Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Active filters
Objects
150 of 236 shown. Pick a type below or narrow with a filter to see the rest.
- Actionv1.0.05 relations
Classify the use case and document the outcome
praxikon:eu:ai-act:action:annex-iii-classify
Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- ActionApplicablev1.0.03 relations
Appoint an authorised representative and record the mandate
praxikon:eu:ai-act:action:appoint-gpai-authorised-representative
Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | gpai, value-chain
- Actionv1.0.04 relations
Set up data governance per dataset
praxikon:eu:ai-act:action:article-10-data-governance-act
Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
Hangs off: Article 10: data and data governance
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Build the technical file per Annex IV
praxikon:eu:ai-act:action:article-11-technical-documentation-act
Document system description, development process, data, oversight measures, performance and risk management before market placement.
Hangs off: Article 11: technical documentation
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design logging into the system
praxikon:eu:ai-act:action:article-12-logging-act
Ensure the system automatically records events relevant to risk identification and post-market monitoring.
Hangs off: Article 12: logging and traceability
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Provide complete instructions for use
praxikon:eu:ai-act:action:article-13-instructions-act
Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design and assign effective human oversight
praxikon:eu:ai-act:action:article-14-human-oversight-act
Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.
Hangs off: Article 14: human oversight
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set and test performance and security levels
praxikon:eu:ai-act:action:article-15-accuracy-robustness-act
Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set up an AI quality management system
praxikon:eu:ai-act:action:article-17-quality-management-act
Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.
Hangs off: Article 17: quality management system
Editorially reviewed | high-risk-requirements
- Actionv1.0.05 relations
Take role- and context-specific AI literacy measures
praxikon:eu:ai-act:action:article-4-measures
Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Actionv1.0.04 relations
Screen every use case against Article 5 first
praxikon:eu:ai-act:action:article-5-screen
Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
Hangs off: Article 5: prohibited practices
Editorially reviewed | prohibited-practices
- Actionv1.0.02 relations
Implement the applicable disclosure, marking or label
praxikon:eu:ai-act:action:article-50-disclosure
First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Editorially reviewed | transparency
- Actionv1.0.03 relations
Perform model evaluations and risk mitigation
praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act
Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | gpai-systemic-risk
- Actionv1.0.04 relations
Draw up a post-market monitoring plan
praxikon:eu:ai-act:action:article-72-post-market-monitoring-act
Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | post-market
- Actionv1.0.04 relations
Set up an incident process with reporting routes
praxikon:eu:ai-act:action:article-73-incident-reporting-act
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | post-market
- ActionEditorialv1.0.03 relations
Record the state of the art and the intended purpose per system
praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline
Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, high-risk-requirements
- Actionv1.0.03 relations
Set up an iterative risk management process
praxikon:eu:ai-act:action:article-9-risk-management-act
Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.
Hangs off: Article 9: risk management system
Editorially reviewed | high-risk-requirements
- ActionEditorialv1.0.03 relations
Determine and record whether your AI component is a safety component
praxikon:eu:ai-act:action:assess-safety-component-role
Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ActionUpcomingv1.0.04 relations
Assess for every design change whether it is significant
praxikon:eu:ai-act:action:assess-significant-design-change
Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- Actionv1.0.04 relations
Complete the conformity route before market placement
praxikon:eu:ai-act:action:conformity-ce-registration-act
Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity
- ActionEditorialv1.0.04 relations
Take and record the decision whether you adhere to a code of practice
praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence
Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | governance, gpai, gpai-systemic-risk
- ActionUpcomingv1.0.05 relations
Enter your data in the EU database and keep it up to date
praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data
Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity
- ActionUpcomingv1.0.03 relations
Establish the product route per product
praxikon:eu:ai-act:action:establish-annex-i-product-route
Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | conformity, high-risk
Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
Hangs off: Article 27: FRIA
Editorially reviewed | fundamental-rights, high-risk
- Actionv1.0.03 relations
Maintain GPAI documentation and transparency information
praxikon:eu:ai-act:action:gpai-document
Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | gpai
- ActionUpcomingv1.0.03 relations
Set up the ten year retention of the system documentation
praxikon:eu:ai-act:action:keep-high-risk-documentation-available
Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.
Hangs off: Article 18: documentation keeping
Editorially reviewed | high-risk-requirements
- ActionUpcomingv1.0.04 relations
Map every system to a point of Annex III
praxikon:eu:ai-act:action:map-system-to-annex-iii-area
Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- ActionEditorialv1.0.05 relations
Mark and register what you submit to an authority or body
praxikon:eu:ai-act:action:mark-confidential-material-on-submission
State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | enforcement, governance
- ActionApplicablev1.0.03 relations
Notify the Commission within two weeks
praxikon:eu:ai-act:action:notify-systemic-risk-threshold
Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- ActionApplicablev1.0.04 relations
Plan compliance for legacy public sector systems by 2 August 2030
praxikon:eu:ai-act:action:plan-legacy-public-system-compliance
Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ActionApplicablev1.0.06 relations
Justify and record your reliance on Article 4a
praxikon:eu:ai-act:action:record-bias-testing-legal-basis
Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- ActionApplicablev1.0.03 relations
Request reassessment after a designation
praxikon:eu:ai-act:action:request-systemic-risk-reassessment
If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Actionv1.0.04 relations
Assess the value-chain role per system and change
praxikon:eu:ai-act:action:value-chain-representative-act
On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | value-chain
- ActionEditorialv1.0.03 relations
Check the standing and independence of your notified body
praxikon:eu:ai-act:action:verify-notified-body-standing
At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, governance
The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.
Editorially reviewed | enforcement, governance, gpai
- Actorv1.0.08 relations
Credit or insurance deployer
praxikon:eu:ai-act:actor:credit-or-insurance-deployer
A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).
Editorially reviewed | fundamental-rights, high-risk
An organisation using an AI system under its authority, excluding personal non-professional use.
Editorially reviewed | governance
A party that places a general-purpose AI model on the Union market.
Editorially reviewed | gpai
- Actorv1.0.03 relations
Market surveillance authority
praxikon:eu:ai-act:actor:market-surveillance-authority
The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.
Editorially reviewed | enforcement, governance
A party that develops or has an AI system developed and places it on the market under its own name.
Editorially reviewed | governance
A deployer that is a body governed by public law.
Editorially reviewed | fundamental-rights
- Actorv1.0.09 relations
Private provider of public services
praxikon:eu:ai-act:actor:public-service-provider
A private deployer providing public services.
Editorially reviewed | fundamental-rights
- ChangeApplicablev1.0.04 relations
The AI Act enters into force
praxikon:eu:ai-act:change:2024-08-01-entry-into-force
The regulation entered into force on 1 August 2024, after which the obligations followed in phases.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | timeline
- ChangeApplicablev1.0.04 relations
Prohibited practices and AI literacy apply
praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable
Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | ai-literacy, timeline
- ChangeGuidancev1.0.02 relations
General-Purpose AI Code of Practice published
praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice
The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.
Hangs off: Article 53: GPAI model providers
Placed against the official source | gpai
- ChangeGuidancev1.0.03 relations
Guidelines on the scope of the GPAI obligations
praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines
The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai
- ChangeGuidancev1.0.04 relations
Guidelines on the definition of an AI system
praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines
The Commission draws the line between software that does and does not fall under the regulation.
Hangs off: Annex III: high-risk AI, Article 4: AI literacy
Placed against the official source | scope
- ChangeGuidancev1.0.03 relations
Guidelines on prohibited AI practices
praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines
Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited
- ChangeApplicablev1.0.03 relations
GPAI model obligations apply
praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable
Since 2 August 2025 the obligations for providers of general-purpose AI models apply.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai, timeline
- ChangeGuidancev1.0.04 relations
Draft guidelines on high-risk classification
praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines
The Commission explains in consultation when a system falls under Annex I or Annex III.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk
- ChangeGuidancev1.0.02 relations
Transparency Code of Practice published
praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice
A voluntary route to comply with parts of Article 50, in two separately signable sections.
Placed against the official source | transparency
- ChangeGuidancev1.0.02 relations
First European AI Act standard approved
praxikon:eu:ai-act:change:2026-07-12-en-18286-approved
EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.
Hangs off: Article 17: quality management system
Placed against the official source | standards
- ChangeGuidancev1.0.02 relations
Final guidelines on Article 50
praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines
The Commission works out the transparency duties and confirms they apply from 2 August 2026.
Placed against the official source | transparency
- ChangeIn forcev1.0.08 relations
Annex III core rules moved to 2 December 2027
praxikon:eu:ai-act:change:2026-07-27-annex-iii-date
The amended application date has been binding law since 27 July 2026.
Hangs off: Annex III: high-risk AI
Placed against the official source | high-risk
- ChangeIn forcev1.0.02 relations
New Article 2(13): requirements for Annex I systems may be limited
praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation
Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | conformity, high-risk
- ChangeIn forcev1.0.05 relations
Article 4 amended to a duty to take measures
praxikon:eu:ai-act:change:2026-07-27-article-4-amended
Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.
Hangs off: Article 4: AI literacy
Placed against the official source | ai-literacy
- ChangeIn forcev1.0.07 relations
Article 4a inserted, Article 10(5) deleted
praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted
Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Placed against the official source | fundamental-rights, high-risk-requirements
- ChangeIn forcev1.0.06 relations
FRIA follows new date and may cross-reference a DPIA
praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link
The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.
Hangs off: Article 27: FRIA
Placed against the official source | fundamental-rights, high-risk
- ChangeIn forcev1.0.02 relations
Machinery moves from Annex I, Section A, to Section B
praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b
Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | conformity, high-risk, scope
- ChangeIn forcev1.0.02 relations
Article 6 gains paragraphs 1a to 1c on safety components
praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed
Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk, scope
- ChangeUpcomingv1.0.02 relations
New prohibitions require technical safeguards
praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards
The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited, timeline
- ChangeUpcomingv1.0.04 relations
Legacy GPAI models must comply
praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply
Models placed on the market before 2 August 2025 have until 2 August 2027.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai, timeline
- ChangeUpcomingv1.0.01 relations
National AI regulatory sandboxes operational on 2 August 2027
praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational
The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.
Placed against the official source | governance, innovation
- ChangeUpcomingv1.0.02 relations
Template for the post-market monitoring plan becomes guidance, by 2 September 2027
praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template
Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.
Hangs off: Article 72: post-market monitoring
Placed against the official source | high-risk, post-market
- ChangeUpcomingv1.0.04 relations
High-risk AI embedded in regulated products
praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable
AI as a safety component of products under Annex I follows on 2 August 2028.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk, timeline
- ControlUpcomingv1.0.03 relations
Reassessment on a change of product or assessment route
praxikon:eu:ai-act:control:annex-i-product-route-change-gate
The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | control, high-risk
- ControlUpcomingv1.0.04 relations
Reassessment on a change of intended purpose
praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger
The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- Controlv1.0.04 relations
Reclassification on purpose or context change
praxikon:eu:ai-act:control:annex-iii-change-trigger
Reopen classification when intended purpose, use context or system functionality changes materially.
Hangs off: Annex III: high-risk AI
Editorially reviewed | control, high-risk
- Controlv1.0.04 relations
Data check before retraining
praxikon:eu:ai-act:control:article-10-data-governance-control
Repeat the data quality assessment before every retraining or dataset change.
Hangs off: Article 10: data and data governance
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Documentation update on every release
praxikon:eu:ai-act:control:article-11-technical-documentation-control
Update the file before every release and retain earlier versions traceably.
Hangs off: Article 11: technical documentation
Editorially reviewed | control, high-risk-requirements
Periodically verify that logging works, is complete and is retained according to the regime.
Hangs off: Article 12: logging and traceability
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Instructions check at deployment
praxikon:eu:ai-act:control:article-13-instructions-control
At every deployment and update, verify instructions are present, current and internally translated.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Oversight test before go-live
praxikon:eu:ai-act:control:article-14-human-oversight-control
Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.
Hangs off: Article 14: human oversight
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Performance monitoring in use
praxikon:eu:ai-act:control:article-15-accuracy-robustness-control
Monitor whether the system stays within declared levels in production and escalate on deviation.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Internal audit cycle
praxikon:eu:ai-act:control:article-17-quality-management-control
Periodically audit whether practice follows the described system and record deviations and improvements.
Hangs off: Article 17: quality management system
Editorially reviewed | control, high-risk-requirements
- ControlUpcomingv1.0.03 relations
Periodic check on completeness and retrievability of the retention file
praxikon:eu:ai-act:control:article-18-retention-review
The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.
Hangs off: Article 18: documentation keeping
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Periodic role and context review
praxikon:eu:ai-act:control:article-4-periodic-review
Check when systems, roles or risks change whether the selected measures remain appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, control
- Controlv1.0.04 relations
Article 5 gate at intake and change
praxikon:eu:ai-act:control:article-5-intake-gate
Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.
Hangs off: Article 5: prohibited practices
Editorially reviewed | control, prohibited-practices
- Controlv1.0.02 relations
Pre-release transparency check
praxikon:eu:ai-act:control:article-50-release-check
Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.
Editorially reviewed | control, transparency
- Controlv1.0.03 relations
Compute threshold monitoring
praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control
Monitor cumulative training compute and notify the Commission when the threshold is reached.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | control, gpai-systemic-risk
- ControlEditorialv1.0.04 relations
Review moment on your reliance on a code of practice
praxikon:eu:ai-act:control:article-56-code-commitment-review
The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | control, governance, gpai, gpai-systemic-risk
- Controlv1.0.04 relations
Signal-to-action loop
praxikon:eu:ai-act:control:article-72-post-market-monitoring-control
Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | control, post-market
- Controlv1.0.04 relations
Incident drill and deadline watch
praxikon:eu:ai-act:control:article-73-incident-reporting-control
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | control, post-market
- ControlEditorialv1.0.05 relations
Review before handing over source code or trade secrets
praxikon:eu:ai-act:control:article-78-disclosure-review
The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | control, enforcement, governance
- ControlEditorialv1.0.03 relations
Review of the overlap with sectoral product documentation
praxikon:eu:ai-act:control:article-8-integrated-documentation-review
The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, control, high-risk-requirements
- Controlv1.0.03 relations
Reassessment on every material change
praxikon:eu:ai-act:control:article-9-risk-management-control
Reopen the risk management process on changes in purpose, data, model or use context and before every release.
Hangs off: Article 9: risk management system
Editorially reviewed | control, high-risk-requirements
- ControlApplicablev1.0.05 relations
Access and deletion control for bias testing
praxikon:eu:ai-act:control:bias-testing-data-deletion
The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- Controlv1.0.04 relations
Reassessment on substantial modification
praxikon:eu:ai-act:control:conformity-ce-registration-control
Rerun the conformity route whenever the system is substantially modified.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, control
- ControlUpcomingv1.0.04 relations
Review gate on a design change
praxikon:eu:ai-act:control:design-change-review-gate
The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ControlUpcomingv1.0.04 relations
Currency check on the database entry
praxikon:eu:ai-act:control:eu-database-entry-currency
The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity, control
- Controlv1.0.05 relations
Pre-deployment FRIA go/no-go
praxikon:eu:ai-act:control:fria-pre-deployment-gate
Block deployment until applicability, assessment, mitigation and notification have been completed.
Hangs off: Article 27: FRIA
Editorially reviewed | control, fundamental-rights
- Controlv1.0.03 relations
GPAI documentation change control
praxikon:eu:ai-act:control:gpai-documentation-change-control
Update documentation and downstream information when the model, capabilities or risks change.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | control, gpai
- ControlApplicablev1.0.03 relations
Periodic review and termination of the mandate
praxikon:eu:ai-act:control:gpai-mandate-review
The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | control, gpai
- ControlEditorialv1.0.03 relations
Control on the continuity of your conformity assessment
praxikon:eu:ai-act:control:notified-body-continuity-review
The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, control, governance
- ControlEditorialv1.0.03 relations
Reassessment on a change of function or purpose
praxikon:eu:ai-act:control:safety-component-reassessment-trigger
The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ControlApplicablev1.0.03 relations
Deadline tracking of the notification
praxikon:eu:ai-act:control:systemic-risk-notification-deadline
The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Controlv1.0.04 relations
Role reassessment on every change
praxikon:eu:ai-act:control:value-chain-representative-control
Repeat the role assessment on every rebranding, modification or new use of an existing system.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | control, value-chain
- DefinitionUpcomingv1.0.03 relations
Annex III, point 1: biometrics
praxikon:eu:ai-act:definition:annex-iii-area-1-biometrics
Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 2: critical infrastructure
praxikon:eu:ai-act:definition:annex-iii-area-2-critical-infrastructure
Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 3: education and vocational training
praxikon:eu:ai-act:definition:annex-iii-area-3-education-and-vocational-training
Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 4: employment and workers management
praxikon:eu:ai-act:definition:annex-iii-area-4-employment-and-workers-management
Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 5: essential private and public services
praxikon:eu:ai-act:definition:annex-iii-area-5-essential-private-and-public-services
Annex III, point 5, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 6: law enforcement
praxikon:eu:ai-act:definition:annex-iii-area-6-law-enforcement
Annex III, point 6, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 7: migration, asylum and border control
praxikon:eu:ai-act:definition:annex-iii-area-7-migration-asylum-and-border-control
Annex III, point 7, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 8: administration of justice and democratic processes
praxikon:eu:ai-act:definition:annex-iii-area-8-justice-and-democratic-processes
Annex III, point 8, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- EvidenceUpcomingv1.0.03 relations
Product route record
praxikon:eu:ai-act:evidence:annex-i-product-route-record
Per product: the Annex I legal act, the section it falls under after 27 July 2026, the conformity assessment procedure chosen and whether a third party is involved, the harmonised standards any opt-out relies on, the AI functions identified as safety components together with the failure analysis, and the role you carry as a result. This is the file that shows why your system is or is not high risk through Article 6(1).
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | evidence, high-risk
- EvidenceUpcomingv1.0.04 relations
Record of the mapping to a point of Annex III
praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record
Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- Evidencev1.0.05 relations
Article 6 and Annex III classification record
praxikon:eu:ai-act:evidence:annex-iii-classification-record
Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.
Hangs off: Annex III: high-risk AI
Editorially reviewed | evidence, high-risk
- Evidencev1.0.04 relations
Data governance file
praxikon:eu:ai-act:evidence:article-10-data-governance-record
Record per dataset of origin, choices, assumptions, bias examination and mitigations.
Hangs off: Article 10: data and data governance
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Technical file (Annex IV)
praxikon:eu:ai-act:evidence:article-11-technical-documentation-record
Technical documentation kept current per system version, ready for a supervisor’s request.
Hangs off: Article 11: technical documentation
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Logs and retention regime
praxikon:eu:ai-act:evidence:article-12-logging-record
Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).
Hangs off: Article 12: logging and traceability
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Instructions and interpretation file
praxikon:eu:ai-act:evidence:article-13-instructions-record
The received instructions for use plus their internal translation into work instructions per role.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Oversight file per system
praxikon:eu:ai-act:evidence:article-14-human-oversight-record
Record of oversight measures, appointed persons, their training and the moments of intervention.
Hangs off: Article 14: human oversight
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Performance and security file
praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record
Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
QMS documentation
praxikon:eu:ai-act:evidence:article-17-quality-management-record
The documented quality system with procedures, role assignment and references to the underlying files.
Hangs off: Article 17: quality management system
Editorially reviewed | evidence, high-risk-requirements
- EvidenceUpcomingv1.0.03 relations
Retention file per high-risk system
praxikon:eu:ai-act:evidence:article-18-retention-dossier
Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.
Hangs off: Article 18: documentation keeping
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.05 relations
AI literacy measures record
praxikon:eu:ai-act:evidence:article-4-measures-record
Versioned record of roles, context, measures, participation or instruction and review moments.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, evidence
- Evidencev1.0.04 relations
Article 5 screening record
praxikon:eu:ai-act:evidence:article-5-screening-record
A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.
Hangs off: Article 5: prohibited practices
Editorially reviewed | evidence, prohibited-practices
- Evidencev1.0.02 relations
Transparency implementation record
praxikon:eu:ai-act:evidence:article-50-implementation-record
Record of scenario, actor, disclosure or marking, technical implementation, test and owner.
Editorially reviewed | evidence, transparency
- Evidencev1.0.03 relations
Systemic-risk file
praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record
Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | evidence, gpai-systemic-risk
- EvidenceEditorialv1.0.04 relations
Record of the decision on a code of practice
praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record
Per model: the decision whether or not to adhere to a code of practice, the version and chapter it relates to, the date and the authorised signatory, whether adherence was limited under paragraph 7 to the obligations in Article 53, and, where the decision is negative, the elaboration of your own for the issues in paragraph 2.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | evidence, governance, gpai, gpai-systemic-risk
- Evidencev1.0.04 relations
Monitoring plan and reports
praxikon:eu:ai-act:evidence:article-72-post-market-monitoring-record
The plan as part of the technical documentation plus the periodic analyses and follow-up actions.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | evidence, post-market
- Evidencev1.0.04 relations
Incident register and reports
praxikon:eu:ai-act:evidence:article-73-incident-reporting-record
Record of incidents, analyses, reports to supervisors and corrective measures.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | evidence, post-market
- EvidenceEditorialv1.0.05 relations
Register of submissions to authorities
praxikon:eu:ai-act:evidence:article-78-submission-register
Per submission: which system, which document, which version, to which recipient, on what date, which part was marked confidential, and which purpose the recipient stated.
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | enforcement, evidence, governance
- EvidenceEditorialv1.0.03 relations
Justification of the state of the art
praxikon:eu:ai-act:evidence:article-8-state-of-the-art-justification
Per system and per version: which intended purpose was taken, which standards, specifications, evaluation methods and test sets were treated as the state of the art, which were deliberately not applied and why, who established that, and on what date the record was reviewed again.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, evidence, high-risk-requirements
- Evidencev1.0.03 relations
Risk management file
praxikon:eu:ai-act:evidence:article-9-risk-management-record
Versioned record of risk analyses, chosen measures, residual risks and test results per system version.
Hangs off: Article 9: risk management system
Editorially reviewed | evidence, high-risk-requirements
- EvidenceApplicablev1.0.06 relations
Necessity file for bias testing
praxikon:eu:ai-act:evidence:bias-testing-necessity-record
Per processing operation: the system or model, the paragraph of Article 4a relied on, the justification why synthetic or anonymised data do not suffice, the technical and organisational safeguards applied, the access list, the confirmation that no other party can reach the data, and the deletion date. This is also the text that paragraph 1, point (f), requires in the record of processing activities.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- Evidencev1.0.04 relations
Conformity file
praxikon:eu:ai-act:evidence:conformity-ce-registration-record
The assessment, EU declaration of conformity, CE marking and registration proof, per system version.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, evidence
- EvidenceUpcomingv1.0.04 relations
EU database registration file
praxikon:eu:ai-act:evidence:eu-database-entry-record
Per system: which Annex VIII data was entered, by which natural person with the legal authority to do so, on what date, in which version, when the entry was last checked against reality, and for a public deployer the URL of the entry made by the provider. This is also the file that shows the public entry and your internal documents say the same thing.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity, evidence
Dated impact assessment, measures, residual risks and, where required, notification to the market surveillance authority.
Hangs off: Article 27: FRIA
Editorially reviewed | evidence, fundamental-rights
Current technical documentation, downstream information, copyright policy and public training summary.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | evidence, gpai
- EvidenceApplicablev1.0.03 relations
Mandate file of the authorised representative
praxikon:eu:ai-act:evidence:gpai-representative-mandate-file
The written mandate itself, in an official language of the institutions of the Union, together with the copy of the Annex XI technical documentation, the contact details of the provider, and the record of the verification under paragraph 3(a). The provider grants the mandate and supplies the documentation; the ten year retention after the placing on the market rests under paragraph 3(b) with the representative, which keeps the file at the disposal of the AI Office and national competent authorities.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | evidence, gpai
- EvidenceApplicablev1.0.04 relations
Transition register of legacy high-risk systems
praxikon:eu:ai-act:evidence:legacy-system-transition-register
Per type and model: the date the first unit was placed on the market or put into service, the route and therefore the cut off date, whether it is intended to be used by public authorities, which design changes have been made since that cut off, and per change the judgement whether it was significant with the reasoning and the date. This is the file that shows which track a system was on and why.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- EvidenceEditorialv1.0.03 relations
File on the chosen notified body
praxikon:eu:ai-act:evidence:notified-body-standing-record
Per body: identification number, Member State of establishment, the conformity assessment activities and system types for which it is notified, the date of each check against the public list, the outcome of the independence test, the subcontracted tasks with your written agreement, and every notice of a change to its designation.
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, evidence, governance
- EvidenceEditorialv1.0.03 relations
Record of the safety component assessment
praxikon:eu:ai-act:evidence:safety-component-assessment-record
Per AI component: the intended purpose, the function inside the product, the failure analysis with its consequence for health and safety, the basis of the third-party conformity assessment, and which of paragraphs 1a, 1b and 1c was applied and why. This is a self-maintained file; the Regulation does not prescribe it, and for products under Annex I, Section B, the technical documentation of Article 11 and Annex IV does not apply at all.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- EvidenceApplicablev1.0.03 relations
Systemic-risk notification file
praxikon:eu:ai-act:evidence:systemic-risk-notification-file
Per model version: the measured and planned training compute with the scope of recital 111, so including pre-training, synthetic data generation and fine-tuning, the moment the threshold was reached or foreseen, the notification sent with its supporting information, any arguments under paragraph 2, any reassessment request under paragraph 5, and the response or designation decision of the Commission.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Evidencev1.0.04 relations
Value-chain file
praxikon:eu:ai-act:evidence:value-chain-representative-record
Record per system of role, contractual arrangements on information and cooperation, and the appointment of a representative where required.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | evidence, value-chain
- ExampleEditorialv1.0.03 relations
Facial recognition at access control: the guard behind the camera counts too
praxikon:eu:ai-act:example:example-artikel-4-gezichtsherkenning-toegangscontrole
An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.
Hangs off: Article 4: AI literacy
Placed against the official source | examples
- ExampleEditorialv1.0.03 relations
Police using AI in investigations: context sets how deep the training goes
praxikon:eu:ai-act:example:example-artikel-4-politie-opsporingsanalyse
A police force uses AI to search large volumes of investigation files and surface connections a detective would otherwise miss. The outputs feed into the choice of which suspect is pursued further and end up in documents that enter the criminal process. The question is whether one and the same basic instruction is enough for the analyst operating the model and for the detective who acts on its output.
Hangs off: Article 4: AI literacy
Placed against the official source | examples
- ExampleEditorialv1.0.02 relations
Newsroom with generative AI: do freelancers count within your measures?
praxikon:eu:ai-act:example:example-artikel-4-redactie-generatieve-content
A newsroom uses generative AI to prepare summaries, headlines and imagery, after which an editor finishes the piece and the desk decides to publish. Part of that work sits with freelancers, and an outside agency produces marketing content with the same tools. The question is whether your AI literacy measures must reach those freelancers and that agency, or only the people on the payroll.
Hangs off: Article 4: AI literacy
Placed against the official source | examples
- ExampleEditorialv1.0.02 relations
AI chat in recruitment and selection: what the applicant must be told
praxikon:eu:ai-act:example:example-artikel-50-ai-chat-sollicitanten
A recruiter deploys an AI chat that puts candidates through a first screening conversation after they respond to a job posting, and adds their answers to their CV. The chat introduces itself with a first name and writes in a casual conversational tone. The question is whether these applicants reasonably realise that they are talking to an AI system.
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
Camera at the entrance: access control versus biometric categorisation
praxikon:eu:ai-act:example:example-artikel-50-camera-toegangscontrole-categorisatie
An organisation admits staff through facial recognition at its access control gate and additionally runs a camera in the visitor area that sorts faces into age groups. Both applications run on the same biometric infrastructure and the same images. The question is which of the two requires the people involved to be actively informed.
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
Code assistant for developers: an exception, until it faces outward
praxikon:eu:ai-act:example:example-artikel-50-code-assistent
A software company uses an AI assistant for code suggestions and code review, available only to professional developers. The same company also runs a helpdesk chatbot for customers.
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
Fraud reporting portal at a bank: why the law enforcement exception drops out
praxikon:eu:ai-act:example:example-artikel-50-fraudemeldportaal-bank
A bank opens an AI-driven reporting portal where customers can flag suspected fraud around their payment account or loan. The system asks follow-up questions, categorises the report and routes it to fraud detection and, where money laundering signals appear, to the internal reporting team. Because the portal concerns criminal offences, the bank assumes the disclosure duty for direct AI interaction does not apply.
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
AI text from a municipality: when a final check counts as editorial control
praxikon:eu:ai-act:example:example-artikel-50-gemeentelijke-ai-tekst
A municipality has an AI system write the web pages about a changed scheme for social assistance and allowances, meant to explain to citizens what they are entitled to. A communications officer reads the text for style and spelling and publishes it. The question is whether this public service thereby falls under the exception to the labelling duty.
Placed against the official source | examples
- ExampleGuidancev1.0.01 relations
Internal assistant for HR and compliance: an exception with a condition
praxikon:eu:ai-act:example:example-artikel-50-interne-medewerkersassistent
An organisation gives staff an internal AI assistant for HR, legal, procurement, compliance and IT questions. Must that assistant disclose at every turn that it is AI?
Placed against the official source | examples
- ExampleGuidancev1.0.01 relations
Diagnostic support for clinicians: no disclosure duty, still due care
praxikon:eu:ai-act:example:example-artikel-50-klinisch-beslissysteem
A hospital deploys an interactive AI system used exclusively by properly trained health professionals to support medical diagnosis and suggest treatments. The question is whether the patient or the clinician must be told it is AI.
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
Law enforcement: exempt from the disclosure duty, with safeguards
praxikon:eu:ai-act:example:example-artikel-50-opsporing-uitzondering
An authority empowered by law to detect criminal offences wants to deploy an interactive AI system without telling those involved that they are communicating with AI.
Placed against the official source | examples
- ExampleEditorialv1.0.03 relations
Performance scoring for staff goes wrong: report or not
praxikon:eu:ai-act:example:example-beoordelingssysteem-personeel-incidentmelding
An employer uses an AI system that scores employee performance and lets that score weigh in promotion and dismissal. After a change to the model it turns out that a group of staff was scored too low for months, and decisions have already been taken on those scores. HR wonders whether this is a serious incident and who would have to report it.
Hangs off: Article 73: serious incident reporting
Placed against the official source | examples
- ExampleGuidancev1.0.02 relations
Face comparison at the border gate: verification or identification
praxikon:eu:ai-act:example:example-biometrische-verificatie-grenspoort
An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.
Hangs off: Annex III: high-risk AI
Placed against the official source | examples
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.