A vehicle's AI answers to three authorities at once
Type approval clears the vehicle for market. The AI Act and the GDPR keep asking questions after it ships. Each desk holds its own legal basis, its own document requests, and its own clock.
01Type approval
The type-approval authority
Before market type approval precedes registration and first sale in the EU
02AI Act
The market surveillance authority
2 Aug 2028 product-safety track duties for AI embedded in type-approved vehicles, per the adopted Digital Omnibus
03GDPR
The data protection authority
72h personal data breach notification under Article 33
The desk
Who can knock, and with what
Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.
Desk 01Type approval
The type-approval authority
The national approval authority that grants EU whole-vehicle type approval under Regulation (EU) 2018/858: the KBA in Germany, the RDW in the Netherlands, or their peer in your member state.
Type approval, extended by the UNECE regulations the EU applies. UN-R 155 requires a certified cybersecurity management system across the vehicle lifecycle, UN-R 156 a software update management system that reaches every over-the-air model update, and UN-R 157 governs automated lane keeping. GSR II (Regulation (EU) 2019/2144) mandates driver drowsiness and attention warning, intelligent speed assistance, and emergency lane keeping. Both layers have applied to all new vehicle registrations since 7 July 2024. Approval comes before market; conformity of production keeps the authority in the file afterwards.
What they can ask for
The cybersecurity management system certificate and risk treatment evidence under UN-R 155
Software update management system certification and update records under UN-R 156
The information package behind the type approval, AI safety components included
Conformity-of-production evidence after approval
The clock
Before market
type approval precedes registration and first sale in the EU
7 Jul 2024
UN-R 155, UN-R 156, and GSR II mandatory for all new vehicle registrations
Desk 02AI Act
The market surveillance authority
The market surveillance authority under Regulation (EU) 2024/1689. For AI embedded in vehicles it works through the type-approval framework; for standalone tools it knocks directly.
AI used as a safety component of a type-approved vehicle runs the Annex I product-safety track tied to Article 6(1): perception, planning, and control in ADAS and automated driving, and the driver monitoring mandated by GSR II. Under the adopted Digital Omnibus these duties apply from 2 August 2028, and for vehicles they arrive integrated with the type-approval regime rather than as a parallel filing. Standalone tools that are not part of the vehicle, such as HR screening at an OEM, follow Annex III from 2 December 2027.
What they can ask for
The technical documentation for each high-risk AI system
Data governance and training data records
Automatically generated logs and human oversight records
Serious incident reports and the post-market monitoring plan
The clock
2 Aug 2028
product-safety track duties for AI embedded in type-approved vehicles, per the adopted Digital Omnibus
2 Dec 2027
Annex III duties for standalone systems that are not part of the vehicle
Desk 03GDPR
The data protection authority
Your lead supervisory authority under the GDPR, applicable since 25 May 2018. Cabin data is already inside its mandate.
Cabin cameras, driver monitoring, biometric entry, and location trails are personal data processing, much of it Article 9 special-category data. Systematic monitoring of drivers triggers a data protection impact assessment under Article 35, and fleet deployments add worker-monitoring rules on top. Article 83(5) caps fines at 4% of worldwide annual turnover.
What they can ask for
Data protection impact assessments under Article 35 for driver monitoring and telematics
Records of processing under Article 30
The lawful basis behind cabin biometrics and location data, retention included
The clock
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
Every desk pulls from the same technical file
UN-R 155 already requires traceable risk treatment across the lifecycle of every vehicle type. The AI Act adds a technical file, a post-market monitoring plan, and a serious-incident pipeline for each high-risk AI system. The GDPR adds impact assessments and processing records for everything the cabin sees.
The evidence behind all three overlaps almost entirely: the AI subsystem inventory, model versions and validation artefacts, OTA change records, oversight logs, and incident history. Modulos keeps that evidence as one governance graph, where a control written once for homologation earns credit for AI Act conformity and ISO/IEC 42001 certification. The desks do not coordinate their requests; the record is ready for whichever one asks first.
01 Type approval02 AI Act03 GDPR→One evidence record
Dates that matter
2 Aug 2026
General application of the EU AI Act and the start of GPAI enforcement
2 Dec 2027
Annex III duties for standalone high-risk systems, per the adopted Digital Omnibus
2 Aug 2028
Product-safety track duties for AI embedded in type-approved vehicles
The use-case docket
Six recurring mobility use cases, compressed to their EU AI Act gates. Duties stack, and a telematics pricing model with no AI Act gate still answers to the data protection desk.
Emotion inference in commercial driver cabins without safety justification
Article 5(1)(f) prohibits inferring emotions in the workplace outside medical or safety exceptions. Driver-state inference has to stay scoped to drowsiness and attention.
Prohibited (Art. 5)
AI safety components in ADAS and automated driving
High risk under Article 6(1): vehicles are Annex I products and type approval is a third-party conformity assessment, so both conditions are met.
High-risk (Annex III)
Driver drowsiness, attention, and distraction warning (GSR)
Mandated by GSR II and treated as a safety component under Article 6(1). Article 50(3) transparency stacks on top where the system infers emotions or categorises biometric data.
High-risk (Annex III)Transparency (Art. 50)
Biometric driver identification and access
High risk under Annex III point 1 when used to identify natural persons. GDPR Article 9 and worker-monitoring law run alongside.
High-risk (Annex III)Transparency (Art. 50)
Usage-based insurance and telematics pricing
No AI Act gate: non-life pricing sits outside Annex III point 5(c). GDPR Article 22 and consumer protection still require human review paths.
No AI Act gate
Generative AI in-car assistants
Article 50: drivers must be told they are interacting with AI. Chapter V GPAI duties sit on the model provider.
Transparency (Art. 50)
Related regulations
Go deeper on the regimes that apply to this sector:
Is ADAS and automated driving automatically high risk under the EU AI Act?
In practice, yes. Article 6(1) classifies AI as high risk when it is a safety component of a product covered by Annex I Union harmonisation legislation and the product is subject to third-party conformity assessment. Vehicles under Regulation (EU) 2018/858 are Annex I and type approval is a third-party conformity assessment, so both conditions are met. The perception, planning, and control stacks of ADAS and automated driving trigger the full conformity, documentation, monitoring, and serious-incident reporting regime. Under the adopted Digital Omnibus, these duties apply from 2 August 2028.
How does the EU AI Act interact with UN-R 155 and 156?
The AI Act does not replace UN-R 155 or 156, it sits alongside them. UN-R 155 remains the type-approval basis for the cybersecurity management system, UN-R 156 for software updates. For vehicle AI the Act runs through the type-approval regime rather than as a parallel filing, adding AI-specific duties like data governance, human oversight, and post-market monitoring to the documentation the OEM already maintains.
Are driver monitoring cameras prohibited by the EU AI Act?
Not outright. Article 5 prohibits AI systems that infer emotions of a natural person in the workplace, with narrow exceptions for medical or safety reasons. Drowsiness and attention warning systems mandated by the General Safety Regulation can be defended under the safety exemption, but they need a documented justification, a GDPR lawful basis, and a design that avoids inferring broader emotional states.
What does ISO/PAS 8800 cover and do we need it?
ISO/PAS 8800, published in 2024, is the automotive specification for the safety of AI in road vehicles. It provides a structured argumentation approach that complements ISO 21448 (SOTIF) and ISO 26262. It is not legally mandatory, but it is becoming the engineering-grade evidence baseline for high-risk automotive AI under the EU AI Act.
How should OEMs handle OTA model updates?
Under UN-R 156, any software update that could affect safety, cybersecurity, or type approval, AI model updates included, must go through a certified software update management system. Under the EU AI Act, substantial modifications require re-assessment. Governance has to capture the model version, training data changes, validation evidence, rollback plans, and regulatory notifications in a single traceable record.
How does Modulos help automotive and mobility companies?
Modulos models the EU AI Act, UN-R 155, 156, and 157, the General Safety Regulation, ISO/PAS 8800, ISO 21448, and ISO/IEC 42001 as a single governance graph. Controls written for homologation also earn credit for AI Act conformity and ISO management system certification. Incident, change, and post-market monitoring workflows produce the same evidence every framework expects.
See the governance graph on one vehicle programme
A demo walks through the three desks with an ADAS or driver monitoring use case. The quiz classifies your role and risk exposure in about three minutes.