Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Public resource

EU AI Act library

Browse the obligations Tracker uses in Essential Compliance. Filter by your role and AI class, then read plain-language guidance next to the official text.

Last reviewed 10 Sept 2026

Obligations

95

124 nested sub-obligations

Already in force

50

45 upcoming

Official provisions

243

Verified from EUR-Lex

Source consolidation

2026

Text dated 27 July 2026

95 obligations in the library

Article 4(1)

CurrentFrom 2 Feb 2025

Support AI Literacy for Personnel Using or Operating AI Systems

Your organization should identify staff and other people who operate or use AI systems on its behalf and take proportionate measures to support their AI literacy. Tailor those measures to their existing technical knowledge, experience, education and training, the context in which the AI is used, and the people or groups affected. The Act does not require any individual to achieve a specific level of AI literacy.

ProviderDeployerRead

Article 4a

CurrentFrom 27 Jul 2026

Apply Required Safeguards When Processing Special-Category Data for Bias Detection or Correction

If your organization processes special categories of personal data for bias detection or correction under Article 4a, first confirm that the relevant Article 4a pathway applies and that the processing is strictly necessary. Apply all required safeguards in Article 4a(1). Article 4a permits this processing in defined circumstances but does not itself require your organization to conduct bias detection or correction.

ProviderDeployer5 sub-obligationsRead

Article 5(1)(a)

CurrentFrom 2 Feb 2025

Do Not Use Manipulative or Deceptive AI Practices That Cause Significant Harm

Your organization should not place on the market, put into service, or use an AI system that uses subliminal, purposefully manipulative, or deceptive techniques in a way that materially impairs informed decision-making and causes, or is reasonably likely to cause, significant harm.

ProviderDeployerRead

Article 5(1)(b)

CurrentFrom 2 Feb 2025

Do Not Exploit Vulnerabilities Using AI in a Manner That Causes Significant Harm

Your organization should not place on the market, put into service, or use an AI system that exploits a person's or group's vulnerabilities due to age, disability, or a specific social or economic situation in a way that materially distorts behaviour and causes, or is reasonably likely to cause, significant harm.

ProviderDeployerRead

Article 5(1)(ba), 5(1a)-(1b)

UpcomingFrom 2 Dec 2026

Do Not Generate or Manipulate Non-Consensual Intimate Content Using AI

For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited non-consensual intimate material, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Apply the specific Article 5(1b) limitation when determining whether a manipulation is covered.

ProviderDeployerRead

Article 5(1)(bb), 5(1a)

UpcomingFrom 2 Dec 2026

Do Not Generate or Manipulate Prohibited Child Sexual Abuse Material Using AI

For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited child sexual abuse material or performance, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Consider the national-law qualification referenced by Article 5(1)(bb).

ProviderDeployerRead

Article 5(1)(c)

CurrentFrom 2 Feb 2025

Do Not Use Prohibited AI-Based Social Scoring

Your organization should not use AI-based social scoring that leads to detrimental or unfavourable treatment of people in social contexts unrelated to the context in which the data were generated or collected, or to treatment that is unjustified or disproportionate to the person's social behaviour or its gravity.

ProviderDeployerRead

Article 5(1)(d)

CurrentFrom 2 Feb 2025

Do Not Predict Individual Criminal Risk Solely From Profiling or Personality Characteristics

Your organization should not use AI to assess or predict an individual's risk of committing a criminal offence solely on the basis of profiling or personality traits and characteristics. The prohibition does not prevent AI from supporting a human assessment that is already based on objective and verifiable facts directly linked to criminal activity.

ProviderDeployerRead

Article 5(1)(e)

CurrentFrom 2 Feb 2025

Do Not Create or Expand Facial Recognition Databases Through Untargeted Image Scraping

Your organization should not create or expand a facial-recognition database through untargeted scraping of facial images from the internet or CCTV footage.

ProviderDeployerRead

Article 5(1)(f)

CurrentFrom 2 Feb 2025

Do Not Use AI Emotion Recognition in Workplaces or Educational Institutions Except for Permitted Purposes

Your organization should not place on the market, put into service for this purpose, or use an AI system to infer emotions of a person in a workplace or educational institution, except where the use is intended for medical or safety reasons.

ProviderDeployerEmployerRead

Article 5(1)(g)

CurrentFrom 2 Feb 2025

Do Not Use Prohibited Biometric Categorisation to Infer Sensitive Characteristics

Your organization should not use biometric categorisation to infer or deduce the sensitive characteristics prohibited by Article 5(1)(g). Review the specific exclusions in the Article before concluding that a biometric categorisation activity is prohibited.

ProviderDeployerRead

Article 5(1)(h), 5(2)-(7)

CurrentFrom 2 Feb 2025

Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted

Law-enforcement use of real-time remote biometric identification in publicly accessible spaces is generally prohibited. If your organization relies on one of the narrow Article 5 exceptions, confirm that the permitted objective and all related necessity, proportionality, assessment, registration, authorisation and notification conditions are satisfied before and during use.

Law EnforcementDeployer4 sub-obligationsRead

Article 6(4); Article 49(2)

UpcomingFrom 2 Dec 2027

Document the Assessment When an Annex III AI System Is Considered Not High-Risk

If your organization is a provider of an Annex III AI system and concludes that it is not high-risk under Article 6(3), document that assessment before the system is placed on the market or put into service. Complete the applicable Article 49(2) registration and be prepared to provide the assessment to a competent authority on request.

ProviderAnnex III High-Risk AIRead

Article 9

UpcomingConditional timing

Establish and Maintain a Risk Management System for High-Risk AI

For each high-risk AI system in scope, establish, implement, document and maintain a continuous and iterative risk-management process throughout the system lifecycle. Periodically review and update it. Address risks that can reasonably be mitigated or eliminated through system development or design, or through appropriate technical information.

ProviderHigh-Risk AI5 sub-obligationsRead

Article 10

UpcomingConditional timing

Establish Appropriate Data Governance for High-Risk AI Systems

For high-risk AI systems trained using data, ensure the training, validation and testing data used meet the Article 10 quality and governance requirements. For high-risk systems that do not use model-training techniques, apply the relevant Article 10 requirements to the testing data.

ProviderHigh-Risk AI4 sub-obligationsRead

Article 11; Annex IV

UpcomingConditional timing

Prepare and Maintain Technical Documentation for High-Risk AI Systems

Prepare the high-risk AI system's technical documentation before it is placed on the market or put into service, keep it up to date, and ensure it clearly demonstrates compliance with the applicable high-risk requirements and contains at least the information in Annex IV. SMEs, start-ups and small mid-cap enterprises may use the simplified documentation approach provided for by Article 11 when the applicable Commission form is available and used.

ProviderHigh-Risk AIRead

Article 12

UpcomingConditional timing

Enable Automatic Event Logging for High-Risk AI Systems

Design the high-risk AI system with logging capabilities that automatically record relevant events over the system's lifetime to the extent appropriate for its intended purpose and support traceability.

ProviderHigh-Risk AI2 sub-obligationsRead

Article 13

UpcomingConditional timing

Provide Transparency and Instructions for Use to High-Risk AI Deployers

Design and document the high-risk AI system so deployers can interpret its output and use it appropriately. Provide instructions for use that are concise, complete, correct, clear, accessible and comprehensible to deployers.

ProviderHigh-Risk AI2 sub-obligationsRead

Article 14

UpcomingConditional timing

Design High-Risk AI Systems for Effective Human Oversight

Design the high-risk AI system so it can be effectively overseen by natural persons during use. Define oversight measures that are proportionate to the system's risks, level of autonomy and context of use and that help prevent or minimise risks to health, safety and fundamental rights.

ProviderHigh-Risk AI3 sub-obligationsRead

Article 15

UpcomingConditional timing

Ensure High-Risk AI Accuracy, Robustness and Cybersecurity

Design and develop each high-risk AI system to achieve an appropriate level of accuracy, robustness and cybersecurity throughout its lifecycle, taking account of the system's intended purpose and relevant risks.

ProviderHigh-Risk AI3 sub-obligationsRead

Article 16(b)

UpcomingConditional timing

Identify the High-Risk AI Provider and Provide Contact Information

If your organization is the provider of a high-risk AI system, display the provider's name or registered trade name/trademark and a contact address on the system. If that is not possible, provide the information on the packaging or accompanying documentation, as applicable.

ProviderHigh-Risk AIRead

Article 16(l)

UpcomingConditional timing

Ensure High-Risk AI Meets Applicable Accessibility Requirements

If your organization is the provider of a high-risk AI system, determine which accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882 apply to the system and ensure those requirements are met.

ProviderHigh-Risk AIRead

Article 17; Article 63(1)-(2)

UpcomingConditional timing

Maintain a Quality Management System for High-Risk AI

Establish a documented quality management system for high-risk AI that covers the Article 17 elements through written policies, procedures and instructions. Implement it proportionately to the size of the provider, including where the provider is an SME, start-up or small mid-cap, while maintaining the required level of rigour and protection. Where relevant, integrate these elements into an existing sectoral quality-management system. Financial institutions may satisfy much of this obligation through applicable Union financial-services governance requirements, but the Article 17(1)(g), (h) and (i) elements remain separately applicable. For Article 6(1)/Annex I systems, also check Article 2(13), which may limit specific Article 17 obligations where equivalent or higher requirements apply under relevant Union harmonisation legislation and overall protection is not reduced. Qualifying SMEs, including start-ups, may comply with certain QMS elements in a simplified manner under Article 63(1), provided they do not have partner or linked enterprises within the meaning of Recommendation 2003/361/EC. This does not exempt them from the other AI Act requirements identified in Article 63(2).

ProviderHigh-Risk AI7 sub-obligationsRead

Article 18

UpcomingConditional timing

Retain Required High-Risk AI Documentation for Ten Years

Keep the required high-risk AI documentation available to national competent authorities for 10 years after the system is placed on the market or put into service. This includes the technical documentation, quality-management documentation, applicable notified-body change documentation and decisions, and the EU declaration of conformity. Financial institutions may maintain the technical documentation within the documentation required by relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.

ProviderHigh-Risk AIRead

Article 19

UpcomingConditional timing

Retain Automatically Generated High-Risk AI Logs

Keep automatically generated Article 12 logs that are under the provider's control for a period appropriate to the system's intended purpose and at least six months, unless applicable Union or national law requires a different period. Financial institutions may maintain these logs within records kept under relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.

ProviderHigh-Risk AIRead

Article 20

UpcomingConditional timing

Take Corrective Action and Provide Required Information for Non-Conforming or Risky High-Risk AI

If your organization is the provider and considers, or has reason to consider, that a high-risk AI system it placed on the market or put into service is non-conforming, act immediately to correct, withdraw, disable or recall it as appropriate and inform the relevant operators. If the system presents a risk within Article 79(1), investigate the causes and inform the competent market-surveillance authority and, where applicable, the notified body. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AI3 sub-obligationsRead

Article 21

UpcomingConditional timing

Provide High-Risk AI Compliance Information and Logs to Competent Authorities on Request

When a competent authority makes a reasoned request, provide the information and documentation necessary to demonstrate conformity with the high-risk AI requirements in a language the authority can readily understand from the official EU languages indicated by the relevant Member State. Where applicable, also provide access to Article 12 logs under the provider's control. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AIRead

Article 22(1)-(2)

UpcomingConditional timing

Appoint an EU Authorised Representative for High-Risk AI When the Provider Is Established Outside the Union

Before making a high-risk AI system available on the Union market, a provider established in a third country should appoint an authorised representative established in the EU through a written mandate and enable that representative to perform the required tasks. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AIRead

Article 22(3)-(4)

UpcomingConditional timing

Perform Required High-Risk AI Authorised Representative Duties

If your organization acts as the authorised representative of a high-risk AI provider, perform the tasks in the written mandate, provide the mandate to market-surveillance authorities on request, carry out the verification, retention, information, cooperation and registration duties assigned by Article 22, and terminate the mandate with the required notifications if the provider is acting contrary to the Regulation.

Authorised RepresentativeHigh-Risk AI5 sub-obligationsRead

Article 23

UpcomingConditional timing

Fulfil Importer Obligations Before and After Placing High-Risk AI on the EU Market

Before placing a high-risk AI system on the EU market, verify the provider's required conformity steps and documentation. While the system is under the importer's responsibility, preserve conformity, retain the required records and cooperate with competent authorities. Do not place a non-conforming or falsified system on the market. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ImporterHigh-Risk AI6 sub-obligationsRead

Article 24

UpcomingConditional timing

Fulfil Distributor Obligations for High-Risk AI Systems

Before making a high-risk AI system available on the market, verify the required conformity indicators and provider/importer information. Withhold non-conforming systems, preserve conformity while the system is under your responsibility, take or ensure corrective action where needed and cooperate with competent authorities. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

DistributorHigh-Risk AI5 sub-obligationsRead

Article 25(2)

UpcomingConditional timing

Cooperate With a New Provider When Provider Responsibility Transfers

If another distributor, importer, deployer or third party becomes the provider of a high-risk AI system under Article 25(1), the initial provider should cooperate closely with the new provider and provide the information, technical access and other assistance reasonably needed for compliance. Where relevant, this now includes technical documentation sufficient to assess Article 16 compliance, information about known limitations and failure modes, and targeted technical access for testing and validation. The duty does not apply where the initial provider clearly specified that its system was not to be changed into a high-risk AI system. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AIRead

Article 25(4)

UpcomingConditional timing

Define Required Information, Technical Access and Assistance in Written High-Risk AI Supply Agreements

If your organization provides a high-risk AI system and relies on a third party that supplies an AI system, AI model, tool, service, component or process used or integrated in it, use a written agreement to specify the information, capabilities, technical access and other assistance needed, based on the generally acknowledged state of the art, so the high-risk AI provider can comply fully with the Regulation. The stated free/open-source exception does not extend to general-purpose AI models. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

Third-Party SupplierProviderHigh-Risk AIRead

Article 26(1)

UpcomingConditional timing

Use High-Risk AI Systems in Accordance With Provider Instructions

If your organization deploys a high-risk AI system, establish appropriate technical and organisational measures so the system is used in accordance with the provider's instructions for use.

DeployerHigh-Risk AIRead

Article 26(2)

UpcomingConditional timing

Assign Qualified and Supported Human Oversight for High-Risk AI Use

Assign human oversight of the high-risk AI system to people who have the necessary competence, training and authority and ensure they receive the support needed to perform that role.

DeployerHigh-Risk AIRead

Article 26(4)

UpcomingConditional timing

Ensure Controlled Input Data Is Relevant and Sufficiently Representative

Where your organization controls the input data used by the high-risk AI system, ensure those inputs are relevant and sufficiently representative for the system's intended purpose.

DeployerHigh-Risk AIRead

Article 26(5)

UpcomingConditional timing

Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents

Monitor the high-risk AI system in accordance with the provider's instructions. If use may cause an Article 79(1) risk, suspend use and notify the required parties without undue delay. If a serious incident is identified, immediately follow the Article 26(5) notification sequence and use Article 73 mutatis mutandis if the provider cannot be reached.

DeployerHigh-Risk AI3 sub-obligationsRead

Article 26(6)

UpcomingConditional timing

Retain High-Risk AI Logs Under the Deployer's Control

Keep automatically generated high-risk AI logs that are under the deployer's control for a period appropriate to the intended purpose and at least six months, unless another period is provided by applicable Union or national law, including personal-data protection law.

DeployerHigh-Risk AIRead

Article 26(7)

UpcomingConditional timing

Inform Workers Before Workplace Use of High-Risk AI

Before putting a high-risk AI system into service or using it in the workplace, inform workers' representatives and affected workers that they will be subject to use of the system, following the applicable information rules and procedures under Union and national law and practice.

DeployerEmployerHigh-Risk AIRead

Article 26(8)

UpcomingConditional timing

Register Public-Authority High-Risk AI Use and Do Not Use Unregistered Systems

If the deployer is, or acts on behalf of, a public authority, agency or body, complete the applicable Article 49 registration before using the relevant Annex III high-risk AI system. If the system is not registered as required, do not use it and inform the provider or distributor.

DeployerPublic AuthorityHigh-Risk AIRead

Article 26(9)

UpcomingConditional timing

Use Provider Information to Support an Applicable Data Protection Impact Assessment

Where your organization is required to carry out a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, use the relevant information supplied by the high-risk AI provider under Article 13 when conducting that assessment.

DeployerHigh-Risk AIRead

Article 26(10)

UpcomingFrom 2 Dec 2027

Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement

For law-enforcement use of a high-risk post-remote biometric identification system, apply all Article 26(10) safeguards, including the required authorisation, strict targeting and necessity limits, deletion if authorisation is refused, the prohibition on solely automated adverse legal decisions, documentation of each use and annual reporting.

Law EnforcementDeployer5 sub-obligationsRead

Article 26(11)

UpcomingFrom 2 Dec 2027

Inform Individuals When Annex III High-Risk AI Is Used to Make or Assist Decisions About Them

If an Annex III high-risk AI system makes or assists in making decisions about natural persons, inform those persons that they are subject to use of the high-risk AI system. For law-enforcement systems, apply the information rules referenced in Article 26(11).

DeployerAnnex III High-Risk AIHigh-Risk AIRead

Article 26(12)

UpcomingConditional timing

Cooperate With Competent Authorities on High-Risk AI Use

Cooperate with relevant competent authorities in actions they take concerning your organization's high-risk AI system to implement the AI Act.

DeployerHigh-Risk AIRead

Article 27

UpcomingFrom 2 Dec 2027

Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment

Before first using an Article 6(2)/Annex III high-risk AI system, perform a fundamental rights impact assessment if your organization is a body governed by public law, a private entity providing public services, or a deployer of the Annex III point 5(b) or 5(c) systems. Assess the required process, use, affected-person, risk, oversight and mitigation information. Update the assessment when relevant information changes and notify the market-surveillance authority of the results. If a GDPR or law-enforcement DPIA already addresses part of the Article 27 requirements, you may cross-reference or incorporate the relevant DPIA sections instead of duplicating that work.

DeployerAnnex III High-Risk AI5 sub-obligationsRead

Article 43

UpcomingConditional timing

Complete the Required Conformity Assessment for High-Risk AI

Before placing a high-risk AI system on the market or putting it into service, determine and complete the conformity-assessment procedure required by Article 43 for the system. The applicable route depends on the system category, including whether it is an Annex III system or is covered by Union harmonisation legislation listed in Annex I, Section A.

ProviderHigh-Risk AI4 sub-obligationsRead

Article 47; Annex V

UpcomingConditional timing

Draw Up, Maintain and Retain the EU Declaration of Conformity for High-Risk AI

Draw up an EU declaration of conformity for each high-risk AI system in the permitted written machine-readable, physical or electronically signed form. Include the Annex V information, identify the system, state conformity with the applicable high-risk requirements, use a language that the relevant national competent authorities can easily understand, keep the declaration up to date, retain it for ten years and provide a copy to competent authorities on request.

ProviderHigh-Risk AIRead

Article 48

UpcomingConditional timing

Affix the Required CE Marking to High-Risk AI Systems

Affix the CE marking in the form appropriate to the system. Digital systems should use an easily accessible digital CE marking. Where required, include the notified body's identification number and ensure the marking is visible, legible and indelible or appropriately placed on packaging/documentation.

ProviderHigh-Risk AIRead

Article 49

UpcomingConditional timing

Complete Applicable High-Risk AI Registration Requirements

Complete the applicable EU or national database registration before market placement, putting into service or qualifying use. The specific registration duty depends on the system category and operator role.

Authorised RepresentativeProviderDeployer4 sub-obligationsRead

Article 50(1), 50(5)

CurrentFrom 2 Aug 2026

Inform People When They Are Interacting With an AI System

Design and develop directly interactive AI systems so natural persons are informed that they are interacting with AI unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use. Apply the statutory law-enforcement exception where relevant. Provide the information clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.

ProviderRead

Article 50(2), 50(5); Article 111(4)

CurrentConditional timing

Mark Synthetic AI Outputs in a Machine-Readable and Detectable Format

Use technically feasible, effective, interoperable, robust and reliable solutions so synthetic audio, image, video or text outputs are marked in machine-readable form and detectable as artificially generated or manipulated, taking account of the content, implementation costs and the generally acknowledged state of the art. Apply the standard-editing and law-enforcement exceptions where relevant and the Article 50(5) transparency requirements. For qualifying systems placed on the market before 2 August 2026, Article 111(4) provides until 2 December 2026 to comply with Article 50(2).

ProviderRead

Article 50(3), 50(5)

CurrentFrom 2 Aug 2026

Inform People Exposed to Emotion Recognition or Biometric Categorisation Systems

Inform natural persons exposed to an emotion-recognition or biometric-categorisation system about the operation of the system and process personal data in accordance with applicable data-protection law. Apply the statutory criminal-law exception where relevant. Provide the information clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.

DeployerRead

Article 50(4), first subparagraph; Article 50(5)

CurrentFrom 2 Aug 2026

Disclose AI-Generated or Manipulated Deepfake Content

Disclose that qualifying image, audio or video deepfake content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or analogous works, disclosure may be limited so it does not hamper display or enjoyment. Apply the statutory law-enforcement exception where relevant. Provide the disclosure clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.

DeployerRead

Article 50(4), second subparagraph; Article 50(5)

CurrentFrom 2 Aug 2026

Disclose AI-Generated or Manipulated Text Published on Matters of Public Interest

Disclose when AI-generated or manipulated text is published for the purpose of informing the public on matters of public interest, unless a statutory exception applies, including qualifying human review or editorial control where a natural or legal person holds editorial responsibility for publication. Provide the disclosure clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.

DeployerRead

Article 52(1)

CurrentConditional timing

Notify the Commission When a GPAI Model Meets the Systemic-Risk Threshold

Notify the Commission without delay and no later than two weeks after the Article 51(1)(a) systemic-risk condition is met or it becomes known that it will be met, and provide the information needed to demonstrate that the threshold is satisfied.

GPAI ProviderGPAIRead

Article 53(1)(a), 53(2); Annex XI

CurrentConditional timing

Prepare and Maintain GPAI Model Technical Documentation

Prepare and keep up-to-date technical documentation for the GPAI model, including its training and testing processes and evaluation results, with at least the information required by Annex XI, so it can be provided to the AI Office and national competent authorities on request. Article 53(2) exempts qualifying free/open-source models from this duty where the stated licence, access and public-parameter conditions are met, but that exception does not apply to GPAI models with systemic risk.

GPAI ProviderGPAIRead

Article 53(1)(b), 53(2); Annex XII

CurrentConditional timing

Provide GPAI Documentation and Information to Downstream AI System Providers

Prepare, keep up to date and make available information and documentation that enables downstream AI-system providers to understand the GPAI model's capabilities and limitations and comply with their own AI Act obligations, including at least the Annex XII information. Article 53(2) exempts qualifying free/open-source models from this duty where the stated licence, access and public-parameter conditions are met, but that exception does not apply to GPAI models with systemic risk.

GPAI ProviderGPAIRead

Article 53(1)(c)

CurrentConditional timing

Maintain a GPAI Copyright Compliance Policy

Maintain a policy for compliance with Union copyright and related-rights law, including identifying and complying with applicable reservations of rights using appropriate state-of-the-art technologies.

GPAI ProviderGPAIRead

Article 53(1)(d)

CurrentConditional timing

Publish a Sufficiently Detailed Summary of GPAI Training Content

Prepare and make publicly available a sufficiently detailed summary of the content used to train the GPAI model using the AI Office template.

GPAI ProviderGPAIRead

Article 53(3)

CurrentConditional timing

Cooperate With the Commission and Competent Authorities on GPAI Compliance

Cooperate as necessary with the Commission and national competent authorities in the exercise of their AI Act powers and responsibilities.

GPAI ProviderGPAIRead

Article 53(4)

CurrentConditional timing

Demonstrate Alternative Adequate GPAI Compliance Where Approved Codes or Harmonised Standards Are Not Used

Where the provider does not adhere to an approved code of practice or comply with an applicable European harmonised standard, demonstrate alternative adequate means of compliance for Commission assessment.

GPAI ProviderGPAIRead

Article 54(1)-(2), 54(6)

CurrentConditional timing

Appoint an EU Authorised Representative for GPAI Models When the Provider Is Established Outside the Union

Before placing a GPAI model on the Union market, a provider established outside the EU must appoint an EU-established authorised representative by written mandate and enable that representative to perform the mandated tasks. A qualifying open-source exception applies unless the GPAI model presents systemic risk.

GPAI ProviderGPAIRead

Article 54(3)-(5)

CurrentConditional timing

Perform Required GPAI Authorised Representative Duties

Perform the tasks specified in the written mandate, maintain required documentation, support AI Office and competent-authority oversight and terminate the mandate with notice if the provider is acting contrary to its obligations.

Authorised RepresentativeGPAI5 sub-obligationsRead

Article 55(1)(a)

CurrentConditional timing

Evaluate and Adversarially Test GPAI Models With Systemic Risk

Perform model evaluation using state-of-the-art standardised protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks.

GPAI ProviderSystemic-Risk GPAIRead

Article 55(1)(b)

CurrentConditional timing

Assess and Mitigate Systemic Risks From GPAI Models

Assess and mitigate possible systemic risks at Union level, including their sources, arising from development, market placement or use of the GPAI model.

GPAI ProviderSystemic-Risk GPAIRead

Article 55(1)(c)

CurrentConditional timing

Track, Document and Report Serious Incidents Involving Systemic-Risk GPAI

Track and document relevant information about serious incidents and possible corrective measures, and report it without undue delay to the AI Office and, as appropriate, national competent authorities.

GPAI ProviderSystemic-Risk GPAIRead

Article 55(1)(d)

CurrentConditional timing

Maintain Adequate Cybersecurity for Systemic-Risk GPAI Models and Infrastructure

Maintain an adequate level of cybersecurity protection for the systemic-risk GPAI model and its physical infrastructure.

GPAI ProviderSystemic-Risk GPAIRead

Article 55(2)

CurrentConditional timing

Demonstrate Alternative Adequate Compliance for Systemic-Risk GPAI Where Codes or Standards Are Not Used

Where the provider does not adhere to an approved code of practice or comply with an applicable European harmonised standard, demonstrate alternative adequate means of compliance for Commission assessment.

GPAI ProviderSystemic-Risk GPAIRead

Article 72

UpcomingConditional timing

Establish and Maintain Post-Market Monitoring for High-Risk AI

Establish, document and operate a post-market monitoring system proportionate to the technology and risks of the high-risk AI system, using a documented post-market monitoring plan.

ProviderHigh-Risk AI2 sub-obligationsRead

Article 73

UpcomingConditional timing

Report and Investigate Serious Incidents Involving High-Risk AI

Report serious incidents involving high-risk AI to the market-surveillance authority of the Member State where the incident occurred within the applicable deadline, then investigate the incident, reassess risk, implement corrective action and cooperate with authorities. Where Article 75(1a) assigns supervisory competence to the AI Office, use the AI Office reporting route reflected in the separate Article 75 library record.

ProviderHigh-Risk AI5 sub-obligationsRead

Article 86

CurrentFrom 2 Aug 2026

Provide Clear and Meaningful Explanations of Certain High-Risk AI-Assisted Decisions

When the conditions in Article 86 are met, provide the affected person with a clear and meaningful explanation of the AI system's role in the decision-making procedure and the main elements of the decision. Apply Union/national-law exceptions and avoid duplicating rights already provided under other Union law.

DeployerAnnex III High-Risk AIHigh-Risk AIRead

Article 29; Article 28(8); Annex XIV(4)

CurrentFrom 2 Aug 2025

Submit and Maintain the Application for Notification as an AI Conformity Assessment Body

Submit the notification application to the notifying authority of the Member State where the conformity assessment body is established. Include the required description of conformity-assessment activities, modules and AI-system competence, together with an accreditation certificate where available or equivalent documentary evidence. Use the Annex XIV codes, categories and corresponding AI-system types to specify the requested scope of designation. Add valid documents from existing designations under other Union harmonisation legislation. Where the Article 28(8) unified-assessment route applies for Annex I Section A legislation, submit the single application to the notifying authority designated under that sectoral legislation. Update the supporting documentation whenever relevant changes occur.

Conformity Assessment BodyNotified BodyRead

Article 31

CurrentFrom 2 Aug 2025

Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body

Maintain the organisational, quality, resource, process, independence, confidentiality, insurance, competence and cybersecurity arrangements required to perform AI conformity assessments with integrity and impartiality.

Notified Body6 sub-obligationsRead

Article 33

CurrentFrom 2 Aug 2025

Govern Subsidiaries and Subcontractors Used for AI Conformity Assessment

Retain full responsibility for subcontracted or subsidiary conformity-assessment work and ensure the Article 31 requirements continue to be met.

Notified Body3 sub-obligationsRead

Article 34

CurrentFrom 2 Aug 2025

Perform Notified-Body AI Conformity Assessment Activities in Accordance With the Act

Verify high-risk AI conformity using the applicable Article 43 procedures, avoid unnecessary provider burden while preserving the required level of rigour, and support notifying-authority monitoring.

Notified Body2 sub-obligationsRead

Article 36

CurrentFrom 2 Aug 2025

Manage Notified-Body Cessation, Restriction, Suspension or Withdrawal Impacts

Manage the notification and certificate-continuity actions triggered when a notified body ceases activities or its designation is restricted, suspended or withdrawn.

Notified BodyProviderHigh-Risk AI3 sub-obligationsRead

Article 41(5)

CurrentFrom 2 Aug 2026

Justify Equivalent Technical Solutions When Applicable Common Specifications Are Not Followed

Where an applicable common specification exists but the provider does not comply with it, document why the adopted technical solutions meet the relevant high-risk AI requirements or GPAI obligations to at least an equivalent level.

ProviderGPAIHigh-Risk AIRead

Article 44

CurrentFrom 2 Aug 2026

Issue, Maintain and Control AI Conformity Certificates and Appeals

Issue and maintain Annex VII certificates in the required language and validity periods, reassess extensions, restrict or withdraw certificates when requirements are no longer met unless timely corrective action restores compliance, provide reasons and maintain an appeal procedure.

Notified Body3 sub-obligationsRead

Article 45

CurrentFrom 2 Aug 2026

Meet Notified-Body Information-Sharing and Reporting Obligations

Report required certificate, approval, notification-scope and market-surveillance information to the notifying authority and exchange specified conformity-assessment information with other notified bodies while protecting confidentiality.

Notified Body2 sub-obligationsRead

Article 46(2), 46(7)

CurrentFrom 2 Aug 2026

Request Emergency Derogation Authorisation and Stop Use if Authorisation Is Refused

Where the urgent Article 46(2) derogation is used without prior authorisation for the specified public-security or imminent life/safety reasons, request authorisation during or after use without undue delay. If authorisation is refused, stop use immediately and discard all results and outputs from that use. For high-risk AI systems related to products covered by Union harmonisation legislation listed in Annex I Section A, use only the conformity-assessment derogations available under that sectoral legislation.

Civil Protection AuthorityHigh-Risk AIRead

Article 59

CurrentFrom 2 Aug 2026

Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox

Use the Article 59 sandbox processing route only when all cumulative public-interest, necessity, monitoring, segregation, sharing, rights, security, retention and documentation conditions are satisfied.

Prospective ProviderProvider6 sub-obligationsRead

Article 60

CurrentFrom 2 Aug 2026

Conduct High-Risk AI Real-World Testing Only Under the Article 60 Conditions

Before placing a qualifying high-risk AI system on the market or putting it into service, conduct real-world testing outside an AI regulatory sandbox only under Article 60. The route now covers both Annex III high-risk AI and high-risk AI covered by Union harmonisation legislation listed in Annex I Section A. Use an approved real-world testing plan and comply with the applicable approval, registration, establishment, duration, participant-protection, oversight, incident, liability and notification safeguards.

Prospective ProviderProspective DeployerProviderDeployer+3 more7 sub-obligationsRead

Article 60a(1)-(6)

CurrentFrom 2 Aug 2026

Comply With the Applicable Article 60a Framework for Real-World Testing of Annex I Section B AI-Enabled Products

Use the Article 60a route only where the relevant Member State has adopted a framework permitting real-world testing of AI-enabled products covered by Union harmonisation legislation listed in Annex I Section B. Follow the mandatory testing plan agreed with the relevant national authority, comply with the Article 60 conditions incorporated by Article 60a(5), including applicable participant and oversight safeguards, and comply with the relevant sectoral product legislation. Treat this as a Member-State-dependent testing route rather than a general EU-wide permission.

Prospective ProviderProviderAnnex I Section B High-Risk AIHigh-Risk AIRead

Article 61; Article 60(4)(i); Article 60a(5)(b)

CurrentFrom 2 Aug 2026

Obtain, Document and Provide Informed Consent for Applicable Real-World Testing

Before a subject participates in real-world testing under Article 60, obtain freely given informed consent after providing concise, clear, relevant and understandable information about the test, its duration, participant rights, reversal or disregarding arrangements, the test identifier and provider contact information. Date and document the consent and give a copy to the participant or legal representative. Where a Member State Article 60a framework incorporates Article 60(4)(i), apply the same Article 61 consent requirement through that framework, subject to the limited law-enforcement alternative in Article 60(4)(i).

Prospective ProviderProviderAnnex III High-Risk AIAnnex I Section A High-Risk AI+2 moreRead

Article 74(12)-(13)

UpcomingConditional timing

Provide Market-Surveillance Authorities Required Access to High-Risk AI Documentation, Data Sets and Source Code

Provide market-surveillance authorities the access necessary for supervision, including documentation and training, validation and testing data sets and, when the statutory conditions are met, source code.

ProviderHigh-Risk AI2 sub-obligationsRead

Article 75(1a); Article 73(2)-(9)

UpcomingConditional timing

Report Serious Incidents to the AI Office When the AI Office Is the Supervisory Authority

For high-risk AI systems supervised by the AI Office under Article 75(1), report serious incidents to the AI Office rather than the ordinary national route, applying the Article 73 timelines and procedures mutatis mutandis.

ProviderHigh-Risk AIRead

Articles 75a-75c

CurrentFrom 2 Aug 2026

Comply With Binding AI Office Supervision, Investigation and Non-Compliance Requirements

Treat binding AI Office decisions, information requests made by decision, inspections, access or data-retention orders, commitments made binding under Article 75b, and non-compliance decisions as formal regulatory obligations. Respond within specified periods, provide correct and complete information when required, cooperate with lawful investigative measures and implement ordered corrective measures.

ProviderDeployer3 sub-obligationsRead

Article 79(2), 79(4)

CurrentFrom 2 Aug 2026

Cooperate With Market-Surveillance Risk Evaluations and Implement Required Corrective Action

Cooperate as necessary with market-surveillance and relevant fundamental-rights authorities during an evaluation of an AI system presenting risk and ensure corrective action is applied to all affected AI systems made available on the Union market.

Relevant OperatorRead

Article 80(2), 80(4)-(5)

UpcomingFrom 2 Dec 2027

Bring an Annex III System Into High-Risk Compliance When a Non-High-Risk Classification Is Overturned

When a market-surveillance authority concludes that an Annex III system classified as non-high-risk is in fact high-risk, take all required steps within the prescribed period to comply with the high-risk requirements and apply corrective action to all affected systems on the Union market.

ProviderAnnex III High-Risk AIRead

Article 82(1)-(2)

UpcomingConditional timing

Take Authority-Directed Corrective Action When a Compliant High-Risk AI System Still Presents a Risk

If a market-surveillance authority finds that a compliant high-risk AI system nevertheless presents a risk to health, safety, fundamental rights or another protected public interest, implement the required risk-reduction measures and corrective action across affected systems within the prescribed timeline.

ProviderRelevant OperatorHigh-Risk AIRead

Article 91(1), 91(3)-(5)

CurrentFrom 2 Aug 2026

Provide GPAI Documentation and Information Requested by the Commission or AI Office

Provide the GPAI documentation and additional information requested by the Commission under Article 91 within the period stated in the request. The provider or its representative is responsible for supplying the requested information, and the provider remains responsible for information that is incomplete, incorrect or misleading even where an authorised lawyer supplies it on the provider's behalf.

GPAI ProviderGPAIRead

Article 92(3)-(5)

CurrentFrom 2 Aug 2026

Provide Requested Technical Access to a GPAI Model for Regulatory Evaluation

When the Commission formally requests access for a regulatory evaluation under Article 92, provide access to the GPAI model through the technical means, tools, components and conditions stated in the decision, which may include APIs, internal access, source code, model weights, hosting infrastructure or system-state access. Do not impose technical or other constraints that materially impede the evaluation, comply with any lawful requirement concerning evaluation logging, and provide the requested access without undue delay and within the deadline in the decision.

GPAI ProviderGPAIRead

Article 93

CurrentFrom 2 Aug 2026

Implement Commission-Requested GPAI Compliance, Systemic-Risk Mitigation or Market Restriction Measures

Where the Commission requests measures under Article 93, take the appropriate steps requested to comply with Articles 53 and 54, mitigate a serious and substantiated systemic risk, or restrict, withdraw or recall the GPAI model as applicable. If commitments offered during structured dialogue are made binding by Commission decision, comply with those commitments.

GPAI ProviderGPAIRead

Article 43(3)

CurrentFrom 2 Aug 2026

Apply for AI Act Designation by 28 January 2028 When Relying on an Existing Annex I Section A Notification

If your organization is a notified body already notified under Union harmonisation legislation listed in Annex I Section A and relies on Article 43(3) to assess high-risk AI systems under that existing notification, apply for designation under Chapter III Section 4 of the AI Act by 28 January 2028. The transitional assessment power also depends on the notified body's compliance with Article 31(4), (5), (10) and (11) having been assessed and evidenced through the existing sectoral notification.

Notified BodyAnnex I Section A High-Risk AIHigh-Risk AIRead

Article 83(1)

CurrentFrom 2 Aug 2026

Remedy Specified Formal High-Risk AI Non-Compliance Within the Authority's Deadline

If a market-surveillance authority identifies one of the formal non-compliance conditions in Article 83(1), bring the matter into compliance within the period prescribed by the authority. The listed conditions concern CE marking, the EU declaration of conformity, EU database registration, appointment of an authorised representative where required, and availability of technical documentation. If non-compliance persists, the authority may restrict, prohibit, recall or withdraw the high-risk AI system.

ProviderHigh-Risk AIRead

Ready to assign owners, evidence, and gaps to these obligations? Explore Essential Compliance

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

EU AI Act Library | Obligations, Guidance & Official Text | Tracker Networks