GovCompass

Art. 49 EU AI Act: registration in the EU database for providers

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 49 requires providers of high-risk AI systems to register the system in the EU database before placing it on the market. The database serves both market surveillance and public accountability, letting citizens see which high-risk systems are in use.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: public accountability through registration

Article 49 of the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → establishes the EU database for high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →, a public-facing transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → instrument that allows regulators, researchers, and the public to see which high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → are deployed in the EU market. Registration is primarily a providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → obligation, but deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → have related verification and, in some cases, direct registration duties.

What is the EU database?

The EU AI database is a centrally managed, publicly accessible registry of high-risk AI systems. It is maintained by the EU AI OfficeAI OfficeThe European Commission body that coordinates implementation of the EU AI Act and supervises general-purpose AI models. National market surveillance authorities enforce the Act for most AI systems; the AI Office is the central point for the general-purpose AI layer. See general-purpose AI, EU AI Act.Open full entry → and includes:

  • Provider identification and contact information
  • The AI system's name and version
  • The Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → classification category
  • Intended purpose and deployment context
  • Countries of deployment within the EU
  • Link to the EU declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry →
  • Post-market monitoringpost-market monitoringProvider-side duty to systematically collect and act on experience from systems in use, the product-regulation half of continuous monitoring.Open full entry → plan summary

The database has a public section (accessible to all) and a restricted section (accessible to market surveillance authorities only, containing confidential technical information).

Provider registration obligations under Art. 49

Art. 49.1 requires providers to register their high-risk AI systems before placing them on the EU market. Key requirements:

  • Registration must occur prior to market placement, not after
  • Each new version of a high-risk AI system requires a new or updated registration
  • Providers outside the EU must designate an EU authorized representativeauthorized representativeA person established in the EU, appointed in writing by a non-EU provider to carry out the provider's obligations under the AI Act.Open full entry → to handle registration
  • Registration generates a unique system identifier that must appear on the EU declaration of conformity

Deployer verification and due diligence

For deployers, Art. 49 creates an important due diligence obligation: verify that your high-risk AI provider has fulfilled registration obligations. Steps:

  1. Request the EU database registration number from your provider
  2. Cross-check the number against the public EU database once operational
  3. If the provider cannot provide a registration number, this is a red flag requiring further investigation before deployment
  4. Document your verification process

Compliance checklist

  1. Have you requested EU database registration numbers from all high-risk AI providers?
  2. Have you verified these numbers against the public database?
  3. If you are a deployer with provider-equivalent obligations (provider outside EU): have you registered?
  4. Are registration numbers retained in your AI system inventory?
Legal referencesArt. 49
Share Share on LinkedIn

More on Transparency & explainability

Transparency templates for EU AI Act Art. 50: ready to use

Guide

Ready-to-use transparency templates help deployers meet the EU AI Act information duties: a chatbot disclosure, an AI-generated-content label, and an Art. 26(11) notice for individuals subject to a high-risk system. The disclosure must be active and comprehensible at the moment of interaction.

Art. 26.8 EU AI Act: registration in the EU database

Reference

Art. 26.8 requires deployers that are public authorities (or act on their behalf) to verify that a high-risk AI system is registered in the EU database before putting it into use, and to refrain from using it if it is not.

Art. 26(11) EU AI Act: informing individuals subject to high-risk AI decisions

Reference

Art. 26(11) requires deployers of high-risk AI to inform the people who are subject to the system's decisions that a high-risk AI system is being used. This applies even where there is no direct interaction, such as CV screening or credit scoring.

Art. 50 EU AI Act, transparency: inform users about AI interaction

Reference

Art. 50 of the EU AI Act sets four transparency duties: providers must ensure people know they are interacting with an AI system and must mark AI-generated content in a machine-readable way; deployers must inform people exposed to emotion recognition or biometric categorization and must disclose deep fakes and AI-generated text on matters of public interest. The obligations apply from 2 August 2026, with fines up to €15 million or 3% of global annual turnover, whichever is higher. One transition applies: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty.