Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.
A deployer that generates or manipulates image, audio or video content that is a deep fake must disclose that the content has been artificially generated or manipulated, with lighter treatment for evidently artistic, creative, satirical or fictional works so that the disclosure does not spoil the work. A deployer that publishes AI-generated text to inform the public on matters of public interest must disclose this unless the text passed human review or editorial control and someone holds editorial responsibility. The disclosure must reach people clearly at the latest at first exposure.
A person affected by a decision that a deployer took on the basis of the output of an Annex III high-risk AI system, other than critical-infrastructure systems, which produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety or fundamental rights, has the right to obtain from the deployer clear and meaningful explanations of the role the system played in the decision and the main elements of the decision. The right does not apply where Union or national law provides an exception.
A deployer must make available on its website, or in another public way, a clear and readily available statement summarising the types of high-risk AI systems it currently deploys, how it manages known or reasonably foreseeable risks of algorithmic discrimination from those systems, and the nature, source and extent of the information it collects and uses. The statement must be updated periodically.
Deployers of Annex III high-risk AI systems that take decisions about natural persons, or help take them, must inform those persons that they are subject to the system. The notice is separate from any explanation owed under Article 86 and from the worker notice in Article 26(7). In law-enforcement contexts the duty follows the information rules of the Law Enforcement Directive.
A deployer of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it that the system is operating and must process their personal data in line with the GDPR, the Law Enforcement Directive and the EU institutions data protection regulation. Systems permitted by law to detect, prevent or investigate criminal offences are excepted, subject to safeguards. Use in workplaces and schools is separately banned by Article 5 except for medical or safety reasons.
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
After an adverse consequential decision, the deployer must tell the consumer that automated decision-making technology was used, give the principal reasons for the decision, and explain how to obtain human review.
Candidates and employees who reside in New York City must be told, at least ten business days before an automated employment decision tool is used to assess them, that such a tool will be used in the hiring or promotion decision, and which job qualifications and characteristics the tool will assess. The DCWP rules allow the notice to be given on the careers page, in the job posting, or by mail or email, and require that it reach the person before the tool is applied.
Before using an automated employment decision tool, the employer or employment agency must make a summary of the most recent bias audit results and the distribution date of the tool publicly available on the employment section of its website. Under the DCWP rules the summary states the audit date, the data source and type, the number of applicants or candidates in each category, and the selection or scoring rates and impact ratios, and must remain posted for at least six months after the tool was last used.
Before putting a high-risk AI system into service or using it at the workplace, a deployer that is an employer must tell the workers' representatives and the affected workers that they will be subject to the system. The information is given following the procedures and rules on informing workers and their representatives under Union and national law and practice, which may include works-council consultation.
California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)
Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its website describing the model, its intended uses and restrictions, the release date and modalities, and how to contact the developer. A large frontier developer must add a summary of its catastrophic-risk assessment for the model, the results, any third-party evaluators involved and the steps taken under its frontier AI framework, with trade-secret and security redactions explained.
A governmental agency that makes an AI system available to interact with consumers must disclose to each consumer, before or at the time of the interaction, that they are interacting with an AI system. The disclosure is owed even where the AI nature of the interaction would be obvious, must be clear and conspicuous, written in plain language and may not use a dark pattern; a hyperlink to the disclosure is acceptable for online services.
A person who provides health-care services or treatment and uses an AI system in relation to those services must disclose that use to the patient, or to the patient's personal representative or guardian, no later than the date the service or treatment is first provided, with an exception for emergencies where the disclosure is made as soon as reasonably possible. The disclosure must be clear, conspicuous and in plain language.
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Deployers must tell a consumer, before the decision is made, that automated decision-making technology will be used to make or materially influence a consequential decision about them. The exact content and timing of the notice follow the enrolled bill, which a reviewer must read.
Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.
Operators of high-impact AI must put in place measures to explain the AI's final results, the main criteria used to reach them, and an overview of the training data, to the extent that this is technically feasible. The duty targets explainability of the system's decisions to users and affected people rather than full disclosure of the model.
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as the state of the art allows, taking account of content type and cost. Systems that only perform assistive editing or do not substantially alter the input, and law-authorised criminal-detection uses, are outside the duty.
A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must set out, in a written agreement, the information, capabilities, technical access and other assistance needed for the provider to meet its obligations, based on the generally acknowledged state of the art. Suppliers of free and open-source tools and components other than general-purpose AI models are outside this duty. The AI Office may publish voluntary model terms.
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Covers data lineage and quality, minimising bias in datasets, model explainability, repeatability, robustness, regular tuning and active monitoring after deployment.
The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.
Source-linked
Voluntary guidancegovernance accountability·United States
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.