Chapter III · Section 2 · Requirements for high-risk AI systems
Article 13 — Transparency and provision of information to deployers
▼ Primary text, verbatim. Our annotations appear below, visibly separated.
1. High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall be ensured with a view to achieving compliance with the relevant obligations of the provider and deployer set out in Section 3.
2. High-risk AI systems shall be accompanied by instructions for use in an appropriate digital format or otherwise that include concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers.
3. The instructions for use shall contain at least the following information:
(a) the identity and the contact details of the provider and, where applicable, of its authorised representative;
(b) the characteristics, capabilities and limitations of performance of the high-risk AI system, including:
(i) its intended purpose;
(ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;
(iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2);
(iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output;
(v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used;
(vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system;
(vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;
(c) the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;
(d) the human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;
(e) the computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;
(f) where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.
Recital 65 — interpretive context
The risk-management system should consist of a continuous, iterative process that is planned and run throughout the entire lifecycle of a high-risk AI system. That process should be aimed at identifying and mitigating the relevant risks of AI systems on health, safety and fundamental rights. The risk-management system should be regularly reviewed and updated to ensure its continuing effectiveness, as well as…
Recital 72 — interpretive context
To address concerns related to opacity and complexity of certain AI systems and help deployers to fulfil their obligations under this Regulation, transparency should be required for high-risk AI systems before they are placed on the market or put it into service. High-risk AI systems should be designed in a manner to enable deployers to understand how the AI system works, evaluate its functionality, and comprehend…
What this means for you
In your terms · Transparency and instructions for deployers
Interpretability of output is partly interface design: expose confidence, provenance and known failure modes where the deployer can see them.
- Output metadata deployers can read
In your terms · Transparency and instructions for deployers
Part of the instructions is operational fact: Article 13(3)(e) wants the computational and hardware resources, the expected lifetime and the maintenance and update cadence. Those numbers come from you, and whatever gets printed becomes the commitment operations is held to.
- Resource, lifetime and maintenance inputs for the instructions
In your terms · Transparency and instructions for deployers
The instructions for use are a product artifact: what the system is for, what it must not be used for, and what the deployer has to set up.
- Instructions for use per system
Failure smells likeA deployer uses the system for something it cannot actually do well, and the instructions never said where the edge was.
Obligations derived from this article
Commonly misquoted
What gets said
Article 13 is the rule that makes you tell people they are talking to an AI.
What the provision says
Article 13 is about transparency towards deployers: a high-risk system must be transparent enough for the deployer to interpret its output and use it appropriately, and it must come with instructions for use. The duty to inform a natural person that they are interacting with an AI system is Article 50(1), it applies to systems that are not high-risk as well, and it is owed by the provider.
If you would rather not read the law
The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.