Substantial modification
A substantial modification is a change to an AI system after it has been placed on the market or put into service, which is not foreseen or planned in the initial conformity assessment, and which affects compliance with the high-risk requirements or modifies the intended purpose for which it was assessed. Anyone who makes a substantial modification to a system already on the market becomes a provider under Article 25.
The concept is defined in Article 3(23), the legal consequence in Article 25(1)(b). It has two cumulative elements: the change must be unplanned (i.e. not foreseen in the original conformity assessment), and it must materially affect either compliance with the high-risk requirements or the intended purpose itself. Two typical scenarios arise in practice: fine-tuning a system on proprietary data in a way that changes its behaviour, or configuring a general-purpose tool for a high-risk purpose — e.g. HR decision-making. The legal consequence is sharp: the full provider compliance package transfers to the company making the modification, typically without it having visibility into the model's internal workings. Under Article 25(2), the original provider is required to provide the necessary information and technical access to enable cooperation.
Fine-tuning a general-purpose AI assistant on proprietary data, or configuring it for HR purposes, can easily qualify as a substantial modification — this is the most likely route by which an SME unexpectedly becomes a provider.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Intended purposeThe intended purpose is the use for which the provider intends an AI system, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, and the technical documentation. Classification — including the high-risk determination — attaches to the intended purpose, not to the underlying technology.
- ProviderA provider is a natural or legal person that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers bear the Regulation's most extensive package of obligations: risk management, data governance, documentation, conformity assessment, CE marking.
- Placing on the marketPlacing on the market means the first making available of an AI system or a general-purpose AI model on the Union market. Making available on the market is a broader concept, denoting repeated, ongoing commercial activity, whereas placing on the market marks that first act, to which numerous obligations — CE marking, conformity assessment — attach.
- GrandfatheringGrandfathering refers to the rule under which the Regulation applies to AI systems already placed on the market before the application date of the high-risk block only if they undergo a substantial modification affecting their design. This protection does not extend to prohibited practices — the prohibition applies to those immediately, with no grace period.
Related questions in the knowledge base (Hungarian)
- Mi számít lényeges módosításnak egy AI-rendszeren?A 3. cikk 23. pontja szerint az a forgalomba hozatal utáni változás, amelyet az eredeti megfelelőségértékelés nem irányzott elő, és amely érinti a III. fejezet 2. szakasza szerinti követelményeknek való megfelelést, vagy megváltoztatja az értékelt rendeltetést. Aki ilyet végez, a 25. cikk alapján szolgáltatóvá válik.
- Mikor válik egy AI-t használó cégből szolgáltató az AI Act szerint?A 25. cikk (1) bekezdése három esetben telepíti át a szolgáltatói státuszt: ha a cég saját nevét vagy védjegyét helyezi el egy már forgalomban lévő magas kockázatú rendszeren, ha lényegesen módosítja azt, vagy ha a rendeltetés megváltoztatásával tesz magas kockázatúvá egy addig nem annak minősülő rendszert. Szerződéses kikötés ezen nem változtat.
- Vonatkozik az AI Act a már korábban bevezetett AI-rendszereinkre?Nem automatikusan. A 111. cikk (2) bekezdése szerint a magas kockázatú blokk alkalmazási dátuma előtt forgalomba hozott rendszerekre a rendelet csak akkor alkalmazandó, ha azok tervezésüket érintő lényeges változáson mennek keresztül. A tilalmakra viszont ez a védelem nem terjed ki.