Harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts

European Union · EU:CJ40-PR-731563

Authoritative source — the official register ↗.

European Parliament 2019-2024 {CJ40}Committee on the Internal Market and Consumer Protection Committee on Civil Liberties, Justice and Home Affairs 2021/0106 (COD) {20/04/2022}20.4.2022 ***I

DRAFT REPORT

on the proposal for a regulation of the European Parliament and of the Council on harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts

(COM2021/0206 – C90146/2021 – 2021/0106(COD))

{CJ40}Committee on the Internal Market and Consumer ProtectionCommittee on Civil Liberties, Justice and Home Affairs Rapporteur: Brando Benifei, Ioan-Dragoş Tudorache (Joint committee procedure – Rule 58 of the Rules of Procedure) PR_COD_1amCom Symbols for procedures * Consultation procedure *** Consent procedure ***I Ordinary legislative procedure (first reading) ***II Ordinary legislative procedure (second reading) ***III Ordinary legislative procedure (third reading)

(The type of procedure depends on the legal basis proposed by the draft act.) Amendments to a draft act Amendments by Parliament set out in two columns Deletions are indicated in bold italics in the left-hand column. Replacements are indicated in bold italics in both columns. New text is indicated in bold italics in the right-hand column.

The first and second lines of the header of each amendment identify the relevant part of the draft act under consideration. If an amendment pertains to an existing act that the draft act is seeking to amend, the amendment heading includes a third line identifying the existing act and a fourth line identifying the provision in that act that Parliament wishes to amend.

Amendments by Parliament in the form of a consolidated text

New text is highlighted in bold italics. Deletions are indicated using either the ▌symbol or strikeout. Replacements are indicated by highlighting the new text in bold italics and by deleting or striking out the text that has been replaced. By way of exception, purely technical changes made by the drafting departments in preparing the final text are not highlighted.

CONTENTS

Page

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION 5

EXPLANATORY STATEMENT 159

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

on the proposal for a regulation of the European Parliament and of the Council on harmonised rules on Artificial Intelligence (Artificial Intelligence Act) and amending certain Union Legislative Acts

(COM2021/0206 – C90146/2021 – 2021/0106(COD))

(Ordinary legislative procedure: first reading) The European Parliament,

<RepeatBlock-Amend> Amendment 1 Proposal for a regulation Recital 1 Text proposed by the Commission Amendment

(1) The purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework in particular for the development, marketing and use of artificial intelligence in conformity with Union values.

This Regulation pursues a number of overriding reasons of public interest, such as a high level of protection of health, safety and fundamental rights, and it ensures the free movement of AI-based goods and services cross-border, thus preventing Member States from imposing restrictions on the development, marketing and use of AI systems, unless explicitly authorised by this Regulation. (1) The purpose of this Regulation is to improve the functioning of the internal market by laying down a uniform legal framework in particular for the development, the placing on the market, the putting into service and the use of artificial intelligence in conformity with Union values.

This Regulation pursues a number of overriding reasons of public interest, such as a high level of protection of health, safety, fundamental rights and the Union values enshrined in Article 2 of the Treaty on European Union (TEU), and it ensures the free movement of AI-based goods and services cross-border, thus preventing Member States from imposing restrictions on the development, marketing and use of AI systems, unless explicitly authorised by this Regulation. Or. {EN}en Amendment 2 Proposal for a regulation Recital 2

Text proposed by the Commission Amendment

(2) Artificial intelligence systems (AI systems) can be easily deployed in multiple sectors of the economy and society, including cross border, and circulate throughout the Union. Certain Member States have already explored the adoption of national rules to ensure that artificial intelligence is safe and is developed and used in compliance with fundamental rights obligations. Differing national rules may lead to fragmentation of the internal market and decrease legal certainty for operators that develop or use AI systems.

A consistent and high level of protection throughout the Union should therefore be ensured, while divergences hampering the free circulation of AI systems and related products and services within the internal market should be prevented, by laying down uniform obligations for operators and guaranteeing the uniform protection of overriding reasons of public interest and of rights of persons throughout the internal market based on Article 114 of the Treaty on the Functioning of the European Union (TFEU).

To the extent that this Regulation contains specific rules on the protection of individuals with regard to the processing of personal data concerning restrictions of the use of AI systems for ‘real-time’ remote biometric identification in publicly accessible spaces for the purpose of law enforcement, it is appropriate to base this Regulation, in as far as those specific rules are concerned, on Article 16 of the TFEU. In light of those specific rules and the recourse to Article 16 TFEU, it is appropriate to consult the European Data Protection Board. (2) Artificial intelligence systems (AI systems) can be easily deployed in multiple sectors of the economy and society, including cross border, and circulate throughout the Union.

Certain Member States have already explored the adoption of national rules to ensure that artificial intelligence is safe and is developed and used in compliance with fundamental rights obligations. Differing national rules may lead to fragmentation of the internal market and decrease legal certainty for operators that develop or use AI systems.

A consistent and high level of protection throughout the Union should therefore be ensured, while divergences hampering the free circulation of AI systems and related products and services within the internal market should be prevented, by laying down uniform obligations for operators and guaranteeing the uniform protection of overriding reasons of public interest and of rights of persons throughout the internal market based on Article 114 of the Treaty on the Functioning of the European Union (TFEU). Or. {EN}en Justification A new recital 2a has been created to explain the reference to Article 16 TFEU.

Amendment 3 Proposal for a regulation Recital 2 a (new) Text proposed by the Commission Amendment

(2a) Artificial intelligence often relies on the processing of large volumes of data, and many AI systems and applications process personal data. This Regulation is therefore also based on Article 16 TFEU, which enshrines the right of everyone to the protection of personal data concerning them and provides for the adoption of rules on the protection of individuals with regard to the processing of personal data. In light of the reliance on Article 16 TFEU, it is appropriate to consult the European Data Protection Board.

Or. {EN}en Amendment 4 Proposal for a regulation Recital 2 b (new) Text proposed by the Commission Amendment

(2b) The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive 2016/680. Directive 2002/58/EC additionally protects private life and the confidentiality of communications, including providing conditions for any personal and non-personal data storing in and access from terminal equipment. Those legal acts provide the basis for sustainable and responsible data processing, including where datasets include a mix of personal and non-personal data. This Regulation complements and does not affect Union law on data protection and privacy, in particular those other Regulations and Directives. This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments. This Regulation does not affect the fundamental rights to private life and data protection as provided for by Union law on data protection and privacy and enshrined in the Charter of Fundamental Rights of the European Union (the ‘Charter’).

Or. {EN}en Amendment 5 Proposal for a

regulation Recital 4

5 Proposal for a regulation Recital 4 Text proposed by the Commission Amendment

(4) At the same time, depending on the circumstances regarding its specific application and use, artificial intelligence may generate risks and cause harm to public interests and rights that are protected by Union law. Such harm might be material or immaterial.

(4) At the same time, depending on the circumstances regarding its specific application and use, artificial intelligence may generate risks and cause harm to public interests and fundamental rights of natural persons that are protected by Union law. Such harm might be material or immaterial. Or. {EN}en Amendment 6 Proposal for a regulation Recital 4 a (new) Text proposed by the Commission Amendment

(4a) Given the major impact that artificial intelligence can have on society and the need to build trust, it is vital for artificial intelligence and its regulatory framework to be developed according to Union values enshrined in Article 2 TEU, the fundamental rights and freedoms enshrined in the Treaties, the Charter, and international human rights law. As a pre-requisite, artificial intelligence should be a human-centric technology. It should not substitute human autonomy or assume the loss of individual freedom and should primarily serve the needs of the people and the common good. Safeguards should be provided to ensure the development and use of ethically embedded artificial intelligence that respects Union values and the Charter.

Or. {EN}en Amendment 7 Proposal for a regulation Recital 5

Text proposed by the Commission Amendment

(5) A Union legal framework laying down harmonised rules on artificial intelligence is therefore needed to foster the development, use and uptake of artificial intelligence in the internal market that at the same time meets a high level of protection of public interests, such as health and safety and the protection of fundamental rights, as recognised and protected by Union law. To achieve that objective, rules regulating the placing on the market and putting into service of certain AI systems should be laid down, thus ensuring the smooth functioning of the internal market and allowing those systems to benefit from the principle of free movement of goods and services.

By laying down those rules, this Regulation supports the objective of the Union of being a global leader in the development of secure, trustworthy and ethical artificial intelligence, as stated by the European Council33, and it ensures the protection of ethical principles, as specifically requested by the European Parliament34. (5) A Union legal framework laying down harmonised rules on artificial intelligence is therefore needed to foster the development,use and uptake of artificial intelligence in the internal market that at the same time meets a high level of protection of public interests, such as health and safety, the protection of fundamental rights, as recognised and protected by Union law and the Union values enshrined in Article 2 TEU.

To achieve that objective, rules regulating the development, the placing on the market, the putting into service and the use of certain AI systems should be laid down, thus ensuring the smooth functioning of the internal market and allowing those systems to benefit from the principle of free movement of goods and services. By laying down those rules, this Regulation supports the objective of the Union of being a global leader in the development of secure, trustworthy and ethical artificial intelligence, as stated by the European Council33, and it ensures the protection of ethical principles, as specifically requested34.

33 European Council, Special meeting of the European Council (1 and 2 October 2020) – Conclusions, EUCO 13/20, 2020, p. 6. 33 European Council, Special meeting of the European Council (1 and 2 October 2020) – Conclusions, EUCO 13/20, 2020, p. 6. 34 European Parliament resolution of 20 October 2020 with recommendations to the Commission on a framework of ethical aspects of artificial intelligence, robotics and related technologies, 2020/2012(INL). 34 European Parliament resolution of 20 October 2020 with recommendations to the Commission on a framework of ethical aspects of artificial intelligence, robotics and related technologies, 2020/2012(INL).

Or. {EN}en Amendment 8 Proposal for a regulation Recital 6

Text proposed by the Commission Amendment

(6) The notion of AI system should be clearly defined to ensure legal certainty, while providing the flexibility to accommodate future technological developments. The definition should be based on the key functional characteristics of the software, in particular the ability, for a given set of human-defined objectives, to generate outputs such as content, predictions, recommendations, or decisions which influence the environment with which the system interacts, be it in a physical or digital dimension.

AI systems can be designed to operate with varying levels of autonomy and be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serve the functionality of the product without being integrated therein (non-embedded). The definition of AI system should be complemented by a list of specific techniques and approaches used for its development, which should be kept up-to–date in the light of market and technological developments through the adoption of delegated acts by the Commission to amend that list. (6) The notion of AI system should be clearly defined to ensure legal certainty, while providing the flexibility to accommodate future technological developments.

The definition should be based on the key functional characteristics of the software, in particular the ability, for a given set of objectives, to generate outputs such as content, predictions, recommendations, or decisions which influence the environment with which the system interacts, be it in a physical or digital dimension. AI systems can be designed to operate with varying levels of autonomy and be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serve the functionality of the product without being integrated therein (non-embedded).

The definition of AI system should be complemented by a list of specific techniques and approaches used for its development, which should be kept up-to–date in the light of market and technological developments through the adoption of delegated acts by the Commission to amend that list. Or. {EN}en Amendment 9 Proposal for a regulation Recital 7

Text proposed by the Commission Amendment

(7) The notion of biometric data used in this Regulation is in line with and should be interpreted consistently with the notion of biometric data as defined in Article 4(14) of Regulation (EU) 2016/679 of the European Parliament and of the Council35, Article 3(18) of Regulation (EU) 2018/1725 of the European Parliament and of the Council36 and Article 3(13) of Directive (EU) 2016/680 of the European Parliament and of the Council37.

(7) The notion of biometric data used in this Regulation is the same as that in Article 4(14) of Regulation (EU) 2016/679 of the European Parliament and of the Council35, Article 3(18) of Regulation (EU) 2018/1725 of the European Parliament and of the Council36 and Article 3(13) of Directive (EU) 2016/680 of the European Parliament and of the Council37 and should therefore be interpreted consistently with those provisions. Biometrics-based data are additional data resulting from specific technical processing relating to physical, physiological or behavioural signals of a natural person.

35 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). 35 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1).

36 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39) 36 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p.

37 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (Law Enforcement Directive) (OJ L 119, 4.5.2016, p. 89). Or. {EN}en Justification The reference to biometrics-based data has been added, in alignment with the new definition inserted in article 3.

Amendment 10 Proposal for a regulation Recital 12

Text proposed by the Commission Amendment

(12) This Regulation should also apply to Union institutions, offices, bodies and agencies when acting as a provider or user of an AI system. AI systems exclusively developed or used for military purposes should be excluded from the scope of this Regulation where that use falls under the exclusive remit of the Common Foreign and Security Policy regulated under Title V of the Treaty on the European Union (TEU). This Regulation should be without prejudice to the provisions regarding the liability of intermediary service providers set out in Directive 2000/31/EC of the European Parliament and of the Council [as amended by the Digital Services Act].

(12) This Regulation should also apply to Union institutions, offices, bodies and agencies when acting as a provider or user of an AI system. Or. {EN}en Justification This recital has been split in three separate recitals for clarity. Amendment 11 Proposal for a regulation Recital 12 a (new)

Text proposed by the Commission Amendment (12a) AI systems developed or used exclusively for military purposes should be excluded from the scope of this Regulation where that use falls under the exclusive remit of the Common Foreign and Security Policy regulated under Title V of the TEU. Or. {EN}en Amendment 12 Proposal for a regulation Recital 12 b (new) Text proposed by the Commission Amendment (12b) This Regulation should be without prejudice to the provisions regarding the liability of intermediary service providers set out in Directive 2000/31/EC of the European Parliament and of the Council1a [as amended by the Digital Services Act].

1a Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market ('Directive on electronic commerce') (OJ L 178, 17.7.2000, p. 1). Or. {EN}en Amendment 13 Proposal for a regulation Recital 13

Text proposed by the Commission Amendment

(13) In order to ensure a consistent and high level of protection of public interests as regards health, safety and fundamental rights, common normative standards for all high-risk AI systems should be established. Those standards should be consistent with the Charter of fundamental rights of the European Union (the Charter) and should be non-discriminatory and in line with the Union’s international trade commitments.

(13) In order to ensure a consistent and high level of protection of public interests as regards health, safety, fundamental rights and the Union values enshrined in Article 2 TEU, common normative standards for all high-risk AI systems should be established. Those standards should be consistent with the Charter and should be non-discriminatory. and in line with the Union’s international trade commitments. Or. {EN}en Amendment 14 Proposal for a regulation Recital 14

Text proposed by the Commission Amendment

(14) In order to introduce a proportionate and effective set of binding rules for AI systems, a clearly defined risk-based approach should be followed. That approach should tailor the type and content of such rules to the intensity and scope of the risks that AI systems can generate. It is therefore necessary to prohibit certain artificial intelligence practices, to lay down requirements for high-risk AI systems and obligations for the relevant operators, and to lay down transparency obligations for certain AI systems.

(14) In order to introduce a proportionate and effective set of binding rules for AI systems, a clearly defined risk-based approach should be followed. That approach should tailor the type and content of such rules to the intensity and scope of the risks that AI systems can generate. It is therefore necessary to prohibit certain unacceptable artificial intelligence practices, to lay down requirements for high-risk AI systems and obligations for the relevant operators, and to lay down transparency obligations for certain AI systems. Or. {EN}en Amendment 15 Proposal for a regulation Recital 15

Text proposed by the Commission Amendment

(15) Aside from the many beneficial uses of artificial intelligence, that technology can also be misused and provide novel and powerful tools for manipulative, exploitative and social control practices. Such practices are particularly harmful and should be prohibited because they contradict Union values of respect for human dignity, freedom, equality, democracy and the rule of law and Union fundamental rights, including the right to non-discrimination, data protection and privacy and the rights of the child.

(15) Aside from the many beneficial uses of artificial intelligence, that technology can also be misused and provide novel and powerful tools for manipulative, exploitative and social control practices. Such practices are particularly harmful and abusive and should be prohibited because they contradict Union values of respect for human dignity, freedom, equality, democracy and the rule of law and Union fundamental rights, including the right to non-discrimination, data protection and privacy and the rights of the child. Or. {EN}en Amendment 16 Proposal for a regulation Recital 17 a (new)

Text proposed by the Commission Amendment (17a) AI systems used by law enforcement authorities or on their behalf to predict the probability of a natural person to offend or to reoffend, based on profiling and individual risk-assessment hold a particular risk of discrimination against certain persons or groups of persons, as they violate human dignity as well as the key legal principle of presumption of innocence. Such AI systems should therefore be prohibited.

Or. {EN}en Justification predictive policing should be added among the prohibited practices as it violates the presumption of innocence as well as human dignity. Amendment 17 Proposal for a regulation Recital 26 a (new)

Text proposed by the Commission Amendment (26a) Practices that are prohibited by Union legislation, including under data protection law, non-discrimination law, consumer protection law, and competition law, are not affected by this Regulation. Or. {EN}en Amendment 18 Proposal for a regulation Recital 26 b (new) Text proposed by the Commission Amendment

(26b) In accordance with the risk-based approach of this Regulation, a list of high-risk AI systems should be established in an annex to this Regulation and should be regularly evaluated and reviewed, subject to the appropriate involvement and consultation of stakeholders and civil society. Or. {EN}en Amendment 19 Proposal for a regulation Recital 27 Text proposed by the Commission Amendment

(27) High-risk AI systems should only be placed on the Union market or put into service if they comply with certain mandatory requirements.

Those requirements should ensure that high-risk AI systems available in the Union or whose output is otherwise used in the Union do not pose unacceptable risks to important Union public interests as recognised and protected by Union law. AI systems identified as high-risk should be limited to those that have a significant harmful impact on the health, safety and fundamental rights of persons in the Union and such limitation minimises any potential restriction to international trade, if any. (27) High-risk AI systems should only be placed on the Union market, put into service or used if they comply with certain mandatory requirements.

Those requirements should ensure that high-risk AI systems available in the Union or whose output is otherwise used in the Union do not pose unacceptable risks to important Union public interests as recognised and protected by Union law and do not contravene the Union values enshrined in Article 2 TEU. AI systems identified as high-risk should be limited to those that have a significant harmful impact on the health, safety, and the fundamental rights of persons in the Union and such limitation minimises any potential restriction to international trade, if any. Or. {EN}en Amendment 20 Proposal for a regulation Recital 28

Text proposed by the Commission Amendment

(28) AI systems could produce adverse outcomes to health and safety of persons, in particular when such systems operate as components of products. Consistently with the objectives of Union harmonisation legislation to facilitate the free movement of products in the internal market and to ensure that only safe and otherwise compliant products find their way into the market, it is important that the safety risks that may be generated by a product as a whole due to its digital components, including AI systems, are duly prevented and mitigated. For instance, increasingly autonomous robots, whether in the context of manufacturing or personal assistance and care should be able to safely operate and performs their functions in complex environments.

Similarly, in the health sector where the stakes for life and health are particularly high, increasingly sophisticated diagnostics systems and systems supporting human decisions should be reliable and accurate. The extent of the adverse impact caused by the AI system on the fundamental rights protected by the Charter is of particular relevance when classifying an AI system as high-risk.

Those rights include the right to human dignity, respect for private and family life, protection of personal data, freedom of expression and information, freedom of assembly and of association, and non-discrimination, consumer protection, workers’ rights, rights of persons with disabilities, right to an effective remedy and to a fair trial, right of defence and the presumption of innocence, right to good administration. In addition to those rights, it is important to highlight that children have specific rights as enshrined in Article 24 of the EU Charter and in the United Nations Convention on the Rights of the Child (further elaborated in the UNCRC General Comment No.

25 as regards the digital environment), both of which require consideration of the children’s vulnerabilities and provision of such protection and care as necessary for their well-being. The fundamental right to a high level of environmental protection enshrined in the Charter and implemented in Union policies should also be considered when assessing the severity of the harm that an AI system can cause, including in relation to the health and safety of persons. (28) AI systems could produce adverse outcomes to health and safety of persons, in particular when such systems operate as safety components of products.

Consistently with the objectives of Union harmonisation legislation to facilitate the free movement of products in the internal market and to ensure that only safe and otherwise compliant products find their way into the market, it is important that the safety and security risks that may be generated by a product as a whole due to its digital components, including AI systems, are duly prevented and mitigated. For instance, increasingly autonomous robots, whether in the context of manufacturing or personal assistance and care should be able to safely operate and performs their functions in complex environments.

Similarly, in the health sector where the stakes for life and health are particularly high, increasingly sophisticated diagnostics systems and systems supporting human decisions should be reliable and accurate. Or. {EN}en Justification This recital has been split in two parts to highlight the fundamental rights element.

Amendment 21 Proposal for a regulation Recital 28 a (new) Text proposed by the Commission Amendment (28a) The extent of the adverse impact caused by an AI system on the fundamental rights protected by the Charter is of particular relevance when classifying an AI system as high-risk, regardless of the field of application.

Those rights include the right to human dignity, respect for private and family life, protection of personal data, freedom of expression and information, freedom of assembly and of association, non-discrimination, consumer protection, workers’ rights, rights of persons with disabilities, the right to an effective remedy and to a fair trial, the presumption of innocence, the right of defence and the right to good administration.

In addition to those rights, it is important to highlight that children have specific rights as enshrined in Article 24 of the Charter and in the United Nations Convention on the Rights of the Child, further elaborated in the UNCRC General Comment No 25 as regards the digital environment, both of which require consideration of the children’s vulnerabilities and provision of such protection and care as necessary for their well-being. The fundamental right to a high level of environmental protection implemented in Union law and policies and enshrined in the Charter should also be considered when assessing the severity of the harm that an AI system can cause, including in relation to the health and safety of persons. Or.

{EN}en Amendment 22 Proposal for a regulation Recital 32 Text proposed by the Commission Amendment

(32) As regards stand-alone AI systems, meaning high-risk AI systems other than those that are safety components of products, or which are themselves products, it is appropriate to classify them as high-risk if, in the light of their intended purpose, they pose a high risk of harm to the health and safety or the fundamental rights of persons, taking into account both the severity of the possible harm and its probability of occurrence and they are used in a number of specifically pre-defined areas specified in the Regulation.

The identification of those systems is based on the same methodology and criteria envisaged also for any future amendments of the list of high-risk AI systems. (32) As regards stand-alone AI systems, meaning high-risk AI systems other than those that are safety components of products, or which are themselves products, it is appropriate to classify them as high-risk if, in the light of their intended purpose, they pose a high risk of harm to the health and safety or the fundamental rights of natural persons or to the Union values enshrined in Article 2 TEU, taking into account both the severity of the possible harm and its probability of occurrence and they are used in a number of specifically pre-defined areas specified in this Regulation.

The identification of those systems is based on the same methodology and criteria envisaged also for any future amendments of the list of high-risk AI systems. Or. {EN}en Amendment 23 Proposal for a regulation Recital 35 Text proposed by the Commission Amendment

(35) AI systems used in education or vocational training, notably for determining access or assigning persons to educational and vocational training institutions or to evaluate persons on tests as part of or as a precondition for their education should be considered high-risk, since they may determine the educational and professional course of a person’s life and therefore affect their ability to secure their livelihood.

When improperly designed and used, such systems may violate the right to education and training as well as the right not to be discriminated against and perpetuate historical patterns of discrimination. (35) AI systems used in education or vocational training, notably for determining access or assigning persons to educational and vocational training institutions or to evaluate persons on tests as part of or as a precondition for their education should be classified as considered high-risk AI systems, since they may determine the educational and professional course of a person’s life and therefore affect their ability to secure their livelihood.

When improperly designed and used, such systems may violate the right to education and training as well as the right not to be discriminated against and perpetuate historical patterns of discrimination. Children, in particular, constitute an especially vulnerable group of people and require additional safeguards. AI systems intended to shape children’s development through personalised education or cognitive or emotional development should therefore be classified as high-risk AI systems. Or. {EN}en Amendment 24 Proposal for a regulation Recital 37

Text proposed by the Commission Amendment

(37) Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living. In particular, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services.

AI systems used for this purpose may lead to discrimination of persons or groups and perpetuate historical patterns of discrimination, for example based on racial or ethnic origins, disabilities, age, sexual orientation, or create new forms of discriminatory impacts. Considering the very limited scale of the impact and the available alternatives on the market, it is appropriate to exempt AI systems for the purpose of creditworthiness assessment and credit scoring when put into service by small-scale providers for their own use. Natural persons applying for or receiving public assistance benefits and services from public authorities are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities.

If AI systems are used for determining whether such benefits and services should be denied, reduced, revoked or reclaimed by authorities, they may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy. Those systems should therefore be classified as high-risk. Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons.

Finally, AI systems used to dispatch or establish priority in the dispatching of emergency first response services should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property. (37) Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living.

In particular, AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons’ access to financial resources or essential services such as housing, electricity, and telecommunication services. AI systems used for this purpose may lead to discrimination of persons or groups and perpetuate historical patterns of discrimination, for example based on racial or ethnic origins, disabilities, age, sexual orientation, or create new forms of discriminatory impacts.

Natural persons applying for or receiving public assistance benefits and services from public authorities are typically dependent on those benefits and services and in a vulnerable position in relation to the responsible authorities. If AI systems are used for determining whether such benefits and services should be denied, reduced, revoked or reclaimed by authorities, they may have a significant impact on persons’ livelihood and may infringe their fundamental rights, such as the right to social protection, non-discrimination, human dignity or an effective remedy. Those systems should therefore be classified as high-risk.

Nonetheless, this Regulation should not hamper the development and use of innovative approaches in the public administration, which would stand to benefit from a wider use of compliant and safe AI systems, provided that those systems do not entail a high risk to legal and natural persons. Finally, AI systems used to dispatch or establish priority in the dispatching of emergency first response services should also be classified as high-risk since they make decisions in very critical situations for the life and health of persons and their property. Or.

{EN}en Justification Small-scale providers should not be exempted, as the impact of biased AI systems to assess credit worthiness can still be relevant on people's lives, regardless of their number. Amendment 25 Proposal for a regulation Recital 38 Text proposed by the Commission Amendment

(38) Actions by law enforcement authorities involving certain uses of AI systems are characterised by a significant degree of power imbalance and may lead to surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on fundamental rights guaranteed in the Charter.

In particular, if the AI system is not trained with high quality data, does not meet adequate requirements in terms of its accuracy or robustness, or is not properly designed and tested before being put on the market or otherwise put into service, it may single out people in a discriminatory or otherwise incorrect or unjust manner. Furthermore, the exercise of important procedural fundamental rights, such as the right to an effective remedy and to a fair trial as well as the right of defence and the presumption of innocence, could be hampered, in particular, where such AI systems are not sufficiently transparent, explainable and documented.

It is therefore appropriate to classify as high-risk a number of AI systems intended to be used in the law enforcement context where accuracy, reliability and transparency is particularly important to avoid adverse impacts, retain public trust and ensure accountability and effective redress.

In view of the nature of the activities in question and the risks relating thereto, those high-risk AI systems should include in particular AI systems intended to be used by law enforcement authorities for individual risk assessments, polygraphs and similar tools or to detect the emotional state of natural person, to detect ‘deep fakes’, for the evaluation of the reliability of evidence in criminal proceedings, for predicting the occurrence or reoccurrence of an actual or potential criminal offence based on profiling of natural persons, or assessing personality traits and characteristics or past criminal behaviour of natural persons or groups, for profiling in the course of detection, investigation or prosecution of criminal offences, as well as for crime analytics regarding natural persons.

AI systems specifically intended to be used for administrative proceedings by tax and customs authorities should not be considered high-risk AI systems used by law enforcement authorities for the purposes of prevention, detection, investigation and prosecution of criminal offences. (38) Actions by law enforcement authorities involving certain uses of AI systems are characterised by a significant degree of power imbalance and may lead to surveillance, arrest or deprivation of a natural person’s liberty as well as other adverse impacts on fundamental rights guaranteed in the Charter.

In particular, if the AI system is not trained with high quality data, does not meet adequate requirements in terms of its accuracy or robustness, or is not properly designed and tested before being put on the market or otherwise put into service, it may single out people in a discriminatory or otherwise incorrect or unjust manner. Furthermore, the exercise of important procedural fundamental rights, such as the right to an effective remedy and to a fair trial as well as the right of defence and the presumption of innocence, could be hampered, in particular, where such AI systems are not sufficiently transparent, explainable and documented.

It is therefore appropriate to classify as high-risk a number of AI systems intended to be used in the law enforcement context where accuracy, reliability and transparency is particularly important to avoid adverse impacts, retain public trust and ensure accountability and effective redress.

In view of the nature of the activities in question and the risks relating thereto, those high-risk AI systems should include in particular AI systems intended to be used by law enforcement authorities, polygraphs and similar tools or to detect the emotional state of natural person, to detect ‘deep fakes’, for the evaluation of the reliability of evidence in criminal proceedings, for profiling in the course of detection, investigation or prosecution of criminal offences, as well as for crime analytics regarding natural persons.

AI systems specifically intended to be used for administrative proceedings by tax and customs authorities should not be classified as high-risk AI systems used by law enforcement authorities for the purposes of prevention, detection, investigation and prosecution of criminal offences. Or. {EN}en Justification The use of AI systems for predictive policing should be prohibited, not high-risk.

Amendment 26 Proposal for a regulation Recital 40

Text proposed by the Commission Amendment

(40) Certain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts.

Such qualification should not extend, however, to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks or allocation of resources. (40) Certain AI systems intended for the administration of justice and democratic processes should be classified as high-risk, considering their potentially significant impact on democracy, rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial.

In particular, to address the risks of potential biases, errors and opacity, it is appropriate to qualify as high-risk AI systems intended to assist judicial authorities in researching and interpreting facts and the law and in applying the law to a concrete set of facts. Such qualification should not extend, however, to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks or allocation of resources.

In order to address the risks to the right to vote enshrined in Article 39 of the Charter of undue external interference, and of disproportionate effects on democratic processes, democracy, and the rule of law, AI systems used in political campaigns to influence the votes of natural persons in local, national or European Parliament elections or for the purpose of vote counting and processing in such elections should be classified as high-risk AI systems. Or. {EN}en Justification To align with the additions in the Justice and Democracy area in Annex III.

Amendment 27 Proposal for a regulation Recital 40 a (new) Text proposed by the Commission Amendment

(40a) Certain AI systems should at the same time be subject to transparency requirements and be classified as high-risk AI systems, given their potential to deceive and cause both individual and societal harm. In particular, AI systems that generate deep fakes representing existing persons have the potential to both manipulate the natural persons that are exposed to those deep fakes and harm the persons they are representing or misrepresenting, while AI systems that, based on limited human input, generate complex text such as news articles, opinion articles, novels, scripts, and scientific articles (“AI authors”) have the potential to manipulate, deceive, or to expose natural persons to built-in biases or inaccuracies.

Or. {EN}en Amendment 28 Proposal for a regulation Recital 41

Text proposed by the Commission Amendment

(41) The fact that an AI system is classified as high risk under this Regulation should not be interpreted as indicating that the use of the system is necessarily lawful under other acts of Union law or under national law compatible with Union law, such as on the protection of personal data, on the use of polygraphs and similar tools or other systems to detect the emotional state of natural persons. Any such use should continue to occur solely in accordance with the applicable requirements resulting from the Charter and from the applicable acts of secondary Union law and national law. This Regulation should not be understood as providing for the legal ground for processing of personal data, including special categories of personal data, where relevant.

(41) The fact that an AI system is classified a high risk AI system under this Regulation should not be interpreted as indicating that the use of the system is necessarily lawful under other acts of Union law or under national law compatible with Union law, such as on the protection of personal data, on the use of polygraphs and similar tools or other systems to detect the emotional state of natural persons. Any such use should continue to occur solely in accordance with the applicable requirements resulting from the Charter and from the applicable acts of secondary Union law and national law. This Regulation should not be understood as providing for the legal ground for processing of personal data, including special categories of personal data. Or.

{EN}en Amendment 29 Proposal for a regulation Recital 44 Text proposed by the Commission Amendment

(44) High data quality is essential for the performance of many AI systems, especially when techniques involving the training of models are used, with a view to ensure that the high-risk AI system performs as intended and safely and it does not become the source of discrimination prohibited by Union law. High quality training, validation and testing data sets require the implementation of appropriate data governance and management practices.

Training, validation and testing data sets should be sufficiently relevant, representative and free of errors and complete in view of the intended purpose of the system. They should also have the appropriate statistical properties, including as regards the persons or groups of persons on which the high-risk AI system is intended to be used. In particular, training, validation and testing data sets should take into account, to the extent required in the light of their intended purpose, the features, characteristics or elements that are particular to the specific geographical, behavioural or functional setting or context within which the AI system is intended to be used.

In order to protect the right of others from the discrimination that might result from the bias in AI systems, the providers shouldbe able to process also special categories of personal data, as a matter of substantial public interest, in order to ensure the bias monitoring, detection and correction in relation to high-risk AI systems. (44) High data quality is essential for the performance of many AI systems, especially when techniques involving the training of models are used, with a view to ensure that the high-risk AI system performs as intended and safely and it does not become the source of discrimination prohibited by Union law.

High quality training, validation and testing data sets require the implementation of appropriate data governance and management practices. Training, validation and testing data sets should be sufficiently relevant, representative, up-to-date and, to the best extent possible, free of errors and as complete as possible, in view of the intended purpose or reasonably foreseeable uses of the system. They should also have the appropriate statistical properties, including as regards the persons or groups of persons on which the high-risk AI system is intended or reasonably foreseeable to be used.

In particular, training, validation and testing datasets should take into account, to the extent required in the light of their intended purpose or reasonably foreseeable uses, the features, characteristics or elements that are particular to the specific geographical, cultural, behavioural or functional setting or context within which the AI system is intended to be used or within which its use is reasonably foreseeable. Or. {EN}en Justification alignment with the changes in art. 10 Amendment 30 Proposal for a regulation Recital 45 a (new) Text proposed by the Commission Amendment

(45a) The right to privacy and to data protection must be guaranteed throughout the entire lifecycle of the AI system. In this regard, the principles of data minimisation and data protection by design and by default, as set out in Union data protection law, are essential when the processing of data involves significant risks to the fundamental rights of individuals. Providers and users of AI systems should implement state-of-the-art technical and organisational measures in order to protect those rights. Such measures should include not only anonymisation and encryption, but also the use of increasingly available technology that permits algorithms to be brought to the data and allows valuable insights to be derived without the transmission between parties or unnecessary copying of the raw or structured data themselves.

Or. {EN}en Justification alignment with the changes in article 10. Amendment 31 Proposal for a regulation Recital 45 b (new)

Text proposed by the Commission Amendment (45b) Providers may not always be able to access the datasets needed to develop high-risk AI systems, such as when the datasets are in the exclusive possession of the user while the provider only provides the tools and the techniques to the user in order to develop the AI system. In such circumstances, the provider cannot objectively comply with the requirements and obligations on the quality of datasets laid down in this Regulation. Such obligations should therefore be fulfilled by the user, on the basis of an agreement between the provider and the user.

Or. {EN}en Justification Alignment with the changes in article 10. Amendment 32 Proposal for a regulation Recital 56

Text proposed by the Commission Amendment

(56) To enable enforcement of this Regulation and create a level-playing field for operators, and taking into account the different forms of making available of digital products, it is important to ensure that, under all circumstances, a person established in the Union can provide authorities with all the necessary information on the compliance of an AI system. Therefore, prior to making their AI systems available in the Union, where an importer cannot be identified, providers established outside the Union shall, by written mandate, appoint an authorised representative established in the Union.

(56) To enable enforcement of this Regulation and create a level-playing field for operators, and taking into account the different forms of making available of digital products, it is important to ensure that, under all circumstances, a person established in the Union can provide authorities with all the necessary information on the compliance of an AI system. Therefore, prior to making their AI systems available in the Union, providers established outside the Union shall, by written mandate, appoint an authorised representative established in the Union. Or. {EN}en Justification Alignment with article 25.1.

Amendment 33 Proposal for a regulation Recital 61

Text proposed by the Commission Amendment

(61) Standardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation. Compliance with harmonised standards as defined in Regulation (EU) No 1025/2012 of the European Parliament and of the Council54 should be a means for providers to demonstrate conformity with the requirements of this Regulation. However, the Commission could adopt common technical specifications in areas where no harmonised standards exist or where they are insufficient. (61) Standardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation.

Compliance with harmonised standards as defined in Regulation (EU) No 1025/2012 of the European Parliament and of the Council54 should be a means for providers to demonstrate conformity with the requirements of this Regulation. To ensure the effectiveness of standards and standardisation as policy tools for the Union, and considering the importance of standards for the competitiveness of undertakings and for ensuring conformity with the requirements of this Regulation, it is necessary to ensure a balanced representation of interests by encouraging the participation of all relevant stakeholders in the development of standards. In areas where no harmonised standards exist or where the standards are insufficient, the Commission could adopt common technical specifications.

54 Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12).

54 Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12). Or. {EN}en Justification Alignment with the changes in article 40.

Amendment 34 Proposal for a regulation Recital 68

Text proposed by the Commission Amendment

(68) Under certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons and the protection of industrial and commercial property, Member States could authorise the placing on the market or putting into service of AI systems which have not undergone a conformity assessment. deleted Or. {EN}en Justification alignment with the deletion of article 47.

Amendment 35 Proposal for a regulation Recital 69

Text proposed by the Commission Amendment

(69) In order to facilitate the work of the Commission and the Member States in the artificial intelligence field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, should be required to register their high-risk AI system in a EU database, to be established and managed by the Commission. The Commission should be the controller of that database, in accordance with Regulation (EU) 2018/1725 of the European Parliament and of the Council55.

In order to ensure the full functionality of the database, when deployed, the procedure for setting the database should include the elaboration of functional specifications by the Commission and an independent audit report. (69) In order to facilitate the work of the Commission and the Member States in the artificial intelligence field as well as to increase the transparency towards the public, providers of high-risk AI systems other than those related to products falling within the scope of relevant existing Union harmonisation legislation, should be required to register their high-risk AI system in a EU database, to be established and managed by the Commission.

Users who are public authorities or Union institutions, bodies, offices and agencies or users acting on their behalf should also register in the EU database before putting into service or using a high-risk AI system. The Commission should be the controller of that database, in accordance with Regulation (EU) 2018/1725 of the European Parliament and of the Council55. In order to ensure the full functionality of the database, when deployed, the procedure for setting the database should include the elaboration of functional specifications by the Commission and an independent audit report.

55 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). 55 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). Or. {EN}en Justification To match changes in article 51.

Amendment 36 Proposal for a regulation Recital 76 Text proposed by the Commission Amendment

(76) In order to facilitate a smooth, effective and harmonised implementation of this Regulation a European Artificial Intelligence Board should be established. The Board should be responsible for a number of advisory tasks, including issuing opinions, recommendations, advice or guidance on matters related to the implementation of this Regulation, including on technical specifications or existing standards regarding the requirements established in this Regulation and providing advice to and assisting the Commission on specific questions related to artificial intelligence.

(76) In order to facilitate a smooth, effective and consistent implementation of this Regulation and to prevent the fragmentation of the internal market, a European Artificial Intelligence Board should be established. The Board should be responsible for a number of advisory tasks, including issuing opinions, recommendations, advice or guidance on matters related to the implementation of this Regulation, including on technical specifications or existing standards regarding the requirements established in this Regulation and providing advice to and assisting the Commission on specific questions related to artificial intelligence, including on possible amendments of the annexes, in particular the annex listing high-risk AI systems.

To contribute to the effective and harmonised enforcement of this Regulation, the Board should also be able to issue recommendations to the relevant national supervisory authorities in order to provide assistance for the settlement of cases involving two or more Member States in which the national competent authorities are in disagreement. Or. {EN}en Justification Alingment with the changes on the governance chapter.

Amendment 37 Proposal for a regulation Recital 76 a (new) Text proposed by the Commission Amendment

(76a) To ensure a common and consistent approach regarding the development and use of AI systems in the various areas and sectors concerned and to ensure synergies and complementarities, the Board should cooperate closely with other relevant institutions, bodies, offices, agencies and boards established at Union level, including the European Data Protection Supervisor, the European Data Protection Board, Data innovation Board set up by... [Data Governance Act] and the European Board for Digital Services established by... [Digital Services Act]. In addition, the Board should regularly consult and work with representatives from industry, SMEs and start-ups and relevant civil society organisations, such as non-governmental organisations (NGOs), consumer associations, the social partners and academia.

Or. {EN}en Amendment 38 Proposal for a regulation Recital 77

Text proposed by the Commission Amendment

(77) Member States hold a key role in the application and enforcement of this Regulation. In this respect, each Member State should designate one or more national competent authorities for the purpose of supervising the application and implementation of this Regulation. In order to increase organisation efficiency on the side of Member States and to set an official point of contact vis-à-vis the public and other counterparts at Member State and Union levels, in each Member State one national authority should be designated as national supervisory authority. (77) Member States hold a key role in the application and enforcement of this Regulation.

In this respect, each Member State should designate one or more national competent authorities for the purpose of supervising the application and implementation of this Regulation. In order to increase organisation efficiency on the side of Member States and to set an official point of contact vis-à-vis the public and other counterparts at Member State and Union levels, in each Member State one single national authority should be designated as national supervisory authority. That national supervisory authority should act as lead authority and should also represent its Member State on the Board.

Where the designated national supervisory authority is not the national data protection authority, the national supervisory authority should act in close cooperation with the national data protection authority, in order to ensure a consistent and efficient implementation of data protection rights and obligations. Or. {EN}en Justification alignment with changes in article 59.

Amendment 39 Proposal for a regulation Recital 78

Text proposed by the Commission Amendment

(78) In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed.

In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents or any breaches to national and Union law protecting fundamental rights resulting from the use of their AI systems. (78) In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place.

This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities, or where relevant, to the Commission, any serious incidents, malfunctioning or any breaches to national and Union law protecting fundamental rights resulting from the use of their AI systems and take appropriate corrective actions.

Users should also report to the relevant authorities or, where relevant, to the Commission, any serious incidents or breaches to national and Union law protecting fundamental rights resulting from the use of their AI system when they become aware of such serious incidents or breaches. Or. {EN}en Justification alignment with article 62.

Amendment 40 Proposal for a regulation Recital 80 a (new) Text proposed by the Commission Amendment

(80a) Given the objectives of this Regulation, namely to ensure an equivalent level of protection of health, safety and fundamental rights of natural persons, to ensure the protection of the Union values enshrined in Article 2 TEU, and to ensure the free movement of AI systems throughout the Union, and taking into account that the mitigation of the risks of AI system against such rights may not be sufficiently achieved at national level or may be subject to diverging interpretation which could ultimately lead to an uneven level of protection of natural persons and create market fragmentation, the Commission should be empowered, on its own initiative or upon recommendation from the Board, to initiate proceedings.

Such proceedings should be initiated where the Commission or the Board have sufficient reasons to believe that an infringement of this Regulation amount to a widespread infringement or a widespread infringement with a Union dimension, or where the AI system presents a risk which affects or is likely to affect at least 45 million individuals within the Union, or where the infringement affects natural persons in at least two Member States and the Member States responsible for enforcing this Regulation have not taken any action. Or. {EN}en Justification to match the new article 68a.

Amendment 41 Proposal for a regulation Recital 80 b (new)

Text proposed by the Commission Amendment (80b) Once the Commission initiates proceedings, the national supervisory authorities of the Member States concerned should be precluded from exercising their investigatory and enforcement powers in respect of the relevant operator or operators, so as to avoid duplication, inconsistencies and risks from the viewpoint of the principle of ne bis in idem. However, in the interest of effectiveness, national supervisory authorities should not be precluded from exercising their power to assist the Commission, on its request in the performance of its tasks, or in respect of other conduct, including conduct by the same operator that is suspected to constitute a new infringement.

National supervisory authorities, as well as the Board and other national competent authorities where relevant, should provide the Commission with all necessary information and assistance to allow it to perform its tasks effectively. The Commission should keep national supervisory authorities informed with regard to the exercise of its powers as appropriate. In that regard, the Commission should, where appropriate, take account of any relevant assessments carried out by the Board or by the national supervisory authorities concerned and of any relevant evidence and information gathered by them, without prejudice to the Commission’s powers and responsibility to carry out additional investigations as necessary. Or.

{EN}en Justification to match new article 68a. Amendment 42 Proposal for a regulation Recital 80 c (new) Text proposed by the Commission Amendment

(80c) In view of both the particular challenges that may arise in seeking to ensure compliance by the relevant operators and the importance of doing so effectively, considering the impact and the harms that their AI systems may cause, the Commission should have strong investigative and enforcement powers to allow it to investigate, enforce and monitor certain of the rules laid down in this Regulation, in full respect of the principle of proportionality and the rights and interests of the affected parties.

Or. {EN}en Justification to match new article 68b. Amendment 43 Proposal for a regulation Recital 80 d (new) Text proposed by the Commission Amendment

(80d) The Commission should have access to any relevant documents, information and data necessary to open and conduct investigations and to monitor the compliance with this Regulation, regardless of their form or format or the manner or location of their storage. The Commission should be able to directly require the operators concerned to provide any relevant evidence, information and data. In addition, the Commission should be able to request any relevant information from any public authority, body or agency within the Member States, or from any natural or legal person for the purpose of this Regulation.

The Commission should be empowered to require access to, and explanations relating to, databases, algorithms and source codes, to interview, upon their consent, any persons who may be in possession of useful information and to record the statements made. The Commission should be able to carry out the necessary remote and on-site inspections, and should have the power to enter any premises, land or means of transport that the economic operator uses for purposes relating to its trade, business, craft or profession. The Commission should also be empowered to undertake such inspections as are necessary to enforce this Regulation.

Where the Commission finds out that the operator or operators concerned do not comply with this Regulation, it should be empowered to adopt decisions and impose fines. Where there is a risk of serious and irreparable harm to natural persons due to non-compliance, the Commission should be able to take measures, where duly justified and proportionate and where there are no other means available to prevent or mitigate such harm. Those investigatory and enforcement powers aim to complement the Commission’s possibility to ask the national supervisory authority and other Member States’ authorities for assistance, for instance by providing information or in the exercise of those powers. Or. {EN}en Justification to match new article 68b.

Amendment 44 Proposal for a regulation Recital 83

Text proposed by the Commission Amendment

(83) In order to ensure trustful and constructive cooperation of competent authorities on Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks.

(83) In order to ensure trustful and constructive cooperation of competent authorities on Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks. The relevant competent authorities should put in place adequate cybersecurity and organisational measures to protect the security and confidentiality of the information and data obtained in carrying out their tasks and activities. Or. {EN}en Justification to match the changes in article 70.

Amendment 45 Proposal for a regulation Recital 84 a (new)

Text proposed by the Commission Amendment (84a) Compliance with this Regulation should be enforceable by means of the imposition of fines by the Commission when carrying out proceedings under the procedure laid down in this Regulation. To that end, appropriate levels of fines should also be laid down for non-compliance with the obligations and for breaches of the procedural rules, subject to appropriate limitation periods.

Or. {EN}en Justification to match the new enforcement powers given to the Commission in the enforcement chapter. Amendment 46 Proposal for a regulation Recital 84 b (new) Text proposed by the Commission Amendment

(84b) Natural and legal persons and groups of natural or legal persons should be entitled to access proportionate and effective remedies. They should in particular have the right to lodge a complaint against the providers or users of AI systems and receive compensation against any direct damage or loss they have with regard to their health, safety, or fundamental rights, due to an infringement of this Regulation by the provider or the user. Without prejudice to any other administrative or non-judicial remedy, natural and legal persons and groups of natural or legal persons should also have the right to an effective judicial remedy with regard to a legally binding decision of a national supervisory authority or of the Commission concerning them or, where the national supervisory authority does not handle a complaint, does not inform the complainant of the progress or preliminary outcome of the complaint lodged or does not comply with its obligation to reach a final decision, with regard to the complaint.

Or. {EN}en Justification to match the new provisions on redress. Amendment 47 Proposal for a regulation Article 1 – paragraph 1 – point a

Text proposed by the Commission Amendment

(a) harmonised rules for the placing on the market, the putting into service and the use of artificial intelligence systems (‘AI systems’) in the Union;

(a) harmonised rules for the development, the placing on the market, the putting into service and the use of artificial intelligence systems (‘AI systems’) in the Union; Or. {EN}en Amendment 48 Proposal for a regulation Article 1 – paragraph 1 – point c a (new) Text proposed by the Commission Amendment

(ca) harmonised rules on high-risk AI systems to ensure a high level of trustworthiness and of protection of health, safety, fundamental rights and the Union values enshrined in Article 2 TEU; Or. {EN}en Amendment 49 Proposal for a regulation Article 1 – paragraph 1 – point d

Text proposed by the Commission Amendment

(d) harmonised transparency rules for AI systems intended to interact with natural persons, emotion recognition systems and biometric categorisation systems, and AI systems used to generate or manipulate image, audio or video content;

(d) harmonised transparency rules for AI systems; Or. {EN}en Amendment 50 Proposal for a regulation Article 2 – paragraph 1 – point a

Text proposed by the Commission Amendment

(a) providers placing on the market or putting into service AI systems in the Union, irrespective of whether those providers are established within the Union or in a third country;

(a) operators placing on the market or putting into service AI systems in the Union, irrespective of whether those operators are established within the Union or in a third country; Or. {EN}en Amendment 51 Proposal for a regulation Article 2 – paragraph 1 – point c

Text proposed by the Commission Amendment

(c) providers and users of AI systems that are located in a third country, where the output produced by the system is used in the Union;

(c) providers and users of AI systems that are located in a third country, where the output produced by the system is used in the Union or affects natural persons within the Union; Or. {EN}en Amendment 52 Proposal for a regulation Article 2 – paragraph 1 – point c a (new) Text proposed by the Commission Amendment

(ca) natural persons affected by the use of an AI system. Or. {EN}en Amendment 53 Proposal for a regulation Article 2 – paragraph 3 a (new) Text proposed by the Commission Amendment 3a. This Regulation shall also apply to Union institutions, offices, bodies and agencies when acting as a provider or user of an AI system.

Or. {EN}en Amendment 54 Proposal for a regulation Article 2 – paragraph 5 a (new) Text proposed by the Commission Amendment

5a. Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation. This Regulation shall not affect Regulation (EU) 2016/679, Regulation (EU) 2018/1725, Directive 2002/58/EC or Directive (EU) 2016/680.

Or. {EN}en Amendment 55 Proposal for a regulation Article 3 – paragraph 1 – point 1

Text proposed by the Commission Amendment

(1) ‘artificial intelligence system’ (AI system) means software that is developed with one or more of the techniques and approaches listed in Annex I and can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations, or decisions influencing the environments they interact with;

(1) ‘artificial intelligence system’ (AI system) means software that is developed with one or more of the techniques and approaches listed in Annex I and can, for a given set of objectives, generate outputs such as content, predictions, hypotheses, recommendations, or decisions influencing the environments they interact with; Or. {EN}en Amendment 56 Proposal for a regulation Article 3 – paragraph 1 – point 4

Text proposed by the Commission Amendment

(4) ‘user’ means any natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity;

(4) ‘user’ means any natural or legal person, public authority, agency or other body using an AI system under its authority and in the course of its professional activity; Or. {EN}en Amendment 57 Proposal for a regulation Article 3 – paragraph 1 – point 14

Text proposed by the Commission Amendment

(14) ‘safety component of a product or system’ means a component of a product or of a system which fulfils a safety function for that product or system or the failure or malfunctioning of which endangers the health and safety of persons or property;

(14) ‘safety component of a product or system’ means a component of a product or of a system which fulfils a safety or security function for that product or system or the failure or malfunctioning of which endangers the health and safety or the fundamental rights of natural persons or which damages property; Or. {EN}en Amendment 58 Proposal for a regulation Article 3 – paragraph 1 – point 15

Text proposed by the Commission Amendment

(15) ‘instructions for use’ means the information provided by the provider to inform the user of in particular an AI system’s intended purpose and proper use, inclusive of the specific geographical, behavioural or functional setting within which the high-risk AI system is intended to be used;

(15) ‘instructions for use’ means the information provided by the provider, on a durable medium, to inform the user of in particular an AI system’s intended purpose and proper use, as well as information on any precautions to be taken, inclusive of the specific geographical, behavioural or functional setting within which the high-risk AI system is intended to be used; Or. {EN}en Amendment 59 Proposal for a regulation Article 3 – paragraph 1 – point 16

Text proposed by the Commission Amendment

(16) ‘recall of an AI system’ means any measure aimed at achieving the return to the provider of an AI system made available to users;

(16) ‘recall of an AI system’ means any measure aimed at achieving the return to the provider of an AI system that has been made available to users; Or. {EN}en Amendment 60 Proposal for a regulation Article 3 – paragraph 1 – point 22

Text proposed by the Commission Amendment

(22) ‘notified body’ means a conformity assessment body designated in accordance with this Regulation and other relevant Union harmonisation legislation;

(22) ‘notified body’ means a conformity assessment body notified in accordance with Article 32 of this Regulation and with other relevant Union harmonisation legislation; Or. {EN}en Amendment 61 Proposal for a regulation Article 3 – paragraph 1 – point 23

Text proposed by the Commission Amendment

(23) ‘substantial modification’ means a change to the AI system following its placing on the market or putting into service which affects the compliance of the AI system with the requirements set out in Title III, Chapter 2 of this Regulation or results in a modification to the intended purpose for which the AI system has been assessed;

(23) ‘substantial modification’ means a change or a series of changes to the AI system following its placing on the market or putting into service which affects the compliance of the AI system with the requirements set out in Title III, Chapter 2 of this Regulation or results in a modification to the intended purpose for which the AI system has been assessed or to its performance; Or. {EN}en Amendment 62 Proposal for a regulation Article 3 – paragraph 1 – point 30

Text proposed by the Commission Amendment

(30) ‘validation data’ means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process, among other things, in order to prevent overfitting; whereas the validation dataset can be a separate dataset or part of the training dataset, either as a fixed or variable split;

(30) ‘validation data’ means data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process, among other things, in order to prevent underfitting or overfitting; whereas the validation dataset can be a separate dataset or part of the training dataset, either as a fixed or variable split; Or. {EN}en Amendment 63 Proposal for a regulation Article 3 – paragraph 1 – point 33

Text proposed by the Commission Amendment

(33) ‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;

(33) ‘biometric data’ means biometric data as defined in Article 4, point (14) of Regulation (EU) 2016/679; Or. {EN}en Amendment 64 Proposal for a regulation Article 3 – paragraph 1 – point 33 a (new) Text proposed by the Commission Amendment

(33a) ‘biometrics-based data’ means data resulting from specific technical processing relating to physical, physiological or behavioural signals of a natural person, such as facial expressions, movements, pulse frequency, voice, key strikes or gait, which may or may not allow or confirm the unique identification of a natural person;

Or. {EN}en Amendment 65 Proposal for a regulation Article 3 – paragraph 1 – point 33 b (new) Text proposed by the Commission Amendment

(33b) ‘subliminal techniques’ means techniques that use sensorial stimuli such as images, text, or sounds, that are below or above the threshold of conscious human perception; Or. {EN}en Amendment 66 Proposal for a regulation Article 3 – paragraph 1 – point 33 c (new) Text proposed by the Commission Amendment (33c) ‘special categories of personal data’ means the categories of personal data referred to in Article 9(1) of Regulation (EU)2016/679;

Or. {EN}en Amendment 67 Proposal for a regulation Article 3 – paragraph 1 – point 34

Text proposed by the Commission Amendment

(34) ‘emotion recognition system’ means an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data;

(34) ‘emotion recognition system’ means an AI system for the purpose of identifying or inferring emotions, thoughts, states of mind or intentions of natural persons on the basis of their biometric and biometric-based data; Or. {EN}en Amendment 68 Proposal for a regulation Article 3 – paragraph 1 – point 35

Text proposed by the Commission Amendment

(35) ‘biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories, such as sex, age, hair colour, eye colour, tattoos, ethnic origin or sexual or political orientation, on the basis of their biometric data;

(35) ‘biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories, such as gender, sex, age, hair colour, eye colour, tattoos, ethnic origin, health, mental or physical ability, behavioural or personality traits or sexual or political orientation, on the basis of their biometric and biometric-based data; Or. {EN}en Amendment 69 Proposal for a regulation Article 3 – paragraph 1 – point 42

Text proposed by the Commission Amendment

(42) ‘national supervisory authority’ means the authority to which a Member State assigns the responsibility for the implementation and application of this Regulation, for coordinating the activities entrusted to that Member State, for acting as the single contact point for the Commission, and for representing the Member State at the European Artificial Intelligence Board;

(42) ‘national supervisory authority’ means a public authority to which a Member State assigns the responsibility for the implementation and application of this Regulation, for coordinating the activities entrusted to that Member State, for acting as the single contact point for the Commission, and for representing the Member State at the European Artificial Intelligence Board; Or. {EN}en Amendment 70 Proposal for a regulation Article 3 – paragraph 1 – point 44 – introductory part

Text proposed by the Commission Amendment

(44) ‘serious incident’ means any incident that directly or indirectly leads, might have led or might lead to any of the following:

(44) ‘serious incident’ means any incident or malfunctioning that directly or indirectly leads, might have led or might lead to any of the following: Or. {EN}en Amendment 71 Proposal for a regulation Article 3 – paragraph 1 – point 44 a (new) Text proposed by the Commission Amendment

(44a) 'personal data' means personal data as defined in Article 4, point (1) of Regulation (EU)2016/679; Or. {EN}en Amendment 72 Proposal for a regulation Article 3 – paragraph 1 – point 44 b (new) Text proposed by the Commission Amendment (44b) ‘non-personal data’ means data other than personal data;

Or. {EN}en Amendment 73 Proposal for a regulation Article 3 – paragraph 1 – point 44 c (new) Text proposed by the Commission Amendment

(44c) ‘risk’ means the combination of the probability of an occurrence of a hazard causing harm and the degree of severity of that harm; Or. {EN}en Amendment 74 Proposal for a regulation Article 3 – paragraph 1 – point 44 d (new) Text proposed by the Commission Amendment (44d) ‘widespread infringement’ means:

(a) any act or omission contrary to Union law that protects the interests of individuals, that has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State, in which:

(i) the act or omission originated or took place;

(ii) the provider concerned, or, where applicable, its authorised representative is established; or,

(iii) the user is established, when the infringement is committed by the user;

(b) any acts or omissions contrary to Union law that protects the interests of individuals, that have done, do or are likely to do harm to the collective interests of individuals and that have common features, including the same unlawful practice, the same interest being infringed and that are occurring concurrently, committed by the same operator, in at least three Member States; Or. {EN}en Justification A definition of widespread infringement has been introduced to clarify the conditions triggering the Commission’s intervention in the enforcement chapter. The concept is taken from Regulation (EU) 2017/2394 of the European Parliament and of the Council of 12 December 2017 on cooperation between national authorities responsible for the enforcement of consumer protection laws and adapted to this Regulation.

Amendment 75 Proposal for a regulation Article 3 – paragraph 1 – point 44 e (new)

Text proposed by the Commission Amendment (44e) ‘widespread infringement with a Union dimension’ means a widespread infringement that has harmed or is likely to harm the collective interests of individuals in at least two-thirds of the Member States, accounting, together, for at least two-thirds of the population of the Union.

Or. {EN}en Amendment 76 Proposal for a regulation Article 5 – paragraph 1 – point c a (new) Text proposed by the Commission Amendment

(ca) the placing on the market, putting into service or use of an AI system for making individual risk assessments of natural persons in order to assess the risk of a natural person for offending or reoffending or for predicting the occurrence or reoccurrence of an actual or potential criminal offence based on profiling of a natural person or on assessing personality traits and characteristics or past criminal behaviour of natural persons or groups of natural persons; Or. {EN}en Justification Predictive policing violates human dignity and the presumption of innocence, and it holds a particular risk of discrimination. It is therefore inserted among the prohibited practices.

Amendment 77 Proposal for a regulation Article 5 – paragraph 4 a (new)

Text proposed by the Commission Amendment 4a. This Article shall not affect the prohibitions that apply where an artificial intelligence practice infringes other law, including data protection law, non-discrimination law, consumer protection law or competition law. Or. {EN}en Amendment 78 Proposal for a regulation Article 7 – paragraph 1 – point a Text proposed by the Commission Amendment

(a) the AI systems are intended to be used in any of the areas listed in points 1 to 8 of Annex III; deleted Or. {EN}en Amendment 79 Proposal for a regulation Article 7 – paragraph 1 – point b

Text proposed by the Commission Amendment

(b) the AI systems pose a risk of harm to the health and safety, or a risk of adverse impact on fundamental rights, that is, in respect of its severity and probability of occurrence, equivalent to or greater than the risk of harm or of adverse impact posed by the high-risk AI systems already referred to in Annex III. deleted Or. {EN}en Amendment 80 Proposal for a regulation Article 7 – paragraph 1 a (new) Text proposed by the Commission Amendment

1a. The Commission is empowered to adopt delegated acts in accordance with Article 73 to amend Annex III by adding areas of high-risk AI systems, where a type of AI system poses a risk of harm to health and safety, a risk of adverse impact on fundamental rights, or a risk of contravention of the Union values enshrined in Article 2 TEU and that risk is, in respect of its severity and probability of occurrence, equivalent to or greater than the risk of harm or of adverse impact posed by high-risk AI systems in use in the areas listed in Annex III.

Or. {EN}en Amendment 81 Proposal for a regulation Article 7 – paragraph 2 – introductory part Text proposed by the Commission Amendment

Or. {EN}en Amendment 82 Proposal for a regulation Article 7 – paragraph 2 – point b

Text proposed by the Commission Amendment

(b) the extent to which an AI system has been used or is likely to be used;

(b) the extent to which an AI system has been used or is likely to be used, including its reasonably foreseeable misuse; Or. {EN}en Amendment 83 Proposal for a regulation Article 7 – paragraph 2 – point b a (new) Text proposed by the Commission Amendment

(ba) the type and nature of the data processed and used by the AI system; Or. {EN}en Amendment 84 Proposal for a regulation Article 7 – paragraph 2 – point c

Text proposed by the Commission Amendment

(c) the extent to which the use of an AI system has already caused harm to the health and safety or adverse impact on the fundamental rights or has given rise to significant concerns in relation to the materialisation of such harm or adverse impact, as demonstrated by reports or documented allegations submitted to national competent authorities;

(c) the extent to which the use of an AI system has already caused harm to natural persons, has contravened the Union values enshrined in Article 2 TEU, has caused harm to health and safety, has had an adverse impact on fundamental rights or has given rise to significant concerns in relation to the materialisation of such harm or adverse impact, as demonstrated by reports or documented allegations submitted to national competent authorities, to the Commission, to the Board, to the EDPS or to the European Union Agency for Fundamental Rights (FRA); Or. {EN}en Amendment 85 Proposal for a regulation Article 7 – paragraph 2 – point d

Text proposed by the Commission Amendment

(d) the potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect a plurality of persons;

(d) the potential extent of such harm or such adverse impact, in particular in terms of its intensity and its ability to affect a plurality of persons or to disproportionately affect a particular group of persons; Or. {EN}en Amendment 86 Proposal for a regulation Article 7 – paragraph 2 – point g

Text proposed by the Commission Amendment

(g) the extent to which the outcome produced with an AI system is easily reversible, whereby outcomes having an impact on the health or safety of persons shall not be considered as easily reversible;

(g) the extent to which the outcome produced with an AI system is easily reversible, whereby outcomes having an impact on health, safety, fundamental rights of persons, or on the Union values enshrined in Article 2 TEU shall not be considered as easily reversible; Or. {EN}en Amendment 87 Proposal for a regulation Article 7 – paragraph 2 a (new) Text proposed by the Commission Amendment

2a. When assessing whether an AI system poses a risk of harm to the health and safety or risk of adverse impact on fundamental rights that is equivalent or greater than the risk of harm posed by the high-risk AI system, the Commission shall consult, where relevant, representatives of groups on which an AI system has an impact, industry, independent experts and civil society organisations. The Commission shall organise public consultations in this regard.

Or. {EN}en Amendment 88 Proposal for a regulation Article 7 – paragraph 2 b (new) Text proposed by the Commission Amendment

2b. The Commission shall publish a detailed report on the assessment referred to in paragraph 2. Or. {EN}en Amendment 89 Proposal for a regulation Article 7 – paragraph 2 c (new) Text proposed by the Commission Amendment 2c. The Commission shall consult the Board before drafting delegated acts pursuant to paragraph 1.

Or. {EN}en Amendment 90 Proposal for a regulation Article 9 – paragraph 2 – point a

Text proposed by the Commission Amendment

(a) identification and analysis of the known and foreseeable risks associated with each high-risk AI system;

(a) identification and analysis of the known and the reasonably foreseeable risks that the high-risk AI system can pose to:

(i) the health or safety of natural persons;

(ii) the legal rights or legal status of natural persons;

(iii) the fundamental rights of natural persons;

(iv) the equal access to services and opportunities of natural persons;

(v) the Union values enshrined in Article 2 TEU. Or. {EN}en Amendment 91 Proposal for a regulation Article 9 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 92 Proposal for a regulation Article 9 – paragraph 4 – subparagraph 3

Text proposed by the Commission Amendment In eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, training to be expected by the user and the environment in which the system is intended to be used.

In eliminating or reducing risks related to the use of the high-risk AI system, due consideration shall be given to the technical knowledge, experience, education, training to be expected by the user and the environment, including possible context, in which the system is intended to be used. Or. {EN}en Amendment 93 Proposal for a regulation Article 9 – paragraph 6 Text proposed by the Commission Amendment

Or. {EN}en Amendment 94 Proposal for a regulation Article 10 – paragraph 2 – point c

Text proposed by the Commission Amendment

(c) relevant data preparation processing operations, such as annotation, labelling, cleaning, enrichment and aggregation;

(c) relevant data preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation; Or. {EN}en Amendment 95 Proposal for a regulation Article 10 – paragraph 2 – point f a (new) Text proposed by the Commission Amendment

(fa) appropriate measures to detect, prevent and mitigate possible biases; Or. {EN}en Amendment 96 Proposal for a regulation Article 10 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 97 Proposal for a regulation Article 10 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 98 Proposal for a regulation Article 10 – paragraph 5

Text proposed by the Commission

Amendment

deleted Or. {EN}en Justification This Regulation should not constitute a separate legal basis for processing personal data. Amendment 99 Proposal for a regulation Article 10 – paragraph 6 a (new)

Text proposed by the Commission Amendment 6a. Where the provider cannot comply with the obligations laid down in this Article because it does not have access to the data and the data is held exclusively by the user, the user may, on the basis of a contract, be made responsible for any infringement of this Article.

Or. {EN}en Amendment 100 Proposal for a regulation Article 10 – paragraph 6 b (new) Text proposed by the Commission Amendment

6b. The principles of data minimisation and of data protection by design and by default, as referred to, respectively, in Article 5(1), point (c) and in Article 25 of Regulation (EU) 2016/679 shall be applied when developing and using high-risk AI systems and during the entire lifecycle of those systems.

Or. {EN}en Amendment 101 Proposal for a regulation Article 11 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 102 Proposal for a regulation Article 12 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 103 Proposal for a regulation Article 12 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 104 Proposal for a regulation Title III – Chapter 3 – title

Text proposed by the Commission Amendment OBLIGATIONS OF PROVIDERS AND USERS OF HIGH-RISK AI SYSTEMS and other parties OBLIGATIONS OF PROVIDERS, USERS OF HIGH-RISK AI SYSTEMS and other parties Or. {EN}en Amendment 105 Proposal for a regulation Article 16 – paragraph 1 – point a a (new) Text proposed by the Commission Amendment

(aa) ensure that natural persons to whom human oversight of high-risk AI systems is assigned are specifically made aware and remain aware of the risk of automation bias; Or. {EN}en Amendment 106 Proposal for a regulation Article 16 – paragraph 1 – point d

Text proposed by the Commission Amendment

(d) when under their control, keep the logs automatically generated by their high-risk AI systems;

(d) when under their control, keep the logs automatically generated by their high-risk AI systems that are required for ensuring and demonstrating compliance with this Regulation, for ex-post audits of any reasonably foreseeable malfunction or misuses of the system, or for ensuring and monitoring for the proper functioning of the system throughout its entire lifecycle; Or. {EN}en Amendment 107 Proposal for a regulation Article 16 – paragraph 1 – point e

Text proposed by the Commission Amendment

(e) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure, prior to its placing on the market or putting into service;

(e) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure, prior to its placing on the market or putting into service, in accordance with Article 43; Or. {EN}en Amendment 108 Proposal for a regulation Article 16 – paragraph 1 – point e a (new) Text proposed by the Commission Amendment

(ea) draw up an EU declaration of conformity in accordance with Article 48; Or. {EN}en Amendment 109 Proposal for a regulation Article 16 – paragraph 1 – point e b (new) Text proposed by the Commission Amendment

(eb) affix the CE marking to their high-risk AI systems to indicate conformity with this Regulation in accordance with Article 49; Or. {EN}en Justification moved up from letter i Amendment 110 Proposal for a regulation Article 16 – paragraph 1 – point g

Text proposed by the Commission Amendment

(g) take the necessary corrective actions, if the high-risk AI system is not in conformity with the requirements set out in Chapter 2 of this Title;

(g) take the necessary corrective actions as referred to in Article 21 and provide information in that regard; Or. {EN}en Amendment 111 Proposal for a regulation Article 16 – paragraph 1 – point h

Text proposed by the Commission Amendment

(h) inform the national competent authorities of the Member States in which they made the AI system available or put it into service and, where applicable, the notified body of the non-compliance and of any corrective actions taken; deleted Or. {EN}en Amendment 112 Proposal for a regulation Article 16 – paragraph 1 – point i

Text proposed by the Commission Amendment

(i) to affix the CE marking to their high-risk AI systems to indicate the conformity with this Regulation in accordance with Article 49; deleted Or. {EN}en Amendment 113 Proposal for a regulation Article 17 – paragraph 1 – introductory part

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 114 Proposal for a regulation Article 17 – paragraph 1 – point j

Text proposed by the Commission Amendment

(j) the handling of communication with national competent authorities, competent authorities, including sectoral ones, providing or supporting the access to data, notified bodies, other operators, customers or other interested parties;

(j) the handling of communication with relevant competent authorities, including sectoral ones, providing or supporting the access to data, notified bodies, other operators, customers or other interested parties; Or. {EN}en Amendment 115 Proposal for a regulation Article 17 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Justification The size of the company needs to be taken into account but should not justify less rigour for compliance. Amendment 116 Proposal for a regulation

Article 19

Text proposed by the Commission Amendment

Article 19 — deleted

Conformity assessment

Or. {EN}en Justification Paragraph 1 of this article has been moved up to art. 16(e) and (ea), while paragraph 2 is already in article 43.2. Amendment 117 Proposal for a regulation Article 21 – paragraph 1

Text proposed by the Commission Amendment Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system which they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system in question and, where applicable, the authorised representative and importers accordingly.

Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system which they have placed on the market or put into service is not in conformity with this Regulation shall immediately and without delay take the necessary corrective actions to bring that system into conformity, to withdraw it or to recall it, as appropriate.

Or. {EN}en Amendment 118 Proposal for a regulation Article 21 – paragraph 1 a (new)

Text proposed by the Commission Amendment In the cases referred to in paragraph 1, providers shall immediately inform the distributors of the high-risk AI system and, where applicable, the authorised representative, importers and users accordingly. They shall also immediately inform the national competent authorities of the Member States in which they made the AI system available or put it into service, and where applicable, the notified body of the non-compliance and of any corrective actions taken.

Or. {EN}en Amendment 119 Proposal for a regulation Article 22 – paragraph 1

Text proposed by the Commission Amendment Where the high-risk AI system presents a risk within the meaning of Article 65(1) and that risk is known to the provider of the system, that provider shall immediately inform the national competent authorities of the Member States in which it made the system available and, where applicable, the notified body that issued a certificate for the high-risk AI system, in particular of the non-compliance and of any corrective actions taken.

Where the high-risk AI system presents a risk and that risk is known to the provider of the system, that provider shall immediately inform the national competent authorities of the Member States in which it made the system available and, where applicable, the notified body that issued a certificate for the high-risk AI system, in particular of the non-compliance and of any corrective actions taken. Where applicable, the provider shall also inform the users of the high-risk AI system.

Or. {EN}en Amendment 120 Proposal for a regulation Article 23 – title

Text proposed by the Commission Amendment Cooperation with competent authorities Cooperation with competent authorities, the Board and the Commission Or. {EN}en Amendment 121 Proposal for a regulation Article 23 – paragraph 1

Text proposed by the Commission Amendment Providers of high-risk AI systems shall, upon request by a national competent authority, provide that authority with all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Chapter 2 of this Title, in an official Union language determined by the Member State concerned. Upon a reasoned request from a national competent authority, providers shall also give that authority access to the logs automatically generated by the high-risk AI system, to the extent such logs are under their control by virtue of a contractual arrangement with the user or otherwise by law.

Providers and where applicable, users of high-risk AI systems shall, upon request by a national competent authority or where applicable, by the Board or the Commission, provide them with all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Chapter 2 of this Title, in an official Union language determined by the Member State concerned.

Or. {EN}en Amendment 122 Proposal for a regulation Article 23 – paragraph 1 a (new)

Text proposed by the Commission Amendment Upon a reasoned request by a national competent authority or, where applicable, by the Commission, providers and, where applicable, users shall also give the requesting national competent authority or the Commission, as applicable, access to the logs automatically generated by the high-risk AI system, to the extent such logs are under their control by virtue of a contractual arrangement with the user or otherwise by law.

Or. {EN}en Amendment 123 Proposal for a regulation Article 25 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 124 Proposal for a regulation Article 25 – paragraph 2 – introductory part Text proposed by the Commission Amendment

Or. {EN}en Amendment 125 Proposal for a regulation Article 25 – paragraph 2 – point c

Text proposed by the Commission Amendment

(c) cooperate with competent national authorities, upon a reasoned request, on any action the latter takes in relation to the high-risk AI system.

(c) cooperate with national competent authorities, upon a reasoned request, on any action the latter takes in relation to the high-risk AI system. Or. {EN}en Amendment 126 Proposal for a regulation Article 25 – paragraph 2 – point c a (new) Text proposed by the Commission Amendment

(ca) where applicable, comply with the registration obligations referred in Article 51. Or. {EN}en Amendment 127 Proposal for a regulation Article 26 – paragraph 1 – point b Text proposed by the Commission Amendment

(b) the provider has drawn up the technical documentation in accordance with Annex IV;

(b) the provider has drawn up the technical documentation in accordance with Article 11 and Annex IV; Or. {EN}en Amendment 128 Proposal for a regulation Article 26 – paragraph 1 – point c a (new) Text proposed by the Commission Amendment

(ca) where applicable, the provider has appointed an authorised representative in accordance with Article 25(1). Or. {EN}en Amendment 129 Proposal for a regulation Article 27 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 130 Proposal for a regulation Article 27 – paragraph 5 Text proposed by the Commission Amendment

Or. {EN}en Amendment 131 Proposal for a regulation Article 28 – paragraph 1 – point a

Text proposed by the Commission Amendment

(a) they place on the market or put into service a high-risk AI system under their name or trademark;

(a) they place on the market or put into service a high-risk AI system under their name or trademark unless a contractual arrangement provides otherwise with regard to the allocation of obligations, where applicable; Or. {EN}en Amendment 132 Proposal for a regulation Article 28 – paragraph 1 – point b a (new) Text proposed by the Commission Amendment

(ba) they modify the intended purpose of an AI system placed on the market or put into service in such manner that the AI system becomes a high risk AI system in accordance with Article 6; Or. {EN}en Amendment 133 Proposal for a regulation Article 28 – paragraph 1 – point c Text proposed by the Commission Amendment

(c) they make a substantial modification to the high-risk AI system.

(c) they make a substantial modification to a high-risk AI system. Or. {EN}en Amendment 134 Proposal for a regulation Article 28 – paragraph 1 – point c a (new) Text proposed by the Commission Amendment

(ca) they make a substantial modification to an AI system in such manner that the AI system becomes a high risk AI system; Or. {EN}en Amendment 135 Proposal for a regulation Article 28 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 136 Proposal for a regulation Article 29 – paragraph 1 a (new) Text proposed by the Commission Amendment

1a. Where relevant, users of high-risk AI systems shall comply with the human oversight requirements laid down in this Regulation. Or. {EN}en Amendment 137 Proposal for a regulation Article 29 – paragraph 1 b (new) Text proposed by the Commission Amendment

1b. Users of high-risk AI systems shall ensure that natural persons assigned to ensure human oversight for high-risk AI systems are competent, properly qualified and trained and have the necessary resources in order to ensure the effective supervision of the system in accordance with Article 14; Or. {EN}en Amendment 138 Proposal for a regulation Article 29 – paragraph 1 c (new) Text proposed by the Commission Amendment

1c. Users of high-risk AI systems shall ensure that the natural persons entrusted with the human oversight of the high-risk AI are competent, properly qualified and trained and have the necessary resources in order to ensure the effective supervision of the AI system in accordance with Article 14. Or. {EN}en Amendment 139 Proposal for a regulation Article 29 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 140 Proposal for a regulation Article 29 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 141 Proposal for a regulation Article 29 – paragraph 4 – subparagraph 1 Text proposed by the Commission Amendment Users shall monitor the operation of the high-risk AI system on the basis of the instructions of use.

When they have reasons to consider that the use in accordance with the instructions of use may result in the AI system presenting a risk within the meaning of Article 65(1) they shall inform the provider or distributor and suspend the use of the system. They shall also inform the provider or distributor when they have identified any serious incident or any malfunctioning within the meaning of Article 62 and interrupt the use of the AI system. In case the user is not able to reach the provider, Article 62 shall apply mutatis mutandis. Users shall monitor the operation of the high-risk AI system on the basis of the instructions of use.

When they have reasons to consider that the use in accordance with the instructions of use may result in the AI system presenting a risk within the meaning of Article 65(1) they shall immediately inform the provider or distributor and suspend the use of the system. They shall also immediately inform the provider or distributor when they have identified any serious incident or any malfunctioning within the meaning of Article 62 and interrupt the use of the AI system. In case the user is not able to reach the provider, Article 62 shall apply mutatis mutandis. Or. {EN}en Amendment 142 Proposal for a regulation Article 29 – paragraph 5 – subparagraph 1

Text proposed by the Commission Amendment Users of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system, to the extent such logs are under their control. The logs shall be kept for a period that is appropriate in the light of the intended purpose of the high-risk AI system and applicable legal obligations under Union or national law.

Users of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system, to the extent that such logs are under their control and are required for ensuring and demonstrating compliance with this Regulation, forex-post audits of any reasonably foreseeable malfunction, incidents or misuses of the system, or for ensuring and monitoring for the proper functioning of the system throughout its lifecycle. The logs shall be kept for a period that is appropriate in light of the intended purpose of the high-risk AI system and applicable legal obligations under Union or national law.

Or. {EN}en Amendment 143 Proposal for a regulation Article 29 – paragraph 5 a (new)

Text proposed by the Commission Amendment 5a. Users of high-risk AI systems that are public authorities or Union institutions, bodies, offices and agencies shall comply with the registration obligations referred to in Article 51. Or. {EN}en Amendment 144 Proposal for a regulation Article 29 – paragraph 6

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 145 Proposal for a regulation Article 29 – paragraph 6 a (new) Text proposed by the Commission Amendment

6a. Users of high-risk AI systems referred to in Annex III, which make decisions or assist in making decisions related to natural persons, shall inform the natural persons that they are subject to the use of the high-risk AI system. Or. {EN}en Amendment 146 Proposal for a regulation Article 29 – paragraph 6 b (new) Text proposed by the Commission Amendment

6b. Users of AI systems that generate, on the basis of limited human input, complex text content, such as news articles, opinion articles, novels, scripts, and scientific articles, shall disclose that the text content has been artificially generated or manipulated, including to the natural persons who are exposed to the content, each time they are exposed, in a clear and intelligible manner.

Or. {EN}en Amendment 147 Proposal for a regulation Article 29 a (new) Text proposed by the Commission Amendment

Article 29a — Notification

Member States shall notify the Commission and the other Member States of conformity assessment bodies. Or. {EN}en (Article 29a is inserted in Chapter 4 before Article 30) Amendment 148 Proposal for a regulation Article 32 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 149 Proposal for a regulation Article 32 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 150 Proposal for a regulation Article 32 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 151 Proposal for a regulation Article 33 – paragraph 7 Text proposed by the Commission Amendment

Or. {EN}en Justification Reflecting Decision No 768/2008/EC of the European Parliament and of the Council on a common framework for the marketing of products, Article R27. Amendment 152 Proposal for a regulation Article 34 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 153 Proposal for a regulation Article 34 – paragraph 4

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 154 Proposal for a regulation Article 35 – title Text proposed by the Commission Amendment Identification numbers and lists of notified bodies designated under this Regulation Identification numbers and lists of notified bodies Or. {EN}en Amendment 155 Proposal for a regulation Article 36 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 156 Proposal for a regulation Article 37 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 157 Proposal for a regulation Article 37 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 158 Proposal for a regulation Article 37 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 159 Proposal for a regulation Article 39 a (new) Text proposed by the Commission Amendment

Article 39a — Exchange of knowhow and best practices

The Commission shall provide for the exchange of knowhow and best practices between the Member States' national authorities responsible for notification policy. Or. {EN}en Amendment 160 Proposal for a regulation Article 40 – paragraph 1 a (new) Text proposed by the Commission Amendment The standardisation process shall ensure a balanced representation of interests and effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.

Or. {EN}en Amendment 161 Proposal for a regulation Article 41 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 162 Proposal for a regulation Article 44 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 163 Proposal for a regulation Article 45 – paragraph 1

Text proposed by the Commission Amendment Member States shall ensure that an appeal procedure against decisions of the notified bodies is available to parties having a legitimate interest in that decision. Member States shall ensure that an appeal procedure against decisions of the notified bodies, including on issued conformity certificates, is available to parties having a legitimate interest in that decision Or. {EN}en Amendment 164 Proposal for a regulation

Article 47

Text proposed by the Commission Amendment [...] deleted Or. {EN}en Justification The public interest reasons indicated in the Article do not justify a derogation from the conformity assessment for urgency reasons. To the contrary, putting into service a high-risk AI system intended to address the indicated concerns without performing a conformity assessment risks aggravating those concerns, if the system is biased, inaccurate, or exposed to vulnerabilities.

Amendment 165 Proposal for a regulation Article 48 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Justification The declaration of conformity already contains the identification of the high-risk AI system pursuant to Annex V. Amendment 166 Proposal for a regulation Article 48 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 167 Proposal for a regulation Article 48 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 168 Proposal for a regulation Article 49 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 169 Proposal for a regulation Article 49 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 170 Proposal for a regulation Article 49 – paragraph 3 a (new) Text proposed by the Commission Amendment

3a. The CE marking shall be affixed only after assessment of the compliance with Union data protection law. Or. {EN}en Amendment 171 Proposal for a regulation Article 51 – paragraph 1

Text proposed by the Commission Amendment Before placing on the market or putting into service a high-risk AI system referred to in Article 6(2), the provider or, where applicable, the authorised representative shall register that system in the EU database referred to in Article 60. Before placing on the market or putting into service a high-risk AI system referred to in Article 6(2), the provider or, where applicable, the authorised representative shall register that system in the EU database referred to in Article 60, in accordance with Article 60(2).

Or. {EN}en Amendment 172 Proposal for a regulation Article 51 – paragraph 1 a (new) Text proposed by the Commission Amendment

Before putting into service or using a high-risk AI system in accordance with Article 6(2), users who are public authorities or Union institutions, bodies, offices or agencies or users acting on their behalf shall register in the EU database referred to in Article 60. Or. {EN}en Amendment 173 Proposal for a regulation Article 53 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 174 Proposal for a regulation Article 53 – paragraph 1 a (new)

Text proposed by the Commission Amendment 1a. The AI regulatory sandbox shall allow and facilitate the involvement of notified bodies, standardisation bodies, and other relevant stakeholders when relevant. Or. {EN}en Amendment 175 Proposal for a regulation Article 53 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 176 Proposal for a regulation Article 53 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 177 Proposal for a regulation Article 53 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 178 Proposal for a regulation Article 53 – paragraph 5 Text proposed by the Commission Amendment

Or. {EN}en Amendment 179 Proposal for a regulation Article 56 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 180 Proposal for a regulation Article 56 – paragraph 2 – introductory part

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 181 Proposal for a regulation Article 56 – paragraph 2 – point b

Text proposed by the Commission Amendment

(b) coordinate and contribute to guidance and analysis by the Commission and the national supervisory authorities and other competent authorities on emerging issues across the internal market with regard to matters covered by this Regulation;

(b) coordinate and provide guidance and analysis to the Commission and to the national supervisory authorities and other competent authorities on emerging issues across the internal market with regard to matters covered by this Regulation; Or. {EN}en Amendment 182 Proposal for a regulation Article 56 – paragraph 2 – point c

Text proposed by the Commission Amendment

(c) assist the national supervisory authorities and the Commission in ensuring the consistent application of this Regulation.

(c) contribute to the effective and consistent application of this Regulation and assist the national supervisory authorities and the Commission in this regard. Or. {EN}en Amendment 183 Proposal for a regulation Article 56 – paragraph 2 – point c a (new) Text proposed by the Commission Amendment

(ca) contribute to the effective cooperation with the competent authorities of third countries and with international organisations. Or. {EN}en Amendment 184 Proposal for a regulation Article 56 – paragraph 2 a (new) Text proposed by the Commission Amendment 2a. The Board shall contribute to the effective and consistent enforcement of this Regulation throughout the Union, including with regard to cases involving two or more Member States as set out in Article 59b.

Or. {EN}en Amendment 185 Proposal for a regulation Article 57 – title

Text proposed by the Commission Amendment Structure of the Board Structure and independence of the Board Or. {EN}en Amendment 186 Proposal for a regulation Article 57 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 187 Proposal for a regulation Article 57 – paragraph 1 a (new) Text proposed by the Commission Amendment

1a. The Board shall act independently when performing its tasks or exercising its powers. Or. {EN}en Amendment 188 Proposal for a regulation Article 57 – paragraph 1 b (new) Text proposed by the Commission Amendment 1b. The Board shall take decisions by a simple majority of its voting members, unless otherwise provided for in this Regulation.

Or. {EN}en Amendment 189 Proposal for a regulation Article 57 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 190 Proposal for a regulation Article 57 – paragraph 2 a (new)

Text proposed by the Commission Amendment 2a. The Board may establish sub-groups as appropriate for the purpose of examining specific questions. Or. {EN}en Amendment 191 Proposal for a regulation Article 57 – paragraph 2 b (new) Text proposed by the Commission Amendment 2b. The Board shall be represented by its Chair.

Or. {EN}en Amendment 192 Proposal for a regulation Article 57 – paragraph 2 c (new) Text proposed by the Commission Amendment

2c. The Board shall elect a Chair and two deputy Chairs from among its voting members by simple majority. The term of office of the Chair and of the deputy Chairs shall be three years. The terms of the Chair and of the deputy Chairs may be renewed once. Or. {EN}en Amendment 193 Proposal for a regulation Article 57 – paragraph 3 Text proposed by the Commission Amendment

The Commission shall provide administrative and analytical support for the activities of the Board pursuant to this Regulation. Or. {EN}en Amendment 194 Proposal for a regulation Article 57 – paragraph 3 a (new) Text proposed by the Commission Amendment 3a. The meetings of the Board shall be considered to be quorate where at least two-thirds of its members are present.

Or. {EN}en Amendment 195 Proposal for a regulation Article 57 – paragraph 3 b (new) Text proposed by the Commission Amendment

3b. The secretariat of the Board shall have the necessary human and financial resources to be able to perform its tasks pursuant to this Regulation. Or. {EN}en Amendment 196 Proposal for a regulation Article 57 – paragraph 3 c (new) Text proposed by the Commission Amendment

3c. The Board shall organise consultations with stakeholders twice a year. Such stakeholders shall include representatives from industry, start-ups and SMEs, civil society organisations, such as NGOs, consumer associations, the social partners and academia, to assess the evolution of trends in technology, issues related to the implementation and the effectiveness of this Regulation, regulatory gaps or loopholes observed in practice.

Or. {EN}en Amendment 197 Proposal for a regulation Article 57 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 198 Proposal for a regulation Article 57 – paragraph 4 a (new) Text proposed by the Commission Amendment

4a. The Board shall cooperate with Union institutions, bodies, offices, agencies and advisory groups and shall make the results of that cooperation publicly available. Or. {EN}en Amendment 199 Proposal for a regulation Article 58 – paragraph 1 – introductory part

Text proposed by the Commission Amendment When providing advice and assistance to the Commission in the context of Article 56(2), the Board shall in particular: When providing advice and assistance to the Commission and the national supervisory authorities in the context of Article 56(2), the Board shall in particular:

Or. {EN}en Amendment 200 Proposal for a regulation Article 58 – paragraph 1 – point a a (new) Text proposed by the Commission Amendment

(aa) issue opinions, recommendations or written contributions with a view to ensuring the consistent implementation of this Regulation; Or. {EN}en Amendment 201 Proposal for a regulation Article 58 – paragraph 1 – point a b (new) Text proposed by the Commission Amendment

(ab) examine, on its own initiative or on request of one of its members, any question covering the application of this Regulation and issue guidelines, recommendations and best practices with a view to ensuring the consistent implementation of this Regulation; Or. {EN}en Amendment 202 Proposal for a regulation Article 58 – paragraph 1 – point c a (new)

Text proposed by the Commission Amendment

(ca) encourage, facilitate and support the drawing up of codes of conduct intended to foster the voluntary application to AI systems of those codes of conduct in close cooperation with relevant stakeholders in accordance with Article 69; Or. {EN}en Amendment 203 Proposal for a regulation Article 58 – paragraph 1 – point c b (new) Text proposed by the Commission Amendment

(cb) cooperate with the European Data Protection Board and with the FRA to provide guidance in relation to the respect of fundamental rights, in particular the right to non-discrimination and to equal treatment, the right to privacy and the protection of personal data; Or. {EN}en Amendment 204 Proposal for a regulation Article 58 – paragraph 1 – point c c (new) Text proposed by the Commission Amendment

(cc) promote public awareness and understanding of the benefits, risks, rules and safeguards and rights in relation to the use of AI systems; Or. {EN}en Amendment 205 Proposal for a regulation Article 58 – paragraph 1 – point c d (new) Text proposed by the Commission Amendment

(cd) promote the cooperation and effective bilateral and multilateral exchange of information and best practices between the national supervisory authorities; Or. {EN}en Amendment 206 Proposal for a regulation Article 58 – paragraph 1 – point c e (new) Text proposed by the Commission Amendment

(ce) advise the Commission on the possible amendment of the Annexes by means of delegated act in accordance with Article 73, in particular the annex listing high-risk AI systems; Or. {EN}en Amendment 207 Proposal for a regulation Article 58 – paragraph 1 – point c f (new) Text proposed by the Commission Amendment

(cf) ensure that the national supervisory authorities actively cooperate in the implementation of this Regulation; Or. {EN}en Amendment 208 Proposal for a regulation Article 58 – paragraph 1 – point c g (new) Text proposed by the Commission Amendment

(cg) provide guidance in relation to children’s rights, applicable law and minimum standards to meet the objectives of this Regulation that pertain to children. Or. {EN}en Amendment 209 Proposal for a regulation Article 58 – paragraph 1 a (new) Text proposed by the Commission Amendment 1a. When acting in the context of Article 59a on cases involving two or more Member States, the Board shall adopt recommendations for national supervisory authorities.

Or. {EN}en Amendment 210 Proposal for a regulation Article 58 – paragraph 1 b (new) Text proposed by the Commission Amendment

1b. The Board shall refer to the Commission any cases referred to in Article 68a of which it becomes aware. Or. {EN}en Amendment 211 Proposal for a regulation Article 58 – paragraph 1 c (new) Text proposed by the Commission Amendment 1c. The Board shall draw up an annual report regarding its activities. The report shall be made public and be transmitted to the European Parliament, to the Council and to the Commission in all official languages of the Union. In particular, the annual report shall include information with regard to:

(a) serious incidents and malfunctioning reported in accordance with Article 62;

(b) serious cases of misuse of high-risk AI systems or cases of use of prohibited practices in accordance with Article 64;

(c) the fines issued pursuant to this Regulation in accordance with Articles 71 and 72;

(d) the possible cases involving two or more Member States and any recommendations issued pursuant with Article 59a;

(e) the practical application of and possible follow-up to the opinions, guidelines, recommendations, advice and other measures taken under paragraph 1. Or. {EN}en Amendment 212 Proposal for a regulation Article 59 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 213 Proposal for a regulation Article 59 – paragraph 2 a (new)

Text proposed by the Commission Amendment 2a. The national supervisory authority shall act as lead authority and be responsible for ensuring the effective coordination between national competent authorities regarding the implementation of this Regulation and shall contribute to the effective and consistent application and enforcement of this Regulation. It shall represent its Member State on the Board, in accordance with Article 57.

Or. {EN}en Amendment 214 Proposal for a regulation Article 59 – paragraph 2 b (new) Text proposed by the Commission Amendment

2b. Each national supervisory authority shall act independently in performing its tasks and exercising its powers in accordance with this Regulation. The member or members of each national supervisory authority shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect, and shall not seek or take instructions from any other body in relation to the exercise of the tasks assigned to them.

Or. {EN}en Amendment 215 Proposal for a regulation Article 59 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 216 Proposal for a regulation Article 59 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 217 Proposal for a regulation Article 59 – paragraph 6

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 218 Proposal for a regulation Article 59 – paragraph 7 Text proposed by the Commission Amendment

Or. {EN}en Amendment 219 Proposal for a regulation Article 59 a (new) Text proposed by the Commission Amendment

Article 59a

Cooperation mechanism between national supervisory authorities in cases involving two or more Member States

Or. {EN}en Amendment 220 Proposal for a regulation Article 60 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 221 Proposal for a regulation Article 60 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 222 Proposal for a regulation Article 60 – paragraph 2 a (new) Text proposed by the Commission Amendment

2a. The data listed in Annex VIII, point (2), shall be entered into the EU database by the users who are or who act on behalf of public authorities or Union institutions, bodies, offices or agencies. The Commission shall provide them with technical and administrative support. Or. {EN}en Amendment 223 Proposal for a regulation Article 60 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 224 Proposal for a regulation Article 60 – paragraph 4

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 225 Proposal for a regulation Article 60 – paragraph 5

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 226 Proposal for a regulation Article 61 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 227 Proposal for a regulation Article 62 – paragraph 1 – subparagraph 1

Text proposed by the Commission Amendment Providers of high-risk AI systems placed on the Union market shall report any serious incident or any malfunctioning of those systems which constitutes a breach of obligations under Union law intended to protect fundamental rights to the market surveillance authorities of the Member States where that incident or breach occurred.

Providers and, where users have identified a serious incident or malfunctioning, users of high-risk AI systems placed on the Union market shall report any serious incident or any malfunctioning of those systems which constitutes a breach of obligations under Union law intended to protect fundamental rights to the market surveillance authorities of the Member States where that incident or breach occurred and, where relevant, to the Commission.

Or. {EN}en Amendment 228 Proposal for a regulation Article 62 – paragraph 1 – subparagraph 2

Text proposed by the Commission Amendment Such notification shall be made immediately after the provider has established a causal link between the AI system and the incident or malfunctioning or the reasonable likelihood of such a link, and, in any event, not later than 15 days after the providers becomes aware of the serious incident or of the malfunctioning.

Such notification shall be made immediately after the provider or where applicable the user has established a causal link between the AI system and the incident or malfunctioning or the reasonable likelihood of such a link, and, in any event, not later than 72 hours after the provider or, where applicable, the user becomes aware of the serious incident or of the malfunctioning.

Or. {EN}en Justification the deadline has been shortened to 3 days to match the corresponding reporting obligations deadlines in the GDPR. Amendment 229 Proposal for a regulation Article 62 – paragraph 1 – subparagraph 2 a (new)

Text proposed by the Commission Amendment Upon establishing a causal link between the AI system and the serious incident or malfunctioning or the reasonable likelihood of such a link, providers shall take appropriate corrective actions pursuant to Article 21. Or. {EN}en Amendment 230 Proposal for a regulation Article 62 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 231 Proposal for a regulation Article 62 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 232 Proposal for a regulation Article 62 – paragraph 3 a (new)

Text proposed by the Commission Amendment 3a. National supervisory authorities shall on an annual basis notify the Board of the serious incidents and malfunctioning reported to them in accordance with this Article. Or. {EN}en Amendment 233 Proposal for a regulation Article 63 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 234 Proposal for a regulation Article 64 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 235 Proposal for a regulation Article 64 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 236 Proposal for a regulation Article 64 – paragraph 3 Text proposed by the Commission Amendment

Or. {EN}en Amendment 237 Proposal for a regulation Article 64 – paragraph 5

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 238 Proposal for a regulation Article 65 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 239 Proposal for a regulation Article 65 – paragraph 2 – subparagraph 1

Text proposed by the Commission Amendment Where the market surveillance authority of a Member State has sufficient reasons to consider that an AI system presents a risk as referred to in paragraph 1, they shall carry out an evaluation of the AI system concerned in respect of its compliance with all the requirements and obligations laid down in this Regulation. When risks to the protection of fundamental rights are present, the market surveillance authority shall also inform the relevant national public authorities or bodies referred to in Article 64(3). The relevant operators shall cooperate as necessary with the market surveillance authorities and the other national public authorities or bodies referred to in Article 64(3).

Where the market surveillance authority of a Member State has sufficient reasons to consider that an AI system presents a risk as referred to in paragraph 1, they shall carry out an evaluation of the AI system concerned in respect of its compliance with all the requirements and obligations laid down in this Regulation. When risks to the protection of fundamental rights are present, the market surveillance authority shall also immediately inform and fully cooperate with the relevant national public authorities or bodies referred to in Article 64(3). The relevant operators shall cooperate as necessary with the market surveillance authorities and the other national public authorities or bodies referred to in Article 64(3). Or.

{EN}en Amendment 240 Proposal for a regulation Article 65 – paragraph 2 – subparagraph 1

Text proposed by the Commission Amendment Where, in the course of that evaluation, the market surveillance authority finds that the AI system does not comply with the requirements and obligations laid down in this Regulation, it shall without delay require the relevant operator to take all appropriate corrective actions to bring the AI system into compliance, to withdraw the AI system from the market, or to recall it within a reasonable period, commensurate with the nature of the risk, as it may prescribe.

Where, in the course of that evaluation, the market surveillance authority or, where relevant, the national public authority referred to in Article 64(3) finds that the AI system does not comply with the requirements and obligations laid down in this Regulation, it shall without delay require the relevant operator to take all appropriate corrective actions to bring the AI system into compliance, to withdraw the AI system from the market, or to recall it within a reasonable period, commensurate with the nature of the risk, as it may prescribe.

Or. {EN}en Amendment 241 Proposal for a regulation Article 65 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 242 Proposal for a regulation Article 65 – paragraph 5

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 243 Proposal for a regulation Article 65 – paragraph 6 – introductory part Text proposed by the Commission Amendment

Or. {EN}en Amendment 244 Proposal for a regulation Article 65 – paragraph 6 – point a

Text proposed by the Commission Amendment

(a) a failure of the AI system to meet requirements set out in Title III, Chapter 2;

(a) a failure of the AI system to meet requirements set out in this Regulation; Or. {EN}en Amendment 245 Proposal for a regulation Article 65 – paragraph 7 Text proposed by the Commission Amendment

Or. {EN}en Amendment 246 Proposal for a regulation Article 65 – paragraph 9 Text proposed by the Commission Amendment

Or. {EN}en Amendment 247 Proposal for a regulation Article 65 – paragraph 9 a (new) Text proposed by the Commission Amendment

9a. National supervisory authorities shall annually report to the Board about the possible use of prohibited practices and serious cases of misuse of high-risk AI systems that occurred during that year and about the measures taken to eliminate or mitigate the risks in accordance with this Article. Or. {EN}en Amendment 248 Proposal for a regulation Article 66 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 249 Proposal for a regulation Article 66 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 250 Proposal for a regulation Article 67 – paragraph 1 Text proposed by the Commission Amendment

Or. {EN}en Amendment 251 Proposal for a regulation Article 67 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 252 Proposal for a regulation Article 67 – paragraph 5

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 253 Proposal for a regulation Article 68 – paragraph 1 – point a Text proposed by the Commission Amendment

(a) the conformity marking has been affixed in violation of Article 49;

(a) the CE marking has been affixed in violation of Article 49; Or. {EN}en Amendment 254 Proposal for a regulation Article 68 – paragraph 1 – point b

Text proposed by the Commission Amendment

(b) the conformity marking has not been affixed;

(b) the CE marking has not been affixed; Or. {EN}en Amendment 255 Proposal for a regulation Article 68 – paragraph 1 – point e a (new) Text proposed by the Commission Amendment

(ea) the technical documentation is not available; Or. {EN}en Amendment 256 Proposal for a regulation Article 68 – paragraph 1 – point e b (new) Text proposed by the Commission Amendment

(eb) the registration in the EU database has not been carried out. Or. {EN}en Amendment 257 Proposal for a regulation Article 68 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 258 Proposal for a regulation Title VIII – Chapter 3 a (new) Text proposed by the Commission Amendment

Chapter 3a

Specific rules regarding enforcement at Union level Or. {EN}en Justification A new chapter setting out the conditions for Commission intervention in enforcing the Regulation is added. This should come before, covering Article 68a to 68i Amendment 259 Proposal for a regulation Article 68 a (new) Text proposed by the Commission Amendment

Article 68a — Commission's intervention and opening of proceedings

(a) the Commission or the Board have sufficient reasons to believe that an AI system infringes this Regulation in such a way to amount to a widespread infringement or a widespread infringement with a Union dimension;

(b) the Commission or the Board have sufficient reasons to believe that an AI system concerned presents a risk which affects or is likely to affect at least 45 million citizens within the Union;

(c) an AI system is suspected of having infringed any of the provisions of this Regulation in two or more Member States and the relevant national supervisory authorities of the Member States concerned have not taken any action.

(a) any information that that national supervisory authority exchanged relating to the infringement or the suspected infringement, as applicable, with the Board and with the operator concerned;

(b) where applicable, the case file of that national supervisory authority relating to the infringement or the suspected infringement, as applicable;

(c) any other information in the possession of that national supervisory authority that may be relevant to the proceedings initiated by the Commission.

Or. {EN}en Amendment 260 Proposal for a regulation Article 68 b (new) Text proposed by the Commission Amendment

Article 68b — Commission's investigation and enforcement power

(a) to require providers or users of an AI system to provide relevant documents, technical specifications, data and information with regard to the compliance and technical aspects of the AI system, in any form or format and irrespective of the medium of storage or the place where such documents, technical specifications, data or information are stored, and to take or obtain copies thereof;

(b) to access data and documentation related to an AI system and its functioning, in accordance with Article 64;

(c) to require providers or users of an AI system to provide relevant information, in accordance with Article 68d;

(d) to carry out unannounced on-site and remote inspections as well as physical checks in accordance with Article 68f;

(e) to conduct interviews in accordance with Article 68e;

(f) to start investigations on its own initiative in order to identify non-compliances and bring them to an end;

(g) to order providers and users of an AI system to take appropriate action to bring an instance of non-compliance to an end or to eliminate the risk in accordance with Article 68h and to adopt interim measures in that regard, in accordance with Article 68i;

(h) to take appropriate measures in accordance with Article 68h;

(i) to impose penalties in accordance with Article 71.

Or. {EN}en Amendment 261 Proposal for a regulation Article 68 c (new) Text proposed by the Commission Amendment

Article 68c

Cooperation and information exchange between the Commission and the national competent authorities

Or. {EN}en Amendment 262 Proposal for a regulation Article 68 d (new)

Text proposed by the Commission Amendment

Article 68d — Commission’s power to request information

Or. {EN}en Amendment 263 Proposal for a regulation Article 68 e (new) Text proposed by the Commission Amendment

Article 68e — Commission's power to take interviews and statements

In order to carry out the tasks assigned to it under Article 68a, the Commission may, subject to their consent, interview any natural or legal person for the purpose of collecting information, relating to the subject-matter of an investigation, in relation to the suspected infringement or infringement, as applicable.

Or. {EN}en Amendment 264 Proposal for a regulation Article 68 f (new) Text proposed by the Commission Amendment

Article 68f — Commission’s power of inspection

(a) enter any premises that the provider or user uses for purposes related to an AI system;

(b) examine any document or record related to an AI system irrespective of the medium on which such a document or record is stored;

(c) take or obtain in any form copies of or extracts from such a document or record;

(d) ask any representative of the provider or user for explanations on facts or document relating to the subject matter and purpose of the inspection and to record the answers.

Or. {EN}en Amendment 265 Proposal for a regulation Article 68 g (new) Text proposed by the Commission Amendment

Article 68g — Non-compliance

Or. {EN}en Amendment 266 Proposal for a regulation Article 68 h (new) Text proposed by the Commission Amendment

Article 68h — Interim measures

Or. {EN}en Amendment 267 Proposal for a regulation Article 68 i (new) Text proposed by the Commission Amendment

Article 68i — Publication of decisions

Or. {EN}en Amendment 268 Proposal for a regulation Title VIII – Chapter 3 b (new) Text proposed by the Commission Amendment Chapter 3b Remedies Or. {EN}en Justification It is appropriate to create a new chapter on remedies. This should come before Art 68 J and 68 K Amendment 269 Proposal for a regulation Article 68 j (new) Text proposed by the Commission Amendment Article 68j Right to lodge a complaint

Or. {EN}en Amendment 270 Proposal for a regulation Article 68 k (new) Text proposed by the Commission Amendment

Article 68k — Right to an effective judicial remedy against a national supervisory authority

Or. {EN}en Amendment 271 Proposal for a regulation Article 70 – paragraph 1 – point b

Text proposed by the Commission Amendment

(b) the effective implementation of this Regulation, in particular for the purpose of inspections, investigations or audits;(c) public and national security interests;

(b) the effective implementation of this Regulation, in particular for the purpose of inspections, investigations or audits; Or. {EN}en Amendment 272 Proposal for a regulation Article 70 – paragraph 1 – point b a (new) Text proposed by the Commission Amendment

(ba) public and national security interests; Or. {EN}en Amendment 273 Proposal for a regulation Article 70 – paragraph 1 a (new) Text proposed by the Commission Amendment 1a. The Commission, the Board, national competent authorities and notified bodies involved in the application of this Regulation shall put in place adequate cybersecurity and organisational measures to protect the security and confidentiality of the information and data obtained in carrying out their tasks and activities.

Or. {EN}en Amendment 274 Proposal for a regulation Article 70 – paragraph 2 – subparagraph 1

Text proposed by the Commission Amendment Without prejudice to paragraph 1, information exchanged on a confidential basis between the national competent authorities and between national competent authorities and the Commission shall not be disclosed without the prior consultation of the originating national competent authority and the user when high-risk AI systems referred to in points 1, 6 and 7 of Annex III are used by law enforcement, immigration or asylum authorities, when such disclosure would jeopardise public and national security interests.

Without prejudice to paragraphs 1 and 1a, information exchanged on a confidential basis between the national competent authorities and between national competent authorities and the Commission shall not be disclosed without the prior consultation of the originating national competent authority and the user when high-risk AI systems referred to in points 1, 6 and 7 of Annex III are used by law enforcement, immigration or asylum authorities, when such disclosure would jeopardise public and national security interests.

Or. {EN}en Amendment 275 Proposal for a regulation Article 70 – paragraph 3

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 276 Proposal for a regulation Article 70 – paragraph 4 Text proposed by the Commission Amendment

Or. {EN}en Amendment 277 Proposal for a regulation Article 71 – title

Text proposed by the Commission Amendment Penalties Penalties and fines Or. {EN}en Amendment 278 Proposal for a regulation Article 71 – paragraph 2

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 279 Proposal for a regulation Article 71 – paragraph 8 a (new) Text proposed by the Commission Amendment 8a. In accordance with Chapter 4 of Title VIII, the Commission may adopt a decision imposing fines pursuant to paragraphs 3 to 6 on providers and users of high-risk AI systems.

Or. {EN}en Amendment 280 Proposal for a regulation Article 71 – paragraph 8 b (new)

Text proposed by the Commission Amendment 8b. In addition to paragraph 8a, the Commission may adopt a decision imposing on the operator concerned fines not exceeding 2 % of the total turnover in the preceding financial year, where the operator intentionally or negligently:

(a) fails to provide information to the Commission by the deadline set in a Commission decision;

(b) fails to rectify by the deadline set in a Commission decision, incorrect, incomplete or misleading information given by a member of staff, or fails or refuses to provide complete information;

(c) refuses to submit to a remote or on-site inspection pursuant to Article 68f. Or. {EN}en Amendment 281 Proposal for a regulation Article 71 – paragraph 8 c (new) Text proposed by the Commission Amendment 8c. The Commission and national supervisory authorities shall, on an annual basis, report to the Board about the fines they have issued during that year, in accordance with this Article.

Or. {EN}en Amendment 282 Proposal for a regulation Article 72 – paragraph 6 Text proposed by the Commission Amendment

Or. {EN}en Amendment 283 Proposal for a regulation Article 72 – paragraph 6 a (new) Text proposed by the Commission Amendment 6a. The European Data Protection Supervisor shall, on an annual basis, notify the Board of the fines it has imposed pursuant to this Article. Or. {EN}en Amendment 284 Proposal for a regulation Article 84 – paragraph 1

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 285 Proposal for a regulation Article 84 – paragraph 2 Text proposed by the Commission Amendment

Or. {EN}en Amendment 286 Proposal for a regulation Article 84 – paragraph 6

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 287 Proposal for a regulation Annex III – paragraph 1 – point 2 – point a

Text proposed by the Commission Amendment

(a) AI systems intended to be used as safety components in the management and operation of road traffic and the supply of water, gas, heating and electricity.

(a) AI systems intended to be used as safety or security components in the management and operation of road traffic and the supply of water, gas, heating, electricity and internet. Or. {EN}en Amendment 288 Proposal for a regulation Annex III – paragraph 1 – point 3 – point b

Text proposed by the Commission Amendment

(b) AI systems intended to be used for the purpose of assessing students in educational and vocational training institutions and for assessing participants in tests commonly required for admission to educational institutions.

(b) AI systems intended to be used for the purpose of assessing students in educational and vocational training institutions and for assessing participants in tests commonly required for admission to educational institutions, for determining learning objectives, and for allocating personalised learning tasks to students. Or. {EN}en Amendment 289 Proposal for a regulation Annex III – paragraph 1 – point 3 – point b a (new)

Text proposed by the Commission Amendment

(ba) AI systems intended to be used by children in ways that have a significant impact on their personal development, including through personalised education or their cognitive or emotional development. Or. {EN}en Amendment 290 Proposal for a regulation Annex III – paragraph 1 – point 5 – point b

Text proposed by the Commission Amendment

(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems put into service by small scale providers for their own use;

(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score; Or. {EN}en Amendment 291 Proposal for a regulation Annex III – paragraph 1 – point 5 – point b a (new) Text proposed by the Commission Amendment

(ba) AI systems intended to be used for making decisions or assisting in making decisions on the eligibility of natural persons for health and life insurance; Or. {EN}en Amendment 292 Proposal for a regulation Annex III – paragraph 1 – point 5 – point c

Text proposed by the Commission Amendment

(c) AI systems intended to be used to dispatch, or to establish priority in the dispatching of emergency first response services, including by firefighters and medical aid.

(c) AI systems intended to be used to evaluate and classify emergency calls by natural persons or to dispatch, or to establish priority in the dispatching of emergency first response services, including by police and law enforcement, firefighters and medical aid, as well as of emergency healthcare patient triage systems; Or. {EN}en Amendment 293 Proposal for a regulation Annex III – paragraph 1 – point 6 – point a

Text proposed by the Commission Amendment

(a) AI systems intended to be used by law enforcement authorities for making individual risk assessments of natural persons in order to assess the risk of a natural person for offending or reoffending or the risk for potential victims of criminal offences; deleted Or. {EN}en Justification predictive policing was inserted in article 5.

Amendment 294 Proposal for a regulation Annex III – paragraph 1 – point 6 – point e

Text proposed by the Commission Amendment

(e) AI systems intended to be used by law enforcement authorities for predicting the occurrence or reoccurrence of an actual or potential criminal offence based on profiling of natural persons as referred to in Article 3(4) of Directive (EU) 2016/680 or assessing personality traits and characteristics or past criminal behaviour of natural persons or groups; deleted Or. {EN}en Justification predictive policing was inserted in article 5.

Amendment 295 Proposal for a regulation Annex III – paragraph 1 – point 8 – point a a (new) Text proposed by the Commission Amendment

(aa) AI systems intended to be used by political parties, political candidates, public authorities, or on their behalf for influencing natural persons in the exercise of their vote in local, national, or European Parliament elections; Or. {EN}en Amendment 296 Proposal for a regulation Annex III – paragraph 1 – point 8 – point a b (new) Text proposed by the Commission Amendment

(ab) AI systems intended to process or count voting ballots for local, national or European Parliament elections; Or. {EN}en Amendment 297 Proposal for a regulation Annex III – paragraph 1 – point 8 a (new)

Text proposed by the Commission Amendment 8a. Other applications:

(a) AI systems intended to be used to generate, on the basis of limited human input, complex text content that would falsely appear to a person to be human-generated and authentic, such as news articles, opinion articles, novels, scripts, and scientific articles;

(b) AI systems intended to be used to generate or manipulate audio or video content that appreciably resembles existing natural persons, in a manner that significantly distorts or fabricates the original situation, meaning, content, or context and would falsely appear to a person to be authentic. Or. {EN}en Amendment 298 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g

Text proposed by the Commission Amendment

(g) instructions of use for the user and, where applicable installation instructions;

(g) instructions of use for the user in accordance with Article 13(2) and (3) and, where applicable installation instructions; Or. {EN}en Amendment 299 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g a (new) Text proposed by the Commission Amendment

(ga) a description of how the AI system works and examples of representative use cases for which the AI system is intended; Or. {EN}en Amendment 300 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g b (new)

Text proposed by the Commission Amendment

(gb) where applicable, a detailed and easily intelligible description of the expected input variables and the expected input data quality so that the high-risk AI system functions properly; Or. {EN}en Amendment 301 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g c (new) Text proposed by the Commission Amendment

(gc) a detailed and easily intelligible description of the system’s main optimisation goal or goals; Or. {EN}en Amendment 302 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g d (new)

Text proposed by the Commission Amendment

(gd) a detailed and easily intelligible description of the high-risk AI system’s expected output and expected output quality; Or. {EN}en Amendment 303 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g e (new) Text proposed by the Commission Amendment

(ge) detailed and easily intelligible instructions for interpreting the high-risk AI system’s output; Or. {EN}en Amendment 304 Proposal for a regulation Annex IV – paragraph 1 – point 1 – point g f (new) Text proposed by the Commission Amendment

(gf) examples of scenarios for which the system should not be used. Or. {EN}en Amendment 305 Proposal for a regulation Annex IV – paragraph 1 – point 6

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 306 Proposal for a regulation Annex V – paragraph 1 – point 4 a (new) Text proposed by the Commission Amendment

4a. Where an AI system involves the processing of personal data, a statement that that AI system complies with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680. Or. {EN}en Amendment 307 Proposal for a regulation Annex V – paragraph 1 – point 7

Text proposed by the Commission

Amendment

Or. {EN}en Amendment 308 Proposal for a regulation Annex VIII – paragraph 1 – point 5 Text proposed by the Commission Amendment

Or. {EN}en Amendment 309 Proposal for a regulation Annex VIII – paragraph 1 a (new) Text proposed by the Commission Amendment

The following information shall be provided and updated with regard to high-risk AI systems to be registered in accordance with Article 51(2) by users who are or act on behalf of public authorities or Union institutions, bodies, offices or agencies:

Or. {EN}en Justification This new subparagraph matches the changes in article 51.2. </RepeatBlock-Amend> EXPLANATORY STATEMENT The co-Rapporteurs share the view that artificial intelligence developed and used in Europe should be human-centric and trustworthy and should respect fundamental rights and Union values enshrined in the Treaties.

At the same time, regulation should not hinder but, rather, it should support innovation and the business environment. Both of these objectives are best achieved by increasing legal certainty and clarity throughout the Regulation proposal, in order to support the private sector and public authorities to comply with the new obligations. The draft Report contains the points on which the co-Rapporteurs could easily agree, and it touches upon all the main elements of the draft Regulation. In terms of scope, the co-rapporteurs agree with the risk-based approach proposed by the Commission. That is, the obligations set out in this Regulation only apply to forbidden practices, to high-risk AI systems, and to certain AI systems that require transparency.

As such, no AI system should be excluded ex-ante, either from the definition of “artificial intelligence” or by carving out exceptions for particular types of AI systems, including general purpose AI. Where, for objective reasons, providers are unable to fulfil the obligations under this Regulation, they should be able to enter into agreements with the users to share the responsibilities. A key element of the draft Report is also the alignment of the text with the GDPR, as the two regulations should work complementary to one another for the development and uptake of AI in Europe.

In terms of forbidden practices, the co-rapporteurs have agreed to add practices that amount to “predictive policing” to the list, as they share the view that liberal societies cannot use technology in breach of the key principle of presumption of innocence. As regards high-risk AI systems, which are the main focus of the Regulation, the co-Rapporteurs propose adding a number of use cases to the list of high-risk AI systems. As children are a particularly vulnerable category, AI systems used to influence or shape their development should be considered high risk.

AI systems used by candidates or parties to influence votes in local, national, or European elections, and AI systems used to count such votes, have the potential, by influencing a large number of citizens of the Union, to impact the very functioning of our democracy. They should therefore be considered high risk. AI systems used for the triage of patients in the healthcare sector, and AI systems used to determine eligibility for health and life insurance are also considered high-risk. Because of their potential for deception, two types of AI systems should be subject to both transparency requirements and the conformity requirements of high-risk AI systems: deepfakes impersonating real persons and editorial content written by AI (“AI authors”).

The co-rapporteurs stress that high-risk AI systems are not prohibited, nor are they to be seen as undesirable. To the contrary, complying with the conformity requirements set out in this Regulation makes such systems more trustworthy and more likely to be successful on the European market. The draft Report considers more closely the chain of responsibility and tries to clarify and re-balance some provisions. Namely, on data governance, the consistency with GDPR has been strengthened and the possible additional legal basis for processing personal data has been removed. In addition, it has been clarified that “error-free” datasets should be an overall objective to reach to the best extent possible, rather than a precise requirement.

The cases of datasets being in the possession of users, while the provider only build the overall architecture of the system, have also been clarified. Most of these clarifications take into account concerns expressed by industry, as the AI value chain is not always linear and responsibilities need to be clearly delineated between different actors in the value chain. Users of high-risk AI systems also play a role in protecting the health, safety, and fundamental rights of EU citizens and EU values, from ensuring that they appoint competent persons responsible for the human oversight of high-risk AI systems to playing a more active role in reporting cases of incidents or malfunctioning of an AI system, as they are sometimes best placed to spot such incidents or malfunctions.

Users who are public authorities are subject to increased transparency expectations in democratic societies. As such, public authorities, Union institutions, agencies, or bodies should register the use of high-risk AI systems in the EU-wide database. This allows for increased democratic oversight, public scrutiny, and accountability, alongside more transparency towards the public on the use of AI systems in sensitive areas impacting upon people’s lives. Additionally, users of high-risk AI systems referred to in Annex III that make decisions or that assist in making decisions related to natural persons should inform the natural persons that they are subject to the use of the high-risk AI system.

Several provisions of the draft Report focus on governance and enforcement, as the co-Rapporteurs are convinced these are key elements to allow the AI Act to be implemented effectively and consistently throughout the Union and therefore help create a true Single Market for AI. To this end, the tasks of the AI Board have been increased. The AI Board should play a more significant role in the uniform application of the Regulation and in providing advice and recommendations to the Commission, for example on the need to amend Annex III, and to national supervisory authorities.

The Board should act as a forum for exchange among national supervisory authorities and, at the same time, it should constitute a place for arbitration of disputes involving two or more Member States’ authorities, in order to avoid the fragmentation of the Single Market through differentiated enforcement. Furthermore, given its increased role and responsibilities, the Board should organize, at least twice a year, consultations with industry, start-ups and SMEs, civil society, and academia, in order to carry out its tasks in collaboration with all relevant stakeholders.

At the national level, the co-Rapporteurs have stressed the need for close cooperation between the market surveillance authorities and the data protection authorities, as the enforcement of the Regulation on AI will require both sets of competences, which, moreover, should be regularly updated. In cases of infringements on fundamental rights, the relevant fundamental rights bodies should also be closely involved. In order to tackle possible issues impacting individuals in several Member States, the co-Rapporteurs propose a new enforcement mechanism by the Commission, to be triggered in cases amounting to widespread infringements (three or more Member States), including in the case of inaction on an infringement impacting at least three Member States.

This mechanism, based on the model of the Digital Services Act but adapted to the different nature of the AI legislation, aims to address some of the enforcement problems that have been observed in other governance setups, to contribute to the uniform implementation of this regulation, and to strengthen the digital single market. According to the mechanism, in such cases of widespread infringements, the Commission should have the powers of a market surveillance authority, on the model of the Market Surveillance and compliance Regulation.

The co-Rapporteurs believe it is important to strengthen the involvement of stakeholders and civil society organizations in several key provisions of the Regulation, such as the updates to the list of high-risk AI systems, the standardization process, as well as the activities of the Board and the sandboxes. Furthermore, in order to ensure that individuals are properly empowered when the use of an AI system infringes on their rights, but also in order to contribute to building trust in AI systems and their widespread use, the co-rapporteurs have added a dedicated chapter on remedies for both natural and legal persons.

The co-rapporteurs want to emphasize, together, that the goal of the AI Act is to ensure both the protection of health, safety, fundamental rights, and Union values and, at the same time, the uptake of AI throughout the Union, a more integrated digital single market, and a legislative environment suited for entrepreneurship and innovation. This spirit has guided and will continue to guide their work on this Regulation.