Source: OJ L, 2024/1689, 12.7.2024

Current language: EN

Article 71 EU database for high-risk AI systems listed in Annex III


Summary What does Article 71 of the AI act regulation say?

This article establishes the EU database for AI systems, a central transparency tool that directly supports the registration obligations set out in Article 49.

The Commission, working with Member States, is responsible for setting up and maintaining this database, which holds information on registered high-risk AI systems as well as systems that have been self-assessed as non-high-risk by their providers.

The article divides responsibility for data entry between providers and public authority deployers, sets out the rules on public accessibility, and designates the Commission as the database controller.

Important points:

  • The Commission is required to set up and maintain the EU database, acting as its controller and providing technical and administrative support to providers and deployers.
  • Providers (or their authorised representatives) are responsible for entering their system registration data into the database, while public authority deployers must enter their own usage data separately.
  • Most information registered under Article 49 must be publicly accessible in a user-friendly and machine-readable format, though information registered in connection with real-world testing under Article 60 is restricted to market surveillance authorities and the Commission unless the provider consents to public disclosure.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The Commission shall, in collaboration with the Member States, set up and maintain an EU database containing information referred to in paragraphs 2 and 3 of this Article concerning high-risk AI systems referred to in Article 6(2) which are registered in accordance with Articles 49 and 60 and AI systems that are not considered as high-risk pursuant to Article 6(3) and which are registered in accordance with Article 6(4) and Article 49. When setting the functional specifications of such database, the Commission shall consult the relevant experts, and when updating the functional specifications of such database, the Commission shall consult the Board.

    1. The data listed in Sections A and B of Annex VIII shall be entered into the EU database by the provider or, where applicable, by the authorised representative.

    1. The data listed in Section C of Annex VIII shall be entered into the EU database by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4).

    1. With the exception of the section referred to in Article 49(4) and Article 60(4), point (c), the information contained in the EU database registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner. The information should be easily navigable and machine-readable. The information registered in accordance with Article 60 shall be accessible only to market surveillance authorities and the Commission, unless the prospective provider or provider has given consent for also making the information accessible the public.

    1. The EU database shall contain personal data only in so far as necessary for collecting and processing information in accordance with this Regulation. That information shall include the names and contact details of natural persons who are responsible for registering the system and have the legal authority to represent the provider or the deployer, as applicable.

    1. The Commission shall be the controller of the EU database. It shall make available to providers, prospective providers and deployers adequate technical and administrative support. The EU database shall comply with the applicable accessibility requirements.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod