Source: OJ L, 2024/1689, 12.7.2024

Current language: EN

Article 42 Presumption of conformity with certain requirements


Summary What does Article 42 of the AI act regulation say?

This brief article establishes two specific presumptions of compliance for high-risk AI systems, acting as a practical shortcut within the broader conformity framework.

It builds directly on the data quality requirements of Article 10 and the cybersecurity requirements of Article 15, by specifying the conditions under which a system is automatically presumed to satisfy those requirements without further proof.

Important points:

  • Train and test your high-risk AI system on data that reflects the specific geographical, behavioural, contextual, or functional setting of its intended use to benefit from a presumption of compliance with Article 10(4).
  • High-risk AI systems holding a valid cybersecurity certificate or statement of conformity under Regulation (EU) 2019/881, published in the Official Journal of the European Union, are presumed to meet the cybersecurity requirements of Article 15.
  • Both presumptions are conditional and only apply to the extent that the relevant certification or data testing actually covers the specific requirements in question.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).

    1. High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod