Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Active filters
Objects
57 objects in this selection.
- ControlApplicablev1.0.05 relations
Intake and deadline tracking for a demand or an inspection
praxikon:eu:ai-act:control:ai-office-proceeding-response
The control that ensures an information request, a notice of investigation or an announced inspection from the AI Office reaches an identifiable person, that it is first established whether it is a simple request or a decision, that the period set is tracked, and that what was supplied is recorded. The substance is sanctioned too: a periodic penalty payment can be imposed where you fail to give correct or complete answers during an ordered inspection, and incorrect, incomplete or misleading information supplied to the Office falls under the fines of Article 99(5). A retention order under Article 75a(6) belongs in this control, because it overrides your deletion routines.
Hangs off: Article 75(1a) and (1e): reporting to and assessment by the AI Office, Article 75: market surveillance, mutual assistance and the powers of the AI Office
Editorially reviewed | control, enforcement
- ControlUpcomingv1.0.03 relations
Reassessment on a change of product or assessment route
praxikon:eu:ai-act:control:annex-i-product-route-change-gate
The control that reruns the route determination as soon as the product, the AI function, the conformity assessment procedure chosen or the list in Annex I changes, instead of standing still after the first market introduction. The move of machinery to Section B on 27 July 2026 shows that the list moves too.
Hangs off: Article 6(1): the product route to high risk
Editorially reviewed | control, high-risk
- ControlUpcomingv1.0.04 relations
Reassessment on a change of intended purpose
praxikon:eu:ai-act:control:annex-iii-area-rescan-trigger
The control that ensures a change of intended purpose, a new vendor feature, a new use inside the organisation or a delegated act under Article 7 triggers a fresh assessment of the mapping to a point of Annex III, instead of the first record standing for years while the system or the list moves.
Hangs off: Annex III: the eight areas separately
Editorially reviewed | high-risk
- Controlv1.0.04 relations
Reclassification on purpose or context change
praxikon:eu:ai-act:control:annex-iii-change-trigger
Reopen classification when intended purpose, use context or system functionality changes materially.
Hangs off: Annex III: high-risk AI
Editorially reviewed | control, high-risk
- ControlUpcomingv1.0.03 relations
Procurement gate: no signature without a completed classification answer
praxikon:eu:ai-act:control:annex-iii-procurement-gate
Block signature of an AI contract until the supplier has answered in writing which Annex III point the intended purpose falls under, whether it relies on Article 6(3), and whether the system profiles natural persons.
Hangs off: Annex III: high-risk AI
Editorially reviewed | high-risk
- Controlv1.0.04 relations
Data check before retraining
praxikon:eu:ai-act:control:article-10-data-governance-control
Repeat the data quality assessment before every retraining or dataset change.
Hangs off: Article 10: data and data governance
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Documentation update on every release
praxikon:eu:ai-act:control:article-11-technical-documentation-control
Update the file before every release and retain earlier versions traceably.
Hangs off: Article 11: technical documentation
Editorially reviewed | control, high-risk-requirements
Periodically verify that logging works, is complete and is retained according to the regime.
Hangs off: Article 12: logging and traceability
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Instructions check at deployment
praxikon:eu:ai-act:control:article-13-instructions-control
At every deployment and update, verify instructions are present, current and internally translated.
Hangs off: Article 13: transparency towards deployers
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.04 relations
Oversight test before go-live
praxikon:eu:ai-act:control:article-14-human-oversight-control
Before go-live, test that intervening, stopping and disregarding output actually works and is assigned.
Hangs off: Article 14: human oversight
Editorially reviewed | control, high-risk-requirements
- Controlv1.0.03 relations
Performance monitoring in use
praxikon:eu:ai-act:control:article-15-accuracy-robustness-control
Monitor whether the system stays within declared levels in production and escalate on deviation.
Hangs off: Article 15: accuracy, robustness and cybersecurity
Editorially reviewed | control, high-risk-requirements
- ControlUpcomingv1.0.03 relations
Release gate before placing on the market
praxikon:eu:ai-act:control:article-16-pre-market-release-gate
A hard block in your release or delivery process: no delivery without a completed conformity assessment, a signed EU declaration of conformity, an affixed CE marking and a completed registration.
Hangs off: Article 16: the twelve duties of a provider of a high-risk AI system
Editorially reviewed | high-risk-requirements
- Controlv1.0.03 relations
Internal audit cycle
praxikon:eu:ai-act:control:article-17-quality-management-control
Periodically audit whether practice follows the described system and record deviations and improvements.
Hangs off: Article 17: quality management system
Editorially reviewed | control, high-risk-requirements
- ControlUpcomingv1.0.03 relations
Periodic check on completeness and retrievability of the retention file
praxikon:eu:ai-act:control:article-18-retention-review
The control that keeps the file complete per system, tracks the end date of the period, and ensures the documents can still be opened after a systems migration, a reorganisation or a change of supplier.
Hangs off: Article 18: documentation keeping
Editorially reviewed | control, high-risk-requirements
- ControlApplicablev1.0.03 relations
Coverage reconciliation: every person with AI access appears in the register
praxikon:eu:ai-act:control:article-4-coverage-reconciliation
Periodically reconcile the list of accounts and licences with access to AI systems against the participation and instruction register, and clear the gap list with an owner and a deadline.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy
- Controlv1.0.04 relations
Periodic role and context review
praxikon:eu:ai-act:control:article-4-periodic-review
Check when systems, roles or risks change whether the selected measures remain appropriate.
Hangs off: Article 4: AI literacy
Editorially reviewed | ai-literacy, control
- ControlEditorialv1.0.05 relations
Review of an authorisation expiring, being refused or withdrawn
praxikon:eu:ai-act:control:article-46-derogation-exit-review
The control that keeps a system running under Article 46 under watch: the ongoing conformity assessment has an owner and an end date, the fifteen calendar days of paragraph 4 are in the calendar, and a rehearsed plan is in place to stop use with immediate effect and discard all results and outputs if the authorisation is refused or withdrawn.
Hangs off: Article 46: derogation from conformity assessment procedure
Editorially reviewed | conformity, control, enforcement
- ControlApplicablev1.0.07 relations
Release gate: no market entry without registration
praxikon:eu:ai-act:control:article-49-pre-market-registration-gate
The control that stops any Annex III system from being placed on the market, put into service or used before the registration is complete, with an explicit check on the Article 6(3) route and on the Article 26(8) question whether the provider entry is present in the database.
Hangs off: Article 49: registration in the EU database before the system reaches the market
Editorially reviewed | conformity, control, high-risk
- Controlv1.0.04 relations
Article 5 gate at intake and change
praxikon:eu:ai-act:control:article-5-intake-gate
Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.
Hangs off: Article 5: prohibited practices
Editorially reviewed | control, prohibited-practices
- ControlApplicablev1.0.03 relations
Quarterly sampling of live disclosures and markings in production
praxikon:eu:ai-act:control:article-50-production-sampling
Each quarter, sample the systems carrying an Article 50 scenario and verify in the production environment that the disclosure still appears and the marking is still present in the actual output, recording finding, owner and remediation deadline.
Hangs off: Article 50: transparency
Editorially reviewed | transparency
- Controlv1.0.04 relations
Pre-release transparency check
praxikon:eu:ai-act:control:article-50-release-check
Before release, test that the applicable disclosure, marking or label is timely, clear and technically effective.
Hangs off: Article 50: transparency
Editorially reviewed | control, transparency
- Controlv1.0.03 relations
Compute threshold monitoring
praxikon:eu:ai-act:control:article-55-gpai-systemic-risk-control
Monitor cumulative training compute and notify the Commission when the threshold is reached.
Hangs off: Article 55: GPAI models with systemic risk
Editorially reviewed | control, gpai-systemic-risk
- ControlEditorialv1.0.04 relations
Review moment on your reliance on a code of practice
praxikon:eu:ai-act:control:article-56-code-commitment-review
The control that periodically rechecks a reliance on a code of practice: does the version you rely on still stand, has the code been reviewed or adapted under paragraph 8, has the Commission published its assessment of adequacy under paragraph 6 as replaced by Regulation (EU) 2026/1744, and has the Commission laid down common rules under paragraph 9.
Hangs off: Article 56: codes of practice for general-purpose AI models
Editorially reviewed | control, governance, gpai, gpai-systemic-risk
- ControlApplicablev1.0.03 relations
Supervision inside the sandbox and the conditional fine shield
praxikon:eu:ai-act:control:article-57-sandbox-supervision-and-fine-shield
The authority retains its supervisory and corrective powers and can suspend your testing or participation. If you stay within the plan and follow the guidance in good faith, authorities impose no administrative fines for infringements of this Regulation.
Hangs off: Article 57: AI regulatory sandboxes
Editorially reviewed | innovation
- ControlApplicablev1.0.04 relations
Oversight during the test, incident reporting and recall procedure
praxikon:eu:ai-act:control:article-60-oversight-and-incident-response
The market surveillance authority may inspect unannounced. On a serious incident you report, take immediate mitigation or suspend, and you must have a procedure in place in advance for prompt recall of the system.
Hangs off: Article 60: testing in real world conditions outside a sandbox
Editorially reviewed | innovation
- ControlEditorialv1.0.04 relations
Consent and withdrawal review before a test in real world conditions starts
praxikon:eu:ai-act:control:article-61-consent-and-withdrawal-review
The control that no subject participates before the information pack is complete, the consent record is dated and a copy has been given, and that the withdrawal route with its recipient, period and deletion step works and has been rehearsed once.
Hangs off: Article 61: informed consent of test subjects for testing in real world conditions
Editorially reviewed | control, fundamental-rights, innovation
- ControlEditorialv1.0.04 relations
Fee and access review on a conformity assessment
praxikon:eu:ai-act:control:article-62-fee-and-access-review
The control that on every application for a conformity assessment under Article 43 and on every sandbox application it is checked whether the SME facilities have been invoked and whether the proportionate fee reduction has been made visible, and that the answer reaches the procurement file.
Hangs off: Article 62: measures for providers and deployers that are SMEs or start-ups
Editorially reviewed | control, governance, innovation
- ControlEditorialv1.0.03 relations
Review of the boundary of the simplification
praxikon:eu:ai-act:control:article-63-simplification-boundary-review
The control that every simplification you make under Article 63 is tested against paragraph 2, so that no item from Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73 falls away, and that the shareholding structure test is redone at every change.
Hangs off: Article 63: derogations for SMEs in the quality management system
Editorially reviewed | control, high-risk-requirements, innovation
- Controlv1.0.04 relations
Signal-to-action loop
praxikon:eu:ai-act:control:article-72-post-market-monitoring-control
Ensure real-world signals (deviations, complaints, incidents) demonstrably lead to analysis and, where needed, measures.
Hangs off: Article 72: post-market monitoring
Editorially reviewed | control, post-market
- Controlv1.0.04 relations
Incident drill and deadline watch
praxikon:eu:ai-act:control:article-73-incident-reporting-control
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Hangs off: Article 73: serious incident reporting
Editorially reviewed | control, post-market
- ControlEditorialv1.0.05 relations
Review before handing over source code or trade secrets
praxikon:eu:ai-act:control:article-78-disclosure-review
The control that sends a submission touching source code, training methodology or trade secrets through a fixed review: is the request reasoned, what purpose was stated, which part is strictly necessary, and who inside the organisation signs off on it.
Hangs off: Article 78: confidentiality of what you submit to an authority
Editorially reviewed | control, enforcement, governance
- ControlEditorialv1.0.03 relations
Review of the overlap with sectoral product documentation
praxikon:eu:ai-act:control:article-8-integrated-documentation-review
The control that ensures, for a system inside a product under Section A of Annex I, that the choice in paragraph 2 was made deliberately and remains visible: a cross-reference per requirement of Section 2 into the existing technical file, or two files with a recorded owner who keeps them in step.
Hangs off: Article 8: compliance with the requirements for high-risk AI systems
Editorially reviewed | conformity, control, high-risk-requirements
- Controlv1.0.03 relations
Reassessment on every material change
praxikon:eu:ai-act:control:article-9-risk-management-control
Reopen the risk management process on changes in purpose, data, model or use context and before every release.
Hangs off: Article 9: risk management system
Editorially reviewed | control, high-risk-requirements
- ControlEditorialv1.0.04 relations
Review that keeps voluntary and mandatory apart
praxikon:eu:ai-act:control:article-95-voluntary-versus-mandatory-review
The control that no external statement, quotation, tender response or annual report presents a code of conduct as cover for an obligation under the Regulation, and that every voluntary commitment has an owner, an indicator and a moment of measurement before it goes out.
Hangs off: Article 95: codes of conduct for voluntary application of specific requirements
Editorially reviewed | control, governance, innovation
- ControlEditorialv1.0.08 relations
Recording of the factors in Article 99(7)
praxikon:eu:ai-act:control:article-99-101-mitigating-factor-record
The control that ensures the factors which determine the amount of a fine are recorded at the time and not reconstructed afterwards: which technical and organisational measures were in place, when you notified an infringement yourself, how you responded to requests from the authority, and what you did to mitigate the harm suffered by affected persons. Those factors cut both ways, so the same record can also count against you; that is a reason to keep it properly rather than not at all.
Hangs off: Article 99, 100 and 101: the penalty structure per obligation
Editorially reviewed | control, enforcement
- ControlUpcomingv1.0.03 relations
Intake and deadline tracking of a request from an authority
praxikon:eu:ai-act:control:authority-request-intake-and-deadline
The control that ensures an incoming request from a competent authority reaches an identifiable owner the same day, that the documents requested are matched to the right system version, and that delivery is complete within the period set by the authority.
Hangs off: Article 21: cooperation with competent authorities
Editorially reviewed | control, high-risk-requirements
- ControlApplicablev1.0.05 relations
Access and deletion control for bias testing
praxikon:eu:ai-act:control:bias-testing-data-deletion
The control that ensures the special categories stay with authorised people, are not transmitted, transferred or otherwise accessed by other parties, and are actually deleted once the bias has been corrected or the retention period ends, instead of lingering because nobody watches the deadline.
Hangs off: Article 4a: legal basis for bias testing with special categories of personal data
Editorially reviewed | fundamental-rights, high-risk-requirements
- Controlv1.0.03 relations
Monitoring of certificate, modification and body
praxikon:eu:ai-act:control:certificate-expiry-monitoring
The control that ensures three signals reach an identifiable person in time instead of surfacing only once the certificate has already lapsed or been suspended: an approaching expiry date, a change that may be substantial within the meaning of Article 43(4), and a notice from or about the notified body itself, including the notification within ten days on suspension, restriction or withdrawal of its designation and the confirmation that Article 36(8), point (b), requires from the provider within three months.
Hangs off: Article 44: certificates of notified bodies
Editorially reviewed | conformity, control
- Controlv1.0.04 relations
Reassessment on substantial modification
praxikon:eu:ai-act:control:conformity-ce-registration-control
Rerun the conformity route whenever the system is substantially modified.
Hangs off: Articles 43-49: conformity assessment, CE and registration
Editorially reviewed | conformity, control
- ControlUpcomingv1.0.04 relations
Suspension and incident notification control
praxikon:eu:ai-act:control:deployer-suspension-and-incident-control
A fixed rule that suspends use and notifies in the correct order as soon as you have reason to consider the system presents a risk or as soon as you identify a serious incident.
Hangs off: Article 26: obligations of deployers of high-risk AI systems
Editorially reviewed | high-risk-requirements
- ControlUpcomingv1.0.04 relations
Review gate on a design change
praxikon:eu:ai-act:control:design-change-review-gate
The control that ensures no change to a legacy high-risk system reaches production without a recorded judgement on whether it is significant, with an identifiable assessor and a demonstrable link to the release.
Hangs off: Article 111(2): legacy high-risk systems and the 2 August 2030 date
Editorially reviewed | high-risk, timeline
- ControlUpcomingv1.0.03 relations
Distributor corrective action, withdrawal and recall control
praxikon:eu:ai-act:control:distributor-corrective-action-control
A pre-arranged capability to bring an already supplied system into conformity, withdraw it or recall it, and to immediately notify the provider or importer and the competent authorities.
Hangs off: Article 24: obligations of distributors
Editorially reviewed | value-chain
- ControlUpcomingv1.0.05 relations
Currency check on the database entry
praxikon:eu:ai-act:control:eu-database-entry-currency
The control that ensures a change of status, Member States, certificate or declaration of conformity leads to an updated entry within a set period, and that a public deployer notices when the provider does not enter its Section A or enters it late, instead of the public page quietly lagging behind reality.
Hangs off: Article 71: EU database for high-risk AI systems listed in Annex III
Editorially reviewed | conformity, control
- ControlApplicablev1.0.05 relations
Routing and deadline tracking of a request for an explanation
praxikon:eu:ai-act:control:explanation-request-routing
The control that ensures an incoming request reaches an identifiable person within a set period and is answered, instead of sitting in a general inbox.
Hangs off: Article 85: right to lodge a complaint with the market surveillance authority, Article 86: right to an explanation of a decision
Editorially reviewed | fundamental-rights
- ControlUpcomingv1.0.04 relations
Currency check on the FRIA elements during use
praxikon:eu:ai-act:control:fria-in-use-currency-check
Periodically and on every change in process, duration of use, affected groups, risks or oversight measures, check whether the recorded elements still hold, and update the information as soon as they do not.
Hangs off: Article 27: FRIA
Editorially reviewed | fundamental-rights
- Controlv1.0.05 relations
Pre-deployment FRIA go/no-go
praxikon:eu:ai-act:control:fria-pre-deployment-gate
Block deployment until applicability, assessment, mitigation and notification have been completed.
Hangs off: Article 27: FRIA
Editorially reviewed | control, fundamental-rights
- ControlApplicablev1.0.02 relations
Half-yearly review of whether your chosen compliance route still covers you
praxikon:eu:ai-act:control:gpai-compliance-route-review
Establish every six months whether you demonstrate compliance through a code of practice, through a published harmonised standard, or through alternative adequate means, and whether the underlying file matches that choice.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | gpai
- Controlv1.0.03 relations
GPAI documentation change control
praxikon:eu:ai-act:control:gpai-documentation-change-control
Update documentation and downstream information when the model, capabilities or risks change.
Hangs off: Article 53: GPAI model providers
Editorially reviewed | control, gpai
- ControlApplicablev1.0.04 relations
Periodic review and termination of the mandate
praxikon:eu:ai-act:control:gpai-mandate-review
The control that ensures the representative can actually reach the documentation, that the verification under paragraph 3(a) is repeated at a fixed moment, and that there is an agreed route for the termination under paragraph 5 with the immediate notification to the AI Office. Without such a moment a mandate stays on paper while nobody tests it.
Hangs off: Article 54: authorised representative of a provider of a GPAI model
Editorially reviewed | control, gpai
- ControlUpcomingv1.0.03 relations
Stop rule and notification route on doubts about conformity
praxikon:eu:ai-act:control:importer-stop-and-notify-control
As soon as you have sufficient reason to consider a system non-conforming or falsified, it does not go to market, and where there is a risk you notify the provider, the authorised representative and the market surveillance authorities.
Hangs off: Article 23: obligations of importers
Editorially reviewed | value-chain
- ControlUpcomingv1.0.03 relations
Escalation gate on a suspicion of non-conformity
praxikon:eu:ai-act:control:non-conformity-escalation-gate
The control that ensures a signal about possible non-conformity reaches an identifiable decision maker within a set period, that it is decided there whether paragraph 1 or also paragraph 2 comes into play and whether the reporting duty of Article 73 runs alongside it, and that the decision is recorded with a date instead of remaining in a support ticket.
Hangs off: Article 20: corrective actions and duty of information
Editorially reviewed | control, post-market
- ControlEditorialv1.0.03 relations
Control on the continuity of your conformity assessment
praxikon:eu:ai-act:control:notified-body-continuity-review
The control that absorbs the loss of a notified body: a fixed periodic check of the public list, a contractual reporting duty mirroring the ten days of Article 36(5), a named alternative body for your type of system, and a handover procedure that stays within the nine months of Article 36(3) and (9).
Hangs off: Articles 28 to 39: notifying authorities and notified bodies
Editorially reviewed | conformity, control, governance
- ControlEditorialv1.0.04 relations
Watch on publications in the Official Journal
praxikon:eu:ai-act:control:official-journal-citation-watch
The control that keeps the coverage matrix current: a fixed check on new references of harmonised standards, on new or amended common specifications, and on the repeal that Article 41(4) prescribes once a standard is published, with a named owner who then updates the matrix.
Hangs off: Articles 40 to 42: standards, common specifications and presumption of conformity
Editorially reviewed | conformity, control, standards
- ControlEditorialv1.0.04 relations
Protection of the person reporting
praxikon:eu:ai-act:control:reporting-person-protection
The control that ensures a report does not reach a line manager in identifiable form and that a person reporting who meets the conditions of Directive (EU) 2019/1937 is not treated differently afterwards. Article 19 of that Directive prohibits retaliation in any form, Article 21 sets out the protection and places the burden of proof on the organisation once the person reporting makes the detriment plausible. That is enforced not through the AI Regulation but through national whistleblower law. Without this control the channel exists but goes unused, and the first person who noticed something never reaches you.
Hangs off: Article 87: reporting of infringements and protection of reporting persons
Editorially reviewed | control, fundamental-rights
- ControlEditorialv1.0.03 relations
Reassessment on a change of function or purpose
praxikon:eu:ai-act:control:safety-component-reassessment-trigger
The control that ensures the assessment is redone as soon as the intended purpose, the function of the component or the applicable harmonisation legislation changes, so that a system does not stay outside the route on the basis of an outdated description. A recommended practice, not a legal duty.
Hangs off: Article 6(1a) to (1c): the tightened classification route
Editorially reviewed | conformity, high-risk
- ControlApplicablev1.0.03 relations
Deadline tracking of the notification
praxikon:eu:ai-act:control:systemic-risk-notification-deadline
The control that ensures the signal from the training pipeline reaches an identifiable owner and that the notification goes out within two weeks. Its trigger point is the allocation of compute and not the end of the run, because recital 111 also counts pre-training, synthetic data and fine-tuning and recital 112 assumes the provider knows the outcome before then. It sits alongside the monitoring of compute itself: that measures the threshold, this guards the clock that starts afterwards.
Hangs off: Article 52: notification of a GPAI model with systemic risk
Editorially reviewed | gpai-systemic-risk
- Controlv1.0.04 relations
Role reassessment on every change
praxikon:eu:ai-act:control:value-chain-representative-control
Repeat the role assessment on every rebranding, modification or new use of an existing system.
Hangs off: Articles 22-25: value chain and authorised representative
Editorially reviewed | control, value-chain
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.