WHAT THE ARTICLE IS ABOUT
Two specific presumptions of compliance for high-risk AI
Article 42 creates targeted presumptions of conformity for specific requirements — separate from the broader standards-based presumption in Articles 40 and 41. It recognises that certain compliance requirements can be demonstrated through specific existing frameworks, reducing duplication and administrative burden for providers who have already met equivalent standards elsewhere.
WHAT IT SAYS
Data relevance and cybersecurity certification both carry presumptions
- Presumption 1 — Data requirements: Where a high-risk AI system is trained and tested on data that reflects the specific geographic, behavioural or functional setting in which it will be used, it is presumed to comply with the data and data governance requirements of Article 10 to the extent those requirements are covered
- Presumption 2 — Cybersecurity: Where a high-risk AI system has been certified or has a statement of conformity under a cybersecurity scheme pursuant to the EU Cybersecurity Act (Regulation (EU) 2019/881), and the cybersecurity certificate or statement covers the cybersecurity requirements of Article 15, it is presumed to comply with those requirements to the extent of the coverage
- Both presumptions are rebuttable — evidence of actual non-compliance overrides the presumption
- The cybersecurity presumption is particularly significant as it enables providers who have already achieved EU Cybersecurity Act certification to avoid duplicating their cybersecurity compliance work under the AI Act
WHO IS AFFECTED
Providers who have already invested in data quality or cybersecurity certification
- Providers of high-risk AI systems who have existing EU Cybersecurity Act certifications covering their AI system
- Providers who have built their training and testing datasets with careful attention to geographic and contextual representativeness
- Organisations that have undergone ENISA-recognised cybersecurity scheme certification
- Notified bodies who must recognise these presumptions when conducting conformity assessments
WHAT IT MEANS FOR SMES
Avoid duplicating compliance work you have already done
- If you have already obtained cybersecurity certification under the EU Cybersecurity Act for your AI system, check whether that certification covers the Article 15 requirements — if it does, you can rely on the presumption and avoid a separate cybersecurity assessment
- This article rewards providers who have invested in data quality — if your training data genuinely reflects the intended deployment context, document this carefully as it supports the Article 10 presumption
- The two presumptions are additive — you can benefit from both simultaneously if both conditions are met
- The cybersecurity intersection is practically important: many AI systems are already subject to cybersecurity requirements under other frameworks — Article 42 prevents double compliance work
- Document the basis for any presumption you rely on — if your conformity assessment is ever questioned, this documentation is your evidence
Related Articles
- Article 10 — Data governance (the requirement the data presumption applies to)
- Article 15 — Accuracy, robustness and cybersecurity (the requirement the cybersecurity presumption applies to)
- Article 40 — Harmonised standards (the primary presumption mechanism)
- Article 41 — Common specifications (the secondary presumption mechanism)
