The EU AI Act
Attaches only to an adaptive controller or a safety component that is an AI system; a fixed-program machine gets no row, and the page says why.
Who it binds: Articles 26 and 4 bind the deployer, which is the asset owner using the system; Articles 12 to 15 bind the provider; a deployer that substantially modifies the system becomes its provider.
On the register, tick "EU AI Act deployer" and these rows appear on every asset the regime reaches. Source framework page on the compliance graph.
The rows, and when each attaches
| Asset owner duty where the controller adapts | As the deployer of an adaptive controller AI Act Art. 4 · Art. 6 · Art. 26 An AI system used as a safety component of a machine, or that is itself the product, under the Union harmonisation legislation in Annex I (the Machinery Regulation is listed there) falls under Article 6(1). The deployer uses it per the instructions, assigns oversight to competent persons, monitors it, keeps its logs and makes its people literate in it. |
|---|---|
| Ask the provider where the controller adapts | Articles 12 to 15 bind the provider, not the deployer AI Act Art. 12 · Art. 13 · Art. 14 · Art. 15 Human oversight by design, accuracy, robustness and cybersecurity, instructions for use that carry the oversight measures, and event logging are the provider's duties; the deployer asks for the evidence of each. |
| Asset owner duty where the controller adapts | If the owner substantially modifies the system AI Act Art. 25 A deployer that substantially modifies a high-risk system, or changes its intended purpose so that it becomes high-risk, takes on the provider's obligations. |
| On the register as a whole | AI Act Art. 4 · Art. 6 |
When a machine is a high-risk AI system
An AI system intended to be used as a safety component of a product covered by the Union harmonisation legislation in Annex I, or that is itself such a product, is high-risk under Article 6(1) where the product must undergo third-party conformity assessment; the Machinery Regulation is listed in Annex I. On the register that is an adaptive controller on a machine, or a safety component that learns. The deployer duties are Article 26 and Article 4; Articles 14 and 15 are what to ask the provider; a deployer that substantially modifies the system becomes its provider under Article 25.
A fixed-program machine is not an AI system: it does not infer from input how to generate its output and it does not learn or re-plan at runtime. No AI Act row attaches to it; the Machinery Regulation and IEC 62443 do. Named reference, not quoted: EU AI Act Annex I, the Union harmonisation legislation whose products carry high-risk classification (the Machinery Regulation is listed in it).
The clauses, quoted
8 of 43 in the frameworkRequirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
AI Act Art. 6 Classification rules for high-risk AI systemsDetermine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.
Common gap: Classification decided once at design time and never revisited when the intended purpose broadened
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.
Common gap: Deployer not following IFU
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 4 AI literacyProviders and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.
Common gap: One generic awareness module issued to everyone regardless of role or technical starting point
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of automation bias, correctly interpret the output, decide not to use the output or override or reverse it, intervene in operation, and stop the system.
Common gap: Oversight is nominal (e.g. cannot stop the system in practice)
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 15 Accuracy, robustness and cybersecurityHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against attempts by unauthorised third parties to alter use, output or performance (incl data poisoning, model poisoning, adversarial examples and confidentiality attacks).
Common gap: No adversarial-attack threat modelling
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 13 Transparency and provision of information to deployersHigh-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret the output and use it appropriately. Providers shall provide instructions for use including the system's intended purpose, level of accuracy/robustness/cybersecurity, foreseeable misuse, performance characteristics, human oversight measures, hardware/software requirements, lifetime and maintenance/care.
Common gap: Generic IFU without the Art.13 content elements
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 12 Record-keeping (logs)High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the reference database against which input data has been checked, the input data for which the search led to a match, and the natural persons involved in the verification.
Common gap: Insufficient logging to reconstruct system operation
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 25 Responsibilities along the AI value chainDistributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider, providing access to information, technical access and other assistance reasonably needed.
Common gap: Substantial modification without taking on provider obligations
Source framework: EU AI Act (Regulation (EU) 2024/1689)
See what it attaches to your list
Paste the equipment list, tick the regime, and every asset it reaches carries these rows. Eight assets free, no account.
Build my cell register