Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries · Mobility

Article 6(1) high-risk duties for vehicle AI apply from 2 August 2028

A vehicle's AI answers to three authorities at once

Type approval clears the vehicle for market. The AI Act and the GDPR keep asking questions after it ships. Each desk holds its own legal basis, its own document requests, and its own clock.

What you need to know

  1. Type approval clears the vehicle; the questions continue afterwards. The type-approval authority signs off before market. For AI embedded in the vehicle, the AI Act's high-risk requirements arrive through vehicle type-approval law, with the Article 6(1) track applying from 2 August 2028, but the GDPR keeps its own document requests and clocks running once the vehicle ships.
  2. Safety-component ADAS and automated driving are high risk. Article 6(1) reaches AI that is a safety component of a type-approved vehicle; assistance features with no safety role sit outside under Article 6(1a). For qualifying vehicle AI the duties apply from 2 August 2028, integrated with the type-approval regime.
  3. UN-R 155, UN-R 156, and GSR II already apply. All three have been mandatory for new registrations of in-scope vehicle categories since 7 July 2024. UN-R 156 reaches over-the-air model updates through the certified software update management system.
  4. Cabin data sits deep inside the GDPR. Biometric identification is Article 9 special-category data, and systematic driver monitoring calls for a data protection impact assessment under Article 35. Emotion inference in workplace cabins, a commercial driver's cab included, is prohibited under Article 5(1)(f) outside its medical and safety exceptions; drowsiness and attention warning sits outside the definition altogether.
  5. One record backs every file. The AI subsystem inventory, model versions, OTA change records, and oversight logs form the evidence base for type approval, AI Act conformity, and ISO/IEC 42001 certification once they live in one governance graph, with each regime keeping its own scope and procedure.
Owners: Head of Homologation, Chief Safety Officer, Head of Software, DPORead the framework docs →
01

The use-case docket

Six recurring mobility use cases, compressed to their EU AI Act gates. Duties stack, and a telematics pricing model with no AI Act gate still answers to the data protection desk.

Emotion inference in commercial driver cabins without safety justification

Article 5(1)(f) prohibits inferring emotions in the workplace outside medical or safety exceptions. Driver-state inference has to stay scoped to drowsiness and attention.

Prohibited (Art. 5)

AI safety components in ADAS and automated driving

High risk under Article 6(1): vehicles are Annex I products and type approval is a third-party conformity assessment, so both conditions are met.

High-risk (Annex III)

Driver drowsiness, attention, and distraction warning (GSR)

Mandated by GSR II and treated as a safety component under Article 6(1). Article 50(3) transparency stacks on top where the system infers emotions or categorises biometric data.

High-risk (Annex III)Transparency (Art. 50)

Biometric driver identification and access

High risk under Annex III point 1 when used to identify natural persons. GDPR Article 9 and worker-monitoring law run alongside.

High-risk (Annex III)Transparency (Art. 50)

Usage-based insurance and telematics pricing

No AI Act gate: non-life pricing sits outside Annex III point 5(c). GDPR Article 22 and consumer protection still require human review paths.

No AI Act gate

Generative AI in-car assistants

Article 50: drivers must be told they are interacting with AI. Chapter V GPAI duties sit on the model provider.

Transparency (Art. 50)
02

Who can knock, and with what

The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.

01Type approvalThe type-approval authority

The national approval authority that grants EU whole-vehicle type approval under Regulation (EU) 2018/858: the KBA in Germany, the RDW in the Netherlands, or their peer in your member state.

Type approval, extended by the UNECE regulations the EU applies. UN-R 155 requires a certified cybersecurity management system across the vehicle lifecycle, UN-R 156 a software update management system that reaches every over-the-air model update, and UN-R 157 governs automated lane keeping. GSR II (Regulation (EU) 2019/2144) mandates driver drowsiness and attention warning, intelligent speed assistance, and emergency lane keeping. Both layers have applied to all new vehicle registrations since 7 July 2024. Approval comes before market; conformity of production keeps the authority in the file afterwards.

What they can ask for

  • The cybersecurity management system certificate and risk treatment evidence under UN-R 155
  • Software update management system certification and update records under UN-R 156
  • The information package behind the type approval, AI safety components included
  • Conformity-of-production evidence after approval
Before market
type approval precedes registration and first sale in the EU
7 Jul 2024
UN-R 155, UN-R 156, and GSR II mandatory for all new vehicle registrations
02AI ActThe market surveillance authority

The market surveillance authority under Regulation (EU) 2024/1689. For AI embedded in vehicles it works through the type-approval framework; for standalone tools it knocks directly.

AI used as a safety component of a type-approved vehicle runs the Annex I product-safety track tied to Article 6(1): perception, planning, and control in ADAS and automated driving, and the driver monitoring mandated by GSR II. Under the Digital Omnibus, now in force, these duties apply from 2 August 2028, and for vehicles they arrive integrated with the type-approval regime rather than as a parallel filing. Standalone tools that are not part of the vehicle, such as HR screening at an OEM, follow Annex III from 2 December 2027.

What they can ask for

  • The technical documentation for each high-risk AI system
  • Data governance and training data records
  • Automatically generated logs and human oversight records
  • Serious incident reports and the post-market monitoring plan
2 Aug 2028
product-safety track duties for AI embedded in type-approved vehicles, per the Digital Omnibus, now in force
2 Dec 2027
Annex III duties for standalone systems that are not part of the vehicle
03GDPRThe data protection authority

Your lead supervisory authority under the GDPR, applicable since 25 May 2018. Cabin data is already inside its mandate.

Cabin cameras, driver monitoring, biometric entry, and location trails are personal data processing, much of it Article 9 special-category data. Systematic monitoring of drivers triggers a data protection impact assessment under Article 35, and fleet deployments add worker-monitoring rules on top. Article 83(5) allows fines up to €20 million or 4% of worldwide annual turnover, whichever is higher.

What they can ask for

  • Data protection impact assessments under Article 35 for driver monitoring and telematics
  • Records of processing under Article 30
  • The lawful basis behind cabin biometrics and location data, retention included
72h
personal data breach notification under Article 33
1 month
response to a data subject request under Article 12(3)
EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189CCPA ADMTNYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

In the framework library, the EU AI Act, the GDPR, and ISO/IEC 42001 share controls, so the evidence behind a driver-monitoring DPIA or an OTA change record is written once and reused across all three, each framework keeping its own scope. The homologation file the type-approval desk already holds reads from the same record.

454 / 958controls in the library serve more than one framework
1controls shared by at least two of these three frameworks

Framework library v1.0.32

03

Frequently asked questions

Is ADAS and automated driving automatically high risk under the EU AI Act?

In practice, yes. Article 6(1) classifies AI as high risk when it is a safety component of a product covered by Annex I Union harmonisation legislation and the product is subject to third-party conformity assessment. Vehicles under Regulation (EU) 2018/858 are Annex I and type approval is a third-party conformity assessment, so both conditions are met. The perception, planning, and control stacks of ADAS and automated driving trigger the full conformity, documentation, monitoring, and serious-incident reporting regime. Under the Digital Omnibus, now in force, these duties apply from 2 August 2028.

How does the EU AI Act interact with UN-R 155 and 156?

The AI Act does not replace UN-R 155 or 156, it sits alongside them. UN-R 155 remains the type-approval basis for the cybersecurity management system, UN-R 156 for software updates. For vehicle AI the Act runs through the type-approval regime rather than as a parallel filing, adding AI-specific duties like data governance, human oversight, and post-market monitoring to the documentation the OEM already maintains.

Are driver monitoring cameras prohibited by the EU AI Act?

Not outright. Article 5 prohibits AI systems that infer emotions of a natural person in the workplace, with narrow exceptions for medical or safety reasons. Drowsiness and attention warning systems mandated by the General Safety Regulation can be defended under the safety exemption, but they need a documented justification, a GDPR lawful basis, and a design that avoids inferring broader emotional states.

What does ISO/PAS 8800 cover and do we need it?

ISO/PAS 8800, published in 2024, is the automotive specification for the safety of AI in road vehicles. It provides a structured argumentation approach that complements ISO 21448 (SOTIF) and ISO 26262. It is not legally mandatory, but it is becoming the engineering-grade evidence baseline for high-risk automotive AI under the EU AI Act.

How should OEMs handle OTA model updates?

Under UN-R 156, any software update that could affect safety, cybersecurity, or type approval, AI model updates included, must go through a certified software update management system. Under the EU AI Act, substantial modifications require re-assessment. Governance has to capture the model version, training data changes, validation evidence, rollback plans, and regulatory notifications in a single traceable record.

How does Modulos help automotive and mobility companies?

Modulos models the EU AI Act, UN-R 155, 156, and 157, the General Safety Regulation, ISO/PAS 8800, ISO 21448, and ISO/IEC 42001 as a single governance graph. Controls written for homologation also earn credit for AI Act conformity and ISO management system certification. Incident, change, and post-market monitoring workflows produce the same evidence every framework expects.

See the governance graph on one vehicle programme

Talk to an expert

A demo walks through the three desks with an ADAS or driver monitoring use case, from the homologation file to the integrated AI Act evidence inside it.

Request a demo

Keep exploring on your own

The risk calculator classifies your likely EU AI Act role in about three minutes, and the regulation primers go deeper on each desk's legal basis.