Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0188 → TA-9-2023-0236

From
A-9-2023-0188 Plenary report of 22 May 2023
To
TA-9-2023-0236 Adopted text of 14 Jun 2023
Changes
105 changes to the text
Paragraphs
+5 added · −28 removed · 105 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts
Title (to)
Artificial Intelligence Act

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 11 of 15: Paragraphs 601–660

58 unchanged paragraphs

Article 62 – paragraph 2 a (new): 2 a. The national supervisory authority shall take appropriate measures within 7 days from the date it received the notification referred to in paragraph 1. Where the infringement takes place or is likely to take place in other Member States, the national supervisory authority shall notify the AI Office and the relevant national supervisory authorities of these Member States.

Article 62 – paragraph 3: 3. For high-risk AI systems referred to in Annex III that are placed on the market or put into service by providers that are subject to Union legislative instruments laying down reporting obligations equivalent to those set out in this Regulation, the notification of serious incidents constituting a breach of fundamental rights under Union law shall be transferred to the national supervisory authority.

Article 62 – paragraph 3 a (new): 3 a. National supervisory authorities shall on an annual basis notify the AI Office of the serious incidents reported to them in accordance with this Article.

Article 63 – paragraph 1 – introductory part: 1. Regulation (EU) 2019/1020 shall apply to AI systems and foundation models covered by this Regulation. However, for the purpose of the effective enforcement of this Regulation:

Article 63 – paragraph 1 – point b a (new): (b a) the national supervisory authorities shall act as market surveillance authorities under this Regulation and have the same powers and obligations as market surveillance authorities under Regulation (EU) 2019/1020.

Article 63 – paragraph 2: 2. The national supervisory authority shall report to the Commission and the AI Office annually the outcomes of relevant market surveillance activities. The national supervisory authority shall report, without delay, to the Commission and relevant national competition authorities any information identified in the course of market surveillance activities that may be of potential interest for the application of Union law on competition rules.

Article 63 – paragraph 3 a (new): 3 a. For the purpose of ensuring the effective enforcement of this Regulation, national supervisory authorities may: / (a) carry out unannounced on-site and remote inspections of high-risk AI systems; / (b) acquire samples related to high-risk AI systems, including through remote inspections, to reverse-engineer the AI systems and to acquire evidence to identify non-compliance.

Article 63 – paragraph 5: 5. For AI systems that are used for law enforcement purposes, Member States shall designate as market surveillance authorities for the purposes of this Regulation the competent data protection supervisory authorities under Directive (EU) 2016/680.

Article 63 – paragraph 7: 7. National supervisory authorities designated under this Regulation shall coordinate with other relevant national authorities or bodies which supervise the application of Union harmonisation law listed in Annex II or other Union law that might be relevant for the high-risk AI systems referred to in Annex III.

Article 64 – paragraph 1: 1. In the context of their activities, and upon their reasoned request the national supervisory authority shall be granted full access to the training, validation and testing datasets used by the provider, or, where relevant, the deployer, that are relevant and strictly necessary for the purpose of its request through appropriate technical means and tools.

Article 64 – paragraph 2: 2. Where necessary to assess the conformity of the high-risk AI system with the requirements set out in Title III, Chapter 2, after all other reasonable ways to verify conformity including paragraph 1 have been exhausted and have proven to be insufficient, and upon a reasoned request, the national supervisory authority shall be granted access to the training and trained models of the AI system, including its relevant model parameters. All information in line with Article 70 obtained shall be treated as confidential information and shall be subject to existing Union law on the protection of intellectual property and trade secrets and shall be deleted upon the completion of the investigation for which the information was requested.

Article 64 – paragraph 2 a (new): 2 a. Paragraphs 1 and 2 are without prejudice to the procedural rights of the concerned operator in accordance with Article 18 of Regulation (EU) 2019/1020.

Article 64 – paragraph 3: 3. National public authorities or bodies which supervise or enforce the respect of obligations under Union law protecting fundamental rights in relation to the use of high-risk AI systems referred to in Annex III shall have the power to request and access any documentation created or maintained under this Regulation when access to that documentation is necessary for the fulfilment of the competences under their mandate within the limits of their jurisdiction. The relevant public authority or body shall inform the national supervisory authority of the Member State concerned of any such request.

Article 64 – paragraph 4: 4. By 3 months after the entering into force of this Regulation, each Member State shall identify the public authorities or bodies referred to in paragraph 3 and make a list publicly available on the website of the national supervisory authority. National supervisory authorities shall notify the list to the Commission, the AI Office, and all other national supervisory authorities and keep the list up to date. The Commission shall publish in a dedicated website the list of all the competent authorities designated by the Member States in accordance with this Article.

Article 64 – paragraph 5: 5. Where the documentation referred to in paragraph 3 is insufficient to ascertain whether a breach of obligations under Union law intended to protect fundamental rights has occurred, the public authority or body referred to in paragraph 3 may make a reasoned request to the national supervisory authority, to organise testing of the high-risk AI system through technical means. The national supervisory authority shall organise the testing with the close involvement of the requesting public authority or body within reasonable time following the request.

Article 65 – paragraph 1: 1. AI systems presenting a risk shall be understood as an AI system having the potential to affect adversely health and safety, fundamental rights of persons in general, including in the workplace, protection of consumers, the environment, public security, or democracy or the rule of law and other public interests, that are protected by the applicable Union harmonisation law, to a degree which goes beyond that considered reasonable and acceptable in relation to its intended purpose or under the normal or reasonably foreseeable conditions of use of the system are concerned, including the duration of use and, where applicable, its putting into service, installation and maintenance requirements.

Article 65 – paragraph 2 – introductory part: 2. Where the national supervisory authority of a Member State has sufficient reasons to consider that an AI system presents a risk as referred to in paragraph 1, it shall carry out an evaluation of the AI system concerned in respect of its compliance with all the requirements and obligations laid down in this Regulation. When risks to fundamental rights are present, the national supervisory authority shall also immediately inform and fully cooperate with the relevant national public authorities or bodies referred to in Article 64(3); Where there is sufficient reason to consider that that an AI system exploits the vulnerabilities of vulnerable groups or violates their rights intentionally or unintentionally, the national supervisory authority shall have the duty to investigate the design goals, data inputs, model selection, implementation and outcomes of the AI system . The relevant operators shall cooperate as necessary with the national supervisory authority and the other national public authorities or bodies referred to in Article 64(3);

Article 65 – paragraph 2 – subparagraph 1: Where, in the course of that evaluation, the national supervisory authority or, where relevant, the national public authority referred to in Article 64(3) finds that the AI system does not comply with the requirements and obligations laid down in this Regulation, it shall without delay require the relevant operator to take all appropriate corrective actions to bring the AI system into compliance, to withdraw the AI system from the market, or to recall it within a reasonable period, commensurate with the nature of the risk, as it may prescribe and in any event no later than fifteen working days or as provided for in the relevant Union harmonisation law as applicable

Article 65 – paragraph 2 – subparagraph 2: The national supervisory authority shall inform the relevant notified body accordingly. Article 18 of Regulation (EU) 2019/1020 shall apply to the measures referred to in the second subparagraph.

Article 65 – paragraph 3: 3. Where the national supervisory authority considers that non-compliance is not restricted to its national territory, it shall inform the Commission, the AI Office and the national supervisory authority of the other Member States without undue delay of the results of the evaluation and of the actions which it has required the operator to take.

Article 65 – paragraph 5: 5. Where the operator of an AI system does not take adequate corrective action within the period referred to in paragraph 2, the national supervisory authority shall take all appropriate provisional measures to prohibit or restrict the AI system's being made available on its national market or put into service, to withdraw the AI system from that market or to recall it. That authority shall immediately inform the Commission, the AI Office and the national supervisory authority of the other Member States of those measures.

Article 65 – paragraph 6 – introductory part: 6. The information referred to in paragraph 5 shall include all available details, in particular the data necessary for the identification of the non-compliant AI system, the origin of the AI system and the supply chain, the nature of the non-compliance alleged and the risk involved, the nature and duration of the national measures taken and the arguments put forward by the relevant operator. In particular, the national supervisory authority shall indicate whether the non-compliance is due to one or more of the following:

Article 65 – paragraph 6 – point a: (a) a failure of the high-risk AI system to meet requirements set out this Regulation;

Article 65 – paragraph 6 – point b a (new): (b a) non-compliance with the prohibition of the artificial intelligence practices referred to in Article 5;

Article 65 – paragraph 6 – point b b (new): (b b) non-compliance with provisions set out in Article 52.

Article 65 – paragraph 7: 7. The national supervisory authorities of the Member States other than the national supervisory authority of the Member State initiating the procedure shall without delay inform the Commission, the AI Office and the other Member States of any measures adopted and of any additional information at their disposal relating to the non-compliance of the AI system concerned, and, in the event of disagreement with the notified national measure, of their objections.

Article 65 – paragraph 8: 8. Where, within three months of receipt of the information referred to in paragraph 5, no objection has been raised by either a national supervisory authority of a Member State or the Commission in respect of a provisional measure taken by a national supervisory authority of another Member State, that measure shall be deemed justified. This is without prejudice to the procedural rights of the concerned operator in accordance with Article 18 of Regulation (EU) 2019/1020. The period referred to in the first sentence of this paragraph shall be reduced to thirty days in the event of non-compliance with the prohibition of the artificial intelligence practices referred to in Article 5.

Article 65 – paragraph 9: 9. The national supervisory authorities of all Member States shall ensure that appropriate restrictive measures are taken in respect of the AI system concerned, such as withdrawal of the AI system from their market, without delay.

Article 65 – paragraph 9 a (new): 9 a. National supervisory authorities shall annually report to the AI Office about the use of prohibited practices that occurred during that year and about the measures taken to eliminate or mitigate the risks in accordance with this Article.

Article 66 – paragraph 1: 1. Where, within three months of receipt of the notification referred to in Article 65(5), or 30 days in the case of non-compliance with the prohibition of the artificial intelligence practices referred to in Article 5, objections are raised by the national supervisory authority of a Member State against a measure taken by another national supervisory authority, or where the Commission considers the measure to be contrary to Union law, the Commission shall without delay enter into consultation with the national supervisory authority of the relevant Member State and operator or operators and shall evaluate the national measure. On the basis of the results of that evaluation, the Commission shall decide whether the national measure is justified or not within three months, or 60 days in the case of non-compliance with the prohibition of the artificial intelligence practices referred to in Article 5, starting from the notification referred to in Article 65(5) and notify such decision to the national supervisory authority of the Member State concerned. The Commission shall also inform all other national supervisory authorities of such decision.

Article 66 – paragraph 2: 2. If the national measure is considered justified, all national supervisory authorities designated under this Regulation shall take the measures necessary to ensure that the non-compliant AI system is withdrawn from their market without delay, and shall inform the Commission and the AI Office accordingly. If the national measure is considered unjustified, the national supervisory authority of the Member State concerned shall withdraw the measure.

Article 66 a (new): Article 66 a / Joint investigations / Where a national supervisory authority has reasons to suspect that the infringement by a provider or a deployer of a high-risk AI system or foundation model to this Regulation amount to a widespread infringement with a Union dimension, or affects or is likely affect at least 45 million individuals, in more than one Member State, that national supervisory authority shall inform the AI Office and may request the national supervisory authorities of the Member States where such infringement took place to start a joint investigation. The AI Office shall provide central coordination to the joint investigation. Investigation powers shall remain within the competence of the national supervisory authorities.

Article 67 – paragraph 1: 1. Where, having performed an evaluation under Article 65, in full cooperation with the relevant national public authority referred to in Article 64(3), the national supervisory authority of a Member State finds that although an AI system is in compliance with this Regulation, it presents a serious risk to the health or safety of persons, to the compliance with obligations under Union or national law intended to protect fundamental rights, or the environment or the democracy and rule of law or to other aspects of public interest protection , it shall require the relevant operator to take all appropriate measures to ensure that the AI system concerned, when placed on the market or put into service, no longer presents that risk.

Article 67 – paragraph 2: 2. The provider or other relevant operators shall ensure that corrective action is taken in respect of all the AI systems concerned that they have made available on the market throughout the Union within the timeline prescribed by the national supervisory authority authority of the Member State referred to in paragraph 1.

Article 67 – paragraph 2 a (new): 2 a. Where the provider or other relevant operators fail to take corrective action as referred to in paragraph 2 and the AI system continues to present a risk as referred to in paragraph 1, the national supervisory authority may require the relevant operator to withdraw the AI system from the market or to recall it within a reasonable period, commensurate with the nature of the risk.

Article 67 – paragraph 3: 3. The national supervisory authority shall immediately inform the Commission, the AI Office and the other national supervisory authorities. That information shall include all available details, in particular the data necessary for the identification of the AI system concerned, the origin and the supply chain of the AI system, the nature of the risk involved and the nature and duration of the national measures taken.

Article 67 – paragraph 4: 4. The Commission, in consultation with the AI Office shall without delay enter into consultation with the national supervisory authorities concerned and the relevant operator and shall evaluate the national measures taken. On the basis of the results of that evaluation, the AI Office shall decide whether the measure is justified or not and, where necessary, propose appropriate measures.

Article 67 – paragraph 5: 5. The Commission, in consultation with the AI Office shall immediately communicate its decision to the national supervisory authorities of the Member States concerned and to the relevant operators. It shall also inform the decision to all other national supervisory authorities.

Article 67 – paragraph 5 a (new): 5 a. The Commission shall adopt guidelines to help national competent authorities to identify and rectify, where necessary, similar problems arising in other AI systems.

Article 68 – paragraph 1 – introductory part: 1. Where the national supervisory authority of a Member State makes one of the following findings, it shall require the relevant provider to put an end to the non-compliance concerned:

Article 68 – paragraph 1 – point a: (a) the CE marking has been affixed in violation of Article 49;

Article 68 – paragraph 1 – point b: (b) the CE marking has not been affixed;

Article 68 – paragraph 1 – point e a (new): (e a) the technical documentation is not available;

Article 68 – paragraph 1 – point e b (new): (e b) the registration in the EU database has not been carried out;

Article 68 – paragraph 1 – point e c (new): (e c) where applicable, the authorised representative has not been appointed.

Article 68 – paragraph 2: 2. Where the non-compliance referred to in paragraph 1 persists, the national supervisory authority of the Member State concerned shall take appropriate and proportionate measures to restrict or prohibit the high-risk AI system being made available on the market or ensure that it is recalled or withdrawn from the market without delay. The national supervisory authority of the Member State concerned shall immediately inform the AI Office of the non-compliance and the measures taken.

Article 68 – Chapter 3a (new): 3 a. Remedies

Article 68 a (new): Article 68 a / Right to lodge a complaint with a national supervisory authority / 1. Without prejudice to any other administrative or judicial remedy, every natural persons or groups of natural persons shall have the right to lodge a complaint with a national supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if they consider that the AI system relating to him or her infringes this Regulation. / 2. The national supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.

Article 68 b (new): Article 68 b / Right to an effective judicial remedy against a national supervisory authority / 1. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a national supervisory authority concerning them. / 2. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to a an effective judicial remedy where the national supervisory authority which is competent pursuant to Articles 59 does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 68a. / 3. Proceedings against a national supervisory authority shall be brought before the courts of the Member State where the national supervisory authority is established. / 4. Where proceedings are brought against a decision of a national supervisory authority which was preceded by an opinion or a decision of the Commission in the union safeguard procedure, the supervisory authority shall forward that opinion or decision to the court.

Article 68 c (new): Article 68 c / A right to explanation of individual decision-making / 1. Any affected person subject to a decision which is taken by the deployer on the basis of the output from an high-risk AI system which produces legal effects or similarly significantly affects him or her in a way that they consider to adversely impact their health, safety, fundamental rights, socio-economic well-being or any other of the rights deriving from the obligations laid down in this Regulation, shall have the right to request from the deployer clear and meaningful explanation pursuant to Article 13(1) on the role of the AI system in the decision-making procedure, the main parameters of the decision taken and the related input data. / 2. Paragraph 1 shall not apply to the use of AI systems for which exceptions from, or restrictions to, the obligation under paragraph 1 follow from Union or national law are provided in so far as such exception or restrictions respect the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society. / 3. This Article shall apply without prejudice to Articles 13, 14, 15, and 22 of the Regulation 2016/679.

Article 68 d (new): Article 68 d / Amendment to Directive (EU) 2020/1828 / In Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council 1a, the following point is added: / “(67a) Regulation xxxx/xxxx of the European Parliament and of the Council [laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts (OJ L ...)]”. / 1a Directive (EU) 2020/1828 of the European Parliament and of the Council of 25 November 2020 on representative actions for the protection of the collective interests of consumers and repealing Directive 2009/22/EC (OJ L 409, 4.12.2020, p. 1).

Article 68 e (new): Article 68 e / Reporting of breaches and protection of reporting persons / Directive (EU) 2019/1937 of the European Parliament and of the Council shall apply to the reporting of breaches of this Regulation and the protection of persons reporting such breaches.

Article 69 – paragraph 1: 1. The Commission, the AI Office and the Member States shall encourage and facilitate the drawing up of codes of conduct intended, including where they are drawn up in order to demonstrate how AI systems respect the principles set out in Article 4a and can thereby be considered trustworthy, to foster the voluntary application to AI systems other than high-risk AI systems of the requirements set out in Title III, Chapter 2 on the basis of technical specifications and solutions that are appropriate means of ensuring compliance with such requirements in light of the intended purpose of the systems.

Article 69 – paragraph 2: 2. Codes of conduct intended to foster the voluntary compliance with the principles underpinning trustworthy AI systems, shall, in particular: / (a) aim for a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems in order to observe such principles; / (b) assess to what extent their AI systems may affect vulnerable persons or groups of persons, including children, the elderly, migrants and persons with disabilities or whether measures could be put in place in order to increase accessibility, or otherwise support such persons or groups of persons; / (c) consider the way in which the use of their AI systems may have an impact or can increase diversity, gender balance and equality; / (d) have regard to whether their AI systems can be used in a way that, directly or indirectly, may residually or significantly reinforce existing biases or inequalities; / (e) reflect on the need and relevance of having in place diverse development teams in view of securing an inclusive design of their systems; / (f) give careful consideration to whether their systems can have a negative societal impact, notably concerning political institutions and democratic processes; / (g) evaluate how AI systems can contribute to environmental sustainability and in particular to the Union’s commitments under the European Green Deal and the European Declaration on Digital Rights and Principles.

Article 69 – paragraph 3: 3. Codes of conduct may be drawn up by individual providers of AI systems or by organisations representing them or by both, including with the involvement of users and any interested stakeholders, including scientific researchers, and their representative organisations, in particular trade unions, and consumer organisations. Codes of conduct may cover one or more AI systems taking into account the similarity of the intended purpose of the relevant systems. Providers adopting codes of conduct will designate at least one natural person responsible for internal monitoring.

Article 69 – paragraph 4: 4. The Commission and the AI Office shall take into account the specific interests and needs of SMEs and start-ups when encouraging and facilitating the drawing up of codes of conduct.

Article 70 – paragraph 1 – introductory part: 1. The Commission, national competent authorities and notified bodies, the AI Office and any other natural or legal person involved in the application of this Regulation shall respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular;

Article 70 – paragraph 1 – point a: (a) intellectual property rights, and confidential business information or trade secrets of a natural or legal person, in accordance with the provisions of Directives 2004/48/EC and 2016/943/EC, including source code, except the cases referred to in Article 5 of Directive 2016/943 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure apply;

Change 102

ChangedArticle 70 – paragraph 1 – point b a (new), Article 70 paragraphg 1 – point c:(new): (b a) public and national security interests

Article 70 – paragraph 1 a (new): 1 a. The authorities involved in the application of this Regulation pursuant to paragraph 1 shall minimise the quantity of data requested for disclosure to the data that is strictly necessary for the perceived risk and the assessment of that risk. They shall delete the data as soon as it is no longer needed for the purpose it was requested for. They shall put in place adequate and effective cybersecurity, technical and organisational measures to protect the security and confidentiality of the information and data obtained in carrying out their tasks and activities;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2023). “Changes between A-9-2023-0188 and TA-9-2023-0236”. Text, 14 June 2023. from A-9-2023-0188, to TA-9-2023-0236. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=11 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-06-14,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0188 and TA-9-2023-0236}},
  year = {2023},
  date = {2023-06-14},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=11}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=11},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0188, to TA-9-2023-0236. Data: European Parliament Open Data (CC BY 4.0)}
}