EU AI Act Art. 10: data and data governance
Data and data governance; representative, relevant, error-checked datasets
AIGE-OBL-EUAIA-ART10. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 10.
- Duty holder: Provider.
- Applies from: 2027-12-02, Deferred.
- Artefact: Data cards.
- Layers: Layer 02, Layer 03.
- Evidence record: Dataset card, +1 more.
- Record schemas: Dataset card , Dataset admission record .
- The same topic in 17 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART10- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 10
- Duty holder
- Provider
- Authority
- National MSA
- Applies from
- Deferred · Annex III
- Later dates
-
- Applies to Annex I embedded (product safety-component) systems
- Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
- System class
- High-risk (Annex III) · High-risk (Annex I)
The artefact that evidences it
Data cards; lineage; bias and quality tests in CI.
Patterns that build it
- Training-Data Rights Ledger (layer 2)
- Dataset Admission Gate (layer 1 and 2)
- Fairness Eval Suite (layer 3)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Fairness and non-discrimination
- EU AI Act Art. 4a Special-category data for bias detection (core)
- GDPR Art. 5(1)(a) Lawfulness, fairness and transparency (core)
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented (core)
- CSA AICM GRC-11 Bias and Fairness Assessment (core)
- CoE Convention CoE Art. 10 Equality and non-discrimination (core)
- China GenAI Measures GenAI Art. 4(2) Prevent discrimination in design, data, training and service (core)
- GAO AI Accountability 2.7 Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases (core)
- GAO AI Accountability 3.8 Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system (core)
- GDPR Art. 9 Processing of special categories of personal data
- ISO 42001 A.5.4 Assessing AI system impact on individuals or groups of individuals (clause not verified)
- NIST AI RMF GOVERN 3.1 GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team
- UK ATRS ATRS 2.4.2 Model specification
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- China Algo. Rec. AlgoRec Art. 21 No unreasonable differential treatment in trading conditions
Cases that cite this article
- A health-risk score that predicted cost, not need (2019)
- A recruiting model that learned the past (reported) (2018)
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-DATA-001Dataset Admission Gate at Read Time (Data admission and privacy profile) -
AIGE-CTL-DATA-002Dataset Card for Every Admitted Version (Data admission and privacy profile) -
AIGE-CTL-DATA-003Training-Data Rights Ledger Row per Source (Data admission and privacy profile) -
AIGE-CTL-DATA-008Fitness-for-Purpose Checks Before Admission (Data admission and privacy profile) -
AIGE-CTL-DATA-009Signed Snapshot Integrity (Data admission and privacy profile) -
AIGE-CTL-DATA-010Lineage from Training Runs to Admitted Sources (Data admission and privacy profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art10.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 10: data and data governance (AIGE-OBL-EUAIA-ART10). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 10: data and data governance (AIGE-OBL-EUAIA-ART10)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10},
note = {Version 0.5.0}
}