Changes between two versions
What changed between the plenary report and the adopted text
From · plenary report· 22 May 2023
on the proposal for a regulation of the European Parliament and of the Council on laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts
+5 added · −28 removed · 105 changed paragraphs, packaging included.
Part 5 of 15: Paragraphs 241–300
60 unchanged paragraphs
Article 5 – paragraph 1 – point d – point i: deleted
Article 5 – paragraph 1 – point d – point ii: deleted
Article 5 – paragraph 1 – point d – point iii: deleted / (deleted)
Article 5 – paragraph 1 – point d a (new): (d a) the placing on the market, putting into service or use of an AI system for making risk assessments of natural persons or groups thereof in order to assess the risk of a natural person for offending or reoffending or for predicting the occurrence or reoccurrence of an actual or potential criminal or administrative offence based on profiling of a natural person or on assessing personality traits and characteristics, including the person’s location, or past criminal behaviour of natural persons or groups of natural persons;
Article 5 – paragraph 1 – point d b (new): (d b) The placing on the market, putting into service or use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;
Article 5 – paragraph 1 – point d c (new): dc) the placing on the market, putting into service or use of AI systems to infer emotions of a natural person in the areas of law enforcement, border management, in workplace and education institutions.
Article 5 – paragraph 1 – point d d (new): (d d) the putting into service or use of AI systems for the analysis of recorded footage of publicly accessible spaces through ‘post’ remote biometric identification systems, unless they are subject to a pre-judicial authorisation in accordance with Union law and strictly necessary for the targeted search connected to a specific serious criminal offense as defined in Article 83(1) of TFEU that already took place for the purpose of law enforcement.
Article 5 – paragraph 1 a (new): 1 a. This Article shall not affect the prohibitions that apply where an artificial intelligence practice infringes another Union law, including Union law on data protection, non discrimination, consumer protection or competition;
Article 5 – paragraph 2: deleted / (deleted) / (deleted) / (deleted)
Article 5 – paragraph 3: deleted / (deleted)
Article 5 – paragraph 4: deleted
Article 6 – paragraph 1 – point a: (a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation law listed in Annex II;
Article 6 – paragraph 1 – point b: (b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment related to risks for health and safety, with a view to the placing on the market or putting into service of that product pursuant to the Union harmonisation law listed in Annex II;
Article 6 – paragraph 2: 2. In addition to the high-risk AI systems referred to in paragraph 1, AI systems falling under one or more of the critical areas and use cases referred to in Annex III shall be considered high-risk if they pose a significant risk of harm to the health, safety or fundamental rights of natural persons. Where an AI system falls under Annex III point 2, it shall be considered to be high-risk if it poses a significant risk of harm to the environment. / The Commission shall, six months prior to the entry into force of this Regulation, after consulting the AI Office and relevant stakeholders, provide guidelines clearly specifying the circumstances where the output of AI systems referred to in Annex III would pose a significant risk of harm to the health, safety or fundamental rights of natural persons or cases in which it would not.
Article 6 – paragraph 2 a (new): 2 a. Where providers falling under one or more of the critical areas and use cases referred to in Annex III consider that their AI system does not pose a significant risk as described in paragraph 2, they shall submit a reasoned notification to the national supervisory authority that they are not subject to the requirements of Title III Chapter 2 of this Regulation. Where the AI system is intended to be used in two or more Member States, that notification shall be addressed to the AI Office. Without prejudice to Article 65, the national supervisory authority shall review and reply to the notification, directly or via the AI Office, within three months if they deem the AI system to be misclassified.
Article 6 – paragraph 2 a (new): 2 b. Providers that misclassify their AI system as not subject to the requirements of Title III Chapter 2 of this Regulation and place it on the market before the deadline for objection by national supervisory authorities shall be subject to fines pursuant to Article 71.
Article 6 – paragraph 2 b (new): 2 c. National supervisory authorities shall submit a yearly report to the AI Office detailing the number of notifications received, the related high-risk areas at stake and the decisions taken concerning received notifications
Article 7 – paragraph 1 – introductory part: 1. The Commission is empowered to adopt delegated acts in accordance with Article 73 to amend Annex III by adding or modifying areas or use-cases of high-risk AI systems where these pose a significant risk of harm to health and safety, or an adverse impact on fundamental rights, to the environment, or to democracy and the rule of law, and that risk is, in respect of its severity and probability of occurrence, equivalent to or greater than the risk of harm or of adverse impact posed by the high-risk AI systems already referred to in Annex III.
Article 7 – paragraph 1 – point a: deleted
Article 7 – paragraph 1 – point b: deleted
Article 7 – paragraph 1 a (new): 1 a. The Commission is also empowered to adopt delegated acts in accordance with Article 73 to remove use-cases of high-risk AI systems from the list in Annex III if the conditions referred to in paragraph 1 no longer apply;
Article 7 – paragraph 2 – introductory part: 2. When assessing an AI system for the purposes of paragraph 1 and 1a the Commission shall take into account the following criteria:
Article 7 – paragraph 2 – point a a (new): (a a) the general capabilities and functionalities of the AI system independent of its intended purpose;
Article 7 – paragraph 2 – point b a (new): (b a) the nature and amount of the data processed and used by the AI system;
Article 7 – paragraph 2 – point b b (new): (b b) the extent to which the AI system acts autonomously;
Article 7 – paragraph 2 – point c: (c) the extent to which the use of an AI system has already caused harm to health and safety, has had an adverse impact on fundamental rights, the environment, democracy and the rule of law or has given rise to significant concerns in relation to the likelihood of such harm or adverse impact, as demonstrated for example by reports or documented allegations submitted to national supervisory authorities, to the Commission, to the AI Office, to the EDPS, or to the European Union Agency for Fundamental Rights;
Article 7 – paragraph 2 – point d: (d) the potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect a plurality of persons or to disproportionately affect a particular group of persons;
Article 7 – paragraph 2 – point e: (e) the extent to which potentially harmed or adversely impacted persons are dependent on the output produced involving an AI system, and that output is purely accessory in respect of the relevant action or decision to be taken, in particular because for practical or legal reasons it is not reasonably possible to opt-out from that output;
Article 7 – paragraph 2 – point e a (new): (e a) the potential misuse and malicious use of the AI system and of the technology underpinning it;
Article 7 – paragraph 2 – point f: (f) the extent to which there is an imbalance of power, or the potentially harmed or adversely impacted persons are in a vulnerable position in relation to the user of an AI system, in particular due to status, authority, knowledge, economic or social circumstances, or age;
Article 7 – paragraph 2 – point g: (g) the extent to which the outcome produced involving an AI system is easily reversible or remedied, whereby outcomes having an adverse impact on health, safety, fundamental rights of persons, the environment, or on democracy and rule of law shall not be considered as easily reversible;
Article 7 – paragraph 2 – point g a (new): (g a) the extent of the availability and use of effective technical solutions and mechanisms for the control, reliability and corrigibility of the AI system;
Article 7 – paragraph 2 – point g b (new): (g b) the magnitude and likelihood of benefit of the deployment of the AI system for individuals, groups, or society at large, including possible improvements in product safety;
Article 7 – paragraph 2 – point g c (new): (g c) the extent of human oversight and the possibility for a human to intercede in order to override a decision or recommendations that may lead to potential harm;
Article 7 – paragraph 2 – point h –: (h) the extent to which existing Union law provides for: / (i) effective measures of redress in relation to the damage caused by an AI system, with the exclusion of claims for direct or indirect damages; / (ii) effective measures to prevent or substantially minimise those risks.
Article 7 – paragraph 2 a (new): 2 a. When assessing an AI system for the purposes of paragraphs 1 or 1a the Commission shall consult the AI Office and, where relevant, representatives of groups on which an AI system has an impact, industry, independent experts, the social partners, and civil society organisations. The Commission shall also organise public consultations in this regard and shall make the results of those consultations and of the final assessment publicly available;
Article 7 – paragraph 2 b (new): 2 b. The AI Office, national supervisory authorities or the European Parliament may request the Commission to reassess and recategorise the risk categorisation of an AI systemin accordance with paragraphs 1 and 1a. The Commission shall give reasons for its decision and make them public.
Article 8 – paragraph 1 a (new): 1 a. In complying with the requirement established in this Chapter, due account shall be taken of guidelines developed as referred to in Article 82b, the generally acknowledged state of the art, including as reflected in the relevant harmonised standards and common specifications as referred to in articles 40 and 41 or those already set out in Union harmonisation law;.
Article 8 – paragraph 2: 2. The intended purpose of the high-risk AI system, the reasonably foreseeable misuses and the risk management system referred to in Article 9 shall be taken into account when ensuring compliance with those requirements.
Article 8 – paragraph 2 a (new): 2 a. As long as the requirements of Title III, Chapters 2 and 3 or Title VIII, Chapters 1, 2 and 3 for high-risk AI systems are addressed by Union harmonisation law listed in Annex II, Section A, the requirements or obligations of those Chapters of this Regulation shall be deemed to be fulfilled, as long as they include the AI component. Requirements of Chapters 2 and 3 of Title III or Title VIII, Chapters 1, 2 and 3 for high-risk AI systems not addressed by Union harmonisation law listed in Annex II Section A, shall be incorporated into that Union harmonisation law, where applicable. The relevant conformity assessment shall be carried out as part of the procedures laid out under Union harmonisation law listed in Annex II, Section A.
Article 9 – paragraph 1: 1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems, throughout the entire lifecycle of the AI system. The risk management system can be integrated into, or a part of, already existing risk management procedures relating to the relevant Union sectoral law insofar as it fulfils the requirements of this article.
Article 9 – paragraph 2 – introductory part: 2. The risk management system shall consist of a continuous iterative process run throughout the entire lifecycle of a high-risk AI system, requiring regular review and updating of the risk management process, to ensure its continuing effectiveness, and documentation of any significant decisions and actions taken subject to this Article. It shall comprise the following steps:
Article 9 – paragraph 2 – point a: (a) identification, estimation and evaluation of the known and the reasonably foreseeable risks that the high-risk AI system can pose to the health or safety of natural persons, their fundamental rights including equal access and opportunities, democracy and rule of law or the environement when the high-risk AI system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse;
Article 9 – paragraph 2 – point b: deleted
Article 9 – paragraph 2 – point c: (c) evaluation of emerging significant risks as described in point (a) and identified based on the analysis of data gathered from the post-market monitoring system referred to in Article 61;
Article 9 – paragraph 2 – point d: (d) adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to points a and b of this paragraph in accordance with the provisions of the following paragraphs
Article 9 – paragraph 3: 3. The risk management measures referred to in paragraph 2, point (d) shall give due consideration to the effects and possible interactions resulting from the combined application of the requirements set out in this Chapter 2, with a view to mitigate risks effectively while ensuring an appropriate and proportionate implementation of the requirements.
Article 9 – paragraph 4 – introductory part: 4. The risk management measures referred to in paragraph 2, point (d) shall be such that relevant residual risk associated with each hazard as well as the overall residual risk of the high-risk AI systems is reasonably judged to be acceptable, provided that the high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse. Those residual risks and the reasoned judgements made shall be communicated to the deployer. / In identifying the most appropriate risk management measures, the following shall be ensured:
Article 9 – paragraph 4 – subparagraph 1 – point a: (a) elimination or reduction of identified risks as far as technically feasible through adequate design and development of the high-risk AI system, involving when relevant, experts and external stakeholders;
Article 9 – paragraph 4 – subparagraph 1 – point b: (b) where appropriate, implementation of adequate mitigation and control measures addressing significant risks that cannot be eliminated;
Article 9 – paragraph 4 – subparagraph 1 – point c: (c) provision of the required information pursuant to Article 13, and, where appropriate, training to deployers.
Article 9 – paragraph 4 – subparagraph 2: In eliminating or reducing risks related to the use of the high-risk AI system, providers shall take into due consideration the technical knowledge, experience, education and training the deployer may need, including in relation to the presumable context of use.
Article 9 – paragraph 5: 5. High-risk AI systems shall be tested for the purposes of identifying the most appropriate and targeted risk management measures and weighing any such measures against the potential benefits and intended goals of the system. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and they are in compliance with the requirements set out in this Chapter.
Article 9 – paragraph 6: 6. Testing procedures shall be suitable to achieve the intended purpose of the AI system.
Article 9 – paragraph 7: 7. The testing of the high-risk AI systems shall be performed, prior to the placing on the market or the putting into service. Testing shall be made against prior defined metrics, and probabilistic thresholds that are appropriate to the intended purpose or reasonably foreseeable misuse of the high-risk AI system.
Article 9 – paragraph 8: 8. When implementing the risk management system described in paragraphs 1 to 7, providers shall give specific consideration to whether the high-risk AI system is likely to adversely impact vulnerable groups of people or children.
Article 9 – paragraph 9: 9. For providers and AI systems already covered by Union law that require them to establish a specific risk management, including credit institutions regulated by Directive 2013/36/EU, the aspects described in paragraphs 1 to 8 shall be part of or combined with the risk management procedures established by that Union law.
Article 10 – paragraph 1: 1. High-risk AI systems which make use of techniques involving the training of models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 as far as this is technically feasible according to the specific market segment or scope of application. / Techniques that do not require labelled input data such as unsupervised learning and reinforcement learning shall be developed on the basis of data sets such as for testing and verification that meet the quality criteria referred to in paragraphs 2 to 5.
Article 10 – paragraph 2 – introductory part: 2. Training, validation and testing data sets shall be subject to data governance appropriate for the context of use as well as the intended purpose of the AI system. Those measures shall concern in particular,
Article 10 – paragraph 2 – point a a (new): (a a) transparency as regards the original purpose of data collection;