Source: OJ L, 2024/1689, 12.7.2024Consolidated text

Current language: EN

Article 42 Presumption of conformity with certain requirements


Summary What does Article 42 of the AI act regulation say?

This article establishes presumptions of conformity for high-risk AI systems in two specific areas: data requirements and cybersecurity.

Rather than requiring providers to demonstrate compliance from scratch, it creates shortcuts whereby meeting certain existing standards or conditions automatically satisfies corresponding requirements under this Regulation.

It connects directly to the data governance requirements of Article 10 and the cybersecurity requirements of Article 15, functioning as a compliance relief mechanism for providers who have already met recognised external benchmarks.

Important points:

  • If you have trained and tested your high-risk AI system on data reflecting the specific geographical, behavioural, contextual, or functional setting of its intended use, you are presumed to comply with the data requirements of Article 10(4).
  • If your high-risk AI system holds a cybersecurity certificate or statement of conformity under Regulation (EU) 2019/881 (the EU Cybersecurity Act), referenced in the Official Journal, you are presumed to meet the cybersecurity requirements of Article 15.
  • A separate deemed compliance pathway for cybersecurity also exists for high-risk AI systems falling within the scope of Regulation (EU) 2024/2847, provided the conditions of that Regulation's Article 12(1) are fulfilled.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).

    1. High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.

  1. ▼M1
    1. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod