Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Objects
34 objects in this selection.
- Actionv1.0.05 relations
Classify the use case and document the outcome
praxikon:eu:ai-act:action:annex-iii-classify
Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- ActionApplicablev1.0.03 relations
Appoint an authorised representative and record the mandate
praxikon:eu:ai-act:action:appoint-gpai-authorised-representative
Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | gpai, value-chain
- Actionv1.0.04 relations
Set up data governance per dataset
praxikon:eu:ai-act:action:article-10-data-governance-act
Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
Hangs off: Article 10: data and data governance
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Build the technical file per Annex IV
praxikon:eu:ai-act:action:article-11-technical-documentation-act
Document system description, development process, data, oversight measures, performance and risk management before market placement.
Hangs off: Article 11: technical documentation
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design logging into the system
praxikon:eu:ai-act:action:article-12-logging-act
Ensure the system automatically records events relevant to risk identification and post-market monitoring.
Hangs off: Article 12: logging and traceability
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Provide complete instructions for use
praxikon:eu:ai-act:action:article-13-instructions-act
Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design and assign effective human oversight
praxikon:eu:ai-act:action:article-14-human-oversight-act
Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.
Hangs off: Article 14: human oversight
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set and test performance and security levels
praxikon:eu:ai-act:action:article-15-accuracy-robustness-act
Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set up an AI quality management system
praxikon:eu:ai-act:action:article-17-quality-management-act
Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.
Hangs off: Article 17: quality management system
Editorially reviewed | high-risk-requirements
- Actionv1.0.05 relations
Take role- and context-specific AI literacy measures
praxikon:eu:ai-act:action:article-4-measures
Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Actionv1.0.04 relations
Screen every use case against Article 5 first
praxikon:eu:ai-act:action:article-5-screen
Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
Hangs off: Article 5: prohibited practices
Editorially reviewed | prohibited-practices
- Actionv1.0.02 relations
Implement the applicable disclosure, marking or label
praxikon:eu:ai-act:action:article-50-disclosure
First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Editorially reviewed | transparency
- Actionv1.0.03 relations
Perform model evaluations and risk mitigation
praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act
Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | gpai-systemic-risk
- Actionv1.0.04 relations
Draw up a post-market monitoring plan
praxikon:eu:ai-act:action:article-72-post-market-monitoring-act
Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | post-market
- Actionv1.0.04 relations
Set up an incident process with reporting routes
praxikon:eu:ai-act:action:article-73-incident-reporting-act
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | post-market
- ActionEditorialv1.0.03 relations
Record the state of the art and the intended purpose per system
praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline
Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, high-risk-requirements
- Actionv1.0.03 relations
Set up an iterative risk management process
praxikon:eu:ai-act:action:article-9-risk-management-act
Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.
Hangs off: Article 9: risk management system
Editorially reviewed | high-risk-requirements
- ActionEditorialv1.0.03 relations
Determine and record whether your AI component is a safety component
praxikon:eu:ai-act:action:assess-safety-component-role
Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ActionUpcomingv1.0.04 relations
Assess for every design change whether it is significant
praxikon:eu:ai-act:action:assess-significant-design-change
Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- Actionv1.0.04 relations
Complete the conformity route before market placement
praxikon:eu:ai-act:action:conformity-ce-registration-act
Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity
- ActionEditorialv1.0.04 relations
Take and record the decision whether you adhere to a code of practice
praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence
Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | governance, gpai, gpai-systemic-risk
- ActionUpcomingv1.0.05 relations
Enter your data in the EU database and keep it up to date
praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data
Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity
- ActionUpcomingv1.0.03 relations
Establish the product route per product
praxikon:eu:ai-act:action:establish-annex-i-product-route
Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | conformity, high-risk
Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
Hangs off: Article 27: FRIA
Editorially reviewed | fundamental-rights, high-risk
- Actionv1.0.03 relations
Maintain GPAI documentation and transparency information
praxikon:eu:ai-act:action:gpai-document
Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | gpai
- ActionUpcomingv1.0.03 relations
Set up the ten year retention of the system documentation
praxikon:eu:ai-act:action:keep-high-risk-documentation-available
Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.
Hangs off: Article 18: documentation keeping
Editorially reviewed | high-risk-requirements
- ActionUpcomingv1.0.04 relations
Map every system to a point of Annex III
praxikon:eu:ai-act:action:map-system-to-annex-iii-area
Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- ActionEditorialv1.0.05 relations
Mark and register what you submit to an authority or body
praxikon:eu:ai-act:action:mark-confidential-material-on-submission
State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | enforcement, governance
- ActionApplicablev1.0.03 relations
Notify the Commission within two weeks
praxikon:eu:ai-act:action:notify-systemic-risk-threshold
Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- ActionApplicablev1.0.04 relations
Plan compliance for legacy public sector systems by 2 August 2030
praxikon:eu:ai-act:action:plan-legacy-public-system-compliance
Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ActionApplicablev1.0.06 relations
Justify and record your reliance on Article 4a
praxikon:eu:ai-act:action:record-bias-testing-legal-basis
Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- ActionApplicablev1.0.03 relations
Request reassessment after a designation
praxikon:eu:ai-act:action:request-systemic-risk-reassessment
If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Actionv1.0.04 relations
Assess the value-chain role per system and change
praxikon:eu:ai-act:action:value-chain-representative-act
On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | value-chain
- ActionEditorialv1.0.03 relations
Check the standing and independence of your notified body
praxikon:eu:ai-act:action:verify-notified-body-standing
At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, governance
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.