiable person , in accordance with fundamental rights law, including data protection law, and applicable medical law, for the purpose of medical diagnosis and treatment by medical professionals where the person concerned is incapable of consent (for instance in an emergency situation). Finally, the prohibition on ‘manipulating’ non-consensual intimate material excludes cases where pre-existing intimate material is manipulated in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities, for instance the mere enhancement of an existing image depicting intimate parts or video depicting sexually explicit activities, such as changing the background, adding a text heading or enhancing the contrast or the brightness. Conversely, any manipulation of material, including material that already depicts intimate parts or sexually explicit activity, that increases the level of exposure or any depicted intimate parts or alters the nature of any depicted sexually explicit activities falls within this prohibition. The prohibition on child sexual abuse material should not prevent the placing on the market, putting into service or use of an AI system where a ‘without right’ defence applies under national law, as referred to in Article 5(1) of Directive 2011/93/EU. This includes activities carried out under domestic legal powers, such as the legitimate generation, or manipulation of child sexual abuse material by the authorities in order to conduct criminal proceedings or to prevent, detect or investigate crime, as well as the legitimate use of the AI system in the context of red-teaming and evaluation activities for the purpose of assessing the system’s compliance with the prohibition laid down in this Regulation.

Extending SME-specific regulations to SMCs should not be the norm; rather, it is fundamental that such harmonisation be exceptional and implemented solely in relation to specific provisions outlined by the AI Act. Treating SMCs and SMEs in the same way entails the inevitable risk of creating a number of competition- and competitiveness-related imbalances that will harm the undertakings that are genuinely the smallest, especially micro-enterprises.

(6c) These prohibitions constitute justified interferences with the freedom of expression and information and the freedom to conduct a business. They pursue weighty objectives of general interest and protect the rights and freedoms of others, including under Articles 1, 3(1), 4, 7, 8, 21, 23 and 24 of the Charter of Fundamental Rights. They are closely tailored. In the case of intimate material, they are limited to realistic depictions of identifiable natural persons; are limited to cases where the AI system is used to increase the level of nudity or explicitness; and exclude generation or manipulation with the person’s consent. Moreover, they are limited to requiring providers to implement ‘reasonable and adequate’ measures and safeguards in the case of systems not intended to generate or manipulate the prohibited material. They are also aligned with existing Union law, including Directive (EU) 2011/93/EU and Directive (EU) 2024/1385. The interferences respect the essence of Articles 11 and 16 of the Charter, are prescribed by law, and are proportionate. The conduct covered by these prohibitions may also violate other law, including criminal law. The prohibitions do not preclude prosecution under that law. However, insofar as an infringement of the prohibitions may result in the imposition of penalties of a criminal nature, which may be laid down pursuant to Article 99(1) of Regulation (EU) 2024/1689, and to the extent that the same conduct is sanctioned under criminal law, including criminal law falling within the scope of Directive 2011/93/EU and Directive (EU) 2024/1385, Member States are required to ensure respect for the ne bis in idem principle in accordance with the Charter of Fundamental Rights.

Amendment 4

(6d) The prohibitions are without prejudice to remedies available under national laws for individuals to protect their fundamental rights, including rights to their image, privacy and human dignity.

Proposal for a regulation

(7) In order to ensure consistency, avoid duplication and minimise administrative burdens in relation to the procedure for designating notified bodies under Regulation (EU) 2024/1689, while maintaining the same level of scrutiny, a single application and a unified assessment procedure should be available for new conformity assessment bodies and notified bodies which are designated under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, such as under Regulations (EU) 2017/745 and (EU) 2017/746 of the European Parliament and of the Council, where such a procedure is established under that Union harmonisation legislation. The single application and unified assessment procedure aims at facilitating, supporting and expediting the designation procedure under Regulation (EU) 2024/1689, while ensuring compliance with the requirements applicable to notified bodies under that Regulation and the Union harmonisation legislation listed in Section A of Annex I thereto. The unified assessment procedure has to be carried out with respect to the tasks and responsibilities of the authorities involved. Moreover, it should be clarified that a conformity assessment body that is designated under more than one Union harmonisation legislation listed in Section A of Annex I should have to apply only once to be designated under this Regulation.

Recital 4 a (new)

(8) With a view to ensuring the smooth application and consistency of Regulation (EU) 2024/1689, amendments should be made to it. A technical correction to Article 43(3), first subparagraph, of Regulation (EU) 2024/1689 should be added to align the conformity assessment requirements with the requirements of providers of high-risk AI systems in Article 16 of that Regulation. Moreover, it should be clarified that where a provider of a high-risk AI system is subject to the conformity assessment procedure under Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689, and the conformity assessment extends to compliance of the quality management system of that Regulation and of such Union harmonisation legislation, the provider should be able to include aspects related to quality management systems under that Regulation as part of the quality management systems under such Union harmonisation legislation, in line with Article 17(3) of Regulation (EU) 2024/1689. Article 43(3), second subparagraph, should be amended to clarify that notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and which aim to assess high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I to that Regulation, should have the power to assess conformity of high-risk AI systems under certain conditions for 18 months from [the entry into application of this Regulation]. This amendment is without prejudice to Article 28 of Regulation (EU) 2024/1689, thus conformity assessment bodies that wish to be designated and notified under that Regulation can submit an application at any time during and after these 18 months. Moreover, Regulation (EU) 2024/1689 should be amended to clarify that where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 and falls within one of the use-cases listed in Annex III to that Regulation, the provider should follow the relevant conformity assessment procedure as required under that relevant harmonisation legislation.

Text proposed by the Commission

(8a) Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847 complement each other so that the safety and cybersecurity of products with digital elements is ensured. Article 12 of Regulation (EU) 2024/2847 lays down that where high-risk AI systems fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847. In order to improve the visibility of the interplay of Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847, the rule of Article 12 of Regulation (EU) 2024/2847 should also be reflected in Regulation (EU) 2024/1689. The interplay between the two instruments should thereby not be affected.

Amendment

(8b) In accordance with Article 6(1) of Regulation (EU) 2024/1689, AI systems are classified as high-risk where an AI system that is a component of a product covered by Union harmonisation legislation listed in Section A of Annex I to that Regulation is a safety component and that product requires a third-party conformity assessment. The requirement that such product must require a third-party conformity assessment, however, does not affect the choice of the manufacturer regarding the conformity assessment procedure for such product. Where Union harmonisation legislation listed in Section A of Annex I allows to choose a conformity assessment procedure based on harmonised standards amongst alternative conformity assessment procedures, this possibility remains applicable also to products in which a high-risk AI system is embedded. Article 6(1) of Regulation (EU) 2024/1689 should not be understood to require products in which a high-risk AI system is embedded automatically to undergo a third-party conformity assessment involving a notified body. Where this possibility is provided under Union harmonisation legislation, the provider of the product in which a high-risk AI system is embedded could continue to rely on harmonised standards to comply with the requirements of the Union harmonisation legislation and Regulation (EU) 2024/1689 as a conformity assessment procedure.

(4a) AI agents should constitute a new category of artificial intelligence applications that can execute sophisticated real-world operations rapidly and with reduced human oversight, including those of dual-use nature covered by Article 2(3) of Regulation (EU) 2024/1689. While conventional AI systems deliver outputs like forecasts, generated content, suggestions or judgments, AI agents distinguish themselves through their capacity to carry out concrete actions autonomously. These features can exacerbate associated risks for consumers stemming from the placing on the market, the putting into service or the use of AI agents. To enhance legal clarity, it is important to clarify that AI agents fall within the definition of AI systems in Article 3, point (1), of Regulation (EU) 2024/1689, while keeping in place a risk-based and future-proof regulatory approach.

(8d) In order to enhance competitiveness and innovation, it is essential to support economic operators that are required to comply simultaneously with the requirements or obligations set out in Chapter III, Sections 2 and 3, and with relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I. To support and simplify the regulatory compliance pathways of such economic operators, the Commission should request, without undue delay, the European standardisation organisations, to develop standardisation deliverables, including, where appropriate, harmonised standards. Those standardisation deliverables should be based on the harmonised standards published in the Official Journal that give presumption of conformity with the requirements or obligations of this Regulation as well as any relevant harmonised standards published in the Official Journal that give presumption of conformity with the relevant requirements or obligations under the Union harmonisation legislation listed in Annex I. Such standardisation deliverables should help reduce legal uncertainty, avoid unnecessary duplication of conformity assessment activities, testing, documentation and reporting obligations, and lower compliance costs, in particular for small and medium-sized enterprises and start-ups. Timely development of such deliverables is essential in order to provide economic operators with practical and reliable technical solutions, strengthen legal certainty and facilitate the placing on the market, putting into service and use of AI systems in accordance with this Regulation and the Union harmonisation legislation listed in Annex I.

Amendment 5

(9) To streamline compliance and reduce the associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the required content in Section B of Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate. This simplification will strike a better balance without undermining the protection laid down by Regulation 2024/1689. Such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons. Furthermore, a provider applying Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

Proposal for a regulation

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document.

Recital 4 b (new)

(10a) In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. To ensure coherence, legal certainty and an efficient allocation of supervisory responsibilities between Union and national levels, the scope of the Union-level AI regulatory sandbox should be clearly defined in order to avoid any overlapping with national AI regulatory sandboxes established pursuant to that Regulation. In order to foster innovation and facilitate the uptake of AI, SMEs, including startups, and SMCs should be provided with priority access to the AI regulatory sandboxes established by the AI Office.

Text proposed by the Commission

(10b) Moreover, the provisions on cooperation between relevant competent authorities for the operation of an AI regulatory sandbox should be clarified in order to ensure their effective functioning. For that reason, the empowerment of the Commission to adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation and supervision of the AI regulatory sandboxes should be extended to also cover governance aspects of such sandboxes. In addition, where AI regulatory sandboxes involve innovative AI systems that process personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the relevant national supervisory authorities should be associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.

Amendment

(11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions, subject to sufficient safeguards. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation.

(4b) To ensure that SMEs and startups can get an early understanding of their risk classification, the Commission and Member States should provide information assistance in a comprehensible manner, including through initiatives such as the AI Act Service Desk.

(11a) It is also appropriate to ensure that real-world testing of high-risk AI systems covered by the Union harmonisation legislation listed in Section B of Annex I to that Regulation is possible. Those systems are subject to the requirements and procedures of the relevant sectoral legislation and are, for most purposes, not directly subject to Regulation (EU) 2024/1689. Those sectoral acts will, in due course, incorporate requirements corresponding to the requirements laid down by Articles 8 to15 of that Regulation. Therefore, it is appropriate to ensure that Member States can allow real-world testing of these AI systems with a view to assessing and verifying the conformity of those systems with the requirements of Articles 8 to 15 of the Regulation. If Member States decide to allow such testing, the Regulation should require Member States to adopt frameworks laying down the detailed requirements for such testing. The Regulation should provide for essential elements to be contained in such frameworks. When designing such frameworks, Member States should ensure a high level of protection of health, safety and fundamental rights of natural persons. Before implementing a framework, Member States should notify it to the Commission. The real-world testing should comply with the relevant Union harmonisation legislation listed in Section B of Annex I, including any applicable provisions regarding testing. However, this should not affect the application of the new article regarding real-world testing.

Amendment 6

(12) Article 63 of Regulation (EU) 2024/1689 offers microenterprises who are providers of high-risk AI systems the possibility to benefit from a simplified way to comply with the obligation to establish a quality management system. With a view to facilitating compliance for more innovators, that possibility should be extended to all SMEs, including start-ups.

Proposal for a regulation

(12a) In light of the important role of the AI Office for the effective and coordinated governance of Regulation (EU) 2024/1689, as further reinforced by this Regulation, and without prejudice to the next Multiannual Financial Framework and to the budgetary procedure, the Commission should allocate adequate human, financial and technical resources to the AI Office to ensure that it can effectively and within reasonable timeframes perform its tasks in respect of Regulation (EU) 2024/1689, including a sufficient number of permanent personnel with in-depth competences and technical expertise.

Recital 5

(13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances.

Text proposed by the Commission

(14) In order to strengthen the governance system for AI systems, it is necessary to clarify the role of the AI Office in monitoring and supervising compliance of such AI systems with Regulation (EU) 2024/1689. The Commission has exclusive competence as regards general-purpose AI models under Article 88 of that Regulation. To increase coherence, clarity and effectiveness, and in light of the reach and impacts of AI systems linked to those competences, the scope of the AI Office’s exclusive competence to supervise systems should be refined. In particular, the AI Office should have exclusive competence over AI systems built on general-purpose AI models not only where both the system and the model are developed by the same provider, but also where they are developed by providers that form part of the same undertaking. However, in certain cases, notably where there is specific sectoral supervision, responsibility should remain with the relevant national competent authority. Accordingly, certain exceptions should be laid down. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. Other deployers should remain subject to national supervision and enforcement. Moreover, this does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689.

Amendment

(15) Additionally, considering the existing supervisory and enforcement system under Regulation (EU) 2022/2065 of the European Parliament and of the Council1, it is appropriate to grant the Commission the powers of a competent market surveillance authority under Regulation (EU) 2024/1689 where an AI system qualifies as a very large online platform or a very large online search engine within the meaning of Regulation (EU) 2022/2065, or where it is embedded in such a platform or search engine. This should contribute to ensuring that the exercise of the Commission’s supervision and enforcement powers under Regulation (EU) 2024/1689 and Regulation (EU) 2022/2065, as well as those applicable to general-purpose AI models integrated into such platforms or search engines, are carried out in a coherent and effective manner. This is also appropriate in light of the importance of such platforms and search engines, in view of their reach, impact and potential to cause complex and large societal harms. The personal scope of this exclusive competence should extend to the providers of those AI systems and to their deployers within the same undertaking. In the case of AI systems embedded in or qualifying as a very large online platform or search engine, the first point of entry for the assessment of the AI systems are the risk assessment, mitigating measures and audit obligations prescribed by Articles 34, 35 and 37 of Regulation (EU) 2022/2065, without prejudice to the AI Office’s powers to investigate and enforce ex post non-compliance with the rules of this Regulation. In the context of the analysis of this risk assessment, mitigating measures and audits, the Commission services responsible for the enforcement of Regulation (EU) 2022/2065 may seek the opinion of the AI Office on the outcome of a potential earlier or parallel risk assessment carried out under this Regulation and the applicability of prohibitions under this Regulation. In addition, the AI Office and the competent national authorities under (EU) 2024/1689 should coordinate their enforcement efforts with the authorities competent for the supervision and enforcement of Regulation (EU) 2022/2065, including the Commission, in order to ensure that the principles of loyal cooperation, proportionality and non bis in idem are respected, while information obtained under the respective other Regulation would be used for the purposes of supervision and enforcement of the other only provided the undertaking agrees. In particular, those authorities should exchange views regularly and take into account, in their respective areas of competence, any fines and penalties imposed on the same provider for the same conduct through a final decision in proceedings relating to an infringement of other Union or national rules, so as to ensure that the overall fines and penalties imposed are proportionate and correspond to the seriousness of the infringements committed.

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

(16) When supervising and enforcing those AI systems, the AI Office has the same role and responsibility as a market surveillance authority under Regulation (EU) 2024/1689. Consequently, it is necessary for the AI Office to have all of the powers and responsibilities that market surveillance authorities have under that Regulation and under Regulation (EU) 2019/1020 (“the general powers”). These must ensure the appropriate and effective enforcement of the requirements and obligations set out by Regulation (EU) 2024/1689. However, it is necessary to specify, complement, and frame certain essential elements and other aspects of the general powers, as well as their safeguards (“the specifying provisions”) . In particular, it is necessary to lay down provisions governing the relationship between the AI Office and national authorities; provisions specifying, complementing, and constraining the powers to request information and conduct on-site inspections; provisions governing investigations, including the possibility for binding commitments; and provisions specifying and constraining power to find non-compliance, impose fines and impose periodic penalties. Where a type of general power has been so specified, the AI Office may not circumvent the conditions and limits of those powers by relying on a related general power. Conversely, types of general power that are not specified and framed in respect of the AI Office – such as the power to adopt measures referred to in Article 16(3) of Regulation (EU) 2019/1020 – may be relied on by the AI Office. As necessary for the good implementation of Regulation (EU) 2024/1689 the Commission may adopt implementing acts further defining the rules and the procedures concerning the application of limitation periods and, the access to the file and the negotiated disclosure of information. In exercising all of these powers, AI Office must comply with the Charter of Fundamental Rights. Additionally, the AI Office is subject to the safeguards and protection for fundamental rights laid down in the specifying provisions.

(5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary notions to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a one-size-fits-all solution is not suitable for all types of providers and deployers in relation to the promotion of AI literacy, rendering such a horizontal obligation ineffective in achieving the objective pursued by this provision. Moreover, data indicate that imposing such an obligation creates an additional compliance burden, particularly for smaller enterprises, whereas AI literacy should be a strategic priority, regardless of regulatory obligations and potential sanctions. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require the Member States and the Commission, without prejudice to their respective competences, to individually, collectively and in cooperation with relevant stakeholders encourage providers and deployers to provide a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, including through offering training opportunities, providing informational resources, and allowing exchange of good practices and other non-legally binding initiatives, without, however, completely eliminating the obligation of providers and implementers of AI systems to take, likewise, the necessary measures to ensure a sufficient level of knowledge in the field of AI of their staff in order to play responsible roles. The European Artificial Intelligence Board (‘Board’) will ensure recurrent exchange between the Commission and Member States on the topic, while the Apply AI Alliance will allow discussion with the wider community. This amendment is without prejudice to the broader measures taken by the Commission and the Member States to promote AI literacy and competences for the wider population, including learners, students, and citizens at different ages and in particular through education and training systems.

(17) In addition to those procedural and fundamental rights safeguards the procedural rights provided for in Article 18 of Regulation (EU) 2019/1020 should apply mutatis mutandis to providers of AI systems, without prejudice to more specific procedural rights provided for in Regulation (EU) 2024/1689. When national market surveillance authorities, through the single point of contact, request that the AI Office takes supervisory and enforcement measures with regards to AI systems under its exclusive supervision, the AI Office shall no later than four months following receipt, inform the single point of contact of its intention to exercise its supervisory and enforcement powers or of its reasons for not exercising its powers. If the AI Office decides to exercise its supervisory and enforcement powers, it shall also inform market surveillance authorities, when suitable through the single point of contact, about the final outcome of such proceedings and of intermediate developments that the AI Officer considers as having a major impact in the investigation, including the decision to open proceedings, to impose a fine pursuant to Article 75d (1c), and to withdraw or recall the AI system from the market.

Amendment 7

(18) To enable access to Union market for AI systems which are under the supervision by the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to third party conformity assessment, the Commission should be responsible for pre-market conformity assessments of those systems.

Proposal for a regulation

(19) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing the cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests without undue delay, and that the involved authorities or bodies should have a mutual obligation to cooperate. It should be clarified that these provisions are without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates. In particular, these provisions do not limit any powers that those authorities and bodies have to request information pursuant to other Union or national law. Accordingly, those authorities and bodies retain any power they have to directly request information from operators pursuant to their mandate or other law.

Recital 5 a (new)

(19a) The requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 address specific risks inherent to AI systems, including bias, unpredictable model behaviour, poor robustness or accuracy, vulnerabilities to attacks by third parties, lack of transparency of AI system. By addressing AI specific risks, that Regulation complements the requirements laid down in Union harmonisation legislation listed in its Annex I, without duplicating them. Regulation (EU) 2024/1689 provides mechanisms for economic operators to minimise the compliance burden. In particular, Articles 8(2) on the interplay with the sectoral legislation, 9(10) on risk management and 17(3) on quality management allow economic operators to integrate, when necessary and appropriate, an assessment of AI specific risks into existing risk and quality management systems. Article 40 further requires the Commission to specify that AI Act harmonised standards must be consistent with standards developed under the Union harmonisation legislation listed in Annex I. The Commission should provide guidelines to assist economic operators of high-risk AI systems covered in Annex I in complying with this Regulation, including by providing guidance on application of Articles 8(2), 9(10) and 17(3) as mechanisms to minimise the compliance burden, in line with principles of complementary and proportionality. These guidelines should be published at the latest on 1 August 2027.

Text proposed by the Commission

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 4 months for providers who have already placed their systems on the market before the 2 August 2026.

Amendment

(21) To provide sufficient time for providers of high-risk AI systems and to clarify applicable rules to the AI systems already placed on the market or put into service before the entry into application of relevant provisions of the Regulation (EU) 2024/1689, it is appropriate to clarify the application of a grace period provided in Article 111(2) of that Regulation. The grace period, for the purpose of Article 111(2), should apply to a type and model of AI systems already placed in the market. This means that if at least one individual unit of the high-risk AI system has been lawfully placed on the market or put into service before the date specified in Article 111(2), other individual units of the same type and model of high-risk AI system are subject to the grace period provided in Article 111(2) and thus may continue to be placed on the market, made available or put into service on the Union market without any additional obligations, requirements or the need for additional certification, as long as the design of that high-risk AI system remains unchanged. For the purposes of application of the grace period provided in Article 111(2), the decisive factor is the date on which the first unit of that type and model of high-risk AI system was placed on the market or put into service on the Union market for the first time. Any significant change to the design of that AI system after the date specified in Article 111(2) should trigger the obligation of the provider to comply fully with all relevant provisions of this Regulation applicable to high-risk AI systems, including the conformity assessment requirements.

(5a) Recent developments have demonstrated the incompatibility of certain AI practices with the Union's fundamental rights framework while increasing legal uncertainty regarding them. AI systems that alter, manipulate or artificially produce images or videos depicting natural persons engaged in sexually explicit activities, displaying their intimate body parts or undresses a person without consent cause harm to victims and violate fundamental rights to dignity and privacy. While Regulation (EU) 2024/1689 establishes a framework for prohibited AI practices, the effective protection of persons, particularly women and minors who are disproportionately targeted, requires the explicit prohibition of such AI systems. Whereas Article 112 of Regulation (EU) 2024/1689 obliges the Commission to assess, on an annual basis, the necessity of amendments to the list of prohibited practices laid down in Article 5 of that Regulation and the list set out in Annex III of that Regulation, and to submit the findings of that assessment to the European Parliament and the Council, the proliferation of technologies, marketed as 'nudification' applications, has created an urgent need for explicit regulatory prohibition. This is without prejudice towards the rights, freedoms and principles recognised by Article 6 TEU and the Charter of Fundamental Rights of the European Union, and the exercise of the rights guaranteed therein to freedom of expression and information and the freedom of the arts and sciences.

(22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026.Against this background, it is appropriate that the date for the application of Sections 1, 2 and 3 of Chapter III is set to 2 December 2027 for AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk pursuant to Article 6(1) and Annex I. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regulation (EU) 2024/1689 and aims to provide the necessary time for adaptation and implementation of the corresponding obligations. The timely availability of support instruments, including guidance, relevant standards, common specifications and codes of practice is important in order to facilitate compliance and reduce the risk of divergent interpretation and uneven application of the rules across Member States. In order to ensure legal certainty and to avoid further delays in application of this Regulation, the Commission should ensure that measures in support of compliance with regard to Chapter III, Sections 1, 2, and 3 are in place in due time to ensure timely and effective implementation of the necessary provisions.

Amendment 8

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. Given that the codes of practice referred to in Article 50(7) and 56(6) have limited legal effect, and in particular do not grant a presumption of conformity, it is not strictly necessary for these codes to be approved by an implementing act. Providers should be able to rely, under Article 53(4) and 54(2), on codes of practice assessed as adequate pursuant to Article 56(6). The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply with their obligation under Article 72(1) of Regulation (EU) 2024/1689, the Commission should be required to publish guidance, including a voluntary template, on the post-market monitoring plan by 2 September 2027.

Proposal for a regulation

(23a) The use of artificial intelligence in machinery can help foster innovation and improve the efficiency of those machines. The application of Regulation (EU) 2023/1230 and Regulation (EU) 2024/1689 might lead to overlaps. At the same time, it is important to ensure a level of protection from risks related to the use of artificial intelligence in machinery that is consistent with the level of protection from high-risk AI systems ensured by Regulation (EU) 2024/1689. Given the specific nature of machinery and the machinery sector, and in order to address the need to simplify the regulatory framework for artificial intelligence-enabled machinery, it is appropriate to move to a sectoral approach by moving Regulation (EU) 2023/1230 from section A to section B of the Regulation (EU) 2024/1689. Accordingly, first, the application of Regulation (EU) 2024/1689 to those machines should be limited to the provisions referred to in Article 2(2) of that Regulation. The references to Directive 2006/42/EC in Annex I to Regulation (EU) 2024/1689 should also be moved from Section A to Section B and updated so as to refer to Regulation (EU) 2023/1230. Second, it is crucial to ensure that Regulation (EU) 2023/1230 incorporates essential health and safety requirements for high-risk AI systems classified under Article 6(1) of (EU) Regulation 2024/1689 used as a safety component in machinery or themselves constituting machinery that ensure a level of protection consistent with Regulation (EU) 2024/1689. To that end, the Commission should be required to adopt delegated acts amending Annex III of Regulation (EU) 2023/1230 in order to reflect relevant requirements from Regulation (EU) 2024/1689. The delegated acts should ensure that the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 are reflected. To avoid a legal gap and ensure alignment with the entry into application of the high-risk AI system rules under Regulation (EU) 2024/1689, those delegated acts should apply by 2 August 2028. For those same reasons, manufacturers should be free to rely on harmonised standards or common specifications referenced or adopted under Regulation (EU) 2024/1689 that cover the relevant essential requirements for the presumption of conformity within the meaning of Article 20 Regulation (EU) 2023/1230 until harmonised standards or common specifications regarding AI are referenced or adopted under Regulation (EU) 2023/1230.

Recital 6

(24) Conformity assessment of high-risk AI systems under Regulation (EU) 2024/1689 may require involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated under that Regulation may carry out conformity assessments and only for the activities related to the categories and types of AI systems concerned. To enable the specification of the scope of the designation of conformity assessment bodies notified under Article 30 of Regulation (EU) 2024/1689, it is necessary to draw up a list of codes, categories, and corresponding types of AI systems. The list of codes should take into account whether the AI system is a component of a product or itself a product covered by the Union harmonisation legislation listed in Annex I (referred to as ‘AIP codes’, for AI systems covered by product legislation) or a system referred in Annex III of Regulation (EU) 2024/1689, which currently concerns only biometric AI systems referred to in point (1) of Annex III (referred to as ‘AIB codes’, for biometric AI systems). Both AIP codes and AIB codes are vertical codes. The AIP codes are reference codes to provide a link to the Union harmonisation legislation listed in Section A of Annex I of Regulation (EU) 2024/1689. The AIB codes are new codes specific to Regulation (EU) 2024/1689 to identify biometric AI systems referred in paragraph 1 of Annex III of that Regulation. The list of codes should also take into account specific types and underlying technologies of AI systems (referred to as ‘AIH codes’, for horizontal AI system codes). The AIH codes are new AI technology-specific codes and can be applied in conjunction with AIP or AIB vertical codes. The AIH codes cover AI systems’ underlying types and technologies. The list of codes, including three categories, should provide for a multi-dimensional typology of AI systems which ensures that conformity assessment bodies designated as notified bodies are fully competent for the AI systems they are required to assess.

Text proposed by the Commission

(25) Regulation (EU) 2018/1139 of the European Parliament and the Council1 lays down common rules in the field of civil aviation. Article 108 of Regulation (EU) 2024/1689 sets out amendments to Regulation (EU) 2018/1139 to ensure that the Commission takes into account, on the basis of the technical and regulatory specificities of the civil aviation sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 when adopting any relevant delegated or implementing acts on the basis of that act. A technical correction extending specific articles of Regulation (EU) 2018/1139 is necessary to ensure that those mandatory requirements for high-risk AI systems laid down in Regulation (EU) 2024/1689 are fully covered when adopting relevant delegated or implementing acts on the basis of Regulation (EU) 2018/1139.

Amendment

(26) In order to ensure legal certainty as soon as possible, with a view to the imminent general application of Regulation (EU) 2024/1689, this Regulation should enter into force as a matter of urgency.

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. Discrimination might result from the bias in AI models and AI systems other than high-risk AI systems for which of Regulation (EU) 2024/1689 already provides a legal basis authorising the processing of special categories of personal data under Article 9(2), point (g), of Regulation (EU) 2016/679 of the European Parliament and of the Council6 . Given that discrimination might result also from those other AI systems and models, it is therefore appropriate that Regulation (EU) 2024/1689 should provide for a legal basis for the processing of special categories of personal data also by providers and deployers of other AI systems and AI models as well as deployers of high-risk AI systems. The legal basis is established in compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council7 and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council8 provides a legal basis allowing, where necessary for the detection and removal of bias, the processing of special categories of personal data by providers and deployers of all AI systems and models, subject to appropriate safeguards that complement Regulations (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680, as applicable.

(26a) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their joint opinion on 20 January 2026,

(6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 already provides a legal basis authorising providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. That legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Nevertheless, biases likely to have those effects might also result from the actions of the deployers of high-risk AI systems. Furthermore, such biases could also arise in the case of other AI systems or models. In each of those further cases, a substantial public interest exists to permit processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it applies to the providers and deployers of other AI systems and AI models. That legal basis should be subject to the same limitations, conditions and safeguards as set out in the existing Article 10(5) of Regulation (EU) 2024/1689, thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council[2]. Furthermore, to enable providers of high risk AI systems to lawfully undertake bias detection and mitigation activities in preparation for compliance with the high-risk requirements, including Article 10(2), points (f) and (g) of Regulation (EU) 2024 /1689 , the legal basis established by Article 4a of that Regulation should apply from the entry into application of this Regulation.

HAVE ADOPTED THIS REGULATION:

__________________

Article 1 Amendments to Regulation (EU) 2024/1689

__________________

Regulation (EU) 2024/1689 is amended as follows:

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(1) in Article 1(2), point (g) is replaced by the following:

6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

’(g) measures to support innovation, with a particular focus on small mid-cap enterprises (SMCs) and small and medium-sized enterprises (SMEs), including start-ups.;’

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(2) Article 2 is amended as follows:

7 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

‘2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Section B of Annex I, only Article 6(1), Article 60a, Articles 102 to 112 shall apply. Articles 57 to 59 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.;’’

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

(2b) paragraph 7 is replaced by the following:

8 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89–131, ELI: http://data.europa.eu/eli/dir/2016/680/oj).

‘7. Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 4a and Article 59 of this Regulation.’

Amendment 9

(2c) In Article 2, the following paragraph 13 is added:

Proposal for a regulation

“13. For high-risk AI systems referred to in Article 6(1), the application of specific requirements or obligations laid down in Articles 9-15 and 17-25 of this Regulation may be limited, where and to the extent that:

Recital 6 a (new)

(a) Union harmonisation legislation listed in Section A of Annex I lays down requirements or obligations providing for an equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned; and (b) such limitation does not reduce the overall level of protection provided for by this Regulation.

Text proposed by the Commission

By 2 August 2027 the Commission shall adopt delegated acts in accordance with Article 97 to specify the high-risk AI systems concerned, the requirements or obligations that may be limited, the conditions under which such limitation applies, and the scope of the limitation.”

Amendment

(3) Article 3 is amended as follows:

(6a) To encourage the use of new technologies for safer products and to avoid duplicative requirements in the New Legislative Framework and Regulation (EU) 2024/1689, the safety component aspect of the high risk-classification should be clarified. Additional layers of safety, where a product is already deemed safe and compliant according to product-specific rules and where the AI embedded system does not serve a safety function to the product, should not automatically lead to designation of the AI system as high-risk.

Point (14) is amended as follows: (14) ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property; for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property;

Amendment 10

‘(a) the following points (14a) and (14b) are inserted:

Proposal for a regulation

(14a) micro, small and medium-sized enterprise (‘SME’) means a micro, small or medium-sized enterprise as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC;

Recital 8 a (new)

(14b) small mid-cap enterprise (‘SMC’) means a small mid-cap enterprise as defined in point (2) of the Annex to Commission Recommendation (EU) 2025/1099;’

Text proposed by the Commission

(4) Article 4 is replaced by the following:

Amendment

‘Article 4

(8a) Regulations (EU) 2024/1689 and (EU) 2024/2847 are complementary laws that ensure the safety and cybersecurity of products with digital elements. It is necessary to ensure alignment of those Regulations to allow for their smooth interplay. Where those high-risk AI systems fulfil the essential cybersecurity requirements set out in this Regulation, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under this Regulation.

AI literacy

Amendment 11

1. Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation shall not be understood as requiring providers or deployers to guarantee any specific level of AI literacy of any individual.

Proposal for a regulation

2. The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1. For that purpose, the Commission shall publish practical examples for compliance with that obligation on the single information platform referred to in point (d) of Article 62(3).

Recital 9

3. The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 2, including by setting out common objectives.’;’

Text proposed by the Commission

(5) the following Article 4a is inserted in Chapter I:

Amendment

‘Article 4a

(9) To streamline compliance and reduce the associated costs, providers of AI systems should not be required to register AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation. Given that such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons, imposing registration requirements would constitute a disproportionate compliance burden. Nevertheless, a provider who considers that an AI system falls under Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

Processing of special categories of personal data for bias detection and mitigation

deleted

1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Amendment 12

(a) the bias detection and correction cannot be effectively fulfilled by processing other data, including synthetic or anonymised data;

Proposal for a regulation

(b) the special categories of personal data are subject to technical limitations on the re-use of the personal data, and state-of-the-art security and privacy-preserving measures, including pseudonymisation;

Recital 10

(c) the special categories of personal data are subject to measures to ensure that the personal data processed are secured, protected, subject to suitable safeguards, including strict controls and documentation of the access, to avoid misuse and ensure that only authorised persons have access to those personal data with appropriate confidentiality obligations;

Text proposed by the Commission

(d) the special categories of personal data are not transmitted, transferred or otherwise accessed by other parties;

Amendment

(e) the special categories of personal data are deleted once the bias has been corrected or the personal data has reached the end of its retention period, whichever comes first;

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

(f) the records of processing activities pursuant to Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680 include the reasons why the processing of special categories of personal data was strictly necessary to detect and correct biases, and why that objective could not be achieved by processing other data.

(10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In addition, it is appropriate that the AI Office establishes an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be better streamlined and resources optimally utilised.

2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that:

Amendment 13

(a) processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations; and

Proposal for a regulation

(b) all of the conditions and safeguards set out in paragraph 1 are applied.

Recital 20

2b. This paragraph does not create any obligation to conduct such bias detection and correction.’

Text proposed by the Commission

(5a) Article 5 is amended as follows:

Amendment

(a) the following points are added to paragraph 1, first subparagraph:

(20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 6 months for providers who have already placed their systems on the market before the 2 August 2026.

(ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;

deleted

(bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, save where a ‘without right’ defence applies under national law;

Amendment 14

(b) The following paragraph is inserted:

Proposal for a regulation

1a. For the purposes of paragraph 1, first subparagraph, points (ba) and (bb):

Recital 22 a (new)

(a) the placing on the market or putting into service of an AI system that generates or manipulates the material or performance referred to in points (ba) or (bb) above is only prohibited where:

Text proposed by the Commission

(i) that generation or manipulation is the intended purpose of the AI system; or

Amendment

(ii) the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse.

(22a) To ensure a sufficient degree of legal clarity in the event of continued delays in the availability of harmonised standards, it is necessary to mitigate potential legal uncertainty resulting from their absence. To that end, the Commission should be required to adopt common specifications by 2 December 2027. This deadline aligns with the deferred application date of Chapter III, Sections 1, 2, and 3, of Regulation (EU) 2024/1689 for AI systems classified as high-risk under Article 6(1) and Annex I of that Regulation, which has also been postponed to 2 December 2027. Additionally, the Commission should be required to issue standardisation requests covering the obligations set forth in Chapter V, Sections 2 and 3, of that Regulation by 2 December 2027, as it has not proceeded without undue delay.

(b) the use of an AI system that generates or manipulates the material or performance referred to in points (ba) and (bb) above is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material or performance.

Amendment 15

1b. For the purposes of paragraph 1, first subparagraph, point (ba), an AI system that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation.’

Proposal for a regulation

(5b) Article 6 is amended as follows:

Recital 23

1a. For the purposes of this Regulation including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components. 1b. AI systems whose failure or malfunctioning would endanger health and safety shall qualify as safety components notwithstanding paragraph 1a. 1c. A product that is required to undergo a third-party conformity assessment solely due to risks other than risks to health and safety in particular risks relating to distribution of radio spectrum or electromagnetic interference that do not affect health and safety shall not be considered as fulfilling the condition in paragraph 1, point (b).

Text proposed by the Commission

(7) Article 10 is amended as follows:

Amendment

(a) paragraph 1 is replaced by the following:

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

‘1. High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2, 3 and 4 of this Article and in Article 4a(1) whenever such data sets are used.;’

(23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. The removal of the empowerment to adopt a harmonised template for a post-market monitoring plan in Article 72(3) of Regulation (EU) 2024/1689 has as an additional benefit that it will offer more flexibility for providers of high-risk AI systems to put in place a system for post-market monitoring that is tailored to their organisation. At the same time, recognising the need to offer clarity on how providers of high-risk AI systems are required to comply, the Commission should be required to publish guidance.

(b) paragraph 5 is deleted;

Amendment 16

(c) paragraph 6 is replaced by the following:

Proposal for a regulation

‘6. For the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2, 3 and 4 of this Article and Article 4a(1) shall apply only to the testing data sets.;’

Recital 23 a (new)

(8) in Article 11(1), the second subparagraph is replaced by the following:

Text proposed by the Commission

‘That technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section and to provide national competent authorities and notified bodies with the necessary information in a clear and comprehensive form to assess the compliance of the AI system with those requirements. It shall contain, at a minimum, the elements set out in Annex IV. SMEs, including start-ups, and SMCs, may provide the elements of the technical documentation specified in Annex IV in a simplified manner. To that end, the Commission shall establish a simplified technical documentation form targeted at the needs of SMEs, including start-ups, and SMCs. Where an SME, including a start-up, or an SMC, opts to provide the information required in Annex IV in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept the form for the purposes of the conformity assessment.;’

Amendment

(9) in Article 17, paragraph 2 is replaced by the following:

(23a) This Regulation shall not alter Regulation (EU) 2024/1689 as regards the scope, classification or compliance timelines applicable to AI systems.

‘2. The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation.;’

Amendment 17

(9a) Article 25(2) is replaced by the following:

Proposal for a regulation

2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. In particular, this obligation shall include, as long as it is relevant for the purposes specified in the previous subparagraph, the following:

Article 1 – paragraph 1 – point 2 a (new)

(a) making available technical documentation sufficient to assess compliance with Article 16 requirements;

Regulation (EU) 2024/1689

(b) informing the new provider about known limitations and failure modes; and

Article 2 – paragraph 10 a (new)

(c) providing the new provider with targeted technical access, including for testing and validation. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.

Text proposed by the Commission

(9ab) Article 25(4) first subparagraph is replaced by the following:

Amendment

4. The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.

(2a)(9b) in Article 2, the following27, paragraph 4 is inserted:replaced by the following:

10a. This Regulation does not apply to AI systems or AI models that are only used intra-group and not consumer-facing with no impact on end-users or natural persons. Such activities shall be conducted in accordance with applicable Union law. The prohibited practices as outlined in Article 5 shall not be covered by that exclusion.

‘4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article include cross references to the relevant sections of that data protection impact assessment or include relevant parts of that data protection impact assessment into the fundamental rights impact assessment.’;

Amendment 18

(9c) In Article 27, paragraph 5 is replaced by the following:

Proposal for a regulation

‘5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross references to the relevant sections of the data protection impact assessment or include relevant parts of that data protection impact assessment into the fundamental rights impact assessment pursuant to paragraph 4 of this Article.’;

Article 1 – paragraph 1 – point 2 b (new)

(10) in Article 28 the following paragraphs are added:

Regulation (EU) 2024/1689

‘8. Notifying authorities designated under this Regulation responsible for AI systems covered by the Union harmonisation legislation listed in Section A of Annex I shall ensure that the conformity assessment body that applies for designation both under this Regulation and the Union harmonisation legislation listed in Section A of Annex I shall be provided with the possibility to submit a single application and undergo a unified assessment procedure to be designated under this Regulation and Union harmonisation legislation listed in Section A of Annex I, where the relevant Union harmonisation legislation provides for such single application and unified assessment procedure. To that end, notifying authorities designated under this Regulation and under any other Union harmonisation legislation listed in Section A of Annex I shall cooperate in their assessments.

Article 2 a (new)

The single application and unified assessment procedure referred to in this paragraph shall also be made available to notified bodies already designated under the Union harmonisation legislation listed in Section A of Annex I, when those notified bodies apply for designation under this Regulation, provided that the relevant Union harmonisation legislation provides for such a procedure.

Text proposed by the Commission

A conformity assessment body that is designated under more than one Union harmonisation legislation listed in Section A of Annex I shall have to apply only once to be designated under this Regulation. A designation under this Regulation shall be applicable for all Union harmonisation legislation listed in Section A of Annex I for which the conformity assessment body is designated.

Amendment

The single application and unified assessment procedure shall avoid any unnecessary duplications, build on the existing procedures for designation under the Union harmonisation legislation listed in Section A of Annex I and ensure compliance with the requirements both relating to notified bodies under this Regulation and the relevant Union harmonisation legislation.’;

(2b) the following article is inserted:

A notifying authority that has been designated under the Union harmonisation legislation listed in Section A of Annex I is also the notifying authority for the application of the single application and unified assessment procedure referred to in paragraph 8, unless the Member State designates another notifying authority for this Regulation.’;’

'Article 2a

(11) in Article 29, paragraph 4 is replaced by the following:

Proportionality and Technological Neutrality

‘4. For notified bodies which are designated under any other Union harmonisation legislation, all documents and certificates linked to those designations may be used to support and expedite their designation procedure under this Regulation, as appropriate.

Without prejudice to explicit prohibitions laid down in Article 5 of this Regulation and to the protection of fundamental rights, the national competent authorities, the AI Office and the Commission shall interpret, implement, apply and enforce this Regulation in a manner that:

Notified bodies, which are designated under any of the Union harmonisation legislation listed in Section A of Annex I and which apply for the unified assessment referred to in Article 28(8), shall submit the single application for assessment to the notifying authority designated in accordance with that Union harmonisation legislation.

a) ensure proportionality, legal certainty and technological neutrality; and

The notified body shall update the documentation referred to in paragraphs 2 and 3 of this Article whenever relevant changes occur, in order to enable the authority responsible for notified bodies to monitor and verify continuous compliance with all the requirements laid down in Article 31.;’

b) minimise administrative and compliance burdens on economic operators

(12) in Article 30, paragraph 2 is replaced by the following:

while ensuring that the requirements of this Regulation, including any secondary legislation resulting from this Regulation, do not exceed what is strictly necessary to achieve the objectives of this Regulation.'

‘2. Notifying authorities shall notify the Commission and the other Member States, based on the list of codes, categories, and corresponding types of AI systems referred to in Annex XIV, and using the electronic notification tool developed and managed by the Commission, of each conformity assessment body referred to in paragraph 1.

Amendment 19

The Commission is empowered to adopt delegated acts in accordance with Article 97 to amend Annex XIV, in the light of technical progress, advances in knowledge or new scientific evidence by adding to the list of codes, categories, and corresponding types of AI systems a new code, a category or a type of AI system, withdrawing an existing code, category or a type of AI system from that list or moving a code or type of AI system from one category to another.;’

Proposal for a regulation

(12a) In Article 40, the following subparagraph is added in paragraph 2:

Article 1 – paragraph 1 – point 2 c (new)

‘The Commission shall request, in accordance with the Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I.;’

Regulation (EU) 2024/1689

(12b) In Article 42, the following paragraph is inserted:

Article 3 – point 1 a (new)

‘ 2a. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 , and where the conditions laid down in Article 12(1) of that Regulation (EU) 2024/2847 are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.;’

Text proposed by the Commission

(13) in Article 43, paragraph 3 is replaced by the following:

Amendment

‘For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 shall also apply, as well as points 3, 4.3, 4.4., 4.5, the fifth paragraph of point 4.6 and 5 of Annex VII.

(2c) in Article 3, the following point is inserted:

For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in Section 2, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under the relevant Union harmonisation legislation and as is evidenced through the assessment as part of the existing notification. Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 at the latest [18 months from the entry into application of this Regulation].

(1a) ''autonomy' means the ability of the artificial intelligence system to operate, within constraints, without human guidance or intervention;'

Where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment not involving a third-party, provided that that manufacturer has applied harmonised standards to show the compliance covering all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system under Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I, including, where applicable, an option to rely on harmonised standards. The manufacturers of such products are not obligated to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by the Union harmonisation legislation.

Amendment 20

Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of the system shall follow the relevant conformity assessment procedure as required under the relevant Union harmonisation legislation listed in Section A of Annex I.;’

Proposal for a regulation

(15) in Article 50, paragraph 7 is replaced by the following:

Article 1 – paragraph 1 – point 2 d (new)

‘7. The Commission shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56(6). If it deems the code of practice is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).’;’

Regulation (EU) 2024/1689

(16) in Article 56, paragraph 6 is replaced by the following:

Article 3 – point 3

‘6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;’

Present text

(17) Article 57 is amended as follows:

Amendment

‘(-a) paragraph 1, first subparagraph, is replaced by the following:

(2d) Article 3, point (3) is replaced by the following:

‘1. Member States shall ensure that their competent authorities establish at least one AI regulatory sandbox at national level, which shall be operational by 2nd August 2027 . That sandbox may also be established jointly with the competent authorities of other Member States. The Commission may provide technical support, advice and tools for the establishment and operation of AI regulatory sandboxes.;’

(3) ‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge;

(-b) paragraph 3 is replaced by:

(3) 'provider' means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge, excluding those that perform fine-tuning, personalisation and technical adaptation operations on AI systems on behalf of third-party clients by using data provided by the latter, unless those operations result in substantial modifications to, or changes in the intended purpose of, the AI systems in question;

‘3. The European Data Protection Supervisor may also establish an AI regulatory sandbox for Union institutions, bodies, offices and agencies. For this purpose references to national competent authorities in this Chapter shall be construed as references to the European Data Protection Supervisor.;’

Justification

(a) the following paragraphs are inserted:

The current Regulation considers small enterprises that perform fine-tuning operations locally (i.e. on client servers) to be providers, thereby imposing totally disproportionate legal responsibilities and certification burdens on them. Among other things, this state of affairs prompts enterprises to forego local fine-tuning and instead perform this operation by means of application programming interfaces (APIs) supplied by (generally non-EU-based) large providers of general-purpose models with a view to retaining their status as deployers.

‘3a. The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). For this purpose references to national competent authorities in this Chapter shall be construed, where relevant, as references to the AI Office. Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when compliance with Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs, including start-ups, and SMCs.

Amendment 21

3b. The establishment of a Union level AI regulatory sandbox by the AI Office shall be without prejudice to the competences of Member States to establish and supervise AI regulatory sandboxes for AI systems under their supervision.’;’

Proposal for a regulation

(b) paragraph 5 is replaced by the following:

Article 1 – paragraph 1 – point 2 e (new)

‘5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authorities, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;’

Regulation (EU) 2024/1689

(c) paragraph 9, point (e) is replaced by the following:

Article 3 – point 14

‘(e) facilitating and accelerating access to the Union market for AI systems, in particular when provided by SMEs, including start-ups, and SMCs.;’

Present text

(ca) paragraph 10 is replaced by the following:

Amendment

’10. National competent authorities shall ensure that, to the extent the innovative AI systems involve the processing of personal data or otherwise fall under the supervisory remit of other national authorities or competent authorities providing or supporting access to data, the competent data protection authorities and those other national or competent authorities are associated with the operation of the AI regulatory sandbox and involved in the supervision of those aspects to the extent of their respective tasks and powers.;’

(2e) in Article 3,(d) pointparagraph (14)13 is replaced by the following:

(14) ‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property;

’13. The AI regulatory sandboxes shall be designed and implemented in such a way that, where relevant, they facilitate cross-border cooperation between national competent authorities.; ’

(14) '‘safety component’ means a component of a product or of an AI system which fulfils a safety function for that product or AI system, and the failure or malfunctioning of which endangers the health and safety of persons or property;'

(e) paragraph 14 is replaced by the following:

Amendment 22

’14. National competent authorities, the EDPS and the AI Office shall, as appropriate and within their respective competences, coordinate their activities and cooperate within the framework of the Board. They may support the joint establishment and operation of AI regulatory sandboxes, including in different sectors and exchange best practices on related matters.;’

Proposal for a regulation

(18) Article 58, paragraph 1, is replaced by the following:

Article 1 – paragraph 1 – point 4

‘1. In order to avoid fragmentation across the Union, the Commission shall adopt implementing acts specifying the detailed arrangements for the establishment, development, implementation, operation, governance, and supervision of the AI regulatory sandboxes. The implementing acts shall include common principles on the following issues:

Regulation (EU) 2024/1689

(a) eligibility and selection criteria for participation in the AI regulatory sandbox;

Article 4 – paragraph 1

(b) procedures for the application, participation, monitoring, exiting from and termination of the AI regulatory sandbox, including the sandbox plan and the exit report;

Text proposed by the Commission

Amendment

‘The Commission and Member States shall encourage providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.;

‘The Commission and Member States shall support providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, level of education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.'

Amendment 23

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4a – paragraph 1 – introductory part

Text proposed by the Commission

Amendment

1. To the extent necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

1. To the extent that is strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Amendment 24

Proposal for a regulation

Article 1 – paragraph 1 – point 5

Regulation (EU) 2024/1689

Article 4a – paragraph 2

Text proposed by the Commission

Amendment

2. Paragraph 1 may apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where necessary and proportionate if the processing occurs for the purposes set out therein and provided that the conditions set out under the safeguards set out in this paragraph.;

2. Paragraph 1 may also apply to providers and deployers of other AI systems and models and deployers of high-risk AI systems where strictly necessary and proportionate for bias detection and correction, subject to all the safeguards set out in this Article and applicable Union data protection law.

This paragraph does not create any obligation to conduct such bias detection and correction with special categories of personal data.

Amendment 25

Proposal for a regulation

Article 1 – paragraph 1 – point 5 a (new)

Regulation (EU) 2024/1689

Article 5 – paragraph 1

Text proposed by the Commission

Amendment

(5 a) In Article 5(1), first subparagraph, the following points are added:

‘(ha) the placing on the market, the putting into service or the use of an AI system that can generate, alter or reproduce sexually or nude content in violation of the dignity, sexual integrity or consent of natural persons, including through the use of deep fake or other synthetic media techniques;

(hb) the placing on the market, the putting into service or the use of an AI system that generates child sexual abuse material, regardless of the nature or origin of the underlying content.’

Amendment 26

Proposal for a regulation

Article 1 – paragraph 1 – point 5 b (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 1

Present text

Amendment

(5b) in Article 6, paragraph 1 is replaced by the following:

1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

'1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(a) the AI system is intended to be used as a safety component of a product and the AI functionality has an impact on the safety of the overall system, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.

A lack of harmonised standards or part thereof, the references of which have been published in the Official Journal of the European Union, leading to third-party conformity assessment according to the applicable Union harmonisation legislation in Annex I, can in itself not lead to a product or AI system being classified as high-risk.'

Amendment 27

Proposal for a regulation

Article 1 – paragraph 1 – point 5 c (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 3 – subparagraph 1

Present text

Amendment

(5c) In Article 6, paragraph 3, the first subparagraph is replaced by the following:

By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.

'By derogation from paragraph 2, an AI system referred to in Annex III shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making or by ensuring meaningful human intervention or review. '

Amendment 28

Proposal for a regulation

Article 1 – paragraph 1 – point 6 a (new)

Regulation (EU) 2024/1689

Article 6 – paragraph 5 a (new)

Text proposed by the Commission

Amendment

(6a) In Article 6, the following paragraph is inserted:

5a. By way of derogation from the previous paragraphs, a high-risk AI system that is developed for internal use and is employed accordingly by a micro-enterprise to optimise its company processes shall not be subject to the obligations set out in Chapter III, Sections 2 and 3, provided that:

(a) the system is neither put on the market nor made available to third parties;

(b) the system does not process the personal data of external subjects;

(c) the system does not fall under the categories set out in Annex III, points 1,2,6 and 8;

(d) the system is only used by members of staff operating devices owned or controlled by the enterprise;

(e) the system does not implement any of the prohibited practices set out in Article 5.

Micro-enterprises making use of the derogation set out in the first subparagraph shall maintain simplified documentation in accordance with the template set out in Annex IV and shall make it available to the competent authorities upon request.

Justification

Micro-enterprises (companies with fewer than 10 employees and an annual turnover that does not exceed EUR 2 million, see Commission Recommendation 2003/361/EC of 6 May 2003) often use AI tools for simple international automation processes (stock management, sales projections, shift optimisation). Making these undertakings subject to the same obligations as multinational corporations or SMCs is disproportionate and discourages digital uptake. The internal use exemption, combined with proportionate guarantees, drastically reduces red tape while maintaining essential protections.

Amendment 29

Proposal for a regulation

Article 1 – paragraph 1 – point 6 b (new)

Regulation (EU) 2024/1689

Article 9 – paragraph 2 – point b

Present text

Amendment

(6a) in Article 9(2), point b is replaced by the following:

(b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse;

'(b) the estimation and evaluation of the risks that may emerge when the high-risk AI system is used in accordance with its intended purpose, and under conditions of reasonably foreseeable misuse, including cybersecurity specific threat modelling;'

Amendment 30

Proposal for a regulation

Article 1 – paragraph 1 – point 8 a (new)

Regulation (EU) 2024/1689

Article 11 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(8a) in Article 11, the following paragraph is inserted:

'1a. The Commission’s simplified form shall be digital-by-default, machine-readable, interoperable (so the same info can be reused for other reporting/authority requests), and enable pre-filling /re-use of previously submitted information.'

Amendment 31

Proposal for a regulation

Article 1 – paragraph 1 – point 9 a (new)

Regulation (EU) 2024/1689

Article 17 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(9a) In Article 17, the following paragraph is added:

'2a. If the provider is an SMC or an SME, including start-ups, the national authorities shall provide appropriate guidance and advice, so that the necessary technical documentation and quality management system requirements are tailored to the organisational size and capacity of these categories of providers;'

Amendment 32

Proposal for a regulation

Article 1 – paragraph 1 – point 12 a (new)

Regulation (EU) 2024/1689

Article 40 – paragraph 2 – subparagraph 1

Present text

Amendment

(12a) In Article 40, paragraph 2, the first subparagraph is replaced by the following:

In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.

‘In accordance with Article 10 of Regulation (EU) (No) 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, by 2 December 2027, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3 of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum.'

Amendment 33

Proposal for a regulation

Article 1 – paragraph 1 – point 12 b (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 – introductory part

Text proposed by the Commission

Amendment

(12b) In Article 41, the introductory wording is replaced by the following:

1. The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:

‘1. The Commission shall adopt implementing acts by 2 December 2027 establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled:’

Amendment 34

Proposal for a regulation

Article 1 – paragraph 1 – point 12 c (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 a (new)

Text proposed by the Commission

Amendment

(12c) in Article 41, the following paragraph is inserted:

‘1a. When there is no harmonised standard that enable compliance with the essential requirements set out in Section 2 of this Chapter, and no reference in the Official Journal of the European Union is expected to be published within a reasonable period, the Commission shall by means of implementing acts adopt common specifications in order to address an urgent concern with regard to non-compliant AI systems which cannot be adequately mitigated by alternative measures. A situation shall be considered to constitute an urgent concern when the suspension of cooperation with international standardisation organisations impedes the development of relevant harmonised standards by European standardisation organisations. In such a situation the Commission shall adopt common specifications only after prior authorisation of the Council. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 98(2). When preparing those implementing acts, the Commission shall be assisted by an expert group that includes relevant stakeholder representatives.

Amendment 35

Proposal for a regulation

Article 1 – paragraph 1 – point 12 d (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 1 b (new)

Text proposed by the Commission

Amendment

(12d) in Article 41, the following paragraph is inserted:

‘1b. The Commission shall provide the European Parliament, in a timely manner, with all relevant information concerning the implementing acts referred to in paragraph 1. That shall include, in particular, details on the drafting process of the implementing act, details on the composition of the expert groups supporting the process, details on the timeline and, where the drafting of an implementing act is outsourced, information on the main contractual aspects of such outsourcing, including the name of the entity responsible for the drafting, the total value of the contract and its duration.’

Amendment 36

Proposal for a regulation

Article 1 – paragraph 1 – point 12 e (new)

Regulation (EU) 2024/1689

Article 41 – paragraph 6

Text proposed by the Commission

Amendment

(12e) in Article 41, paragraph 6 is replaced by the following:

6. Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.

‘6. Where the European Parliament or a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.’

Amendment 37

Proposal for a regulation

Article 1 – paragraph 1 – point 12 f (new)

Regulation (EU) 2024/1689

Article 42 – paragraph 2 a (new)

Text proposed by the Commission

Amendment

(12f) In Article 42, the following paragraph is added:

'2a. Where an AI system is subject to the requirements of Regulation (EU) 2024/2847 as well as requirements set out in Article 15 of this Regulation, and where those high-risk AI systems fulfil the essential cybersecurity requirements set out in the Regulation (EU) 2024/2847, they shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under Regulation (EU) 2024/2847.'

Amendment 38

Proposal for a regulation

Article 1 – paragraph 1 – point 14

Regulation (EU) 2024/1689

Article 49 – paragraph 2

Text proposed by the Commission

Amendment

(14) in Article 49, paragraph 2 is deleted;

deleted

Amendment 39

Proposal for a regulation

Article 1 – paragraph 1 – point 15

Regulation (EU) 2024/1689

Article 50 – paragraph 7

Text proposed by the Commission

Amendment

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).;

7. The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content. The Commission may assess whether adherence to those codes of practice is adequate to ensure compliance with the obligation laid down in paragraph 2, in accordance with the procedure laid down in Article 56(6), first subparagraph. If it deems the code is not adequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations in accordance with the examination procedure laid down in Article 98(2).; The Commission shall ensure that any implementing act adopted pursuant to this paragraph is limited to what is strictly necessary to ensure interoperability and effective implementation of the marking obligations.

Amendment 40

Proposal for a regulation

Article 1 – paragraph 1 – point 15 a (new)

Regulation (EU) 2024/1689

Article 50 – paragraph 7 a (new)

Text proposed by the Commission

Amendment

(15a) in Article 50, the following paragraph is added:

'7a. The AI Office, in cooperation with the European Union Agency for Cybersecurity (ENISA), shall develop non-binding technical guidance on emerging AI-specific cybersecurity threats, risks including from autonomous operational capabilities and secure-by-design AI development practices in accordance with the NIS2 and Cyber Resilience Act frameworks.'

Amendment 41

Proposal for a regulation

Article 1 – paragraph 1 – point 16

Regulation (EU) 2024/1689

Article 56 – paragraph 6

Text proposed by the Commission

Amendment

(16) in Article 56(6), the first subparagraph is replaced by the following:

deleted

6. The Commission and the Board shall regularly monitor and evaluate the achievement of the objectives of the codes of practice by the participants and their contribution to the proper application of this Regulation. The Commission, taking utmost account of the opinion of the Board, shall assess whether the codes of practice cover the obligations provided for in Articles 53 and 55, and shall regularly monitor and evaluate the achievement of their objectives. The Commission shall publish its assessment of the adequacy of the codes of practice.;

Amendment 42

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point a

Regulation (EU) 2024/1689

Article 57 – paragraph 3a

Text proposed by the Commission

Amendment

The AI Office may also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.;

‘The AI Office shall also establish an AI regulatory sandbox at Union level for AI systems covered by Article 75(1). Such an AI regulatory sandbox shall be implemented in close cooperation with relevant competent authorities, in particular when Union legislation other than this Regulation is supervised in the AI regulatory sandbox, and shall provide priority access to SMEs.’;

Amendment 43

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point b

Regulation (EU) 2024/1689

Article 57 – paragraph 5

Text proposed by the Commission

Amendment

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place. Such sandboxes may include testing in real world conditions supervised therein. When applicable, the sandbox plan shall incorporate in a single document the real-world testing plan.;

5. AI regulatory sandboxes established under this Article shall provide for a controlled environment that fosters innovation and facilitates the development, training, testing and validation of innovative AI systems for a limited time before their being placed on the market or put into service pursuant to a specific sandbox plan agreed between the providers or prospective providers and the competent authority, ensuring that appropriate safeguards are in place.;

Amendment 44

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e

Regulation (EU)2024/1689

Article 57 – paragraph 14

Text proposed by the Commission

Amendment

14. National competent authorities shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.;

14. National competent authorities, the European Commission, the European Data Protection Supervisor and the AI Office shall coordinate their activities and cooperate within the framework of the Board. They shall support the joint establishment and operation of AI regulatory sandboxes, including in different sectors.

Amendment 45

Proposal for a regulation

Article 1 – paragraph 1 – point 17 – point e a (new)

Regulation (EU)2024/1689

Article 57 – paragraph 14 a (new)

Text proposed by the Commission

Amendment

(ea) in Article 57 the following paragraph is inserted:

'(14a) The Commission and the AI Office shall ensure transparent and non-discriminatory criteria for accessing the EU-level sandbox and shall support the participation of SMEs and the public administrations of Member States with developing administrative capacity and innovation ecosystems, including by providing technical assistance and procedural guidance.'

Amendment 46

Proposal for a regulation

Article 1 – paragraph 1 – point 18

Regulation (EU)2024/1689

Article 58 – paragraph 1 – point c

Text proposed by the Commission

Amendment

(c) the terms and conditions applicable to the participants;

(c) the terms and conditions applicable to the participants, in particular those concerning SMEs and SMCs;

(d) the detailed rules applicable to the governance of AI regulatory sandboxes covered under Article 57, including as regards the involvement and supervision by the competent data protection authorities, where relevant, and the coordination and cooperation at national and EU level.;’

Amendment 47

(19) Article 60 is amended as follows:

Proposal for a regulation

(a) in paragraph 1, the first subparagraph is replaced by the following:

Article 1 – paragraph 1 – point 20 a (new) – point a (new)

‘Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes may be conducted by providers or prospective providers of high-risk AI systems listed in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I, in accordance with this Article and the real-world testing plan referred to in this Article, without prejudice to the prohibitions under Article 5.;’

Regulation (EU) 2024/1689

(b) paragraph 2 is replaced by the following:

Article 62 – paragraph 1 – point d

‘2. Providers or prospective providers may conduct testing of high-risk AI systems referred to in Annex III or covered by Union harmonisation legislation listed in Section A of Annex I in real world conditions at any time before the placing on the market or the putting into service of the AI system on their own or in partnership with one or more deployers or prospective deployers.;’

Present text

(20) the following Article 60a is inserted:

Amendment

‘Article 60a

(20a) Article 62 is amended as follows:

Testing of high-risk AI systems covered by Union harmonisation legislation listed in Section B of Annex I in real-world conditions outside AI regulatory sandboxes

(a) in paragraph 1, point (d) is replaced by the following:

1. Member States may permit the testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes by providers or prospective providers of AI enabled products covered by Union harmonisation legislation listed in Section B of Annex I, with a view to assessing and verifying the conformity of those systems with the requirements of Articles 8 to 15 of this Regulation, in accordance with this Article.

(d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process.

2a. Member States which choose to permit testing as referred to in paragraph 1 shall, individually or jointly, adopt frameworks for real-world testing.

(d) facilitate the participation of SMEs and other relevant stakeholders in the standardisation development process, including through appropriate dedicated financial support mechanisms to reimburse the cost of SME experts participating in European bodies;

2b. Each Member State shall notify the Commission of any real-world testing framework it adopts before implementing that framework. This shall not affect the competences of the Commission under the Union harmonisation legislation listed in Section B of Annex I.

Justification

3. Member States that have adopted real-world testing frameworks shall ensure that the relevant national competent authorities, appropriate authorities and public authorities responsible for the management and operation of infrastructure and products covered by Union harmonisation legislation listed in Section B of Annex I cooperate closely with each other and in good faith, and remove any practical obstacles, including on procedural rules providing access to physical public infrastructure, where this is necessary, to successfully implement those real-world testing frameworks and test AI-enabled products covered by Union harmonisation legislation listed in Section B of Annex I.

Compliance with the regulation will depend on the appropriate tools being made available to small businesses for regulatory compliance. In this regard, it is essential to step up support for SMEs in the process of setting authorised standards. As it stands, participation in technical committees is sustainable only for large companies. What is more, it will be essential to relieve SMEs from overly complex audits on open-source components developed by third parties. In this regard, a 'safe harbour' linked to an EU repository must be established.

4. The frameworks for real-world testing shall lay down the requirements by which testing in real-world conditions shall occur. Those frameworks shall:

Amendment 48

(a) include provision of a mandatory real-world testing plan to be agreed between the provider or prospective provider and the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I;

Proposal for a regulation

(b) ensure compliance with the requirements laid down in Article 60(2), (3), (4)(d)-(j) and (5)-(9), save that any reference to market surveillance authorities in those provisions shall be read as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I;

Article 1 – paragraph 1 – point 20 a (new) – point b (new)

(c) include effective governance and accountability arrangements.

Regulation (EU) 2024/1689

(d) ensure a high level of protection of health, safety and fundamental rights.

Article 62 – paragraph 3 – point d a (new)

4a. The real-world testing shall comply with any applicable provisions laid down in the Union harmonisation legislation listed in Section B of Annex I. Any requirements laid down in those provisions shall not affect the application of this Article to the extent necessary to enable the testing referred to in paragraph 1.’

Text proposed by the Commission

(21) Article 63(1) is replaced by the following:

Amendment

‘1. SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. For that purpose, the Commission shall develop guidelines on the elements of the quality management system which may be complied with in a simplified manner considering the needs of SMEs, without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems.’;’

(b) in(21a) paragraphIn 3,Article the64, followingparagraph point2a is added:

(da) establish and maintain a public repository of certified open-source AI components; also for the purposes of the obligations referred to in Article 16, the use of these components shall be presumed to be consistent with the requirements laid down in Section 2.

‘(2a) Without prejudice to the budgetary procedure, the AI Office shall be allocated with adequate resources to effectively perform its duties and exercise its powers in respect of the enforcement of Regulation (EU) 2024/1689.’

Justification

(22) Article 69 is amended as follows:

Compliance with the regulation will depend on the appropriate tools being made available to small businesses for regulatory compliance. In this regard, it is essential to step up support for SMEs in the process of setting authorised standards. As it stands, participation in technical committees is sustainable only for large companies. What is more, it will be essential to relieve SMEs from overly complex audits on open-source components developed by third parties. In this regard, a 'safe harbour' linked to an EU repository must be established.

(a) paragraph 2 is replaced by the following:

Amendment 49

‘2. The Member States may be required to pay fees for the advice and support provided by the experts at a rate equivalent to the remuneration fees applicable to the Commission pursuant to the implementing act referred to in Article 68(1).;’

Proposal for a regulation

(23) in Article 70, paragraph 8 is replaced by the following:

Article 1 – paragraph 1 – point 22 – point b

‘8. National competent authorities may provide guidance and advice on the implementation of this Regulation, in particular to SMEs, including start-ups, and SMCs, taking into account the guidance and advice of the Board and the Commission, as appropriate. Whenever national competent authorities intend to provide guidance and advice with regard to an AI system in areas covered by other Union law, the national competent authorities under that Union law shall be consulted, as appropriate.;’

Regulation (EU) 2024/1689

(24) in Article 72, paragraph 3 is replaced by the following:

Article 69 – paragraph 3

‘3. The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.’;’

Text proposed by the Commission

(25) Article 75 is amended as follows:

Amendment

(a) the heading of Article 75 is replaced by the following:

(b) paragraph 3 is deleted.

‘Market surveillance and control of AI systems and mutual assistance;’

deleted

(b) paragraph 1 is replaced by the following:

Amendment 50

‘1. 1. The AI Office shall be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to the following AI systems:

Proposal for a regulation

(a) AI systems based on general-purpose AI models where that model and that system are developed by the same provider, or by providers forming part of the same undertaking as that provider, with the exception of:

Article 1 – paragraph 1 – point 25 – point b

(i) AI systems related to products covered by the Union harmonisation listed in Annex I;

Regulation (EU)2024/1689

(ii) AI systems referred to in Annex III, point (2);

Article 75 – paragraph 1 – subparagraph 1

(iii) AI systems provided by law enforcement authorities, border management authorities, and financial institutions insofar as those AI systems fall under Article 74(6); and

Text proposed by the Commission

(iv) AI systems referred to in Annex III, point (8) as regards the administration of justice.

Amendment

(b) AI systems that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.

Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I, and that model and that system are developed by the same provider, the AI Office shall be exclusively competent for the supervision and enforcement of that system with the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to AI system that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.

The exclusive competence referred to in the first subparagraph shall apply to the providers of those systems. It shall also apply to the deployers of those systems, but only when they are also the provider or part of the same undertaking as the provider.

Where an AI system is based on a general-purpose AI model, with the exclusion of AI systems related to products covered by the Union harmonisation legislation listed in Annex I, and that model and that system are developed by the same provider, the AI Office shall be exclusively competent for the supervision and enforcement of that system with the obligations of this Regulation in accordance with the tasks and responsibilities assigned by it to market surveillance authorities. The AI Office shall also be exclusively competent for the supervision and enforcement of the obligations under this Regulation in relation to AI system that constitute or that are integrated into a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065. The competent national authorities may refer signs of non-compliance or systemic risks that have arisen in their country to the AI Office and the AI Office shall, within a reasonable time, inform the referring authority about follow-up measures. The AI Office shall, in exercising its duties, work with the competent national authorities and with the relevant authorities under Regulation (EU) 2022/2065, in accordance with the principles of proportionality and ne bis in idem.

(c) the following paragraphs are inserted:

Justification

‘1ab. By way of derogation from Article 73, providers of high-risk AI systems subject to the AI Office’s competence under paragraph 1 of this Article shall report any serious incidents to the AI Office. Article 73(2)-(9) shall apply mutatis mutandis. The AI Office shall promptly transmit the relevant information to the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated.

While centralised supervision by the AI Office enhances consistency, national competent authorities must retain an effective right to notify potential non-compliance or systemic risks identified on their territory. The amendment strengthens cooperative enforcement without creating duplication of competences or additional administrative burden.

1a. The authorities involved in the application of this Regulation shall cooperate actively and afford the AI Office the necessary assistance for the exercise of its powers, including, where necessary, in connection with inspections or other enforcement measures carried out in the territory of a Member State. To this end, those authorities shall enjoy the powers provided for under this Regulation and Regulation (EU) 2019/1020, and where relevant and limited to what is necessary to fulfil their tasks under this paragraph, in accordance with the applicable national procedures.

Amendment 51

1ba. When taking investigatory or enforcement action in the territory of a Member State that involves access to a public authority’s data or AI system, the AI Office shall be assisted by the relevant market surveillance authority.

Proposal for a regulation

1c. Before taking a decision that would have the effect of prohibiting or restricting the AI system being made available or put into service on a national market, or a decision to withdraw or recall the AI system from the market, the AI Office shall, without undue delay, notify the market surveillance authority competent for that market of the intention to take such a decision. The AI Office shall consult the authorities involved in the application of this Regulation, where appropriate, on any matter relating to the application and enforcement of this Regulation.

Article 1 – paragraph 1 – point 26 – point b

1d. The AI Office shall be responsible for pre-market conformity assessments and tests of AI systems referred to in paragraph 1 that are classified as high-risk and subject to third-party conformity assessment under Article 43 before such AI systems are placed on the market or put into service. These tests and assessments shall verify that the systems comply with the relevant requirements of this Regulation and may be placed on the market or put into service in the Union in accordance with this Regulation. The Commission shall entrust the performance of these tests or assessments to notified bodies designated under this Regulation, in which case the notified body shall act on behalf of the Commission. If a notified body to which the Commission has delegated tasks under this paragraph does not perform those tasks adequately, the Commission may withdraw the delegation with immediate effect.’

Regulation(EU)2024/1689

1e. The fees for testing and assessment activities shall be levied on the provider of a high-risk AI system who has applied for third-party conformity assessment to the Commission. The costs related to the services entrusted by the Commission to the notified bodies in accordance with this Article shall be directly paid by the provider to the notified body.;

Article 77 – paragraph 1

2a. Where a market surveillance authority has well-founded and sufficient reasons to suspect that a provider or a deployer of an AI system referred to in paragraph 1 has infringed this Regulation, it may request, through the relevant single point of contact foreseen in Article 70(2) of this Regulation, the AI Office to assess the matter in order to take the necessary supervisory and enforcement measures to ensure prompt compliance with this Regulation. Such a request shall be duly reasoned and shall include at least:

Text proposed by the Commission

(a) the name of the provider or the deployer concerned;

Amendment

(b) a description of the relevant facts, the provisions of this Regulation that have allegedly been infringed, and the well-founded and sufficient reasons for suspecting an infringement, including, where applicable, the description of the negative effects of the alleged infringement;

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and format where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction.;

(c) the market surveillance authority making the request.

1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have direct access to the technical documentation necessary for the exercise of their duties and shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and format where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction.;

The AI Office shall take utmost account of the request and the market surveillance shall cooperate actively and afford the AI office the necessary assistance for the exercise of its powers in line with paragraph 1a of this Article. The AI Office shall, without undue delay and in any event no later than four months following receipt of the request, inform the single point of contact of its intention to exercise its powers under Article 75a or of its reasons for not exercising its powers. If the AI Office decides to exercise its powers under Article 75a, it shall periodically inform that single point of contact about major developments in the proceedings and the outcome of such proceedings, without disclosing any confidential information.

Amendment 52

(25a) The following articles are inserted after Article 75:

Proposal for a regulation

‘Article 75a

Article 1 – paragraph 1 – point 30 – point a

Supervisory and enforcement powers of the AI Office

Regulation (EU) 2024/1689

1. When exercising its tasks of supervision and enforcement outlined in Article 75(1), the AI Office shall have all the powers of a market surveillance authority provided for in this Section and in Article 14(4) and Article 16(3) of Regulation (EU) 2019/1020. The AI Office shall also be authorised to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities with respect to instances of non-compliance, including costs for human and technical resources, in accordance with Article 15 of Regulation (EU) 2019/1020. Article 17 of Regulation (EU) 2019/1020 shall apply mutatis mutandis.

Article 111 – paragraph 2

2. Where the AI Office has reasonable grounds to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may adopt a decision initiating an investigation into that non-compliance in accordance with Article 14(4)(f) of Regulation 2019/1020. Upon the initiation of such an investigation, the AI Office shall notify the operator of the AI system concerned. The AI Office may exercise the powers listed in paragraph 1 on its own initiative or following a complaint received pursuant to Article 85 of this Regulation, even before initiating an investigation pursuant to Article 14(4)(f) of Regulation 2019/1020. Where a market surveillance authority has reason to suspect non-compliance with this Regulation by a provider or a deployer of an AI system referred to in Article 75(1), it may send a request to the AI Office to assess the matter.

Text proposed by the Commission

3. The AI Office may exercise the powers listed in Article 14(4)(a) to (c) of Regulation 2019/1020 and Article 74(12-13) of this Regulation by simple request or by decision. When requesting information, the AI Office shall state the legal basis and the purpose of the request, specify what information is required, set the period within which the information is to be provided. Where the request is a simple request, the AI Office shall additionally indicate that although there is no obligation to provide the information requested, in the case of a voluntary reply, the information must be correct and not misleading, and indicate the potential fines provided for in Article 99(5) for supplying incorrect or misleading information. Where the request is made by decision, the AI Office shall additionally indicate the fines provided for in Article 99(5) for supplying incorrect, incomplete and misleading information and indicate the right to have the decision reviewed by the Court of Justice of the European Union. The AI Office shall send a copy of the request to the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated.

Amendment

4. In order to carry out the tasks assigned to it under this Section, the AI Office may conduct all necessary remote or on-site inspections pursuant to the powers laid down in Article 14(4)(d) and (e) of Regulation (EU) 2019/1020 and Article 74(5) of this Regulation. When ordering inspections , the AI Office shall inform the provider concerned of the subject matter and purpose of the investigation, the relevant penalties referred to in Article 99(5), and the right to have the decision reviewed by the Court of Justice of the European Union. Prior to conducting an inspection, the Commission shall inform the market surveillance authority of the Member State in whose territory the operator or its legal representative is situated. During such an inspection, the officials of the AI Office shall be empowered to: (a) enter any of the business premises, land or property located in the Union of the operator concerned; (b) examine the books, data and other material relevant to the execution of their tasks, irrespective of the medium on which they are stored; (c) take or obtain in any form copies of or extracts from such books, data and other records; (d) ask any of the persons subject to the inspection, or their representatives, or staff, for oral or written explanations on factors or documents relating to the subject matter and purpose of the inspection, and to record the answers. (e ) seal any business premises and books or records for the duration of, and to the extent necessary for, the inspection; Where the AI Office finds that a natural or legal person opposes or obstructs such an inspection, the national competent authority of the Member State concerned shall afford it the necessary assistance, requesting, where appropriate, the assistance of the police or an equivalent enforcement authority, to enable it to conduct its on-site inspection. Where an on-site inspection of business premises, land or property requires authorisation by a judicial authority in accordance with national law, the AI Office shall apply for such an authorisation. The AI Office may also apply for such authorisation as a precautionary measure. Where such an authorisation is applied for, the national judicial authority shall promptly verify that the coercive measures envisaged are neither arbitrary nor excessive having regard to the subject matter of the investigation or inspection and the documents provided by the AI Office with the decision. In its verification of the proportionality of coercive measures, the national judicial authority may ask the AI Office for detailed explanations, in particular relating to the grounds the AI Office has for suspecting that an infringement of this Regulation has taken place and the seriousness of the suspected infringement and, where relevant, the nature of the involvement of the person subject to the coercive measures. However, the national judicial authority shall not review the necessity of the investigation or inspection nor demand information from the case file of the Commission. In accordance with the Treaties, the legality of the Commission’s decision is subject to review only by the Court of Justice of the European Union.

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.;

5. At the request of the AI Office, the competent market surveillance authority of a Member State may in its own territory carry out any investigation, inspection or other fact-finding measure on behalf and for the account of the AI Office in order to establish whether there has been an infringement of this Regulation. The officials of the competent authorities of the Member States who are responsible for conducting these investigations, inspections, or fact-finding measures as well as those authorised or appointed by them shall exercise their powers in accordance with their national law.

2. Without prejudice to the application of Article 5 as referred to in Article 113(3), third paragraph, point (a), this Regulation shall apply to providers and deployers of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, they shall be brought into compliance with this Regulation by 31 August 2029.'

6. In addition to the powers set out in paragraph 1, the AI Office, in the exercise of its competences listed in Article 75(1), may: (a) order operators to provide access to, and explanations relating to, their AI systems; (b) impose an obligation on an operator to retain all data and documents deemed to be necessary to assess the implementation of and compliance with the obligations under this Regulation.

Amendment 53

7. To assist it in monitoring the effective implementation and compliance with the relevant provisions of this Regulation and to provide it with specific expertise or knowledge in the exercise of its competences under Article 75(1), the AI Office may appoint independent external experts and auditors, as well as experts, investigative teams and auditors from the Member State’s competent authorities with the agreement of the authority concerned,. Information obtained as a result of such monitoring actions shall be shared with the relevant competent authorities of the Member States.

Proposal for a regulation

8. Information collected pursuant to this provision shall be used only for the purpose of this Regulation.

Article 1 – paragraph 1 – point 30 – point b

Article 75c

Regulation (EU) 2024/1689

Commitments

Article 111 – paragraph 4

If, during proceedings under Article 75a(2), the operator concerned offers commitments to ensure compliance with the relevant provisions of this Regulation, the AI Office may, by decision, make those commitments binding on the operator concerned and declare that there are no further grounds for action. The AI Office may, upon request or on its own initiative, reopen the proceedings:

Text proposed by the Commission

(a) where there has been a material change in any of the facts on which the decision was based;

Amendment

(b) where the operator acts contrary to its commitments; or

(c) where the decision was based on incomplete, incorrect or misleading information provided by the operator concerned.

Where the AI Office considers that the commitments offered by the operator concerned are unable to ensure effective compliance with the relevant provisions of this Regulation, it shall reject those commitments in a reasoned decision when concluding the proceedings.

Article 75d

Non-compliance, fines and periodic penalties

1. Where the Commission finds that an operator of an AI system falling within the scope of Article 75(1) does not comply with the relevant provisions of this Regulation or with commitments made binding pursuant to Article 75c, it shall adopt a decision establishing such non-compliance.

2. Before adopting a decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the operator concerned. In the preliminary findings, the Commission shall explain the measures that it considers taking, or that it considers that the operator concerned should take, in order to effectively address the preliminary findings.

3. In the decision pursuant to the paragraph 1, the AI Office shall, where relevant, order the operator concerned to take the necessary measures to ensure compliance with the decision within a reasonable period specified therein and to provide information on the measures that that operator intends to take to comply with the decision. The operator concerned shall provide the AI Office with a description of the measures it has taken to ensure compliance with the decision upon their implementation. Prior to requesting any measure, the AI Office may engage in a structured dialogue with the operator of the AI system in question. During this dialogue, the operator may propose commitments in accordance with paragraph Article 75c.

4. A decision adopted pursuant to paragraph 1 may be accompanied by the imposition of penalties in accordance with Article 99 (3)-(7), which provisions shall apply mutatis mutandis to the AI Office in the execution of its supervision and enforcement tasks laid out in Article 75(1) of this Regulation.

In particular, the following shall be subject to administrative fines as referred to in Article 99(4):

(a) infringement of any applicable provision of this Regulation, including those not listed in Article 99(4);

(b) failure to comply with decisions or measures adopted pursuant to the powers listed in Article 14(4) or 16(3) of Regulation (EU) 2019/1020, as well as those specified in Article 75b;

(c) failure to comply with a commitment made binding by a decision pursuant to Article 75c.

The supply of incorrect, incomplete or misleading information to the Commission in reply to a request shall be subject to administrative fines as referred to in Article 99(5).

5. The Commission may adopt a decision imposing periodic penalty payments to compel the operators subject to its competence pursuant to Article 75(1) to submit to an investigation, to comply with an information request ordered by a decision adopted under paragraph Article 75a(3), to submit to an inspection ordered by a decision pursuant to Article 75a(4), to provide correct or complete answers or explanations in the context of such an inspection, to comply with corrective actions ordered pursuant to the power listed in Article 16 of Regulation (EU) 2019/1020, to comply with commitments made legally binding by a decision pursuant to Article 75c, or to comply with a decision pursuant to the first paragraph of this Article. Those penalty payments shall be effective and proportionate, and where applicable shall not exceed 5% of the average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date appointed by the decision.

6. The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine or periodic penalty payment under this Article. It may cancel, reduce or increase the fine or periodic penalty payment imposed.

7. Funds collected through the imposition of fines or periodic penalty payments under this Article shall contribute to the general budget of the Union.

7a. The powers conferred on the Commission by this Article shall be subject to a limitation period of five years. Time shall begin to run on the day on which the infringement is committed. However, the case of continuing or repeated infringements, time shall begin to run on the day on which the infringement ceases.

The power of the Commission to enforce decisions taken pursuant to this Article shall be subject to a limitation period of five years. The limitation period shall begin to run on the day on which the decision becomes final.

The implementing act referred to in Article 75e(3) shall specify the first and second subparagraphs of this paragraph, including the circumstances in which the limitation periods shall be interrupted.

8. Where the Commission determines that there are no grounds to adopt a decision of non-compliance, it shall close the proceeding by a decision. That decision shall apply with immediate effect.

Article 75e

Safeguards and further specification

1. Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to operators subject to the AI Office’s competence pursuant to Article 75(1), without prejudice to more specific procedural rights provided for in this Regulation.

2. The rights of defence and of access to the file of operators of AI systems falling within the scope of Article 75(1) shall be fully respect in proceedings. In view of the possible adoption of decisions on the basis of Article 75d(1), those operators shall be entitled to have access to the Commission's file under the terms of a negotiated disclosure, subject to the legitimate interest of the operator or other person concerned in the protection of their business secrets. The AI Office shall have the power to adopt decisions setting out such terms of disclosure in case of disagreement between the parties. The right of access to the file shall not extend to confidential information and internal documents of the AI Office, the Board, competent market surveillance authorities or other public authorities of the Member States. In particular, the right of access shall not extend to correspondence between the Commission and those authorities. Nothing in this paragraph shall prevent the Commission from disclosing and using information necessary to prove an infringement.

3. The Commission may adopt implementing acts concerning the practical arrangements for access to the file and the negotiated disclosure of information provided for in paragraph 2.

4. The Commission shall publish the decisions it adopts pursuant to Articles75c and 75d. Such publication shall state the names of the parties and the main content of the decision, including any penalties imposed. The publication shall have regard to the rights and legitimate interests of any person concerned in the protection of their confidential information.’

(25b) In Article 76(1), the following subparagraph is added:

‘Where testing in real world conditions is based on Article 60a, any reference to a market surveillance authority in this Article shall be construed as a reference to the national competent authority or appropriate authority under the Union harmonisation legislation listed in Section B of Annex I, and references to Article 60 shall be construed as references to Article 60a as appropriate.’;’.

(26) Article 77 is amended as follows:

(a) the heading is replaced by the following:

‘Powers of authorities protecting fundamental rights and cooperation with market surveillance authorities’

(b) paragraph 1 is replaced by the following:

‘1. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights, including the right to non-discrimination, shall have the power to make a request and access any information or documentation created or maintained from the relevant market surveillance authority under this Regulation in accessible language and machine-readable format by electronic means where access to that information or documentation is necessary for effectively fulfilling their mandates within the limits of their jurisdiction. This article is without prejudice to the competences, tasks, powers and independence of the relevant national public authorities or bodies under their mandates.’;’

(c) the following paragraph 1a and 1b are inserted:

‘1a. Subject to the conditions specified in this Article, the market surveillance authority shall grant the relevant public authority or body referred to in paragraph 1 access to such information or documentation, including by requesting such information or documentation from the provider or the deployer, where necessary and without undue delay.

1b. Market surveillance authorities and public authorities or bodies referred to in paragraph 1 shall cooperate closely and provide each other with mutual assistance necessary for fulfilling their respective mandates, with a view to ensuring coherent application of this Regulation and Union law protecting fundamental rights and streamlining procedures while respecting their respective competences, tasks, powers and independence. This shall include, in particular, exchange of information where necessary for the effective supervision or enforcement of this Regulation and the respective other Union legislation.;’

(27) Article 95, paragraph 4 is replaced by the following:

‘4. The AI Office and the Member States shall take into account the specific interests and needs of SMEs, including start-ups, and SMCs, when encouraging and facilitating the drawing up of codes of conduct.;

(28) Article 96 is amended as follows:

(a) in paragraph 1, the following point (g) is added:

‘(g) the practical implementation of Articles 8(2), 9(10), and 17(3) in line with the principle of complementarity and proportionality, with a view to ensuring consistency, avoiding duplication and minimising additional burdens when complying with the requirements of this Regulation and the requirements of the Union harmonisation legislation listed in Section A of Annex I. These guidelines shall be published at the latest on 1 August 2027.”;’

(b) paragraph 1, the second subparagraph is replaced by the following:

‘the application of the requirements and obligations referred to in Articles 8 to 15 and in Articles 25 and 26;

‘When issuing such guidelines, the Commission shall involve the AI Board and pay particular attention to the needs of SMEs, including start-ups, and SMCs, of local public authorities and of the sectors most likely to be affected by this Regulation.’;’’

(29) Article 99 is amended as follows:

(a) paragraph 1 is replaced by the following:

‘1. In accordance with the terms and conditions laid down in this Regulation, Member States shall lay down the rules on penalties and other enforcement measures, which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators, and shall take all measures necessary to ensure that they are properly and effectively implemented, thereby taking into account the guidelines issued by the Commission pursuant to Article 96. The penalties provided for shall be effective, proportionate and dissuasive. The Member States shall take into account the interests of SMEs, including start-ups, and SMCs, and their economic viability when imposing penalties.’;’

(aa) in paragraph 4 the following point (da) is inserted:

(da) 'obligations of providers and operators pursuant to Article 25(2) and (4); ’

(b) paragraph 6 is replaced by the following:

‘6. In the case of SMEs, including start-ups, each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower.;’

(29a) In Article 99, paragraph 6a is inserted:

‘In the case of SMCs each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred to in paragraph 4 or 5, whichever thereof is lower.’

(30) Article 111 is amended as follows:

(a) paragraph 2 is replaced by the following:

‘2. Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III and corresponding obligations referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.;’

(b) the following paragraph 4 is added:

deleted

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.’

‘4. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 February 2027.;’

(31) Article 113 is amended as follows:

Amendment 54

(-a) in the third paragraph, point (a) is replaced by the following:

Proposal for a regulation

(a) Chapters I and II shall apply from 2 February 2025, except for Article 5(1), first subparagraph, points (ba) and (bb), Article 5(1a) and Article 5(1b) which shall apply from 2 December 2026 ;’

Article 1 – paragraph 1 – point 31 – point a

(a) in the third paragraph, point (c) is replaced by the following:

Regulation (EU) 2024/1689

‘Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply

Article 113 –paragraph 3 – point d – subparagraph 1 – introductory part

(i) on 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

Text proposed by the Commission

(ii) on 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.;’

Amendment

(b) in the third paragraph, point (d) is added:

(d) Chapter III, Sections 1, 2, and 3, shall apply following the adoption of a decision of the Commission confirming that adequate measures in support of compliance with Chapter III are available, from the following dates:

‘(d) Articles 102 to 110 shall apply from [the date of entry into force of this amending Regulation].’;’

(d) Chapter III, Sections 1, 2, and 3, shall apply:

(31a) Annex I is amended as follows:

Amendment 55

(a) in Section A, point 1 is deleted. (b) in Section B, the following point 21 is added: ‘21. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC.’

Proposal for a regulation

(32) in Annex VIII, section B, points 7 and 9 are deleted;

Article 1 – paragraph 1 – point 31 – point a

(33) the following Annex XIV is added:

Regulation (EU) 2024/1689

‘Annex XIV

Article 113 –paragraph 3 – point d – subparagraph 1 –point i

The list of codes, categories and corresponding types of AI systems for the purpose of the notification procedure referred to in Article 30 specifying the scope of the designation as notified bodies

Text proposed by the Commission

1. Introduction

Amendment

Conformity assessment of high-risk AI systems under this Regulation may require involvement of conformity assessment bodies. Only conformity assessment bodies that have been designated in accordance with this Regulation may carry out conformity assessments and only for the activities related to the types of AI systems concerned. The list of codes, categories, and corresponding types of AI systems sets the scope of the designation of conformity assessment bodies notified under Article 30 of this Regulation.

(i) 6 months after the adoption of that decision as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and

2. List of Codes, categories, and corresponding AI systems

deleted

1. AI systems subject to Annex I of the AI Act

Amendment 56

AIA Code

Proposal for a regulation

AIP 0101

Article 1 – paragraph 1 – point 31 – point a

AI systems subject to Annex I.A.1. of the AI Act.

Regulation (EU) 2024/1689

AIP 0102

Article 113 – paragraph 3 – point d – subparagraph 1 – point ii

AI systems subject to Annex I.A.2. of the AI Act.

Text proposed by the Commission

AIP 0103

Amendment

AI systems subject to Annex I.A.3. of the AI Act.

(ii) 12 months after the adoption of the decision as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.

AIP 0104

deleted

AI systems subject to Annex I.A.4. of the AI Act.

Amendment 57

AIP 0105

Proposal for a regulation

AI systems subject to Annex I.A.5. of the AI Act.

Article 1 – paragraph 1 – point 31 – point a

AIP 0106

Regulation (EU) 2024/1689

AI systems subject to Annex I.A.6. of the AI Act.

Article 113 –paragraph 3 – point d –subparagraph 2 – introductory part

AIP 0107

Text proposed by the Commission

AI systems subject to Annex I.A.7. of the AI Act.

Amendment

AIP 0108

In the absence of the adoption of the decision within the meaning of subparagraph 1, or where the dates below are earlier than those that follow the adoption of that decision, Chapter III, Sections 1, 2, and 3, shall apply:

AI systems subject to Annex I.A.8. of the AI Act.

deleted

AIP 0109

Amendment 58

AI systems subject to Annex I.A.9. of the AI Act.

Proposal for a regulation

AIP 0110

Article 1 – paragraph 1 – point 31 a (new)

AI systems subject to Annex I.A.10. of the AI Act.

Regulation (EU) 2024/1689

AIP 0111

Article 113 – paragraph 3 –subparagraph 2 a (new)

AI systems subject to Annex I.A.11. of the AI Act.

Text proposed by the Commission

AIP 0112

Amendment

AI systems subject to Annex I.A.12. of the AI Act.

(31a) in Article 11 , the following paragraph is added:

2. AI systems subject to Annex III.1 of the AI Act

By way of derogation from the deadlines referred to in the the third paragraph, micro-enterprises established in the Union shall benefit from an additional transition period of 24 months for the application of the provisions of Chapter II, Sections 1, 2 and 3. During this additional period:

AIA Code

(a) the placing on the market of high-risk AI systems by those undertakings shall continue to be permitted, provided that the supplier demonstrates that it has taken proportionate risk self-assessment measures based on harmonised standards or recognised good practices;

AIB 0201

(b) national supervisory authorities shall adopt a non-sanctioning monitoring regime, giving priority to technical assistance and guided correction of non-compliance, without prejudice to provisions on public safety and the protection of fundamental rights;

Remote biometric identification systems

(c) the Commission shall, within ... [36 months of the date of entry into force of this amending regulation], submit a report on the compliance capacity of micro-enterprises, assessing the need for further support measures or an adjustment of the requirements in accordance with the principle of proportionality;

AIB 0202

Justification

Biometric categorisation AI systems

Micro-enterprises and smaller enterprises (often made up of one to three individuals) do not have dedicated compliance resources. Often, the owner accumulates technical, commercial and administrative roles. The standard timelines are unrealistic. The extension requested is in line with the precedent set with GDPR: many Member States granted up to 36 months in an effort to provide soft enforcement for SMEs. A 2024 study by the Commission notes that micro-enterprises need 3.5 times longer than large certified companies. A gradual, assisted approach reduces business failures.

AIB 0203

Amendment 59

Emotion recognition AI systems

Proposal for a regulation

3. AI technology-specific codes

Article 1 – paragraph 1 – point 31 b (new)

a. Symbolic AI and expert systems

Regulation (EU) 2024/1689

AIA Code

Annex 1: List of Union Harmonisation Legislation

AIH 0101

Present text

AI systems based on symbolic AI, expert and knowledge-based systems, and AI systems based on search and optimisation

Amendment

b. Machine learning, excluding generative AI and GPAI

(31b) The Machinery Regulation (EU) 2023/1230 is moved from Annex I Section A to Section B

AIA Code

Annex I

AIH 0201

"Annex I

AI systems that process structured data

Section A. List of Union harmonisation legislation based on the New Legislative Framework as amended as follows:

AIH 0202

(2) Section B, the following points are added from section A:

AI systems that process signal and audio data

1. Directive 2006/42/EC of the European Parliament and of the Council of 17 May 2006 on machinery, and amending Directive 95/16/EC (OJ L 157, 9.6.2006, p. 24);

AIH 0203

13. Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery and repealing Directive 2006/42/EC of the European Parliament and of the Council and Council Directive 73/361/EEC"

AI systems that process text data

(32024R1689)

AIH 0204

Justification

AI systems that process image and video

Particularly in the area of self-learning machines and software, the AI Act contains a number of safety requirements that are already included in the Machinery Regulation. To avoid double regulation, the Machinery Regulation contained in Annex I Section A is to be moved to Section B.

AIH 0205

ANNEX: DECLARATION OF INPUT

AI systems that learn from their environment, excluding AI systems covered under AIH 0401

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur for opinion declares that he included in his opinion input on matters pertaining to the subject of the file that he received, in the preparation of the opinion, prior to the adoption thereof in committee, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

c. AI systems based on GPAI or generative AI

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

AIA Code

Volkswagen

AIH 0301

Logitech

generative AI systems, including AI systems based on GPAI models

DKB

d. Emerging AI technologies

Indeed

AIA Code

Adobe

AIH 0401

Vzbv

AI systems based on other emerging AI technologies not covered by other codes, including Agentic AI

Mozilla Foundation

3. Application for designation

Bitkom

Conformity assessment bodies shall use the lists of codes, categories and corresponding types of AI systems set out in this Annex when specifying the types of AI systems in the application for designation referred to in Article 29 of this Regulation.’.

Cocir

Article 2 Amendments to Regulation (EU) 2018/1139

E-on

Regulation (EU) 2018/1139 is amended as follows:

Milestones Systems

(1) in Article 27, the following paragraph is added:

Volkswagen

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council1, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;

German Chamber of Commerce

_____________

German Association of Local Public Utilities

1 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).’

Philips

(2) in Article 31, the following paragraph is added:

OpenAI

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies

(3) in Article 32, the following paragraph is added:

The list above is drawn up under the exclusive responsibility of the rapporteur for opinion.

‘3. When adopting delegated acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur for opinion declares that he has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.

(4) in Article 36, the following paragraph is added:

PROCEDURE – COMMITTEE ASKED FOR OPINION

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

Title

(5) in Article 39 the following paragraph is added:

Amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

‘3. When adopting delegated acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

References

(6) in Article 50, the following paragraph is added:

COM(2025)0836 – C10-0304/2025 – 2025/0359(COD)

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.;’

Committee(s) responsible

(7) in Article 53, the following paragraph is added:

Date announced in plenary

‘3. Without prejudice to paragraph 2, when adopting implementing acts pursuant to paragraph 1 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.’

IMCO

Article 2a Amendments to Regulation (EU) 2023/1230

19.1.2026

Regulation (EU) 2023/1230 is amended as follows:

LIBE

(1) in Article 8, the following subparagraphs are added:

19.1.2026

‘The Commission shall adopt delegated acts in accordance with Article 47 to amend Annex III by adding health and safety requirements in respect of AI-systems that are classified as high-risk pursuant to Article 6(1) of Regulation (EU) 2024/1689 because they are a safety component in a product covered by this Regulation, or because they are themselves a product covered by this Regulation. Those requirements shall ensure that the relevant requirements set out in Chapter III, Section 2, and Articles 17, 19, 72 and 73 of Regulation (EU) 2024/1689 are reflected.

Opinion by

When adopting the delegated acts referred to in the third paragraph, the Commission shall take into account the objectives of Regulation (EU) 2024/1689 and ensure a level of protection consistent with that Regulation.

Date announced in plenary

Such delegated acts shall apply by 2 August 2028.’;

JURI

(2) in Article 20, the following paragraph is added:

19.1.2026

‘10. Until harmonised standards or common specifications are referenced or adopted under this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards or common specifications referenced or adopted under Articles 40 and 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III as regards high-risk AI systems.’.

Rapporteur for the opinion

Article 3 Entry into force and application

Date appointed

This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union.

Sergey Lagodinsky

This Regulation shall be binding in its entirety and directly applicable in all Member States.

3.12.2025

Done at Brussels,

Rule 59 – Joint committee procedure

For the European Parliament For the Council

Date announced in plenary

The President The President

19.1.2026

Discussed in committee

12.2.2026

Date adopted

24.2.2026

Result of final vote

+:

–:

0:

18

6

0

FINAL VOTE BY ROLL CALL BY THE COMMITTEE ASKED FOR OPINION

Key to symbols: