Article 25(2)
UpcomingConditional timingCooperate With a New Provider When Provider Responsibility Transfers
Applies to Initial Provider; High-Risk AI.
- Actors
- Provider
- AI class
- High-Risk AI
- Themes
- Third Parties & Supply ChainGovernance & Accountability
Tracker Guidance
If another distributor, importer, deployer or third party becomes the provider of a high-risk AI system under Article 25(1), the initial provider should cooperate closely with the new provider and provide the information, technical access and other assistance reasonably needed for compliance. Where relevant, this now includes technical documentation sufficient to assess Article 16 compliance, information about known limitations and failure modes, and targeted technical access for testing and validation. The duty does not apply where the initial provider clearly specified that its system was not to be changed into a high-risk AI system. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Official text
2. Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular with regard to compliance with the conformity assessment of high-risk AI systems. In particular, the obligation laid down in the second subparagraph shall include, where relevant for the purposes specified therein, the following: (a) making available of technical documentation sufficient to assess compliance with the requirements laid down in Article 16; (b) informing the new providers about known limitations and failure modes; and (c) providing the new providers with targeted technical access, including for testing and validation. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to cooperate with the new providers and hand over the documentation.
Timing depends on the system
- 2 Dec 2027 — Article 6(2) / Annex III high-risk AI
- 2 Aug 2028 — Article 6(1) / Annex I Section A high-risk AI
- 2 Dec 2027 — Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
- 2 Aug 2028 — Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
- 2 Aug 2030 — Pre-existing high-risk AI intended to be used by public authorities