Legal requirement
accuracy robustness security
·
European Union
EU AI Act · Article 15
High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.
Source-linked
Applies from 2 Aug 2026
Legal requirement
ai literacy
·
European Union
EU AI Act · Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Source-linked
Applies from 2 Feb 2025
Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked
Applies from 2 Aug 2026
Legal requirement
copyright training data
·
European Union
EU AI Act · Article 53 and Annexes XI–XII
Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.
Source-linked
Applies from 2 Aug 2025
Legal requirement
data governance
·
European Union
EU AI Act · Article 10
High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.
Source-linked
Applies from 2 Aug 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
European Union
EU AI Act · Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
incident handling
·
European Union
EU AI Act · Article 73
Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.
Source-linked
Applies from 2 Aug 2026
Legal requirement
post market monitoring
·
European Union
EU AI Act · Article 72
Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.
Source-linked
Applies from 2 Aug 2026
Legal requirement
prohibited practice
·
European Union
EU AI Act · Article 5
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Source-linked
Applies from 2 Feb 2025
Legal requirement
quality management
·
European Union
EU AI Act · Article 17
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Source-linked
Applies from 2 Aug 2026
Legal requirement
record keeping
·
European Union
EU AI Act · Article 12; Article 26(6) for deployers
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Source-linked
Applies from 2 Aug 2026
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked
Applies from 2 Aug 2026
Legal requirement
safety testing
·
European Union
EU AI Act · Articles 51, 52 and 55
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Source-linked
Applies from 2 Aug 2025
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 13
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Source-linked
Applies from 2 Aug 2026
Legal requirement
vendor governance
·
European Union
EU AI Act · Articles 23 and 24
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Source-linked
Applies from 2 Aug 2026