Article 10: data and data governance
Article 10 is where the AI Act stops being a governance regulation and starts being a data engineering one. It asks questions most teams cannot answer about data they acquired years ago, where it came from, what it was originally collected for, and what it fails to represent.
The eight governance practices
Article 10(2) lists what your data governance must concern. Read it as an evidence checklist, because that is how it will be examined.
- Design choices: the decisions that shaped the data set, recorded at the time.
- Data collection processes and origin, and for personal data, the original purpose of collection. This is the question that catches repurposed operational data.
- Preparation operations: annotation, labelling, cleaning, updating, enrichment, aggregation.
- Assumptions about what the data is supposed to measure and represent. Rarely written down; frequently wrong.
- Assessment of availability, quantity and suitability of the data needed.
- Examination for possible biases likely to affect health, safety or fundamental rights, or lead to discrimination prohibited under Union law.
- Measures to detect, prevent and mitigate those biases.
- Identification of relevant data gaps or shortcomings that prevent compliance, and how they can be addressed.
Point 4 is the one to start with
“What is this feature supposed to measure?” is a question with an answer that is often a proxy nobody examined. Prior salary as a proxy for seniority. Postcode as a proxy for creditworthiness. Article 10(2)(d) requires the assumption to be stated, which is the point at which proxies become visible.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The quality standard in 10(3)
Training, validation and testing data sets must be relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose. They must have appropriate statistical properties, including as regards the persons or groups of persons on which the system is intended to be used.
Three things follow.
- Representativeness is judged against intended use, not against the world. A system intended for use in Portugal is not deficient for under-representing Finland. It is deficient for under-representing Portuguese populations it will be used on.
- “Best extent possible” is a real qualifier. Perfection is not the standard. Documented effort against a stated target is.
- Article 10(4) adds context: consider characteristics or elements particular to the specific geographical, contextual, behavioural or functional setting in which the system is to be used.
The 10(5) special-category permission
A narrow door, not an open one
You may process special categories of personal data to the extent strictly necessary for bias detection and correction, but only with all of the following: technical limitations on re-use and state-of-the-art security and privacy-preserving measures; measures ensuring the data is secured, protected and subject to access control; no transmission, transfer or other access by other parties; deletion once the bias is corrected or the retention period ends, whichever comes first; and records of processing activities.
This exists because you cannot test for discrimination against a characteristic you refuse to collect. It does not authorise retaining that data for any other purpose, and it sits alongside the GDPR rather than displacing it. How the two regimes interact →
If your system was not trained on data
Article 10(6): for high-risk systems not developed using techniques involving the training of AI models, paragraphs 2 to 5 apply only to the testing data sets. Rule-based and knowledge-based systems that fall within the Article 3(1) definition still owe testing-data governance. Is it an AI system? →
Status labels on this page
Verified fact: The eight practices, the 10(3) quality criteria, the 10(4) context requirement, the 10(5) conditions and the 10(6) carve-out.
Expert analysis: The proxy-variable framing and the representativeness reading.
Unsettled: How ‘sufficiently representative’ will be measured in practice. Harmonised standards addressing this are still in development.
Data lineage is the artefact
Article 10 is answered with lineage: per data set, where it came from, what it was originally for, how it was prepared, what it assumes, what bias testing was run, and what is missing. Reconstructing that after the fact is the expensive version.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What does Article 10 of the EU AI Act require?
Article 10 requires that high-risk AI systems developed with training of models use training, validation and testing data sets that meet quality criteria and are subject to appropriate data governance and management practices. Those practices cover design choices, data collection processes and origin, data preparation operations such as annotation, labelling, cleaning, updating, enrichment and aggregation, assumptions about what the data is supposed to measure and represent, assessment of availability quantity and suitability, examination for possible biases, measures to detect prevent and mitigate those biases, and identification of relevant data gaps or shortcomings.
Does data have to be error free under the EU AI Act?
No. Article 10(3) requires that training, validation and testing data sets are relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose. The standard is best extent possible and in view of intended purpose, not perfection. Data sets must also have the appropriate statistical properties, including as regards the persons or groups on which the system is intended to be used.
Can you process special category personal data to test for bias?
Yes, within strict limits. Article 10(5) permits processing of special categories of personal data to the extent strictly necessary for the purposes of ensuring bias detection and correction, subject to safeguards including technical limitations on re-use and state-of-the-art security and privacy-preserving measures, measures ensuring the data is secured and access-controlled, no transmission or transfer to other parties, deletion once the bias has been corrected or the retention period ends, and records of processing activities. This is a narrow permission, not a general licence.
Does Article 10 apply to systems that are not trained on data?
Only in part. Article 10(6) provides that for high-risk AI systems not developed using techniques involving the training of AI models, the data governance requirements in paragraphs 2 to 5 apply only to the testing data sets.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →