Effective Date

EU AI Act Articles 10 and 17 — covering data governance and quality management for high-risk AI — became enforceable for new systems on 2 August 2026.

What the Law Requires

High-risk AI systems must now demonstrate:

  1. Data provenance documentation — where training and operational data came from
  2. Bias and quality audits — periodic checks on data representativeness
  3. Error correction processes — documented procedures for identifying and fixing data errors
  4. Version control — traceability of which data version was used to produce which output

Sectors Affected

  • Medical device AI (diagnostics, treatment recommendation)
  • Credit scoring and loan decisioning
  • Employment screening tools
  • Educational assessment systems

Practical Implication

Organisations in these sectors must be able to trace any AI output to its underlying data, including the verification status of claims embedded in that data. Unverified benchmark data feeding an AI decisioning model is now a compliance risk, not just a quality issue.