Direct answer
What data requirements does the AI Act set for high-risk AI (Article 10)?
You describe: You want to know which requirements apply to training, validation and test data and what you must be able to demonstrate about them. Likely role: mainly the provider; the deployer controls relevant input data.
This applies now
- For this situation, the preparation phase matters most right now.
Coming up
- Article 10: data and data governancefrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
Article 10 requires data governance across the lifecycle: datasets appropriate for the intended purpose, attention to representativeness, errors and completeness, and examination of possible bias with appropriate mitigation. The requirement follows the high-risk timeline to 2 December 2027, but the datasets you build or procure now determine whether you can comply then.
Your first actions
- Set up data governance per dataset. Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
- Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Record this
- Data governance file
- Article 6 and Annex III classification record
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationFollow-up questions
Execution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approach