Article 46(2) of the EU AI Act (Regulation (EU) 2024/1689) lets law enforcement or civil protection authorities put a specific high-risk AI system into service without prior authorisation, in a duly justified situation of urgency, for exceptional reasons of public security or a specific, substantial and imminent threat to the life or physical safety of natural persons — on condition that authorisation is then requested during or after use, without undue delay. If that authorisation is refused, use of the system stops with immediate effect, and all results and outputs of that use are immediately deleted. A statutory evidence-destruction clause sitting inside what is, on paper, a product-safety regulation — and almost nothing has been written about what it actually does.
Two different derogations, often confused
Article 46 contains two distinct mechanisms, and conflating them gets the sequencing wrong.
Article 46(1) is the general derogation. Any market surveillance authority — not limited to law enforcement — may authorise placing a specific high-risk system on the market or putting it into service, for exceptional reasons of public security, protection of life and health, environmental protection, or protection of essential industrial and infrastructure assets. The authorisation lasts for a limited period while the necessary conformity assessment is carried out, and that assessment has to be completed as quickly as possible. Authority acts first here too, but conditionally — it has to conclude compliance before authorising anything.
Article 46(2) is narrower and more dramatic. Only law enforcement authorities or civil protection authorities can use it, and only in genuine urgency — the deployment happens with no authorisation at all, and the paperwork follows during or after the fact. This is the deploy-now, ask-later route, and it’s the one carrying the discard consequence.
One scope point worth having on hand: neither derogation touches high-risk AI embedded in products covered by Annex I Section A legislation. Those systems use only whatever conformity-assessment derogations their own sectoral legislation provides — Article 46 doesn’t reach them at all.
The discard rule
If the Article 46(1) authorisation is refused after a paragraph 2 deployment, two things happen simultaneously: use stops immediately, and every result and output the system produced during that use is immediately deleted. Both are unconditional — there’s no grace period, no partial retention for review.
What the Act doesn’t say is where that leaves anything built on top of those outputs. If an officer already acted on a system’s flagged match, or an output already made its way into a case file, the text gives no answer for what happens to the decision or the file once the outputs behind it are gone. That’s a genuine, open gap rather than something this piece can resolve — and it’s worth knowing it’s open before you assume the Act has an answer.
The 15-day clock
The paragraph 1 authorisation is only granted if the market surveillance authority concludes the system actually complies with the Chapter III Section 2 requirements. Once granted — whether under paragraph 1 directly or via the paragraph 2 route — the authority notifies the Commission and other Member States, though that notification duty doesn’t extend to sensitive operational data tied to law enforcement activities specifically.
From there, a silent-consent structure runs on calendar days, not business days. If no Member State or the Commission raises an objection within 15 calendar days of receiving that notification, the authorisation is deemed justified — no further action needed. If a Member State does object to another Member State’s authorisation, or the Commission itself considers the authorisation contrary to EU law or the underlying compliance conclusion unfounded, the Commission consults with the Member State concerned without delay, and the operators involved are consulted and given a chance to present their views before the Commission decides. If the Commission ultimately finds the authorisation unjustified, the market surveillance authority that granted it has to withdraw it.
Who assesses police AI in the normal case
Outside of Article 46’s emergency mechanics, high-risk AI intended for use by law enforcement, immigration or asylum authorities, or EU institutions, doesn’t go through a notified body of the provider’s choosing at all — the market surveillance authority itself carries out the assessment. And when these systems are registered, the entry sits in the EU database’s secure, non-public section rather than the ordinary public one. Emergency deployment isn’t a shortcut around an otherwise-open marketplace of assessors; it’s a shortcut inside a system that was already centralised and restricted.
What this means if you sell to police forces
The commercial consequence is straightforward and worth putting in writing before it happens, not after. Your customer can lawfully deploy your system under genuine urgency, use it, and then be told — days or weeks later — to stop immediately and delete everything it produced. If your contract assumes deployment implies an ongoing, stable engagement, it doesn’t account for this. Build the discard scenario into your terms: what data reverts to you, what your customer owes you notice of, and what happens to your own copies of anything derived from that use.
Frequently asked questions
Does Article 46 override the Article 5 prohibitions?
No. Article 46 is a derogation from the conformity assessment procedure for high-risk systems — it has nothing to do with the absolute prohibitions in Article 5, which ban certain practices outright regardless of risk classification or urgency. A practice that’s prohibited under Article 5 doesn’t become available under emergency conditions; Article 46 only ever touches something that would otherwise be lawful but for the timing of its paperwork.
Who decides what counts as urgent?
The law enforcement or civil protection authority makes that call itself in the moment it deploys under paragraph 2 — that’s the point of the mechanism. The market surveillance authority’s role comes after, when it decides whether to grant the paragraph 1 authorisation the deployment is retroactively seeking.
Is there an appeal if authorisation is refused?
The text gives operators a consultation right specifically within the paragraph 5 process — where the Commission is reviewing a granted authorisation that another Member State or the Commission has challenged, operators are consulted and get to present their views before the Commission decides. It’s less clear there’s an equivalent route for challenging an initial refusal itself; nothing in the article spells one out.
Does the discard rule reach models trained on the deleted outputs?
The text doesn’t address this, and it would be overreaching to assume an answer either way. If a derived model or downstream system incorporated something built from the discarded outputs before deletion happened, the Article doesn’t say what that means for the derived material — treat it as unresolved rather than settled.
Does this apply to migration or asylum authorities?
Not under paragraph 2 specifically — that provision names only law enforcement authorities and civil protection authorities. Migration and asylum authorities aren’t included in the deploy-first mechanism, even though they’re treated alongside law enforcement for other purposes elsewhere in the Act, such as who conducts the conformity assessment in the ordinary case.
