Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0188 → TA-9-2023-0236

From
A-9-2023-0188 Plenary report of 22 May 2023
To
TA-9-2023-0236 Adopted text of 14 Jun 2023
Changes
105 changes to the text
Paragraphs
+5 added · −28 removed · 105 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts
Title (to)
Artificial Intelligence Act

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 8 of 15: Paragraphs 421–480

60 unchanged paragraphs

Article 29 – paragraph 1 a (new): 1 a. To the extent deployers exercise control over the high-risk AI system, they shall / i) implement human oversight according to the requirements laid down in this Regulation / (ii) ensure that the natural persons assigned to ensure human oversight of the high-risk AI systems are competent, properly qualified and trained, and have the necessary resources in order to ensure the effective supervision of the AI system in accordance with Article 14 / (iii) ensure that relevant and appropriate robustness and cybersecurity measures are regularly monitored for effectiveness and are regularly adjusted or updated.

Article 29 – paragraph 2: 2. The obligations in paragraph 1 and 1a, are without prejudice to other deployer obligations under Union or national law and to the deployer’s discretion in organising its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider.

Article 29 – paragraph 3: 3. Without prejudice to paragraph 1 and 1a, to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system.

Article 29 – paragraph 4 – introductory part: 4. Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions of use and when relevant, inform providers in accordance with Article 61. When they have reasons to consider that the use in accordance with the instructions of use may result in the AI system presenting a risk within the meaning of Article 65(1) they shall, without undue delay, inform the provider or distributor and relevant national supervisory authorities and suspend the use of the system. They shall also immediately inform first the provider, and then the importer or distributor and relevant national supervisory authorities when they have identified any serious incident or any malfunctioning within the meaning of Article 62 and interrupt the use of the AI system. If the deployer is not able to reach the provider, Article 62 shall apply mutatis mutandis.

Article 29 – paragraph 4 – subparagraph 1: For deployers that are credit institutions regulated by Directive 2013/36/EU, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to Article 74 of that Directive.

Article 29 – paragraph 5 – introductory part: 5. Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system, to the extent that such logs are under their control and are required for ensuring and demonstrating compliance with this Regulation, for ex-post audits of any reasonably foreseeable malfunction, incidents or misuses of the system, or for ensuring and monitoring for the proper functioning of the system throughout its lifecycle. Without prejudice to applicable Union or national law, the logs shall be kept for a period of at least six months. The retention period shall be in accordance with industry standards and appropriate to the intended purpose of the high-risk AI system.

Article 29 – paragraph 5 – subparagraph 1: Deployers that are credit institutions regulated by Directive 2013/36/EU shall maintain the logs as part of the documentation concerning internal governance arrangements, processes and mechanisms pursuant to Article 74 of that Directive.

Article 29 – paragraph 5 a (new): 5 a. Prior to putting into service or use a high-risk AI system at the workplace, deployers shall consult workers representatives with a view to reaching an agreement in accordance with Directive 2002/14/EC and inform the affected employees that they will be subject to the system.

Article 29 – paragraph 5 b (new): 5 b. Deployers of high-risk AI systems that are public authorities or Union institutions, bodies, offices and agencies or undertakings referred to in Article 51(1a)(b) shall comply with the registration obligations referred to in Article 51.

Article 29 – paragraph 6: 6. Where applicable, deployers of high-risk AI systems shall use the information provided under Article 13 to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, a summary of which shall be published, having regard to the specific use and the specific context in which the AI system is intended to operate. Deployers may revert in part to those data protection impact assessments for fulfilling some of the obligations set out in this article, insofar as the data protection impact assesment fulfill those obligations.

Article 29 – paragraph 6 a (new): 6 a. Without prejudice to Article 52, deployers of high-risk AI systems referred to in Annex III, which make decisions or assist in making decisions related to natural persons, shall inform the natural persons that they are subject to the use of the high-risk AI system. This information shall include the intended purpose and the type of decisions it makes. The deployer shall also inform the natural person about its right to an explanation referred to in Article 68c.

Article 29 – paragraph 6 b (new): 6 b. Deployers shall cooperate with the relevant national competent authorities on any action those authorities take in relation with the high-risk system in order to implement this Regulation.

Article 29 a (new): Article 29 a / Fundamental rights impact assessment for high-risk AI systems / Prior to putting a high-risk AI system as defined in Article 6(2) into use, with the exception of AI systems intended to be used in area 2 of Annex III, deployers shall conduct an assessment of the systems’ impact in the specific context of use. This assessment shall include, at a minimum, the following elements: / (a) a clear outline of the intended purpose for which the system will be used; / (b) a clear outline of the intended geographic and temporal scope of the system’s use; / (c) categories of natural persons and groups likely to be affected by the use of the system; / (d) verification that the use of the system is compliant with relevant Union and national law on fundamental rights; / (e) the reasonably foreseeable impact on fundamental rights of putting the high-risk AI system into use; / (f) specific risks of harm likely to impact marginalised persons or vulnerable groups; / (g) the reasonably foreseeable adverse impact of the use of the system on the environment; / (h) a detailed plan as to how the harms and the negative impact on fundamental rights identified will be mitigated. / (j) the governance system the deployer will put in place, including human oversight, complaint-handling and redress. / 2. If a detailed plan to mitigate the risks outlined in the course of the assessment outlined in paragraph 1 cannot be identified, the deployer shall refrain from putting the high-risk AI system…

Article 30 – paragraph 1: 1. Each Member State shall designate or establish a notifying authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. Those procedures shall be developed in cooperation between the notifying authorities of all Member States.

Article 30 – paragraph 7: 7. Notifying authorities shall have a sufficient number of competent personnel at their disposal for the proper performance of their tasks. Where applicable, competent personnel shall have the necessary expertise, such as a degree in an appropriate legal field, in the supervision of fundamental rights enshrined in the Charter of Fundamental Rights of the European Union.

Article 30 – paragraph 8: 8. Notifying authorities shall make sure that conformity assessments are carried out in a proportionate and timely manner, avoiding unnecessary burdens for providers, and that notified bodies perform their activities taking due account of the size of an undertaking, the sector in which it operates, its structure and the degree of complexity of the AI system in question. Particular attention shall be paid to minimising administrative burdens and compliance costs for micro and small enterprises as defined in the Annex to Commission Recommendation 2003/361/EC.

Article 32 – paragraph 1: 1. Notifying authorities shall notify only conformity assessment bodies which have satisfied the requirements laid down in Article 33.

Article 32 – paragraph 2: 2. Notifying authorities shall notify the Commission and the other Member States using the electronic notification tool developed and managed by the Commission of each conformity assessment body referred to in paragraph 1.

Article 32 – paragraph 3: 3. The notification referred to in paragraph 2 shall include full details of the conformity assessment activities, the conformity assessment module or modules and the artificial intelligence technologies concerned, as well as the relevant attestation of competence.

Article 32 – paragraph 4: 4. The conformity assessment body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of the validation of the notification where it includes an accreditation certificate referred to in Article 31(2), or within two months of the notification where it incudes documentary evidence referred to in Article 31(3.

Article 32 – paragraph 4 a (new): 4 a. Where objections are raised, the Commission shall without delay enter into consultation with the relevant Member States and the conformity assessment body. In view thereof, the Commission shall decide whether the authorisation is justified or not. The Commission shall address its decision to the Member State concerned and the relevant conformity assessment body.

Article 32 – paragraph 4 b (new): 4 b. Member States shall notify the Commission and the other Member States of conformity assessment bodies.

Article 33 – paragraph 2: 2. Notified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks as well as the minimum cybersecurity requirements set out for public administration entities identified as operators of essential services pursuant to Directive (EU 2022/2555.

Article 33 – paragraph 4: 4. Notified bodies shall be independent of the provider of a high-risk AI system in relation to which it performs conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in the high-risk AI system that is assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed AI systems that are necessary for the operations of the conformity assessment body or the use of such systems for personal purposes.

Article 33 – paragraph 4 a (new): 4 a. A conformity assessment pursuant to paragraph 1 shall be performed by employees of notified bodies who have not provided any other other service related to the matter assessed than the conformity assessment to the provider of a high-risk AI system nor to any legal person connected to that provider in the 12 months’ period before the assessment and have committed to not providing them with such services in the 12 month period following the completion of the assessment.

Article 33 – paragraph 6: 6. Notified bodies shall have documented procedures in place ensuring that their personnel, committees, subsidiaries, subcontractors and any associated body or personnel of external bodies respect the confidentiality of the information which comes into their possession during the performance of conformity assessment activities, except when disclosure is required by law. The staff of notified bodies shall be bound to observe professional secrecy with regard to all information obtained in carrying out their tasks under this Regulation, except in relation to the notifying authorities of the Member State in which their activities are carried out. Any information and documentation obtained by notified bodies pursuant to the provisions of this Article shall be treated in compliance with the confidentiality obligations set out in Article 70.

Article 34 – paragraph 3: 3. Activities may be subcontracted or carried out by a subsidiary only with the agreement of the provider. Notified bodies shall make a list of their subsidiaries publicly available.

Article 34 – paragraph 4: 4. Notified bodies shall keep at the disposal of the notifying authority the relevant documents concerning the verification of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation.

Article 35 – title: Identification numbers and lists of notified bodies

Article 36 – paragraph 1: 1. Where a notifying authority has suspicions or has been informed that a notified body no longer meets the requirements laid down in Article 33, or that it is failing to fulfil its obligations, that authority shall without delay investigate the matter with the utmost diligence. In that context, it shall inform the notified body concerned about the objections raised and give it the possibility to make its views known. If the notifying authority comes to the conclusion that the notified body no longer meets the requirements laid down in Article 33 or that it is failing to fulfil its obligations, it shall restrict, suspend or withdraw the notification as appropriate, depending on the seriousness of the failure. It shall also immediately inform the Commission and the other Member States accordingly.

Article 36 – paragraph 2: 2. In the event of restriction, suspension or withdrawal of notification, or where the notified body has ceased its activity, the notifying authority shall take appropriate steps to ensure that the files of that notified body are either taken over by another notified body or kept available for the responsible notifying authorities, and market surveillance authority at their request.

Article 37 – paragraph 1: 1. The Commission shall, where necessary, investigate all cases where there are reasons to doubt the competence of a notified body or the continued fulfilment by a notified body of the applicable requirements and responsibilities.

Article 37 – paragraph 2: 2. The Notifying authority shall provide the Commission, on request, with all relevant information relating to the notification or the maintenance of the competence of the notified body concerned.

Article 37 – paragraph 3: 3. The Commission shall ensure that all sensitive information obtained in the course of its investigations pursuant to this Article is treated confidentially.

Article 37 – paragraph 4: 4. Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including suspension or withdrawal of the notification if necessary. Where the Member State fails to take the necessary corrective measures, the Commission may, by means of an implementing act, suspend, restrict or withdraw the designation. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 74(2).

Article 38 – paragraph 2 a (new): 2 a. The Commission shall provide for the exchange of knowledge and best practices between the Member States' national authorities responsible for notification policy.

Article 40 – paragraph 1: High-risk AI systems and foundation models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) 1025/2012 shall be presumed to be in conformity with the requirements set out in Chapter 2 of this Title or Article 28b, to the extent those standards cover those requirements.

Article 40 – paragraph 1 a (new): The Commission shall issue standardisation requests covering all requirements of this Regulation, in accordance with Article 10 of Regulation EU (No)1025/2012 by... [two months after the date of entry into force of this Regulation]. When preparing standardisation request, the Commission shall consult the AI Office and the Advisory Forum;

Article 40 – paragraph 1 b (new): When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be consistent, including with the sectorial law listed in Annex II, and aimed at ensuring that AI systems or foundation models placed on the market or put into service in the Union meet the relevant requirements laid down in this Regulation;

Article 40 – paragraph 1 c (new): The actors involved in the standardisation process shall take into account the general principles for trustworthy AI set out in Article 4(a), seek to promote investment and innovation in AI as well as competitiveness and growth of the Union market, and contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and ensure a balanced representation of interests and effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012

Article 41 – paragraph 1: deleted

Article 41 – paragraph 1 a (new): 1 a. The Commission may, by means of implementing act adopted in accordance with the examination procedure referred to in Article 74(2) and after consulting the AI Office and the AI Advisory Forum, adopt common specifications in respect of the requirements set out in Chapter 2 of this Title or Article 28b wherein all of the following conditions are fulfilled: / (a) there is no reference to harmonised standards already published in the Official Journal of the European Union related to the essential requirement(s), unless the harmonised standard in question is an existing standard that must be revised; / (b) the Commission has requested one or more European standardisation organisations to draft a harmonised standard for the essential requirement(s) set out in Chapter 2; / (c) the request referred to in point (b) has not been accepted by any of the European standardisation organisations; or there are undue delays in the establishment of an appropriate harmonised standard; or the standard provided does not satisfy the requirements of the relevant Union law, or does not comply with the request of the Commission.

Article 41 – paragraph 1 b (new): 1 b. Where the Commission considers there to be a need to address specific fundamental rights concerns, common specifications adopted by the Commission in accordance with paragraph 1a shall also address those specific fundamental rights concerns.

Article 41 – paragraph 1 c (new): 1 c. The Commission shall develop common specifications for the methodology to fulfil the reporting and documentation requirement on the consumption of energy and resources during development, training and deployment of the high risk AI system.

Article 41 – paragraph 2: 2. The Commission shall, throughout the whole process of drafting the common specifications referred to in paragraphs 1a and 1b, regularly consult the AI Office and the Advisory Forum, the European standardisation organisations and bodies or expert groups established under relevant sectorial Union law as well as other relevant stakeholders. The Commission shall fulfil the objectives referred to in Article 40 (1c) and duly justify why it decided to resort to common specifications. / Where the Commission intends to adopt common specifications pursuant to paragraph 1a of this Article, it shall also clearly identify the specific fundamental rights concern to be addressed. / When adopting common specifications pursuant to paragraphs 1a and 1b of this Article, the Commission shall take into account the opinion issued by the AI Office referred to in Article 56e(b) of this Regulation. Where the Commission decides not to follow the opinion of the AI Office, it shall provide a reasoned explanation to the AI Office.

Article 41 – paragraph 3: 3. High-risk AI systems which are in conformity with the common specifications referred to in paragraph 1a and 1b shall be presumed to be in conformity with the requirements set out in Chapter 2 of this Title, to the extent those common specifications cover those requirements

Article 41 – paragraph 3 a (new): 3 a. Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference of a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal acts referred to in paragraph 1 and 1b, or parts thereof which cover the same requirements set out in Chapter 2 of this Title.

Article 41 – paragraph 4: 4. Where providers of high-risk AI systems do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Chapter II to a level at least equivalent thereto;

Article 42 – paragraph 1: 1. Taking into account their intended purpose, high-risk AI systems that have been trained and tested on data concerning the specific geographical, behavioural contextual and functional setting within which they are intended to be used shall be presumed to be in compliance with the respective requirements set out in Article 10(4).

Article 43 – paragraph 1 – introductory part: 1. For high-risk AI systems listed in point 1 of Annex III, where, in demonstrating the compliance of a high-risk AI system with the requirements set out in Chapter 2 of this Title, the provider has applied harmonised standards referred to in Article 40, or, where applicable, common specifications referred to in Article 41, the provider shall opt for one of the following procedures;

Article 43 – paragraph 1 – point a: (a) the conformity assessment procedure based on internal control referred to in Annex VI; or

Article 43 – paragraph 1 – point b: (b) the conformity assessment procedure based on assessment of the quality management system and of the technical documentation, with the involvement of a notified body, referred to in Annex VII;

Article 43 – paragraph 1 – subparagraph 1: In demonstrating the compliance of a high-risk AI system with the requirements set out in Chapter 2 of this Title, the provider shall follow the conformity assessment procedure set out in Annex VII in the following cases: / (a) where harmonised standards referred to in Article 40, the reference number of which has been published in the Official Journal of the European Union, covering all relevant safety requirements for the AI system, do not exist and common specifications referred to in Article 41 are not available; / (b) where the technical specifications referred to in point (a) exist but the provider has not applied them or has applied them only in part; / (c) where one or more of the technical specifications referred to in point (a) has been published with a restriction and only on the part of the standard that was restricted; / (d) when the provider considers that the nature, design, construction or purpose of the AI system necessitate third party verification, regardless of its risk level.

Article 43 – paragraph 1 – subparagraph 2: For the purpose of carrying out the conformity assessment procedure referred to in Annex VII, the provider may choose any of the notified bodies. However, when the system is intended to be put into service by law enforcement, immigration or asylum authorities as well as EU institutions, bodies or agencies, the market surveillance authority referred to in Article 63(5) or (6), as applicable, shall act as a notified body.

Article 43 – paragraph 4 – introductory part: 4. High-risk AI systems that have already been subject to a conformity assessment procedure shall undergo a new conformity assessment procedure whenever they are substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer;

Article 43 – paragraph 4 a (new): 4 a. The specific interests and needs of SMEs shall be taken into account when setting the fees for third-party conformity assessment under this Article, reducing those fees proportionately to their size and market share;

Article 43 – paragraph 5: 5. The Commission is empowered to adopt delegated acts in accordance with Article 73 for the purpose of updating Annexes VI and Annex VII in order to introduce elements of the conformity assessment procedures that become necessary in light of technical progress. When preparing such delegated acts, the Commission shall consult the AI Office and the stakeholders affected;

Article 43 – paragraph 6: 6. The Commission is empowered to adopt delegated acts to amend paragraphs 1 and 2 in order to subject high-risk AI systems referred to in points 2 to 8 of Annex III to the conformity assessment procedure referred to in Annex VII or parts thereof. The Commission shall adopt such delegated acts taking into account the effectiveness of the conformity assessment procedure based on internal control referred to in Annex VI in preventing or minimizing the risks to health and safety and protection of fundamental rights posed by such systems as well as the availability of adequate capacities and resources among notified bodies. When preparing such delegated acts, the Commission shall consult the AI Office and the stakeholders affected;

Article 44 – paragraph 1: 1. Certificates issued by notified bodies in accordance with Annex VII shall be drawn-up in one or several official Union languages determined by the Member State in which the notified body is established or in one or several official Union languages otherwise acceptable to the notified body;

Article 44 – paragraph 2: 2. Certificates shall be valid for the period they indicate, which shall not exceed four years. On application by the provider, the validity of a certificate may be extended for further periods, each not exceeding four years, based on a re-assessment in accordance with the applicable conformity assessment procedures;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2023). “Changes between A-9-2023-0188 and TA-9-2023-0236”. Text, 14 June 2023. from A-9-2023-0188, to TA-9-2023-0236. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=8 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-06-14,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0188 and TA-9-2023-0236}},
  year = {2023},
  date = {2023-06-14},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=8}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0188/compare/TA-9-2023-0236?all=1&part=8},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0188, to TA-9-2023-0236. Data: European Parliament Open Data (CC BY 4.0)}
}