Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 10 — Data and data governance

Article 10 governs the training, validation and testing data behind a high-risk system: documented governance practices, examination for bias, and datasets that are relevant, sufficiently representative and — to the best extent possible — free of errors. Those last qualifiers are the whole provision, and they are the half most often quoted away.

§ 1 — Who it binds

Which data this reaches, and whose duty it is

Provider

High-risk systems that make use of techniques involving the training of AI models with data, and only whenever such datasets are used. Systems that train no model are not exempt — the governance, representativeness and setting requirements then apply to the testing datasets. Annex I Section B systems carry no Article 10 duty at all under the amended scope provision.

§ 2 — In practice

The qualifiers that are the obligation

The sentence everyone cites is "free of errors and complete", and it is never cited whole. The text reads relevant, sufficiently representative, and to the best extent possible free of errors and complete in view of the intended purpose. No dataset of consequence is error-free; the obligation is a reasonable-endeavours one measured against a declared purpose. What carries no such qualifier is the duty to identify relevant data gaps and shortcomings and how they can be addressed — so an honest defect register discharges more of this article than an assertion of cleanliness does.

"Sufficiently representative" is read as demographic parity and means something narrower. The requirement is appropriate statistical properties as regards the persons or groups the system is intended to be used on — representativeness of the deployment population, not of the general population, and not equalised outcomes. The provision then grants latitude that is routinely overlooked: those characteristics may be met at the level of individual datasets or at the level of a combination of them.

Two things follow that catch people. A system that trains no model is not exempt: for those, the governance, representativeness and setting requirements apply to the testing data instead. And Article 10 does not reach production data at all — the live-input duty belongs to the deployer under Article 26, in narrower terms and against a different party. Presenting production data-quality controls against Article 10 is a recurring finding in regulated firms, and it answers a question nobody asked.

The Digital Omnibus deleted the special-category derogation that used to sit here, and several commentaries filed that under deregulation. It was relocated, essentially intact, into a new provision — and then widened, extending the same permission to systems that are not high-risk and to deployers. The closing words of that extension are the ones to quote at anyone reading it as a new fairness-testing mandate: it creates no obligation to conduct bias detection and correction. It is a permission with binding conditions attached, not an exemption and not a duty.

The bias limb is where this article meets the rest of the Regulation. Examination for biases likely to affect health and safety, to have a negative impact on fundamental rights, or to lead to prohibited discrimination is not a standalone data exercise — it is the input to the risk process in Article 9 and the thing the declared accuracy figures under Article 15 are eventually measured against. A bias examination that produces no entry in the risk register has been performed and not used.

§ 3 — What a weak answer looks like

A data quality report is not a data governance file

A data quality report answering the wrong question. It reports completeness, null rates and duplicate counts — a competent engineering artefact — and says nothing about whether the data represents the people the system will be used on, what is known to be missing from it, or whether examination for bias changed anything. Article 10 is not a data hygiene requirement. It asks whether the data supports the intended purpose for the population in question, and a report that never names that population cannot answer it.

§ 4 — What discharges it

What a defensible data file contains

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    A dataset defect register, with treatment

    The duty to identify relevant gaps and shortcomings and how they can be addressed is unqualified, unlike the error-freedom language around it. A register naming known limitations and what was done about each is the strongest single artefact under this article.

  2. 02

    The representativeness argument, tied to intended use

    Not a demographic table. A stated deployment population, evidence the data reflects it, and where it does not, the consequence. The article permits the argument to be made across a combination of datasets rather than each one.

  3. 03

    Provenance and original collection purpose for personal data

    Governance practices must cover data origin and, for personal data, the purpose it was originally collected for. This is where the article overlaps with data-protection law and where reuse of historical operational data usually fails.

  4. 04

    A bias examination that reached the risk register

    The examination is required; its use is what makes it evidence. An assessor traces a finding from the bias work to a risk entry, a mitigation, and a measurement.

  5. 05

    Where special-category data was processed, the conditions record

    The relocated derogation carries binding conditions, and it is additive to data-protection law rather than a standalone basis. The record shows which conditions were met and why the processing was strictly necessary.

§ 5 — Worked example

Worked example — a bias check that tested the wrong thing

A recruiter licenses a CV-screening model trained on eight years of its own placements. The provider’s file records a bias examination: overall selection rates were compared across sex and age bands and no material difference was found. The evaluation set was a random sample of the same eight years of placements.

Does the bias examination discharge Article 10(2)?

Partly, and the gap is in the design rather than the execution. Comparing selection rates on a random sample of historical placements tests whether the model reproduces the historical pattern — which it will, that being what it was trained to do. It does not test what the article asks about: biases likely to lead to discrimination prohibited under Union law, in the population the system is intended to be used on. Two things are missing. The representativeness question is unanswered, because the deployment population is other employers’ applicant pools rather than this recruiter’s past hires, and the article ties representativeness to intended use. And the data gaps duty is unaddressed: eight years of one firm’s placements has known shortcomings, and the article requires those to be identified and their treatment described, not eliminated. A defensible file would state the shortcoming plainly and say what was done about it.

§ 6 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • ISO/IEC 42001

    ISO/IEC 42001 Annex A carries a family of controls covering data for development, acquisition, quality, provenance and preparation. It is the closest clause-level correspondence between the standard and this article; cited by number and title so the reference stays checkable.

  • NIST AI RMF

    MEASURE 2.11 addresses evaluation and documentation of fairness and bias identified in the MAP function. It supplies measurement method for the examination this article requires.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 7 — When it applies

When the data duties apply

  1. 2 December 2027

    Annex III standalone high-risk systems. Moved from 2 August 2026 by the Digital Omnibus — a sixteen-month extension driven by undesignated national authorities and the absence of harmonised standards, not by any relaxation of the Section 2 requirements themselves.

  2. 2 August 2028

    Annex I embedded high-risk systems — medical devices, machinery, vehicles — where AI Act requirements fold into the existing sectoral conformity assessment. Moved from 2 August 2027.

§ 8 — Exposure

Exposure — two regulators, not one

€15 million or 3% of worldwide annual turnover, whichever is higher

Article 99(4)(a), reached through Article 16(a) — Article 10 sits in Chapter III Section 2 and is not itself enumerated in Article 99(4). A second and separate exposure runs through data-protection law where special-category data is processed outside the conditions the relocated derogation sets, which is a different regulator and a different ceiling. Articles 99(6) and 99(6a) give SMEs and small mid-caps the lower figure.

§ 9 — Where this is assessed

Where this is assessed

Examined in 3 credentials, in the domains named on each card.

CAIC-FCompliance

Certified AI Compliance Fundamentals — EU AI Act

High-risk obligations and conformity · 25% of the paper

The EU AI Act as enacted: the risk-tier structure, the roles the Act defines, the obligations attaching to each, and the timeline on which they apply.

Compliance
CAIA-EMP-FAssurance

Certified AI Assurance Employment Fundamentals

Disparate-impact fundamentals · 25% of the paper

Employment-AI law and bias-audit fundamentals: automated employment decision tools under NYC Local Law 144, adverse impact and the four-fifths rule, and the EU AI Act’s high-risk employment scope.

Employment & hiring
CAIC-DP-FCompliance

Certified AI Compliance Fundamentals — Data Protection

Data-protection foundations applied to AI · 25% of the paper

Data protection applied to AI: automated decision-making under GDPR Article 22, data protection impact assessments, and privacy by design in systems that learn from personal data.

Data protection

§ 10 — provenance

The provision itself

This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.