Skip to content

Regulation Tracker / EU AI Act / Chapter III · Section 5

Article 42
Presumption of conformity with certain requirements

Chapter III — Classification rules for high-risk AI systems, Section 5 — Harmonised standards and standardisation deliverables. 3 distinct duties, powers or definitions are coded from this article, applying from 2026-08-02.

Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 45 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex.

official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub

The text

1. High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4).

2. High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.

3. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.

What it requires, coded

SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.

  1. Art. 42(1)Scope or definitionHigh-risk

    High-risk AI systems trained and tested on data reflecting their intended geographical, behavioural, contextual or functional setting are presumed compliant with Article 10(4) data-relevance requirements.

    "High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply"
    Who
    Provider
    From
    (Art. 113 second subparagraph)Chapter III Sections 1-3 apply from 2027-12-02 for Annex III high-risk systems and 2028-08-02 for Annex I high-risk systems under Art. 113(c) as amended; this row applies when the relevant high-risk rules bite.
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to legal-AI vendors that need to evidence context-appropriate data for high-risk legal or justice systems.
    See
    Art. 10(4)
  2. Art. 42(2)Scope or definitionHigh-risk

    A high-risk AI system certified under a published EU cybersecurity scheme is presumed compliant with Article 15 cybersecurity requirements to the extent the certificate or statement covers them.

    "High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply"
    Who
    Provider
    From
    (Art. 113 second subparagraph)Chapter III Sections 1-3 apply from 2027-12-02 for Annex III high-risk systems and 2028-08-02 for Annex I high-risk systems under Art. 113(c) as amended; this row applies when the relevant high-risk rules bite.
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant to high-risk legal-AI vendors relying on cybersecurity certification in conformity work.
    See
    Art. 15 · Regulation (EU) 2019/881
  3. Art. 42(3)Scope or definitionHigh-risk

    High-risk AI systems within Regulation (EU) 2024/2847 that meet Article 12(1) of that Regulation are deemed compliant with Article 15 cybersecurity requirements.

    "Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply"
    Who
    Provider
    From
    (Art. 113 second subparagraph)Chapter III Sections 1-3 apply from 2027-12-02 for Annex III high-risk systems and 2028-08-02 for Annex I high-risk systems under Art. 113(c) as amended; this row applies when the relevant high-risk rules bite.
    Legal practice
    Reaches legal-AI vendors or public bodies — Relevant where a legal-AI product is also covered by EU cyber-resilience legislation.
    See
    Art. 15 · Regulation (EU) 2024/2847

Cite

Regulation (EU) 2024/1689, Article 42 (Presumption of conformity with certain requirements), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_42 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-42, accessed 2026-09-08, CC BY 4.0.