Praxikon

Obligations register

AI Act obligations from rule to evidence

Start with your role and situation. Every route separates official fact, our interpretation and recommended action and shows source, version and latest review.

Public and no account required. The official source remains authoritative.

  1. Upcomingv1.0.0

    Annex III: high-risk AI

    Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.

    Relevant to: Deployer, Provider of an AI system

    First action

    Classify the use case and document the outcome

    Evidence to retain

    Article 6 and Annex III classification record

    Open obligation
  2. Upcomingv1.0.0

    Article 10: data and data governance

    Quality and governance requirements for training, validation and test data of high-risk AI.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up data governance per dataset

    Evidence to retain

    Data governance file

    Open obligation
  3. Upcomingv1.0.0

    Article 11: technical documentation

    The technical file demonstrating before market placement that a high-risk system meets the requirements.

    Relevant to: Provider of an AI system

    First action

    Build the technical file per Annex IV

    Evidence to retain

    Technical file (Annex IV)

    Open obligation
  4. Upcomingv1.0.0

    Article 12: logging and traceability

    Automatic recording of events over the lifetime of a high-risk AI system.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design logging into the system

    Evidence to retain

    Logs and retention regime

    Open obligation
  5. Upcomingv1.0.0

    Article 13: transparency towards deployers

    Comprehensible instructions for use and system information so deployers can operate the system correctly.

    Relevant to: Deployer, Provider of an AI system

    First action

    Provide complete instructions for use

    Evidence to retain

    Instructions and interpretation file

    Open obligation
  6. Upcomingv1.0.0

    Article 14: human oversight

    High-risk AI must be designed so that humans can effectively oversee it and intervene.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design and assign effective human oversight

    Evidence to retain

    Oversight file per system

    Open obligation
  7. Upcomingv1.0.0

    Article 16: the twelve duties of a provider of a high-risk AI system

    Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.

    Relevant to: Provider of an AI system

    First action

    Assign an internal owner and a date to each point of Article 16

    Evidence to retain

    Provider dossier per high-risk AI system

    Open obligation
  8. Upcomingv1.0.0

    Article 17: quality management system

    The documented quality system through which a high-risk AI provider structurally assures compliance.

    Relevant to: Provider of an AI system

    First action

    Set up an AI quality management system

    Evidence to retain

    QMS documentation

    Open obligation
  9. Upcomingv1.0.0

    Article 23: obligations of importers

    Before placing a system on the market the importer verifies four things about the provider, and afterwards carries its own retention, information and notification package with a ten-year term.

    Relevant to: Importer

    First action

    Run the four verifications of Article 23(1) before importing

    Evidence to retain

    Importer dossier with ten-year retention

    Open obligation
  10. Upcomingv1.0.0

    Article 24: obligations of distributors

    Before making a system available on the market the distributor verifies the marking, the declaration and the instructions for use plus compliance by provider and importer, and must afterwards be able to correct, withdraw or recall.

    Relevant to: Distributor

    First action

    Perform the Article 24(1) check before making available

    Evidence to retain

    Distributor log of checks and corrective actions

    Open obligation
  11. Upcomingv1.0.0

    Article 26: obligations of deployers of high-risk AI systems

    Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.

    Relevant to: Deployer, Body governed by public law

    First action

    Assign human oversight and give those people a mandate

    Evidence to retain

    Deployment dossier: logs, worker information and information to affected persons

    Open obligation
  12. Upcomingv1.0.0

    Article 27: FRIA

    Fundamental rights impact assessment before deploying certain high-risk AI systems.

    Relevant to: Credit or insurance deployer, Body governed by public law, Private provider of public services

    First action

    Perform a FRIA before deployment

    Evidence to retain

    FRIA report and notification

    Open obligation
  13. Applicablev2.0.0

    Article 4: AI literacy

    Providers and deployers take measures that support the development of AI literacy.

    Relevant to: Deployer, Provider of an AI system

    First action

    Take role- and context-specific AI literacy measures

    Evidence to retain

    AI literacy measures record

    Open obligation
  14. Applicablev1.0.0

    Article 5: prohibited practices

    The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.

    Relevant to: Deployer, Provider of an AI system

    First action

    Screen every use case against Article 5 first

    Evidence to retain

    Article 5 screening record

    Open obligation
  15. Applicablev1.0.0

    Article 50: transparency

    Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.

    Relevant to: Deployer, Provider of an AI system

    First action

    Implement the applicable disclosure, marking or label

    Evidence to retain

    Transparency implementation record

    Open obligation
  16. Applicablev1.0.0

    Article 53: GPAI model providers

    Documentation, information, copyright and transparency duties for providers of general-purpose AI models.

    Relevant to: Provider of a GPAI model

    First action

    Maintain GPAI documentation and transparency information

    Evidence to retain

    GPAI compliance file

    Open obligation
  17. Applicablev1.0.0

    Article 55: GPAI models with systemic risk

    Additional duties for the most capable general-purpose AI models, on top of Article 53.

    Relevant to: Provider of a GPAI model

    First action

    Perform model evaluations and risk mitigation

    Evidence to retain

    Systemic-risk file

    Open obligation
  18. Applicablev1.0.0

    Article 57: AI regulatory sandboxes

    Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.

    Relevant to: Deployer, Provider of an AI system, Body governed by public law

    First action

    Apply to a sandbox and agree the sandbox plan

    Evidence to retain

    Written proof of participation and the exit report

    Open obligation
  19. Applicablev1.0.0

    Article 60: testing in real world conditions outside a sandbox

    If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.

    Relevant to: Deployer, Provider of an AI system

    First action

    Submit the testing plan, obtain approval and register the test

    Evidence to retain

    Dated and documented informed consent of test subjects

    Open obligation
  20. Upcomingv1.0.0

    Article 72: post-market monitoring

    Systematic monitoring of high-risk AI in real use, after market placement.

    Relevant to: Deployer, Provider of an AI system

    First action

    Draw up a post-market monitoring plan

    Evidence to retain

    Monitoring plan and reports

    Open obligation
  21. Upcomingv1.0.0

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up an incident process with reporting routes

    Evidence to retain

    Incident register and reports

    Open obligation
  22. Upcomingv1.0.0

    Article 9: risk management system

    A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.

    Relevant to: Provider of an AI system

    First action

    Set up an iterative risk management process

    Evidence to retain

    Risk management file

    Open obligation