AIPolicyTracker

AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

117 results · page 1 of 5

Results

Legal requirement accuracy robustness security European Union

Achieve appropriate accuracy, robustness and cybersecurity

EU AI Act · Article 15

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement accuracy robustness security New York (United States)

Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool

NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(1); 6 RCNY Section 5-301

An automated employment decision tool may not be used to screen candidates or employees for hiring or promotion in New York City unless it has been the subject of a bias audit by an independent auditor within the year before use. The audit calculates selection rates and impact ratios by sex, race/ethnicity and their intersections, and scoring-rate comparisons for tools that score rather than select, using the employer's historical data or, where insufficient, test data as the DCWP rules allow.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 5 Jul 2023
Legal requirement accuracy robustness security European Union

Providers of systemic-risk GPAI models must secure the model and its infrastructure

EU AI Act · Article 55(1)(d)

Providers of general-purpose AI models with systemic risk must ensure an adequate level of cybersecurity protection for the model and for the physical infrastructure it runs on, which in practice covers protection of model weights, training and inference environments, and access controls against theft, tampering and unauthorised release. Codes of practice and harmonised standards may be used to show compliance.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement ai literacy European Union

Ensure AI literacy of staff operating AI systems

EU AI Act · Article 4

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Feb 2025
Legal requirement conformity assessment European Union

Complete conformity assessment, CE marking and EU database registration

EU AI Act · Articles 43, 47, 48 and 49; Annex VIII

Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement copyright training data European Union

Meet general-purpose AI model provider obligations

EU AI Act · Article 53 and Annexes XI–XII

Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement data governance European Union

Apply data governance and quality criteria to training, validation and testing data

EU AI Act · Article 10

High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement data governance European Union

Deployers must ensure input data they control is relevant and representative

EU AI Act · Article 26(4)

To the extent a deployer controls the data fed into a high-risk AI system, it must make sure that input data is relevant to, and sufficiently representative for, the system's intended purpose. The duty sits with the deployer even though the provider designed the system, because the deployer chooses what the system is run on.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability European Union

Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI

EU AI Act · Article 25(1) and 25(2)

A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name or trademark on a system already on the market, makes a substantial modification to a high-risk system that stays high-risk, or changes the intended purpose of a system so that it becomes high-risk. The original provider then ceases to be provider for that system but must cooperate and supply the information and access needed for the new provider to comply.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability South Korea

Foreign AI business operators above the threshold must designate a domestic representative in Korea

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 36

An AI business operator without an address or place of business in Korea, whose user numbers or revenue meet the thresholds set by Presidential Decree, must designate in writing a domestic representative with an address in Korea. The representative handles the operator's duties under the Act, including submitting the Article 32 safety results, supporting high-impact AI confirmation and cooperating with fact-finding investigations, and the operator is treated as responsible for the representative's acts.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement governance accountability California (United States)

Frontier developers must protect employees who report catastrophic-risk concerns

California SB 53 · Labor Code Section 1107 (as added by SB 53)

A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal authority, a manager or another employee with authority that the developer's activities pose a specific and substantial danger to public health or safety from catastrophic risk, or that it has violated the Act. Covered employees must be given clear notice of these rights, and large frontier developers must run an anonymous internal reporting process with regular updates to the reporter and to officers and directors.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement governance accountability European Union

Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually

EU AI Act · Article 26(10)

A deployer using a high-risk post-remote biometric identification system in a criminal investigation must request authorisation from a judicial or independent administrative authority in advance or within 48 hours, unless the use is only the initial identification of a potential suspect on objective and verifiable facts. Use is limited to a targeted search; if authorisation is refused, use stops and the data is deleted. No adverse legal decision may rest solely on the output, each use is documented, and the deployer reports annually to the market surveillance and data protection authorities.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability European Union

Non-EU providers must appoint an EU authorised representative for high-risk AI

EU AI Act · Article 22

Before making a high-risk AI system available in the Union, a provider established outside the EU must appoint, by written mandate, an authorised representative established in the Union. The representative verifies that the EU declaration of conformity and technical documentation exist and that conformity assessment was done, keeps the provider's contact details and the documentation available for ten years, supplies information to authorities, cooperates with them, and must end the mandate if the provider acts contrary to the Regulation.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability European Union

Non-EU providers of GPAI models must appoint an EU authorised representative

EU AI Act · Article 54

Before placing a general-purpose AI model on the Union market, a provider established in a third country must appoint, by written mandate, an authorised representative established in the Union. The representative checks that the Annex XI documentation exists and the Article 53 duties are met, keeps a copy of the documentation and the provider's contact details for ten years after market placement, provides information to the AI Office on request, cooperates with authorities, and must end the mandate if the provider breaches the Regulation. Open-source models without systemic risk are exempt.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement governance accountability South Korea

Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)

Operators of high-impact AI must prepare and implement a plan to protect users, and must prepare and keep documents describing the measures they take to secure the AI's safety and reliability, so that they can be shown to the Ministry of Science and ICT on request. Further items may be added by Presidential Decree, and the ministry may publish guidelines on how to meet these duties.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement governance accountability European Union

Providers must meet the full set of provider duties for high-risk AI

EU AI Act · Article 16

Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its documentation, a quality management system, retention of documentation and logs, conformity assessment, an EU declaration of conformity, CE marking, registration, corrective action when needed, cooperation with authorities on request, and accessibility in line with the EU accessibility directives.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability European Union

Providers must supply conformity evidence and log access to authorities on request

EU AI Act · Article 21

On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show that the system meets the Section 2 requirements, in a language the authority can readily understand, and must give the authority access to the automatically generated logs it holds. Authorities must treat what they receive as confidential under Article 78.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement governance accountability European Union

Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold

EU AI Act · Article 52(1)

A provider whose general-purpose AI model meets the Article 51(1)(a) high-impact capability condition, which is presumed once cumulative training compute exceeds 10^25 floating-point operations, must notify the Commission without delay and in any event within two weeks of the condition being met or of learning that it will be met. The notification may include arguments that the model nonetheless does not present systemic risk; the Commission decides and keeps a public list of designated models.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement governance accountability European Union

Use high-risk AI as instructed, monitor it and inform affected people

EU AI Act · Article 26

Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement human oversight United Kingdom

Apply safeguards to solely automated decisions with significant effects

ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025

Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement human oversight New York (United States)

Employers and employment agencies must let candidates request an alternative selection process or accommodation

NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1); 6 RCNY Section 5-303

The advance notice to candidates and employees must allow them to request an alternative selection process or a reasonable accommodation. The DCWP rules make clear that the law itself does not require the employer to provide an alternative process, but the request route must exist and accommodation requests remain governed by disability and human-rights law. Instructions for making the request must be included in the notice.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 5 Jul 2023
Legal requirement human oversight European Union

Enable and assign effective human oversight

EU AI Act · Article 14; Article 26(2) for deployers

High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement human oversight South Korea

Operators of high-impact AI must ensure human management and supervision

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)

Operators of high-impact AI must ensure that the AI is subject to human management and supervision, so that people remain able to monitor its operation and intervene in or override its outputs where those outputs may affect life, physical safety or fundamental rights.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement human oversight United Arab Emirates

Respect the right to object to automated decision-making without human intervention

UAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)

Data subjects may object to decisions based solely on automated processing, including profiling, that produce legal or similarly serious effects, subject to exceptions such as contractual necessity or consent.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Search

Frequently asked questions

What is an obligation on this site?
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.