AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

31 results · page 1 of 2

Legal requirement accuracy robustness security European Union

Achieve appropriate accuracy, robustness and cybersecurity

EU AI Act · Article 15

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Source-linked Applies from 2 Aug 2026
Legal requirement data governance European Union

Apply data governance and quality criteria to training, validation and testing data

EU AI Act · Article 10

High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.

Source-linked Applies from 2 Aug 2026
Legal requirement governance accountability European Union

Use high-risk AI as instructed, monitor it and inform affected people

EU AI Act · Article 26

Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.

Source-linked Applies from 2 Aug 2026
Legal requirement human oversight United Kingdom

Apply safeguards to solely automated decisions with significant effects

ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025

Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.

Source-linked
Legal requirement human oversight European Union

Enable and assign effective human oversight

EU AI Act · Article 14; Article 26(2) for deployers

High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.

Source-linked Applies from 2 Aug 2026
Legal requirement impact assessment European Union

Carry out a fundamental rights impact assessment before deployment

EU AI Act · Article 27

Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.

Source-linked Applies from 2 Aug 2026
Legal requirement impact assessment Colorado (United States)

Deployers must complete impact assessments for high-risk AI

Colorado AI Act · C.R.S. 6-1-1703(3)

Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.

Source-linked Applies from 30 Jun 2026
Legal requirement post market monitoring European Union

Operate a post-market monitoring system

EU AI Act · Article 72

Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.

Source-linked Applies from 2 Aug 2026
Legal requirement privacy data protection Nepal

Collect and use personal information only with consent and for the stated purpose

Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)

Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other purposes without consent, subject to statutory exceptions. AI systems trained on or processing personal data of people in Nepal must respect these limits.

Source-linked
Legal requirement privacy data protection Singapore

Identify consent or an applicable PDPA exception before using personal data in AI

PDPC AI advisory guidelines · Advisory guidelines, sections on consent, business improvement and research exceptions

Personal data used to train or operate AI systems requires consent unless an exception applies, such as the business improvement exception for improving products and services or the research exception for developing models, each subject to conditions.

Source-linked
Legal requirement quality management European Union

Operate a quality management system

EU AI Act · Article 17

Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.

Source-linked Applies from 2 Aug 2026
Legal requirement record keeping European Union

Design high-risk systems to log events automatically

EU AI Act · Article 12; Article 26(6) for deployers

High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.

Source-linked Applies from 2 Aug 2026
Legal requirement risk management Colorado (United States)

Deployers must implement a risk management policy and programme

Colorado AI Act · C.R.S. 6-1-1703(2)

Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.

Source-linked Applies from 30 Jun 2026
Legal requirement risk management European Union

Establish a risk management system for high-risk AI

EU AI Act · Article 9

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Source-linked Applies from 2 Aug 2026
Legal requirement technical documentation Colorado (United States)

Developers must document high-risk systems and disclose known risks

Colorado AI Act · C.R.S. 6-1-1702

Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.

Source-linked Applies from 30 Jun 2026
Legal requirement technical documentation European Union

Draw up technical documentation before placing a high-risk system on the market

EU AI Act · Article 11 and Annex IV

Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.

Source-linked Applies from 2 Aug 2026
Legal requirement transparency Colorado (United States)

Notify consumers and explain adverse consequential decisions

Colorado AI Act · C.R.S. 6-1-1703(4)

Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.

Source-linked Applies from 30 Jun 2026
Legal requirement transparency European Union

Provide deployers with clear instructions for use

EU AI Act · Article 13

High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.

Source-linked Applies from 2 Aug 2026
Search