Substantial modification
Article 3, point 23, of Regulation (EU) 2024/1689:
a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed.
Term defined in Article 3, point 23: a change after placing on the market or putting into service that was not foreseen in the initial conformity assessment and that affects compliance with the requirements of Chapter III, Section 2, or modifies the intended purpose assessed. On a high-risk system that remains high-risk, it is the act that makes whoever performs it the provider of that system (Article 25(1), point (b)).
It is one of the three acts that turn a deployer into a provider, and all three exist only on high-risk systems.
Which obligations it carries
It is not an obligation: it is a fact that transfers obligations. Whoever incurs it becomes subject to the provider obligations of Article 16, which are a legal obligation applicable from 2 December 2027 for systems classified as high-risk under Annex III and from 2 August 2028 for those classified under Annex I.
What it is not
It is not “any change”. Tuning parameters, updating the provider’s version, integrating it with another tool or changing who uses it inside the organisation are not. And above all: it does not operate on minimal-risk systems. The three circumstances of Article 25(1) — own brand on a high-risk system already on the market; substantial modification of a high-risk system that remains so; change of intended purpose of a system that was not high-risk so that it becomes so — are limited to high risk in all three. On a minimal-risk tool, none of the three is triggered.
The nuance almost nobody captures
Point (c) is the most overlooked, and the only one that starts outside high risk: changing the intended purpose of a system that was not high-risk — including a general-purpose AI system — in such a way that it becomes so. No need to touch the system: changing what it is used for is enough. And Article 25(1) has a counterweight that Regulation (EU) 2026/1744 strengthened: where those circumstances occur, the initial provider ceases to be so with respect to that system and is required to cooperate — sufficient technical documentation, information on known limitations and failure modes, and specific technical access — unless it had clearly specified that its system is not to be changed into a high-risk one.