AIPolicyTracker

AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

117 results · page 3 of 5

Results

Legal requirement public sector use United States

Federal agencies must review and revise actions inconsistent with the new AI policy

EO 14179 · Section 5

Agency heads were directed to identify actions taken under Executive Order 14110 that are inconsistent with the policy of EO 14179 and to suspend, revise or rescind them, and OMB was directed to revise its federal AI use and procurement memoranda.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement public sector use European Union

Public authorities must register their use of high-risk AI and must not use unregistered systems

EU AI Act · Article 26(8); Article 49(3) and 49(4)

Deployers that are public authorities or Union institutions, bodies, offices or agencies must register their use of an Annex III high-risk AI system in the EU database before putting it into service. If they find that the system they intend to use has not been registered in the database by its provider, they must not use it and must inform the provider or distributor.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement quality management European Union

Operate a quality management system

EU AI Act · Article 17

Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement record keeping European Union

Design high-risk systems to log events automatically

EU AI Act · Article 12; Article 26(6) for deployers

High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement record keeping European Union

Providers must keep high-risk AI documentation for ten years

EU AI Act · Article 18

For ten years after a high-risk AI system is placed on the market or put into service, the provider must keep at the disposal of national competent authorities the technical documentation, the quality management system documentation, any changes approved by a notified body, the notified body's decisions and other documents, and the EU declaration of conformity. Financial institutions keep these as part of their sector record-keeping.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement record keeping European Union

Providers must retain automatically generated logs under their control

EU AI Act · Article 19

Providers must keep the event logs that a high-risk AI system generates under Article 12, to the extent those logs are within their control, for a period appropriate to the system's intended purpose and in any case for at least six months, unless Union or national law on personal data sets a different period. Financial institutions keep the logs under their sector rules.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement risk management United States

Apply minimum risk-management practices to high-impact AI

OMB M-25-21 · Section 4

For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement risk management Colorado (United States)

Deployers must implement a risk management policy and programme

Colorado AI Act · C.R.S. 6-1-1703(2)

Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement risk management Colorado (United States)

Deployers must use reasonable care to avoid algorithmic discrimination

Colorado AI Act · C.R.S. 6-1-1703(1)

A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A deployer that runs the required risk-management programme, completes impact assessments, gives consumer notices and makes the required disclosures benefits from a rebuttable presumption of reasonable care; some deployers with fewer than 50 employees are relieved of parts of the programme and assessment duties when they rely on the developer's impact assessment.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement risk management Colorado (United States)

Developers must use reasonable care to avoid algorithmic discrimination

Colorado AI Act · C.R.S. 6-1-1702(1)

A developer of a high-risk AI system must use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination arising from the intended and contracted uses of the system. A developer that meets the documentation, public-statement and Attorney General disclosure duties in the rest of section 6-1-1702 benefits from a rebuttable presumption that it used reasonable care.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement risk management European Union

Establish a risk management system for high-risk AI

EU AI Act · Article 9

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement risk management South Korea

Operators of high-impact AI must establish and operate a risk management plan

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)

An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. High-impact AI is AI used in areas such as energy, drinking water, health care and medical devices, nuclear safety, biometric analysis for criminal investigation, decisions on recruitment or loans, transport, public services and education, where it may materially affect life, safety or fundamental rights.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement safety testing California (United States)

Large frontier developers must publish a frontier AI framework

California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)

Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, apply mitigations, secure model weights, and govern internal processes, and must review it at least annually.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement safety testing California (United States)

Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state

California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)

A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment of catastrophic risk that results from the internal use of its frontier models. This covers risks arising before public deployment, such as during internal evaluation or use of the model to accelerate research, and complements the public transparency report.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement safety testing European Union

Manage systemic risk for high-impact general-purpose models

EU AI Act · Articles 51, 52 and 55

A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement safety testing South Korea

Operators of AI above the compute threshold must run lifecycle risk management and report safety results

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 32

An AI business operator whose AI system's cumulative training computation exceeds the threshold set by Presidential Decree must identify, assess and mitigate risks across the system's life cycle, build a risk management system to monitor and respond to safety incidents caused by the AI, and submit the results of these measures to the Minister of Science and ICT. The threshold and reporting form are set in the Decree.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement technical documentation Colorado (United States)

Developers must document high-risk systems and disclose known risks

Colorado AI Act · C.R.S. 6-1-1702

Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement technical documentation European Union

Draw up technical documentation before placing a high-risk system on the market

EU AI Act · Article 11 and Annex IV

Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement technical documentation European Union

Providers must document and register a conclusion that an Annex III system is not high-risk

EU AI Act · Article 6(4); Article 49(2)

A provider that considers a system listed in Annex III to be outside the high-risk tier because it meets one of the Article 6(3) conditions, such as performing a narrow procedural task or only preparing a human assessment, must write down that assessment before placing the system on the market or putting it into service, register the system in the EU database under Article 49(2), and hand over the assessment on request from a national competent authority.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement technical documentation European Union

Providers of GPAI models must maintain technical documentation and inform downstream providers

EU AI Act · Article 53(1)(a) and 53(1)(b); Annexes XI and XII

Providers of general-purpose AI models must draw up and keep up to date technical documentation covering the training and testing process and evaluation results, as set in Annex XI, and supply it to the AI Office or national authorities on request. They must also keep current the Annex XII information for providers that integrate the model into their own AI systems, so those providers understand its capabilities and limitations and can meet their own duties. Free and open-source models without systemic risk are exempt from both duties.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement transparency South Korea

AI business operators must label generative AI output and clearly flag realistic synthetic media

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(2) and 31(3)

An AI business operator that provides generative AI or a product or service using it must indicate that the output was generated by generative AI. Where the operator provides content such as virtual sound, images or video that is hard to distinguish from reality, it must clearly notify users that the content is AI-generated, in a manner that does not impair a work's artistic or creative expression where that applies. Detailed methods are left to Presidential Decree and ministry guidance.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement transparency South Korea

AI business operators must notify users in advance that a product or service runs on high-impact or generative AI

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(1)

An AI business operator that provides a product or service operated by high-impact AI or by generative AI must notify users in advance that the product or service is based on such AI. The notice is owed before use and is the entry point of the Act's transparency chapter; failure to give it can attract an administrative fine after a corrective order.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement transparency Colorado (United States)

Deployers and developers must disclose to consumers that they are interacting with an AI system

Colorado AI Act · C.R.S. 6-1-1704

Any developer or deployer that makes an AI system available to consumers that is intended to interact with them must disclose to each consumer that they are interacting with an AI system, unless that would be obvious to a reasonable person. This duty is not limited to high-risk systems and covers chatbots and voice agents offered to Colorado consumers.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Search

Frequently asked questions

What is an obligation on this site?
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.