Source: OJ L, 2024/1689, 12.7.2024Consolidated text

Current language: DE

Artikel 63 Ausnahmen für bestimmte Akteure


Summary What does Article 63 of the AI act regulation say?

This article carves out a limited concession for SMEs, including start-ups, by allowing them to meet certain quality management system obligations from Article 17 in a simplified manner.

Importantly, the article is careful to contain its own scope: the simplification is narrow and does not amount to a general exemption.

The Commission is tasked with developing guidelines to define what "simplified" looks like in practice, while ensuring the overall level of protection for high-risk AI systems remains intact.

Important points:

  • If you are an SME or start-up without partner or linked enterprises, you may comply with certain Article 17 quality management system requirements in a simplified manner.
  • The Commission is required to develop guidelines specifying which elements of the quality management system can be simplified for SMEs.
  • This simplification does not exempt SMEs from any other obligations under the regulation, including those on risk management, data governance, transparency, human oversight, and incident reporting.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

  1. ▼M1
    1. KMU, einschließlich Start-up-Unternehmen können bestimmte Elemente des in Artikel 17 vorgeschriebenen Qualitätsmanagementsystems in vereinfachter Weise einhalten, sofern sie keine Partnerunternehmen oder verbundenen Unternehmen im Sinne der Empfehlung 2003/361/EG haben. Zu diesem Zweck arbeitet die Kommission Leitlinien zu den Elementen des Qualitätsmanagementsystems aus, die unter Berücksichtigung der Bedürfnisse von KMU in vereinfachter Weise eingehalten werden können, ohne das Schutzniveau oder die Notwendigkeit zur Einhaltung der Anforderungen in Bezug auf Hochrisiko-KI-Systeme zu beeinträchtigen.

    1. Absatz 1 dieses Artikels ist nicht dahin gehend auszulegen, dass diese Akteure auch von anderen in dieser Verordnung festgelegten Anforderungen oder Pflichten, einschließlich der nach den Artikeln 9, 10, 11, 12, 13, 14, 15, 72 und 73 geltenden, befreit sind.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod