EU AI Act obligations
The 54 operator duties the compliance engine scores against — each one with the article it comes from, the roles it binds, and the artifact that discharges it. These pages are derived from the engine’s own table rather than written alongside it, so they say exactly what the product would tell you.
Read against Regulation (EU) 2024/1689 as amended, consolidated text 02024R1689-20260727 (consolidation 001.001, incorporating Regulation (EU) 2026/1744).
- criticalAnnex IV §3Annex IV §3 Training data / methodology
- criticalAnnex IV §5Annex IV §5 Risk management measures
- criticalAnnex IV §8Annex IV §8 Cybersecurity measures
- criticalArt.10, Annex IV §3Data and data governance
- criticalArt.11, Annex IVTechnical documentation
- criticalArt.14Human oversight
- criticalArt.15Accuracy, robustness and cybersecurity
- criticalArt.16Obligations of providers of high-risk AI systems
- criticalArt.17Quality management system
- criticalArt.26Obligations of deployers of high-risk AI systems
- criticalArt.26(5), Art.73Reporting serious incidents by deployers
- criticalArt.27Fundamental rights impact assessment (FRIA) for deployers
- criticalArt.5(1)(a)Prohibited: subliminal / manipulative techniques (material harm)
- criticalArt.5(1)(b)Prohibited: exploitation of vulnerabilities
- criticalArt.5(1)(c)Prohibited: social scoring — evaluating or classifying people over time by social behaviour or personal characteristics, where the score causes detrimental treatment in an unrelated context or is disproportionate. Binds private actors as well as public ones
- criticalArt.5(1)(d)Prohibited: predicting the risk that a person will commit a criminal offence, based solely on profiling or on assessing personality traits — does not cover systems supporting a human assessment already grounded in objective, verifiable facts
- criticalArt.5(1)(e)Prohibited: creating or expanding facial recognition databases by untargeted scraping of facial images from the internet or CCTV footage
- criticalArt.5(1)(f)Prohibited: inferring emotions of a person in the workplace or in education institutions — except where the system is intended for medical or safety reasons
- criticalArt.5(1)(g)Prohibited: biometric categorisation deducing race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation — does not cover labelling or filtering of lawfully acquired biometric datasets, or categorisation of biometric data in law enforcement
- criticalArt.5(1)(h)Prohibited: real-time remote biometric identification in publicly accessible spaces for law enforcement — unless strictly necessary for one of the narrow listed objectives, and subject to the Art.5(2)-(4) authorisation regime
- criticalArt.5(1)(bb), Art.5(1a)Prohibited: AI producing child sexual abuse material (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
- criticalArt.5(1)(ba), Art.5(1a)Prohibited: AI generating or manipulating non-consensual intimate imagery of identifiable people (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
- criticalArt.53Obligations for providers of general-purpose AI models
- criticalArt.73Serious incident reporting
- criticalArt.9, Annex IVRisk management system throughout the lifecycle
- majorAnnex IV §1Annex IV §1 General description of the AI system
- majorAnnex IV §2Annex IV §2 System architecture / logical interactions
- majorAnnex IV §4Annex IV §4 Performance metrics / robustness
- majorAnnex IV §6Annex IV §6 Lifecycle changes / versions
- majorAnnex IV §9Annex IV §9 Operational design domain / context of use
- majorArt.4a(1)Special-category data processed for bias detection in a high-risk system — strict necessity, pseudonymisation, access control, no onward transfer, deletion once corrected
- majorArt.12Record-keeping / logging
- majorArt.13Transparency and provision of information to deployers (high-risk)
- majorArt.18Documentation keeping (provider retention, 10 years)
- majorArt.19Automatically generated logs (provider retention)
- majorArt.20Corrective actions and duty of information
- majorArt.22Obligations of authorized representatives
- majorArt.23Obligations of importers
- majorArt.24Obligations of distributors
- majorArt.25Responsibilities along the value chain
- majorArt.26(5)Monitoring high-risk AI systems operated by deployers
- majorArt.4Measures to support AI literacy among staff and operators (applies to ALL AI systems)
- majorArt.43Conformity assessment — notified body involvement (high-risk)
- majorArt.47EU declaration of conformity
- majorArt.49, Art.71Registration of high-risk AI systems in the EU database — timing unsettled: Art.49 sits in Chapter III Section 5, which the Omnibus did NOT defer, but the Commission states the Annex III rules apply from 2 Dec 2027, and the database is not yet reachable
- majorArt.49(3)EU database registration — deployer duties where applicable. Timing unsettled: Art.49 was not among the provisions the Omnibus deferred, yet the Commission states the Annex III rules apply from 2 Dec 2027 and the database is not yet reachable
- majorArt.4a(2)Special-category data processed for bias detection outside the high-risk provider case — deployers of high-risk systems, and providers and deployers of other AI systems and models
- majorArt.50Transparency: tell people they are dealing with AI, mark synthetic content, and disclose deepfakes and emotion recognition
- majorArt.72Post-market monitoring
- minorAnnex IV §7Annex IV §7 Standards / specifications applied
- minorArt.21Cooperation with competent authorities
- minorArt.40(2)Conformity presumed via harmonised standards — the Commission must now seek unified standards covering the AI Act and sectoral law together
- minorArt.54Authorised representative of general-purpose AI model provider (third country)
- minorArt.74Cooperation with market surveillance authorities