Skip to main content
Praxikon

Obligations register

AI Act obligations from rule to evidence

Start with your role and situation. Every route separates official fact, our interpretation and recommended action and shows source, version and latest review.

Public and no account required. The official source remains authoritative.

Praxikon tracks every obligation under the EU AI Act, citing the source for every statement.

  1. Upcomingv1.0.0

    Annex III: the eight areas separately

    Annex III names eight areas in which an AI system can be high-risk under Article 6(2). This object publishes those eight areas as separate objects, so that a question about recruitment, assessment, creditworthiness or border control lands on the point that names it rather than on the list as a whole.

    Relevant to: Deployer, Provider of an AI system

    First action

    Map every system to a point of Annex III

    Evidence to retain

    Record of the mapping to a point of Annex III

    Open obligation
  2. Upcomingv1.0.0

    Annex III: high-risk AI

    Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.

    Relevant to: Deployer, Provider of an AI system

    First action

    Classify the use case and document the outcome

    Evidence to retain

    Article 6 and Annex III classification record

    Open obligation
  3. Upcomingv1.0.0

    Article 10: data and data governance

    Quality and governance requirements for training, validation and test data of high-risk AI.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up data governance per dataset

    Evidence to retain

    Data governance file

    Open obligation
  4. Upcomingv1.0.0

    Article 11: technical documentation

    The technical file demonstrating before market placement that a high-risk system meets the requirements.

    Relevant to: Provider of an AI system

    First action

    Build the technical file per Annex IV

    Evidence to retain

    Technical file (Annex IV)

    Open obligation
  5. Applicablev1.0.0

    Article 111(2): legacy high-risk systems and the 2 August 2030 date

    High-risk AI systems placed on the market or put into service before the date of application of Chapter III, since the Digital Omnibus 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, come under the high-risk requirements of that Chapter only once their design is significantly changed as from that date. This is not an exemption from the whole Regulation: Article 4 and Article 50 keep running. For systems intended to be used by public authorities the carve out falls away entirely: their providers and deployers must in any case comply with the requirements and obligations by 2 August 2030.

    Relevant to: Authorised representative, Deployer, Distributor, Importer, Provider of an AI system

    First action

    Assess for every design change whether it is significant

    Evidence to retain

    Transition register of legacy high-risk systems

    Open obligation
  6. Upcomingv1.0.0

    Article 12: logging and traceability

    Automatic recording of events over the lifetime of a high-risk AI system.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design logging into the system

    Evidence to retain

    Logs and retention regime

    Open obligation
  7. Upcomingv1.0.0

    Article 13: transparency towards deployers

    Comprehensible instructions for use and system information so deployers can operate the system correctly.

    Relevant to: Deployer, Provider of an AI system

    First action

    Provide complete instructions for use

    Evidence to retain

    Instructions and interpretation file

    Open obligation
  8. Upcomingv1.0.0

    Article 14: human oversight

    High-risk AI must be designed so that humans can effectively oversee it and intervene.

    Relevant to: Deployer, Provider of an AI system

    First action

    Design and assign effective human oversight

    Evidence to retain

    Oversight file per system

    Open obligation
  9. Upcomingv1.0.0

    Article 16: the twelve duties of a provider of a high-risk AI system

    Article 16 is the summary list of duties for providers: twelve points that route onward to the quality management system, the documentation, the logs, the conformity assessment, the EU declaration of conformity, the CE marking, the registration, corrective actions and accessibility requirements.

    Relevant to: Provider of an AI system

    First action

    Assign an internal owner and a date to each point of Article 16

    Evidence to retain

    Provider dossier per high-risk AI system

    Open obligation
  10. Upcomingv1.0.0

    Article 17: quality management system

    The documented quality system through which a high-risk AI provider structurally assures compliance.

    Relevant to: Provider of an AI system

    First action

    Set up an AI quality management system

    Evidence to retain

    QMS documentation

    Open obligation
  11. Upcomingv1.0.0

    Article 18: documentation keeping

    The provider of a high-risk AI system keeps the technical documentation, the quality management system documentation, the changes approved by notified bodies and the decisions they issued, and the EU declaration of conformity at the disposal of the national competent authorities for a period ending ten years after the system has been placed on the market or put into service.

    Relevant to: Authorised representative, Deployer, Provider of an AI system

    First action

    Set up the ten year retention of the system documentation

    Evidence to retain

    Retention file per high-risk system

    Open obligation
  12. Upcomingv1.0.0

    Article 20: corrective actions and duty of information

    A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.

    Relevant to: Authorised representative, Deployer, Distributor, Importer, Provider of an AI system

    First action

    Set up the procedure for corrective actions and notification

    Evidence to retain

    Record of corrective actions

    Open obligation
  13. Upcomingv1.0.0

    Article 21: cooperation with competent authorities

    Upon a reasoned request by a competent authority, the provider of a high-risk AI system provides all the information and documentation necessary to demonstrate conformity with the requirements of Chapter III, Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned. Upon the same request the provider also gives, as applicable, access to the automatically generated logs, to the extent those logs are under its control.

    Relevant to: Authorised representative, Deployer, Provider of an AI system

    First action

    Make your conformity file deliverable on request

    Evidence to retain

    Response file for a request from a competent authority

    Open obligation
  14. Applicablev1.0.0

    Articles 28 to 39: notifying authorities and notified bodies

    Section 4 of Chapter III governs who may carry out your conformity assessment and on what conditions that power continues to exist. Each Member State designates a notifying authority that assesses, designates, notifies and monitors conformity assessment bodies. A notified body is established under the national law of a Member State, has legal personality, and is independent of the provider, of any other operator with an economic interest and of the provider competitors; consultancy services in particular are ruled out. Subcontracting to a subcontractor or a subsidiary is allowed only with the agreement of the provider, and the body then retains full responsibility. In its work it avoids unnecessary burdens for providers and minimises administrative burdens and compliance costs for micro- and small enterprises, without giving up the required degree of rigour. Article 36 distinguishes the cases. Where it ceases its activities, the certificates remain valid under paragraph 3 for at most nine months, provided another notified body assumes responsibility in writing. Where its designation is suspended, restricted or withdrawn, it informs the providers concerned within ten days under paragraph 5; paragraph 8 sets continuity conditions there without that general nine-month limit, and paragraph 9 gives certificates a nine-month validity on withdrawal, with a conditional extension in periods of three months up to twelve months at most. A body from a third country can carry out these activities only where the Union has concluded an agreement with that country.

    Relevant to: Provider of an AI system

    First action

    Check the standing and independence of your notified body

    Evidence to retain

    File on the chosen notified body

    Open obligation
  15. Applicablev2.0.0

    Article 4: AI literacy

    Providers and deployers take measures that support the development of AI literacy.

    Relevant to: Deployer, Provider of an AI system

    First action

    Take role- and context-specific AI literacy measures

    Evidence to retain

    AI literacy measures record

    Open obligation
  16. Applicablev1.0.0

    Articles 40 to 42: standards, common specifications and presumption of conformity

    A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.

    Relevant to: Provider of a GPAI model, Provider of an AI system

    First action

    Record per requirement which standard or specification you rely on, and justify every departure

    Evidence to retain

    Coverage matrix and justification for standards and specifications

    Open obligation
  17. Applicablev1.0.0

    Article 44: certificates of notified bodies

    A certificate issued by a notified body is valid for at most five years for AI systems covered by Annex I and at most four years for AI systems covered by Annex III, and may be extended at the request of the provider after a re-assessment. Where the system no longer meets the requirements of Section 2, the body shall, taking account of the principle of proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes corrective action within an appropriate deadline it sets so as to ensure compliance with those requirements. An appeal procedure against that decision is available.

    Relevant to: Provider of an AI system

    First action

    Manage the life of the certificate

    Evidence to retain

    Certificate file per system

    Open obligation
  18. Applicablev1.0.0

    Article 46: derogation from conformity assessment procedure

    By way of derogation from Article 43, a market surveillance authority may, upon a duly justified request, authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security, the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets. The authorisation is for a limited period while the conformity assessment is carried out, and those procedures are completed without undue delay. Law-enforcement authorities and civil protection authorities may start without an authorisation in a situation of urgency, provided that it is requested without undue delay; if it is refused, use stops with immediate effect and all results and outputs are discarded. The authorisation is issued only if the system complies with the requirements of Section 2, goes to the Commission and the other Member States, and is deemed justified after fifteen calendar days without objection.

    Relevant to: Deployer, Provider of an AI system, Body governed by public law

    First action

    Prepare a derogation request and the exit plan that goes with it

    Evidence to retain

    File accompanying a request to derogate from the conformity assessment

    Open obligation
  19. Applicablev1.0.0

    Article 49: registration in the EU database before the system reaches the market

    The provider of a high-risk AI system listed in Annex III, or where applicable its authorised representative, registers itself and that system in the EU database before it is placed on the market or put into service. The same duty applies to the provider that concludes under Article 6(3) that its Annex III system is precisely not high-risk: that provider too registers itself and that system. The deployer that is a public authority or a Union body, or that acts on behalf of such an authority, registers itself, selects the system and registers its use. For the areas of law enforcement, migration, asylum and border control management the registration goes into a secure non-public section with fewer fields, to which only the Commission and the national authorities referred to in Article 74(8) have access. For the systems in point 2 of Annex III registration does not run through the EU database but at national level.

    Relevant to: Authorised representative, Deployer, Distributor, Provider of an AI system, Body governed by public law

    First action

    Register yourself and the system before it reaches the market or is put into service

    Evidence to retain

    Article 49 registration dossier

    Open obligation
  20. Applicablev1.0.0

    Article 4a: legal basis for bias testing with special categories of personal data

    Article 4a grants permission rather than instruction, and to two different sets of parties. Paragraph 1 allows only the provider of a high-risk AI system to process special categories of personal data by way of exception, to the extent strictly necessary for bias detection and correction within the meaning of Article 10(2), points (f) and (g), and only where all six conditions (a) to (f) are met. Paragraph 2 opens the same room to providers and deployers of other AI systems and models and to deployers of high-risk systems, but only for bias likely to affect the health and safety of persons, to have a negative impact on fundamental rights or to lead to discrimination prohibited under Union law, and subject to the same six conditions. Until 27 July 2026 this basis sat in Article 10(5).

    Relevant to: Deployer, Provider of a GPAI model, Provider of an AI system

    First action

    Justify and record your reliance on Article 4a

    Evidence to retain

    Necessity file for bias testing

    Open obligation
  21. Applicablev1.0.0

    Article 5: prohibited practices

    The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.

    Relevant to: Deployer, Provider of an AI system

    First action

    Screen every use case against Article 5 first

    Evidence to retain

    Article 5 screening record

    Open obligation
  22. Applicablev1.0.0

    Article 50: transparency

    Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.

    Relevant to: Deployer, Provider of an AI system

    First action

    Implement the applicable disclosure, marking or label

    Evidence to retain

    Transparency implementation record

    Open obligation
  23. Applicablev1.0.0

    Article 56: codes of practice for general-purpose AI models

    The AI Office encourages and facilitates the drawing up of codes of practice at Union level, and the AI Office and the Board see to it that those codes cover at least the obligations in Articles 53 and 55. Providers of general-purpose AI models and national competent authorities may be invited to participate in the drawing up; civil society organisations, industry, academia and other stakeholders may support the process. Until 27 July 2026 the Commission could approve a code of practice by implementing act and give it general validity within the Union; Article 1, point (21), of Regulation (EU) 2026/1744 replaced paragraph 6 and removed that power. Since then the Commission assesses whether the codes cover the obligations of Articles 53 and 55 and publishes that assessment. The codes were to be ready by 2 May 2025 at the latest; if no code existed by 2 August 2025, or if the AI Office deems one inadequate, the Commission may lay down common rules by implementing acts for the implementation of Articles 53 and 55. For you this is therefore not a separate duty but a route: a code is a voluntary instrument with which you can demonstrate compliance.

    Relevant to: Provider of a GPAI model, Provider of an AI system

    First action

    Take and record the decision whether you adhere to a code of practice

    Evidence to retain

    Record of the decision on a code of practice

    Open obligation
  24. Applicablev1.0.0

    Article 57: AI regulatory sandboxes

    Member States must provide at least one national AI regulatory sandbox. For you this is a voluntary route: you develop, train, test and validate an innovative AI system in a controlled, supervised environment under a plan agreed with the competent authority, before placing it on the market or putting it into service.

    Relevant to: Deployer, Provider of an AI system, Body governed by public law

    First action

    Apply to a sandbox and agree the sandbox plan

    Evidence to retain

    Written proof of participation and the exit report

    Open obligation
  25. Upcomingv1.0.0

    Article 6(1): the product route to high risk

    An AI system counts as high risk where it is intended to be used as a safety component of a product covered by the Union harmonisation legislation listed in Annex I, or is itself such a product, and that product is required to undergo a third-party conformity assessment. This route does not run through Annex III but through the product legislation that already applies to the product. For Section A products the requirements of Chapter III, Section 2, form part of the sectoral assessment under Article 43(3); for Section B products Article 2(2) limits the operation of this Regulation to a short list of provisions.

    Relevant to: Deployer, Provider of an AI system

    First action

    Establish the product route per product

    Evidence to retain

    Product route record

    Open obligation
  26. In forcev1.0.0

    Article 6(1a) to (1c): the tightened classification route

    The Digital Omnibus inserts three paragraphs into Article 6 that draw the notion of safety component more tightly: which AI systems do not qualify as safety components, which still do despite that exclusion because failure would endanger health and safety, and which mandatory third-party conformity assessment does not count. Paragraph 1a is written for the purposes of the Regulation as a whole and therefore bears on both the Annex I route and Annex III, point 2.

    Relevant to: Provider of an AI system

    First action

    Determine and record whether your AI component is a safety component

    Evidence to retain

    Record of the safety component assessment

    Open obligation
  27. Applicablev1.0.0

    Article 60: testing in real world conditions outside a sandbox

    If you want to test an Annex III high-risk AI system with real people and real outcomes before placing it on the market, a full regime applies: a plan, prior approval by the market surveillance authority, registration, informed consent and a maximum duration.

    Relevant to: Deployer, Provider of an AI system

    First action

    Submit the testing plan, obtain approval and register the test

    Evidence to retain

    Dated and documented informed consent of test subjects

    Open obligation
  28. Applicablev1.0.0

    Article 61: informed consent of test subjects for testing in real world conditions

    If you test a high-risk AI system in real world conditions outside an AI regulatory sandbox, freely-given informed consent must be obtained from every test subject before they participate. Beforehand the subject receives concise, clear, relevant and understandable information on five prescribed topics: the nature and objectives of the testing and the possible inconvenience, the conditions under which the testing is to be conducted including the expected duration of participation, their rights and guarantees including the right to refuse and the right to withdraw at any time without detriment and without justification, the arrangements for requesting the reversal or the disregarding of the outputs of the system, and the Union-wide unique single identification number with the contact details from whom further information can be obtained. The consent is dated and documented and the subject is given a copy.

    Relevant to: Deployer, Provider of an AI system

    First action

    Inform the test subject and obtain consent to participate

    Evidence to retain

    Information pack for subjects of testing in real world conditions

    Open obligation
  29. Applicablev1.0.0

    Article 62: measures for providers and deployers that are SMEs or start-ups

    Member States give SMEs, including start-ups, with a registered office or a branch in the Union priority access to the AI regulatory sandboxes, organise specific awareness raising and training activities, use or establish dedicated communication channels to provide advice and answer queries, and facilitate the participation of SMEs in the standardisation development process. When setting the fees for conformity assessment under Article 43, the specific interests and needs of SME providers are taken into account, those fees being reduced proportionately to their size, market size and other relevant indicators. The AI Office provides standardised templates, maintains a single information platform, organises communication campaigns and promotes the convergence of best practices in public procurement. This article lowers no requirement; it makes the road towards one cheaper and more accessible.

    Relevant to: Deployer, Provider of an AI system

    First action

    Make use of the SME facilities in Article 62

    Evidence to retain

    File on SME status and facilities used

    Open obligation
  30. Applicablev1.0.0

    Article 63: derogations for SMEs in the quality management system

    SMEs, including start-ups, may comply with certain elements of the quality management system required by Article 17 in a simplified manner, provided that they do not have partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Until 27 July 2026 this read microenterprises; Article 1, point (26), of Regulation (EU) 2026/1744 replaced paragraph 1 and widened the circle to SMEs. Which elements those are is for the Commission to set out in guidelines, considering the needs of SMEs and without affecting the level of protection or the need for compliance with the requirements in respect of high-risk AI systems. Paragraph 2 rules out any wider reading: the provision shall not be interpreted as exempting those operators from fulfilling any other requirements or obligations laid down in this Regulation, including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73.

    Relevant to: Provider of an AI system

    First action

    Determine and bound the simplification of your quality management system

    Evidence to retain

    File on microenterprise status

    Open obligation
  31. Upcomingv1.0.0

    Article 71: EU database for high-risk AI systems listed in Annex III

    The provider or, where applicable, the authorised representative enters the data listed in Sections A and B of Annex VIII into the EU database; the deployer who is, or who acts on behalf of, a public authority, agency or body enters the data listed in Section C. Information registered in accordance with Article 49 is publicly available in a user-friendly manner and machine-readable, except for the secure section covering law enforcement, migration, asylum and border control management and the registration of testing in real world conditions. Setting up and maintaining the database itself is a task of the Commission and not a duty of yours.

    Relevant to: Authorised representative, Provider of an AI system, Body governed by public law

    First action

    Enter your data in the EU database and keep it up to date

    Evidence to retain

    EU database registration file

    Open obligation
  32. Applicablev2.0.0

    Article 72: post-market monitoring

    Systematic monitoring of high-risk AI in real use, after market placement.

    Relevant to: Deployer, Provider of an AI system

    First action

    Draw up a post-market monitoring plan

    Evidence to retain

    Monitoring plan and reports

    Open obligation
  33. Applicablev2.0.0

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

    Relevant to: Deployer, Provider of an AI system

    First action

    Set up an incident process with reporting routes

    Evidence to retain

    Incident register and reports

    Open obligation
  34. Upcomingv1.0.0

    Article 75(1a) and (1e): reporting to and assessment by the AI Office

    If you are the provider of a high-risk AI system subject to the competence of the AI Office, you report serious incidents to the Office rather than to your national authority, with the machinery and the deadlines of Article 73(2) to (9) applying in full, and the Office still transmits the information to your national market surveillance authority. Where that system is subject to a third-party conformity assessment under Article 43, the Office is responsible for it, the notified body acts on behalf of the Commission, and you pay the costs directly to that body.

    Relevant to: Provider of an AI system

    First action

    Route reporting and conformity assessment to the AI Office

    Evidence to retain

    File of reports and assessments with the AI Office

    Open obligation
  35. Applicablev1.0.0

    Article 75: market surveillance, mutual assistance and the powers of the AI Office

    For a defined group of AI systems the AI Office is exclusively competent for supervision and enforcement instead of the national market surveillance authority. The Office can request information by simple request or by decision, open investigations, carry out remote and on-site inspections, make commitments binding, and impose both fines through Article 99 and periodic penalty payments. Four groups are carved out; there a national authority remains competent.

    Relevant to: Deployer, Provider of an AI system

    First action

    Establish per system who your supervisor is

    Evidence to retain

    Record of the competent supervisor per system

    Open obligation
  36. Applicablev1.0.0

    Article 78: confidentiality of what you submit to an authority

    The Commission, the market surveillance authorities, the notified bodies and everyone involved in the application of the Regulation respect the confidentiality of what they obtain in carrying out their tasks, and in doing so expressly protect the intellectual property rights, the confidential business information and the trade secrets of a natural or legal person, including source code. They may request only data that is strictly necessary, must secure it, and must delete it as soon as it is no longer needed. For you this is therefore not a duty but a protection, with a limit: the exception in Article 5 of Directive (EU) 2016/943 remains, and the provision leaves the exchange of information and the dissemination of warnings between authorities untouched.

    Relevant to: Deployer, Provider of a GPAI model, Provider of an AI system

    First action

    Mark and register what you submit to an authority or body

    Evidence to retain

    Register of submissions to authorities

    Open obligation
  37. Upcomingv1.0.0

    Article 8: compliance with the requirements for high-risk AI systems

    High-risk AI systems comply with the requirements of Chapter III, Section 2, and that is assessed taking into account the intended purpose and the generally acknowledged state of the art on AI and AI-related technologies, with the risk management system of Article 9 as the instrument. Where the system sits in a product also covered by the Union harmonisation legislation of Section A of Annex I, the provider is responsible for full compliance with all applicable requirements of that legislation, and may integrate the testing and reporting processes and the information and documentation on the product into the documentation and procedures that already exist there.

    Relevant to: Provider of an AI system

    First action

    Record the state of the art and the intended purpose per system

    Evidence to retain

    Justification of the state of the art

    Open obligation
  38. Applicablev1.0.0

    Article 87: reporting of infringements and protection of reporting persons

    The whistleblower Directive applies to the reporting of infringements of the AI Regulation and to the protection of the persons who report them. For an organisation that falls under that Directive this means a report about an AI system runs through the same protected channel as any other report, and a person reporting who meets the conditions of that Directive may not be disadvantaged for it. Whether you fall under that Directive is not stated in Article 87 but in national transposition law.

    Relevant to: Deployer, Provider of an AI system

    First action

    Make sure a report about an AI system reaches your reporting channel

    Evidence to retain

    File of reports about AI systems

    Open obligation
  39. Upcomingv1.0.0

    Article 9: risk management system

    A continuous, documented risk management system across the entire lifecycle of a high-risk AI system.

    Relevant to: Provider of an AI system

    First action

    Set up an iterative risk management process

    Evidence to retain

    Risk management file

    Open obligation
  40. Applicablev1.0.0

    Article 95: codes of conduct for voluntary application of specific requirements

    The AI Office and the Member States encourage and facilitate the drawing up of codes of conduct, including related governance mechanisms, intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2, taking into account the available technical solutions and industry best practices. They also facilitate codes on the voluntary application of specific requirements to all AI systems, on the basis of clear objectives and key performance indicators, with elements such as the Union ethical guidelines for trustworthy AI, assessing and minimising the impact on environmental sustainability, promoting AI literacy, facilitating an inclusive and diverse design, and assessing and preventing the negative impact on vulnerable persons. Codes may be drawn up by individual providers or deployers or by organisations representing them, and in encouraging and facilitating them the specific interests and needs of SMEs, including start-ups, and of small mid-cap enterprises are taken into account; that last group was added by Article 1, point (35), of Regulation (EU) 2026/1744. This article imposes no duty on the organisation and replaces no obligation.

    Relevant to: Deployer, Provider of an AI system

    First action

    Scope a voluntary code of conduct and separate it from your duties

    Evidence to retain

    Register of voluntary commitments alongside the obligations

    Open obligation
  41. Applicablev1.0.0

    Article 99, 100 and 101: the penalty structure per obligation

    The Regulation carries no single fine amount. For operators, three ceilings attach to different paragraphs of Article 99; in addition the Commission itself fines providers of general-purpose AI models under Article 101, the AI Office can fine in its own right since the 2026 amendment, and Union institutions and bodies face the separate amounts of Article 100. Which ceiling applies depends on which provision was infringed and on who enforces, and not on how serious the consequences are.

    Relevant to: Authorised representative, Deployer, Distributor, Provider of a GPAI model, Importer, Provider of an AI system

    First action

    Assign to each obligation the penalty ceiling that belongs to it

    Evidence to retain

    Register of penalty ceilings per obligation

    Open obligation
  42. Applicablev2.0.0

    Articles 43-49: conformity assessment, CE and registration

    The route from assessment to CE marking and EU database registration before market placement of high-risk AI.

    Relevant to: Provider of an AI system, Body governed by public law

    First action

    Complete the conformity route before market placement

    Evidence to retain

    Conformity file

    Open obligation