Evaluating ERM or GRC software? Get free Excel and Word RFP templates — 250+ requirements

Get the templates

Public resource

EU AI Act Compliance Obligations Library

A practical, searchable library of EU AI Act obligations, sub-obligations, official provisions, suggested controls and related risks.

Explore the EU AI Act’s compliance obligations in plain language. Filter requirements by actor, AI class and timing, review current and upcoming duties, and compare Tracker Networks Guidance with the official legal text.

Go beyond the legislation with suggested controls and related risks designed to help turn EU AI Act requirements into an operational compliance program.

Last reviewed 20 Sept 2026

Obligations

97

124 nested sub-obligations

Suggested controls

60

40 related risks

Already in force

50

47 upcoming

Official provisions

245

Verified from EUR-Lex

Source consolidation

2026

Text dated 27 July 2026

97 obligations grouped by the Act’s structure

Article 4(1)

CurrentFrom 2 Feb 2025

Support AI Literacy for Personnel Using or Operating AI Systems

Your organization should identify staff and other people who operate or use AI systems on its behalf and take proportionate measures to support their AI literacy. Tailor those measures to their existing technical knowledge, experience, education and training, the context in which the AI is used, and the people or groups affected. The Act does not require any individual to achieve a specific level of AI literacy.

ProviderDeployer1 suggested control1 related risk

Article 4a

CurrentFrom 27 Jul 2026

Apply Required Safeguards When Processing Special-Category Data for Bias Detection or Correction

If your organization processes special categories of personal data for bias detection or correction under Article 4a, first confirm that the relevant Article 4a pathway applies and that the processing is strictly necessary. Apply all required safeguards in Article 4a(1). Article 4a permits this processing in defined circumstances but does not itself require your organization to conduct bias detection or correction.

ProviderDeployer2 suggested controls3 related risks
Open details

Article 5(1)(b)

CurrentFrom 2 Feb 2025

Do Not Exploit Vulnerabilities Using AI in a Manner That Causes Significant Harm

Your organization should not place on the market, put into service, or use an AI system that exploits a person's or group's vulnerabilities due to age, disability, or a specific social or economic situation in a way that materially distorts behaviour and causes, or is reasonably likely to cause, significant harm.

ProviderDeployer3 suggested controls2 related risks

Article 5(1)(ba), 5(1a)-(1b)

UpcomingFrom 2 Dec 2026

Do Not Generate or Manipulate Non-Consensual Intimate Content Using AI

For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited non-consensual intimate material, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Apply the specific Article 5(1b) limitation when determining whether a manipulation is covered.

ProviderDeployer3 suggested controls2 related risks

Article 5(1)(bb), 5(1a)

UpcomingFrom 2 Dec 2026

Do Not Generate or Manipulate Prohibited Child Sexual Abuse Material Using AI

For providers, do not place on the market or put into service an AI system whose intended purpose is to generate or manipulate the prohibited child sexual abuse material or performance, or where that outcome is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards to prevent and correct misuse. For deployers, do not use an AI system for that prohibited purpose. Consider the national-law qualification referenced by Article 5(1)(bb).

ProviderDeployer3 suggested controls2 related risks

Article 5(1)(d)

CurrentFrom 2 Feb 2025

Do Not Predict Individual Criminal Risk Solely From Profiling or Personality Characteristics

Your organization should not use AI to assess or predict an individual's risk of committing a criminal offence solely on the basis of profiling or personality traits and characteristics. The prohibition does not prevent AI from supporting a human assessment that is already based on objective and verifiable facts directly linked to criminal activity.

ProviderDeployer2 suggested controls2 related risks

Article 5(1)(a)

CurrentFrom 2 Feb 2025

Do Not Use Manipulative or Deceptive AI Practices That Cause Significant Harm

Your organization should not place on the market, put into service, or use an AI system that uses subliminal, purposefully manipulative, or deceptive techniques in a way that materially impairs informed decision-making and causes, or is reasonably likely to cause, significant harm.

ProviderDeployer3 suggested controls2 related risks

Article 5(1)(c)

CurrentFrom 2 Feb 2025

Do Not Use Prohibited AI-Based Social Scoring

Your organization should not use AI-based social scoring that leads to detrimental or unfavourable treatment of people in social contexts unrelated to the context in which the data were generated or collected, or to treatment that is unjustified or disproportionate to the person's social behaviour or its gravity.

ProviderDeployer3 suggested controls2 related risks

Article 5(1)(h), 5(2)-(7)

CurrentFrom 2 Feb 2025

Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted

Law-enforcement use of real-time remote biometric identification in publicly accessible spaces is generally prohibited. If your organization relies on one of the narrow Article 5 exceptions, confirm that the permitted objective and all related necessity, proportionality, assessment, registration, authorisation and notification conditions are satisfied before and during use.

Law EnforcementDeployer5 suggested controls5 related risks
Open details

Article 6(4); Article 49(2)

UpcomingFrom 2 Dec 2027

Document the Assessment When an Annex III AI System Is Considered Not High-Risk

If your organization is a provider of an Annex III AI system and concludes that it is not high-risk under Article 6(3), document that assessment before the system is placed on the market or put into service. Complete the applicable Article 49(2) registration and be prepared to provide the assessment to a competent authority on request.

ProviderAnnex III High-Risk AI2 suggested controls1 related risk

Article 9

UpcomingConditional timing

Establish and Maintain a Risk Management System for High-Risk AI

For each high-risk AI system in scope, establish, implement, document and maintain a continuous and iterative risk-management process throughout the system lifecycle. Periodically review and update it. Address risks that can reasonably be mitigated or eliminated through system development or design, or through appropriate technical information.

ProviderHigh-Risk AI2 suggested controls3 related risks
Open details

Article 10

UpcomingConditional timing

Establish Appropriate Data Governance for High-Risk AI Systems

For high-risk AI systems trained using data, ensure the training, validation and testing data used meet the Article 10 quality and governance requirements. For high-risk systems that do not use model-training techniques, apply the relevant Article 10 requirements to the testing data.

ProviderHigh-Risk AI1 suggested control2 related risks
Open details

Article 11; Annex IV

UpcomingConditional timing

Prepare and Maintain Technical Documentation for High-Risk AI Systems

Prepare the high-risk AI system's technical documentation before it is placed on the market or put into service, keep it up to date, and ensure it clearly demonstrates compliance with the applicable high-risk requirements and contains at least the information in Annex IV. SMEs, start-ups and small mid-cap enterprises may use the simplified documentation approach provided for by Article 11 when the applicable Commission form is available and used.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 12

UpcomingConditional timing

Enable Automatic Event Logging for High-Risk AI Systems

Design the high-risk AI system with logging capabilities that automatically record relevant events over the system's lifetime to the extent appropriate for its intended purpose and support traceability.

ProviderHigh-Risk AI2 suggested controls2 related risks
Open details

Article 14

UpcomingConditional timing

Design High-Risk AI Systems for Effective Human Oversight

Design the high-risk AI system so it can be effectively overseen by natural persons during use. Define oversight measures that are proportionate to the system's risks, level of autonomy and context of use and that help prevent or minimise risks to health, safety and fundamental rights.

ProviderHigh-Risk AI2 suggested controls2 related risks
Open details

Article 15

UpcomingConditional timing

Ensure High-Risk AI Accuracy, Robustness and Cybersecurity

Design and develop each high-risk AI system to achieve an appropriate level of accuracy, robustness and cybersecurity throughout its lifecycle, taking account of the system's intended purpose and relevant risks.

ProviderHigh-Risk AI2 suggested controls1 related risk
Open details

Article 16(b)

UpcomingConditional timing

Identify the High-Risk AI Provider and Provide Contact Information

If your organization is the provider of a high-risk AI system, display the provider's name or registered trade name/trademark and a contact address on the system. If that is not possible, provide the information on the packaging or accompanying documentation, as applicable.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 16(l)

UpcomingConditional timing

Ensure High-Risk AI Meets Applicable Accessibility Requirements

If your organization is the provider of a high-risk AI system, determine which accessibility requirements under Directives (EU) 2016/2102 and (EU) 2019/882 apply to the system and ensure those requirements are met.

ProviderHigh-Risk AI2 suggested controls2 related risks

Article 17; Article 63(1)-(2)

UpcomingConditional timing

Maintain a Quality Management System for High-Risk AI

Establish a documented quality management system for high-risk AI that covers the Article 17 elements through written policies, procedures and instructions. Implement it proportionately to the size of the provider, including where the provider is an SME, start-up or small mid-cap, while maintaining the required level of rigour and protection. Where relevant, integrate these elements into an existing sectoral quality-management system. Financial institutions may satisfy much of this obligation through applicable Union financial-services governance requirements, but the Article 17(1)(g), (h) and (i) elements remain separately applicable. For Article 6(1)/Annex I systems, also check Article 2(13), which may limit specific Article 17 obligations where equivalent or higher requirements apply under relevant Union harmonisation legislation and overall protection is not reduced. Qualifying SMEs, including start-ups, may comply with certain QMS elements in a simplified manner under Article 63(1), provided they do not have partner or linked enterprises within the meaning of Recommendation 2003/361/EC. This does not exempt them from the other AI Act requirements identified in Article 63(2).

ProviderHigh-Risk AI6 suggested controls6 related risks
Open details

Article 18

UpcomingConditional timing

Retain Required High-Risk AI Documentation for Ten Years

Keep the required high-risk AI documentation available to national competent authorities for 10 years after the system is placed on the market or put into service. This includes the technical documentation, quality-management documentation, applicable notified-body change documentation and decisions, and the EU declaration of conformity. Financial institutions may maintain the technical documentation within the documentation required by relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 19

UpcomingConditional timing

Retain Automatically Generated High-Risk AI Logs

Keep automatically generated Article 12 logs that are under the provider's control for a period appropriate to the system's intended purpose and at least six months, unless applicable Union or national law requires a different period. Financial institutions may maintain these logs within records kept under relevant Union financial-services law. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral Union harmonisation requirements.

ProviderHigh-Risk AI2 suggested controls2 related risks

Article 20

UpcomingConditional timing

Take Corrective Action and Provide Required Information for Non-Conforming or Risky High-Risk AI

If your organization is the provider and considers, or has reason to consider, that a high-risk AI system it placed on the market or put into service is non-conforming, act immediately to correct, withdraw, disable or recall it as appropriate and inform the relevant operators. If the system presents a risk within Article 79(1), investigate the causes and inform the competent market-surveillance authority and, where applicable, the notified body. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AI2 suggested controls3 related risks
Open details

Article 21

UpcomingConditional timing

Provide High-Risk AI Compliance Information and Logs to Competent Authorities on Request

When a competent authority makes a reasoned request, provide the information and documentation necessary to demonstrate conformity with the high-risk AI requirements in a language the authority can readily understand from the official EU languages indicated by the relevant Member State. Where applicable, also provide access to Article 12 logs under the provider's control. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 22(1)-(2)

UpcomingConditional timing

Appoint an EU Authorised Representative for High-Risk AI When the Provider Is Established Outside the Union

Before making a high-risk AI system available on the Union market, a provider established in a third country should appoint an authorised representative established in the EU through a written mandate and enable that representative to perform the required tasks. For Article 6(1)/Annex I systems, check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 22(3)-(4)

UpcomingConditional timing

Perform Required High-Risk AI Authorised Representative Duties

If your organization acts as the authorised representative of a high-risk AI provider, perform the tasks in the written mandate, provide the mandate to market-surveillance authorities on request, carry out the verification, retention, information, cooperation and registration duties assigned by Article 22, and terminate the mandate with the required notifications if the provider is acting contrary to the Regulation.

Authorised RepresentativeHigh-Risk AI3 suggested controls3 related risks
Open details

Article 23

UpcomingConditional timing

Fulfil Importer Obligations Before and After Placing High-Risk AI on the EU Market

Before placing a high-risk AI system on the EU market, verify the provider's required conformity steps and documentation. While the system is under the importer's responsibility, preserve conformity, retain the required records and cooperate with competent authorities. Do not place a non-conforming or falsified system on the market. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ImporterHigh-Risk AI4 suggested controls4 related risks
Open details

Article 24

UpcomingConditional timing

Fulfil Distributor Obligations for High-Risk AI Systems

Before making a high-risk AI system available on the market, verify the required conformity indicators and provider/importer information. Withhold non-conforming systems, preserve conformity while the system is under your responsibility, take or ensure corrective action where needed and cooperate with competent authorities. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

DistributorHigh-Risk AI3 suggested controls3 related risks
Open details

Article 25(1)

UpcomingConditional timing

Assume Provider Responsibilities When Your Actions Make You the Provider of a High-Risk AI System

If your organization is a distributor, importer, deployer or other third party and it puts its name or trademark on an existing high-risk AI system, substantially modifies a high-risk AI system so that it remains high-risk, or changes the intended purpose of an AI system so that it becomes high-risk, Article 25(1) treats your organization as the provider. In that case, assume the applicable Article 16 provider obligations and manage the resulting provider responsibilities before the affected system is placed on the market, put into service or otherwise operated under your responsibility.

DeployerDistributorImporterThird-Party Supplier+1 more2 suggested controls1 related risk

Article 25(2)

UpcomingConditional timing

Cooperate With a New Provider When Provider Responsibility Transfers

If another distributor, importer, deployer or third party becomes the provider of a high-risk AI system under Article 25(1), the initial provider should cooperate closely with the new provider and provide the information, technical access and other assistance reasonably needed for compliance. Where relevant, this now includes technical documentation sufficient to assess Article 16 compliance, information about known limitations and failure modes, and targeted technical access for testing and validation. The duty does not apply where the initial provider clearly specified that its system was not to be changed into a high-risk AI system. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

ProviderHigh-Risk AI1 suggested control1 related risk

Article 25(3)

UpcomingConditional timing

Assume Provider Responsibilities as the Product Manufacturer of Certain Annex I Section A High-Risk AI

If your organization manufactures a product covered by Union harmonisation legislation in Annex I Section A and a high-risk AI system is a safety component of that product, Article 25(3) treats the product manufacturer as the provider when the AI system is placed on the market together with the product under the manufacturer's name or trademark, or is put into service under that name or trademark after the product has been placed on the market. When this applies, the manufacturer is subject to the Article 16 provider obligations. Review the Provider obligations in this library as well as the Annex I Section A conformity-assessment requirements.

Product ManufacturerAnnex I Section A High-Risk AIHigh-Risk AI1 suggested control1 related risk

Article 25(4)

UpcomingConditional timing

Define Required Information, Technical Access and Assistance in Written High-Risk AI Supply Agreements

If your organization provides a high-risk AI system and relies on a third party that supplies an AI system, AI model, tool, service, component or process used or integrated in it, use a written agreement to specify the information, capabilities, technical access and other assistance needed, based on the generally acknowledged state of the art, so the high-risk AI provider can comply fully with the Regulation. The stated free/open-source exception does not extend to general-purpose AI models. For Article 6(1)/Annex I systems, also check Article 2(13) for any permitted limitation based on equivalent or higher sectoral requirements.

Third-Party SupplierProviderHigh-Risk AI1 suggested control1 related risk

Get library updates

The library stays open to browse. Leave a work email if you want Tracker Networks to send future updates, saved-view links, or downloadable extracts when they are available.

Ready to assign owners, evidence, and gaps to these obligations? Explore Essential Compliance

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

EU AI Act Compliance Obligations Library | Tracker Networks