Skip to main content
Praxikon

Obligations register

AI Act obligations from rule to evidence

Start with your role and situation. Every route separates official fact, our interpretation and recommended action and shows source, version and latest review.

Public and no account required. The official source remains authoritative.

Praxikon tracks every obligation under the EU AI Act, citing the source for every statement.

  1. Upcomingv1.0.0

    Annex III: the eight areas separately

    Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.

    Relevant to: Deployer, Provider of an AI system

    First action

    Map every system to a point of Annex III

    Evidence to retain

    Record of the mapping to a point of Annex III

    Open obligation
  2. Upcomingv1.0.0

    Annex III: high-risk AI

    Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.

    Relevant to: Deployer, Provider of an AI system

    First action

    Classify the use case and document the outcome

    Evidence to retain

    Article 6 and Annex III classification record

    Open obligation
  3. Upcomingv1.0.0

    Article 10: data and data governance

    Quality and governance requirements for training, validation and test data of high-risk AI.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up data governance per dataset

    Evidence to retain

    Data governance file

    Open obligation
  4. Applicablev1.0.0

    Article 111(2): legacy high-risk systems and the 2 August 2030 date

    High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.

    Relevant to: Authorised representative, Deployer, Distributor, Importer, Provider of an AI system

    First action

    Assess for every design change whether it is significant

    Evidence to retain

    Transition register of legacy high-risk systems

    Open obligation
  5. Upcomingv1.0.0

    Article 12: logging and traceability

    Automatic recording of events over the lifetime of a high-risk AI system.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design logging into the system

    Evidence to retain

    Logs and retention regime

    Open obligation
  6. Upcomingv1.0.0

    Article 13: transparency towards deployers

    Comprehensible instructions for use and system information so deployers can operate the system correctly.

    Relevant to: Deployer, Provider of an AI system

    First action

    Provide complete instructions for use

    Evidence to retain

    Instructions and interpretation file

    Open obligation
  7. Upcomingv1.0.0

    Article 14: human oversight

    High-risk AI must be designed so that humans can effectively oversee it and intervene.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design and assign effective human oversight

    Evidence to retain

    Oversight file per system

    Open obligation
  8. Upcomingv1.0.0

    Article 18: documentation keeping

    The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.

    Relevant to: Authorised representative, Deployer, Provider of an AI system

    First action

    Set up the ten year retention of the system documentation

    Evidence to retain

    Retention file per high-risk system

    Open obligation
  9. Upcomingv1.0.0

    Article 20: corrective actions and duty of information

    A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.

    Relevant to: Authorised representative, Deployer, Distributor, Importer, Provider of an AI system

    First action

    Set up the procedure for corrective actions and notification

    Evidence to retain

    Record of corrective actions

    Open obligation
  10. Upcomingv1.0.0

    Article 21: cooperation with competent authorities

    Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.

    Relevant to: Authorised representative, Deployer, Provider of an AI system

    First action

    Make your conformity file deliverable on request

    Evidence to retain

    Response file for a request from a competent authority

    Open obligation
  11. Upcomingv1.0.0

    Article 26: obligations of deployers of high-risk AI systems

    Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.

    Relevant to: Deployer, Body governed by public law

    First action

    Assign human oversight and give those people a mandate

    Evidence to retain

    Deployment dossier: logs, worker information and information to affected persons

    Open obligation
  12. Upcomingv1.0.0

    Article 27: FRIA

    Fundamental rights impact assessment before deploying certain high-risk AI systems.

    Relevant to: Credit or insurance deployer, Body governed by public law, Private provider of public services

    First action

    Perform a FRIA before deployment

    Evidence to retain

    FRIA report and notification

    Open obligation
  13. Applicablev2.0.0

    Article 4: AI literacy

    Providers and deployers take measures that support the development of AI literacy.

    Relevant to: Deployer, Provider of an AI system

    First action

    Take role- and context-specific AI literacy measures

    Evidence to retain

    AI literacy measures record

    Open obligation
  14. Applicablev1.0.0

    Article 46: derogation from conformity assessment procedure

    By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.

    Relevant to: Deployer, Provider of an AI system, Body governed by public law

    First action

    Prepare a derogation request and the exit plan that goes with it

    Evidence to retain

    File accompanying a request to derogate from the conformity assessment

    Open obligation
  15. Applicablev1.0.0

    Article 49: registration in the EU database before the system reaches the market

    The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.

    Relevant to: Authorised representative, Deployer, Distributor, Provider of an AI system, Body governed by public law

    First action

    Register yourself and the system before it reaches the market or is put into service

    Evidence to retain

    Article 49 registration dossier

    Open obligation
  16. Applicablev1.0.0

    Article 4a: legal basis for bias testing with special categories of personal data

    Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).

    Relevant to: Deployer, Provider of a GPAI model, Provider of an AI system

    First action

    Justify and record your reliance on Article 4a

    Evidence to retain

    Necessity file for bias testing

    Open obligation
  17. Applicablev1.0.0

    Article 5: prohibited practices

    The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.

    Relevant to: Deployer, Provider of an AI system

    First action

    Screen every use case against Article 5 first

    Evidence to retain

    Article 5 screening record

    Open obligation
  18. Applicablev1.0.0

    Article 50: transparency

    Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.

    Relevant to: Deployer, Provider of an AI system

    First action

    Implement the applicable disclosure, marking or label

    Evidence to retain

    Transparency implementation record

    Open obligation
  19. Applicablev1.0.0

    Article 57: AI regulatory sandboxes

    Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.

    Relevant to: Deployer, Provider of an AI system, Body governed by public law

    First action

    Apply to a sandbox and agree the sandbox plan

    Evidence to retain

    Written proof of participation and the exit report

    Open obligation
  20. Upcomingv1.0.0

    Article 6(1): the product route to high risk

    An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.

    Relevant to: Deployer, Provider of an AI system

    First action

    Establish the product route per product

    Evidence to retain

    Product route record

    Open obligation
  21. Applicablev1.0.0

    Article 60: testing in real world conditions outside a sandbox

    If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.

    Relevant to: Deployer, Provider of an AI system

    First action

    Submit the testing plan, obtain approval and register the test

    Evidence to retain

    Dated and documented informed consent of test subjects

    Open obligation
  22. Applicablev1.0.0

    Article 61: informed consent of test subjects for testing in real world conditions

    If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.

    Relevant to: Deployer, Provider of an AI system

    First action

    Inform the test subject and obtain consent to participate

    Evidence to retain

    Information pack for subjects of testing in real world conditions

    Open obligation
  23. Applicablev1.0.0

    Article 62: measures for providers and deployers that are SMEs or start-ups

    Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.

    Relevant to: Deployer, Provider of an AI system

    First action

    Make use of the SME facilities in Article 62

    Evidence to retain

    File on SME status and facilities used

    Open obligation
  24. Applicablev2.0.0

    Article 72: post-market monitoring

    Systematic monitoring of high-risk AI in real use, after market placement.

    Relevant to: Deployer, Provider of an AI system

    First action

    Draw up a post-market monitoring plan

    Evidence to retain

    Monitoring plan and reports

    Open obligation
  25. Applicablev2.0.0

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up an incident process with reporting routes

    Evidence to retain

    Incident register and reports

    Open obligation
  26. Applicablev1.0.0

    Article 75: market surveillance, mutual assistance and the powers of the AI Office

    For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.

    Relevant to: Deployer, Provider of an AI system

    First action

    Establish per system who your supervisor is

    Evidence to retain

    Record of the competent supervisor per system

    Open obligation
  27. Applicablev1.0.0

    Article 78: confidentiality of what you submit to an authority

    The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.

    Relevant to: Deployer, Provider of a GPAI model, Provider of an AI system

    First action

    Mark and register what you submit to an authority or body

    Evidence to retain

    Register of submissions to authorities

    Open obligation
  28. Applicablev2.0.0

    Article 85: right to lodge a complaint with the market surveillance authority

    Anyone with grounds to consider that the Regulation has been infringed may lodge a complaint with the relevant market surveillance authority. For an organisation that means your own staff, customers and candidates have a route to the regulator that does not run through you.

    Relevant to: Deployer

    First action

    Make sure you can answer a complaint with documents

    Evidence to retain

    Register of requests for an explanation

    Open obligation
  29. Applicablev2.0.0

    Article 86: right to an explanation of a decision

    A person affected by a decision that a deployer takes on the basis of the output of a high-risk AI system listed in Annex III may request an explanation of the role of that system in the decision-making procedure and of the main elements of the decision taken.

    Relevant to: Deployer

    First action

    Set up how you handle a request for an explanation

    Evidence to retain

    Register of requests for an explanation

    Open obligation
  30. Applicablev1.0.0

    Article 87: reporting of infringements and protection of reporting persons

    The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.

    Relevant to: Deployer, Provider of an AI system

    First action

    Make sure a report about an AI system reaches your reporting channel

    Evidence to retain

    File of reports about AI systems

    Open obligation
  31. Applicablev1.0.0

    Article 95: codes of conduct for voluntary application of specific requirements

    The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.

    Relevant to: Deployer, Provider of an AI system

    First action

    Scope a voluntary code of conduct and separate it from your duties

    Evidence to retain

    Register of voluntary commitments alongside the obligations

    Open obligation
  32. Applicablev1.0.0

    Article 99, 100 and 101: the penalty structure per obligation

    The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.

    Relevant to: Authorised representative, Deployer, Distributor, Provider of a GPAI model, Importer, Provider of an AI system

    First action

    Assign to each obligation the penalty ceiling that belongs to it

    Evidence to retain

    Register of penalty ceilings per obligation

    Open obligation