# AI Registration — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-system-registration-requirements
> Sources are cited per item. Verify against the official texts before relying on them.

The AI Act includes specific registration requirements for high-risk AI systems and their providers. This topic is not adequately covered by existing topics and requires dedicated coverage of registration procedures, databases, timelines, and obligations specific to AI systems under the AI Act.

## Overview

## Legal Framework
Article 49 of the AI Act establishes the mandatory registration requirement for providers of high-risk AI systems. Specifically, providers must enter information into the EU database for high-risk AI systems before placing such systems on the market or putting them into service. This obligation applies to high-risk AI systems not covered by existing Union harmonisation legislation (e.g., machinery, medical devices) and to providers who consider a system listed in Annex III to present a high risk.

## Practical Application
The registration obligation, detailed in Recitals 66 and 131, serves a dual purpose of facilitating market surveillance for authorities and enhancing public transparency. The primary legal text indicates that registration is a prerequisite for market entry, creating a clear compliance checkpoint. While the provided T&C commentary pertains to data protection law, its underlying principle—that specific procedural obligations are mandatory and cannot be circumvented by general provisions—is instructive. In the context of AI registration, this underscores that the requirement is not discretionary. The database entry must contain accurate information as specified by the AI Act and implementing acts, including details on the provider and the high-risk AI system itself. Failure to register properly could prevent lawful market placement and constitute a breach of the regulation.

## Key Considerations
*   **Timing is Critical:** Registration in the EU database is a pre-market requirement. Providers cannot legally place a high-risk AI system on the EU market or put it into service until the registration is complete.
*   **Scope Verification:** Providers must carefully assess whether their AI system is classified as high-risk under Annex I or Annex III of the AI Act, as this triggers the registration duty. Systems already falling under other harmonised product legislation follow different conformity assessment procedures.
*   **Accuracy of Submission:** The information submitted to the database must be complete, truthful, and kept up-to-date, as it forms a key tool for post-market monitoring and enforcement by national authorities.

## Legislation (full text of key provisions)

### EU database for high-risk AI systems listed in Annex III

*Source: AI Act, aiact-art-71-en, 2024-06-12 — https://overview.legal/posts/93161*

### Recital 131 — EU database for high-risk AI registration

*Source: AI Act, aiact-rec-131-en, 2024-06-12 — https://overview.legal/posts/93944*

In order to facilitate the work of the Commission and the Member States in the AI field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, as well as providers who consider that an AI system listed in the high-risk use cases in an annex to this Regulation is not high-risk on the basis of a derogation, should be required to register themselves and information about their AI system in an EU database, to be established and managed by the Commission. Before using an AI system listed in the high-risk use cases in an annex to this Regulation, deployers of high-risk AI systems that are public authorities, agencies or bodies, should register themselves in such database and select the system that they envisage to use. Other deployers should be entitled to do so voluntarily. This section of the EU database should be publicly accessible, free of charge, the information should be easily navigable, understandable and machine-readable. The EU database should also be user-friendly, for example by providing search functionalities, including through keywords, allowing the general public to find relevant information to be submitted upon the registration of high-risk AI systems and on the use case of high-risk AI systems, set out in an annex to this Regulation, to which the high-risk AI systems correspond. Any substantial modification of high-risk AI systems should also be registered in the EU database. For high-risk AI systems in the area of law enforcement, migration, asylum and border control management, the registration obligations should be fulfilled in a secure non-public section of the EU database. Access to the secure non-public section should be strictly limited to the Commission as well as to market surveillance authorities with regard to their national section of that database. High-risk AI systems in the area of critical infrastructure should only be registered at national level. The Commission should be the controller of the EU database, in accordance with Regulation (EU) 2018/1725. In order to ensure the full functionality of the EU database, when deployed, the procedure for setting the database should include the development of functional specifications by the Commission and an independent audit report. The Commission should take into account cybersecurity risks when carrying out its tasks as data controller on the EU database. In order to maximise the availability and use of the EU database by the public, the EU database, including the information made available through it, should comply with requirements under the Directive (EU) 2019/882.

## Recent developments

### Europol told to hand over personal data to Dutch activist

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/6280 — original: https://www.fairtrials.org/articles/news/fair-trials-welcomes-a-decision-by-the-european-data-protection-supervisor-edps-ordering-europol-to-hand-over-personal-data-to-dutch-activist-frank-van-der-linde/#entry-356*

The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Record-Keeping** — https://overview.legal/topics/record-keeping-ai
  The AI Act imposes specific record-keeping obligations for AI systems that are distinct from general GDPR record-keeping. A dedicated topic would capture AI-spe
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Annex III Amendments** — https://overview.legal/topics/annex-iii-amendments
  This new topic is needed because amendments to Annex III represent specific regulatory changes to the AI Act's classification framework that warrant dedicated t
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data

---
Generated by overview.legal · https://overview.legal/topics/ai-system-registration-requirements · 2026-08-22
