Obligation explorer
Filter state lives in the URL: send anyone a pre-filtered view. Every row cites the provision it derives from.
Provider, deployer, substantial modification: every term of art below is defined in the Regulation. Glossary →
Filters (0)
GET /explorer/
| Source | Obligation | Applies |
|---|---|---|
| Art. 4 | AI literacy measures Providers and deployers take measures to support the AI literacy of staff and others operating AI systems on their behalf. As replaced by the 2026 amendment, this is an obligation of means: it does not require guaranteeing any specific literacy level. Cross-cutting ProviderDeployer EU Art. 4 EU Regulation (EU) 2026/1744 You produce
| Applies In force 2 Feb 2025 You produce Team enablement plan for people operating AI systems |
| Art. 5(1) | Prohibited practices Placing on the market, putting into service or using systems for the banned practices: subliminal or manipulative techniques causing significant harm, exploiting vulnerability, social scoring, certain predictive policing, untargeted facial-image scraping, emotion inference at work and school, biometric categorisation that deduces race, political opinion, beliefs or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside its narrow exceptions. Prohibited practice ProviderDeployerImporter You produce
| Applies In force 2 Feb 2025 You produce Prohibited-practices check in feature review |
| Art. 5(1)(ba) and (bb) | Intimate-image and abuse-material generators The prohibitions the 2026 amendment added to Article 5: systems that generate or manipulate non-consensual intimate material of identifiable people, or child sexual abuse material, where that generation is the intended purpose or a reasonably foreseeable and reproducible outcome absent adequate safeguards. Prohibited practice ProviderDeployerImporter EU Art. 5(1)(ba) and (bb) EU Regulation (EU) 2026/1744 You produce
| Applies 2 Dec 2026 You produce Abuse-prevention safeguards for generative features |
| Art. 9 | Risk management system A continuous, iterative risk management process across the whole lifecycle of a high-risk system: identify, estimate, evaluate and treat risks, and test that the measures work. Not a document produced once. High-risk Provider EU Art. 9 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Living risk register with review cadence |
| Art. 10 | Data and data governance Training, validation and test sets for high-risk systems meet quality criteria: relevant, sufficiently representative, examined for bias, with documented provenance and preparation choices. The 2026 amendment added a lawful basis for processing special-category data for bias correction, under strict conditions. High-risk Provider EU Art. 10 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Bias examination report |
| Art. 11 | Technical documentation Documentation drawn up before market placement and kept current, following Annex IV: architecture, design choices, data, training, metrics and known limitations, described as the system actually runs. The 2026 amendment lets SMEs and small mid-caps use a simplified form. High-risk Provider EU Art. 11 EU Annex IV EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Annex IV technical file |
| Art. 12 | Automatic recording of events High-risk systems technically allow automatic recording of events over their lifetime, rich enough to trace the situations that create risk or amount to substantial modification, and to support post-market monitoring. High-risk Provider EU Art. 12 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Inference event schema |
| Art. 13 | Transparency and instructions for deployers High-risk systems are transparent enough for deployers to interpret output and use them appropriately, and ship with instructions for use covering capabilities, limitations, oversight measures and expected lifetime. High-risk Provider EU Art. 13 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Instructions for use per system |
| Art. 14 | Human oversight High-risk systems are designed so natural persons can effectively oversee them: understand capabilities and limitations, interpret output, decide not to use it, and intervene or stop the system. High-risk ProviderDeployer contested EU Art. 14 ES AEPD, guidance on agentic AI EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Oversight UX with override path |
| Art. 15 | Accuracy, robustness and cybersecurity High-risk systems achieve appropriate accuracy, robustness and cybersecurity, and hold those levels consistently through their lifecycle, including resilience against attempts to alter use or performance, data poisoning and adversarial input. High-risk Provider EU Art. 15 EU Art. 113(c)(i) EU Art. 16(a) You produce
| Applies 2 Dec 2027 You produce Model performance SLOs with alerts |
| Art. 17 | Quality management system Providers of high-risk systems run a documented quality management system: compliance strategy, design control, testing, data management, risk management, incident procedures and accountability. The 2026 amendment extended the simplified form from microenterprises to all SMEs. High-risk Provider EU Art. 17 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Documented QMS with named owners |
| Art. 18(1) | Keeping the documentation for ten years For ten years after a high-risk system is placed on the market or put into service, the provider keeps at the disposal of the authorities the technical documentation, the quality management documentation, approved-change records and the EU declaration of conformity. High-risk Provider EU Art. 18(1) EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Ten-year documentation archive with named custodian |
| Art. 19(1) | Keeping the automatically generated logs Providers keep the Article 12 logs that are under their control for a period appropriate to the system's purpose, and at least six months, subject to Union or national law, in particular on personal data. High-risk Provider EU Art. 19(1) EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Restore test on aged logs |
| Art. 20(1) | Corrective actions and duty of information A provider that considers a placed high-risk system non-conformant immediately takes the corrective action needed: bring it into conformity, withdraw it, disable it or recall it, and informs the distributors, deployers, authorised representative and importers concerned. High-risk Provider EU Art. 20(1) EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Downstream notification list |
| Art. 21 | Cooperation with competent authorities On a reasoned request, providers give a competent authority the information and documentation demonstrating the system's conformity, and access to the automatically generated Article 12 logs to the extent those logs are under their control. High-risk Provider You produce
| Applies 2 Dec 2027 You produce Authority response runbook with named owner |
| Art. 22(1) | Authorised representative for third-country providers Before making a high-risk system available on the Union market, providers established in third countries appoint, by written mandate, an authorised representative established in the Union, who verifies and keeps the conformity documentation and cooperates with the authorities. High-risk ProviderAuthorised rep EU Art. 22(1) EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Written mandate for the authorised representative |
| Art. 23 | Importer obligations Before placing a third-country provider's high-risk system on the Union market, importers verify that the conformity assessment was carried out, the technical documentation was drawn up, and the system bears the required marking and documentation, and they identify themselves on it. High-risk Importer You produce
| Applies 2 Dec 2027 You produce Import verification record per system |
| Art. 24 | Distributor obligations Before making a high-risk system available, distributors verify that it bears the CE marking and is accompanied by the EU declaration of conformity and instructions for use, and they hold it back or act when they consider it non-conformant. High-risk Distributor You produce
| Applies 2 Dec 2027 You produce Distribution verification checklist |
| Art. 25(1) | Becoming the provider along the value chain Any distributor, importer, deployer or other third party inherits the full provider obligations through three routes: putting their name or trademark on a high-risk system, substantially modifying one, or modifying the intended purpose of a system so that it becomes high-risk. High-risk DistributorImporterDeployer EU Art. 25(1) EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Value-chain role assessment per system |
| Art. 26 | Deployer obligations Deployers of high-risk systems use them per the instructions for use, assign competent human oversight, ensure relevant and representative input data where they control it, monitor operation, keep the logs under their control, and inform affected workers before workplace use. High-risk Deployer You produce
| Applies 2 Dec 2027 You produce Deployment instructions record per system |
| Art. 27 | Fundamental rights impact assessment Before first use of certain Annex III systems, deployers that are public bodies or private operators providing public services, and deployers using systems for creditworthiness or life and health insurance pricing, assess the impact on fundamental rights and notify the market surveillance authority. High-risk Deployer emerging EU Art. 27 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) You produce
| Applies 2 Dec 2027 You produce Fundamental rights impact assessment |
| Art. 43 | Conformity assessment High-risk systems go through the applicable conformity assessment before market placement, by internal control or with a notified body depending on the case, and again after substantial modification. In practice it bites per system when the high-risk requirements start applying to that system's classification route. High-risk Provider EU Art. 43 EU Regulation (EU) 2026/1744 EU Art. 113 You produce
| Applies In force 2 Aug 2026 You produce Conformity route decision per system |
| Art. 47(1) | EU declaration of conformity and CE marking The provider draws up a machine-readable, signed EU declaration of conformity per high-risk system, keeps it at the authorities' disposal for ten years, and affixes the CE marking, digitally for systems provided digitally. In practice these bite per system when the high-risk requirements reach its classification route. High-risk Provider EU Art. 47(1) EU Art. 48 EU Art. 113 You produce
| Applies In force 2 Aug 2026 You produce EU declaration of conformity per system |
| Art. 49 | Registration in the EU database Providers register Annex III high-risk systems in the EU database before placing them on the market or into service, and public-authority deployers register their use. Providers who conclude a system is not high-risk under Article 6(3) document and register that too. High-risk ProviderDeployerAuthorised rep You produce
| Applies In force 2 Aug 2026 You produce Registration entries per system |
| Art. 50(3) and (4) | Deployer disclosure: emotion recognition and deep fakes Deployers of emotion recognition or biometric categorisation systems inform the people exposed to them. Deployers of systems that generate or manipulate deep-fake image, audio or video disclose that the content has been artificially generated or manipulated. Transparency Deployer You produce
| Applies In force 2 Aug 2026 You produce Exposure disclosure flow per affected surface |
| Art. 50(1) | Disclosing interaction with an AI system Systems intended to interact directly with people are designed so those people are informed they are dealing with an AI system, unless that is obvious to a reasonably informed person from the context. Transparency Provider You produce
| Applies In force 2 Aug 2026 You produce Disclosure pattern in the design system |
| Art. 50(2) | Machine-readable marking of synthetic content Generative systems mark audio, image, video and text output in a machine-readable format, detectable as artificially generated or manipulated, with solutions as effective, interoperable, robust and reliable as technically feasible. The 2026 amendment extended the duty to generative systems placed on the market before the general date, on a transition period. Transparency Provider EU Art. 50(2) EU Regulation (EU) 2026/1744 You produce
| Applies In force 2 Aug 2026 You produce Content marking in the generation pipeline |
| Art. 53(1) | General-purpose AI provider duties Providers of general-purpose models keep model documentation current, give downstream providers the information they need to comply, put a copyright policy in place, and publish a sufficiently detailed summary of training content. General-purpose AI Provider EU Art. 53(1) EU Commission guidelines on GPAI obligations Commission interpretation You produce
| Applies In force 2 Aug 2025 You produce Downstream information pack |
| Art. 54(1) | Authorised representative for GPAI model providers Before placing a general-purpose AI model on the Union market, providers established in third countries appoint, by written mandate, an authorised representative established in the Union to keep the model documentation and cooperate with the AI Office and the authorities. General-purpose AI ProviderAuthorised rep You produce
| Applies In force 2 Aug 2025 You produce Written mandate for the model's authorised representative |
| Art. 55 | Systemic-risk model obligations Providers of general-purpose models with systemic risk additionally run state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and protect the model with adequate cybersecurity. The presumption threshold is training compute above 10²⁵ floating-point operations. General-purpose AI Provider emerging EU Art. 55 EU Art. 51(2) EU GPAI Code of Practice You produce
| Applies In force 2 Aug 2025 You produce Evaluation program with adversarial testing |
| Art. 60 | Real-world testing outside sandboxes Providers or prospective providers may test Annex III high-risk systems in real-world conditions outside a regulatory sandbox, once the market surveillance authority has approved a real-world testing plan, tacitly if it does not answer within 30 days, the test is registered in the EU database, and the subjects have given freely-given informed consent under Article 61. High-risk Provider EU Art. 60 EU Art. 61 EU Regulation (EU) 2026/1744 EU Art. 113 You produce
| Applies In force 2 Aug 2026 You produce Informed-consent flow for test subjects |
| Art. 72 | Post-market monitoring Providers run a documented post-market monitoring system proportionate to the system's risks: actively collecting and analyzing performance data from the field across the system's lifetime, feeding continuous compliance evaluation. The 2026 amendment scheduled Commission guidance and a voluntary plan template. High-risk Provider EU Art. 72 EU Regulation (EU) 2026/1744 You produce
| Applies In force 2 Aug 2026 You produce Post-market monitoring plan |
| Art. 73 | Serious incident reporting Serious incidents go to the market surveillance authority of the Member State where they occurred, immediately after a causal link is established or reasonably likely, and no later than 15 days after awareness, with shorter clocks for widespread infringements and deaths. Meeting the clock depends on detection and on reconstructing what happened fast. High-risk ProviderDeployer EU Art. 73 EU Draft Art. 73 reporting guidance DraftCommission interpretation You produce
| Applies In force 2 Aug 2026 You produce Authority notification runbook |
| Art. 86 | Right to explanation of individual decisions People subject to a decision taken by a deployer on the basis of output from certain Annex III high-risk systems, with legal or similarly significant adverse effects, can obtain from the deployer a clear and meaningful explanation of the system's role in the procedure and the main elements of the decision. High-risk Deployer contested EU Art. 86 EU CJEU C-634/21 (SCHUFA) EU CJEU C-203/22 (Dun & Bradstreet) You produce
| Applies In force 2 Aug 2026 You produce Explanation request process |
No obligation matches those filters.