AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

11 results

Legal requirement accuracy robustness security European Union

Achieve appropriate accuracy, robustness and cybersecurity

EU AI Act · Article 15

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Source-linked Applies from 2 Aug 2026
Legal requirement conformity assessment European Union

Complete conformity assessment, CE marking and EU database registration

EU AI Act · Articles 43, 47, 48 and 49; Annex VIII

Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.

Source-linked Applies from 2 Aug 2026
Legal requirement data governance European Union

Apply data governance and quality criteria to training, validation and testing data

EU AI Act · Article 10

High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.

Source-linked Applies from 2 Aug 2026
Legal requirement human oversight European Union

Enable and assign effective human oversight

EU AI Act · Article 14; Article 26(2) for deployers

High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.

Source-linked Applies from 2 Aug 2026
Legal requirement incident handling European Union

Report serious incidents to market surveillance authorities

EU AI Act · Article 73

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Source-linked Applies from 2 Aug 2026
Legal requirement privacy data protection Nepal

Collect and use personal information only with consent and for the stated purpose

Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)

Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other purposes without consent, subject to statutory exceptions. AI systems trained on or processing personal data of people in Nepal must respect these limits.

Source-linked
Legal requirement prohibited practice European Union

Do not deploy or provide AI for prohibited practices

EU AI Act · Article 5

Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.

Source-linked Applies from 2 Feb 2025
Legal requirement record keeping European Union

Design high-risk systems to log events automatically

EU AI Act · Article 12; Article 26(6) for deployers

High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.

Source-linked Applies from 2 Aug 2026
Search