Governance

EU Database for High-Risk AI Systems

The EU-managed registry where providers and certain public deployers must record key information about high‑risk AI systems (and some non‑high‑risk registrations) to ensure transparency and oversight.

Definition

Official/legal definition: The EU database for high‑risk AI systems is the European Commission‑maintained database that contains the information referred to in Article 71(2) and (3) of Regulation (EU) 2024/1689 (the EU AI Act). The Commission, in collaboration with Member States, shall set up and maintain that database and act as its controller; the database shall hold data entered by providers (or authorised representatives) and by public‑authority deployers as specified, and it shall make most registered information publicly available while protecting restricted sections. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))

Context and scope: The database implements Chapter VIII of the EU AI Act and applies to AI systems classified as high‑risk under Article 6(2) that are registered in accordance with Articles 49 and 60, and to AI systems that providers classify as non‑high‑risk but register under Article 6(4) and Article 49. Its functional specifications are to be developed in consultation with experts and the European AI Board, and the Commission must ensure accessibility, machine‑readability and user‑friendliness of the public sections. The database is intended to support transparency, market surveillance, and public awareness while protecting necessary confidentiality and personal data. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))

Practical implications for businesses and public deployers: Providers (or their authorised representatives) of high‑risk AI systems are required to enter prescribed data items (see Annex VIII, Sections A and B) into the database before placing the system on the market or putting it into service as required by the registration provisions (Article 49). Public authorities, agencies or bodies that deploy high‑risk AI systems must enter the deployer‑specific data (Annex VIII, Section C) in the secure/deployer section. Most entries will be publicly accessible; however, certain sensitive information (for example specific data required under Article 60 for some public‑sector uses) may be restricted to market surveillance authorities and the Commission unless the provider opts for public disclosure. This creates a binding compliance step: failure to register or to keep entries accurate can trigger enforcement and market‑surveillance actions under the Regulation. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))

Key requirements and criteria:

  • Who enters data: Providers or authorised representatives enter the data in Sections A and B of Annex VIII; public authority deployers enter Section C data. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))
  • Content and scope of entries: The Regulation prescribes the specific data fields (identity of responsible persons, system identification, intended use, conformity status, applicable standards and other compliance information) in Annex VIII. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))
  • Access and confidentiality: Most registered information is public and machine‑readable; limited sections (e.g., some law‑enforcement/migration uses and the data entered under Article 60) are accessible only to competent authorities and the Commission unless the provider consents to public disclosure. Personal data is included only as strictly necessary (such as names and contacts of legally responsible persons). ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))
  • Commission role: The Commission is the controller of the database and must provide technical and administrative support and ensure compliance with accessibility obligations. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))

Examples and cross‑references: Examples of entries expected include a medical diagnostic AI system listed as high‑risk (provider enters technical documentation pointers, conformity assessment status and contact details), or a public‑sector deployer registering use of a biometric identification system under the secure deployer section. See also Article 49 (registration), Article 60 (special registration rules for certain public sector uses), Annex III (classification of high‑risk uses) and Annex VIII (data fields for the database) for related obligations and the precise lists of required data. Practically, businesses must integrate database registration into pre‑market workflows and compliance management to avoid enforcement risk. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-71?utm_source=openai))

Sources

  • EU AI Act Article 71
  • EU AI Act Article 49