Skip to content

AIS-103

Safety-training marking cross-check

Not high-risk (Annex III exemption)Deployer6/61 obligations

Already applicable: art.4 AI literacy. Compliance is owed from placement, not from a future date. No further dated milestone.

⚠ Problems to check before validating (0)

None. The register raises no warning on this row — which is not the same as a validated row: a human still signs it off.

How this was decided

  1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
  2. DIYes — One of the art.6(3) conditions is met and neither disqualifier applies, so the system is not high-risk despite falling in an Annex III area. The reasoning must be documented and the system still registered.[DJ]From your answers to: Q7.3 — Is the tool limited to AT LEAST ONE of the following?
  3. FNot high-risk (Annex III exemption) — Falls in an Annex III area but meets an art.6(3) condition without profiling or materially influencing a decision. The system is NOT high-risk — but the assessment must be documented and the system still registered under art.49(2).[HR, DJ]From your answers to: Q6.4 — Within the selected context or contexts, what is the system intended to do? ; Q7.3 — Is the tool limited to AT LEAST ONE of the following?

Obligations that apply (6 of 61; 55 ruled out)

art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

  • art.4AI literacy (art.4)

Personal data is processed and the GDPR applies territorially. These duties are owed under the GDPR independently of anything the AI Act requires — a minimal-risk system can still carry all of them.

  • art.6 / art.9(2)Legal basis identified & documented (art.6 / art.9(2))
  • art.30Record of processing activities (art.30)
  • art.13-14Information to data subjects (art.13-14)
  • art.32Security of processing — technical and organisational measures (art.32)

A third party processes this personal data on your behalf. art.28 requires a written processor agreement containing the mandated terms — a supplier contract that is silent on them does not satisfy it.

  • art.28(3)Written processor agreement with each processor (art.28(3))

Compliance dates

  • Art.4 AI literacy have applied since 2 February 2025. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.
  • No art.50 transparency duties apply to this system.
  • No GPAI model obligations apply to this system.

Answers behind it

Q1 · What does THE COMPANY do with this tool?
THE COMPANY buys or subscribes to an external AI system, or a foundation model, for internal usage
Q2 · At go-live, whose name or trademark is on it?
—
[B] High-risk area — Annex III
Education & vocational training
Personal data present? (GDPR art.4)
Yes

One worked example under the register v11 rules. Fictional data; no account, nothing stored.