Articles 49 and 71 of Regulation (EU) 2024/1689 were read at the European Commission AI Act Service Desk on 25 September 2026, and the paragraph numbering below is that of the text served there. Neither page carried an amendment notice on that date, and this desk has not read an amended text of either article. Where the Act does not answer a question, this article says so rather than supplying an answer of its own. It does not describe any national measure, and it is not legal advice.
- Article 49(1) is the main duty and it is the provider's. Before placing on the market or putting into service an Annex III high-risk system, other than one in point 2 of Annex III, the provider or, where applicable, the authorised representative registers itself and the system in the EU database.
- Article 49(2) is the paragraph that catches people. Where a provider has concluded under Article 6(3) that a system in an Annex III area is not high-risk, it registers itself and that system anyway. The self-assessment is filed, and it is filed in a database the public can read.
- Article 49(3) is the only deployer registration in the article, and it applies to public authorities, Union institutions, bodies, offices and agencies, and persons acting on their behalf. They register themselves, select the system and register its use. A private company deploying the same system registers nothing.
- Two groups sit outside the public central register. Law enforcement, migration, asylum and border control systems go into a secure non-public section under Article 49(4) with limited information. Point 2 of Annex III, critical infrastructure, is registered at national level under Article 49(5).
- Under Article 71 the Commission is the controller of the database, providers and representatives enter Sections A and B of Annex VIII, public authority deployers enter Section C, and what is registered under Article 49 is publicly available and free of charge apart from the secure section and certain real world testing information.
One article, four registrations
Read Article 49 as a list of who files rather than as a single obligation and it becomes straightforward. Paragraph 1 addresses the provider of an Annex III high-risk system. Paragraph 2 addresses the provider of a system that the provider has concluded is not high-risk. Paragraph 3 addresses a public sector deployer. Paragraph 4 addresses the law enforcement and border family. Paragraph 5 sends critical infrastructure somewhere else entirely.
The first paragraph reads: "Before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71." Two registrations are being made in one sentence. The organisation is registered, and the system is registered. A provider with six Annex III systems registers once as an organisation and six times as a system.
The trigger is an act and not a date. Placing on the market is defined in Article 3(9) as the first making available of an AI system on the Union market, and putting into service in Article 3(11) as the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose. Both are single moments, and the duty sits in front of them. Nothing in Article 49 requires a periodic refiling, although the accuracy of what is on the register is a different question from whether the initial entry was made.
The paragraph that turns an exemption into a filing
Article 6(3) is the route by which a provider whose system falls into an Annex III area concludes that the system is nonetheless not high-risk, because it does not pose a significant risk of harm to health, safety or fundamental rights. It is the most consequential judgement call in the classification regime, and it is covered separately in the Article 6 classification guide.
Article 49(2) then says what happens next: "Before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71."
The structural point is worth stating plainly, because it is the opposite of how exemptions usually behave. Concluding that you are outside the high-risk obligations does not remove you from the register. It puts you on it. The Act pairs a self-assessment with a public record of the fact that the self-assessment was made, and the assessment itself is documented under Article 6(4), which requires the provider to document that assessment before the system is placed on the market or put into service and to provide it to national competent authorities on request.
For an operator planning a classification exercise, that changes the standard the work has to meet. A judgement that is defensible in an internal file is one thing. A judgement whose existence is discoverable by a competitor, a claimant, a journalist or a supervisory authority looking down a list is another. The reasoning does not become public, but the conclusion does.
The only deployer registration in the article
Paragraph 3 reads: "Before putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71."
Three acts again, and a different shape from the provider's. The body registers itself, then selects a system that is already on the register, then registers the use it is making of it. The design assumes the provider filed first, which is why the deployer's step is a selection rather than a fresh description of the system.
The class is defined by what the deployer is, not by what the system does. A hospital trust, a ministry, a municipality, a Union agency and a contractor acting on behalf of one of them are inside it. A bank, an insurer, a recruitment firm and a manufacturer deploying an identical Annex III system are outside it, and they make no Article 49 registration at all. That asymmetry surprises private sector compliance teams who have read about the EU database and assumed a filing duty of their own. Their high-risk duties are real and they are set out in Article 26, and they are covered in the Article 26 deployer guide. Registration is not among them. The one exception to that is the public sector case in Article 26(8), which cross refers to this same Article 49(3) duty.
There is one way a private deployer arrives at Article 49(1) anyway, and it is not through Article 49 at all. Article 25 sets out when a deployer, distributor or importer is considered to be a provider of a high-risk system, which includes putting its own name or trademark on a high-risk system already placed on the market and making a substantial modification to such a system. The party that crosses that line takes the provider's obligations with it, registration included. The crossing is examined in the Article 25 value chain guide, and it is the single most common way an organisation acquires duties it did not budget for.
Two groups that are not in the public register
Paragraph 4 deals with high-risk systems in the areas of law enforcement, migration, asylum and border control management. Registration for those is made in a secure non-public section of the database, and the information recorded is limited. Paragraph 5 is one sentence: "High-risk AI systems referred to in point 2 of Annex III shall be registered at national level." Point 2 of Annex III is the critical infrastructure category, and it is the reason both paragraph 1 and paragraph 3 carry the same carve out in their opening words.
The practical consequence for anyone intending to use the register as a diligence tool is that absence proves less than it appears to. A system that is not in the public database may be unregistered, or it may be a critical infrastructure system registered nationally, or it may sit in the secure section, or it may not be high-risk at all and never have had a duty. A search of the register answers one question well, which is whether a named provider and system are there, and answers the inverse question badly.
What Article 71 actually establishes
Article 71 is the database itself. The Commission is the controller of it, and it makes available to providers, prospective providers and deployers adequate technical and administrative support. The data comes from Annex VIII: providers or their authorised representatives enter the information in Sections A and B, and deployers acting as or for public authorities enter the information in Section C.
On access, the article provides that information registered under Article 49 is accessible and publicly available in a user friendly manner, free of charge, and machine readable, with the exception of the section referred to in Article 49(4) and of the real world testing information under Article 60(4)(c), for which publication requires the provider's consent. The service desk page for Article 71 served a summary rather than the full text on the date this article was written, and the paragraph numbering of Article 71 is therefore not cited here. The propositions above are the ones the page stated.
Free, public and machine readable is the part to sit with. A register of that shape is read by procurement teams, by underwriters assessing a risk, by research groups and by the assistants those people now use. What an organisation writes into Sections A and B is public description of its own product, filed by itself, under a legal duty of accuracy. It is the first machine readable statement most AI providers will make about their systems to anyone outside their own customers.
Where this sits on the calendar
Article 49 has no application date of its own. It arrives with the high-risk regime it belongs to. Following Regulation (EU) 2026/1744, the obligations for stand alone Annex III high-risk systems apply from 2 December 2027, and those for Annex I high-risk systems embedded in regulated products from 2 August 2028. What already applies, and has since 2 August 2026, is the transparency layer in Article 50, the prohibitions, the general purpose AI provisions and the AI literacy duty, with supervision and enforcement running.
So for most operators this is a duty with roughly fourteen months in front of it, and that is exactly the reason to settle the classification question now rather than later. The registration is a form. The thing that takes the time is knowing, for every system, which of these four paragraphs applies to it, and that is a question about classification and about role, not about filing. The sequencing is set out in the deployer plan to December 2027.
One further note on the text, and it is a caution rather than a finding. The European Commission has described the AI Omnibus as simplifying the registration of exempted systems in the EU database. The Article 49 page at the service desk carried no amendment notice on 25 September 2026, while the Article 50 page on the same site carried one stating that the provision had been amended and that the displayed text had not yet been updated. This desk therefore reproduces Article 49 as served and flags that an amended text of it has not been read. The general problem, of an authoritative surface serving a text that is no longer the operative one, is set out in the note on unamended article text.
What to do with this before December 2027
Four questions, asked once per system, produce every answer Article 49 needs.
Are we the provider of this system or the deployer of it? Not who built it, but whose name is on it and who has modified it. The answer decides whether any Article 49 paragraph is addressed to you at all.
Is it in an Annex III area, and if so which point? Point 2 goes to a national register. Everything else in Annex III, other than the law enforcement and border family, goes to the public one.
If we are relying on Article 6(3), is that documented and is the filing understood as public? The Article 6(4) documentation duty and the Article 49(2) registration duty are two halves of the same decision, and teams routinely plan for the first without noticing the second.
Are we a public authority or acting on behalf of one? If yes, Article 49(3) is yours and it is a separate entry from anything the provider did. If no, no registration is yours unless Article 25 has made you a provider.
The evidence that answers those four questions is the same evidence that answers most other questions in this regime, which is a current list of the AI systems in the organisation with a role and a classification recorded against each. The case for building it first, and what it has to contain to be worth anything later, is made on the certification desk in the AI asset inventory as the first evidence artefact.
Questions
Does a company that deploys an AI system have to register it in the EU database?
Only if it is a public authority, a Union institution, body, office or agency, or a person acting on their behalf. Article 49(3) places the deployer registration duty on those bodies alone, for Annex III high-risk systems other than point 2. A private company that deploys a high-risk AI system registers nothing under Article 49. The registration for that system is made by its provider under Article 49(1), or by the provider's authorised representative.
Do you have to register an AI system you have assessed as not high-risk?
Yes, where the conclusion is reached under Article 6(3). Article 49(2) provides that before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71. The exemption is a filing, not a silence.
Is the EU database for high-risk AI systems public?
Largely yes. Article 71 provides that information registered under Article 49 is accessible and publicly available in a user friendly manner, free of charge and machine readable, with two carve outs: the secure non-public section for the law enforcement, migration, asylum and border control systems covered by Article 49(4), and real world testing information under Article 60(4)(c), whose publication requires the provider's consent. The Commission is the controller of the database.
When does the Article 49 registration duty actually bite?
Registration is tied to an act rather than to a calendar date: it happens before placing on the market or putting into service. The calendar matters because the obligations for stand alone Annex III high-risk systems apply from 2 December 2027 following Regulation (EU) 2026/1744, and those for Annex I systems embedded in regulated products from 2 August 2028.
Which high-risk systems are not registered centrally?
Two groups. Point 2 of Annex III, critical infrastructure, is registered at national level under Article 49(5). Systems used in law enforcement, migration, asylum and border control management are registered under Article 49(4) in a secure non-public section of the database, with a limited set of information.
Can a deployer become the party that has to register?
Yes, by becoming a provider. Article 25 sets out when a deployer, distributor or importer is considered a provider of a high-risk system, which includes putting its own name or trademark on the system and making a substantial modification to it. A party that crosses into the provider role takes the provider's duties with it, and the Article 49(1) registration is one of them.
Sources
- Regulation (EU) 2024/1689 (EU AI Act), Article 49, read at the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu, on 25 September 2026. Quotations of paragraphs 1, 2, 3 and 5 are verbatim from the text served there. The page carried no amendment notice on that date.
- Regulation (EU) 2024/1689, Article 71 (EU database for high-risk AI systems listed in Annex III), read at ai-act-service-desk.ec.europa.eu on 25 September 2026. That page served a summary rather than the full text, so no paragraph of Article 71 is cited by number and nothing in section 5 is presented as a quotation.
- Regulation (EU) 2024/1689, Article 3(9) and Article 3(11) (placing on the market, putting into service), read at ai-act-service-desk.ec.europa.eu on 25 September 2026.
- Regulation (EU) 2024/1689, Article 26, read at ai-act-service-desk.ec.europa.eu on 25 September 2026, for the deployer duties referred to in section 3.
- Regulation (EU) 2026/1744 (the AI Omnibus), under which Annex III high-risk obligations apply from 2 December 2027 and Annex I obligations from 2 August 2028, and which is described as simplifying the registration of exempted systems in the EU database, as published by the European Commission at digital-strategy.ec.europa.eu. An amended text of Article 49 was not read for this article.
- The observation in section 4 that absence from the public register is weakly informative, the reading in section 2 of Article 49(2) as a public record of a self-assessment, and the four questions in section 7 are this desk's own analysis and are not attributed to any institution.
- No national measure has been read for this article, and nothing in it describes the law or the practice of any Member State.
- No relationship exists between Future Proof Intelligence and any institution named in this article.