EU AI Act Art.71 Database Registration: Complete Developer Compliance Checklist 2026

This post closes the five-part EU AI Act Art.71 database registration series. Whether you have read the previous four parts or are arriving here fresh, this checklist stands on its own. It covers both registration regimes under Art.71, what each requires you to submit, the exact deadline picture after the Digital Omnibus amendments, and a practical action plan.
One critical update before the checklist: the registration deadline for Annex III high-risk AI systems has changed. If you have been planning toward an August 2026 deadline, you need the corrected timeline below before anything else.
Critical: The Deadline Picture After the Digital Omnibus
On 16 June 2026, the European Parliament adopted the Digital Omnibus — a set of targeted amendments to Regulation (EU) 2024/1689, the EU AI Act. The Council of the European Union formally adopted it on 29 June 2026. The primary effect was a 16-month extension of the Annex III compliance timeline.
Many earlier posts on this blog and elsewhere mentioned 2 August 2026 as the deadline for Annex III high-risk AI compliance, including Art.71 database registration. That date was correct when written. It is no longer correct.
Here is the complete, current deadline map:
| Obligation | Original Deadline | Current Deadline |
|---|---|---|
| Art.5 prohibited AI practices | 2 February 2025 | 2 February 2025 (already in force) |
| GPAI model obligations Chapter V (Art.51–56) | 2 August 2025 | 2 August 2025 (already in force — not changed) |
| Art.4 AI literacy obligations | 2 August 2025 | 2 August 2025 (already in force) |
| Art.50 transparency requirements | 2 August 2026 | 2 August 2026 (unchanged) |
| Art.50 grace period for existing systems | — | 2 December 2026 (new, Omnibus-introduced) |
| AI regulatory sandboxes (Art.57–65) | 2 August 2026 | 2 August 2027 |
| Annex III standalone high-risk AI systems — including Art.71 registration | 2 August 2026 | 2 December 2027 |
| Annex I embedded high-risk AI (safety components in regulated products) | 2 August 2026 | 2 August 2028 |
The key distinction this post is built around: The Digital Omnibus extension applies to Annex III standalone high-risk AI systems. It does not affect GPAI model obligations under Chapter V (Art.51–56). GPAI model registration under Art.71(2) became applicable on 2 August 2025 and has been a live obligation since then.
If your organisation provides a GPAI model with systemic risk, you are already overdue or compliant. If you are building a standalone high-risk AI system under Annex III, your Art.71 registration deadline is now 2 December 2027.
Two Parallel Registration Regimes Under Art.71
Art.71 creates two separate registration obligations in a single EU database. Understanding which applies to your situation is the first step.
| Dimension | Art.71(1) — Annex III High-Risk AI Systems | Art.71(2) — GPAI Models with Systemic Risk |
|---|---|---|
| Legal basis | Art.49(1)–(3), Art.71(1) | Art.52, Art.71(2) |
| Who registers | Provider of high-risk AI system (or their authorised representative) | Provider of GPAI model with systemic risk |
| Registration template | Annex VIII, Sections A and B | Annex VIII, Part II (separate GPAI template) |
| Oversight authority | National competent authority (NCA) | European AI Office (EU-level) |
| Deadline | 2 December 2027 (post-Omnibus) | 2 August 2025 (already in force) |
| Pre-launch gate | Yes — must register before placing on market | Yes — must register before making available in EU |
| Public visibility | Yes for non-confidential fields; restricted section for law enforcement/migration | Yes for non-confidential fields; IP and confidential business info protected |
Most SaaS developers fall into one or both categories:
- If you are building a product that qualifies as an Annex III standalone high-risk AI system, Art.71(1) applies.
- If you are a foundation model provider whose model exceeds 10^25 FLOPs training compute or has been designated by the Commission as having high-impact capabilities, Art.71(2) applies.
- If you are a downstream operator building on a third-party GPAI API (OpenAI, Anthropic, Google, Mistral), neither Art.71(1) nor Art.71(2) makes you the registrant — but you must verify that your upstream provider has fulfilled their Art.71(2) obligation.
Regime 1: Annex III High-Risk AI System Registration
Step 1 — Determine Whether Annex III Applies
Annex III of the EU AI Act lists eight categories of high-risk AI. Work through this checklist:
- Biometric systems (real-time remote biometric identification, emotion recognition used in employment or education contexts, biometric categorisation that infers sensitive attributes)
- Critical infrastructure management (AI managing electricity grids, water systems, digital infrastructure)
- Education and vocational training (AI that determines access to or evaluates performance in education, detects prohibited behaviour during exams)
- Employment and workers management (CV screening, recruitment, task allocation, performance monitoring, termination decisions)
- Access to essential private services (creditworthiness assessment, insurance risk scoring, emergency services dispatch prioritisation)
- Law enforcement (risk profiling of individuals, polygraph-adjacent tools, crime prediction and analytics)
- Migration, asylum, and border control (lie detection at borders, risk assessment for asylum seekers, irregular migration prediction)
- Administration of justice (AI assisting courts or juries in researching or evaluating facts and applying law)
If your system falls into any of these, check whether you are a provider under Art.3(3) — meaning you develop the system and place it on the EU market or put it into service, including through a SaaS model.
One exception: If your AI is a safety component embedded in a product already regulated under existing EU product legislation (medical devices, vehicles, aircraft, lifts, toys — listed in Annex I of the EU AI Act), the Art.71 database is not where you register. Those systems follow the conformity assessment procedures of the relevant product legislation (e.g., EUDAMED for medical devices).
A second exception: Annex III, point 2 systems (critical infrastructure) register at national level with the national competent authority, not in the central EU database.
Step 2 — Complete the Pre-Registration Prerequisites
Registration is not the first step. You cannot meaningfully complete an Art.71 database entry without having the following documentation ready:
- Technical documentation package (Annex IV): intended purpose, AI system description, model architecture, training data specifications, risk management system implementation, post-market monitoring plan, accuracy/robustness/cybersecurity measures
- Risk Management System (Art.9): documented and tested. The registration form requires a summary of your risk management approach.
- Conformity assessment completed (Art.43): self-assessment for most Annex III systems; notified-body assessment is mandatory for biometric identification systems and certain other categories.
- EU Declaration of Conformity issued (Art.47): signed document attesting that the system meets all applicable requirements. A copy is submitted as part of the registration.
- CE marking affixed (Art.48): must be visible on the system or accompanying documentation before you register and place on market.
- Authorised representative designated (Art.22): required for providers established outside the EU. The authorised representative is the registrant of record.
- Electronic instructions for use prepared: must be available for operators as part of the registration submission. (Exception: law enforcement, migration/asylum/border control systems are exempt from this specific field being publicly visible.)
Step 3 — Assemble Annex VIII Section A Fields
Annex VIII Section A is the registration form for providers placing high-risk AI systems on the market under Art.49(1). Required fields:
- Provider identity: Legal name, registered address, contact details. If non-EU, the authorised representative's details.
- System identification: Trade name of the AI system, any applicable reference or version numbers, unique identifier assigned at registration.
- Intended purpose: A description of what the system is designed to do, the specific Annex III category it falls under, and the sector of deployment.
- Data inputs and operating logic summary: What types of data the system processes, a high-level description of the logic by which the system produces its outputs.
- Current market status: Whether the system has been placed on the market, is in service, or has been recalled or withdrawn.
- Conformity assessment details: The procedure followed (self-assessment or notified-body), the notified body's name and identification number if applicable, and the certificate reference.
- EU Declaration of Conformity: A copy or link to the declaration.
- Electronic instructions for use: Link to or copy of the documentation provided to operators and deployers.
- Optional additional URL: A web link where further information about the system is publicly available.
Step 4 — Non-High-Risk Self-Assessment Registration (Art.49(2))
If you have assessed your AI system and concluded it does not meet the Annex III threshold (e.g., through the Art.6(3) self-classification mechanism), you are still required to register that conclusion in the EU database. This registration uses Annex VIII Section B:
- Provider and system identification (same as Section A)
- Intended purpose
- Art.6(3) conditions justifying non-high-risk classification: Which specific conditions in Art.6(3) your system meets, and why.
- Summary of grounds: The reasoning behind the non-high-risk determination, written in a form that could withstand NCA scrutiny.
- Current system status
- Member States where deployed
This obligation is frequently overlooked. The Digital Omnibus preserved it despite some proposals to remove it. Registering your non-high-risk determination makes your classification transparent and creates a documented audit trail if the NCA later disputes it.
Step 5 — Public Deployer Registration (Art.49(3))
If you are a public authority deploying a high-risk AI system — or a private body acting on behalf of a public authority — you have a separate registration obligation under Art.49(3). This uses Annex VIII Section C:
- Deployer contact details: Legal name, address, contact information.
- Link to provider's EU database entry: The registration ID of the provider's entry for the same system.
- Fundamental Rights Impact Assessment (FRIA) summary: Art.27 requires public sector deployers of high-risk AI to conduct a FRIA before deployment. A summary of findings must be entered in the database.
- Data protection impact assessment summary: Where a DPIA was required under GDPR (Art.35 GDPR) in connection with the AI system, a summary is required.
SaaS developers selling to the public sector: if your customer is a public authority, their Art.49(3) obligation is separate from yours, but you should factor this into your onboarding documentation and help them meet it.
Regime 2: GPAI Model Registration (Art.71(2)) — Already Applicable
This section applies to providers of GPAI models with systemic risk. If you are building on top of a GPAI API, skip to the supply chain verification checklist below this section.
Does Art.51 Systemic Risk Classification Apply?
A GPAI model must be registered if it falls into Art.51 systemic risk:
- Route 1 — Compute threshold: Does the model's training computation exceed 10^25 floating point operations (FLOPs)? If yes, systemic risk is presumed.
- Route 2 — Commission designation: Has the Commission issued a decision designating the model as having systemic risk based on high-impact capabilities, following a recommendation from the scientific panel or the AI Office's own assessment under Art.52?
If either condition applies, the provider must notify the Commission within two weeks of the threshold being met or the designation being issued (Art.52(1)).
Annex VIII Part II Fields (GPAI Registration)
The GPAI registration template is separate from Section A. It covers:
- Provider identity: Legal name, address, contact, any EU authorised representative.
- Model identification: Name, version numbers, unique identifier.
- Training methodology summary: Description of training approach (pre-training, fine-tuning, RLHF variants).
- Training data summary: Types and sources of data used; whether web-scraped, licensed, or synthetic.
- Computational resources: Training compute in FLOPs or the basis for the systemic risk classification.
- Capabilities and limitations: Known capability profile, known limitations, evaluation results.
- Intended purposes and reasonably foreseeable misuses: The range of downstream uses the model is designed or expected to support.
- Code of Practice adherence: Whether the provider has signed and is adhering to the AI Office's GPAI Code of Practice. The Code of Practice status is part of the registration.
Supply Chain Verification for Downstream Operators
If you build on a GPAI API, you are not the registrant — but you should be able to verify the following:
- Request from your GPAI provider (via contract terms or documentation portal) confirmation that they have completed Art.52 notification if applicable.
- Request a reference to the EU database entry for their model.
- Verify that your contract with the GPAI provider includes the Art.53(1)(b) disclosure obligations: usage policy, downstream obligations, and information about the model's capabilities and limitations.
- Confirm your GPAI provider publishes or provides to downstream operators a summary of their technical documentation, as required by Art.53(1)(a).
Ongoing Registration Obligations
Registration is not a one-time event. The EU database must reflect the current state of your system. Obligations that trigger an update:
| Event | Action Required | Timing |
|---|---|---|
| Substantial modification of the AI system (Art.3(23)) | Update the registration to reflect new technical documentation, conformity assessment, and Declaration of Conformity | Before the modified system is re-placed on market |
| Change in intended purpose | Update Section A intended purpose field | Before deploying the system for the new purpose |
| System recalled or withdrawn | Update market status field | Promptly after decision to recall/withdraw |
| Change of authorised representative (non-EU providers) | Update provider/representative details | Without undue delay |
| Notified body certificate updated, renewed, or withdrawn | Update conformity assessment details | Before or upon change |
| NCA requests correction | Comply with the corrective action | Within the period specified by the NCA |
For GPAI providers with systemic risk, additional triggers include:
- Model update that significantly changes training compute or capability profile → reassess systemic risk classification
- Commission decision to reassess or revoke systemic risk designation → update registration status
- Code of Practice adherence changes → update registration
Developer Action Plan by Timeline
Based on the current deadline picture, here is the priority order:
Immediate (if you are a GPAI provider with systemic risk)
The Art.71(2) obligation has been in force since 2 August 2025. If your model meets the 10^25 FLOPs threshold or has been designated by the Commission:
- Confirm Art.52 notification was sent to the Commission within the required two-week window.
- Verify your EU database entry exists and Annex VIII Part II fields are complete.
- Review Code of Practice adherence status and update the registration if needed.
Near-term (if you are a downstream GPAI API operator)
- Request from your GPAI provider confirmation of their Art.52 notification and EU database entry reference.
- Review your contracts for Art.53(1)(b) downstream disclosure obligations.
- Document your supply chain verification in your compliance file.
Medium-term planning (if you build Annex III high-risk AI systems)
Your Art.71 registration deadline is 2 December 2027. Registration is a pre-launch gate — it must be completed before you place the system on the market. Plan backward from your product launch date.
24–18 months before launch:
- Complete your Art.9 Risk Management System documentation
- Begin Annex IV technical documentation package
- Identify your conformity assessment route (self-assessment vs. notified body)
12 months before launch:
- Finalize technical documentation
- Complete and document conformity assessment
- Engage notified body if required (lead times can be 6–12 months for biometric identification systems)
6 months before launch:
- Issue EU Declaration of Conformity
- Affix CE marking
- Prepare Annex VIII Section A fields
- Draft electronic instructions for use
Before launch:
- Complete EU database registration
- Receive registration confirmation
- Proceed to market placement
If planning to launch before 2 December 2027, the Digital Omnibus deadline is a floor, not a reason to delay. Early registration is permitted and demonstrates compliance posture to NCAs and enterprise customers conducting due diligence.
Non-High-Risk Determination Registration
If you have conducted an Art.6(3) self-assessment and determined your system is not high-risk:
- Document the full reasoning with reference to Art.6(3) conditions
- Complete Annex VIII Section B registration before deploying the system
- Retain the underlying assessment in your compliance file in case of NCA challenge
What This Series Covered
This post concludes the five-part EU AI Act Art.71 database registration series:
- Part 1: Who must register, the two regimes, the database structure, and what pre-launch registration means in practice.
- Part 2: Annex VIII Part I in detail — every field in the registration form, what level of detail is required, and common submission errors.
- Part 3: The GPAI registration regime under Art.71(2) — systemic risk classification, the Art.52 notification procedure, Annex VIII Part II, and what downstream operators must verify.
- Part 4: How NCAs use the database for market surveillance, what triggers scrutiny, and how to respond to an NCA inquiry.
- Part 5 (this post): Complete developer compliance checklist covering both registration regimes, Annex VIII requirements, ongoing obligations, and a timeline-based action plan incorporating the Digital Omnibus deadline update.
Primary Sources
All registration obligations cited in this post derive from the following primary legal texts. Verify any article number or deadline directly against these sources:
- Regulation (EU) 2024/1689 — EU AI Act full text (EUR-Lex) — Art.49, Art.51, Art.52, Art.71, Annex III, Annex VIII
- Art.71 annotated text with entry-into-force dates (artificialintelligenceact.eu)
- Art.49 registration obligations (artificialintelligenceact.eu)
- Art.51 systemic risk classification (artificialintelligenceact.eu)
- Annex VIII registration information requirements (artificialintelligenceact.eu)
- Digital Omnibus deadline changes — canonical explanation on this blog
EU-Native Hosting
Ready to move to EU-sovereign infrastructure?
sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.