AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

10 results

Legal requirement accuracy robustness security European Union

Achieve appropriate accuracy, robustness and cybersecurity

EU AI Act · Article 15

High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.

Source-linked Applies from 2 Aug 2026
Legal requirement conformity assessment European Union

Complete conformity assessment, CE marking and EU database registration

EU AI Act · Articles 43, 47, 48 and 49; Annex VIII

Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.

Source-linked Applies from 2 Aug 2026
Legal requirement incident handling European Union

Report serious incidents to market surveillance authorities

EU AI Act · Article 73

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Source-linked Applies from 2 Aug 2026
Legal requirement post market monitoring European Union

Operate a post-market monitoring system

EU AI Act · Article 72

Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.

Source-linked Applies from 2 Aug 2026
Legal requirement quality management European Union

Operate a quality management system

EU AI Act · Article 17

Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.

Source-linked Applies from 2 Aug 2026
Legal requirement risk management European Union

Establish a risk management system for high-risk AI

EU AI Act · Article 9

Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.

Source-linked Applies from 2 Aug 2026
Legal requirement technical documentation European Union

Draw up technical documentation before placing a high-risk system on the market

EU AI Act · Article 11 and Annex IV

Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.

Source-linked Applies from 2 Aug 2026
Legal requirement vendor governance European Union

Verify conformity before importing or distributing high-risk AI

EU AI Act · Articles 23 and 24

Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.

Source-linked Applies from 2 Aug 2026
Search