Skip to main content
Praxikon

Explorer

Why this object hangs off that object

Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.

Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.

This is the knowledge layer under the four levels of the assessment. See the four levels.

Filters

Only dimensions the data carries. A dimension without values is absent rather than empty.

Eleven types, including evidence, control and standard.

Is about this role. Walks the role hierarchy upward.

The duty rests on this role, not merely: it is about it.

The article route this object hangs off.

Free slugs, not a taxonomy with objects of its own.

The phase of the object, not its quality.

Whether this object carries a source line of its own.

Searches label, summary, topics, conditions and statement texts. The ordering is the same heuristic as the search API; build on the identifiers, not on the ranking.

Time

Two axes. Legal time is what applied; knowledge time is what we had published by then. Leaving them empty means the default of this release.

Clear all

Objects

150 of 573 shown. Pick a type below or narrow with a filter to see the rest.

  1. ActionUpcomingv1.0.02 relations

    Justify the Article 6(3) exception against each individual condition

    praxikon:eu:ai-act:action:annex-iii-article-6-3-justification

    Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | high-risk

  2. Actionv1.0.05 relations

    Classify the use case and document the outcome

    praxikon:eu:ai-act:action:annex-iii-classify

    Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | high-risk

  3. ActionUpcomingv1.0.02 relations

    Run the profiling test before invoking the Article 6(3) exception

    praxikon:eu:ai-act:action:annex-iii-profiling-test

    Establish as the first question whether the system performs profiling of natural persons; if yes, the Article 6(3) route falls away and the system remains high-risk, regardless of the four conditions.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | high-risk

  4. ActionUpcomingv1.0.03 relations

    Assign human oversight and give those people a mandate

    praxikon:eu:ai-act:action:appoint-and-empower-human-oversight

    Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.

    Hangs off: Article 26: obligations of deployers of high-risk AI systems

    Editorially reviewed | high-risk-requirements

  5. ActionApplicablev1.0.04 relations

    Appoint an authorised representative and record the mandate

    praxikon:eu:ai-act:action:appoint-gpai-authorised-representative

    Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.

    Hangs off: Article 54: authorised representative of a provider of a GPAI model

    Editorially reviewed | gpai, value-chain

  6. Actionv1.0.04 relations

    Set up data governance per dataset

    praxikon:eu:ai-act:action:article-10-data-governance-act

    Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.

    Hangs off: Article 10: data and data governance

    Editorially reviewed | high-risk-requirements

  7. Actionv1.0.03 relations

    Build the technical file per Annex IV

    praxikon:eu:ai-act:action:article-11-technical-documentation-act

    Document system description, development process, data, oversight measures, performance and risk management before market placement.

    Hangs off: Article 11: technical documentation

    Editorially reviewed | high-risk-requirements

  8. Actionv1.0.04 relations

    Design logging into the system

    praxikon:eu:ai-act:action:article-12-logging-act

    Ensure the system automatically records events relevant to risk identification and post-market monitoring.

    Hangs off: Article 12: logging and traceability

    Editorially reviewed | high-risk-requirements

  9. Actionv1.0.04 relations

    Provide complete instructions for use

    praxikon:eu:ai-act:action:article-13-instructions-act

    Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.

    Hangs off: Article 13: transparency towards deployers

    Editorially reviewed | high-risk-requirements

  10. Actionv1.0.04 relations

    Design and assign effective human oversight

    praxikon:eu:ai-act:action:article-14-human-oversight-act

    Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.

    Hangs off: Article 14: human oversight

    Editorially reviewed | high-risk-requirements

  11. Actionv1.0.03 relations

    Set and test performance and security levels

    praxikon:eu:ai-act:action:article-15-accuracy-robustness-act

    Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.

    Hangs off: Article 15: accuracy, robustness and cybersecurity

    Editorially reviewed | high-risk-requirements

  12. Actionv1.0.03 relations

    Set up an AI quality management system

    praxikon:eu:ai-act:action:article-17-quality-management-act

    Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.

    Hangs off: Article 17: quality management system

    Editorially reviewed | high-risk-requirements

  13. Actionv1.0.05 relations

    Take role- and context-specific AI literacy measures

    praxikon:eu:ai-act:action:article-4-measures

    Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy

  14. ActionApplicablev1.0.03 relations

    Determine per role which knowledge is needed to use the specific system responsibly

    praxikon:eu:ai-act:action:article-4-role-needs-matrix

    Map roles against the AI systems they use and record per combination what a person must be able to judge: what the system does, where it fails, who it is applied to, and when to intervene or escalate.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy

  15. ActionApplicablev1.0.03 relations

    Deliver instruction at the moment a new tool or a new employee arrives

    praxikon:eu:ai-act:action:article-4-tool-and-onboarding-instruction

    Attach the literacy measure to two fixed moments in existing processes: the rollout of a new AI tool and the onboarding of anyone gaining access to an existing tool.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy

  16. Actionv1.0.04 relations

    Screen every use case against Article 5 first

    praxikon:eu:ai-act:action:article-5-screen

    Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.

    Hangs off: Article 5: prohibited practices

    Editorially reviewed | prohibited-practices

  17. Actionv1.0.05 relations

    Implement the applicable disclosure, marking or label

    praxikon:eu:ai-act:action:article-50-disclosure

    First determine which paragraph of Article 50 applies, then implement the specific transparency measure.

    Hangs off: Article 50: transparency

    Editorially reviewed | transparency

  18. ActionApplicablev1.0.02 relations

    Record per publication channel when AI text carries a disclosure and who holds editorial responsibility

    praxikon:eu:ai-act:action:article-50-editorial-labelling-policy

    Determine per channel whether the text is published to inform the public on matters of public interest, who performs the human review, who holds editorial responsibility, and which standard wording you use when the disclosure is required.

    Hangs off: Article 50: transparency

    Editorially reviewed | transparency

  19. ActionApplicablev1.0.03 relations

    Test every system in your AI register against the five Article 50 scenarios

    praxikon:eu:ai-act:action:article-50-scenario-triage

    For each AI system, walk through the distinct Article 50 scenarios (direct interaction, synthetic output, emotion recognition or biometric categorisation, deep fake, published text on matters of public interest) and record per paragraph whether it applies, does not apply or falls under an exception, with the reason.

    Hangs off: Article 50: transparency

    Editorially reviewed | transparency

  20. Actionv1.0.03 relations

    Perform model evaluations and risk mitigation

    praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act

    Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.

    Hangs off: Article 55: GPAI models with systemic risk

    Editorially reviewed | gpai-systemic-risk

  21. ActionApplicablev1.0.04 relations

    Apply to a sandbox and agree the sandbox plan

    praxikon:eu:ai-act:action:article-57-sandbox-application-and-plan

    Apply to the competent authority, agree a specific sandbox plan, and record which uncertainty about the Regulation you want resolved inside the sandbox.

    Hangs off: Article 57: AI regulatory sandboxes

    Editorially reviewed | innovation

  22. ActionApplicablev1.0.05 relations

    Submit the testing plan, obtain approval and register the test

    praxikon:eu:ai-act:action:article-60-testing-plan-and-authorisation

    Draw up a real-world testing plan, submit it to the market surveillance authority, obtain approval, register the test with a Union-wide unique single identification number, and record the division of roles with your deployer.

    Hangs off: Article 60: testing in real world conditions outside a sandbox

    Editorially reviewed | innovation

  23. ActionApplicablev1.0.04 relations

    Inform the test subject and obtain consent to participate

    praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent

    Give every test subject concise, clear, relevant and understandable information beforehand on the five points of Article 61(1), then obtain freely-given informed consent, date and document that consent, and give a copy to the subject or the legal representative.

    Hangs off: Article 61: informed consent of test subjects for testing in real world conditions

    Editorially reviewed | fundamental-rights, innovation

  24. ActionEditorialv1.0.04 relations

    Make use of the SME facilities in Article 62

    praxikon:eu:ai-act:action:article-62-claim-sme-facilities

    Apply for priority access to the AI regulatory sandbox, use the national communication channel for questions about implementation, sign up for the standardisation process, and on a conformity assessment under Article 43 ask how the fee reduction has been applied.

    Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups

    Editorially reviewed | governance, innovation

  25. ActionEditorialv1.0.03 relations

    Determine and bound the simplification of your quality management system

    praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management

    Test whether you are a microenterprise with no partner or linked enterprises, build the Article 17 system, mark which elements you would want to simplify once the Commission guidelines exist, and keep the nine articles of Article 63(2) expressly outside that simplification.

    Hangs off: Article 63: derogations for SMEs in the quality management system

    Editorially reviewed | high-risk-requirements, innovation

  26. Actionv1.0.04 relations

    Draw up a post-market monitoring plan

    praxikon:eu:ai-act:action:article-72-post-market-monitoring-act

    Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.

    Hangs off: Article 72: post-market monitoring

    Editorially reviewed | post-market

  27. Actionv1.0.04 relations

    Set up an incident process with reporting routes

    praxikon:eu:ai-act:action:article-73-incident-reporting-act

    Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.

    Hangs off: Article 73: serious incident reporting

    Editorially reviewed | post-market

  28. ActionEditorialv1.0.03 relations

    Record the state of the art and the intended purpose per system

    praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline

    Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.

    Hangs off: Article 8: compliance with the requirements for high-risk AI systems

    Editorially reviewed | conformity, high-risk-requirements

  29. Actionv1.0.03 relations

    Set up an iterative risk management process

    praxikon:eu:ai-act:action:article-9-risk-management-act

    Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.

    Hangs off: Article 9: risk management system

    Editorially reviewed | high-risk-requirements

  30. ActionEditorialv1.0.04 relations

    Scope a voluntary code of conduct and separate it from your duties

    praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code

    Choose the paragraph 1 or the paragraph 2 route, name which requirements you apply voluntarily and which you do not, give the code clear objectives and key performance indicators, and keep the voluntary commitments administratively separate from the obligations that continue to apply in full.

    Hangs off: Article 95: codes of conduct for voluntary application of specific requirements

    Editorially reviewed | governance, innovation

  31. ActionEditorialv1.0.08 relations

    Assign to each obligation the penalty ceiling that belongs to it

    praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers

    Walk through your obligations register and mark per line which ceiling applies: Article 99(3) for Article 5, Article 99(4) for the role duties enumerated there, Article 25(2) and (4) and Article 50, Article 99(5) for answering information requests, and otherwise the national penalty regime under Article 99(1). Add the Article 101 regime wherever you provide a general-purpose AI model yourself, and the Article 75c regime wherever the AI Office is competent.

    Hangs off: Article 99, 100 and 101: the penalty structure per obligation

    Editorially reviewed | enforcement, governance

  32. ActionEditorialv1.0.03 relations

    Determine and record whether your AI component is a safety component

    praxikon:eu:ai-act:action:assess-safety-component-role

    Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.

    Hangs off: Article 6(1a) to (1c): the tightened classification route

    Editorially reviewed | conformity, high-risk

  33. ActionUpcomingv1.0.04 relations

    Assess for every design change whether it is significant

    praxikon:eu:ai-act:action:assess-significant-design-change

    Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  34. ActionUpcomingv1.0.03 relations

    Assign an internal owner and a date to each point of Article 16

    praxikon:eu:ai-act:action:assign-article-16-provider-duties

    Translate the twelve points (a) to (l) into twelve named owners with a start date, so that no point falls between product management, quality and legal.

    Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system

    Editorially reviewed | high-risk-requirements

  35. Actionv1.0.04 relations

    Complete the conformity route before market placement

    praxikon:eu:ai-act:action:conformity-ce-registration-act

    Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Editorially reviewed | conformity

  36. ActionEditorialv1.0.04 relations

    Take and record the decision whether you adhere to a code of practice

    praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence

    Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.

    Hangs off: Article 56: codes of practice for general-purpose AI models

    Editorially reviewed | governance, gpai, gpai-systemic-risk

  37. ActionUpcomingv1.0.06 relations

    Enter your data in the EU database and keep it up to date

    praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data

    Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.

    Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III

    Editorially reviewed | conformity

  38. ActionUpcomingv1.0.03 relations

    Establish the product route per product

    praxikon:eu:ai-act:action:establish-annex-i-product-route

    Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.

    Hangs off: Article 6(1): the product route to high risk

    Editorially reviewed | conformity, high-risk

  39. ActionApplicablev1.0.03 relations

    Establish per system who your supervisor is

    praxikon:eu:ai-act:action:establish-competent-supervisor

    Assess per AI system whether it falls under the exclusive competence of the AI Office or under a national authority, record the outcome with its reasoning, and determine which carve-out in paragraph 1 applies if any and which counter follows from it.

    Hangs off: Article 75: market surveillance, mutual assistance and the powers of the AI Office

    Editorially reviewed | enforcement, governance

  40. ActionUpcomingv1.0.04 relations

    Map the affected groups and their specific risks of harm

    praxikon:eu:ai-act:action:fria-affected-groups-analysis

    Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.

    Hangs off: Article 27: FRIA

    Editorially reviewed | fundamental-rights

  41. Actionv1.0.06 relations

    Perform a FRIA before deployment

    praxikon:eu:ai-act:action:fria-assess

    Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.

    Hangs off: Article 27: FRIA

    Editorially reviewed | fundamental-rights, high-risk

  42. ActionUpcomingv1.0.04 relations

    Set up the complaint mechanism and internal governance before the system runs

    praxikon:eu:ai-act:action:fria-complaint-mechanism-setup

    Describe the measures taken if a risk materialises, who decides internally, through which route an affected person can complain, within which deadline you respond, and who is authorised to stop the use.

    Hangs off: Article 27: FRIA

    Editorially reviewed | fundamental-rights

  43. Actionv1.0.04 relations

    Maintain GPAI documentation and transparency information

    praxikon:eu:ai-act:action:gpai-document

    Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | gpai

  44. ActionApplicablev1.0.02 relations

    Assemble the downstream information package under Annex XII

    praxikon:eu:ai-act:action:gpai-downstream-information-package

    Build one package for providers integrating your model, covering the intended tasks and integration options, acceptable use policies, release date and distribution methods, interaction with external hardware or software, software versions, architecture and parameter count, modality and format of inputs and outputs including maximum size, licence, required technical means, and information on the training, testing and validation data used.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | gpai

  45. ActionApplicablev1.0.02 relations

    Implement rights-reservation detection inside your copyright policy

    praxikon:eu:ai-act:action:gpai-rights-reservation-detection

    Record which techniques you use to identify a reservation of rights within the meaning of Article 4(3) of Directive (EU) 2019/790 when collecting training data, how often you recheck, and how you then comply with that reservation.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | gpai

  46. ActionApplicablev1.0.03 relations

    Set up how you handle a request for an explanation

    praxikon:eu:ai-act:action:handle-explanation-requests

    Ensure your complaints or objections desk recognises a request for an explanation of an AI-supported decision, that it can be traced per decision which system in which version contributed to it, and that someone is designated to give the explanation.

    Hangs off: Article 86: right to an explanation of a decision

    Editorially reviewed | fundamental-rights

  47. ActionEditorialv1.0.04 relations

    Record per requirement which standard or specification you rely on, and justify every departure

    praxikon:eu:ai-act:action:justify-standards-and-specification-choices

    Keep a coverage matrix of the requirements of Section 2 against the harmonised standards, common specifications and own documents applied, noting per row the publication status in the Official Journal, and write out the Article 41(5) justification for every common specification you do not apply.

    Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity

    Editorially reviewed | conformity, standards

  48. ActionUpcomingv1.0.03 relations

    Set up the ten year retention of the system documentation

    praxikon:eu:ai-act:action:keep-high-risk-documentation-available

    Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.

    Hangs off: Article 18: documentation keeping

    Editorially reviewed | high-risk-requirements

  49. Actionv1.0.03 relations

    Manage the life of the certificate

    praxikon:eu:ai-act:action:manage-notified-body-certificate

    A practical working out for whoever holds a certificate: watch the expiry date, ask in time for the re-assessment that carries the extension, test every change against the substantial modification of Article 43(4), and make sure a deadline set by the body for corrective action reaches an identifiable person. Also track the body itself, because on cessation or withdrawal of its designation the deadlines of Article 36 apply.

    Hangs off: Article 44: certificates of notified bodies

    Editorially reviewed | conformity

  50. ActionUpcomingv1.0.04 relations

    Map every system to a point of Annex III

    praxikon:eu:ai-act:action:map-system-to-annex-iii-area

    Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.

    Hangs off: Annex III: the eight areas separately

    Editorially reviewed | high-risk

  51. ActionEditorialv1.0.05 relations

    Mark and register what you submit to an authority or body

    praxikon:eu:ai-act:action:mark-confidential-material-on-submission

    State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).

    Hangs off: Article 78: confidentiality of what you submit to an authority

    Editorially reviewed | enforcement, governance

  52. ActionApplicablev1.0.03 relations

    Notify the Commission within two weeks

    praxikon:eu:ai-act:action:notify-systemic-risk-threshold

    Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.

    Hangs off: Article 52: notification of a GPAI model with systemic risk

    Editorially reviewed | gpai-systemic-risk

  53. ActionEditorialv1.0.04 relations

    Make sure a report about an AI system reaches your reporting channel

    praxikon:eu:ai-act:action:open-a-protected-reporting-route

    Only for organisations that must already have a reporting arrangement. Make visible in it that an infringement of the AI Regulation is a reportable infringement, designate who receives such a report, agree how the identity of the person reporting stays out of the rest of the process, and record whether you handle anonymous reports.

    Hangs off: Article 87: reporting of infringements and protection of reporting persons

    Editorially reviewed | fundamental-rights, governance

  54. ActionApplicablev1.0.04 relations

    Plan compliance for legacy public sector systems by 2 August 2030

    praxikon:eu:ai-act:action:plan-legacy-public-system-compliance

    Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  55. ActionEditorialv1.0.05 relations

    Prepare a derogation request and the exit plan that goes with it

    praxikon:eu:ai-act:action:prepare-article-46-derogation-request

    Write in advance the reasoning paragraph 1 calls for, with the exceptional reason invoked, the evidence that the system complies with the requirements of Section 2, the status of the ongoing conformity assessment, and an exit plan in case the authorisation is refused or withdrawn.

    Hangs off: Article 46: derogation from conformity assessment procedure

    Editorially reviewed | conformity, enforcement

  56. ActionUpcomingv1.0.04 relations

    Make your conformity file deliverable on request

    praxikon:eu:ai-act:action:prepare-authority-information-request

    Map per high-risk system where each part of the file sits, which system version it belongs to, who assembles it, how long the logs are kept and in which language indicated by the Member State concerned you can supply it, so that a reasoned request becomes a delivery task rather than a search.

    Hangs off: Article 21: cooperation with competent authorities

    Editorially reviewed | high-risk-requirements

  57. ActionApplicablev1.0.03 relations

    Make sure you can answer a complaint with documents

    praxikon:eu:ai-act:action:prepare-for-a-complaint

    Record per AI system which assessment was carried out, by whom, on what date and against which system version, and agree who receives a question from the authority and within what period.

    Hangs off: Article 85: right to lodge a complaint with the market surveillance authority

    Editorially reviewed | fundamental-rights

  58. ActionApplicablev1.0.06 relations

    Justify and record your reliance on Article 4a

    praxikon:eu:ai-act:action:record-bias-testing-legal-basis

    Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Editorially reviewed | fundamental-rights, high-risk-requirements

  59. ActionApplicablev1.0.07 relations

    Register yourself and the system before it reaches the market or is put into service

    praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry

    Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used.

    Hangs off: Article 49: registration in the EU database before the system reaches the market

    Editorially reviewed | conformity, high-risk

  60. ActionApplicablev1.0.03 relations

    Request reassessment after a designation

    praxikon:eu:ai-act:action:request-systemic-risk-reassessment

    If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.

    Hangs off: Article 52: notification of a GPAI model with systemic risk

    Editorially reviewed | gpai-systemic-risk

  61. ActionUpcomingv1.0.03 relations

    Route reporting and conformity assessment to the AI Office

    praxikon:eu:ai-act:action:route-high-risk-duties-to-ai-office

    Adjust your incident procedure so that a serious incident concerning a high-risk system under the competence of the AI Office reaches the Office, with the Article 73 deadlines intact, and establish whether your third-party conformity assessment now runs through the Commission, including the fees you pay directly to the notified body.

    Hangs off: Article 75(1a) and (1e): reporting to and assessment by the AI Office

    Editorially reviewed | enforcement, high-risk-requirements

  62. ActionUpcomingv1.0.03 relations

    Set up the procedure for corrective actions and notification

    praxikon:eu:ai-act:action:run-corrective-action-procedure

    Work out the four measures in paragraph 1 as scenarios with an owner and a lead time, keep a record per system version of who runs it and how you reach that party, and set out the route along which the investigation of causes, the notification to the market surveillance authorities and the message to the notified body run once paragraph 2 comes into play.

    Hangs off: Article 20: corrective actions and duty of information

    Editorially reviewed | high-risk-requirements, post-market

  63. ActionUpcomingv1.0.03 relations

    Perform the Article 24(1) check before making available

    praxikon:eu:ai-act:action:run-distributor-market-check

    Verify the CE marking, the presence of the EU declaration of conformity and the instructions for use, and whether the provider and importer complied with Article 16, points (b) and (c), and Article 23(3).

    Hangs off: Article 24: obligations of distributors

    Editorially reviewed | value-chain

  64. ActionUpcomingv1.0.03 relations

    Run the four verifications of Article 23(1) before importing

    praxikon:eu:ai-act:action:run-importer-verification-checklist

    Check and record: the conformity assessment has been carried out, the technical documentation exists, the CE marking plus declaration and instructions for use are present, and an authorised representative has been appointed.

    Hangs off: Article 23: obligations of importers

    Editorially reviewed | value-chain

  65. Actionv1.0.04 relations

    Assess the value-chain role per system and change

    praxikon:eu:ai-act:action:value-chain-representative-act

    On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.

    Hangs off: Articles 22-25: value chain and authorised representative

    Editorially reviewed | value-chain

  66. ActionEditorialv1.0.03 relations

    Check the standing and independence of your notified body

    praxikon:eu:ai-act:action:verify-notified-body-standing

    At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.

    Hangs off: Articles 28 to 39: notifying authorities and notified bodies

    Editorially reviewed | conformity, governance

  67. Actorv1.0.09 relations

    AI Office

    praxikon:eu:ai-act:actor:ai-office

    The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.

    Editorially reviewed | enforcement, governance, gpai

  68. ActorIn forcev1.0.034 relations

    Authorised representative

    praxikon:eu:ai-act:actor:authorised-representative

    The authorised representative is the party located in the Union that, on the basis of a written mandate, performs and carries out the obligations and procedures of the Regulation on behalf of a provider established outside the EU. The definition in Article 3(5) already applies today, so the role can be determined now. The appointment duty itself starts on 2 December 2027 for the standalone Annex III route and on 2 August 2028 for the embedded Annex I route. From those dates, a third-country provider may not place a high-risk AI system on the Union market without an appointed representative.

    Editorially reviewed | value-chain

  69. Actorv1.0.014 relations

    Credit or insurance deployer

    praxikon:eu:ai-act:actor:credit-or-insurance-deployer

    A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).

    Editorially reviewed | fundamental-rights, high-risk

  70. Actorv1.0.0345 relations

    Deployer

    praxikon:eu:ai-act:actor:deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

    Editorially reviewed | governance

  71. ActorIn forcev1.0.024 relations

    Distributor

    praxikon:eu:ai-act:actor:distributor

    You are a distributor if you make an AI system available on the Union market without being the provider or the importer. This catches resellers, systems integrators and managed service providers that pass on someone else's AI.

    Editorially reviewed | value-chain

  72. Actorv1.0.070 relations

    Provider of a GPAI model

    praxikon:eu:ai-act:actor:gpai-model-provider

    A party that places a general-purpose AI model on the Union market.

    Editorially reviewed | gpai

  73. ActorIn forcev1.0.020 relations

    Importer

    praxikon:eu:ai-act:actor:importer

    You are an importer as soon as you, from within the EU, first place an AI system on the Union market that bears the name or trade mark of a party established outside the EU. What counts is not your purchasing role but whose brand is on the system and who first brings it to market.

    Editorially reviewed | value-chain

  74. Actorv1.0.014 relations

    Market surveillance authority

    praxikon:eu:ai-act:actor:market-surveillance-authority

    The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.

    Editorially reviewed | enforcement, governance

  75. Actorv1.0.0483 relations

    Provider of an AI system

    praxikon:eu:ai-act:actor:provider

    A party that develops or has an AI system developed and places it on the market under its own name.

    Editorially reviewed | governance

  76. Actorv1.0.050 relations

    Body governed by public law

    praxikon:eu:ai-act:actor:public-law-body

    A deployer that is a body governed by public law.

    Editorially reviewed | fundamental-rights

  77. Actorv1.0.015 relations

    Private provider of public services

    praxikon:eu:ai-act:actor:public-service-provider

    A private deployer providing public services.

    Editorially reviewed | fundamental-rights

  78. ChangeApplicablev1.0.04 relations

    The AI Act enters into force

    praxikon:eu:ai-act:change:2024-08-01-entry-into-force

    The regulation entered into force on 1 August 2024, after which the obligations followed in phases.

    Hangs off: Article 4: AI literacy, Article 5: prohibited practices

    Placed against the official source | timeline

  79. ChangeApplicablev1.0.04 relations

    Prohibited practices and AI literacy apply

    praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable

    Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.

    Hangs off: Article 4: AI literacy, Article 5: prohibited practices

    Placed against the official source | ai-literacy, timeline

  80. ChangeGuidancev1.0.02 relations

    General-Purpose AI Code of Practice published

    praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice

    The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.

    Hangs off: Article 53: GPAI model providers

    Placed against the official source | gpai

  81. ChangeGuidancev1.0.03 relations

    Guidelines on the scope of the GPAI obligations

    praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines

    The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai

  82. ChangeGuidancev1.0.04 relations

    Guidelines on the definition of an AI system

    praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines

    The Commission draws the line between software that does and does not fall under the regulation.

    Hangs off: Annex III: high-risk AI, Article 4: AI literacy

    Placed against the official source | scope

  83. ChangeGuidancev1.0.03 relations

    Guidelines on prohibited AI practices

    praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines

    Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.

    Hangs off: Article 5: prohibited practices

    Placed against the official source | prohibited

  84. ChangeApplicablev1.0.03 relations

    GPAI model obligations apply

    praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable

    Since 2 August 2025 the obligations for providers of general-purpose AI models apply.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai, timeline

  85. ChangeGuidancev1.0.04 relations

    Draft guidelines on high-risk classification

    praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines

    The Commission explains in consultation when a system falls under Annex I or Annex III.

    Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk

  86. ChangeGuidancev1.0.03 relations

    Transparency Code of Practice published

    praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice

    A voluntary route to comply with parts of Article 50, in two separately signable sections.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  87. ChangeGuidancev1.0.02 relations

    First European AI Act standard approved

    praxikon:eu:ai-act:change:2026-07-12-en-18286-approved

    EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.

    Hangs off: Article 17: quality management system

    Placed against the official source | standards

  88. ChangeGuidancev1.0.03 relations

    Final guidelines on Article 50

    praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines

    The Commission works out the transparency duties and confirms they apply from 2 August 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  89. ChangeIn forcev1.0.08 relations

    Annex III core rules moved to 2 December 2027

    praxikon:eu:ai-act:change:2026-07-27-annex-iii-date

    The amended application date has been binding law since 27 July 2026.

    Hangs off: Annex III: high-risk AI

    Placed against the official source | high-risk

  90. ChangeIn forcev1.0.02 relations

    New Article 2(13): requirements for Annex I systems may be limited

    praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation

    Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | conformity, high-risk

  91. ChangeIn forcev1.0.05 relations

    Article 4 amended to a duty to take measures

    praxikon:eu:ai-act:change:2026-07-27-article-4-amended

    Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.

    Hangs off: Article 4: AI literacy

    Placed against the official source | ai-literacy

  92. ChangeIn forcev1.0.07 relations

    Article 4a inserted, Article 10(5) deleted

    praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted

    Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Placed against the official source | fundamental-rights, high-risk-requirements

  93. ChangeIn forcev1.0.06 relations

    FRIA follows new date and may cross-reference a DPIA

    praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link

    The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.

    Hangs off: Article 27: FRIA

    Placed against the official source | fundamental-rights, high-risk

  94. ChangeIn forcev1.0.02 relations

    Machinery moves from Annex I, Section A, to Section B

    praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b

    Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | conformity, high-risk, scope

  95. ChangeIn forcev1.0.02 relations

    Article 6 gains paragraphs 1a to 1c on safety components

    praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed

    Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk, scope

  96. ChangeApplicablev1.0.05 relations

    Article 50 is applicable

    praxikon:eu:ai-act:change:2026-08-02-article-50-applicable

    The transparency duties apply since 2 August 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  97. ChangeApplicablev1.0.05 relations

    GPAI enforcement powers active

    praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement

    Since 2 August 2026 the Commission can request GPAI information, conduct evaluations and require measures.

    Hangs off: Article 53: GPAI model providers

    Placed against the official source | enforcement, gpai

  98. ChangeUpcomingv1.0.03 relations

    Grace period for machine-readable marking ends

    praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends

    Systems placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | timeline, transparency

  99. ChangeUpcomingv1.0.02 relations

    New prohibitions require technical safeguards

    praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards

    The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.

    Hangs off: Article 5: prohibited practices

    Placed against the official source | prohibited, timeline

  100. ChangeUpcomingv1.0.04 relations

    Legacy GPAI models must comply

    praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply

    Models placed on the market before 2 August 2025 have until 2 August 2027.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai, timeline

  101. ChangeUpcomingv1.0.02 relations

    National AI regulatory sandboxes operational on 2 August 2027

    praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational

    The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.

    Hangs off: Article 57: AI regulatory sandboxes

    Placed against the official source | governance, innovation

  102. ChangeUpcomingv1.0.02 relations

    Template for the post-market monitoring plan becomes guidance, by 2 September 2027

    praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template

    Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.

    Hangs off: Article 72: post-market monitoring

    Placed against the official source | high-risk, post-market

  103. ChangeUpcomingv1.0.04 relations

    High-risk AI embedded in regulated products

    praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable

    AI as a safety component of products under Annex I follows on 2 August 2028.

    Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk, timeline

  104. ControlApplicablev1.0.05 relations

    Intake and deadline tracking for a demand or an inspection

    praxikon:eu:ai-act:control:ai-office-proceeding-response

    The control that ensures an information request, a notice of investigation or an announced inspection from the AI Office reaches an identifiable person, that it is first established whether it is a simple request or a decision, that the period set is tracked, and that what was supplied is recorded. The substance is sanctioned too: a periodic penalty payment can be imposed where you fail to give correct or complete answers during an ordered inspection, and incorrect, incomplete or misleading information supplied to the Office falls under the fines of Article 99(5). A retention order under Article 75a(6) belongs in this control, because it overrides your deletion routines.

    Hangs off: Article 75(1a) and (1e): reporting to and assessment by the AI Office, Article 75: market surveillance, mutual assistance and the powers of the AI Office

    Editorially reviewed | control, enforcement

  105. ControlUpcomingv1.0.03 relations

    Reassessment on a change of product or assessment route

    praxikon:eu:ai-act:control:annex-i-product-route-change-gate

    The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.

    Hangs off: Article 6(1): the product route to high risk

    Editorially reviewed | control, high-risk

  106. ControlUpcomingv1.0.04 relations

    Reassessment on a change of intended purpose

    praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger

    The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.

    Hangs off: Annex III: the eight areas separately

    Editorially reviewed | high-risk

  107. Controlv1.0.04 relations

    Reclassification on purpose or context change

    praxikon:eu:ai-act:control:annex-iii-change-trigger

    Reopen classification when intended purpose, use context or system functionality changes materially.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | control, high-risk

  108. ControlUpcomingv1.0.03 relations

    Procurement gate: no signature without a completed classification answer

    praxikon:eu:ai-act:control:annex-iii-procurement-gate

    Block signature of an AI contract until the supplier has answered in writing which Annex III point the intended purpose falls under, whether it relies on Article 6(3), and whether the system profiles natural persons.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | high-risk

  109. Controlv1.0.04 relations

    Data check before retraining

    praxikon:eu:ai-act:control:article-10-data-governance-control

    Repeat the data quality assessment before every retraining or dataset change.

    Hangs off: Article 10: data and data governance

    Editorially reviewed | control, high-risk-requirements

  110. Controlv1.0.03 relations

    Documentation update on every release

    praxikon:eu:ai-act:control:article-11-technical-documentation-control

    Update the file before every release and retain earlier versions traceably.

    Hangs off: Article 11: technical documentation

    Editorially reviewed | control, high-risk-requirements

  111. Controlv1.0.04 relations

    Periodic log review

    praxikon:eu:ai-act:control:article-12-logging-control

    Periodically verify that logging works, is complete and is retained according to the regime.

    Hangs off: Article 12: logging and traceability

    Editorially reviewed | control, high-risk-requirements

  112. Controlv1.0.04 relations

    Instructions check at deployment

    praxikon:eu:ai-act:control:article-13-instructions-control

    At every deployment and update, verify instructions are present, current and internally translated.

    Hangs off: Article 13: transparency towards deployers

    Editorially reviewed | control, high-risk-requirements

  113. Controlv1.0.04 relations

    Oversight test before go-live

    praxikon:eu:ai-act:control:article-14-human-oversight-control

    Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.

    Hangs off: Article 14: human oversight

    Editorially reviewed | control, high-risk-requirements

  114. Controlv1.0.03 relations

    Performance monitoring in use

    praxikon:eu:ai-act:control:article-15-accuracy-robustness-control

    Monitor whether the system stays within declared levels in production and escalate on deviation.

    Hangs off: Article 15: accuracy, robustness and cybersecurity

    Editorially reviewed | control, high-risk-requirements

  115. ControlUpcomingv1.0.03 relations

    Release gate before placing on the market

    praxikon:eu:ai-act:control:article-16-pre-market-release-gate

    A hard block in your release or delivery process: no delivery without a completed conformity assessment, a signed EU declaration of conformity, an affixed CE marking and a completed registration.

    Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system

    Editorially reviewed | high-risk-requirements

  116. Controlv1.0.03 relations

    Internal audit cycle

    praxikon:eu:ai-act:control:article-17-quality-management-control

    Periodically audit whether practice follows the described system and record deviations and improvements.

    Hangs off: Article 17: quality management system

    Editorially reviewed | control, high-risk-requirements

  117. ControlUpcomingv1.0.03 relations

    Periodic check on completeness and retrievability of the retention file

    praxikon:eu:ai-act:control:article-18-retention-review

    The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.

    Hangs off: Article 18: documentation keeping

    Editorially reviewed | control, high-risk-requirements

  118. ControlApplicablev1.0.03 relations

    Coverage reconciliation: every person with AI access appears in the register

    praxikon:eu:ai-act:control:article-4-coverage-reconciliation

    Periodically reconcile the list of accounts and licences with access to AI systems against the participation and instruction register, and clear the gap list with an owner and a deadline.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy

  119. Controlv1.0.04 relations

    Periodic role and context review

    praxikon:eu:ai-act:control:article-4-periodic-review

    Check when systems, roles or risks change whether the selected measures remain appropriate.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy, control

  120. ControlEditorialv1.0.05 relations

    Review of an authorisation expiring, being refused or withdrawn

    praxikon:eu:ai-act:control:article-46-derogation-exit-review

    The control that keeps a system running under Article 46 under watch: the ongoing conformity assessment has an owner and an end date, the fifteen calendar days of paragraph 4 are in the calendar, and a rehearsed plan is in place to stop use with immediate effect and discard all results and outputs if the authorisation is refused or withdrawn.

    Hangs off: Article 46: derogation from conformity assessment procedure

    Editorially reviewed | conformity, control, enforcement

  121. ControlApplicablev1.0.07 relations

    Release gate: no market entry without registration

    praxikon:eu:ai-act:control:article-49-pre-market-registration-gate

    The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.

    Hangs off: Article 49: registration in the EU database before the system reaches the market

    Editorially reviewed | conformity, control, high-risk

  122. Controlv1.0.04 relations

    Article 5 gate at intake and change

    praxikon:eu:ai-act:control:article-5-intake-gate

    Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.

    Hangs off: Article 5: prohibited practices

    Editorially reviewed | control, prohibited-practices

  123. ControlApplicablev1.0.03 relations

    Quarterly sampling of live disclosures and markings in production

    praxikon:eu:ai-act:control:article-50-production-sampling

    Each quarter, sample the systems carrying an Article 50 scenario and verify in the production environment that the disclosure still appears and the marking is still present in the actual output, recording finding, owner and remediation deadline.

    Hangs off: Article 50: transparency

    Editorially reviewed | transparency

  124. Controlv1.0.04 relations

    Pre-release transparency check

    praxikon:eu:ai-act:control:article-50-release-check

    Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.

    Hangs off: Article 50: transparency

    Editorially reviewed | control, transparency

  125. Controlv1.0.03 relations

    Compute threshold monitoring

    praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control

    Monitor cumulative training compute and notify the Commission when the threshold is reached.

    Hangs off: Article 55: GPAI models with systemic risk

    Editorially reviewed | control, gpai-systemic-risk

  126. ControlEditorialv1.0.04 relations

    Review moment on your reliance on a code of practice

    praxikon:eu:ai-act:control:article-56-code-commitment-review

    The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.

    Hangs off: Article 56: codes of practice for general-purpose AI models

    Editorially reviewed | control, governance, gpai, gpai-systemic-risk

  127. ControlApplicablev1.0.03 relations

    Supervision inside the sandbox and the conditional fine shield

    praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield

    The authority retains its supervisory and corrective powers and can suspend your testing or participation. If you stay within the plan and follow the guidance in good faith, authorities impose no administrative fines for infringements of this Regulation.

    Hangs off: Article 57: AI regulatory sandboxes

    Editorially reviewed | innovation

  128. ControlApplicablev1.0.04 relations

    Oversight during the test, incident reporting and recall procedure

    praxikon:eu:ai-act:control:article-60-oversight-and-incident-response

    The market surveillance authority may inspect unannounced. On a serious incident you report, take immediate mitigation or suspend, and you must have a procedure in place in advance for prompt recall of the system.

    Hangs off: Article 60: testing in real world conditions outside a sandbox

    Editorially reviewed | innovation

  129. ControlEditorialv1.0.04 relations

    Consent and withdrawal review before a test in real world conditions starts

    praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review

    The control that no subject participates before the information pack is complete, the consent record is dated and a copy has been given, and that the withdrawal route with its recipient, period and deletion step works and has been rehearsed once.

    Hangs off: Article 61: informed consent of test subjects for testing in real world conditions

    Editorially reviewed | control, fundamental-rights, innovation

  130. ControlEditorialv1.0.04 relations

    Fee and access review on a conformity assessment

    praxikon:eu:ai-act:control:article-62-fee-and-access-review

    The control that on every application for a conformity assessment under Article 43 and on every sandbox application it is checked whether the SME facilities have been invoked and whether the proportionate fee reduction has been made visible, and that the answer reaches the procurement file.

    Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups

    Editorially reviewed | control, governance, innovation

  131. ControlEditorialv1.0.03 relations

    Review of the boundary of the simplification

    praxikon:eu:ai-act:control:article-63-simplification-boundary-review

    The control that every simplification you make under Article 63 is tested against paragraph 2, so that no item from Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73 falls away, and that the shareholding structure test is redone at every change.

    Hangs off: Article 63: derogations for SMEs in the quality management system

    Editorially reviewed | control, high-risk-requirements, innovation

  132. Controlv1.0.04 relations

    Signal-to-action loop

    praxikon:eu:ai-act:control:article-72-post-market-monitoring-control

    Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.

    Hangs off: Article 72: post-market monitoring

    Editorially reviewed | control, post-market

  133. Controlv1.0.04 relations

    Incident drill and deadline watch

    praxikon:eu:ai-act:control:article-73-incident-reporting-control

    Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.

    Hangs off: Article 73: serious incident reporting

    Editorially reviewed | control, post-market

  134. ControlEditorialv1.0.05 relations

    Review before handing over source code or trade secrets

    praxikon:eu:ai-act:control:article-78-disclosure-review

    The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.

    Hangs off: Article 78: confidentiality of what you submit to an authority

    Editorially reviewed | control, enforcement, governance

  135. ControlEditorialv1.0.03 relations

    Review of the overlap with sectoral product documentation

    praxikon:eu:ai-act:control:article-8-integrated-documentation-review

    The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.

    Hangs off: Article 8: compliance with the requirements for high-risk AI systems

    Editorially reviewed | conformity, control, high-risk-requirements

  136. Controlv1.0.03 relations

    Reassessment on every material change

    praxikon:eu:ai-act:control:article-9-risk-management-control

    Reopen the risk management process on changes in purpose, data, model or use context and before every release.

    Hangs off: Article 9: risk management system

    Editorially reviewed | control, high-risk-requirements

  137. ControlEditorialv1.0.04 relations

    Review that keeps voluntary and mandatory apart

    praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review

    The control that no external statement, quotation, tender response or annual report presents a code of conduct as cover for an obligation under the Regulation, and that every voluntary commitment has an owner, an indicator and a moment of measurement before it goes out.

    Hangs off: Article 95: codes of conduct for voluntary application of specific requirements

    Editorially reviewed | control, governance, innovation

  138. ControlEditorialv1.0.08 relations

    Recording of the factors in Article 99(7)

    praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record

    The control that ensures the factors which determine the amount of a fine are recorded at the time and not reconstructed afterwards: which technical and organisational measures were in place, when you notified an infringement yourself, how you responded to requests from the authority, and what you did to mitigate the harm suffered by affected persons. Those factors cut both ways, so the same record can also count against you; that is a reason to keep it properly rather than not at all.

    Hangs off: Article 99, 100 and 101: the penalty structure per obligation

    Editorially reviewed | control, enforcement

  139. ControlUpcomingv1.0.03 relations

    Intake and deadline tracking of a request from an authority

    praxikon:eu:ai-act:control:authority-request-intake-and-deadline

    The control that ensures an incoming request from a competent authority reaches an identifiable owner the same day, that the documents requested are matched to the right system version, and that delivery is complete within the period set by the authority.

    Hangs off: Article 21: cooperation with competent authorities

    Editorially reviewed | control, high-risk-requirements

  140. ControlApplicablev1.0.05 relations

    Access and deletion control for bias testing

    praxikon:eu:ai-act:control:bias-testing-data-deletion

    The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Editorially reviewed | fundamental-rights, high-risk-requirements

  141. Controlv1.0.03 relations

    Monitoring of certificate, modification and body

    praxikon:eu:ai-act:control:certificate-expiry-monitoring

    The control that ensures three signals reach an identifiable person in time instead of surfacing only once the certificate has already lapsed or been suspended: an approaching expiry date, a change that may be substantial within the meaning of Article 43(4), and a notice from or about the notified body itself, including the notification within ten days on suspension, restriction or withdrawal of its designation and the confirmation that Article 36(8), point (b), requires from the provider within three months.

    Hangs off: Article 44: certificates of notified bodies

    Editorially reviewed | conformity, control

  142. Controlv1.0.04 relations

    Reassessment on substantial modification

    praxikon:eu:ai-act:control:conformity-ce-registration-control

    Rerun the conformity route whenever the system is substantially modified.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Editorially reviewed | conformity, control

  143. ControlUpcomingv1.0.04 relations

    Suspension and incident notification control

    praxikon:eu:ai-act:control:deployer-suspension-and-incident-control

    A fixed rule that suspends use and notifies in the correct order as soon as you have reason to consider the system presents a risk or as soon as you identify a serious incident.

    Hangs off: Article 26: obligations of deployers of high-risk AI systems

    Editorially reviewed | high-risk-requirements

  144. ControlUpcomingv1.0.04 relations

    Review gate on a design change

    praxikon:eu:ai-act:control:design-change-review-gate

    The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  145. ControlUpcomingv1.0.03 relations

    Distributor corrective action, withdrawal and recall control

    praxikon:eu:ai-act:control:distributor-corrective-action-control

    A pre-arranged capability to bring an already supplied system into conformity, withdraw it or recall it, and to immediately notify the provider or importer and the competent authorities.

    Hangs off: Article 24: obligations of distributors

    Editorially reviewed | value-chain

  146. ControlUpcomingv1.0.05 relations

    Currency check on the database entry

    praxikon:eu:ai-act:control:eu-database-entry-currency

    The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.

    Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III

    Editorially reviewed | conformity, control

  147. ControlApplicablev1.0.05 relations

    Routing and deadline tracking of a request for an explanation

    praxikon:eu:ai-act:control:explanation-request-routing

    The control that ensures an incoming request reaches an identifiable person within a set period and is answered, instead of sitting in a general inbox.

    Hangs off: Article 85: right to lodge a complaint with the market surveillance authority, Article 86: right to an explanation of a decision

    Editorially reviewed | fundamental-rights

  148. ControlUpcomingv1.0.04 relations

    Currency check on the FRIA elements during use

    praxikon:eu:ai-act:control:fria-in-use-currency-check

    Periodically and on every change in process, duration of use, affected groups, risks or oversight measures, check whether the recorded elements still hold, and update the information as soon as they do not.

    Hangs off: Article 27: FRIA

    Editorially reviewed | fundamental-rights

  149. Controlv1.0.05 relations

    Pre-deployment FRIA go/no-go

    praxikon:eu:ai-act:control:fria-pre-deployment-gate

    Block deployment until applicability, assessment, mitigation and notification have been completed.

    Hangs off: Article 27: FRIA

    Editorially reviewed | control, fundamental-rights

  150. ControlApplicablev1.0.02 relations

    Half-yearly review of whether your chosen compliance route still covers you

    praxikon:eu:ai-act:control:gpai-compliance-route-review

    Establish every six months whether you demonstrate compliance through a code of practice, through a published harmonised standard, or through alternative adequate means, and whether the underlying file matches that choice.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | gpai

What this explorer does not do

  • There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
  • No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
  • A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
  • The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
  • The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
  • Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.

The same selection as data

The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.