Skip to content
EU Parl Watch

Changes between two versions

What changed between the plenary report and the adopted text

From · plenary report· 19 Mar 2026

A-10-2026-0073

on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

To · adopted text· 26 Mar 2026

TA-10-2026-0098

Simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

AI:What changed, in short

The main substantive change adds a new condition for high-risk AI systems requiring third-party conformity assessment.3 Other changes are formal or wording: correcting references, punctuation, and formatting.1245

1 change of substance · 8 formal · 1 of wording only

Written by AI from the two texts only · read the changes before relying on it · 4 Sept 2026 · Report a problem

+4 added · −20 removed · 12 changed paragraphs, packaging included.

Part 1 of 4: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

Removed:DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

Added:P10_TA(2026)0098

Changed:on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplificationSimplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)

Removed:(COM(2025)0836 – C100304/2025 – 2025/0359(COD))

Added:Committee on the Internal Market and Consumer Protection, Committee on Civil Liberties, Justice and Home Affairs

Added:PE782.530

Added:Amendments adopted by the European Parliament on 26 March 2026 on the proposal for a regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (COM(2025)0836 – C10-0304/2025 – 2025/0359(COD))

(Ordinary legislative procedure: first reading)

Removed:The European Parliament,

Removed:– having regard to the Commission proposal to Parliament and the Council (COM(2025)0836),

Removed:– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100304/2025),

Removed:– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

Removed:– having regard to Rule 60 of its Rules of Procedure,

Removed:– having regard to the joint deliberations of the Committee on Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs under Rule 58 of the Rules of Procedure,

Removed:– having regard to the report of the Committee on the Internal Market and Consumer Protection and the Committee on Civil Liberties, Justice and Home Affairs (A10-0073/2026),

Removed:1. Adopts its position at first reading hereinafter set out;

Removed:2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

Removed:3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Recital 3: (3) Consequently, targeted amendments to Regulation (EU) 2024/1689 are necessary to address certain implementation challenges, with a view to the effective, simple and uniform application of the relevant rules.

Recital 3 a (new): (3a) Additionally, the Commission, the AI Office and Member States’ competent authorities should ensure that supervision, enforcement and monitoring of sectorial and national laws do not create overlaps, inconsistent interpretations or divergent enforcement in order to enable AI innovation in the private and public sector.

Change 1

Changed:Recital 4: (4) 99,8% of all Union companies are small and medium-sized enterprises, the majority of which are micro and small enterprises.3a Enterprises outgrowing the micro, small and medium-sized enterprises (‘SME’) definition – the ‘small mid-cap enterprises’ (‘SMCs’) – play a vital role in the Union’s economy. Compared to SMEs, SMCs tend to demonstrate a higher pace of growth, and level of innovation and digitisation. Nevertheless, they face challenges similar to SMEs in relation to administrative burden, leading to a need for proportionality in the implementation of Regulation (EU) 2024/1689 and for targeted support. To enable the smooth transition of enterprises from SMEs into SMCs, it is important to address in a coherent manner the effect that regulation may have on their activity once those enterprises outgrow the segment of SMEs and are faced with rules that apply to large enterprises. Regulation (EU) 2024/1689 provides for several measures for small-scale providers, which should be extended to SMCs where appropriate while safeguarding the overarching objectives and level of protection afforded under Regulation (EU) 2024/16893b. In order to clarify the treatment of SMEs and SMCs in Regulation (EU) 2024/1689, it is necessary to introduce definitions for SMEs and SMCs, which should correspond to the definition set out in the Annex to Commission Recommendation 2003/361/EC4 and Annex to Commission Recommendation 2025/3500/EC5(EU) 2025/35005 . / 3a https://single-market-economy.ec.europa.eu/syste…https://single-market-economy.ec.europa.eu/sys…

7 unchanged paragraphs

Recital 5: (5) Article 4 of Regulation (EU) 2024/1689 currently imposes an obligation on all providers and deployers of AI systems to ensure AI literacy of their staff. AI literacy development starting from education and training and continuing in a lifelong learning manner is crucial to equip providers, deployers and other affected persons with the necessary skills to make informed decisions regarding AI systems deployment. However, experience shared by stakeholders reveals that a solution imposing stringent obligations to ensure a sufficient level of AI literacy is not suitable for all types of providers and deployers in relation to the promotion of AI literacy. In light of that, Article 4 of Regulation (EU) 2024/1689 should be amended to require providers and deployers of AI systems to support AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. The European Commission should promote AI literacy and competences for the wider population, and in order to support, facilitate and complement the efforts of providers, should be tasked to issue guidance on the practical implementation regarding the obligation on providers and deployers of AI systems, and should, together with the Member States, encourage and support AI literacy in society. This should include facilitating and complementing the efforts of providers and deployers of AI systems, in particular SMEs, as the implementation of the relevant obligations poses particular chall…

Recital 5 a (new): (5a) AI systems that alter, manipulate or artificially generates realistic images or videos depicting sexually explicit activities, or the intimate parts of an identifiable natural person, without that person’s consent, cause harm to victims and violate fundamental rights to dignity and privacy. The proliferation of such technologies, often marketed as 'nudification’ applications, has created an urgent need for explicit regulatory prohibition. Regulation (EU) 2024/1689 establishes a framework for prohibited AI practices, which is to be kept under review. This is without prejudice towards the rights, freedoms and principles recognised by Article 6 TEU and the Charter of Fundamental Rights of the European Union, and the exercise of the rights guaranteed therein to freedom of expression and information and the freedom of the arts and sciences. This prohibition should not apply to providers or deployers of AI systems who have put in place effective safety measures, such as technical and organisational measures, to prevent the generation of such depictions and to avoid continuously misuse, after the system has been placed, on the market or put into service, despite the intention of the provider or deployer. Moreover, this prohibition should not prevent AI providers from developing their technical capabilities to alter, manipulate or artificially generate images or videos.

Recital 6: (6) Bias detection and correction constitute a substantial public interest because they protect natural persons from biases’ adverse effects, including discrimination. For that reason, Regulation (EU) 2024/1689 already provides a legal basis authorising the providers of high-risk AI systems to process special categories of personal data in certain exceptional cases and subject to strict safeguards. This legal basis is linked to those providers’ obligation to establish practices concerning the detection, prevention and mitigation of biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law. Accordingly, a substantial public interest exists to permit, where strictly necessary, the processing of special categories of personal data for the purposes of bias detection and correction. It is therefore necessary to extend the legal basis established under Regulation (EU) 2024/1689 so that it also applies to the also by providers and deployers of other AI systems and AI models. That legal basis should be subject to the same conditions and safeguards as apply under the existing Article 10(5), thereby ensuring compliance with Article 9(2), point (g) of Regulation (EU) 2016/679 Article 10(2), point (g) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and Article 10, point (a) of Directive (EU) 2016/680 of the European Parliament and of the Council.

Recital 7: deleted / (deleted) / (deleted)

Recital 8: (8) deleted

Recital 8 a (new): (8a) Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847 complement each other so that the safety and cybersecurity of products with digital elements is ensured. It is necessary to ensure the alignment of Regulation (EU) 2024/1689 and Regulation (EU) 2024/2847, to allow for their smooth implementation. Where high-risk AI systems fulfil the essential cybersecurity requirements set out in Regulation (EU) 2024/2847, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to Regulation (EU) 2024/2847.

Recital 8 b (new): (8b) For the purposes of this Regulation, the fact that an AI system is integrated into, or operates within, a product subject to Union harmonisation legislation on product safety should not, in itself, imply that the AI system performs a safety function. An AI system should be regarded as performing a safety function only where its functioning is necessary to ensure that the product or the AI system complies with applicable Union safety requirements. By contrast, functionalities intended solely for user assistance, performance optimisation, service efficiency, automation, convenience, or quality control of non-safety-related aspects should not be regarded as safety functions under this Regulation, where their failure would not directly create risks to health or safety.

Change 2

Changed:Recital 9: (9) To streamline compliance and reduce the associated costs, the registration of AI systems referred to in Article 6(3) of Regulation (EU) 2024/1689 in the EU database pursuant to Article 49(2) of that Regulation should be simplified by streamlining the required content in Section B of Annex VIII to that Regulation. While it remains crucial for effective market surveillance and public accountability that such AI systems are registered in the EU database, the registration requirements should be simplified and made more proportionate. This simplification will strike a better balance without undermining the protection laid down by Regulation (EU) 2024/1689. Such systems are not considered high-risk under certain conditions where they do not pose significant risk of harm to the health, safety or fundamental rights of persons. Furthermore, a provider applying Article 6(3) remains obligated to document its assessment before that system is placed on the market or put into service. This assessment may be requested by national competent authorities.

30 unchanged paragraphs

Recital 10: (10) Articles 57, 58 and 60 of Regulation (EU) 2024/1689 should be amended to strengthen further cooperation at Union level of AI regulatory sandboxes, foster clarity and consistency in the governance of AI regulatory sandboxes, and to extend the scope of real-world testing outside AI regulatory sandboxes to high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation. In particular, to allow procedural simplification, where applicable, in the projects supervised in the AI regulatory sandboxes that include also real-world testing, the real-world testing plan should be integrated in the sandbox plan agreed by the providers or prospective providers and the competent authority in a single document. In addition, it is appropriate to provide for the possibility of the AI Office to establish an AI regulatory sandbox at Union level for AI systems that are covered by Article 75(1) of Regulation (EU) 2024/1689. When discussions are held within the framework of the Board, the European Data Protection Supervisor and the AI Office, as part of their roles within the board, should provide feedback and exchange best practices on matters related to the establishment and operation of AI regulatory sandboxes that were established under their respective competences. By leveraging these infrastructures and facilitating cross-border collaboration, coordination would be streamlined and resources optimally utilised. In order to foster innovation and facil…

Recital 11: (11) To foster innovation, it is also appropriate to extend the scope of real-world testing outside AI regulatory sandboxes in Article 60 of Regulation (EU) 2024/1689, currently applicable to high-risk AI systems listed in Annex III to that Regulation, and allow providers and prospective providers of high-risk AI systems covered by the Union harmonisation legislation listed in Annex I to that Regulation to also test such systems in real-world conditions. This is without prejudice to other Union or national law on the testing in real-world conditions of high-risk AI systems related to products covered by that Union harmonisation legislation. To address the specific situation of high-risk AI systems covered the Union harmonisation legislation listed in Section B of Annex I to that Regulation, it is necessary to allow the conclusion of voluntary agreements between the Commission and Member States to enable testing of such high-risk AI systems in real-world conditions, subject to sufficient safeguards.

Recital 12 a (new): (12a) In order to allow the AI Office to effectively exercise its duties under Regulation (EU) 2024/1689 and in light of the new powers conferred on it by this Regulation, adequate human, financial and technical resources should be provided, without prejudice to the budgetary procedure and existing financial instruments. In particular, the AI Office should have a sufficient number of personnel whose expertise include an in-depth understanding of AI technologies.

Recital 13: (13) Article 69 of Regulation (EU) 2024/1689 should be amended to simplify the fee structure of the scientific panel. If Member States call upon the panel’s expertise, the fees they may be required to pay the experts should be equivalent to the remuneration the Commission is obliged to pay in similar circumstances.

Recital 14: (14) In order to strengthen the governance system for AI systems based on general-purpose AI models, it is necessary to clarify the role of the AI Office in monitoring and supervising compliance of such AI systems with Regulation (EU) 2024/1689, while excluding AI systems related to products covered by the Union harmonisation legislation listed in Annex I and AI systems referred to in Annex III, point 2 to that Regulation. While sectoral authorities continue to remain responsible for the supervision of AI systems related to products covered by that Union harmonisation legislation, Article 75(1) Regulation (EU) 2024/1689 should be modified to bring all AI systems based on general-purpose AI models developed by the same provider within the scope of the AI Office's supervision. This does not include AI systems placed on the market, put into service or used by Union institutions, bodies, offices or agencies, which are under the supervision of the European Data Protection Supervisor pursuant to Article 74(9) of Regulation (EU) 2024/1689. To ensure effective supervision for those AI systems in accordance with the tasks and responsibilities assigned to market surveillance authorities under Regulation (EU) 2024/1689, the AI Office should take the appropriate measures and decisions to adequately exercise its powers provided for in that Section and Regulation (EU) 2019/1020 of the European Parliament and of the Council11. Article 14 of Regulation (EU) 2019/1020 should apply mutatis mut…

Recital 16: (16) To further operationalise the AI Office’s supervision and enforcement set out in Article 75(1) of Regulation (EU) 2024/1689, it is necessary to further define which of the powers listed in Article 14 of Regulation (EU) 2019/1020 should be conferred upon the AI Office. The Commission should therefore be empowered to adopt implementing acts to specify those powers, including the ability to impose penalties, such as fines or other administrative sanctions, in accordance with the conditions and ceilings referred to in Article 99, and applicable procedures. This should ensure that the AI Office has the necessary tools to effectively monitor and supervise compliance with Regulation (EU) 2024/1689.

Recital 18: (18) To enable access to Union market for AI systems which are under the supervision by the AI Office pursuant to Article 75 of Regulation (EU) 2024/1689 and subject to third party conformity assessment, the Commission should ensure that pre-market conformity assessments are carried out for those systems. Furthermore, the AI Office should maintain organised records of communications with providers and deployers of general-purpose AI models with systemic risk. Such records should be documented in a consistent manner.

Recital 19: (19) Article 77 and related provisions of Regulation (EU) 2024/1689 constitute an important governance mechanism, as they aim to enable authorities or bodies responsible for enforcing or supervising Union law intended to protect fundamental rights to fulfil their mandate under specific conditions and to foster cooperation with market surveillance authorities responsible for the supervision and enforcement of that Regulation. It is necessary to clarify the scope of such cooperation, as well as to clarify which public authorities or bodies benefit from it. With a view to reinforcing the cooperation, it should be clarified that requests to access information and documentation should be made to the competent market surveillance authority, which should respond to such requests without undue delay, and that the involved authorities or bodies should have a mutual obligation to cooperate. It should be clarified that these provisions are without prejudice to the tasks, powers and independence of the relevant national public authorities or bodies under their mandates. In particular, those provisions do not limit any powers that those authorities and bodies have to request information pursuant to other Union or national law. Accordingly, those authorities and bodies retain any power they have to directly request information from operators pursuant to their mandate or other law.

Recital 20: (20) To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of 3 months for providers who have already placed their systems on the market before the 2 August 2026.

Recital 22: (22) Article 113 of Regulation (EU) 2024/1689 establishes the dates of entry into force and application of that Regulation, notably that the general date of application is 2 August 2026. For the obligations related to high-risk AI systems laid down in Sections 1, 2 and 3 of Chapter III of Regulation (EU) 2024/1689, the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise those obligation’s effective entry into application and that risk to significantly increase implementation costs in a way that does not justify maintaining their initial date of application, namely 2 August 2026. It is appropriate that the date of application of obligations on AI systems classified as high-risk pursuant to Article 6(2) and Annex III and on AI systems classified as high-risk pursuant to Article 6(1) and Annex I to Regulation (EU) 2024/1689 is postponed until 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and until 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I to that Regulation. The distinction between the entry into application of the rules as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III and Article 6(1) and Annex I to that Regulation is consistent with the difference between the initial dates of application envisaged in Regul…

Recital 22 a (new): (22a) In order to ensure legal certainty and to avoid further delays in application of this Regulation, the Commission should ensure that measures in support of compliance with regard to Chapter III, Sections 1, 2, and 3 are in place in due time to ensure timely and effective implementation of the necessary provisions.

Recital 23: (23) In light of the objective to reduce implementation challenges for citizens, businesses and public administrations, it is essential that harmonised conditions for the implementation of certain rules are adopted only where strictly necessary. For that purpose, it is appropriate to remove certain empowerments bestowed on the Commission to adopt such harmonised conditions by means of implementing acts in cases where those conditions are not met. Regulation (EU) 2024/1689 should therefore be amended to remove the empowerments conferred on the Commission in Article 50(7), Article 56(6), and Article 72(3) thereof to adopt implementing acts. At the same time, recognising the need to offer clarity how providers of high-risk AI systems are required to comply with their monitoring obligations, the Commission should be required to publish guidance on the post-market monitoring plan, including a template with elements to be included therein, by 2 February 2027.

Recital 23 a (new): (23a) The parallel application of sectoral Union harmonisation legislation listed in Section A of Annex I to Regulation (EU) 2024/1689 of the European Parliament and of the Council and the requirements set out in that Regulation for high-risk artificial intelligence systems may lead to overlaps of requirements and unnecessary administrative burden for economic operators. Such overlaps could create legal uncertainty, increase compliance costs and potentially lead to competitive disadvantages, without providing additional benefits for the protection of health, safety or fundamental rights. In order to ensure a more coherent and proportionate regulatory framework and to simplify the application of requirements for artificial intelligence systems embedded in products regulated under Union harmonisation legislation, the references to the Union harmonisation legislation currently listed in Section A of Annex I to Regulation (EU) 2024/1689 should therefore be moved to Section B of that Annex. This approach clarifies that artificial intelligence systems integrated into products covered by those sectoral acts are subject to the requirements of this Regulation where relevant, while allowing the conformity assessment procedures and product safety requirements under the respective sectoral legislation to remain the primary framework. Any remaining gaps relating to artificial intelligence systems integrated into such products should be addressed within the relevant sectoral legislation.

Recital 23 b (new): (23b) In order to safeguard the horizontal nature of this Regulation and ensure the proper functioning of the internal market, the relevant requirements laid down in Chapter III, Section 2 of this Regulation should be deemed to constitute essential health and safety requirements for high-risk AI systems covered by Union harmonisation legislation listed in Annex I and should be applied in a consistent and coherent manner across those sectoral frameworks. For this purpose, the Commission should be entitled to adopt delegated acts taking into account the requirements set out in Chapter III, Section 2 of this Regulation as regards their application to AI systems falling within its scope as well as relevant harmonised standards. In doing so, the Commission should not go beyond the requirements laid down in Regulation (EU) 2024/1689 for this purpose and should take into account the specific context of sectorial legislation. Before adopting the acts referred to in the first subparagraph, the Commission should conduct open and transparent consultations with relevant stakeholders, including competent authorities, notified bodies, civil society and industry.

Recital 25 a (new): (25a) When implementing and enforcing this Regulation, national competent authorities, the AI office and the Commission should take into account the objectives set out in Article 1(1) of Regulation (EU) 2024/1689 and follow the principles of necessity, proportionality, legal certainty and technological neutrality, while at the same time ensuring that unnecessary administrative and compliance burdens are minimised.

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 2, Article 2 – paragraph 2: 2. For AI systems classified as high-risk AI systems in accordance with Article 6(1) related to products covered by the Union harmonisation legislation listed in Annex I, only Article 6(1), Article 60a, Articles 102 to 109, Articles 110a-110l and Articles 111 and 112 shall apply. Article 57 shall apply only in so far as the requirements for high-risk AI systems under this Regulation have been integrated in that Union harmonisation legislation.;

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 4, Article 4 – paragraph 1: 1. ‘Providers and deployers of AI systems shall take measures to support the improvement of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not cover any guarantee of a specific level of AI literacy of any individual.;

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 4, Article 4 – paragraph 1a (new): (1a) The Commission shall issue guidance on the practical implementation of the obligation on providers and deployers of AI systems under paragraph 1.

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 4, Article 4 – paragraph 1b (new): (1b) The Commission and the Member States shall encourage and support AI literacy in society and among the general population and support, facilitate and complement the efforts of providers and deployers of AI systems, in particular SMEs, for example via the creation of Public Private Partnerships in fulfilling their obligation under paragraph 1.;

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 5, Article 4 a (new) – paragraph 1: 1. To the extent strictly necessary to ensure bias detection and correction in relation to high-risk AI systems in accordance with Article 10 (2), points (f) and (g), of this Regulation, providers of such systems may exceptionally process special categories of personal data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. In addition to the safeguards set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable, all the following conditions shall be met in order for such processing to occur:

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 5, Article 4 a (new) – paragraph 2: 2. Providers and deployers of other AI systems and models and deployers of high-risk AI systems may exceptionally process special categories of personal data to the extent that: / (a) processing is necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations; and / (b) all of the conditions and safeguards set out in paragraph 1 are applied. / This paragraph does not create any obligation to conduct such bias detection and correction.’

Regulation (EU) 2024/1689

Article 1 – paragraph 1 – point 5 a (new), Article 5 – paragraph 1 – subparagraph 1 – point ha (new): (5a) in Article 5, paragraph 1, subparagraph 1 the following point is added: / (ha) the placing on the market, the putting into service or the use of an AI system that alters, manipulates or artificially generates realistic images or videos so as to depict sexually explicit activities or the intimate parts of an identifiable natural person, without that person’s consent. / This prohibition does not apply to providers or deployers of AI systems who have put in place effective safety measures to prevent the generation of such depictions and to avoid misuse continuously, after the system has been placed, on the market or put into service despite the intention of the provider or deployer. / This prohibition shall not prevent AI providers from developing any capabilities referred to in the first subparagraph.

Regulation (EU) 2024/1689

Change 3

Changed:Article 1 – paragraph 1 – point 5 b (new), Article 6 – paragraph 1: (5b) Article 6(1) is amended as follows: / "1. Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: / (a) the AI system is intended to be used as a safety component of a product and whose functioning is necessary to ensure that the product or AI system complies with applicable Union safety requirements, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I; / "(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I."