Legal requirement
accuracy robustness security
·
European Union
EU AI Act · Article 15
High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.
Source-linked
Applies from 2 Aug 2026
Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked
Applies from 2 Aug 2026
Legal requirement
incident handling
·
European Union
EU AI Act · Article 73
Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.
Source-linked
Applies from 2 Aug 2026
Legal requirement
post market monitoring
·
European Union
EU AI Act · Article 72
Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.
Source-linked
Applies from 2 Aug 2026
Legal requirement
quality management
·
European Union
EU AI Act · Article 17
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Source-linked
Applies from 2 Aug 2026
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked
Applies from 2 Aug 2026
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked
Applies from 2 Aug 2026
Legal requirement
vendor governance
·
European Union
EU AI Act · Articles 23 and 24
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Source-linked
Applies from 2 Aug 2026
Voluntary guidance
risk management
·
United Kingdom
UK AI regulation framework · Principle 1, Part 3
Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.
Source-linked
Voluntary guidance
safety testing
·
United States
NIST AI RMF · MEASURE function
Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.
Source-linked