Skip to main content
Praxikon

Explorer

Why this object hangs off that object

Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.

Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.

This is the knowledge layer under the four levels of the assessment. See the four levels.

Filters

Only dimensions the data carries. A dimension without values is absent rather than empty.

Eleven types, including evidence, control and standard.

Is about this role. Walks the role hierarchy upward.

The duty rests on this role, not merely: it is about it.

The article route this object hangs off.

Free slugs, not a taxonomy with objects of its own.

The phase of the object, not its quality.

Whether this object carries a source line of its own.

Searches label, summary, topics, conditions and statement texts. The ordering is the same heuristic as the search API; build on the identifiers, not on the ranking.

Time

Two axes. Legal time is what applied; knowledge time is what we had published by then. Leaving them empty means the default of this release.

Clear all

Objects

150 of 298 shown. Pick a type below or narrow with a filter to see the rest.

  1. Actionv1.0.05 relations

    Classify the use case and document the outcome

    praxikon:eu:ai-act:action:annex-iii-classify

    Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | high-risk

  2. ActionApplicablev1.0.03 relations

    Appoint an authorised representative and record the mandate

    praxikon:eu:ai-act:action:appoint-gpai-authorised-representative

    Determine whether you are the provider of the model, appoint an authorised representative established in the Union by written mandate before placing the model on the market, and write out in that mandate the four tasks in paragraph 3, the access to the Annex XI documentation and the point of contact under paragraph 4.

    Hangs off: Article 54: authorised representative of a provider of a GPAI model

    Editorially reviewed | gpai, value-chain

  3. Actionv1.0.04 relations

    Set up data governance per dataset

    praxikon:eu:ai-act:action:article-10-data-governance-act

    Assess origin, representativeness, errors and completeness and examine possible bias with appropriate mitigation.

    Hangs off: Article 10: data and data governance

    Editorially reviewed | high-risk-requirements

  4. Actionv1.0.03 relations

    Build the technical file per Annex IV

    praxikon:eu:ai-act:action:article-11-technical-documentation-act

    Document system description, development process, data, oversight measures, performance and risk management before market placement.

    Hangs off: Article 11: technical documentation

    Editorially reviewed | high-risk-requirements

  5. Actionv1.0.04 relations

    Design logging into the system

    praxikon:eu:ai-act:action:article-12-logging-act

    Ensure the system automatically records events relevant to risk identification and post-market monitoring.

    Hangs off: Article 12: logging and traceability

    Editorially reviewed | high-risk-requirements

  6. Actionv1.0.04 relations

    Provide complete instructions for use

    praxikon:eu:ai-act:action:article-13-instructions-act

    Describe capabilities, limitations, accuracy, oversight measures and expected lifetime in comprehensible form.

    Hangs off: Article 13: transparency towards deployers

    Editorially reviewed | high-risk-requirements

  7. Actionv1.0.04 relations

    Design and assign effective human oversight

    praxikon:eu:ai-act:action:article-14-human-oversight-act

    Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.

    Hangs off: Article 14: human oversight

    Editorially reviewed | high-risk-requirements

  8. Actionv1.0.03 relations

    Set and test performance and security levels

    praxikon:eu:ai-act:action:article-15-accuracy-robustness-act

    Determine appropriate accuracy, test robustness against errors and misuse, and take AI-specific security measures.

    Hangs off: Article 15: accuracy, robustness and cybersecurity

    Editorially reviewed | high-risk-requirements

  9. Actionv1.0.03 relations

    Set up an AI quality management system

    praxikon:eu:ai-act:action:article-17-quality-management-act

    Describe strategies, procedures and responsibilities for compliance, from design and data to post-market monitoring.

    Hangs off: Article 17: quality management system

    Editorially reviewed | high-risk-requirements

  10. Actionv1.0.05 relations

    Take role- and context-specific AI literacy measures

    praxikon:eu:ai-act:action:article-4-measures

    Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy

  11. Actionv1.0.04 relations

    Screen every use case against Article 5 first

    praxikon:eu:ai-act:action:article-5-screen

    Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.

    Hangs off: Article 5: prohibited practices

    Editorially reviewed | prohibited-practices

  12. Actionv1.0.05 relations

    Implement the applicable disclosure, marking or label

    praxikon:eu:ai-act:action:article-50-disclosure

    First determine which paragraph of Article 50 applies, then implement the specific transparency measure.

    Hangs off: Article 50: transparency

    Editorially reviewed | transparency

  13. Actionv1.0.03 relations

    Perform model evaluations and risk mitigation

    praxikon:eu:ai-act:action:article-55-gpai-systemic-risk-act

    Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.

    Hangs off: Article 55: GPAI models with systemic risk

    Editorially reviewed | gpai-systemic-risk

  14. ActionApplicablev1.0.04 relations

    Inform the test subject and obtain consent to participate

    praxikon:eu:ai-act:action:article-61-inform-and-obtain-consent

    Give every test subject concise, clear, relevant and understandable information beforehand on the five points of Article 61(1), then obtain freely-given informed consent, date and document that consent, and give a copy to the subject or the legal representative.

    Hangs off: Article 61: informed consent of test subjects for testing in real world conditions

    Editorially reviewed | fundamental-rights, innovation

  15. ActionEditorialv1.0.04 relations

    Make use of the SME facilities in Article 62

    praxikon:eu:ai-act:action:article-62-claim-sme-facilities

    Apply for priority access to the AI regulatory sandbox, use the national communication channel for questions about implementation, sign up for the standardisation process, and on a conformity assessment under Article 43 ask how the fee reduction has been applied.

    Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups

    Editorially reviewed | governance, innovation

  16. ActionEditorialv1.0.03 relations

    Determine and bound the simplification of your quality management system

    praxikon:eu:ai-act:action:article-63-scope-simplified-quality-management

    Test whether you are a microenterprise with no partner or linked enterprises, build the Article 17 system, mark which elements you would want to simplify once the Commission guidelines exist, and keep the nine articles of Article 63(2) expressly outside that simplification.

    Hangs off: Article 63: derogations for SMEs in the quality management system

    Editorially reviewed | high-risk-requirements, innovation

  17. Actionv1.0.04 relations

    Draw up a post-market monitoring plan

    praxikon:eu:ai-act:action:article-72-post-market-monitoring-act

    Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.

    Hangs off: Article 72: post-market monitoring

    Editorially reviewed | post-market

  18. Actionv1.0.04 relations

    Set up an incident process with reporting routes

    praxikon:eu:ai-act:action:article-73-incident-reporting-act

    Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.

    Hangs off: Article 73: serious incident reporting

    Editorially reviewed | post-market

  19. ActionEditorialv1.0.03 relations

    Record the state of the art and the intended purpose per system

    praxikon:eu:ai-act:action:article-8-state-of-the-art-baseline

    Establish, per high-risk system, what currently counts as the generally acknowledged state of the art and against which intended purpose the requirements of Section 2 have been met, with a fixed re-assessment moment and with the location in the risk management file of Article 9.

    Hangs off: Article 8: compliance with the requirements for high-risk AI systems

    Editorially reviewed | conformity, high-risk-requirements

  20. Actionv1.0.03 relations

    Set up an iterative risk management process

    praxikon:eu:ai-act:action:article-9-risk-management-act

    Identify and analyse known and reasonably foreseeable risks, evaluate them and take measures, repeating the cycle on every change.

    Hangs off: Article 9: risk management system

    Editorially reviewed | high-risk-requirements

  21. ActionEditorialv1.0.04 relations

    Scope a voluntary code of conduct and separate it from your duties

    praxikon:eu:ai-act:action:article-95-scope-a-voluntary-code

    Choose the paragraph 1 or the paragraph 2 route, name which requirements you apply voluntarily and which you do not, give the code clear objectives and key performance indicators, and keep the voluntary commitments administratively separate from the obligations that continue to apply in full.

    Hangs off: Article 95: codes of conduct for voluntary application of specific requirements

    Editorially reviewed | governance, innovation

  22. ActionEditorialv1.0.05 relations

    Assign to each obligation the penalty ceiling that belongs to it

    praxikon:eu:ai-act:action:article-99-101-map-penalty-tiers

    Walk through your obligations register and mark per line which ceiling applies: Article 99(3) for Article 5, Article 99(4) for the role duties enumerated there, Article 25(2) and (4) and Article 50, Article 99(5) for answering information requests, and otherwise the national penalty regime under Article 99(1). Add the Article 101 regime wherever you provide a general-purpose AI model yourself, and the Article 75c regime wherever the AI Office is competent.

    Hangs off: Article 99, 100 and 101: the penalty structure per obligation

    Editorially reviewed | enforcement, governance

  23. ActionEditorialv1.0.03 relations

    Determine and record whether your AI component is a safety component

    praxikon:eu:ai-act:action:assess-safety-component-role

    Describe, per AI component inside a product under Annex I, Section A, which function it performs, whether that is a safety function, what happens on failure or malfunctioning, and whether the mandatory third-party conformity assessment rests on health and safety risks or only on other risks. A recommended practice, not a legal duty.

    Hangs off: Article 6(1a) to (1c): the tightened classification route

    Editorially reviewed | conformity, high-risk

  24. ActionUpcomingv1.0.04 relations

    Assess for every design change whether it is significant

    praxikon:eu:ai-act:action:assess-significant-design-change

    Fix a moment in your change and release process at which someone assesses and records whether an intended change to a legacy high-risk system is a significant change in its design, before the change goes into production.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  25. Actionv1.0.04 relations

    Complete the conformity route before market placement

    praxikon:eu:ai-act:action:conformity-ce-registration-act

    Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Editorially reviewed | conformity

  26. ActionEditorialv1.0.04 relations

    Take and record the decision whether you adhere to a code of practice

    praxikon:eu:ai-act:action:decide-and-record-gpai-code-adherence

    Determine per general-purpose AI model whether you adhere to a code of practice, to which version and which chapter, whether under paragraph 7 the obligations in Article 53 suffice for you, and which elaboration of your own you apply for the issues in paragraph 2 where you do not join.

    Hangs off: Article 56: codes of practice for general-purpose AI models

    Editorially reviewed | governance, gpai, gpai-systemic-risk

  27. ActionUpcomingv1.0.05 relations

    Enter your data in the EU database and keep it up to date

    praxikon:eu:ai-act:action:enter-and-maintain-eu-database-data

    Compile per system the data listed in Sections A and B of Annex VIII, or Section C where you are a public deployer, designate the natural person with the legal authority to register, and make sure the entry stays correct when the status, the Member States or the declaration of conformity change. Section C can only be completed after the provider has entered Section A, because point 3 asks for the URL of that entry.

    Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III

    Editorially reviewed | conformity

  28. ActionUpcomingv1.0.03 relations

    Establish the product route per product

    praxikon:eu:ai-act:action:establish-annex-i-product-route

    Determine per product which Annex I legal act it falls under and whether that is Section A or Section B, which conformity assessment procedure applies there, which AI functions are safety components and who is thereby the provider.

    Hangs off: Article 6(1): the product route to high risk

    Editorially reviewed | conformity, high-risk

  29. Actionv1.0.06 relations

    Perform a FRIA before deployment

    praxikon:eu:ai-act:action:fria-assess

    Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.

    Hangs off: Article 27: FRIA

    Editorially reviewed | fundamental-rights, high-risk

  30. Actionv1.0.04 relations

    Maintain GPAI documentation and transparency information

    praxikon:eu:ai-act:action:gpai-document

    Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | gpai

  31. ActionApplicablev1.0.03 relations

    Set up how you handle a request for an explanation

    praxikon:eu:ai-act:action:handle-explanation-requests

    Ensure your complaints or objections desk recognises a request for an explanation of an AI-supported decision, that it can be traced per decision which system in which version contributed to it, and that someone is designated to give the explanation.

    Hangs off: Article 86: right to an explanation of a decision

    Editorially reviewed | fundamental-rights

  32. ActionEditorialv1.0.04 relations

    Record per requirement which standard or specification you rely on, and justify every departure

    praxikon:eu:ai-act:action:justify-standards-and-specification-choices

    Keep a coverage matrix of the requirements of Section 2 against the harmonised standards, common specifications and own documents applied, noting per row the publication status in the Official Journal, and write out the Article 41(5) justification for every common specification you do not apply.

    Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity

    Editorially reviewed | conformity, standards

  33. ActionUpcomingv1.0.03 relations

    Set up the ten year retention of the system documentation

    praxikon:eu:ai-act:action:keep-high-risk-documentation-available

    Bring the five components of Article 18(1) together per high-risk system in an identifiable place, record both the date of placing on the market and the date of putting into service, calculate the end date from the later moment, and assign the upkeep to a role rather than to a person.

    Hangs off: Article 18: documentation keeping

    Editorially reviewed | high-risk-requirements

  34. Actionv1.0.03 relations

    Manage the life of the certificate

    praxikon:eu:ai-act:action:manage-notified-body-certificate

    A practical working out for whoever holds a certificate: watch the expiry date, ask in time for the re-assessment that carries the extension, test every change against the substantial modification of Article 43(4), and make sure a deadline set by the body for corrective action reaches an identifiable person. Also track the body itself, because on cessation or withdrawal of its designation the deadlines of Article 36 apply.

    Hangs off: Article 44: certificates of notified bodies

    Editorially reviewed | conformity

  35. ActionUpcomingv1.0.04 relations

    Map every system to a point of Annex III

    praxikon:eu:ai-act:action:map-system-to-annex-iii-area

    Determine per AI system which of the eight areas and which lettered subpoint the intended purpose touches, or establish with reasons that no point applies. Then run the Article 6(3) test and record the outcome as Article 6(4) requires. Do so at the level of the intended purpose and not at the level of the department or the sector.

    Hangs off: Annex III: the eight areas separately

    Editorially reviewed | high-risk

  36. ActionEditorialv1.0.05 relations

    Mark and register what you submit to an authority or body

    praxikon:eu:ai-act:action:mark-confidential-material-on-submission

    State on every submission which part is confidential business information, trade secret or source code, keep track of what was handed to whom on what date, and on a further request ask about the necessity and the purpose within the meaning of Article 78(2).

    Hangs off: Article 78: confidentiality of what you submit to an authority

    Editorially reviewed | enforcement, governance

  37. ActionApplicablev1.0.03 relations

    Notify the Commission within two weeks

    praxikon:eu:ai-act:action:notify-systemic-risk-threshold

    Notify the model as soon as it meets the condition in Article 51(1), point (a), or as soon as it becomes known that it will, with the information necessary to demonstrate that the requirement has been met, and with any substantiation that the model does not present systemic risks after all.

    Hangs off: Article 52: notification of a GPAI model with systemic risk

    Editorially reviewed | gpai-systemic-risk

  38. ActionEditorialv1.0.04 relations

    Make sure a report about an AI system reaches your reporting channel

    praxikon:eu:ai-act:action:open-a-protected-reporting-route

    Only for organisations that must already have a reporting arrangement. Make visible in it that an infringement of the AI Regulation is a reportable infringement, designate who receives such a report, agree how the identity of the person reporting stays out of the rest of the process, and record whether you handle anonymous reports.

    Hangs off: Article 87: reporting of infringements and protection of reporting persons

    Editorially reviewed | fundamental-rights, governance

  39. ActionApplicablev1.0.04 relations

    Plan compliance for legacy public sector systems by 2 August 2030

    praxikon:eu:ai-act:action:plan-legacy-public-system-compliance

    Determine which high-risk systems are intended to be used by public authorities and were already running before the cut off date for their route, and count back from the conformity assessment and the registration to a plan that finishes before 2 August 2030.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  40. ActionEditorialv1.0.05 relations

    Prepare a derogation request and the exit plan that goes with it

    praxikon:eu:ai-act:action:prepare-article-46-derogation-request

    Write in advance the reasoning paragraph 1 calls for, with the exceptional reason invoked, the evidence that the system complies with the requirements of Section 2, the status of the ongoing conformity assessment, and an exit plan in case the authorisation is refused or withdrawn.

    Hangs off: Article 46: derogation from conformity assessment procedure

    Editorially reviewed | conformity, enforcement

  41. ActionApplicablev1.0.03 relations

    Make sure you can answer a complaint with documents

    praxikon:eu:ai-act:action:prepare-for-a-complaint

    Record per AI system which assessment was carried out, by whom, on what date and against which system version, and agree who receives a question from the authority and within what period.

    Hangs off: Article 85: right to lodge a complaint with the market surveillance authority

    Editorially reviewed | fundamental-rights

  42. ActionApplicablev1.0.06 relations

    Justify and record your reliance on Article 4a

    praxikon:eu:ai-act:action:record-bias-testing-legal-basis

    Only for those who themselves decide to process special categories of personal data for bias testing. In that case record which paragraph of Article 4a you rely on and whether that paragraph is open to your role, why other data do not suffice, which safeguards apply, who has access and when the data are deleted. Replace old references to Article 10(5) while you are there.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Editorially reviewed | fundamental-rights, high-risk-requirements

  43. ActionApplicablev1.0.05 relations

    Register yourself and the system before it reaches the market or is put into service

    praxikon:eu:ai-act:action:register-in-eu-database-before-market-entry

    Determine per system which of the four Article 49 routes applies, the ordinary Annex III route, the Article 6(3) route, the secure section for law enforcement, migration, asylum and border control management, or the national route for point 2 of Annex III, and complete the registration before the system is placed on the market, put into service or used.

    Hangs off: Article 49: registration in the EU database before the system reaches the market

    Editorially reviewed | conformity, high-risk

  44. ActionApplicablev1.0.03 relations

    Request reassessment after a designation

    praxikon:eu:ai-act:action:request-systemic-risk-reassessment

    If your model has been designated under Article 52(4), you may request reassessment by reasoned request. The request must contain objective, detailed and new reasons that have arisen since the designation decision, and may be made at the earliest six months after that decision; where the designation is maintained, a further six months apply.

    Hangs off: Article 52: notification of a GPAI model with systemic risk

    Editorially reviewed | gpai-systemic-risk

  45. Actionv1.0.04 relations

    Assess the value-chain role per system and change

    praxikon:eu:ai-act:action:value-chain-representative-act

    On white-labelling, substantial modification or purpose change, assess whether your organisation becomes the provider, and arrange the representative for non-EU supply.

    Hangs off: Articles 22-25: value chain and authorised representative

    Editorially reviewed | value-chain

  46. ActionEditorialv1.0.03 relations

    Check the standing and independence of your notified body

    praxikon:eu:ai-act:action:verify-notified-body-standing

    At the moment of choice and periodically thereafter, verify whether the body appears in the Commission public list, for which activities and system types it is notified, whether its designation has been restricted or suspended, and whether the independence of Article 31(4) and (5) holds; also ask which tasks are subcontracted and give your agreement under Article 33(3) in writing.

    Hangs off: Articles 28 to 39: notifying authorities and notified bodies

    Editorially reviewed | conformity, governance

  47. Actorv1.0.07 relations

    AI Office

    praxikon:eu:ai-act:actor:ai-office

    The Commission office that supervises providers of general-purpose AI models. AI Office enforcement is active since 2 August 2026.

    Editorially reviewed | enforcement, governance, gpai

  48. Actorv1.0.08 relations

    Credit or insurance deployer

    praxikon:eu:ai-act:actor:credit-or-insurance-deployer

    A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).

    Editorially reviewed | fundamental-rights, high-risk

  49. Actorv1.0.0181 relations

    Deployer

    praxikon:eu:ai-act:actor:deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

    Editorially reviewed | governance

  50. Actorv1.0.059 relations

    Provider of a GPAI model

    praxikon:eu:ai-act:actor:gpai-model-provider

    A party that places a general-purpose AI model on the Union market.

    Editorially reviewed | gpai

  51. Actorv1.0.08 relations

    Market surveillance authority

    praxikon:eu:ai-act:actor:market-surveillance-authority

    The national authority that supervises compliance with the Regulation and receives serious incident and risk notifications. Which body fills this role per Member State is not recorded in the graph.

    Editorially reviewed | enforcement, governance

  52. Actorv1.0.0258 relations

    Provider of an AI system

    praxikon:eu:ai-act:actor:provider

    A party that develops or has an AI system developed and places it on the market under its own name.

    Editorially reviewed | governance

  53. Actorv1.0.038 relations

    Body governed by public law

    praxikon:eu:ai-act:actor:public-law-body

    A deployer that is a body governed by public law.

    Editorially reviewed | fundamental-rights

  54. Actorv1.0.09 relations

    Private provider of public services

    praxikon:eu:ai-act:actor:public-service-provider

    A private deployer providing public services.

    Editorially reviewed | fundamental-rights

  55. ChangeApplicablev1.0.04 relations

    The AI Act enters into force

    praxikon:eu:ai-act:change:2024-08-01-entry-into-force

    The regulation entered into force on 1 August 2024, after which the obligations followed in phases.

    Hangs off: Article 4: AI literacy, Article 5: prohibited practices

    Placed against the official source | timeline

  56. ChangeApplicablev1.0.04 relations

    Prohibited practices and AI literacy apply

    praxikon:eu:ai-act:change:2025-02-02-prohibitions-and-literacy-applicable

    Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.

    Hangs off: Article 4: AI literacy, Article 5: prohibited practices

    Placed against the official source | ai-literacy, timeline

  57. ChangeGuidancev1.0.02 relations

    General-Purpose AI Code of Practice published

    praxikon:eu:ai-act:change:2025-07-10-gpai-code-of-practice

    The voluntary code of practice gives GPAI model providers a route to demonstrate compliance.

    Hangs off: Article 53: GPAI model providers

    Placed against the official source | gpai

  58. ChangeGuidancev1.0.03 relations

    Guidelines on the scope of the GPAI obligations

    praxikon:eu:ai-act:change:2025-07-18-gpai-guidelines

    The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai

  59. ChangeGuidancev1.0.04 relations

    Guidelines on the definition of an AI system

    praxikon:eu:ai-act:change:2025-07-29-ai-system-definition-guidelines

    The Commission draws the line between software that does and does not fall under the regulation.

    Hangs off: Annex III: high-risk AI, Article 4: AI literacy

    Placed against the official source | scope

  60. ChangeGuidancev1.0.03 relations

    Guidelines on prohibited AI practices

    praxikon:eu:ai-act:change:2025-07-29-prohibited-practices-guidelines

    Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.

    Hangs off: Article 5: prohibited practices

    Placed against the official source | prohibited

  61. ChangeApplicablev1.0.03 relations

    GPAI model obligations apply

    praxikon:eu:ai-act:change:2025-08-02-gpai-obligations-applicable

    Since 2 August 2025 the obligations for providers of general-purpose AI models apply.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai, timeline

  62. ChangeGuidancev1.0.04 relations

    Draft guidelines on high-risk classification

    praxikon:eu:ai-act:change:2026-05-19-draft-high-risk-guidelines

    The Commission explains in consultation when a system falls under Annex I or Annex III.

    Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk

  63. ChangeGuidancev1.0.03 relations

    Transparency Code of Practice published

    praxikon:eu:ai-act:change:2026-06-10-transparency-code-of-practice

    A voluntary route to comply with parts of Article 50, in two separately signable sections.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  64. ChangeGuidancev1.0.02 relations

    First European AI Act standard approved

    praxikon:eu:ai-act:change:2026-07-12-en-18286-approved

    EN 18286:2026 on the quality management system is the first completed standard under the standardisation request.

    Hangs off: Article 17: quality management system

    Placed against the official source | standards

  65. ChangeGuidancev1.0.03 relations

    Final guidelines on Article 50

    praxikon:eu:ai-act:change:2026-07-20-article-50-guidelines

    The Commission works out the transparency duties and confirms they apply from 2 August 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  66. ChangeIn forcev1.0.08 relations

    Annex III core rules moved to 2 December 2027

    praxikon:eu:ai-act:change:2026-07-27-annex-iii-date

    The amended application date has been binding law since 27 July 2026.

    Hangs off: Annex III: high-risk AI

    Placed against the official source | high-risk

  67. ChangeIn forcev1.0.02 relations

    New Article 2(13): requirements for Annex I systems may be limited

    praxikon:eu:ai-act:change:2026-07-27-article-2-13-limitation

    Since 27 July 2026 the application of the requirements or obligations in Articles 9 to 15 and 17 to 25 may be limited for high-risk systems referred to in Article 6(1) where the Annex I Section A harmonisation legislation provides an equivalent or higher level of protection. That limitation exists only once a delegated act is adopted, which must happen by 2 August 2027. Until then the requirements apply in full.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | conformity, high-risk

  68. ChangeIn forcev1.0.05 relations

    Article 4 amended to a duty to take measures

    praxikon:eu:ai-act:change:2026-07-27-article-4-amended

    Since 27 July 2026 the organisational duty supports the development of AI literacy without guaranteeing an individual level.

    Hangs off: Article 4: AI literacy

    Placed against the official source | ai-literacy

  69. ChangeIn forcev1.0.07 relations

    Article 4a inserted, Article 10(5) deleted

    praxikon:eu:ai-act:change:2026-07-27-article-4a-inserted

    Since 27 July 2026 the legal basis for bias detection using special categories of personal data sits as Article 4a in Chapter I and no longer as Article 10(5) in Chapter III. The circle has widened from providers of high-risk systems alone to providers and deployers of other AI systems and models and deployers of high-risk systems, on the same conditions.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Placed against the official source | fundamental-rights, high-risk-requirements

  70. ChangeIn forcev1.0.06 relations

    FRIA follows new date and may cross-reference a DPIA

    praxikon:eu:ai-act:change:2026-07-27-fria-date-and-dpia-link

    The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.

    Hangs off: Article 27: FRIA

    Placed against the official source | fundamental-rights, high-risk

  71. ChangeIn forcev1.0.02 relations

    Machinery moves from Annex I, Section A, to Section B

    praxikon:eu:ai-act:change:2026-07-27-machinery-moved-to-annex-i-b

    Since 27 July 2026 point 1 of Section A of Annex I, the machinery directive, has been deleted and Regulation (EU) 2023/1230 has been added as point 21 to Section B. For AI in machinery the limited regime of the amended Article 2(2) therefore applies: only Article 6(1), Article 60a and Articles 102 to 112.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | conformity, high-risk, scope

  72. ChangeIn forcev1.0.02 relations

    Article 6 gains paragraphs 1a to 1c on safety components

    praxikon:eu:ai-act:change:2026-07-27-safety-component-narrowed

    Since 27 July 2026 AI systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control do not qualify as safety components, unless failure or malfunctioning would endanger health and safety. A product required to undergo a third-party assessment only because of radio spectrum or electromagnetic interference that does not affect health and safety does not fulfil the condition in paragraph 1, point (b).

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk, scope

  73. ChangeApplicablev1.0.05 relations

    Article 50 is applicable

    praxikon:eu:ai-act:change:2026-08-02-article-50-applicable

    The transparency duties apply since 2 August 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | transparency

  74. ChangeApplicablev1.0.05 relations

    GPAI enforcement powers active

    praxikon:eu:ai-act:change:2026-08-02-gpai-enforcement

    Since 2 August 2026 the Commission can request GPAI information, conduct evaluations and require measures.

    Hangs off: Article 53: GPAI model providers

    Placed against the official source | enforcement, gpai

  75. ChangeUpcomingv1.0.03 relations

    Grace period for machine-readable marking ends

    praxikon:eu:ai-act:change:2026-12-02-article-50-marking-grace-ends

    Systems placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.

    Hangs off: Article 50: transparency

    Placed against the official source | timeline, transparency

  76. ChangeUpcomingv1.0.02 relations

    New prohibitions require technical safeguards

    praxikon:eu:ai-act:change:2026-12-02-new-prohibitions-technical-safeguards

    The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.

    Hangs off: Article 5: prohibited practices

    Placed against the official source | prohibited, timeline

  77. ChangeUpcomingv1.0.04 relations

    Legacy GPAI models must comply

    praxikon:eu:ai-act:change:2027-08-02-legacy-gpai-models-comply

    Models placed on the market before 2 August 2025 have until 2 August 2027.

    Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk

    Placed against the official source | gpai, timeline

  78. ChangeUpcomingv1.0.01 relations

    National AI regulatory sandboxes operational on 2 August 2027

    praxikon:eu:ai-act:change:2027-08-02-sandboxes-operational

    The first subparagraph of Article 57(1) has been replaced. The date by which each Member State must have at least one AI regulatory sandbox operational moved from 2 August 2026 to 2 August 2027. For a provider that is the day the route to supervised testing actually exists.

    Placed against the official source | governance, innovation

  79. ChangeUpcomingv1.0.02 relations

    Template for the post-market monitoring plan becomes guidance, by 2 September 2027

    praxikon:eu:ai-act:change:2027-09-02-post-market-monitoring-template

    Article 72(3) has been replaced. The original text required an implementing act with a template by 2 February 2026, and that deadline had passed without an act. Since 27 July 2026 it is guidance including a template, to be adopted by 2 September 2027. There is therefore no overdue implementing act; anyone waiting for the old template is waiting for something that will not come.

    Hangs off: Article 72: post-market monitoring

    Placed against the official source | high-risk, post-market

  80. ChangeUpcomingv1.0.04 relations

    High-risk AI embedded in regulated products

    praxikon:eu:ai-act:change:2028-08-02-annex-i-high-risk-applicable

    AI as a safety component of products under Annex I follows on 2 August 2028.

    Hangs off: Annex III: high-risk AI, Articles 43-49: conformity assessment, CE and registration

    Placed against the official source | high-risk, timeline

  81. ControlUpcomingv1.0.03 relations

    Reassessment on a change of product or assessment route

    praxikon:eu:ai-act:control:annex-i-product-route-change-gate

    The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.

    Hangs off: Article 6(1): the product route to high risk

    Editorially reviewed | control, high-risk

  82. ControlUpcomingv1.0.04 relations

    Reassessment on a change of intended purpose

    praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger

    The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.

    Hangs off: Annex III: the eight areas separately

    Editorially reviewed | high-risk

  83. Controlv1.0.04 relations

    Reclassification on purpose or context change

    praxikon:eu:ai-act:control:annex-iii-change-trigger

    Reopen classification when intended purpose, use context or system functionality changes materially.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | control, high-risk

  84. Controlv1.0.04 relations

    Data check before retraining

    praxikon:eu:ai-act:control:article-10-data-governance-control

    Repeat the data quality assessment before every retraining or dataset change.

    Hangs off: Article 10: data and data governance

    Editorially reviewed | control, high-risk-requirements

  85. Controlv1.0.03 relations

    Documentation update on every release

    praxikon:eu:ai-act:control:article-11-technical-documentation-control

    Update the file before every release and retain earlier versions traceably.

    Hangs off: Article 11: technical documentation

    Editorially reviewed | control, high-risk-requirements

  86. Controlv1.0.04 relations

    Periodic log review

    praxikon:eu:ai-act:control:article-12-logging-control

    Periodically verify that logging works, is complete and is retained according to the regime.

    Hangs off: Article 12: logging and traceability

    Editorially reviewed | control, high-risk-requirements

  87. Controlv1.0.04 relations

    Instructions check at deployment

    praxikon:eu:ai-act:control:article-13-instructions-control

    At every deployment and update, verify instructions are present, current and internally translated.

    Hangs off: Article 13: transparency towards deployers

    Editorially reviewed | control, high-risk-requirements

  88. Controlv1.0.04 relations

    Oversight test before go-live

    praxikon:eu:ai-act:control:article-14-human-oversight-control

    Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.

    Hangs off: Article 14: human oversight

    Editorially reviewed | control, high-risk-requirements

  89. Controlv1.0.03 relations

    Performance monitoring in use

    praxikon:eu:ai-act:control:article-15-accuracy-robustness-control

    Monitor whether the system stays within declared levels in production and escalate on deviation.

    Hangs off: Article 15: accuracy, robustness and cybersecurity

    Editorially reviewed | control, high-risk-requirements

  90. Controlv1.0.03 relations

    Internal audit cycle

    praxikon:eu:ai-act:control:article-17-quality-management-control

    Periodically audit whether practice follows the described system and record deviations and improvements.

    Hangs off: Article 17: quality management system

    Editorially reviewed | control, high-risk-requirements

  91. ControlUpcomingv1.0.03 relations

    Periodic check on completeness and retrievability of the retention file

    praxikon:eu:ai-act:control:article-18-retention-review

    The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.

    Hangs off: Article 18: documentation keeping

    Editorially reviewed | control, high-risk-requirements

  92. Controlv1.0.04 relations

    Periodic role and context review

    praxikon:eu:ai-act:control:article-4-periodic-review

    Check when systems, roles or risks change whether the selected measures remain appropriate.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy, control

  93. ControlEditorialv1.0.05 relations

    Review of an authorisation expiring, being refused or withdrawn

    praxikon:eu:ai-act:control:article-46-derogation-exit-review

    The control that keeps a system running under Article 46 under watch: the ongoing conformity assessment has an owner and an end date, the fifteen calendar days of paragraph 4 are in the calendar, and a rehearsed plan is in place to stop use with immediate effect and discard all results and outputs if the authorisation is refused or withdrawn.

    Hangs off: Article 46: derogation from conformity assessment procedure

    Editorially reviewed | conformity, control, enforcement

  94. ControlApplicablev1.0.05 relations

    Release gate: no market entry without registration

    praxikon:eu:ai-act:control:article-49-pre-market-registration-gate

    The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.

    Hangs off: Article 49: registration in the EU database before the system reaches the market

    Editorially reviewed | conformity, control, high-risk

  95. Controlv1.0.04 relations

    Article 5 gate at intake and change

    praxikon:eu:ai-act:control:article-5-intake-gate

    Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.

    Hangs off: Article 5: prohibited practices

    Editorially reviewed | control, prohibited-practices

  96. Controlv1.0.04 relations

    Pre-release transparency check

    praxikon:eu:ai-act:control:article-50-release-check

    Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.

    Hangs off: Article 50: transparency

    Editorially reviewed | control, transparency

  97. Controlv1.0.03 relations

    Compute threshold monitoring

    praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control

    Monitor cumulative training compute and notify the Commission when the threshold is reached.

    Hangs off: Article 55: GPAI models with systemic risk

    Editorially reviewed | control, gpai-systemic-risk

  98. ControlEditorialv1.0.04 relations

    Review moment on your reliance on a code of practice

    praxikon:eu:ai-act:control:article-56-code-commitment-review

    The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.

    Hangs off: Article 56: codes of practice for general-purpose AI models

    Editorially reviewed | control, governance, gpai, gpai-systemic-risk

  99. ControlEditorialv1.0.04 relations

    Consent and withdrawal review before a test in real world conditions starts

    praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review

    The control that no subject participates before the information pack is complete, the consent record is dated and a copy has been given, and that the withdrawal route with its recipient, period and deletion step works and has been rehearsed once.

    Hangs off: Article 61: informed consent of test subjects for testing in real world conditions

    Editorially reviewed | control, fundamental-rights, innovation

  100. ControlEditorialv1.0.04 relations

    Fee and access review on a conformity assessment

    praxikon:eu:ai-act:control:article-62-fee-and-access-review

    The control that on every application for a conformity assessment under Article 43 and on every sandbox application it is checked whether the SME facilities have been invoked and whether the proportionate fee reduction has been made visible, and that the answer reaches the procurement file.

    Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups

    Editorially reviewed | control, governance, innovation

  101. ControlEditorialv1.0.03 relations

    Review of the boundary of the simplification

    praxikon:eu:ai-act:control:article-63-simplification-boundary-review

    The control that every simplification you make under Article 63 is tested against paragraph 2, so that no item from Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73 falls away, and that the shareholding structure test is redone at every change.

    Hangs off: Article 63: derogations for SMEs in the quality management system

    Editorially reviewed | control, high-risk-requirements, innovation

  102. Controlv1.0.04 relations

    Signal-to-action loop

    praxikon:eu:ai-act:control:article-72-post-market-monitoring-control

    Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.

    Hangs off: Article 72: post-market monitoring

    Editorially reviewed | control, post-market

  103. Controlv1.0.04 relations

    Incident drill and deadline watch

    praxikon:eu:ai-act:control:article-73-incident-reporting-control

    Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.

    Hangs off: Article 73: serious incident reporting

    Editorially reviewed | control, post-market

  104. ControlEditorialv1.0.05 relations

    Review before handing over source code or trade secrets

    praxikon:eu:ai-act:control:article-78-disclosure-review

    The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.

    Hangs off: Article 78: confidentiality of what you submit to an authority

    Editorially reviewed | control, enforcement, governance

  105. ControlEditorialv1.0.03 relations

    Review of the overlap with sectoral product documentation

    praxikon:eu:ai-act:control:article-8-integrated-documentation-review

    The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.

    Hangs off: Article 8: compliance with the requirements for high-risk AI systems

    Editorially reviewed | conformity, control, high-risk-requirements

  106. Controlv1.0.03 relations

    Reassessment on every material change

    praxikon:eu:ai-act:control:article-9-risk-management-control

    Reopen the risk management process on changes in purpose, data, model or use context and before every release.

    Hangs off: Article 9: risk management system

    Editorially reviewed | control, high-risk-requirements

  107. ControlEditorialv1.0.04 relations

    Review that keeps voluntary and mandatory apart

    praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review

    The control that no external statement, quotation, tender response or annual report presents a code of conduct as cover for an obligation under the Regulation, and that every voluntary commitment has an owner, an indicator and a moment of measurement before it goes out.

    Hangs off: Article 95: codes of conduct for voluntary application of specific requirements

    Editorially reviewed | control, governance, innovation

  108. ControlEditorialv1.0.05 relations

    Recording of the factors in Article 99(7)

    praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record

    The control that ensures the factors which determine the amount of a fine are recorded at the time and not reconstructed afterwards: which technical and organisational measures were in place, when you notified an infringement yourself, how you responded to requests from the authority, and what you did to mitigate the harm suffered by affected persons. Those factors cut both ways, so the same record can also count against you; that is a reason to keep it properly rather than not at all.

    Hangs off: Article 99, 100 and 101: the penalty structure per obligation

    Editorially reviewed | control, enforcement

  109. ControlApplicablev1.0.05 relations

    Access and deletion control for bias testing

    praxikon:eu:ai-act:control:bias-testing-data-deletion

    The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.

    Hangs off: Article 4a: legal basis for bias testing with special categories of personal data

    Editorially reviewed | fundamental-rights, high-risk-requirements

  110. Controlv1.0.03 relations

    Monitoring of certificate, modification and body

    praxikon:eu:ai-act:control:certificate-expiry-monitoring

    The control that ensures three signals reach an identifiable person in time instead of surfacing only once the certificate has already lapsed or been suspended: an approaching expiry date, a change that may be substantial within the meaning of Article 43(4), and a notice from or about the notified body itself, including the notification within ten days on suspension, restriction or withdrawal of its designation and the confirmation that Article 36(8), point (b), requires from the provider within three months.

    Hangs off: Article 44: certificates of notified bodies

    Editorially reviewed | conformity, control

  111. Controlv1.0.04 relations

    Reassessment on substantial modification

    praxikon:eu:ai-act:control:conformity-ce-registration-control

    Rerun the conformity route whenever the system is substantially modified.

    Hangs off: Articles 43-49: conformity assessment, CE and registration

    Editorially reviewed | conformity, control

  112. ControlUpcomingv1.0.04 relations

    Review gate on a design change

    praxikon:eu:ai-act:control:design-change-review-gate

    The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.

    Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date

    Editorially reviewed | high-risk, timeline

  113. ControlUpcomingv1.0.04 relations

    Currency check on the database entry

    praxikon:eu:ai-act:control:eu-database-entry-currency

    The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.

    Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III

    Editorially reviewed | conformity, control

  114. ControlApplicablev1.0.05 relations

    Routing and deadline tracking of a request for an explanation

    praxikon:eu:ai-act:control:explanation-request-routing

    The control that ensures an incoming request reaches an identifiable person within a set period and is answered, instead of sitting in a general inbox.

    Hangs off: Article 85: right to lodge a complaint with the market surveillance authority, Article 86: right to an explanation of a decision

    Editorially reviewed | fundamental-rights

  115. Controlv1.0.05 relations

    Pre-deployment FRIA go/no-go

    praxikon:eu:ai-act:control:fria-pre-deployment-gate

    Block deployment until applicability, assessment, mitigation and notification have been completed.

    Hangs off: Article 27: FRIA

    Editorially reviewed | control, fundamental-rights

  116. Controlv1.0.03 relations

    GPAI documentation change control

    praxikon:eu:ai-act:control:gpai-documentation-change-control

    Update documentation and downstream information when the model, capabilities or risks change.

    Hangs off: Article 53: GPAI model providers

    Editorially reviewed | control, gpai

  117. ControlApplicablev1.0.03 relations

    Periodic review and termination of the mandate

    praxikon:eu:ai-act:control:gpai-mandate-review

    The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.

    Hangs off: Article 54: authorised representative of a provider of a GPAI model

    Editorially reviewed | control, gpai

  118. ControlEditorialv1.0.03 relations

    Control on the continuity of your conformity assessment

    praxikon:eu:ai-act:control:notified-body-continuity-review

    The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).

    Hangs off: Articles 28 to 39: notifying authorities and notified bodies

    Editorially reviewed | conformity, control, governance

  119. ControlEditorialv1.0.04 relations

    Watch on publications in the Official Journal

    praxikon:eu:ai-act:control:official-journal-citation-watch

    The control that keeps the coverage matrix current: a fixed check on new references of harmonised standards, on new or amended common specifications, and on the repeal that Article 41(4) prescribes once a standard is published, with a named owner who then updates the matrix.

    Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity

    Editorially reviewed | conformity, control, standards

  120. ControlEditorialv1.0.04 relations

    Protection of the person reporting

    praxikon:eu:ai-act:control:reporting-person-protection

    The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.

    Hangs off: Article 87: reporting of infringements and protection of reporting persons

    Editorially reviewed | control, fundamental-rights

  121. ControlEditorialv1.0.03 relations

    Reassessment on a change of function or purpose

    praxikon:eu:ai-act:control:safety-component-reassessment-trigger

    The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.

    Hangs off: Article 6(1a) to (1c): the tightened classification route

    Editorially reviewed | conformity, high-risk

  122. ControlApplicablev1.0.03 relations

    Deadline tracking of the notification

    praxikon:eu:ai-act:control:systemic-risk-notification-deadline

    The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.

    Hangs off: Article 52: notification of a GPAI model with systemic risk

    Editorially reviewed | gpai-systemic-risk

  123. Controlv1.0.04 relations

    Role reassessment on every change

    praxikon:eu:ai-act:control:value-chain-representative-control

    Repeat the role assessment on every rebranding, modification or new use of an existing system.

    Hangs off: Articles 22-25: value chain and authorised representative

    Editorially reviewed | control, value-chain

  124. DefinitionUpcomingv1.0.03 relations

    Annex III, point 1: biometrics

    praxikon:eu:ai-act:definition:annex-iii-area-1-biometrics

    Annex III, point 1, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  125. DefinitionUpcomingv1.0.03 relations

    Annex III, point 2: critical infrastructure

    praxikon:eu:ai-act:definition:annex-iii-area-2-critical-infrastructure

    Annex III, point 2, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  126. DefinitionUpcomingv1.0.03 relations

    Annex III, point 3: education and vocational training

    praxikon:eu:ai-act:definition:annex-iii-area-3-education-and-vocational-training

    Annex III, point 3, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  127. DefinitionUpcomingv1.0.03 relations

    Annex III, point 4: employment and workers management

    praxikon:eu:ai-act:definition:annex-iii-area-4-employment-and-workers-management

    Annex III, point 4, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  128. DefinitionUpcomingv1.0.03 relations

    Annex III, point 5: essential private and public services

    praxikon:eu:ai-act:definition:annex-iii-area-5-essential-private-and-public-services

    Annex III, point 5, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  129. DefinitionUpcomingv1.0.03 relations

    Annex III, point 6: law enforcement

    praxikon:eu:ai-act:definition:annex-iii-area-6-law-enforcement

    Annex III, point 6, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  130. DefinitionUpcomingv1.0.03 relations

    Annex III, point 7: migration, asylum and border control

    praxikon:eu:ai-act:definition:annex-iii-area-7-migration-asylum-and-border-control

    Annex III, point 7, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  131. DefinitionUpcomingv1.0.03 relations

    Annex III, point 8: administration of justice and democratic processes

    praxikon:eu:ai-act:definition:annex-iii-area-8-justice-and-democratic-processes

    Annex III, point 8, as that point stands in the Regulation, with its lettered subpoints and the exceptions named in them.

    Hangs off: Annex III: the eight areas separately

    Placed against the official source | high-risk

  132. EvidenceUpcomingv1.0.03 relations

    Product route record

    praxikon:eu:ai-act:evidence:annex-i-product-route-record

    Per product: the Annex I legal act, the section it falls under after 27 July 2026, the conformity assessment procedure chosen and whether a third party is involved, the harmonised standards any opt-out relies on, the AI functions identified as safety components together with the failure analysis, and the role you carry as a result. This is the file that shows why your system is or is not high risk through Article 6(1).

    Hangs off: Article 6(1): the product route to high risk

    Editorially reviewed | evidence, high-risk

  133. EvidenceUpcomingv1.0.04 relations

    Record of the mapping to a point of Annex III

    praxikon:eu:ai-act:evidence:annex-iii-area-mapping-record

    Per system: the intended purpose in your own words, the chosen point and lettered subpoint, the reasoning, the outcome of the Article 6(3) assessment with the condition it rests on, whether the system performs profiling, and for a reasoned no also the documentation and registration required by Article 6(4) and Article 49(2). Plus who assessed it and when. This is the document with which you later explain why the system was out of scope.

    Hangs off: Annex III: the eight areas separately

    Editorially reviewed | high-risk

  134. Evidencev1.0.05 relations

    Article 6 and Annex III classification record

    praxikon:eu:ai-act:evidence:annex-iii-classification-record

    Traceable rationale covering intended purpose, Annex III category, Article 6(3) assessment and registration decision.

    Hangs off: Annex III: high-risk AI

    Editorially reviewed | evidence, high-risk

  135. Evidencev1.0.04 relations

    Data governance file

    praxikon:eu:ai-act:evidence:article-10-data-governance-record

    Record per dataset of origin, choices, assumptions, bias examination and mitigations.

    Hangs off: Article 10: data and data governance

    Editorially reviewed | evidence, high-risk-requirements

  136. Evidencev1.0.03 relations

    Technical file (Annex IV)

    praxikon:eu:ai-act:evidence:article-11-technical-documentation-record

    Technical documentation kept current per system version, ready for a supervisor’s request.

    Hangs off: Article 11: technical documentation

    Editorially reviewed | evidence, high-risk-requirements

  137. Evidencev1.0.04 relations

    Logs and retention regime

    praxikon:eu:ai-act:evidence:article-12-logging-record

    Log files with a retention period appropriate to the purpose and at least six months for deployers (Articles 19 and 26).

    Hangs off: Article 12: logging and traceability

    Editorially reviewed | evidence, high-risk-requirements

  138. Evidencev1.0.04 relations

    Instructions and interpretation file

    praxikon:eu:ai-act:evidence:article-13-instructions-record

    The received instructions for use plus their internal translation into work instructions per role.

    Hangs off: Article 13: transparency towards deployers

    Editorially reviewed | evidence, high-risk-requirements

  139. Evidencev1.0.04 relations

    Oversight file per system

    praxikon:eu:ai-act:evidence:article-14-human-oversight-record

    Record of oversight measures, appointed persons, their training and the moments of intervention.

    Hangs off: Article 14: human oversight

    Editorially reviewed | evidence, high-risk-requirements

  140. Evidencev1.0.03 relations

    Performance and security file

    praxikon:eu:ai-act:evidence:article-15-accuracy-robustness-record

    Declared accuracy levels, test results, and measures against data poisoning and adversarial attacks among others.

    Hangs off: Article 15: accuracy, robustness and cybersecurity

    Editorially reviewed | evidence, high-risk-requirements

  141. Evidencev1.0.03 relations

    QMS documentation

    praxikon:eu:ai-act:evidence:article-17-quality-management-record

    The documented quality system with procedures, role assignment and references to the underlying files.

    Hangs off: Article 17: quality management system

    Editorially reviewed | evidence, high-risk-requirements

  142. EvidenceUpcomingv1.0.03 relations

    Retention file per high-risk system

    praxikon:eu:ai-act:evidence:article-18-retention-dossier

    Per system: the technical documentation, the quality management system documentation, the changes approved by notified bodies, the decisions and documents they issued, and the EU declaration of conformity, with the date of placing on the market, the date of putting into service and the resulting end date of the retention period.

    Hangs off: Article 18: documentation keeping

    Editorially reviewed | evidence, high-risk-requirements

  143. Evidencev1.0.05 relations

    AI literacy measures record

    praxikon:eu:ai-act:evidence:article-4-measures-record

    Versioned record of roles, context, measures, participation or instruction and review moments.

    Hangs off: Article 4: AI literacy

    Editorially reviewed | ai-literacy, evidence

  144. EvidenceEditorialv1.0.05 relations

    File accompanying a request to derogate from the conformity assessment

    praxikon:eu:ai-act:evidence:article-46-derogation-request-file

    Per request: which system and which version, which exceptional reason was invoked and on which facts, to which market surveillance authority and on what date the request was made, what the status of the conformity assessment was, which end date was agreed, when the notification of paragraph 3 was made, and what the outcome was.

    Hangs off: Article 46: derogation from conformity assessment procedure

    Editorially reviewed | conformity, enforcement, evidence

  145. EvidenceApplicablev1.0.05 relations

    Article 49 registration dossier

    praxikon:eu:ai-act:evidence:article-49-registration-dossier

    Per system: which Article 49 route was followed, the registration number, the date of registration, the name of the person who submitted it, the system version the entry relates to, and, for the secure section, a statement of which limited fields from Annex VIII and Annex IX were completed.

    Hangs off: Article 49: registration in the EU database before the system reaches the market

    Editorially reviewed | conformity, evidence, high-risk

  146. Evidencev1.0.04 relations

    Article 5 screening record

    praxikon:eu:ai-act:evidence:article-5-screening-record

    A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.

    Hangs off: Article 5: prohibited practices

    Editorially reviewed | evidence, prohibited-practices

  147. Evidencev1.0.05 relations

    Transparency implementation record

    praxikon:eu:ai-act:evidence:article-50-implementation-record

    Record of scenario, actor, disclosure or marking, technical implementation, test and owner.

    Hangs off: Article 50: transparency

    Editorially reviewed | evidence, transparency

  148. Evidencev1.0.03 relations

    Systemic-risk file

    praxikon:eu:ai-act:evidence:article-55-gpai-systemic-risk-record

    Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.

    Hangs off: Article 55: GPAI models with systemic risk

    Editorially reviewed | evidence, gpai-systemic-risk

  149. EvidenceEditorialv1.0.04 relations

    Record of the decision on a code of practice

    praxikon:eu:ai-act:evidence:article-56-code-adherence-decision-record

    Per model: the decision whether or not to adhere to a code of practice, the version and chapter it relates to, the date and the authorised signatory, whether adherence was limited under paragraph 7 to the obligations in Article 53, and, where the decision is negative, the elaboration of your own for the issues in paragraph 2.

    Hangs off: Article 56: codes of practice for general-purpose AI models

    Editorially reviewed | evidence, governance, gpai, gpai-systemic-risk

  150. EvidenceApplicablev1.0.04 relations

    Information pack for subjects of testing in real world conditions

    praxikon:eu:ai-act:evidence:article-61-subject-information-pack

    The document that precedes consent: per test the five points of Article 61(1) written out, with the Union-wide unique single identification number, the contact details from whom further information can be obtained, and the mechanism for requesting the reversal or the disregarding of an output. This is a different item from the dated consent record itself, which sits in article-61-informed-consent-record.

    Hangs off: Article 61: informed consent of test subjects for testing in real world conditions

    Editorially reviewed | evidence, fundamental-rights, innovation

What this explorer does not do

  • There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
  • No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
  • A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
  • The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
  • The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
  • Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.

The same selection as data

The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.