sota.io
Join the waitlist
2026-07-23·14 min read·sota.io team

EU AI Act Art.71 Database Registration: Complete Developer Compliance Checklist 2026

EU AI Act Art.71 Database Registration: Complete Developer Compliance Checklist 2026

This post closes the five-part EU AI Act Art.71 database registration series. Whether you have read the previous four parts or are arriving here fresh, this checklist stands on its own. It covers both registration regimes under Art.71, what each requires you to submit, the exact deadline picture after the Digital Omnibus amendments, and a practical action plan.

One critical update before the checklist: the registration deadline for Annex III high-risk AI systems has changed. If you have been planning toward an August 2026 deadline, you need the corrected timeline below before anything else.


Critical: The Deadline Picture After the Digital Omnibus

On 16 June 2026, the European Parliament adopted the Digital Omnibus — a set of targeted amendments to Regulation (EU) 2024/1689, the EU AI Act. The Council of the European Union formally adopted it on 29 June 2026. The primary effect was a 16-month extension of the Annex III compliance timeline.

Many earlier posts on this blog and elsewhere mentioned 2 August 2026 as the deadline for Annex III high-risk AI compliance, including Art.71 database registration. That date was correct when written. It is no longer correct.

Here is the complete, current deadline map:

ObligationOriginal DeadlineCurrent Deadline
Art.5 prohibited AI practices2 February 20252 February 2025 (already in force)
GPAI model obligations Chapter V (Art.51–56)2 August 20252 August 2025 (already in force — not changed)
Art.4 AI literacy obligations2 August 20252 August 2025 (already in force)
Art.50 transparency requirements2 August 20262 August 2026 (unchanged)
Art.50 grace period for existing systems2 December 2026 (new, Omnibus-introduced)
AI regulatory sandboxes (Art.57–65)2 August 20262 August 2027
Annex III standalone high-risk AI systems — including Art.71 registration2 August 20262 December 2027
Annex I embedded high-risk AI (safety components in regulated products)2 August 20262 August 2028

The key distinction this post is built around: The Digital Omnibus extension applies to Annex III standalone high-risk AI systems. It does not affect GPAI model obligations under Chapter V (Art.51–56). GPAI model registration under Art.71(2) became applicable on 2 August 2025 and has been a live obligation since then.

If your organisation provides a GPAI model with systemic risk, you are already overdue or compliant. If you are building a standalone high-risk AI system under Annex III, your Art.71 registration deadline is now 2 December 2027.


Two Parallel Registration Regimes Under Art.71

Art.71 creates two separate registration obligations in a single EU database. Understanding which applies to your situation is the first step.

DimensionArt.71(1) — Annex III High-Risk AI SystemsArt.71(2) — GPAI Models with Systemic Risk
Legal basisArt.49(1)–(3), Art.71(1)Art.52, Art.71(2)
Who registersProvider of high-risk AI system (or their authorised representative)Provider of GPAI model with systemic risk
Registration templateAnnex VIII, Sections A and BAnnex VIII, Part II (separate GPAI template)
Oversight authorityNational competent authority (NCA)European AI Office (EU-level)
Deadline2 December 2027 (post-Omnibus)2 August 2025 (already in force)
Pre-launch gateYes — must register before placing on marketYes — must register before making available in EU
Public visibilityYes for non-confidential fields; restricted section for law enforcement/migrationYes for non-confidential fields; IP and confidential business info protected

Most SaaS developers fall into one or both categories:


Regime 1: Annex III High-Risk AI System Registration

Step 1 — Determine Whether Annex III Applies

Annex III of the EU AI Act lists eight categories of high-risk AI. Work through this checklist:

If your system falls into any of these, check whether you are a provider under Art.3(3) — meaning you develop the system and place it on the EU market or put it into service, including through a SaaS model.

One exception: If your AI is a safety component embedded in a product already regulated under existing EU product legislation (medical devices, vehicles, aircraft, lifts, toys — listed in Annex I of the EU AI Act), the Art.71 database is not where you register. Those systems follow the conformity assessment procedures of the relevant product legislation (e.g., EUDAMED for medical devices).

A second exception: Annex III, point 2 systems (critical infrastructure) register at national level with the national competent authority, not in the central EU database.

Step 2 — Complete the Pre-Registration Prerequisites

Registration is not the first step. You cannot meaningfully complete an Art.71 database entry without having the following documentation ready:

Step 3 — Assemble Annex VIII Section A Fields

Annex VIII Section A is the registration form for providers placing high-risk AI systems on the market under Art.49(1). Required fields:

Step 4 — Non-High-Risk Self-Assessment Registration (Art.49(2))

If you have assessed your AI system and concluded it does not meet the Annex III threshold (e.g., through the Art.6(3) self-classification mechanism), you are still required to register that conclusion in the EU database. This registration uses Annex VIII Section B:

This obligation is frequently overlooked. The Digital Omnibus preserved it despite some proposals to remove it. Registering your non-high-risk determination makes your classification transparent and creates a documented audit trail if the NCA later disputes it.

Step 5 — Public Deployer Registration (Art.49(3))

If you are a public authority deploying a high-risk AI system — or a private body acting on behalf of a public authority — you have a separate registration obligation under Art.49(3). This uses Annex VIII Section C:

SaaS developers selling to the public sector: if your customer is a public authority, their Art.49(3) obligation is separate from yours, but you should factor this into your onboarding documentation and help them meet it.


Regime 2: GPAI Model Registration (Art.71(2)) — Already Applicable

This section applies to providers of GPAI models with systemic risk. If you are building on top of a GPAI API, skip to the supply chain verification checklist below this section.

Does Art.51 Systemic Risk Classification Apply?

A GPAI model must be registered if it falls into Art.51 systemic risk:

If either condition applies, the provider must notify the Commission within two weeks of the threshold being met or the designation being issued (Art.52(1)).

Annex VIII Part II Fields (GPAI Registration)

The GPAI registration template is separate from Section A. It covers:

Supply Chain Verification for Downstream Operators

If you build on a GPAI API, you are not the registrant — but you should be able to verify the following:


Ongoing Registration Obligations

Registration is not a one-time event. The EU database must reflect the current state of your system. Obligations that trigger an update:

EventAction RequiredTiming
Substantial modification of the AI system (Art.3(23))Update the registration to reflect new technical documentation, conformity assessment, and Declaration of ConformityBefore the modified system is re-placed on market
Change in intended purposeUpdate Section A intended purpose fieldBefore deploying the system for the new purpose
System recalled or withdrawnUpdate market status fieldPromptly after decision to recall/withdraw
Change of authorised representative (non-EU providers)Update provider/representative detailsWithout undue delay
Notified body certificate updated, renewed, or withdrawnUpdate conformity assessment detailsBefore or upon change
NCA requests correctionComply with the corrective actionWithin the period specified by the NCA

For GPAI providers with systemic risk, additional triggers include:


Developer Action Plan by Timeline

Based on the current deadline picture, here is the priority order:

Immediate (if you are a GPAI provider with systemic risk)

The Art.71(2) obligation has been in force since 2 August 2025. If your model meets the 10^25 FLOPs threshold or has been designated by the Commission:

  1. Confirm Art.52 notification was sent to the Commission within the required two-week window.
  2. Verify your EU database entry exists and Annex VIII Part II fields are complete.
  3. Review Code of Practice adherence status and update the registration if needed.

Near-term (if you are a downstream GPAI API operator)

  1. Request from your GPAI provider confirmation of their Art.52 notification and EU database entry reference.
  2. Review your contracts for Art.53(1)(b) downstream disclosure obligations.
  3. Document your supply chain verification in your compliance file.

Medium-term planning (if you build Annex III high-risk AI systems)

Your Art.71 registration deadline is 2 December 2027. Registration is a pre-launch gate — it must be completed before you place the system on the market. Plan backward from your product launch date.

24–18 months before launch:

12 months before launch:

6 months before launch:

Before launch:

If planning to launch before 2 December 2027, the Digital Omnibus deadline is a floor, not a reason to delay. Early registration is permitted and demonstrates compliance posture to NCAs and enterprise customers conducting due diligence.

Non-High-Risk Determination Registration

If you have conducted an Art.6(3) self-assessment and determined your system is not high-risk:


What This Series Covered

This post concludes the five-part EU AI Act Art.71 database registration series:


Primary Sources

All registration obligations cited in this post derive from the following primary legal texts. Verify any article number or deadline directly against these sources:

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.