Art.42
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 42

Article 42 — Presumption of Conformity with Certain Requirements

High-Risk Systems SME Relevant ~2 min read · 458 words

Article 42 is short but legally significant. It establishes a specific presumption of conformity for two situations: AI systems trained and tested on data reflecting the specific geographic, contextual and functional settings of their intended use, and AI systems that have been cybersecurity certified under the EU Cybersecurity Act.

⚠ Medium compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Two specific presumptions of compliance for high-risk AI

Article 42 creates targeted presumptions of conformity for specific requirements — separate from the broader standards-based presumption in Articles 40 and 41. It recognises that certain compliance requirements can be demonstrated through specific existing frameworks, reducing duplication and administrative burden for providers who have already met equivalent standards elsewhere.

WHAT IT SAYS

Data relevance and cybersecurity certification both carry presumptions

  • Presumption 1 — Data requirements: Where a high-risk AI system is trained and tested on data that reflects the specific geographic, behavioural or functional setting in which it will be used, it is presumed to comply with the data and data governance requirements of Article 10 to the extent those requirements are covered
  • Presumption 2 — Cybersecurity: Where a high-risk AI system has been certified or has a statement of conformity under a cybersecurity scheme pursuant to the EU Cybersecurity Act (Regulation (EU) 2019/881), and the cybersecurity certificate or statement covers the cybersecurity requirements of Article 15, it is presumed to comply with those requirements to the extent of the coverage
  • Both presumptions are rebuttable — evidence of actual non-compliance overrides the presumption
  • The cybersecurity presumption is particularly significant as it enables providers who have already achieved EU Cybersecurity Act certification to avoid duplicating their cybersecurity compliance work under the AI Act

WHO IS AFFECTED

Providers who have already invested in data quality or cybersecurity certification

  • Providers of high-risk AI systems who have existing EU Cybersecurity Act certifications covering their AI system
  • Providers who have built their training and testing datasets with careful attention to geographic and contextual representativeness
  • Organisations that have undergone ENISA-recognised cybersecurity scheme certification
  • Notified bodies who must recognise these presumptions when conducting conformity assessments

WHAT IT MEANS FOR SMES

Avoid duplicating compliance work you have already done

  • If you have already obtained cybersecurity certification under the EU Cybersecurity Act for your AI system, check whether that certification covers the Article 15 requirements — if it does, you can rely on the presumption and avoid a separate cybersecurity assessment
  • This article rewards providers who have invested in data quality — if your training data genuinely reflects the intended deployment context, document this carefully as it supports the Article 10 presumption
  • The two presumptions are additive — you can benefit from both simultaneously if both conditions are met
  • The cybersecurity intersection is practically important: many AI systems are already subject to cybersecurity requirements under other frameworks — Article 42 prevents double compliance work
  • Document the basis for any presumption you rely on — if your conformity assessment is ever questioned, this documentation is your evidence

Related Articles

← Previous Art. 41 — Common Specifications Next → Art. 43 — Conformity Assessment