Obligation explorer

Filter state lives in the URL: send anyone a pre-filtered view. Every row cites the provision it derives from.

Provider, deployer, substantial modification: every term of art below is defined in the Regulation. Glossary →

34 of 34 obligations
Source Obligation Applies
Art. 4 AI literacy measures

Providers and deployers take measures to support the AI literacy of staff and others operating AI systems on their behalf. As replaced by the 2026 amendment, this is an obligation of means: it does not require guaranteeing any specific literacy level.

Cross-cutting ProviderDeployer

EU Art. 4 EU Regulation (EU) 2026/1744

You produce
CTO
Team enablement plan for people operating AI systems
Product
Onboarding notes for AI-touching roles
Applies In force

2 Feb 2025

You produce Team enablement plan for people operating AI systems

Art. 5(1) Prohibited practices

Placing on the market, putting into service or using systems for the banned practices: subliminal or manipulative techniques causing significant harm, exploiting vulnerability, social scoring, certain predictive policing, untargeted facial-image scraping, emotion inference at work and school, biometric categorisation that deduces race, political opinion, beliefs or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside its narrow exceptions.

Prohibited practice ProviderDeployerImporter

EU Art. 5(1)

You produce
Product
Prohibited-practices check in feature review
CTO
Design-review gate referencing Article 5
Applies In force

2 Feb 2025

You produce Prohibited-practices check in feature review

Art. 5(1)(ba) and (bb) Intimate-image and abuse-material generators

The prohibitions the 2026 amendment added to Article 5: systems that generate or manipulate non-consensual intimate material of identifiable people, or child sexual abuse material, where that generation is the intended purpose or a reasonably foreseeable and reproducible outcome absent adequate safeguards.

Prohibited practice ProviderDeployerImporter

EU Art. 5(1)(ba) and (bb) EU Regulation (EU) 2026/1744

You produce
Product
Abuse-prevention safeguards for generative features
Developer
Safeguard test suite with recorded results
Applies Upcoming

2 Dec 2026

You produce Abuse-prevention safeguards for generative features

Art. 9 Risk management system

A continuous, iterative risk management process across the whole lifecycle of a high-risk system: identify, estimate, evaluate and treat risks, and test that the measures work. Not a document produced once.

High-risk Provider

EU Art. 9 EU Art. 113(c)(i) EU Art. 16(a)

You produce
CTO
Living risk register with review cadence
Product
Foreseeable-misuse analysis per release
Developer
Risk-to-control mapping in the design docs
DevOps / SRE
Field-risk signal feed into the register Escalation path for emergent risk
Applies Upcoming

2 Dec 2027

You produce Living risk register with review cadence

Art. 10 Data and data governance

Training, validation and test sets for high-risk systems meet quality criteria: relevant, sufficiently representative, examined for bias, with documented provenance and preparation choices. The 2026 amendment added a lawful basis for processing special-category data for bias correction, under strict conditions.

High-risk Provider

EU Art. 10 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) EU Art. 16(a)

You produce
Developer
Dataset cards with provenance Bias examination report
DevOps / SRE
Per-run lineage records
Product
Stated assumptions per data set Representativeness note for the target population
Applies Upcoming

2 Dec 2027

You produce Bias examination report

Art. 11 Technical documentation

Documentation drawn up before market placement and kept current, following Annex IV: architecture, design choices, data, training, metrics and known limitations, described as the system actually runs. The 2026 amendment lets SMEs and small mid-caps use a simplified form.

High-risk Provider

EU Art. 11 EU Annex IV EU Regulation (EU) 2026/1744 EU Art. 113(c)(i) EU Art. 16(a)

You produce
Developer
Annex IV technical file Doc generation wired into CI
CTO
Documentation format decision on record
Applies Upcoming

2 Dec 2027

You produce Annex IV technical file

Art. 12 Automatic recording of events

High-risk systems technically allow automatic recording of events over their lifetime, rich enough to trace the situations that create risk or amount to substantial modification, and to support post-market monitoring.

High-risk Provider

EU Art. 12 EU Art. 113(c)(i) EU Art. 16(a)

You produce
DevOps / SRE
Inference event schema Tamper-evident log storage Replay runbook
You already have A log pipeline and retention config. The gap is decision-grade fidelity, not plumbing.
Developer
Decision-correlation IDs across services
Applies Upcoming

2 Dec 2027

You produce Inference event schema

Art. 13 Transparency and instructions for deployers

High-risk systems are transparent enough for deployers to interpret output and use them appropriately, and ship with instructions for use covering capabilities, limitations, oversight measures and expected lifetime.

High-risk Provider

EU Art. 13 EU Art. 113(c)(i) EU Art. 16(a)

You produce
Product
Instructions for use per system
Developer
Output metadata deployers can read
DevOps / SRE
Resource, lifetime and maintenance inputs for the instructions
Applies Upcoming

2 Dec 2027

You produce Instructions for use per system

Art. 14 Human oversight

High-risk systems are designed so natural persons can effectively oversee them: understand capabilities and limitations, interpret output, decide not to use it, and intervene or stop the system.

High-risk ProviderDeployer contested

EU Art. 14 ES AEPD, guidance on agentic AI EU Art. 113(c)(i) EU Art. 16(a)

You produce
Product
Oversight UX with override path
Developer
Kill switch and override, with tests
DevOps / SRE
Oversight runbook
Applies Upcoming

2 Dec 2027

You produce Oversight UX with override path

Art. 15 Accuracy, robustness and cybersecurity

High-risk systems achieve appropriate accuracy, robustness and cybersecurity, and hold those levels consistently through their lifecycle, including resilience against attempts to alter use or performance, data poisoning and adversarial input.

High-risk Provider

EU Art. 15 EU Art. 113(c)(i) EU Art. 16(a)

You produce
DevOps / SRE
Model performance SLOs with alerts
Developer
Adversarial and injection test suite
Product
Declared accuracy levels and metrics
Applies Upcoming

2 Dec 2027

You produce Model performance SLOs with alerts

Art. 17 Quality management system

Providers of high-risk systems run a documented quality management system: compliance strategy, design control, testing, data management, risk management, incident procedures and accountability. The 2026 amendment extended the simplified form from microenterprises to all SMEs.

High-risk Provider

EU Art. 17 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i)

You produce
CTO
Documented QMS with named owners
Developer
Design control and verification procedures Test and validation records
Applies Upcoming

2 Dec 2027

You produce Documented QMS with named owners

Art. 18(1) Keeping the documentation for ten years

For ten years after a high-risk system is placed on the market or put into service, the provider keeps at the disposal of the authorities the technical documentation, the quality management documentation, approved-change records and the EU declaration of conformity.

High-risk Provider

EU Art. 18(1) EU Art. 113(c)(i)

You produce
CTO
Ten-year documentation archive with named custodian
DevOps / SRE
Archive restore test on a schedule
Applies Upcoming

2 Dec 2027

You produce Ten-year documentation archive with named custodian

Art. 19(1) Keeping the automatically generated logs

Providers keep the Article 12 logs that are under their control for a period appropriate to the system's purpose, and at least six months, subject to Union or national law, in particular on personal data.

High-risk Provider

EU Art. 19(1) EU Art. 113(c)(i)

You produce
DevOps / SRE
Retention policy meeting the six-month floor Restore test on aged logs
You already have Retention exists, typically at days or weeks and sampled. The floor here is months, complete.
CTO
Retention budget and DPO sign-off
Applies Upcoming

2 Dec 2027

You produce Restore test on aged logs

Art. 20(1) Corrective actions and duty of information

A provider that considers a placed high-risk system non-conformant immediately takes the corrective action needed: bring it into conformity, withdraw it, disable it or recall it, and informs the distributors, deployers, authorised representative and importers concerned.

High-risk Provider

EU Art. 20(1) EU Art. 113(c)(i)

You produce
DevOps / SRE
Withdraw-or-disable runbook per system Downstream notification list
CTO
Corrective-action decision record
Applies Upcoming

2 Dec 2027

You produce Downstream notification list

Art. 21 Cooperation with competent authorities

On a reasoned request, providers give a competent authority the information and documentation demonstrating the system's conformity, and access to the automatically generated Article 12 logs to the extent those logs are under their control.

High-risk Provider

EU Art. 21 EU Art. 113(c)(i)

You produce
CTO
Authority response runbook with named owner
DevOps / SRE
Evidence retrieval procedure
Applies Upcoming

2 Dec 2027

You produce Authority response runbook with named owner

Art. 22(1) Authorised representative for third-country providers

Before making a high-risk system available on the Union market, providers established in third countries appoint, by written mandate, an authorised representative established in the Union, who verifies and keeps the conformity documentation and cooperates with the authorities.

High-risk ProviderAuthorised rep

EU Art. 22(1) EU Art. 113(c)(i)

You produce
CTO
Written mandate for the authorised representative
Applies Upcoming

2 Dec 2027

You produce Written mandate for the authorised representative

Art. 23 Importer obligations

Before placing a third-country provider's high-risk system on the Union market, importers verify that the conformity assessment was carried out, the technical documentation was drawn up, and the system bears the required marking and documentation, and they identify themselves on it.

High-risk Importer

EU Art. 23 EU Art. 113(c)(i)

You produce
CTO
Import verification record per system
Applies Upcoming

2 Dec 2027

You produce Import verification record per system

Art. 24 Distributor obligations

Before making a high-risk system available, distributors verify that it bears the CE marking and is accompanied by the EU declaration of conformity and instructions for use, and they hold it back or act when they consider it non-conformant.

High-risk Distributor

EU Art. 24 EU Art. 113(c)(i)

You produce
CTO
Distribution verification checklist
Applies Upcoming

2 Dec 2027

You produce Distribution verification checklist

Art. 25(1) Becoming the provider along the value chain

Any distributor, importer, deployer or other third party inherits the full provider obligations through three routes: putting their name or trademark on a high-risk system, substantially modifying one, or modifying the intended purpose of a system so that it becomes high-risk.

High-risk DistributorImporterDeployer

EU Art. 25(1) EU Regulation (EU) 2026/1744 EU Art. 113(c)(i)

You produce
CTO
Value-chain role assessment per system
Product
Repurposing check in launch review
Applies Upcoming

2 Dec 2027

You produce Value-chain role assessment per system

Art. 26 Deployer obligations

Deployers of high-risk systems use them per the instructions for use, assign competent human oversight, ensure relevant and representative input data where they control it, monitor operation, keep the logs under their control, and inform affected workers before workplace use.

High-risk Deployer

EU Art. 26 EU Art. 113(c)(i)

You produce
Product
Deployment instructions record per system
DevOps / SRE
Deployer-side log retention
CTO
Named oversight roles Worker information notice
Applies Upcoming

2 Dec 2027

You produce Deployment instructions record per system

Art. 27 Fundamental rights impact assessment

Before first use of certain Annex III systems, deployers that are public bodies or private operators providing public services, and deployers using systems for creditworthiness or life and health insurance pricing, assess the impact on fundamental rights and notify the market surveillance authority.

High-risk Deployer emerging

EU Art. 27 EU Regulation (EU) 2026/1744 EU Art. 113(c)(i)

You produce
Product
Fundamental rights impact assessment
CTO
Scope determination on record
Applies Upcoming

2 Dec 2027

You produce Fundamental rights impact assessment

Art. 43 Conformity assessment

High-risk systems go through the applicable conformity assessment before market placement, by internal control or with a notified body depending on the case, and again after substantial modification. In practice it bites per system when the high-risk requirements start applying to that system's classification route.

High-risk Provider

EU Art. 43 EU Regulation (EU) 2026/1744 EU Art. 113

You produce
CTO
Conformity route decision per system
Applies In force

2 Aug 2026

You produce Conformity route decision per system

Art. 47(1) EU declaration of conformity and CE marking

The provider draws up a machine-readable, signed EU declaration of conformity per high-risk system, keeps it at the authorities' disposal for ten years, and affixes the CE marking, digitally for systems provided digitally. In practice these bite per system when the high-risk requirements reach its classification route.

High-risk Provider

EU Art. 47(1) EU Art. 48 EU Art. 113

You produce
CTO
EU declaration of conformity per system
Applies In force

2 Aug 2026

You produce EU declaration of conformity per system

Art. 49 Registration in the EU database

Providers register Annex III high-risk systems in the EU database before placing them on the market or into service, and public-authority deployers register their use. Providers who conclude a system is not high-risk under Article 6(3) document and register that too.

High-risk ProviderDeployerAuthorised rep

EU Art. 49 EU Art. 113

You produce
CTO
Registration entries per system
Applies In force

2 Aug 2026

You produce Registration entries per system

Art. 50(3) and (4) Deployer disclosure: emotion recognition and deep fakes

Deployers of emotion recognition or biometric categorisation systems inform the people exposed to them. Deployers of systems that generate or manipulate deep-fake image, audio or video disclose that the content has been artificially generated or manipulated.

Transparency Deployer

EU Art. 50(3) and (4)

You produce
Product
Exposure disclosure flow per affected surface
Developer
Deep-fake disclosure label in the content pipeline
Applies In force

2 Aug 2026

You produce Exposure disclosure flow per affected surface

Art. 50(1) Disclosing interaction with an AI system

Systems intended to interact directly with people are designed so those people are informed they are dealing with an AI system, unless that is obvious to a reasonably informed person from the context.

Transparency Provider

EU Art. 50(1)

You produce
Product
Disclosure pattern in the design system
Developer
Reusable disclosure component
Applies In force

2 Aug 2026

You produce Disclosure pattern in the design system

Art. 50(2) Machine-readable marking of synthetic content

Generative systems mark audio, image, video and text output in a machine-readable format, detectable as artificially generated or manipulated, with solutions as effective, interoperable, robust and reliable as technically feasible. The 2026 amendment extended the duty to generative systems placed on the market before the general date, on a transition period.

Transparency Provider

EU Art. 50(2) EU Regulation (EU) 2026/1744

You produce
Developer
Content marking in the generation pipeline
DevOps / SRE
Provenance-preservation test in CI
Applies In force

2 Aug 2026

You produce Content marking in the generation pipeline

Art. 53(1) General-purpose AI provider duties

Providers of general-purpose models keep model documentation current, give downstream providers the information they need to comply, put a copyright policy in place, and publish a sufficiently detailed summary of training content.

General-purpose AI Provider

EU Art. 53(1) EU Commission guidelines on GPAI obligations Commission interpretation

You produce
Developer
Model documentation Downstream information pack Public training-content summary
CTO
Provider-status assessment for fine-tunes
Applies In force

2 Aug 2025

You produce Downstream information pack

Art. 54(1) Authorised representative for GPAI model providers

Before placing a general-purpose AI model on the Union market, providers established in third countries appoint, by written mandate, an authorised representative established in the Union to keep the model documentation and cooperate with the AI Office and the authorities.

General-purpose AI ProviderAuthorised rep

EU Art. 54(1)

You produce
CTO
Written mandate for the model's authorised representative
Applies In force

2 Aug 2025

You produce Written mandate for the model's authorised representative

Art. 55 Systemic-risk model obligations

Providers of general-purpose models with systemic risk additionally run state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and protect the model with adequate cybersecurity. The presumption threshold is training compute above 10²⁵ floating-point operations.

General-purpose AI Provider emerging

EU Art. 55 EU Art. 51(2) EU GPAI Code of Practice

You produce
DevOps / SRE
Evaluation program with adversarial testing Model-weight security controls
CTO
Training-compute accounting
Developer
Documented adversarial test runs for the model
Applies In force

2 Aug 2025

You produce Evaluation program with adversarial testing

Art. 60 Real-world testing outside sandboxes

Providers or prospective providers may test Annex III high-risk systems in real-world conditions outside a regulatory sandbox, once the market surveillance authority has approved a real-world testing plan, tacitly if it does not answer within 30 days, the test is registered in the EU database, and the subjects have given freely-given informed consent under Article 61.

High-risk Provider

EU Art. 60 EU Art. 61 EU Regulation (EU) 2026/1744 EU Art. 113

You produce
Product
Real-world testing plan Informed-consent flow for test subjects
CTO
Testing-regime scope determination
DevOps / SRE
Test monitoring with a halt path Prompt-recall procedure
Applies In force

2 Aug 2026

You produce Informed-consent flow for test subjects

Art. 72 Post-market monitoring

Providers run a documented post-market monitoring system proportionate to the system's risks: actively collecting and analyzing performance data from the field across the system's lifetime, feeding continuous compliance evaluation. The 2026 amendment scheduled Commission guidance and a voluntary plan template.

High-risk Provider

EU Art. 72 EU Regulation (EU) 2026/1744

You produce
DevOps / SRE
Post-market monitoring plan Versioned field telemetry
Product
Field-data review cadence
Applies In force

2 Aug 2026

You produce Post-market monitoring plan

Art. 73 Serious incident reporting

Serious incidents go to the market surveillance authority of the Member State where they occurred, immediately after a causal link is established or reasonably likely, and no later than 15 days after awareness, with shorter clocks for widespread infringements and deaths. Meeting the clock depends on detection and on reconstructing what happened fast.

High-risk ProviderDeployer

EU Art. 73 EU Draft Art. 73 reporting guidance DraftCommission interpretation

You produce
DevOps / SRE
Incident classification with regulatory branch Authority notification runbook
CTO
Named reporting roles
Applies In force

2 Aug 2026

You produce Authority notification runbook

Art. 86 Right to explanation of individual decisions

People subject to a decision taken by a deployer on the basis of output from certain Annex III high-risk systems, with legal or similarly significant adverse effects, can obtain from the deployer a clear and meaningful explanation of the system's role in the procedure and the main elements of the decision.

High-risk Deployer contested

EU Art. 86 EU CJEU C-634/21 (SCHUFA) EU CJEU C-203/22 (Dun & Bradstreet)

You produce
Product
Explanation request process
Developer
Decision factors captured per output
Applies In force

2 Aug 2026

You produce Explanation request process