Law / European Union

AI Act, Article 10 (data and data governance)

Regulation (EU) 2024/1689, Article 10

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 437 days, effective 2 December 2027.

An AI risk obligations rule binding public and private bodies.

As of 21 September 2026.

What it requires

  • This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
  • If you are the provider of a high-risk AI system that uses techniques involving the training of AI models, develop it on training, validation and testing data sets that meet the criteria below, whenever you use such data sets.
  • Apply data governance and management practices appropriate to the system's intended purpose, covering your design choices; how you collected the data and, for personal data, why you originally collected it; your data-preparation operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation; the assumptions you made about what the data measures and represents; an assessment of whether the data sets you need are available, sufficient in quantity, and suitable; examination of the data for biases likely to affect health and safety, harm fundamental rights, or lead to discrimination prohibited under Union law, especially where one operation's data outputs become a later operation's inputs; and measures to detect, prevent and mitigate any bias you find.
  • Identify any data gaps or shortcomings that would prevent the system from complying with the Regulation, and say how you will address them.
  • Make your training, validation and testing data sets relevant, sufficiently representative, and as free of errors and as complete as possible for the intended purpose, with statistical properties appropriate to the persons or groups the system is intended to be used on, and take into account the specific geographic, contextual, behavioural or functional setting the system is intended to be used in, to the extent your intended purpose requires it.
  • If your high-risk AI system does not use training techniques, these criteria apply only to its testing data set.

If you get it wrong

Private right of actionNo

What it reaches

Obligation class

Governance

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Providers of a high-risk AI system that uses techniques involving the training of AI models must develop it on training, validation and testing data sets that meet the quality criteria in paragraphs 2, 3 and 4 of Article 10 and in Article 4a(1), whenever such data sets are used.

Those data sets must be subject to data governance and management practices appropriate to the system's intended purpose, covering the provider's design choices, how the data was collected and, for personal data, why it was originally collected, data-preparation operations such as annotation, labelling, cleaning, updating, enrichment and aggregation, the assumptions made about what the data measures and represents, an assessment of whether the needed data sets are available, sufficient in quantity and suitable, examination for biases likely to affect health and safety, harm fundamental rights or lead to prohibited discrimination, especially where one operation's outputs become a later operation's inputs, measures to detect, prevent and mitigate any bias found, and identification of data gaps or shortcomings that would prevent compliance, with how they will be addressed.

The data sets must be relevant, sufficiently representative, as free of errors and as complete as possible for the intended purpose, with statistical properties appropriate to the persons or groups the system is intended to be used on, and must take into account the specific geographic, contextual, behavioural or functional setting the system is intended to be used in, to the extent the intended purpose requires it; where the system does not use training techniques, these criteria apply only to its testing data set.

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) deleted Article 10(5), which had let a provider exceptionally process special categories of personal data to detect and correct bias. That same permission now sits in a new Article 4a, which also reaches a deployer of a high-risk AI system and a provider or deployer of any other AI system or model.

Article 10 sits in Chapter III, Section 2, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for a system classified as high-risk under Article 6(1) and Annex I, rather than the Regulation's general 2 August 2026 application date.

When LexLint raises it

  • high_risk_decisions
  • trains_models

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app