Source: OJ L, 2024/1689, 12.7.2024Consolidated text

Current language: SV

Artikel 42 Presumtion om överensstämmelse med vissa krav


Summary What does Article 42 of the AI act regulation say?

This article establishes presumptions of conformity for high-risk AI systems in two specific areas: data requirements and cybersecurity.

Rather than requiring providers to demonstrate compliance from scratch, it creates shortcuts whereby meeting certain existing standards or conditions automatically satisfies corresponding requirements under this Regulation.

It connects directly to the data governance requirements of Article 10 and the cybersecurity requirements of Article 15, functioning as a compliance relief mechanism for providers who have already met recognised external benchmarks.

Important points:

  • If you have trained and tested your high-risk AI system on data reflecting the specific geographical, behavioural, contextual, or functional setting of its intended use, you are presumed to comply with the data requirements of Article 10(4).
  • If your high-risk AI system holds a cybersecurity certificate or statement of conformity under Regulation (EU) 2019/881 (the EU Cybersecurity Act), referenced in the Official Journal, you are presumed to meet the cybersecurity requirements of Article 15.
  • A separate deemed compliance pathway for cybersecurity also exists for high-risk AI systems falling within the scope of Regulation (EU) 2024/2847, provided the conditions of that Regulation's Article 12(1) are fulfilled.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. AI-system med hög risk som har tränats och testats på data som återspeglar den specifika geografiska, beteendemässiga, kontextuella eller funktionella miljö inom vilken de är avsedda att användas ska förutsättas uppfylla de relevanta kraven i artikel 10.4.

    1. AI-system med hög risk som har certifierats, eller för vilka en försäkran om överensstämmelse har utfärdats inom ramen för en ordning för cybersäkerhetscertifiering enligt förordning (EU) 2019/881, och till vilka hänvisningar har offentliggjorts i Europeiska unionens officiella tidning, ska förutsättas uppfylla de cybersäkerhetskrav som anges i artikel 15 i den här förordningen, förutsatt att cybersäkerhetscertifikatet eller försäkran om överensstämmelse eller delar därav omfattar dessa krav.

  1. ▼M1
    1. Om AI-system med hög risk omfattas av förordning (EU) 2024/2847 och villkoren i artikel 12.1 i den förordningen är uppfyllda ska sådana system anses uppfylla de cybersäkerhetskrav som anges i artikel 15 i den här förordningen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod