Article 49: registration in the EU database
Registration makes your system publicly visible. That is the point of it: the Article 71 database is the mechanism by which the high-risk regime becomes observable to regulators, researchers and the public. It also catches organisations that thought the Article 6(3) derogation put them out of scope entirely.
Who registers what
| Who | What they register | When |
|---|---|---|
| Provider or authorised representative of an Annex III high-risk system (other than Annex III point 2) | Themselves and the system, in the EU database under Art. 71 | Before placing on the market or putting into service |
| Provider claiming the Art. 6(3) derogation | Themselves and that system | Before placing on the market or putting into service |
| Public authority deployers, Union institutions, bodies, offices and agencies, and persons acting on their behalf | Themselves; then select the system and register its use | Before putting into service or using |
| Annex III point 2: critical infrastructure safety components | Registered at national level, not in the public EU database | Before placing on the market or putting into service |
The information to be submitted is set out in Annex VIII. Regulation (EU) 2026/1744 made narrow simplifications to Annex VIII Section B for systems self-assessed as non-high-risk. Check the consolidated Annex VIII rather than a pre-2026 summary.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The derogation trap
Not high-risk still means registered
Article 6(3) lets you conclude an Annex III system is not high-risk. It does not let you disappear. You still register yourself and that system, and Article 80 gives a market surveillance authority a defined procedure for dealing with systems a provider has classified as non-high-risk.
Practically: registering a derogation claim publishes it. Your Article 6(4) documented assessment is the thing that has to withstand the attention that follows. The Art. 6(3) derogation →
What registration exposes
The Article 71 database is largely public. That has consequences most compliance plans do not price:
- Competitors can see your system entries. Intended purpose and system description become public artefacts.
- Journalists and researchers can enumerate deployments: particularly public-sector ones, which are registered by the deploying authority.
- Civil society can compare your registered intended purpose against your marketing. A divergence between the two is a story, and it is also evidence.
Practical recommendation. Write the registration entry and the product marketing in the same room. The intended purpose you register constrains what you can claim commercially, and it is the reference point against which substantial modification is later judged.
Status labels on this page
Verified fact: The Art. 49 registration duties, the Annex III point 2 national-level route, the derogation registration duty, and the Art. 80 procedure.
Expert analysis: The exposure analysis above and the recommendation to align registration with marketing.
Unsettled: Operational details of the database and national procedures, which have developed over time. Confirm current practice with your national competent authority.
Registration follows an inventory
You cannot register what you have not catalogued. An AI system inventory recording intended purpose, role, risk tier and registration status per system is the artefact that makes Article 49 a form-filling exercise rather than a discovery project.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
Who has to register in the EU AI database?
Under Article 49, before placing on the market or putting into service a high-risk AI system listed in Annex III, other than systems under Annex III point 2, the provider or its authorised representative must register themselves and their system in the EU database referred to in Article 71. Providers who have concluded under Article 6(3) that their Annex III system is not high-risk must also register themselves and that system.
Deployers that are public authorities, Union institutions bodies offices or agencies, or persons acting on their behalf, must register themselves, select the system and register its use before putting a high-risk Annex III system into service or using it.
Do critical infrastructure AI systems have to be registered in the EU database?
Annex III point 2 covers AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. Article 49 provides that registration for these systems is at national level rather than in the public EU database.
Does registration apply if you use the Article 6(3) derogation?
Yes. A provider who concludes that an Annex III system is not high-risk under Article 6(3) still registers itself and that system. The derogation removes the Chapter III Section 2 obligations; it does not remove you from the register. Article 80 gives market surveillance authorities a procedure for dealing with systems the provider has classified as non-high-risk.
When does the Article 49 registration obligation apply?
Article 49 has applied since 2 August 2026 as part of the obligations that were not deferred by the Digital Omnibus. The underlying high-risk obligations it accompanies apply from 2 December 2027 for stand-alone Annex III systems. Providers should confirm the current registration position for their system type with their national competent authority, since the practical availability of the database and national procedures has developed over time.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →