! High compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
Data quality as a legal obligation
Article 10 establishes data governance requirements for high-risk AI systems. It recognises that the quality of an AI system’s output is fundamentally dependent on the quality of its training data — and makes data quality a legal obligation, not just a technical best practice.
WHAT IT SAYS
Quality, representativeness, and bias detection
- Training, validation, and testing datasets must meet quality criteria — they must be relevant, representative, free of errors, and complete to the best extent possible
- Datasets must be subject to appropriate data governance practices covering the data collection process, data preparation operations, and examination for possible biases
- Providers must examine datasets for potential biases that could lead to discriminatory outcomes or other risks — and implement measures to detect and correct these biases
- Datasets must take into account the specific geographic, behavioural, or functional context in which the AI system will be used
- In exceptional and justified cases, providers may process special categories of personal data — such as health data, racial or ethnic origin, or political opinions — for the purpose of detecting and correcting bias, subject to strict safeguards
WHO IS AFFECTED
Providers, data teams, and DPOs
- Providers of high-risk AI systems who develop or procure training data
- Data science and machine learning teams building high-risk AI
- Organisations using third-party datasets for AI training — they remain responsible for data quality compliance
- Data protection officers, given the intersection with GDPR obligations
WHAT IT MEANS FOR SMES
Document your data — and interrogate third-party datasets
- If you are training a high-risk AI system, you must be able to demonstrate the quality and representativeness of your training data — this needs to be documented
- Many SMEs use publicly available or third-party datasets — you are still responsible for assessing whether those datasets meet the Article 10 requirements
- The bias detection obligation is significant — it is not enough to say your data seemed fine; you must have a process for identifying and correcting bias
- Article 10 intersects heavily with GDPR — if you are processing personal data for AI training, your data governance framework must satisfy both regimes simultaneously
- For deployers using third-party high-risk AI: ask your provider for documentation on their data governance practices — you may need this for your own compliance records
Related Articles
- Article 9 — Risk management (data quality feeds directly into risk identification)
- Article 11 — Technical documentation (data governance must be documented)
- Article 71 — EU Database for High-Risk AI Systems (relevant for SMEs needing to access data for testing)
