Guide to actors
subject to the RIA

The different persons involved in the development, commercialisation and implementation of an AI system do not have to respond in the same way to all the obligations set out in the Regulation, but the RIA assigns different obligations according to the particular role played by each of these subjects.

This guide aims to make it easier for operators to identify what their role is in relation to the RIA and for which requirements they can be held responsible in the event of non-compliance.

By provider we refer to a natural or legal person, public authority, agency or other body that develops or has developed an AI system and markets or puts it into service under its own name or trademark, whether for consideration or free of charge.
Most of the obligations contemplated in the RIA fall on these actors.

La majoria de d’obligacions contemplades al RIA recauen sobre aquests actors.

Art. 16 RIA: Obligations with respect to high-risk systems

Ensure that the AI system has the risk management system referred to in art. 9 RIA.

Ensure that the system complies with the data governance requirements  of art. 10 RIA.

Guarantee that the system has the technical documentation contemplated in art. 11 RIA.

Ensure that the system can maintain automatic records of its operation as required by art. 12 RIA, and keep these records when they are under its control, in accordance with art. 19 RIA.

Ensure that the system complies with the requirements of transparency and information to the deployers contemplated in art. 13 RIA.

Ensure that the system complies with the requirements of human supervision demanded by art. 14 RIA.

Guarantee that the system meets the requirements of precision, robustness and security contemplated in art. 15 RIA.

Inform in the high-risk system or the accompanying documentation their name, registered trade name or registered trademark as well as the address at which they can be contacted.

Have a quality management system  that complies with the requirements of art. 17 RIA.

To keep and keep at the disposal of the competent national authorities the documentation listed in art. 18 RIA for a period of 10 years from the marketing or commissioning of the system.

Ensure that, before the AI systems are marketed or put into service, they have been subjected  to the conformity assessment provided for in art. 43 RIA.

Prepare the declaration of responsibility required  by art. 47 RIA for each high-risk system, which must be machine-readable and must be kept at the disposal of the competent authorities for a period of 10 years from the marketing and/or commissioning of the system.

Affix the CE marking to the system or, if this is not possible, to its packaging or to the accompanying documentation, in accordance with art. 48 RIA.

In the case of a system listed in Annex III of the Regulation (with the exception of the systems referred to in point 2 thereof), it must be registered in the EU database regulated in art. 71 RIA, in accordance with art. 49 RIA.

Carry out the corrective and information measures referred to in art. 20 RIA when it suspects that a system already marketed or put into service may fail to comply with any provision of the RIA.

Demonstrate that the system complies with the requirements of Articles 9 to 15 RIA when requested to do so by a competent national authority in accordance with Art. 21 RIA.

Ensure that the high-risk AI system complies  with accessibility requirements in accordance with Directives (EU) 2016/2102 and (EU) 2019/882.

Art. 50 RIA: Obligations regarding limited risk systems (generative AI applications and general-purpose models)erativa i models de propòsit general)

Providers of systems that interact directly with natural persons must ensure that they are designed and developed in such a way that those affected are informed that they are interacting with them.

Providers of generative AI systems  must ensure that their results are marked in a machine-readable format and detectable as artificially generated or manipulated.

Art. 53 RIA: Obligations with respect to general purpose models

Prepare and keep up to date the technical documentation of the model, including its training process, testing and the results of the evaluation, and which contains, at least, the information detailed in Annex XI RIA. This documentation must be provided to the European AI Office and the competent national authorities, upon request.  

The conformity of the AI system will be presumed when the provider complies with the approved European harmonized standards, provided for in art. 40 RIA, to the extent that such standards regulate these obligations. As long as harmonised standards are not published, the approved codes of good practice may be used. Otherwise, compliance must be demonstrated to the Commission through appropriate alternative means.

To this end, we recommend adherence to the Code of Good Practice for General Purpose Models of the European AI Office, especially with regard to the chapter on transparency.

When another provider intends to integrate the general purpose model into its system, the provider of the general purpose model must provide documentation  containing at least the elements detailed in Annex XII RIA, as well as provide information  that allows it to fully understand the capabilities and limitations of the general purpose model and comply with its obligations in accordance with the RIA.

Establish a policy to comply  with European legislation on copyright and related rights and, in particular, to identify a reservation of rights expressed in accordance with art. 4.3 of Directive (EU) 2019/790. To this end, we recommend adherence to the  European AI Bureau’s Code of Good Practice for General Purpose Models, especially with regard to the chapter on copyright.

Prepare and make available to the public a sufficiently detailed summary of the content used for the training of the model carried out in accordance with the template prepared by the European AI Office.

Cooperate with the Commission and the competent national authorities in the exercise of their powers and powers.

Art. 55 RIA: Obligations with respect to general purpose models of systemic risk

Evaluate the conformity model with standardized protocols and tools that reflect prior art, including conducting and documenting contradictory tests to identify and mitigate systemic risks.

Assess and mitigate potential systemic risks at Union level that may arise from the development, commercialisation or use of the system, including their sources.

Keep a record, document and communicate without delay to the European AI Office and, where appropriate, to the competent national authorities, relevant information on serious incidents and possible corrective measures to deal with them.

Ensure an appropriate level of cybersecurity for the model and its physical infrastructure.

To comply with the obligations contained in this article, we recommend adhering to the Code of Good Practice for General Purpose Models of the European AI Office, and following the indications contained in the chapter on safety and security, relating to the development of a safety and security framework.

A natural or legal person located or established in the Union who has accepted a written mandate from a provider of an AI system to comply with and carry out on its behalf the obligations and procedures set out in the RIA.

This figure is mandatory in cases where the provider is located in a territory that is not part of the EU.

Art. 22 RIA: Obligations with respect to high-risk systems

Carry out the tasks specified in the mandate received from the provider, of which they must provide a copy to the competent authorities, upon request, in English, French or German, as indicated by them. The mandate must empower the authorised representative to carry out, at least, the tasks mentioned in the following boxes.

Verify that the declaration of conformity referred to  in art. 47 RIA and the technical documentation referred to in art. 11 RIA has been drawn up, and that the provider has carried out an  appropriate conformity assessment procedure.

Keep the  provider’s contact details, a copy of the EU declaration of conformity, the technical documentation and, where applicable, the certificate issued by the notified body available to the competent authorities for a period of 10 years after the system has been placed on the market or put into service.

Provide a competent authority, upon reasoned request, with all the information and documentation necessary to demonstrate the compliance of a high-risk AI system with the RIA, including access to the automatic registers provided for in Art. 12 RIA if these were under the control of the provider;

Cooperate with the competent authorities, upon reasoned request, in any action they take in relation to the system, in particular to reduce and mitigate the risks posed by it.

Comply with the registration obligations referred to in Article 49.1 RIA or, if the registration is carried out by the same provider, ensure that the information regarding your name, address and contact details is correct.

Terminate the mandate if it considers that the provider is acting contrary to its obligations under the RIA. In this case, it must immediately inform the relevant market surveillance authority and notified body.

Art. 54 RIA: Obligations with respect to general purpose systems

Carry out the tasks specified in the mandate received from the provider, of which they must provide a copy to the competent authorities, upon request, in the official language of the EU institutions indicated by them. The mandate must empower the authorised representative to carry out, at least, the tasks mentioned in the following boxes.

Check that the technical documentation specified in Annex XI has been prepared  and that the provider has complied with all the obligations provided for in art. 53 and, in the case of a general-purpose model of systemic risk, in art. 55 RIA.

Keep a copy of the aforementioned technical documentation available to the competent national authorities and the European AI Office for a period of 10 years from the marketing of the model, as well as the  provider’s contact details.

Provide the European AI Office, upon a reasoned request, with all the information and documentation necessary to demonstrate compliance  with the RIA.

Cooperate with the European AI Office and the competent authorities, upon a reasoned request, in any action related to the model, even when it is integrated into systems marketed or put into service in the EU.

Terminate the mandate if it considers that the provider is acting contrary to its obligations. In this case, it will also immediately inform the European IA Office of the termination of the mandate and the reasons for it.

A natural or legal person located or established in the Union that markets an AI system bearing the name or trademark of a natural or legal person established in a third country.

Art. 23 RIA: Obligations with respect to high-risk systems

Verify that the system provider has performed the Relevant conformity assessment procedure in accordance with Art. 43 RIA.

Verify that the provider has prepared the technical documentation in accordance with art. 11 and Annex IV RIA.

Verify that the system bears the  required CE marking and is accompanied by the EU declaration of conformity, pursuant to art. 47 RIA, and the instructions for use.

If applicable, verify that the provider has appointed an authorised representative, in accordance with art. 22.1 RIA.

When you have sufficient reason to consider that a system is not compliant with the RIA, or is falsified or accompanied by falsified documentation, you must not market it until it  has been brought into compliance.

Inform the system provider, the authorised representative and the market surveillance authorities when the system may present a risk to health, safety or fundamental rights, in accordance with art. 79.1 RIA.

Indicate your name, registered trade name or registered trademark and the contact address  on the system and its packaging or in the accompanying documentation.

Ensure that, while a system is under your responsibility, storage or transport conditions do not jeopardize its legal compliance.

Keep a copy of the certificate issued by the notified body, where applicable, of the instructions for use and of the EU declaration of conformity provided for in art. 47 RIA, for a period of 10 years from the time the system has been placed on the market or put into service.

To provide the competent authorities, upon a reasoned request, with all the information and documentation necessary to demonstrate the conformity of a system with the RIA.

Cooperate with the competent authorities in any action they take in relation to a system they have placed on the market, in particular to reduce and mitigate the risks posed by it.

A natural or legal person in the supply chain, other than the provider or importer, who makes an AI system available to the Union market.

Art. 24 RIA: Obligations with respect to high-risk systems

Verify that the system bears the  required CE marking, is accompanied by the EU declaration of conformity, by virtue of art. 47 RIA, as well as the instructions for use, and that the provider and importer comply with their obligations, before its marketing.

Garantir que mentre un sistema estigui sota la seva responsabilitat les condicions d’emmagatzematge o transport no posin en perill el compliment del RIA.

Ensure that while a system is under its responsibility, storage or transport conditions do not jeopardize compliance with the RIA.

Adopt the  necessary corrective measures, when it considers that a system that it has made available to the market does not comply with the requirements of the RIA, to correct the lack of conformity, withdraw or recover it, or to ensure that other operators take these measures.

To provide the competent authorities, upon reasoned request, with all the information and documentation relating to their actions necessary to demonstrate the conformity of the system with the RIA.

Cooperate with the competent authorities in any action they take in relation to a system that they have made available to the market, in particular to reduce or mitigate the risk that it may pose.

A natural or legal person, public authority, agency or other body that uses an AI system under its authority, except when the AI system is used in the course of a personal non-professional activity.

Art. 26 RIA: Obligations with respect to high-risk systems

Adopt the appropriate technical and organisational measures  to ensure that they use the systems in accordance with the  accompanying instructions for use.

Assign human supervision to natural persons who have the  necessary competence, training and authority, and provide them with the necessary support.

Ensure that the input data is relevant and sufficiently representative taking into account the intended purpose of the system, to the extent that it exercises control over the input data.

Supervise the operation of the system on the basis of the instructions for use and, where appropriate, inform providers as provided for in art. 72.2 RIA.

Immediately inform the provider or distributor, as well as the relevant market surveillance authority, and suspend the use of a system when it, despite following the instructions for use, may present a risk to health, safety or fundamental rights, under the terms provided for in art. 79.1 RIA.

Inform the provider immediately, and then the importer or distributor and the relevant market surveillance authorities, when a serious incident is identified. If you are unable to contact the provider, you must comply with the obligation to notify serious incidents that Art. 73 RIA imposes on providers.

In the event that the deployer is a financial institution, this obligation will be carried out in compliance with the rules on internal governance provisions, processes and mechanisms in accordance with the relevant financial services legislation.

To keep the records automatically generated by the system to the extent that these records are under its control, for a period appropriate to the intended purpose of the system, which will be at least 6 months, unless there is a legal rule that indicates otherwise.  

In case the deployer is a financial institution, it will have to lie the records as part of the documentation maintained in accordance with the Union financial services legislation.

Before putting into service or using a system in the workplace, deployers who are employers must inform the workers’ representatives and the workers affected by its use, following the existing rules regarding the information of workers and their representatives.

Deployers who are public authorities must comply with the registration obligations set out in Article 49 RIA. When they find that the system they intend to use has not been registered in the EU database provided for in Article 71 RIA, they will not use it and will inform  the provider or distributor.

Use the information provided to them by virtue of art. 13 RIA

 (on transparency and information to deployers), to carry out a data protection impact assessment when required  to do so under Article 35 of Regulation 2016/679 (General Data Protection) or Article 27 of Directive (EU) 2016/680.

Deployers of deferred remote biometric identification systems must comply with the requirements set out in art. 26.10 RIA, as well as with the restrictions provided for in Regulation (EU) 2016/679 and Directive (EU) 2016/680 that are applicable.

Inform persons subject to the use of a high-risk system of those included in Annex III RIA when it makes or helps to make decisions related to natural persons.

Cooperate with the relevant competent authorities in any action they take in relation to the system in order to implement the RIA.

Art. 50 RIA: Obligations regarding limited risk systems (generative AI applications and general-purpose models)

The developer of an emotion recognition or biometric categorization system  must inform the natural persons exposed to it, and process their personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680.

The deployer of a system that generates or manipulates image, audio or video content that constitutes a deepfake, must disclose that the content has been artificially generated or manipulated.

The developer of a system that generates or manipulates published text for the purpose of reporting on issues of public interest must disclose that the text has been artificially generated or manipulated, except when the generated content has been subjected to a process of human review or editorial control and a natural or legal person has responsibility for its publication.

The information described in the two previous points must be provided in a clear and distinguishable manner, at the latest at the time of the first exhibition, and in accordance with the applicable accessibility requirements.

To avoid uncertainty about the role of the different operators that participate in the value chain of an AI system, the RIA includes a series of rules to identify which actor is responsible for ensuring that the system complies with all legal requirements.

Art. 25: Obligations with respect to high-risk systems

Any actor will be considered a provider for the purposes of the RIA, and will be subject to the obligations provided for in art. 16 RIA, if, in relation to a system already introduced on the market or put into service:

  1. It puts its name or brand in a high-risk system, without prejudice to contractual agreements that stipulate that obligations are assigned in another way;
  2. It makes a substantial modification to a high-risk system, provided that it continues to be a high-risk system in accordance with art.6 RIA; or

It modifies the intended purpose of a system, including a system that would have been classified as high-risk, so that the system in question becomes a high-risk system in accordance with art. 6 RIA.

In the cases described, the provider that initially marketed or put the system into service will no longer be considered a provider of that specific system. The old provider will cooperate closely with the new ones and will provide the information and other assistance necessary for the fulfilment of the obligations required by the RIA.

However, you will be exempt from this obligation if you have clearly specified that your system should not become a high-risk system.

The  provider of a product covered by the standards listed in Annex I RIA to which an AI system has been incorporated as  a safety component will be considered a provider of a high-risk AI system, subject to the obligations contained in art. 16 RIA, if:

  1. The system is placed on the market together with the product under the name or trademark of the manufacturer of the product; or

The system is put into service under the name or trademark of the manufacturer of the product after the product has been placed on the market.

The provider of a high-risk system and the third party  supplying other AI systems, tools, components or processes that are integrated into the high-risk system must specify, by means of a written agreement, the information other assistance necessary in order to enable the provider of the high-risk system to fully comply with the obligations imposed on it by the RIA.

This obligation will not operate if these other tools have been made accessible to the public under a free and open source license, except if they are general-purpose models.

ATTENTION! The interactions between the different operators, as well as the individual actions of some of them, can give rise to complex situations that make it difficult to identify the responsible party within the chain of responsibility.

For example, company A acquires a general-purpose model produced by company B to integrate it into an AI system. Company A will be the provider with respect to whoever acquires its AI system, and Company B will continue to be the provider with respect to Company A, but if the system results in an incident, which company will be liable?

In the event of uncertainty, Article 25 provides rules for identifying the responsible subjects for the system to comply with the legal requirements, which are set out at the bottom of this page.

If you have any doubts about what your role is for the purposes of the RIA and what are the obligations that you must attend to in a particular situation, you can contact us so that we can assess your specific case.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.