Start with Maditon
← Back to Resource Center
EU AI Act · Article 49 6 min read

How to register a high-risk AI system in the EU database

The EU AI Act Article 49 registration process for high-risk AI systems — what data goes in, who submits it, and what happens after the 2 December 2027 deadline.


Most Annex III high-risk AI systems must be registered in the EU’s central public database before they are placed on the market or put into service — but Article 49 has important routes and exceptions: critical-infrastructure systems (Annex III point 2) are registered at national level; certain law-enforcement, migration, asylum, and border-control systems go in a secure, non-public section; providers relying on the Article 6(3) non-high-risk carve-out register that assessment; and public-authority deployers (or those acting on their behalf) have their own registration duty. The high-risk regime is expected to apply from 2 December 2027 (postponed from 2 August 2026 under the Digital Omnibus, politically agreed May 2026 and pending formal adoption). Article 49 sets out the obligation; Annex VIII details the data. This guide is the practical walkthrough of what to prepare, who submits it, and what to expect after submission.

Who registers — providers and certain deployers

Providers of high-risk AI systems register their products in the database before placing them on the market (Article 49(1)).

Deployers that are public authorities, agencies, or bodies — or private entities acting on their behalf — register the deployment (their use of the system) before putting it into service (Article 49(3)).

A private SME deploying a high-risk system bought from a vendor typically does not register. The vendor (the provider) registers the system. The SME’s audit trail tracks the EU database ID that the vendor obtained.

What goes in the database — Annex VIII

The required content is split between Annex VIII Section A (providers), Section B (Article 6(3) exception providers), and Section C (deployers). Section A is the core:

  • Provider name, address, contact details
  • Authorised representative in the EU (if the provider is non-EU)
  • Trade name and AI system identifiers
  • Description of the intended purpose and components
  • Status of the AI system (on the market, in service, recalled, withdrawn)
  • Type of conformity-assessment procedure followed
  • Member State(s) where the system is being placed on the market or put into service
  • Date and reference of any decision by a notified body
  • Instructions for use, in a readable format

Section B is for providers relying on the Article 6(3) carve-out — a separate, lighter dataset that records the basis for the exception.

Section C — for public-authority deployers — includes the deployer’s identity, the system being used, the area of use, and the period of deployment.

Where the database lives

The EU AI database is operated by the European Commission. As of late 2026, the access portal is at the official Commission domain. The registration interface is web-based, requires authentication via an EU Login account, and accepts submissions in English plus the language of the country where the system is placed on the market.

Each registered system gets a unique reference number — the “EU database ID” — which becomes part of your declaration of conformity, your product labelling, and your customer-facing documentation.

The mechanics — five-step submission

  1. Prepare your technical documentation (Annex IV) — risk management, data governance, training methodology, model evaluation, post-market monitoring plan
  2. Complete your conformity assessment — internal procedure for Annex III systems not on the Annex II safety-component list; notified-body assessment for those that are
  3. Sign your declaration of conformity — Annex V
  4. Submit the Annex VIII data via the EU portal
  5. Receive your EU database ID — typically within a few weeks of submission for straightforward cases

If your conformity assessment requires a notified body, the bottleneck is usually scheduling the notified body, not the database registration itself.

Public visibility — what shows on the database

The database is public. Anyone can search for registered AI systems. The publicly visible fields include:

  • Provider name and authorised representative
  • Trade name of the system
  • Description of intended purpose
  • Member States of deployment
  • Status (on market, recalled, etc.)

Some fields are restricted to supervisory authorities — typically the conformity-assessment details and any commercially confidential elements of the instructions for use.

When updates are required

You must update the database when material changes occur (Article 49(2)):

  • Substantial modification of the system (which itself requires a new conformity assessment under Article 43(4))
  • Recall or withdrawal from the market
  • Changes to the provider’s authorised representative in the EU
  • Material changes to intended purpose

Trivial changes (logo, copy, internal architecture not affecting safety or fundamental rights) don’t trigger an update.

Penalties for non-registration

Failing to register a high-risk system before placing it on the market is an Article 99(4) infringement — fines up to €15 million or 3% of global turnover for most entities, capped lower for SMEs. The database is also where supervisory authorities look first when investigating a complaint. A high-risk system “in the wild” without a database entry is the cleanest evidence of non-compliance.

What if you’re using the Article 6(3) exception

If you provide a system that would be high-risk under Annex III but you’ve classified it as exempt under Article 6(3), Article 6(4) requires you to register the assessment in Section B of the database, even though the system isn’t fully high-risk. You also retain the documentation for 10 years for supervisory inspection.

This is one of the lesser-known traps. Companies relying on Article 6(3)(d) — including Maditon itself — must register the exception, not the system. The database entry is shorter, but it is mandatory.

Practical advice if you’re racing the 2 December 2027 deadline

  • Start technical documentation 6+ months before launch. Annex IV is long.
  • If a notified body is required, book them 9–12 months ahead. Notified-body capacity is constrained.
  • Submit the database entry 2–4 weeks before launch. Allow time for the Commission’s review.
  • If you’re an Article 6(3) provider, prepare the Section B documentation anyway — it’s a one-page exercise and shows good faith.

The Maditon registration tab — built into every AI system in the platform — captures the EU database ID, submission status, and registration dates so this trail lives in the same place as the classification and the dossier. See the Compliance checklist guide for how this fits the broader compliance flow.