Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Active filters
Objects
150 of 298 shown. Pick a type below or narrow with a filter to see the rest.
- Actionv1.0.05 relations
Classify the use case and document the outcome
praxikon:eu:ai-act:action:annex-iii-classify
Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- ActionApplicablev1.0.03 relations
Appoint an authorised representative and record the mandate
praxikon:eu:ai-act:action:appoint-gpai-authorised-representative
Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | gpai, value-chain
- Actionv1.0.04 relations
Set up data governance per dataset
praxikon:eu:ai-act:action:article-10-data-governance-act
Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.
Hangs off: Article 10: data and data governance
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Build the technical file per Annex IV
praxikon:eu:ai-act:action:article-11-technical-documentation-act
Document system description, development process, data, oversight measures, performance and risk management before market placement.
Hangs off: Article 11: technical documentation
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design logging into the system
praxikon:eu:ai-act:action:article-12-logging-act
Ensure the system automatically records events relevant to risk identification and post-market monitoring.
Hangs off: Article 12: logging and traceability
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Provide complete instructions for use
praxikon:eu:ai-act:action:article-13-instructions-act
Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | high-risk-requirements
- Actionv1.0.04 relations
Design and assign effective human oversight
praxikon:eu:ai-act:action:article-14-human-oversight-act
Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.
Hangs off: Article 14: human oversight
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set and test performance and security levels
praxikon:eu:ai-act:action:article-15-accuracy-robustness-act
Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Set up an AI quality management system
praxikon:eu:ai-act:action:article-17-quality-management-act
Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.
Hangs off: Article 17: quality management system
Editorially reviewed | high-risk-requirements
- Actionv1.0.05 relations
Take role- and context-specific AI literacy measures
praxikon:eu:ai-act:action:article-4-measures
Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Actionv1.0.04 relations
Screen every use case against Article 5 first
praxikon:eu:ai-act:action:article-5-screen
Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
Hangs off: Article 5: prohibited practices
Editorially reviewed | prohibited-practices
- Actionv1.0.05 relations
Implement the applicable disclosure, marking or label
praxikon:eu:ai-act:action:article-50-disclosure
First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- Actionv1.0.03 relations
Perform model evaluations and risk mitigation
praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act
Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | gpai-systemic-risk
- ActionApplicablev1.0.04 relations
Inform the test subject and obtain consent to participate
praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent
Give every test subject concise, clear, relevant and understandable information beforehand on the five points of Article 61(1), then obtain freely-given informed consent, date and document that consent, and give a copy to the subject or the legal representative.
Hangs off: Article 61: informed consent of test subjects for testing in real world conditions
Editorially reviewed | fundamental-rights, innovation
- ActionEditorialv1.0.04 relations
Make use of the SME facilities in Article 62
praxikon:eu:ai-act:action:article-62-claim-sme-facilities
Apply for priority access to the AI regulatory sandbox, use the national communication channel for questions about implementation, sign up for the standardisation process, and on a conformity assessment under Article 43 ask how the fee reduction has been applied.
Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups
Editorially reviewed | governance, innovation
- ActionEditorialv1.0.03 relations
Determine and bound the simplification of your quality management system
praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management
Test whether you are a microenterprise with no partner or linked enterprises, build the Article 17 system, mark which elements you would want to simplify once the Commission guidelines exist, and keep the nine articles of Article 63(2) expressly outside that simplification.
Hangs off: Article 63: derogations for SMEs in the quality management system
Editorially reviewed | high-risk-requirements, innovation
- Actionv1.0.04 relations
Draw up a post-market monitoring plan
praxikon:eu:ai-act:action:article-72-post-market-monitoring-act
Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | post-market
- Actionv1.0.04 relations
Set up an incident process with reporting routes
praxikon:eu:ai-act:action:article-73-incident-reporting-act
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | post-market
- ActionEditorialv1.0.03 relations
Record the state of the art and the intended purpose per system
praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline
Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, high-risk-requirements
- Actionv1.0.03 relations
Set up an iterative risk management process
praxikon:eu:ai-act:action:article-9-risk-management-act
Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.
Hangs off: Article 9: risk management system
Editorially reviewed | high-risk-requirements
- ActionEditorialv1.0.04 relations
Scope a voluntary code of conduct and separate it from your duties
praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code
Choose the paragraph 1 or the paragraph 2 route, name which requirements you apply voluntarily and which you do not, give the code clear objectives and key performance indicators, and keep the voluntary commitments administratively separate from the obligations that continue to apply in full.
Hangs off: Article 95: codes of conduct for voluntary application of specific requirements
Editorially reviewed | governance, innovation
- ActionEditorialv1.0.05 relations
Assign to each obligation the penalty ceiling that belongs to it
praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers
Walk through your obligations register and mark per line which ceiling applies: Article 99(3) for Article 5, Article 99(4) for the role duties enumerated there, Article 25(2) and (4) and Article 50, Article 99(5) for answering information requests, and otherwise the national penalty regime under Article 99(1). Add the Article 101 regime wherever you provide a general-purpose AI model yourself, and the Article 75c regime wherever the AI Office is competent.
Hangs off: Article 99, 100 and 101: the penalty structure per obligation
Editorially reviewed | enforcement, governance
- ActionEditorialv1.0.03 relations
Determine and record whether your AI component is a safety component
praxikon:eu:ai-act:action:assess-safety-component-role
Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ActionUpcomingv1.0.04 relations
Assess for every design change whether it is significant
praxikon:eu:ai-act:action:assess-significant-design-change
Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- Actionv1.0.04 relations
Complete the conformity route before market placement
praxikon:eu:ai-act:action:conformity-ce-registration-act
Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity
- ActionEditorialv1.0.04 relations
Take and record the decision whether you adhere to a code of practice
praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence
Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | governance, gpai, gpai-systemic-risk
- ActionUpcomingv1.0.05 relations
Enter your data in the EU database and keep it up to date
praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data
Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity
- ActionUpcomingv1.0.03 relations
Establish the product route per product
praxikon:eu:ai-act:action:establish-annex-i-product-route
Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | conformity, high-risk
Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
Hangs off: Article 27: FRIA
Editorially reviewed | fundamental-rights, high-risk
- Actionv1.0.04 relations
Maintain GPAI documentation and transparency information
praxikon:eu:ai-act:action:gpai-document
Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | gpai
- ActionApplicablev1.0.03 relations
Set up how you handle a request for an explanation
praxikon:eu:ai-act:action:handle-explanation-requests
Ensure your complaints or objections desk recognises a request for an explanation of an AI-supported decision, that it can be traced per decision which system in which version contributed to it, and that someone is designated to give the explanation.
Hangs off: Article 86: right to an explanation of a decision
Editorially reviewed | fundamental-rights
- ActionEditorialv1.0.04 relations
Record per requirement which standard or specification you rely on, and justify every departure
praxikon:eu:ai-act:action:justify-standards-and-specification-choices
Keep a coverage matrix of the requirements of Section 2 against the harmonised standards, common specifications and own documents applied, noting per row the publication status in the Official Journal, and write out the Article 41(5) justification for every common specification you do not apply.
Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity
Editorially reviewed | conformity, standards
- ActionUpcomingv1.0.03 relations
Set up the ten year retention of the system documentation
praxikon:eu:ai-act:action:keep-high-risk-documentation-available
Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.
Hangs off: Article 18: documentation keeping
Editorially reviewed | high-risk-requirements
- Actionv1.0.03 relations
Manage the life of the certificate
praxikon:eu:ai-act:action:manage-notified-body-certificate
A practical working out for whoever holds a certificate: watch the expiry date, ask in time for the re-assessment that carries the extension, test every change against the substantial modification of Article 43(4), and make sure a deadline set by the body for corrective action reaches an identifiable person. Also track the body itself, because on cessation or withdrawal of its designation the deadlines of Article 36 apply.
Hangs off: Article 44: certificates of notified bodies
Editorially reviewed | conformity
- ActionUpcomingv1.0.04 relations
Map every system to a point of Annex III
praxikon:eu:ai-act:action:map-system-to-annex-iii-area
Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- ActionEditorialv1.0.05 relations
Mark and register what you submit to an authority or body
praxikon:eu:ai-act:action:mark-confidential-material-on-submission
State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | enforcement, governance
- ActionApplicablev1.0.03 relations
Notify the Commission within two weeks
praxikon:eu:ai-act:action:notify-systemic-risk-threshold
Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- ActionEditorialv1.0.04 relations
Make sure a report about an AI system reaches your reporting channel
praxikon:eu:ai-act:action:open-a-protected-reporting-route
Only for organisations that must already have a reporting arrangement. Make visible in it that an infringement of the AI Regulation is a reportable infringement, designate who receives such a report, agree how the identity of the person reporting stays out of the rest of the process, and record whether you handle anonymous reports.
Hangs off: Article 87: reporting of infringements and protection of reporting persons
Editorially reviewed | fundamental-rights, governance
- ActionApplicablev1.0.04 relations
Plan compliance for legacy public sector systems by 2 August 2030
praxikon:eu:ai-act:action:plan-legacy-public-system-compliance
Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ActionEditorialv1.0.05 relations
Prepare a derogation request and the exit plan that goes with it
praxikon:eu:ai-act:action:prepare-article-46-derogation-request
Write in advance the reasoning paragraph 1 calls for, with the exceptional reason invoked, the evidence that the system complies with the requirements of Section 2, the status of the ongoing conformity assessment, and an exit plan in case the authorisation is refused or withdrawn.
Hangs off: Article 46: derogation from conformity assessment procedure
Editorially reviewed | conformity, enforcement
- ActionApplicablev1.0.03 relations
Make sure you can answer a complaint with documents
praxikon:eu:ai-act:action:prepare-for-a-complaint
Record per AI system which assessment was carried out, by whom, on what date and against which system version, and agree who receives a question from the authority and within what period.
Hangs off: Article 85: right to lodge a complaint with the market surveillance authority
Editorially reviewed | fundamental-rights
- ActionApplicablev1.0.06 relations
Justify and record your reliance on Article 4a
praxikon:eu:ai-act:action:record-bias-testing-legal-basis
Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- ActionApplicablev1.0.05 relations
Register yourself and the system before it reaches the market or is put into service
praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry
Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used.
Hangs off: Article 49: registration in the EU database before the system reaches the market
Editorially reviewed | conformity, high-risk
- ActionApplicablev1.0.03 relations
Request reassessment after a designation
praxikon:eu:ai-act:action:request-systemic-risk-reassessment
If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Actionv1.0.04 relations
Assess the value-chain role per system and change
praxikon:eu:ai-act:action:value-chain-representative-act
On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | value-chain
- ActionEditorialv1.0.03 relations
Check the standing and independence of your notified body
praxikon:eu:ai-act:action:verify-notified-body-standing
At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, governance
The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.
Editorially reviewed | enforcement, governance, gpai
- Actorv1.0.08 relations
Credit or insurance deployer
praxikon:eu:ai-act:actor:credit-or-insurance-deployer
A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).
Editorially reviewed | fundamental-rights, high-risk
An organisation using an AI system under its authority, excluding personal non-professional use.
Editorially reviewed | governance
A party that places a general-purpose AI model on the Union market.
Editorially reviewed | gpai
- Actorv1.0.08 relations
Market surveillance authority
praxikon:eu:ai-act:actor:market-surveillance-authority
The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.
Editorially reviewed | enforcement, governance
A party that develops or has an AI system developed and places it on the market under its own name.
Editorially reviewed | governance
A deployer that is a body governed by public law.
Editorially reviewed | fundamental-rights
- Actorv1.0.09 relations
Private provider of public services
praxikon:eu:ai-act:actor:public-service-provider
A private deployer providing public services.
Editorially reviewed | fundamental-rights
- ChangeApplicablev1.0.04 relations
The AI Act enters into force
praxikon:eu:ai-act:change:2024-08-01-entry-into-force
The regulation entered into force on 1 August 2024, after which the obligations followed in phases.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | timeline
- ChangeApplicablev1.0.04 relations
Prohibited practices and AI literacy apply
praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable
Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.
Hangs off: Article 4: AI literacy, Article 5: prohibited practices
Placed against the official source | ai-literacy, timeline
- ChangeGuidancev1.0.02 relations
General-Purpose AI Code of Practice published
praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice
The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.
Hangs off: Article 53: GPAI model providers
Placed against the official source | gpai
- ChangeGuidancev1.0.03 relations
Guidelines on the scope of the GPAI obligations
praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines
The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai
- ChangeGuidancev1.0.04 relations
Guidelines on the definition of an AI system
praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines
The Commission draws the line between software that does and does not fall under the regulation.
Hangs off: Annex III: high-risk AI, Article 4: AI literacy
Placed against the official source | scope
- ChangeGuidancev1.0.03 relations
Guidelines on prohibited AI practices
praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines
Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited
- ChangeApplicablev1.0.03 relations
GPAI model obligations apply
praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable
Since 2 August 2025 the obligations for providers of general-purpose AI models apply.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai, timeline
- ChangeGuidancev1.0.04 relations
Draft guidelines on high-risk classification
praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines
The Commission explains in consultation when a system falls under Annex I or Annex III.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk
- ChangeGuidancev1.0.03 relations
Transparency Code of Practice published
praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice
A voluntary route to comply with parts of Article 50, in two separately signable sections.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeGuidancev1.0.02 relations
First European AI Act standard approved
praxikon:eu:ai-act:change:2026-07-12-en-18286-approved
EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.
Hangs off: Article 17: quality management system
Placed against the official source | standards
- ChangeGuidancev1.0.03 relations
Final guidelines on Article 50
praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines
The Commission works out the transparency duties and confirms they apply from 2 August 2026.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeIn forcev1.0.08 relations
Annex III core rules moved to 2 December 2027
praxikon:eu:ai-act:change:2026-07-27-annex-iii-date
The amended application date has been binding law since 27 July 2026.
Hangs off: Annex III: high-risk AI
Placed against the official source | high-risk
- ChangeIn forcev1.0.02 relations
New Article 2(13): requirements for Annex I systems may be limited
praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation
Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | conformity, high-risk
- ChangeIn forcev1.0.05 relations
Article 4 amended to a duty to take measures
praxikon:eu:ai-act:change:2026-07-27-article-4-amended
Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.
Hangs off: Article 4: AI literacy
Placed against the official source | ai-literacy
- ChangeIn forcev1.0.07 relations
Article 4a inserted, Article 10(5) deleted
praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted
Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Placed against the official source | fundamental-rights, high-risk-requirements
- ChangeIn forcev1.0.06 relations
FRIA follows new date and may cross-reference a DPIA
praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link
The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.
Hangs off: Article 27: FRIA
Placed against the official source | fundamental-rights, high-risk
- ChangeIn forcev1.0.02 relations
Machinery moves from Annex I, Section A, to Section B
praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b
Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | conformity, high-risk, scope
- ChangeIn forcev1.0.02 relations
Article 6 gains paragraphs 1a to 1c on safety components
praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed
Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).
Hangs off: Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk, scope
- ChangeApplicablev1.0.05 relations
Article 50 is applicable
praxikon:eu:ai-act:change:2026-08-02-article-50-applicable
The transparency duties apply since 2 August 2026.
Hangs off: Article 50: transparency
Placed against the official source | transparency
- ChangeApplicablev1.0.05 relations
GPAI enforcement powers active
praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement
Since 2 August 2026 the Commission can request GPAI information, conduct evaluations and require measures.
Hangs off: Article 53: GPAI model providers
Placed against the official source | enforcement, gpai
- ChangeUpcomingv1.0.03 relations
Grace period for machine-readable marking ends
praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends
Systems placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.
Hangs off: Article 50: transparency
Placed against the official source | timeline, transparency
- ChangeUpcomingv1.0.02 relations
New prohibitions require technical safeguards
praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards
The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.
Hangs off: Article 5: prohibited practices
Placed against the official source | prohibited, timeline
- ChangeUpcomingv1.0.04 relations
Legacy GPAI models must comply
praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply
Models placed on the market before 2 August 2025 have until 2 August 2027.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai, timeline
- ChangeUpcomingv1.0.01 relations
National AI regulatory sandboxes operational on 2 August 2027
praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational
The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.
Placed against the official source | governance, innovation
- ChangeUpcomingv1.0.02 relations
Template for the post-market monitoring plan becomes guidance, by 2 September 2027
praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template
Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.
Hangs off: Article 72: post-market monitoring
Placed against the official source | high-risk, post-market
- ChangeUpcomingv1.0.04 relations
High-risk AI embedded in regulated products
praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable
AI as a safety component of products under Annex I follows on 2 August 2028.
Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration
Placed against the official source | high-risk, timeline
- ControlUpcomingv1.0.03 relations
Reassessment on a change of product or assessment route
praxikon:eu:ai-act:control:annex-i-product-route-change-gate
The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | control, high-risk
- ControlUpcomingv1.0.04 relations
Reassessment on a change of intended purpose
praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger
The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- Controlv1.0.04 relations
Reclassification on purpose or context change
praxikon:eu:ai-act:control:annex-iii-change-trigger
Reopen classification when intended purpose, use context or system functionality changes materially.
Hangs off: Annex III: high-risk AI
Editorially reviewed | control, high-risk
- Controlv1.0.04 relations
Data check before retraining
praxikon:eu:ai-act:control:article-10-data-governance-control
Repeat the data quality assessment before every retraining or dataset change.
Hangs off: Article 10: data and data governance
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Documentation update on every release
praxikon:eu:ai-act:control:article-11-technical-documentation-control
Update the file before every release and retain earlier versions traceably.
Hangs off: Article 11: technical documentation
Editorially reviewed | control, high-risk-requirements
Periodically verify that logging works, is complete and is retained according to the regime.
Hangs off: Article 12: logging and traceability
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Instructions check at deployment
praxikon:eu:ai-act:control:article-13-instructions-control
At every deployment and update, verify instructions are present, current and internally translated.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Oversight test before go-live
praxikon:eu:ai-act:control:article-14-human-oversight-control
Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.
Hangs off: Article 14: human oversight
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Performance monitoring in use
praxikon:eu:ai-act:control:article-15-accuracy-robustness-control
Monitor whether the system stays within declared levels in production and escalate on deviation.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Internal audit cycle
praxikon:eu:ai-act:control:article-17-quality-management-control
Periodically audit whether practice follows the described system and record deviations and improvements.
Hangs off: Article 17: quality management system
Editorially reviewed | control, high-risk-requirements
- ControlUpcomingv1.0.03 relations
Periodic check on completeness and retrievability of the retention file
praxikon:eu:ai-act:control:article-18-retention-review
The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.
Hangs off: Article 18: documentation keeping
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Periodic role and context review
praxikon:eu:ai-act:control:article-4-periodic-review
Check when systems, roles or risks change whether the selected measures remain appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, control
- ControlEditorialv1.0.05 relations
Review of an authorisation expiring, being refused or withdrawn
praxikon:eu:ai-act:control:article-46-derogation-exit-review
The control that keeps a system running under Article 46 under watch: the ongoing conformity assessment has an owner and an end date, the fifteen calendar days of paragraph 4 are in the calendar, and a rehearsed plan is in place to stop use with immediate effect and discard all results and outputs if the authorisation is refused or withdrawn.
Hangs off: Article 46: derogation from conformity assessment procedure
Editorially reviewed | conformity, control, enforcement
- ControlApplicablev1.0.05 relations
Release gate: no market entry without registration
praxikon:eu:ai-act:control:article-49-pre-market-registration-gate
The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.
Hangs off: Article 49: registration in the EU database before the system reaches the market
Editorially reviewed | conformity, control, high-risk
- Controlv1.0.04 relations
Article 5 gate at intake and change
praxikon:eu:ai-act:control:article-5-intake-gate
Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.
Hangs off: Article 5: prohibited practices
Editorially reviewed | control, prohibited-practices
- Controlv1.0.04 relations
Pre-release transparency check
praxikon:eu:ai-act:control:article-50-release-check
Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.
Hangs off: Article 50: transparency
Editorially reviewed | control, transparency
- Controlv1.0.03 relations
Compute threshold monitoring
praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control
Monitor cumulative training compute and notify the Commission when the threshold is reached.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | control, gpai-systemic-risk
- ControlEditorialv1.0.04 relations
Review moment on your reliance on a code of practice
praxikon:eu:ai-act:control:article-56-code-commitment-review
The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | control, governance, gpai, gpai-systemic-risk
- ControlEditorialv1.0.04 relations
Consent and withdrawal review before a test in real world conditions starts
praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review
The control that no subject participates before the information pack is complete, the consent record is dated and a copy has been given, and that the withdrawal route with its recipient, period and deletion step works and has been rehearsed once.
Hangs off: Article 61: informed consent of test subjects for testing in real world conditions
Editorially reviewed | control, fundamental-rights, innovation
- ControlEditorialv1.0.04 relations
Fee and access review on a conformity assessment
praxikon:eu:ai-act:control:article-62-fee-and-access-review
The control that on every application for a conformity assessment under Article 43 and on every sandbox application it is checked whether the SME facilities have been invoked and whether the proportionate fee reduction has been made visible, and that the answer reaches the procurement file.
Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups
Editorially reviewed | control, governance, innovation
- ControlEditorialv1.0.03 relations
Review of the boundary of the simplification
praxikon:eu:ai-act:control:article-63-simplification-boundary-review
The control that every simplification you make under Article 63 is tested against paragraph 2, so that no item from Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73 falls away, and that the shareholding structure test is redone at every change.
Hangs off: Article 63: derogations for SMEs in the quality management system
Editorially reviewed | control, high-risk-requirements, innovation
- Controlv1.0.04 relations
Signal-to-action loop
praxikon:eu:ai-act:control:article-72-post-market-monitoring-control
Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | control, post-market
- Controlv1.0.04 relations
Incident drill and deadline watch
praxikon:eu:ai-act:control:article-73-incident-reporting-control
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | control, post-market
- ControlEditorialv1.0.05 relations
Review before handing over source code or trade secrets
praxikon:eu:ai-act:control:article-78-disclosure-review
The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | control, enforcement, governance
- ControlEditorialv1.0.03 relations
Review of the overlap with sectoral product documentation
praxikon:eu:ai-act:control:article-8-integrated-documentation-review
The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, control, high-risk-requirements
- Controlv1.0.03 relations
Reassessment on every material change
praxikon:eu:ai-act:control:article-9-risk-management-control
Reopen the risk management process on changes in purpose, data, model or use context and before every release.
Hangs off: Article 9: risk management system
Editorially reviewed | control, high-risk-requirements
- ControlEditorialv1.0.04 relations
Review that keeps voluntary and mandatory apart
praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review
The control that no external statement, quotation, tender response or annual report presents a code of conduct as cover for an obligation under the Regulation, and that every voluntary commitment has an owner, an indicator and a moment of measurement before it goes out.
Hangs off: Article 95: codes of conduct for voluntary application of specific requirements
Editorially reviewed | control, governance, innovation
- ControlEditorialv1.0.05 relations
Recording of the factors in Article 99(7)
praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record
The control that ensures the factors which determine the amount of a fine are recorded at the time and not reconstructed afterwards: which technical and organisational measures were in place, when you notified an infringement yourself, how you responded to requests from the authority, and what you did to mitigate the harm suffered by affected persons. Those factors cut both ways, so the same record can also count against you; that is a reason to keep it properly rather than not at all.
Hangs off: Article 99, 100 and 101: the penalty structure per obligation
Editorially reviewed | control, enforcement
- ControlApplicablev1.0.05 relations
Access and deletion control for bias testing
praxikon:eu:ai-act:control:bias-testing-data-deletion
The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- Controlv1.0.03 relations
Monitoring of certificate, modification and body
praxikon:eu:ai-act:control:certificate-expiry-monitoring
The control that ensures three signals reach an identifiable person in time instead of surfacing only once the certificate has already lapsed or been suspended: an approaching expiry date, a change that may be substantial within the meaning of Article 43(4), and a notice from or about the notified body itself, including the notification within ten days on suspension, restriction or withdrawal of its designation and the confirmation that Article 36(8), point (b), requires from the provider within three months.
Hangs off: Article 44: certificates of notified bodies
Editorially reviewed | conformity, control
- Controlv1.0.04 relations
Reassessment on substantial modification
praxikon:eu:ai-act:control:conformity-ce-registration-control
Rerun the conformity route whenever the system is substantially modified.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, control
- ControlUpcomingv1.0.04 relations
Review gate on a design change
praxikon:eu:ai-act:control:design-change-review-gate
The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ControlUpcomingv1.0.04 relations
Currency check on the database entry
praxikon:eu:ai-act:control:eu-database-entry-currency
The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity, control
- ControlApplicablev1.0.05 relations
Routing and deadline tracking of a request for an explanation
praxikon:eu:ai-act:control:explanation-request-routing
The control that ensures an incoming request reaches an identifiable person within a set period and is answered, instead of sitting in a general inbox.
Hangs off: Article 85: right to lodge a complaint with the market surveillance authority, Article 86: right to an explanation of a decision
Editorially reviewed | fundamental-rights
- Controlv1.0.05 relations
Pre-deployment FRIA go/no-go
praxikon:eu:ai-act:control:fria-pre-deployment-gate
Block deployment until applicability, assessment, mitigation and notification have been completed.
Hangs off: Article 27: FRIA
Editorially reviewed | control, fundamental-rights
- Controlv1.0.03 relations
GPAI documentation change control
praxikon:eu:ai-act:control:gpai-documentation-change-control
Update documentation and downstream information when the model, capabilities or risks change.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | control, gpai
- ControlApplicablev1.0.03 relations
Periodic review and termination of the mandate
praxikon:eu:ai-act:control:gpai-mandate-review
The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | control, gpai
- ControlEditorialv1.0.03 relations
Control on the continuity of your conformity assessment
praxikon:eu:ai-act:control:notified-body-continuity-review
The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, control, governance
- ControlEditorialv1.0.04 relations
Watch on publications in the Official Journal
praxikon:eu:ai-act:control:official-journal-citation-watch
The control that keeps the coverage matrix current: a fixed check on new references of harmonised standards, on new or amended common specifications, and on the repeal that Article 41(4) prescribes once a standard is published, with a named owner who then updates the matrix.
Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity
Editorially reviewed | conformity, control, standards
- ControlEditorialv1.0.04 relations
Protection of the person reporting
praxikon:eu:ai-act:control:reporting-person-protection
The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.
Hangs off: Article 87: reporting of infringements and protection of reporting persons
Editorially reviewed | control, fundamental-rights
- ControlEditorialv1.0.03 relations
Reassessment on a change of function or purpose
praxikon:eu:ai-act:control:safety-component-reassessment-trigger
The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ControlApplicablev1.0.03 relations
Deadline tracking of the notification
praxikon:eu:ai-act:control:systemic-risk-notification-deadline
The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Controlv1.0.04 relations
Role reassessment on every change
praxikon:eu:ai-act:control:value-chain-representative-control
Repeat the role assessment on every rebranding, modification or new use of an existing system.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | control, value-chain
- DefinitionUpcomingv1.0.03 relations
Annex III, point 1: biometrics
praxikon:eu:ai-act:definition:annex-iii-area-1-biometrics
Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 2: critical infrastructure
praxikon:eu:ai-act:definition:annex-iii-area-2-critical-infrastructure
Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 3: education and vocational training
praxikon:eu:ai-act:definition:annex-iii-area-3-education-and-vocational-training
Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 4: employment and workers management
praxikon:eu:ai-act:definition:annex-iii-area-4-employment-and-workers-management
Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 5: essential private and public services
praxikon:eu:ai-act:definition:annex-iii-area-5-essential-private-and-public-services
Annex III, point 5, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 6: law enforcement
praxikon:eu:ai-act:definition:annex-iii-area-6-law-enforcement
Annex III, point 6, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 7: migration, asylum and border control
praxikon:eu:ai-act:definition:annex-iii-area-7-migration-asylum-and-border-control
Annex III, point 7, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- DefinitionUpcomingv1.0.03 relations
Annex III, point 8: administration of justice and democratic processes
praxikon:eu:ai-act:definition:annex-iii-area-8-justice-and-democratic-processes
Annex III, point 8, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.
Hangs off: Annex III: the eight areas separately
Placed against the official source | high-risk
- EvidenceUpcomingv1.0.03 relations
Product route record
praxikon:eu:ai-act:evidence:annex-i-product-route-record
Per product: the Annex I legal act, the section it falls under after 27 July 2026, the conformity assessment procedure chosen and whether a third party is involved, the harmonised standards any opt-out relies on, the AI functions identified as safety components together with the failure analysis, and the role you carry as a result. This is the file that shows why your system is or is not high risk through Article 6(1).
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | evidence, high-risk
- EvidenceUpcomingv1.0.04 relations
Record of the mapping to a point of Annex III
praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record
Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- Evidencev1.0.05 relations
Article 6 and Annex III classification record
praxikon:eu:ai-act:evidence:annex-iii-classification-record
Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.
Hangs off: Annex III: high-risk AI
Editorially reviewed | evidence, high-risk
- Evidencev1.0.04 relations
Data governance file
praxikon:eu:ai-act:evidence:article-10-data-governance-record
Record per dataset of origin, choices, assumptions, bias examination and mitigations.
Hangs off: Article 10: data and data governance
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Technical file (Annex IV)
praxikon:eu:ai-act:evidence:article-11-technical-documentation-record
Technical documentation kept current per system version, ready for a supervisor’s request.
Hangs off: Article 11: technical documentation
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Logs and retention regime
praxikon:eu:ai-act:evidence:article-12-logging-record
Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).
Hangs off: Article 12: logging and traceability
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Instructions and interpretation file
praxikon:eu:ai-act:evidence:article-13-instructions-record
The received instructions for use plus their internal translation into work instructions per role.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.04 relations
Oversight file per system
praxikon:eu:ai-act:evidence:article-14-human-oversight-record
Record of oversight measures, appointed persons, their training and the moments of intervention.
Hangs off: Article 14: human oversight
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
Performance and security file
praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record
Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.03 relations
QMS documentation
praxikon:eu:ai-act:evidence:article-17-quality-management-record
The documented quality system with procedures, role assignment and references to the underlying files.
Hangs off: Article 17: quality management system
Editorially reviewed | evidence, high-risk-requirements
- EvidenceUpcomingv1.0.03 relations
Retention file per high-risk system
praxikon:eu:ai-act:evidence:article-18-retention-dossier
Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.
Hangs off: Article 18: documentation keeping
Editorially reviewed | evidence, high-risk-requirements
- Evidencev1.0.05 relations
AI literacy measures record
praxikon:eu:ai-act:evidence:article-4-measures-record
Versioned record of roles, context, measures, participation or instruction and review moments.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, evidence
- EvidenceEditorialv1.0.05 relations
File accompanying a request to derogate from the conformity assessment
praxikon:eu:ai-act:evidence:article-46-derogation-request-file
Per request: which system and which version, which exceptional reason was invoked and on which facts, to which market surveillance authority and on what date the request was made, what the status of the conformity assessment was, which end date was agreed, when the notification of paragraph 3 was made, and what the outcome was.
Hangs off: Article 46: derogation from conformity assessment procedure
Editorially reviewed | conformity, enforcement, evidence
- EvidenceApplicablev1.0.05 relations
Article 49 registration dossier
praxikon:eu:ai-act:evidence:article-49-registration-dossier
Per system: which Article 49 route was followed, the registration number, the date of registration, the name of the person who submitted it, the system version the entry relates to, and, for the secure section, a statement of which limited fields from Annex VIII and Annex IX were completed.
Hangs off: Article 49: registration in the EU database before the system reaches the market
Editorially reviewed | conformity, evidence, high-risk
- Evidencev1.0.04 relations
Article 5 screening record
praxikon:eu:ai-act:evidence:article-5-screening-record
A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.
Hangs off: Article 5: prohibited practices
Editorially reviewed | evidence, prohibited-practices
- Evidencev1.0.05 relations
Transparency implementation record
praxikon:eu:ai-act:evidence:article-50-implementation-record
Record of scenario, actor, disclosure or marking, technical implementation, test and owner.
Hangs off: Article 50: transparency
Editorially reviewed | evidence, transparency
- Evidencev1.0.03 relations
Systemic-risk file
praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record
Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | evidence, gpai-systemic-risk
- EvidenceEditorialv1.0.04 relations
Record of the decision on a code of practice
praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record
Per model: the decision whether or not to adhere to a code of practice, the version and chapter it relates to, the date and the authorised signatory, whether adherence was limited under paragraph 7 to the obligations in Article 53, and, where the decision is negative, the elaboration of your own for the issues in paragraph 2.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | evidence, governance, gpai, gpai-systemic-risk
- EvidenceApplicablev1.0.04 relations
Information pack for subjects of testing in real world conditions
praxikon:eu:ai-act:evidence:article-61-subject-information-pack
The document that precedes consent: per test the five points of Article 61(1) written out, with the Union-wide unique single identification number, the contact details from whom further information can be obtained, and the mechanism for requesting the reversal or the disregarding of an output. This is a different item from the dated consent record itself, which sits in article-61-informed-consent-record.
Hangs off: Article 61: informed consent of test subjects for testing in real world conditions
Editorially reviewed | evidence, fundamental-rights, innovation
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.