EU Privacy Law EU/EEA

High-Risk AI Data Governance: Article 10 Requirements Under the EU AI Act

What EU AI Act Article 10 demands of training, validation, and testing data for high-risk AI: quality criteria, bias controls, documentation, and GDPR overlap.

Regulation

Regulation (EU) 2024/1689 (AI Act), Articles 10 to 12

Max Penalty

EUR 15 million or 3% of global annual turnover for high-risk obligations

Enforcing Authority

EU AI Office and national market surveillance authorities

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 10 requires high-risk AI systems to be built on training, validation, and testing data governed by documented practices covering design choices, provenance, preparation, and bias examination.
  • Datasets must be relevant, sufficiently representative, and to the best extent possible free of errors and complete for the intended purpose.
  • Article 10(5) permits processing special category personal data strictly for bias detection and correction, under tight safeguards, which is otherwise hard to justify under GDPR Article 9.
  • Technical documentation (Article 11, Annex IV) and automatic logging (Article 12) turn the data governance into auditable evidence.
  • Most high-risk obligations apply from 2 August 2026; retrofitting data provenance onto already-trained systems is the hardest part, so the record-keeping needs to start now.

For high-risk AI systems, the EU AI Act regulates the data before it regulates the model. Article 10 makes dataset governance a legal requirement: where the data came from, how it was prepared, whether it represents the people the system will judge, and what was done about bias. From 2 August 2026, a high-risk system whose training data cannot answer those questions is non-compliant regardless of how well it performs.

RegulationAI Act (2024/1689), Articles 10 to 12
Applies from2 August 2026 (most high-risk obligations)
Max penaltyEUR 15M or 3% of global turnover (Art. 99(4))
Enforcing authorityEU AI Office, national market surveillance authorities
Official textEUR-Lex CELEX 32024R1689

What Article 10 demands

The article requires data governance and management practices, documented, for every training, validation, and testing set. The enumerated topics read like a data science review checklist with legal force: relevant design choices; data collection processes and the origin of data; preparation operations such as annotation, labeling, cleaning, and aggregation; an assessment of availability, quantity, and suitability; examination for possible biases likely to affect health, safety, or fundamental rights; measures to detect, prevent, and mitigate those biases; and identification of data gaps with how they were addressed.

The quality standard in Article 10(3) is deliberate: datasets shall be relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose. It also requires appropriate statistical properties for the persons on whom the system will be used, which is the representativeness requirement with teeth: a hiring model trained on one demographic fails it.

The bias-testing gate for sensitive data

Article 10(5) solves a real dilemma. Detecting whether a model discriminates by ethnicity or health status can require processing exactly those attributes, which GDPR Article 9 ordinarily prohibits. The AI Act creates a specific permission: special category data may be processed where strictly necessary for bias detection and correction in high-risk systems, with safeguards including technical limits on re-use, access restriction, no transmission to third parties, and deletion once the bias work is done. Use the gate as written and document each condition; it does not authorize keeping sensitive attributes around for general model improvement.

Documentation and logging make it auditable

Articles 11 and 12 convert governance into evidence. The technical documentation (Annex IV) must describe the datasets, their provenance, and the Article 10 practices, kept current for ten years after market placement. Automatic logging must capture system operation so problems can be traced. Practically, this means dataset datasheets, versioned lineage records, and bias evaluation reports are now regulatory artifacts, not just engineering hygiene.

Start with the provenance record: it is the item that cannot be reconstructed later. Then align the GDPR layer, since personal data in the same datasets needs lawful basis and retention treatment in parallel; our AI Act and GDPR overview maps the interaction, and the combined assessment guide covers the impact assessments both regimes expect.

Frequently Asked Questions

What does AI Act Article 10 actually require?

Documented data governance for training, validation, and testing datasets: the design choices, data origin and collection process, preparation steps such as labeling and cleaning, an assessment of availability and suitability, examination for possible biases, and measures to address gaps.

Does the training data have to be error-free?

The standard is 'to the best extent possible, free of errors and complete' in view of the intended purpose (Article 10(3)). It is a documented-diligence standard, not perfection: you must show a process that finds and addresses quality problems.

Can I process sensitive data to test for bias?

Yes, uniquely. Article 10(5) allows processing special categories of personal data where strictly necessary for bias detection and correction in high-risk systems, subject to safeguards including access controls, prohibition of transmission, and deletion once the purpose is served. It is one of the few explicit legal gates for Article 9 data in engineering work.

Who is responsible for data governance, provider or deployer?

Primarily the provider, who builds and documents the system. Deployers have a related duty: ensure input data under their control is relevant and sufficiently representative for the system's intended purpose (Article 26(4)).

How does this interact with GDPR?

Fully additively. Personal data in training sets needs a GDPR lawful basis, minimization, and retention limits regardless of Article 10. The AI Act adds quality, bias, and documentation duties on top; only the 10(5) bias gate relaxes anything, and narrowly.

Regulatory Crosswalk

GDPRISO/IEC 42001ISO/IEC 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.