Reasonably foreseeable misuse
Reasonably foreseeable misuse means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. Providers must account for this in risk management and design, not only for the intended use.
The concept is set out in Article 3(13) and is closely tied to intended purpose: together they define the scope of the provider's duty of foresight. The emphasis is on „reasonably” — a provider is not expected to prepare for every conceivable misuse, only for what is realistically foreseeable given experience or the nature of the system. This standard also appears in risk management and technical documentation: the provider must be able to show which misuse scenarios were considered during design and testing. When documenting a classification decision, this concept marks the outer edge of the provider's continuing responsibility — beyond it, the deployer's own, separate obligations begin, particularly where the system is used deliberately for a purpose other than the one intended.
A classification file and risk-management documentation only hold up if they record not just the intended use but also realistically foreseeable misuse — this is what a regulator will check for after the fact.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Intended purposeThe intended purpose is the use for which the provider intends an AI system, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, and the technical documentation. Classification — including the high-risk determination — attaches to the intended purpose, not to the underlying technology.
- Risk management systemThe risk management system is a continuous, documented, testing-based process spanning the entire lifecycle of a high-risk AI system, which identifies, evaluates and mitigates the risks the system poses to the health, safety and fundamental rights of third persons. It does not manage organisational risk — it protects a different interest than ISO 31000 or ISO/IEC 42001, and neither creates a presumption of conformity, since neither is a harmonised standard.
- Substantial modificationA substantial modification is a change to an AI system after it has been placed on the market or put into service, which is not foreseen or planned in the initial conformity assessment, and which affects compliance with the high-risk requirements or modifies the intended purpose for which it was assessed. Anyone who makes a substantial modification to a system already on the market becomes a provider under Article 25.
Related questions in the knowledge base (Hungarian)
- Mi számít lényeges módosításnak egy AI-rendszeren?A 3. cikk 23. pontja szerint az a forgalomba hozatal utáni változás, amelyet az eredeti megfelelőségértékelés nem irányzott elő, és amely érinti a III. fejezet 2. szakasza szerinti követelményeknek való megfelelést, vagy megváltoztatja az értékelt rendeltetést. Aki ilyet végez, a 25. cikk alapján szolgáltatóvá válik.
- Hogyan soroljuk be az AI-rendszerünket lépésről lépésre úgy, hogy a hatóság előtt is védhető legyen?Hét lépéses, dokumentált döntési fa vezet védhető eredményre: hatály, AI-rendszer-e, szerepkör, tiltott-e, I. melléklet, III. melléklet, végül a 6. cikk (3) szűrő és az 50. cikk átfedése. A védhetőséget nem a következtetés adja, hanem hogy minden csomóponthoz van datált, aláírt indokolás és verziókövetés. A hatóság a folyamatot kéri, nem a végeredményt.