Public resource
EU AI Act library
Browse the obligations Tracker uses in Essential Compliance. Filter by your role and AI class, then read plain-language guidance next to the official text.
Last reviewed 10 Sept 2026
95
124 nested sub-obligations
50
45 upcoming
243
Verified from EUR-Lex
2026
Text dated 27 July 2026
95 obligations in the library
Article 4(1)
Support AI Literacy for Personnel Using or Operating AI Systems
Your organization should identify staff and other people who operate or use AI systems on its behalf and take proportionate measures to support their AI literacy. Tailor those measures to their existing technical knowledge, experience, education and training, the context in which the AI is used, and the people or groups affected. The Act does not require any individual to achieve a specific level of AI literacy.
Article 4a
Apply Required Safeguards When Processing Special-Category Data for Bias Detection or Correction
If your organization processes special categories of personal data for bias detection or correction under Article 4a, first confirm that the relevant Article 4a pathway applies and that the processing is strictly necessary. Apply all required safeguards in Article 4a(1). Article 4a permits this processing in defined circumstances but does not itself require your organization to conduct bias detection or correction.
Article 5(1)(a)
Do Not Use Manipulative or Deceptive AI Practices That Cause Significant Harm
Your organization should not place on the market, put into service, or use an AI system that uses subliminal, purposefully manipulative, or deceptive techniques in a way that materially impairs informed decision-making and causes, or is reasonably likely to cause, significant harm.
Article 5(1)(b)
Do Not Exploit Vulnerabilities Using AI in a Manner That Causes Significant Harm
Your organization should not place on the market, put into service, or use an AI system that exploits a person's or group's vulnerabilities due to age, disability, or a specific social or economic situation in a way that materially distorts behaviour and causes, or is reasonably likely to cause, significant harm.
Article 5(1)(ba), 5(1a)-(1b)
Do Not Generate or Manipulate Non-Consensual Intimate Content Using AI
For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited non-consensual intimate material, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Apply the specific Article 5(1b) limitation when determining whether a manipulation is covered.
Article 5(1)(bb), 5(1a)
Do Not Generate or Manipulate Prohibited Child Sexual Abuse Material Using AI
For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited child sexual abuse material or performance, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Consider the national-law qualification referenced by Article 5(1)(bb).
Article 5(1)(c)
Do Not Use Prohibited AI-Based Social Scoring
Your organization should not use AI-based social scoring that leads to detrimental or unfavourable treatment of people in social contexts unrelated to the context in which the data were generated or collected, or to treatment that is unjustified or disproportionate to the person's social behaviour or its gravity.
Article 5(1)(d)
Do Not Predict Individual Criminal Risk Solely From Profiling or Personality Characteristics
Your organization should not use AI to assess or predict an individual's risk of committing a criminal offence solely on the basis of profiling or personality traits and characteristics. The prohibition does not prevent AI from supporting a human assessment that is already based on objective and verifiable facts directly linked to criminal activity.
Article 5(1)(e)
Do Not Create or Expand Facial Recognition Databases Through Untargeted Image Scraping
Your organization should not create or expand a facial-recognition database through untargeted scraping of facial images from the internet or CCTV footage.
Article 5(1)(f)
Do Not Use AI Emotion Recognition in Workplaces or Educational Institutions Except for Permitted Purposes
Your organization should not place on the market, put into service for this purpose, or use an AI system to infer emotions of a person in a workplace or educational institution, except where the use is intended for medical or safety reasons.
Article 5(1)(g)
Do Not Use Prohibited Biometric Categorisation to Infer Sensitive Characteristics
Your organization should not use biometric categorisation to infer or deduce the sensitive characteristics prohibited by Article 5(1)(g). Review the specific exclusions in the Article before concluding that a biometric categorisation activity is prohibited.
Article 5(1)(h), 5(2)-(7)
Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Law-enforcement use of real-time remote biometric identification in publicly accessible spaces is generally prohibited. If your organization relies on one of the narrow Article 5 exceptions, confirm that the permitted objective and all related necessity, proportionality, assessment, registration, authorisation and notification conditions are satisfied before and during use.
Article 6(4); Article 49(2)
Document the Assessment When an Annex III AI System Is Considered Not High-Risk
If your organization is a provider of an Annex III AI system and concludes that it is not high-risk under Article 6(3), document that assessment before the system is placed on the market or put into service. Complete the applicable Article 49(2) registration and be prepared to provide the assessment to a competent authority on request.
Article 9
Establish and Maintain a Risk Management System for High-Risk AI
For each high-risk AI system in scope, establish, implement, document and maintain a continuous and iterative risk-management process throughout the system lifecycle. Periodically review and update it. Address risks that can reasonably be mitigated or eliminated through system development or design, or through appropriate technical information.
Article 10
Establish Appropriate Data Governance for High-Risk AI Systems
For high-risk AI systems trained using data, ensure the training, validation and testing data used meet the Article 10 quality and governance requirements. For high-risk systems that do not use model-training techniques, apply the relevant Article 10 requirements to the testing data.
Article 11; Annex IV
Prepare and Maintain Technical Documentation for High-Risk AI Systems
Prepare the high-risk AI system's technical documentation before it is placed on the market or put into service, keep it up to date, and ensure it clearly demonstrates compliance with the applicable high-risk requirements and contains at least the information in Annex IV. SMEs, start-ups and small mid-cap enterprises may use the simplified documentation approach provided for by Article 11 when the applicable Commission form is available and used.
Article 12
Enable Automatic Event Logging for High-Risk AI Systems
Design the high-risk AI system with logging capabilities that automatically record relevant events over the system's lifetime to the extent appropriate for its intended purpose and support traceability.
Article 13
Provide Transparency and Instructions for Use to High-Risk AI Deployers
Design and document the high-risk AI system so deployers can interpret its output and use it appropriately. Provide instructions for use that are concise, complete, correct, clear, accessible and comprehensible to deployers.
Article 14
Design High-Risk AI Systems for Effective Human Oversight
Design the high-risk AI system so it can be effectively overseen by natural persons during use. Define oversight measures that are proportionate to the system's risks, level of autonomy and context of use and that help prevent or minimise risks to health, safety and fundamental rights.
Article 15
Ensure High-Risk AI Accuracy, Robustness and Cybersecurity
Design and develop each high-risk AI system to achieve an appropriate level of accuracy, robustness and cybersecurity throughout its lifecycle, taking account of the system's intended purpose and relevant risks.
Article 16(b)
Identify the High-Risk AI Provider and Provide Contact Information
If your organization is the provider of a high-risk AI system, display the provider's name or registered trade name/trademark and a contact address on the system. If that is not possible, provide the information on the packaging or accompanying documentation, as applicable.
Article 16(l)
Ensure High-Risk AI Meets Applicable Accessibility Requirements
If your organization is the provider of a high-risk AI system, determine which accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882 apply to the system and ensure those requirements are met.
Article 17; Article 63(1)-(2)
Maintain a Quality Management System for High-Risk AI
Establish a documented quality management system for high-risk AI that covers the Article 17 elements through written policies, procedures and instructions. Implement it proportionately to the size of the provider, including where the provider is an SME, start-up or small mid-cap, while maintaining the required level of rigour and protection. Where relevant, integrate these elements into an existing sectoral quality-management system. Financial institutions may satisfy much of this obligation through applicable Union financial-services governance requirements, but the Article 17(1)(g), (h) and (i) elements remain separately applicable. For Article 6(1)/Annex I systems, also check Article 2(13), which may limit specific Article 17 obligations where equivalent or higher requirements apply under relevant Union harmonisation legislation and overall protection is not reduced. Qualifying SMEs, including start-ups, may comply with certain QMS elements in a simplified manner under Article 63(1), provided they do not have partner or linked enterprises within the meaning of Recommendation 2003/361/EC. This does not exempt them from the other AI Act requirements identified in Article 63(2).
Article 18
Retain Required High-Risk AI Documentation for Ten Years
Keep the required high-risk AI documentation available to national competent authorities for 10 years after the system is placed on the market or put into service. This includes the technical documentation, quality-management documentation, applicable notified-body change documentation and decisions, and the EU declaration of conformity. Financial institutions may maintain the technical documentation within the documentation required by relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.
Article 19
Retain Automatically Generated High-Risk AI Logs
Keep automatically generated Article 12 logs that are under the provider's control for a period appropriate to the system's intended purpose and at least six months, unless applicable Union or national law requires a different period. Financial institutions may maintain these logs within records kept under relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.
Article 20
Take Corrective Action and Provide Required Information for Non-Conforming or Risky High-Risk AI
If your organization is the provider and considers, or has reason to consider, that a high-risk AI system it placed on the market or put into service is non-conforming, act immediately to correct, withdraw, disable or recall it as appropriate and inform the relevant operators. If the system presents a risk within Article 79(1), investigate the causes and inform the competent market-surveillance authority and, where applicable, the notified body. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 21
Provide High-Risk AI Compliance Information and Logs to Competent Authorities on Request
When a competent authority makes a reasoned request, provide the information and documentation necessary to demonstrate conformity with the high-risk AI requirements in a language the authority can readily understand from the official EU languages indicated by the relevant Member State. Where applicable, also provide access to Article 12 logs under the provider's control. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 22(1)-(2)
Appoint an EU Authorised Representative for High-Risk AI When the Provider Is Established Outside the Union
Before making a high-risk AI system available on the Union market, a provider established in a third country should appoint an authorised representative established in the EU through a written mandate and enable that representative to perform the required tasks. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 22(3)-(4)
Perform Required High-Risk AI Authorised Representative Duties
If your organization acts as the authorised representative of a high-risk AI provider, perform the tasks in the written mandate, provide the mandate to market-surveillance authorities on request, carry out the verification, retention, information, cooperation and registration duties assigned by Article 22, and terminate the mandate with the required notifications if the provider is acting contrary to the Regulation.
Article 23
Fulfil Importer Obligations Before and After Placing High-Risk AI on the EU Market
Before placing a high-risk AI system on the EU market, verify the provider's required conformity steps and documentation. While the system is under the importer's responsibility, preserve conformity, retain the required records and cooperate with competent authorities. Do not place a non-conforming or falsified system on the market. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 24
Fulfil Distributor Obligations for High-Risk AI Systems
Before making a high-risk AI system available on the market, verify the required conformity indicators and provider/importer information. Withhold non-conforming systems, preserve conformity while the system is under your responsibility, take or ensure corrective action where needed and cooperate with competent authorities. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 25(2)
Cooperate With a New Provider When Provider Responsibility Transfers
If another distributor, importer, deployer or third party becomes the provider of a high-risk AI system under Article 25(1), the initial provider should cooperate closely with the new provider and provide the information, technical access and other assistance reasonably needed for compliance. Where relevant, this now includes technical documentation sufficient to assess Article 16 compliance, information about known limitations and failure modes, and targeted technical access for testing and validation. The duty does not apply where the initial provider clearly specified that its system was not to be changed into a high-risk AI system. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 25(4)
Define Required Information, Technical Access and Assistance in Written High-Risk AI Supply Agreements
If your organization provides a high-risk AI system and relies on a third party that supplies an AI system, AI model, tool, service, component or process used or integrated in it, use a written agreement to specify the information, capabilities, technical access and other assistance needed, based on the generally acknowledged state of the art, so the high-risk AI provider can comply fully with the Regulation. The stated free/open-source exception does not extend to general-purpose AI models. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.
Article 26(1)
Use High-Risk AI Systems in Accordance With Provider Instructions
If your organization deploys a high-risk AI system, establish appropriate technical and organisational measures so the system is used in accordance with the provider's instructions for use.
Article 26(2)
Assign Qualified and Supported Human Oversight for High-Risk AI Use
Assign human oversight of the high-risk AI system to people who have the necessary competence, training and authority and ensure they receive the support needed to perform that role.
Article 26(4)
Ensure Controlled Input Data Is Relevant and Sufficiently Representative
Where your organization controls the input data used by the high-risk AI system, ensure those inputs are relevant and sufficiently representative for the system's intended purpose.
Article 26(5)
Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Monitor the high-risk AI system in accordance with the provider's instructions. If use may cause an Article 79(1) risk, suspend use and notify the required parties without undue delay. If a serious incident is identified, immediately follow the Article 26(5) notification sequence and use Article 73 mutatis mutandis if the provider cannot be reached.
Article 26(6)
Retain High-Risk AI Logs Under the Deployer's Control
Keep automatically generated high-risk AI logs that are under the deployer's control for a period appropriate to the intended purpose and at least six months, unless another period is provided by applicable Union or national law, including personal-data protection law.
Article 26(7)
Inform Workers Before Workplace Use of High-Risk AI
Before putting a high-risk AI system into service or using it in the workplace, inform workers' representatives and affected workers that they will be subject to use of the system, following the applicable information rules and procedures under Union and national law and practice.
Article 26(8)
Register Public-Authority High-Risk AI Use and Do Not Use Unregistered Systems
If the deployer is, or acts on behalf of, a public authority, agency or body, complete the applicable Article 49 registration before using the relevant Annex III high-risk AI system. If the system is not registered as required, do not use it and inform the provider or distributor.
Article 26(9)
Use Provider Information to Support an Applicable Data Protection Impact Assessment
Where your organization is required to carry out a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, use the relevant information supplied by the high-risk AI provider under Article 13 when conducting that assessment.
Article 26(10)
Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
For law-enforcement use of a high-risk post-remote biometric identification system, apply all Article 26(10) safeguards, including the required authorisation, strict targeting and necessity limits, deletion if authorisation is refused, the prohibition on solely automated adverse legal decisions, documentation of each use and annual reporting.
Article 26(11)
Inform Individuals When Annex III High-Risk AI Is Used to Make or Assist Decisions About Them
If an Annex III high-risk AI system makes or assists in making decisions about natural persons, inform those persons that they are subject to use of the high-risk AI system. For law-enforcement systems, apply the information rules referenced in Article 26(11).
Article 26(12)
Cooperate With Competent Authorities on High-Risk AI Use
Cooperate with relevant competent authorities in actions they take concerning your organization's high-risk AI system to implement the AI Act.
Article 27
Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment
Before first using an Article 6(2)/Annex III high-risk AI system, perform a fundamental rights impact assessment if your organization is a body governed by public law, a private entity providing public services, or a deployer of the Annex III point 5(b) or 5(c) systems. Assess the required process, use, affected-person, risk, oversight and mitigation information. Update the assessment when relevant information changes and notify the market-surveillance authority of the results. If a GDPR or law-enforcement DPIA already addresses part of the Article 27 requirements, you may cross-reference or incorporate the relevant DPIA sections instead of duplicating that work.
Article 43
Complete the Required Conformity Assessment for High-Risk AI
Before placing a high-risk AI system on the market or putting it into service, determine and complete the conformity-assessment procedure required by Article 43 for the system. The applicable route depends on the system category, including whether it is an Annex III system or is covered by Union harmonisation legislation listed in Annex I, Section A.
Article 47; Annex V
Draw Up, Maintain and Retain the EU Declaration of Conformity for High-Risk AI
Draw up an EU declaration of conformity for each high-risk AI system in the permitted written machine-readable, physical or electronically signed form. Include the Annex V information, identify the system, state conformity with the applicable high-risk requirements, use a language that the relevant national competent authorities can easily understand, keep the declaration up to date, retain it for ten years and provide a copy to competent authorities on request.
Article 48
Affix the Required CE Marking to High-Risk AI Systems
Affix the CE marking in the form appropriate to the system. Digital systems should use an easily accessible digital CE marking. Where required, include the notified body's identification number and ensure the marking is visible, legible and indelible or appropriately placed on packaging/documentation.
Article 49
Complete Applicable High-Risk AI Registration Requirements
Complete the applicable EU or national database registration before market placement, putting into service or qualifying use. The specific registration duty depends on the system category and operator role.
Article 50(1), 50(5)
Inform People When They Are Interacting With an AI System
Design and develop directly interactive AI systems so natural persons are informed that they are interacting with AI unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use. Apply the statutory law-enforcement exception where relevant. Provide the information clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.
Article 50(2), 50(5); Article 111(4)
Mark Synthetic AI Outputs in a Machine-Readable and Detectable Format
Use technically feasible, effective, interoperable, robust and reliable solutions so synthetic audio, image, video or text outputs are marked in machine-readable form and detectable as artificially generated or manipulated, taking account of the content, implementation costs and the generally acknowledged state of the art. Apply the standard-editing and law-enforcement exceptions where relevant and the Article 50(5) transparency requirements. For qualifying systems placed on the market before 2 August 2026, Article 111(4) provides until 2 December 2026 to comply with Article 50(2).
Article 50(3), 50(5)
Inform People Exposed to Emotion Recognition or Biometric Categorisation Systems
Inform natural persons exposed to an emotion-recognition or biometric-categorisation system about the operation of the system and process personal data in accordance with applicable data-protection law. Apply the statutory criminal-law exception where relevant. Provide the information clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.
Article 50(4), first subparagraph; Article 50(5)
Disclose AI-Generated or Manipulated Deepfake Content
Disclose that qualifying image, audio or video deepfake content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or analogous works, disclosure may be limited so it does not hamper display or enjoyment. Apply the statutory law-enforcement exception where relevant. Provide the disclosure clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.
Article 50(4), second subparagraph; Article 50(5)
Disclose AI-Generated or Manipulated Text Published on Matters of Public Interest
Disclose when AI-generated or manipulated text is published for the purpose of informing the public on matters of public interest, unless a statutory exception applies, including qualifying human review or editorial control where a natural or legal person holds editorial responsibility for publication. Provide the disclosure clearly and distinguishably, no later than the person's first interaction or exposure, and in accordance with applicable accessibility requirements.
Article 52(1)
Notify the Commission When a GPAI Model Meets the Systemic-Risk Threshold
Notify the Commission without delay and no later than two weeks after the Article 51(1)(a) systemic-risk condition is met or it becomes known that it will be met, and provide the information needed to demonstrate that the threshold is satisfied.
Article 53(1)(a), 53(2); Annex XI
Prepare and Maintain GPAI Model Technical Documentation
Prepare and keep up-to-date technical documentation for the GPAI model, including its training and testing processes and evaluation results, with at least the information required by Annex XI, so it can be provided to the AI Office and national competent authorities on request. Article 53(2) exempts qualifying free/open-source models from this duty where the stated licence, access and public-parameter conditions are met, but that exception does not apply to GPAI models with systemic risk.
Article 53(1)(b), 53(2); Annex XII
Provide GPAI Documentation and Information to Downstream AI System Providers
Prepare, keep up to date and make available information and documentation that enables downstream AI-system providers to understand the GPAI model's capabilities and limitations and comply with their own AI Act obligations, including at least the Annex XII information. Article 53(2) exempts qualifying free/open-source models from this duty where the stated licence, access and public-parameter conditions are met, but that exception does not apply to GPAI models with systemic risk.
Article 53(1)(c)
Maintain a GPAI Copyright Compliance Policy
Maintain a policy for compliance with Union copyright and related-rights law, including identifying and complying with applicable reservations of rights using appropriate state-of-the-art technologies.
Article 53(1)(d)
Publish a Sufficiently Detailed Summary of GPAI Training Content
Prepare and make publicly available a sufficiently detailed summary of the content used to train the GPAI model using the AI Office template.
Article 53(3)
Cooperate With the Commission and Competent Authorities on GPAI Compliance
Cooperate as necessary with the Commission and national competent authorities in the exercise of their AI Act powers and responsibilities.
Article 53(4)
Demonstrate Alternative Adequate GPAI Compliance Where Approved Codes or Harmonised Standards Are Not Used
Where the provider does not adhere to an approved code of practice or comply with an applicable European harmonised standard, demonstrate alternative adequate means of compliance for Commission assessment.
Article 54(1)-(2), 54(6)
Appoint an EU Authorised Representative for GPAI Models When the Provider Is Established Outside the Union
Before placing a GPAI model on the Union market, a provider established outside the EU must appoint an EU-established authorised representative by written mandate and enable that representative to perform the mandated tasks. A qualifying open-source exception applies unless the GPAI model presents systemic risk.
Article 54(3)-(5)
Perform Required GPAI Authorised Representative Duties
Perform the tasks specified in the written mandate, maintain required documentation, support AI Office and competent-authority oversight and terminate the mandate with notice if the provider is acting contrary to its obligations.
Article 55(1)(a)
Evaluate and Adversarially Test GPAI Models With Systemic Risk
Perform model evaluation using state-of-the-art standardised protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks.
Article 55(1)(b)
Assess and Mitigate Systemic Risks From GPAI Models
Assess and mitigate possible systemic risks at Union level, including their sources, arising from development, market placement or use of the GPAI model.
Article 55(1)(c)
Track, Document and Report Serious Incidents Involving Systemic-Risk GPAI
Track and document relevant information about serious incidents and possible corrective measures, and report it without undue delay to the AI Office and, as appropriate, national competent authorities.
Article 55(1)(d)
Maintain Adequate Cybersecurity for Systemic-Risk GPAI Models and Infrastructure
Maintain an adequate level of cybersecurity protection for the systemic-risk GPAI model and its physical infrastructure.
Article 55(2)
Demonstrate Alternative Adequate Compliance for Systemic-Risk GPAI Where Codes or Standards Are Not Used
Where the provider does not adhere to an approved code of practice or comply with an applicable European harmonised standard, demonstrate alternative adequate means of compliance for Commission assessment.
Article 72
Establish and Maintain Post-Market Monitoring for High-Risk AI
Establish, document and operate a post-market monitoring system proportionate to the technology and risks of the high-risk AI system, using a documented post-market monitoring plan.
Article 73
Report and Investigate Serious Incidents Involving High-Risk AI
Report serious incidents involving high-risk AI to the market-surveillance authority of the Member State where the incident occurred within the applicable deadline, then investigate the incident, reassess risk, implement corrective action and cooperate with authorities. Where Article 75(1a) assigns supervisory competence to the AI Office, use the AI Office reporting route reflected in the separate Article 75 library record.
Article 86
Provide Clear and Meaningful Explanations of Certain High-Risk AI-Assisted Decisions
When the conditions in Article 86 are met, provide the affected person with a clear and meaningful explanation of the AI system's role in the decision-making procedure and the main elements of the decision. Apply Union/national-law exceptions and avoid duplicating rights already provided under other Union law.
Article 29; Article 28(8); Annex XIV(4)
Submit and Maintain the Application for Notification as an AI Conformity Assessment Body
Submit the notification application to the notifying authority of the Member State where the conformity assessment body is established. Include the required description of conformity-assessment activities, modules and AI-system competence, together with an accreditation certificate where available or equivalent documentary evidence. Use the Annex XIV codes, categories and corresponding AI-system types to specify the requested scope of designation. Add valid documents from existing designations under other Union harmonisation legislation. Where the Article 28(8) unified-assessment route applies for Annex I Section A legislation, submit the single application to the notifying authority designated under that sectoral legislation. Update the supporting documentation whenever relevant changes occur.
Article 31
Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Maintain the organisational, quality, resource, process, independence, confidentiality, insurance, competence and cybersecurity arrangements required to perform AI conformity assessments with integrity and impartiality.
Article 33
Govern Subsidiaries and Subcontractors Used for AI Conformity Assessment
Retain full responsibility for subcontracted or subsidiary conformity-assessment work and ensure the Article 31 requirements continue to be met.
Article 34
Perform Notified-Body AI Conformity Assessment Activities in Accordance With the Act
Verify high-risk AI conformity using the applicable Article 43 procedures, avoid unnecessary provider burden while preserving the required level of rigour, and support notifying-authority monitoring.
Article 36
Manage Notified-Body Cessation, Restriction, Suspension or Withdrawal Impacts
Manage the notification and certificate-continuity actions triggered when a notified body ceases activities or its designation is restricted, suspended or withdrawn.
Article 41(5)
Justify Equivalent Technical Solutions When Applicable Common Specifications Are Not Followed
Where an applicable common specification exists but the provider does not comply with it, document why the adopted technical solutions meet the relevant high-risk AI requirements or GPAI obligations to at least an equivalent level.
Article 44
Issue, Maintain and Control AI Conformity Certificates and Appeals
Issue and maintain Annex VII certificates in the required language and validity periods, reassess extensions, restrict or withdraw certificates when requirements are no longer met unless timely corrective action restores compliance, provide reasons and maintain an appeal procedure.
Article 45
Meet Notified-Body Information-Sharing and Reporting Obligations
Report required certificate, approval, notification-scope and market-surveillance information to the notifying authority and exchange specified conformity-assessment information with other notified bodies while protecting confidentiality.
Article 46(2), 46(7)
Request Emergency Derogation Authorisation and Stop Use if Authorisation Is Refused
Where the urgent Article 46(2) derogation is used without prior authorisation for the specified public-security or imminent life/safety reasons, request authorisation during or after use without undue delay. If authorisation is refused, stop use immediately and discard all results and outputs from that use. For high-risk AI systems related to products covered by Union harmonisation legislation listed in Annex I Section A, use only the conformity-assessment derogations available under that sectoral legislation.
Article 59
Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox
Use the Article 59 sandbox processing route only when all cumulative public-interest, necessity, monitoring, segregation, sharing, rights, security, retention and documentation conditions are satisfied.
Article 60
Conduct High-Risk AI Real-World Testing Only Under the Article 60 Conditions
Before placing a qualifying high-risk AI system on the market or putting it into service, conduct real-world testing outside an AI regulatory sandbox only under Article 60. The route now covers both Annex III high-risk AI and high-risk AI covered by Union harmonisation legislation listed in Annex I Section A. Use an approved real-world testing plan and comply with the applicable approval, registration, establishment, duration, participant-protection, oversight, incident, liability and notification safeguards.
Article 60a(1)-(6)
Comply With the Applicable Article 60a Framework for Real-World Testing of Annex I Section B AI-Enabled Products
Use the Article 60a route only where the relevant Member State has adopted a framework permitting real-world testing of AI-enabled products covered by Union harmonisation legislation listed in Annex I Section B. Follow the mandatory testing plan agreed with the relevant national authority, comply with the Article 60 conditions incorporated by Article 60a(5), including applicable participant and oversight safeguards, and comply with the relevant sectoral product legislation. Treat this as a Member-State-dependent testing route rather than a general EU-wide permission.
Article 61; Article 60(4)(i); Article 60a(5)(b)
Obtain, Document and Provide Informed Consent for Applicable Real-World Testing
Before a subject participates in real-world testing under Article 60, obtain freely given informed consent after providing concise, clear, relevant and understandable information about the test, its duration, participant rights, reversal or disregarding arrangements, the test identifier and provider contact information. Date and document the consent and give a copy to the participant or legal representative. Where a Member State Article 60a framework incorporates Article 60(4)(i), apply the same Article 61 consent requirement through that framework, subject to the limited law-enforcement alternative in Article 60(4)(i).
Article 74(12)-(13)
Provide Market-Surveillance Authorities Required Access to High-Risk AI Documentation, Data Sets and Source Code
Provide market-surveillance authorities the access necessary for supervision, including documentation and training, validation and testing data sets and, when the statutory conditions are met, source code.
Article 75(1a); Article 73(2)-(9)
Report Serious Incidents to the AI Office When the AI Office Is the Supervisory Authority
For high-risk AI systems supervised by the AI Office under Article 75(1), report serious incidents to the AI Office rather than the ordinary national route, applying the Article 73 timelines and procedures mutatis mutandis.
Articles 75a-75c
Comply With Binding AI Office Supervision, Investigation and Non-Compliance Requirements
Treat binding AI Office decisions, information requests made by decision, inspections, access or data-retention orders, commitments made binding under Article 75b, and non-compliance decisions as formal regulatory obligations. Respond within specified periods, provide correct and complete information when required, cooperate with lawful investigative measures and implement ordered corrective measures.
Article 79(2), 79(4)
Cooperate With Market-Surveillance Risk Evaluations and Implement Required Corrective Action
Cooperate as necessary with market-surveillance and relevant fundamental-rights authorities during an evaluation of an AI system presenting risk and ensure corrective action is applied to all affected AI systems made available on the Union market.
Article 80(2), 80(4)-(5)
Bring an Annex III System Into High-Risk Compliance When a Non-High-Risk Classification Is Overturned
When a market-surveillance authority concludes that an Annex III system classified as non-high-risk is in fact high-risk, take all required steps within the prescribed period to comply with the high-risk requirements and apply corrective action to all affected systems on the Union market.
Article 82(1)-(2)
Take Authority-Directed Corrective Action When a Compliant High-Risk AI System Still Presents a Risk
If a market-surveillance authority finds that a compliant high-risk AI system nevertheless presents a risk to health, safety, fundamental rights or another protected public interest, implement the required risk-reduction measures and corrective action across affected systems within the prescribed timeline.
Article 91(1), 91(3)-(5)
Provide GPAI Documentation and Information Requested by the Commission or AI Office
Provide the GPAI documentation and additional information requested by the Commission under Article 91 within the period stated in the request. The provider or its representative is responsible for supplying the requested information, and the provider remains responsible for information that is incomplete, incorrect or misleading even where an authorised lawyer supplies it on the provider's behalf.
Article 92(3)-(5)
Provide Requested Technical Access to a GPAI Model for Regulatory Evaluation
When the Commission formally requests access for a regulatory evaluation under Article 92, provide access to the GPAI model through the technical means, tools, components and conditions stated in the decision, which may include APIs, internal access, source code, model weights, hosting infrastructure or system-state access. Do not impose technical or other constraints that materially impede the evaluation, comply with any lawful requirement concerning evaluation logging, and provide the requested access without undue delay and within the deadline in the decision.
Article 93
Implement Commission-Requested GPAI Compliance, Systemic-Risk Mitigation or Market Restriction Measures
Where the Commission requests measures under Article 93, take the appropriate steps requested to comply with Articles 53 and 54, mitigate a serious and substantiated systemic risk, or restrict, withdraw or recall the GPAI model as applicable. If commitments offered during structured dialogue are made binding by Commission decision, comply with those commitments.
Article 43(3)
Apply for AI Act Designation by 28 January 2028 When Relying on an Existing Annex I Section A Notification
If your organization is a notified body already notified under Union harmonisation legislation listed in Annex I Section A and relies on Article 43(3) to assess high-risk AI systems under that existing notification, apply for designation under Chapter III Section 4 of the AI Act by 28 January 2028. The transitional assessment power also depends on the notified body's compliance with Article 31(4), (5), (10) and (11) having been assessed and evidenced through the existing sectoral notification.
Article 83(1)
Remedy Specified Formal High-Risk AI Non-Compliance Within the Authority's Deadline
If a market-surveillance authority identifies one of the formal non-compliance conditions in Article 83(1), bring the matter into compliance within the period prescribed by the authority. The listed conditions concern CE marking, the EU declaration of conformity, EU database registration, appointment of an authorised representative where required, and availability of technical documentation. If non-compliance persists, the authority may restrict, prohibit, recall or withdraw the high-risk AI system.
Ready to assign owners, evidence, and gaps to these obligations? Explore Essential Compliance