Art.10
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 10

Article 10 — Data and Data Governance

High-Risk Systems SME Relevant ~2 min read · 409 words
! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Data quality as a legal obligation

Article 10 establishes data governance requirements for high-risk AI systems. It recognises that the quality of an AI system’s output is fundamentally dependent on the quality of its training data — and makes data quality a legal obligation, not just a technical best practice.

WHAT IT SAYS

Quality, representativeness, and bias detection

  • Training, validation, and testing datasets must meet quality criteria — they must be relevant, representative, free of errors, and complete to the best extent possible
  • Datasets must be subject to appropriate data governance practices covering the data collection process, data preparation operations, and examination for possible biases
  • Providers must examine datasets for potential biases that could lead to discriminatory outcomes or other risks — and implement measures to detect and correct these biases
  • Datasets must take into account the specific geographic, behavioural, or functional context in which the AI system will be used
  • In exceptional and justified cases, providers may process special categories of personal data — such as health data, racial or ethnic origin, or political opinions — for the purpose of detecting and correcting bias, subject to strict safeguards

WHO IS AFFECTED

Providers, data teams, and DPOs

  • Providers of high-risk AI systems who develop or procure training data
  • Data science and machine learning teams building high-risk AI
  • Organisations using third-party datasets for AI training — they remain responsible for data quality compliance
  • Data protection officers, given the intersection with GDPR obligations

WHAT IT MEANS FOR SMES

Document your data — and interrogate third-party datasets

  • If you are training a high-risk AI system, you must be able to demonstrate the quality and representativeness of your training data — this needs to be documented
  • Many SMEs use publicly available or third-party datasets — you are still responsible for assessing whether those datasets meet the Article 10 requirements
  • The bias detection obligation is significant — it is not enough to say your data seemed fine; you must have a process for identifying and correcting bias
  • Article 10 intersects heavily with GDPR — if you are processing personal data for AI training, your data governance framework must satisfy both regimes simultaneously
  • For deployers using third-party high-risk AI: ask your provider for documentation on their data governance practices — you may need this for your own compliance records

Related Articles

← Previous Art. 9 — Risk Management System Next → Art. 11 — Technical Documentation