# Implementation Guidelines — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/commission-implementation-guidelines
> Sources are cited per item. Verify against the official texts before relying on them.

This content is specifically about Commission guidelines for implementing the AI Act. A dedicated topic would capture guidance documents, interpretive materials, and practical implementation support materials from the European Commission.

## Overview

## Legal Framework

The AI Act establishes a multi-layered implementation architecture through which the European Commission provides operational guidance to providers, deployers, and national authorities. Recital 49 frames the Commission's coordinating role particularly for high-risk AI systems that serve as safety components within regulated products — including those covered by sectoral instruments such as Regulations (EC) No 300/2008 (aviation security), (EU) No 167/2013 (agricultural vehicles), and (EU) No 168/2013 (two- or three-wheel vehicles). The recital clarifies that implementation guidance must bridge the AI Act's horizontal requirements with sector-specific conformity assessment regimes.

DSA Article 83 illustrates the procedural template the Commission follows when adopting implementing acts: practical arrangements for intervention procedures, hearings, and agreed disclosure of information are subject to a mandatory public consultation period of no less than one month before adoption. These acts proceed through the advisory procedure under Article 88, ensuring Member State involvement. While Article 83 sits within the DSA, it reflects the Commission's institutional practice for implementing acts across the digital regulation acquis — a practice the AI Act replicates for its own implementing measures.

## Key Developments

The Commission's approach to implementation guidance under adjacent digital regulation demonstrates a pattern of iterative, stakeholder-informed rulemaking. The Article 29 Working Party's transparency guidelines (WP260 rev.01) and the EDPB's consent guidelines (05/2020) show how interpretive materials evolve through revision cycles informed by practical experience and stakeholder feedback. The AI Act's implementation framework is expected to follow this trajectory, with the AI Office serving as the central hub for guidance development and dissemination.

The Amsterdam District Court's February 2026 ruling underscores how evidentiary standards in regulatory enforcement hinge on the precision of implementing rules — where technical specifications and practical arrangements are ambiguous, enforcement outcomes become unpredictable.

## Practical Guidance

- **Monitor the AI Office's guidance pipeline**: Track published guidance documents, FAQs, and interpretive communications, as these will define operational expectations for AI Act compliance well before enforcement begins.
- **Engage in public consultations**: When the Commission publishes draft implementing acts, submit comments within the prescribed period — participation shapes the final text and demonstrates good-faith compliance efforts.
- **Map sectoral overlaps early**: For high-risk AI systems embedded in regulated products, identify which sectoral conformity assessment regime applies alongside the AI Act, as Recital 49 signals the Commission will issue guidance on interaction between these frameworks.
- **Build compliance documentation around anticipated implementing acts**: Structure internal governance to accommodate the practical arrangements the Commission will specify, particularly for risk management, technical documentation, and post-market monitoring procedures.
- **Leverage advisory procedure transparency**: Implementing acts adopted under advisory procedures reflect Member State input — monitor national positions to anticipate which practical requirements will survive consultation.

## Legislation (full text of key provisions)

### Amendment to Regulation (EU) 2019/2144

*Source: AI Act, aiact-art-109-en, 2024-06-12 — https://overview.legal/posts/93627*

In Article 11 of Regulation (EU) 2019/2144, the following paragraph is added:‘3. When adopting the implementing acts pursuant to paragraph 2, concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive (EU) 2016/797

*Source: AI Act, aiact-art-106-en, 2024-06-12 — https://overview.legal/posts/93615*

In Article 5 of Directive (EU) 2016/797, the following paragraph is added:‘12. When adopting delegated acts pursuant to paragraph 1 and implementing acts pursuant to paragraph 11 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Recital 145 — implementation support facilities for AI regulation

*Source: AI Act, aiact-rec-145-en, 2024-06-12 — https://overview.legal/posts/93972*

In order to minimise the risks to implementation resulting from lack of knowledge and expertise in the market as well as to facilitate compliance of providers, in particular SMEs, including start-ups, and notified bodies with their obligations under this Regulation, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation facilities established by the Commission and the Member States at Union or national level should contribute to the implementation of this Regulation. Within their respective mission and fields of competence, the AI-on-demand platform, the European Digital Innovation Hubs and the testing and experimentation Facilities are able to provide in particular technical and scientific support to providers and notified bodies.

### Recital 49 — high-risk AI safety products sectoral regulations

*Source: AI Act, aiact-rec-49-en, 2024-06-12 — https://overview.legal/posts/93780*

As regards high-risk AI systems that are safety components of products or systems, or which are themselves products or systems falling within the scope of Regulation (EC) No 300/2008 of the European Parliament and of the Council (24), Regulation (EU) No 167/2013 of the European Parliament and of the Council (25), Regulation (EU) No 168/2013 of the European Parliament and of the Council (26), Directive 2014/90/EU of the European Parliament and of the Council (27), Directive (EU) 2016/797 of the European Parliament and of the Council (28), Regulation (EU) 2018/858 of the European Parliament and of the Council (29), Regulation (EU) 2018/1139 of the European Parliament and of the Council (30), and Regulation (EU) 2019/2144 of the European Parliament and of the Council (31), it is appropriate to amend those acts to ensure that the Commission takes into account, on the basis of the technical and regulatory specificities of each sector, and without interfering with existing governance, conformity assessment and enforcement mechanisms and authorities established therein, the mandatory requirements for high-risk AI systems laid down in this Regulation when adopting any relevant delegated or implementing acts on the basis of those acts.

### Recital 117 — general-purpose AI model compliance codes

*Source: AI Act, aiact-rec-117-en, 2024-06-12 — https://overview.legal/posts/93916*

The codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models. Providers should be able to rely on codes of practice to demonstrate compliance with the obligations. By means of implementing acts, the Commission may decide to approve a code of practice and give it a general validity within the Union, or, alternatively, to provide common rules for the implementation of the relevant obligations, if, by the time this Regulation becomes applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. Once a harmonised standard is published and assessed as suitable to cover the relevant obligations by the AI Office, compliance with a European harmonised standard should grant providers the presumption of conformity. Providers of general-purpose AI models should furthermore be able to demonstrate compliance using alternative adequate means, if codes of practice or harmonised standards are not available, or they choose not to rely on those.

### Recital 121 — standardisation for regulatory compliance and innovation

*Source: AI Act, aiact-rec-121-en, 2024-06-12 — https://overview.legal/posts/93924*

Standardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation, in line with the state of the art, to promote innovation as well as competitiveness and growth in the single market. Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity with the requirements of this Regulation. A balanced representation of interests involving all relevant stakeholders in the development of standards, in particular SMEs, consumer organisations and environmental and social stakeholders in accordance with Articles 5 and 6 of Regulation (EU) No 1025/2012 should therefore be encouraged. In order to facilitate compliance, the standardisation requests should be issued by the Commission without undue delay. When preparing the standardisation request, the Commission should consult the advisory forum and the Board in order to collect relevant expertise. However, in the absence of relevant references to harmonised standards, the Commission should be able to establish, via implementing acts, and after consultation of the advisory forum, common specifications for certain requirements under this Regulation. The common specification should be an exceptional fall back solution to facilitate the provider’s obligation to comply with the requirements of this Regulation, when the standardisation request has not been accepted by any of the European standardisation organisations, or when the relevant harmonised standards insufficiently address fundamental rights concerns, or when the harmonised standards do not comply with the request, or when there are delays in the adoption of an appropriate harmonised standard. Where such a delay in the adoption of a harmonised standard is due to the technical complexity of that standard, this should be considered by the Commission before contemplating the establishment of common specifications. When developing common specifications, the Commission is encouraged to cooperate with international partners and international standardisation bodies.

## Guidance

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

### Report on stakeholder event on processing of personal data to target or deliver political advertisements

*Source: EDPB, report-on-stakeholder-event-on-processing-of-personal-data-en, 2026-03-27 — https://overview.legal/posts/125684 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-processing-of-personal-data_en*

Report on stakeholder event on processing of personal data to target or deliver political advertisements 27 March 2026 1. Background The EDPB organised an online stakeholder event on 27 March 2026 to collect stakeholders’ input on processing of personal data to target or deliver political advertisements. The objective was to engage with stakeholders at an early stage of drafting the EDPB Guidelines on the processing of personal data to target or deliver political advertisements (Chapter III of…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### EDPB Strategy 2021-2023

*Source: EDPB, edpb-strategy-2021-2023-en, 2020-12-15 — https://overview.legal/posts/126089 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2021-2023_en*

Adopted EDPB Strategy 2021 - 2023 Adopted on 15 December 2020 Adopted Adopted 1 INTRODUCTION 1. The mission of the European Data Protection Board (EDPB) is to ensure the consistent application of European data protection rules and to promote effective cooperation among supervisory authorities throughout the European Economic Area (EEA). 2. On 25 May 2018, the EDPB began putting into practice a new institutiona l and legal framework. This framework comprises both the General Data Protection…

## Recent developments

### noyb's Consent Banner Report: How authorities actually decide

*Source: noyb - European Center for Digital Rights, 2024-07-11 — https://overview.legal/posts/53187 — original: https://noyb.eu/en/noybs-consent-banner-report-how-authorities-actually-decide*

Cookie Banners Following several hundred noyb complaints against companies that use questionable consent banners, the European Data Protection Board established a "cookie banner taskforce" in September 2021. In January 2023, the taskforce then published a report offering its opinion and recommendations regarding the different kind of violations found in consent banners. With its new Consent Banner Report, noyb compared the taskforce's findings with the positions taken by national DPAs in guidanc

## Literature

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Related topics

- **Committee Procedure under AI Act** — https://overview.legal/topics/committee-procedure-ai-act
  The content specifically addresses 'Committee procedure' as a distinct procedural mechanism under the AI Act. This topic is not adequately covered by existing t
- **Delegation of Powers** — https://overview.legal/topics/delegation-of-powers-procedures
  The content specifically addresses 'Exercise of the delegation' which is a distinct procedural topic covering how delegated powers are exercised, implemented, a
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **International Transfer** — https://overview.legal/topics/internationale-doorgifte
  Transfer of personal data outside the EU/EEA
- **Accountability** — https://overview.legal/topics/accountability
  Principle of demonstrating GDPR compliance

---
Generated by overview.legal · https://overview.legal/topics/commission-implementation-guidelines · 2026-08-22
