What Art. 49 actually requires
Art. 49 AI Act obliges providers (and, where applicable, their authorised representatives) of high-risk AI systems to register themselves and their system in the EU database referred to in Art. 71 before placing the system on the market or putting it into service (Art. 49(1)). This obligation applies to all high-risk AI systems listed in Annex III – with one exception: systems falling under Annex III, point 2, are not registered in the EU database but at national level (Art. 49(5)).
Even where a provider, when carrying out the classification under Art. 6(3), concludes that its system is in fact not high-risk despite the general Annex III classification, the registration obligation does not simply disappear: under Art. 49(2), that assessment too – i.e. the finding of “not high-risk despite Annex III classification” – must be registered in the EU database before the system is placed on the market or put into service.
Who must register: providers and deployers
The registration obligation does not fall solely on providers. Art. 49(3) also obliges deployers, where these are public authorities, institutions, bodies or agencies of the Union, or persons acting on their behalf. Before putting into service or using a high-risk AI system under Annex III (again, with the exception of point 2), such deployers must register themselves in the EU database, select the relevant system and record it there.
In practice, this means: if you develop a high-risk AI system as a provider, the registration obligation falls on you. If, on the other hand, you merely deploy such a system as a public body within the meaning of paragraph 3, a separate, additional registration obligation arises on the deployer side. Both obligations must be assessed independently of one another.
Special rules for sensitive areas
For certain high-risk AI systems under Annex III, points 1, 6 and 7 – that is, systems used in law enforcement, migration, asylum and border control management – Art. 49(4) provides for a different transparency regime: registration takes place in a secure, non-public section of the EU database. Only selected information from Annex VIII, Section A (points 1 to 10, excluding points 6, 8 and 9), Section B (points 1 to 5, and 8 and 9), Section C (points 1 to 3), and from Annex IX (points 1, 2, 3 and 5) is entered there. Access to these restricted sections is limited to the Commission and the national authorities competent under Art. 74(8).
For these categories of system, it is therefore not sufficient to submit the same dataset as for “ordinary” high-risk systems – a separate, reduced and non-public scope of information applies.
A common gap in practice
In practice, the registration obligation is often misunderstood as a purely administrative formality tacked on at the end of the conformity process – along the lines of “someone in legal will enter that shortly before launch”. This underestimates two things.
First, registration is a precondition, not a subsequent step: under Art. 49(1) to (3), the system may only be placed on the market, put into service or used once registration has taken place – the wording explicitly refers to “before placing on the market or putting into service”. A launch date without completed registration is a compliance risk, not merely a formal loose end.
Second, the special-case assessment under Art. 49(2) is often overlooked: those who initially classify their system under Annex III but then conclude, via Art. 6(3), that it is “not high-risk”, sometimes assume this disposes of any registration obligation. The opposite is true – it is precisely this assessment that must be documented and entered in the EU database.
As 2 August 2026 marks the deadline for the high-risk obligations under Annex III, providers and affected public deployers should clarify now – not shortly before the deadline – who is responsible for registration, with which data, and in which part of the database.
Where to start
The registration obligation under Art. 49 cannot be fulfilled in isolation – it presupposes that you know whether, and under which Annex III category, your system falls; who qualifies as a provider or deployer within the meaning of the Regulation; and which information from Annex VIII and IX is relevant to your case. Using the free risk check at /einstufung, you can obtain an initial classification of your AI system and an overview of the resulting obligations – as a starting point for further implementation.