Skip to content

AIS-102

Substation load-shedding advisor

High risk (Annex III)Provider19/61 obligations

Already applicable: art.4 AI literacy. Compliance is owed from placement, not from a future date. The art.6(2) high-risk requirements apply from 2 December 2027. The registration (art.49(2)) and the documentation of the non-classification assessment (art.6(4)) are due BEFORE the system is placed on the market or put into service — an event-anchored duty with no calendar date.

⚠ Problems to check before validating (0)

None. The register raises no warning on this row — which is not the same as a validated row: a human still signs it off.

How this was decided

  1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
  2. DINo — materially influences a decision — The system materially influences the outcome of a decision, so it cannot be said to pose no significant risk.[DH]From your answers to: Q7.2 — Could the tool MATERIALLY influence the outcome of a decision, in a way liable to harm a person?
  3. FHigh risk (Annex III) — Falls within an Annex III area and the art.6(3) exemption is unavailable: high-risk under art.6(2).[HR]From your answers to: Q6.4 — Within the selected context or contexts, what is the system intended to do?

Obligations that apply (19 of 61; 42 ruled out)

The system is high-risk and you are its provider. Chapter III, Section 2 applies in full — these are the duties that must be discharged BEFORE the system is placed on the market or put into service, not afterwards.

  • art.9Risk management system (art.9)
  • art.10Data and data governance (art.10)
  • art.11 / Annex IVTechnical documentation (art.11 / Annex IV)
  • art.12Record-keeping / logs (art.12)
  • art.13Instructions & transparency for the deployer (art.13)
  • art.14Human oversight (art.14)
  • art.15Accuracy, robustness, cybersecurity (art.15)
  • art.16(b)Name, registered trade name and contact address on the system or packaging (art.16(b))
  • art.16(l)Accessibility requirements — Directives (EU) 2016/2102 and (EU) 2019/882 (art.16(l))
  • art.17Quality management system (art.17)
  • art.18Retain technical documentation, QMS records and declarations for 10 years (art.18)
  • art.19Retain automatically generated logs for at least 6 months (art.19)
  • art.20Corrective actions and duty to inform the chain and authorities (art.20)
  • art.16(k), art.21Cooperate with authorities and demonstrate conformity on reasoned request (art.16(k), art.21)
  • art.43/47/48Conformity assessment + CE + EU declaration (art.43/47/48)
  • art.72Post-market monitoring (art.72)
  • art.73Reporting of serious incidents (art.73)

Critical-infrastructure systems register in the secure national section rather than the public EU database (art.49(1), second subparagraph). Same duty, different register — filing in the public one would not discharge it. The same TIMING CAVEAT applies as to the EU-database registration above: the trigger is placing on the market, the calendar date is under legal review, and the 2 December 2027 substantive milestone is not relief from it.

  • art.49(5)Registration at NATIONAL level — Annex III point 2 (art.49(5))

art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

  • art.4AI literacy (art.4)

Compliance dates

  • The art.6(2) high-risk requirements apply from 2 December 2027.
  • No art.50 transparency duties apply to this system.
  • No GPAI model obligations apply to this system.

Answers behind it

Q1 · What does THE COMPANY do with this tool?
THE COMPANY sells or licenses an AI system or component to a Client or partner, under THE COMPANY's name
Q2 · At go-live, whose name or trademark is on it?
—
[B] High-risk area — Annex III
Critical infrastructure
Personal data present? (GDPR art.4)
No

One worked example under the register v11 rules. Fictional data; no account, nothing stored.