High-risk provider requirements, Art. 8 to 49
The provider's stack for a high-risk system in the order the Act sets it: the seven requirements of Section 2, the Art. 16–22 provider duties, then conformity assessment, the declaration, CE marking and registration — and how Veritome's six phases carry them.
A provider of a high-risk AI system owes two things: the system must meet the requirements of Chapter III Section 2 (Art. 8–15), and the provider must run the processes of Section 3 (Art. 16–22) that prove it does and keep it that way. Then come the pre-market steps. For Annex III systems all of this applies from 2 December 2027.
The seven requirements (Art. 8–15)
Art. 8 says the system shall comply with the following, taking its intended purpose and the state of the art into account:
| Article | Requirement | The record Veritome produces |
|---|---|---|
| Art. 9 | A risk-management system — continuous and iterative across the lifecycle: identify, estimate, evaluate and treat the reasonably foreseeable risks, test against them, consider vulnerable groups. | The risk register and its review schedule. |
| Art. 10 | Data and data governance — training, validation and testing data meet quality criteria; design choices, provenance, bias examination and mitigation are documented. Special-category data may be processed for bias detection only under the conditions of Art. 4a, the provision the Digital Omnibus moved out of Art. 10(5). | The data-governance datasheet. |
| Art. 11 | Technical documentation per Annex IV, drawn up before market placement and kept up to date. | The Annex IV technical file. |
| Art. 12 | Record-keeping — the system technically allows automatic logging of events over its lifetime. | The logging record. |
| Art. 13 | Transparency and instructions for use — deployers get instructions covering identity, characteristics, limitations, oversight measures and expected lifetime (Art. 13(3)). | The instructions-for-use package. |
| Art. 14 | Human oversight — designed so natural persons can understand, monitor, override and stop it. | The human-oversight assignment. |
| Art. 15 | Accuracy, robustness and cybersecurity — appropriate levels, declared metrics, resilience to errors and to attacks such as data poisoning and adversarial inputs. | The accuracy, robustness and cybersecurity record. |
The provider's processes (Art. 16–22)
- Art. 16 — the umbrella list: comply with Section 2, identify yourself on the system, run a QMS, keep the documentation and logs, carry out conformity assessment, draw up the declaration, affix the CE marking, register, take corrective action, cooperate, and meet the accessibility requirements of Directives (EU) 2016/2102 and 2019/882 (Art. 16(l)).
- Art. 17 — a quality management system, documented as policies, procedures and instructions covering the aspects in Art. 17(1)(a)–(m): regulatory strategy, design and development controls, data management, risk management, post-market monitoring, incident reporting, communication with authorities, record-keeping, resource management, accountability. Providers already running a QMS under sectoral Union law may fold these aspects into it (Art. 17(3)); financial institutions subject to Union internal-governance rules are deemed to meet most of it through those rules, except points (g), (h) and (i) (Art. 17(4)).
- Art. 18 — keep the technical documentation, the QMS documentation, notified-body decisions and the declaration at the authorities' disposal for 10 years after market placement.
- Art. 19 — keep the automatically generated logs under your control for a period appropriate to the intended purpose and at least six months.
- Art. 20 — corrective action, withdrawal, disabling or recall of a non-conforming system, and informing the chain and the authorities.
- Art. 21 — cooperate with competent authorities on reasoned request.
- Art. 22 — a non-EU provider appoints an authorised representative in the Union.
Pre-market: assessment, declaration, marking, registration
- Art. 43 — conformity assessment. For Annex III systems the route is the internal-control procedure of Annex VI, except certain biometric systems where Annex VII's notified-body procedure applies; a system already covered by Annex I product legislation follows that legislation's procedure. A substantial modification triggers a new assessment.
- Art. 47 + Annex V — the written EU declaration of conformity, kept for 10 years.
- Art. 48 — the CE marking, affixed visibly, legibly and indelibly (or digitally), with the notified body's identification number where one was involved.
- Art. 49 + Annex VIII — registration in the EU database before market placement or putting into service.
After market: monitoring and incidents
- Art. 72 — a documented post-market monitoring system and plan, part of the technical documentation.
- Art. 73 — serious incidents reported to the market-surveillance authority of the Member State where they occurred: within 15 days in general, 10 where a death may have been caused, 2 for a widespread infringement or a critical-infrastructure disruption.
In Veritome
The engine lays these out across the six phases — Classify (Art. 5, Art. 6) → Scope → Implement (Art. 8–15, Art. 17) → Assess (Art. 43, 47, 48) → Register (Art. 49) → Monitor (Art. 72–73) — and gate-locks each phase until the one before it is complete. Documents produces the Annex IV file, the Annex V declaration and the Annex VIII registration sheet from the same obligation data, so nothing is typed twice. Where the Act itself lets existing work count — Art. 8(2) for Annex I documentation, Art. 17(3) and (4) for the QMS — the obligation shows the route and lets you declare reliance without changing its status.