Explorer
Why this object hangs off that object
Every object in this graph has its own address and can be cited on its own. This page shows which objects exist and, once you open one, why it hangs off another: from which source with its locator, through which condition or exception, to which consequence.
Since the last release an obligation states separately who carries the duty and who is merely affected. Filter by duty holder and you get the duties resting on a role; filter by actor and you get everything that is about that role. That difference is visible on purpose.
This is the knowledge layer under the four levels of the assessment. See the four levels.
Filters
Only dimensions the data carries. A dimension without values is absent rather than empty.
Active filters
Objects
54 objects in this selection.
- ObligationUpcomingv1.0.019 relations
Annex III: the eight areas separately
praxikon:eu:ai-act:obligation:annex-iii-eight-areas
Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.
Placed against the official source | high-risk
- ObligationUpcomingv1.0.066 relations
Annex III: high-risk AI
praxikon:eu:ai-act:obligation:annex-iii-high-risk
Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.
Placed against the official source | high-risk
- ObligationUpcomingv1.0.013 relations
Article 10: data and data governance
praxikon:eu:ai-act:obligation:article-10-data-governance
Quality and governance requirements for training, validation and test data of high-risk AI.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.011 relations
Article 11: technical documentation
praxikon:eu:ai-act:obligation:article-11-technical-documentation
The technical file demonstrating before market placement that a high-risk system meets the requirements.
Placed against the official source | high-risk-requirements
- ObligationApplicablev1.0.020 relations
Article 111(2): legacy high-risk systems and the 2 August 2030 date
praxikon:eu:ai-act:obligation:article-111-legacy-public-systems
High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.
Placed against the official source | high-risk, timeline
- ObligationUpcomingv1.0.015 relations
Article 12: logging and traceability
praxikon:eu:ai-act:obligation:article-12-logging
Automatic recording of events over the lifetime of a high-risk AI system.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.011 relations
Article 13: transparency towards deployers
praxikon:eu:ai-act:obligation:article-13-instructions
Comprehensible instructions for use and system information so deployers can operate the system correctly.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.012 relations
Article 14: human oversight
praxikon:eu:ai-act:obligation:article-14-human-oversight
High-risk AI must be designed so that humans can effectively oversee it and intervene.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.012 relations
Article 15: accuracy, robustness and cybersecurity
praxikon:eu:ai-act:obligation:article-15-accuracy-robustness
Appropriate levels of performance, robustness and security across the lifecycle of high-risk AI.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.010 relations
Article 16: the twelve duties of a provider of a high-risk AI system
praxikon:eu:ai-act:obligation:article-16-provider-obligations
Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.013 relations
Article 17: quality management system
praxikon:eu:ai-act:obligation:article-17-quality-management
The documented quality system through which a high-risk AI provider structurally assures compliance.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.012 relations
Article 18: documentation keeping
praxikon:eu:ai-act:obligation:article-18-document-retention
The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.015 relations
Article 20: corrective actions and duty of information
praxikon:eu:ai-act:obligation:article-20-corrective-actions
A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.
Placed against the official source | high-risk-requirements, post-market
- ObligationUpcomingv1.0.012 relations
Article 21: cooperation with competent authorities
praxikon:eu:ai-act:obligation:article-21-cooperation-with-authorities
Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.
Placed against the official source | high-risk-requirements
- ObligationUpcomingv1.0.011 relations
Article 23: obligations of importers
praxikon:eu:ai-act:obligation:article-23-importer-obligations
Before placing a system on the market the importer verifies four things about the provider, and afterwards carries its own retention, information and notification package with a ten-year term.
Placed against the official source | value-chain
- ObligationUpcomingv1.0.010 relations
Article 24: obligations of distributors
praxikon:eu:ai-act:obligation:article-24-distributor-obligations
Before making a system available on the market the distributor verifies the marking, the declaration and the instructions for use plus compliance by provider and importer, and must afterwards be able to correct, withdraw or recall.
Placed against the official source | value-chain
- ObligationUpcomingv1.0.013 relations
Article 26: obligations of deployers of high-risk AI systems
praxikon:eu:ai-act:obligation:article-26-deployer-obligations
Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.
Placed against the official source | high-risk-requirements
Fundamental rights impact assessment before deploying certain high-risk AI systems.
Placed against the official source | fundamental-rights, high-risk
- ObligationApplicablev1.0.010 relations
Articles 28 to 39: notifying authorities and notified bodies
praxikon:eu:ai-act:obligation:article-28-39-notified-bodies
Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.
Placed against the official source | conformity, governance
- ObligationApplicablev2.0.046 relations
Article 4: AI literacy
praxikon:eu:ai-act:obligation:article-4-ai-literacy
Providers and deployers take measures that support the development of AI literacy.
Placed against the official source | ai-literacy
- ObligationApplicablev1.0.012 relations
Articles 40 to 42: standards, common specifications and presumption of conformity
praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications
A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.
Placed against the official source | conformity, standards
- ObligationApplicablev1.0.09 relations
Article 44: certificates of notified bodies
praxikon:eu:ai-act:obligation:article-44-notified-body-certificates
A certificate issued by a notified body is valid for at most five years for AI systems covered by Annex I and at most four years for AI systems covered by Annex III, and may be extended at the request of the provider after a re-assessment. Where the system no longer meets the requirements of Section 2, the body shall, taking account of the principle of proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes corrective action within an appropriate deadline it sets so as to ensure compliance with those requirements. An appeal procedure against that decision is available.
Placed against the official source | conformity
- ObligationApplicablev1.0.012 relations
Article 46: derogation from conformity assessment procedure
praxikon:eu:ai-act:obligation:article-46-derogation-from-conformity-assessment
By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.
Placed against the official source | conformity, enforcement
- ObligationApplicablev1.0.017 relations
Article 49: registration in the EU database before the system reaches the market
praxikon:eu:ai-act:obligation:article-49-registration
The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.
Placed against the official source | conformity, high-risk
- ObligationApplicablev1.0.016 relations
Article 4a: legal basis for bias testing with special categories of personal data
praxikon:eu:ai-act:obligation:article-4a-bias-testing-legal-basis
Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).
Placed against the official source | fundamental-rights, high-risk-requirements
- ObligationApplicablev1.0.030 relations
Article 5: prohibited practices
praxikon:eu:ai-act:obligation:article-5-prohibited-practices
The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.
Placed against the official source | prohibited-practices
- ObligationApplicablev1.0.048 relations
Article 50: transparency
praxikon:eu:ai-act:obligation:article-50-transparency
Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.
Placed against the official source | transparency
- ObligationApplicablev1.0.015 relations
Article 52: notification of a GPAI model with systemic risk
praxikon:eu:ai-act:obligation:article-52-systemic-risk-classification
The provider of a general-purpose AI model that meets the condition in Article 51(1), point (a), notifies the Commission without delay and in any event within two weeks, with the information needed to demonstrate that the requirement has been met. With that notification the provider may present substantiated arguments that the model exceptionally does not present systemic risks after all.
Placed against the official source | gpai-systemic-risk
- ObligationApplicablev1.0.028 relations
Article 53: GPAI model providers
praxikon:eu:ai-act:obligation:article-53-gpai
Documentation, information, copyright and transparency duties for providers of general-purpose AI models.
Placed against the official source | gpai
- ObligationApplicablev1.0.015 relations
Article 54: authorised representative of a provider of a GPAI model
praxikon:eu:ai-act:obligation:article-54-gpai-authorised-representative
A provider established in a third country appoints, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market. The representative performs the tasks the mandate assigns to it and provides a copy of that mandate to the AI Office upon request. The mandate empowers it at least to verify the documentation, keep a copy available for ten years, provide information and cooperate, and appoints it as the point of contact in addition to or instead of the provider.
Hangs off: Article 53: GPAI model providers, Article 55: GPAI models with systemic risk
Placed against the official source | gpai, value-chain
- ObligationApplicablev1.0.015 relations
Article 55: GPAI models with systemic risk
praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk
Additional duties for the most capable general-purpose AI models, on top of Article 53.
Placed against the official source | gpai-systemic-risk
- ObligationApplicablev1.0.011 relations
Article 56: codes of practice for general-purpose AI models
praxikon:eu:ai-act:obligation:article-56-gpai-codes-of-practice
The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.
Placed against the official source | governance, gpai, gpai-systemic-risk
- ObligationApplicablev1.0.012 relations
Article 57: AI regulatory sandboxes
praxikon:eu:ai-act:obligation:article-57-regulatory-sandboxes
Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.
Placed against the official source | innovation
- ObligationUpcomingv1.0.011 relations
Article 6(1): the product route to high risk
praxikon:eu:ai-act:obligation:article-6-1-annex-i-product-route
An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.
Placed against the official source | conformity, high-risk
- ObligationIn forcev1.0.010 relations
Article 6(1a) to (1c): the tightened classification route
praxikon:eu:ai-act:obligation:article-6-1bis-1quater-route
The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.
Placed against the official source | conformity, high-risk
- ObligationApplicablev1.0.012 relations
Article 60: testing in real world conditions outside a sandbox
praxikon:eu:ai-act:obligation:article-60-real-world-testing
If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.
Placed against the official source | innovation
- ObligationApplicablev1.0.012 relations
Article 61: informed consent of test subjects for testing in real world conditions
praxikon:eu:ai-act:obligation:article-61-informed-consent
If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.
Placed against the official source | fundamental-rights, innovation
- ObligationApplicablev1.0.011 relations
Article 62: measures for providers and deployers that are SMEs or start-ups
praxikon:eu:ai-act:obligation:article-62-sme-support-measures
Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.
Placed against the official source | governance, innovation
- ObligationApplicablev1.0.09 relations
Article 63: derogations for SMEs in the quality management system
praxikon:eu:ai-act:obligation:article-63-sme-derogations
SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Until 27 July 2026 this read microenterprises; Article 1, point (26), of Regulation (EU) 2026/1744 replaced paragraph 1 and widened the circle to SMEs. Which elements those are is for the Commission to set out in guidelines, considering the needs of SMEs and without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 rules out any wider reading: the provision shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.
Placed against the official source | high-risk-requirements, innovation
- ObligationUpcomingv1.0.015 relations
Article 71: EU database for high-risk AI systems listed in Annex III
praxikon:eu:ai-act:obligation:article-71-eu-database
The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.
Placed against the official source | conformity, high-risk
- ObligationApplicablev2.0.015 relations
Article 72: post-market monitoring
praxikon:eu:ai-act:obligation:article-72-post-market-monitoring
Systematic monitoring of high-risk AI in real use, after market placement.
Placed against the official source | post-market
- ObligationApplicablev2.0.015 relations
Article 73: serious incident reporting
praxikon:eu:ai-act:obligation:article-73-incident-reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
Placed against the official source | post-market
- ObligationUpcomingv1.0.012 relations
Article 75(1a) and (1e): reporting to and assessment by the AI Office
praxikon:eu:ai-act:obligation:article-75-ai-office-high-risk-duties
If you are the provider of a high-risk AI system subject to the competence of the AI Office, you report serious incidents to the Office rather than to your national authority, with the machinery and the deadlines of Article 73(2) to (9) applying in full, and the Office still transmits the information to your national market surveillance authority. Where that system is subject to a third-party conformity assessment under Article 43, the Office is responsible for it, the notified body acts on behalf of the Commission, and you pay the costs directly to that body.
Placed against the official source | enforcement, governance, high-risk-requirements
- ObligationApplicablev1.0.013 relations
Article 75: market surveillance, mutual assistance and the powers of the AI Office
praxikon:eu:ai-act:obligation:article-75-market-surveillance-assistance
For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.
Placed against the official source | enforcement, governance, gpai
- ObligationApplicablev1.0.012 relations
Article 78: confidentiality of what you submit to an authority
praxikon:eu:ai-act:obligation:article-78-confidentiality
The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.
Placed against the official source | enforcement, governance
- ObligationUpcomingv1.0.010 relations
Article 8: compliance with the requirements for high-risk AI systems
praxikon:eu:ai-act:obligation:article-8-compliance-with-requirements
High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.
Placed against the official source | conformity, high-risk-requirements
- ObligationApplicablev2.0.011 relations
Article 85: right to lodge a complaint with the market surveillance authority
praxikon:eu:ai-act:obligation:article-85-right-to-complain
Anyone with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority. For an organisation that means your own staff, customers and candidates have a route to the regulator that does not run through you.
Placed against the official source | fundamental-rights
- ObligationApplicablev2.0.010 relations
Article 86: right to an explanation of a decision
praxikon:eu:ai-act:obligation:article-86-right-to-explanation
A person affected by a decision that a deployer takes on the basis of the output of a high-risk AI system listed in Annex III may request an explanation of the role of that system in the decision-making procedure and of the main elements of the decision taken.
Placed against the official source | fundamental-rights
- ObligationApplicablev1.0.010 relations
Article 87: reporting of infringements and protection of reporting persons
praxikon:eu:ai-act:obligation:article-87-reporting-infringements
The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.
Placed against the official source | fundamental-rights, governance
- ObligationUpcomingv1.0.013 relations
Article 9: risk management system
praxikon:eu:ai-act:obligation:article-9-risk-management
A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.
Placed against the official source | high-risk-requirements
- ObligationApplicablev1.0.011 relations
Article 95: codes of conduct for voluntary application of specific requirements
praxikon:eu:ai-act:obligation:article-95-voluntary-codes-of-conduct
The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.
Placed against the official source | governance, innovation
- ObligationApplicablev1.0.016 relations
Article 99, 100 and 101: the penalty structure per obligation
praxikon:eu:ai-act:obligation:article-99-101-penalties
The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.
Placed against the official source | enforcement, prohibited-practices
- ObligationApplicablev2.0.041 relations
Articles 43-49: conformity assessment, CE and registration
praxikon:eu:ai-act:obligation:conformity-ce-registration
The route from assessment to CE marking and EU database registration before market placement of high-risk AI.
Placed against the official source | conformity
- ObligationUpcomingv1.0.011 relations
Articles 22-25: value chain and authorised representative
praxikon:eu:ai-act:obligation:value-chain-representative
Role shifts in the AI value chain and the mandatory representative for non-EU providers.
Placed against the official source | value-chain
What this explorer does not do
- There is no article object. The article sits as a locator on the citations of an obligation, as free text. Filtering on the obligation is the same question, and the data does carry that.
- No object carries an Annex III domain or use case. A selection of the form "systems for this purpose" cannot be expressed here.
- A locator hangs on a statement in the data, not on a relation. The source next to a path is the source anchor of the object carrying the relation, not proof of that one connection.
- The split between duty holder and affected actor exists on obligations only. On every other type the actor list is still one undifferentiated list.
- The graph stores no inverse relations. The incoming direction is computed here over the same release and adds nothing to the data.
- Topics are free slugs, not a taxonomy with objects, labels or a hierarchy of their own.
The same selection as data
The explorer and the API read the same object against the same two time axes. What you see here can be fetched with the same parameters.