Cell Register
Regimes · AI Act

The EU AI Act

Attaches only to an adaptive controller or a safety component that is an AI system; a fixed-program machine gets no row, and the page says why.

Who it binds: Articles 26 and 4 bind the deployer, which is the asset owner using the system; Articles 12 to 15 bind the provider; a deployer that substantially modifies the system becomes its provider.

On the register, tick "EU AI Act deployer" and these rows appear on every asset the regime reaches. Source framework page on the compliance graph.

The rows, and when each attaches

Asset owner duty
where the controller adapts
As the deployer of an adaptive controller
AI Act Art. 4 · Art. 6 · Art. 26
An AI system used as a safety component of a machine, or that is itself the product, under the Union harmonisation legislation in Annex I (the Machinery Regulation is listed there) falls under Article 6(1). The deployer uses it per the instructions, assigns oversight to competent persons, monitors it, keeps its logs and makes its people literate in it.
Ask the provider
where the controller adapts
Articles 12 to 15 bind the provider, not the deployer
AI Act Art. 12 · Art. 13 · Art. 14 · Art. 15
Human oversight by design, accuracy, robustness and cybersecurity, instructions for use that carry the oversight measures, and event logging are the provider's duties; the deployer asks for the evidence of each.
Asset owner duty
where the controller adapts
If the owner substantially modifies the system
AI Act Art. 25
A deployer that substantially modifies a high-risk system, or changes its intended purpose so that it becomes high-risk, takes on the provider's obligations.
On the register as a wholeAI Act Art. 4 · Art. 6

When a machine is a high-risk AI system

An AI system intended to be used as a safety component of a product covered by the Union harmonisation legislation in Annex I, or that is itself such a product, is high-risk under Article 6(1) where the product must undergo third-party conformity assessment; the Machinery Regulation is listed in Annex I. On the register that is an adaptive controller on a machine, or a safety component that learns. The deployer duties are Article 26 and Article 4; Articles 14 and 15 are what to ask the provider; a deployer that substantially modifies the system becomes its provider under Article 25.

A fixed-program machine is not an AI system: it does not infer from input how to generate its output and it does not learn or re-plan at runtime. No AI Act row attaches to it; the Machinery Regulation and IEC 62443 do. Named reference, not quoted: EU AI Act Annex I, the Union harmonisation legislation whose products carry high-risk classification (the Machinery Regulation is listed in it).

The clauses, quoted

8 of 43 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

AI Act Art. 6 Classification rules for high-risk AI systems

Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

Evidence an auditor accepts: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation
Common gap: Classification decided once at design time and never revisited when the intended purpose broadened
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable
Common gap: Deployer not following IFU
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 4 AI literacy

Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

Evidence an auditor accepts: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort
Common gap: One generic awareness module issued to everyone regardless of role or technical starting point
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of automation bias, correctly interpret the output, decide not to use the output or override or reverse it, intervene in operation, and stop the system.

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
Common gap: Oversight is nominal (e.g. cannot stop the system in practice)
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 15 Accuracy, robustness and cybersecurity

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against attempts by unauthorised third parties to alter use, output or performance (incl data poisoning, model poisoning, adversarial examples and confidentiality attacks).

Evidence an auditor accepts: Accuracy/robustness measurements relevant to the intended purpose; Adversarial/data-poisoning threat modelling and mitigation; Cybersecurity controls aligned with state-of-the-art
Common gap: No adversarial-attack threat modelling
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 13 Transparency and provision of information to deployers

High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret the output and use it appropriately. Providers shall provide instructions for use including the system's intended purpose, level of accuracy/robustness/cybersecurity, foreseeable misuse, performance characteristics, human oversight measures, hardware/software requirements, lifetime and maintenance/care.

Evidence an auditor accepts: Instructions for use covering the Art.13 content list; Deployer-facing system documentation
Common gap: Generic IFU without the Art.13 content elements
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the reference database against which input data has been checked, the input data for which the search led to a match, and the natural persons involved in the verification.

Evidence an auditor accepts: Logging capability design evidence; Log-retention policy aligned with the intended purpose
Common gap: Insufficient logging to reconstruct system operation
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 25 Responsibilities along the AI value chain

Distributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider, providing access to information, technical access and other assistance reasonably needed.

Evidence an auditor accepts: Documented allocation of provider status across the value chain; Cooperation agreements between original and new providers
Common gap: Substantial modification without taking on provider obligations
Source framework: EU AI Act (Regulation (EU) 2024/1689)

See what it attaches to your list

Paste the equipment list, tick the regime, and every asset it reaches carries these rows. Eight assets free, no account.

Build my cell register