EU AI ACT REQUIREMENTS REGISTRY

One place to inspect the obligation, actor, evidence, and governance route.

This registry organises the EU AI Act into major requirement families without collapsing legal applicability, operational implementation, evidence, review, and outcome into a single checklist. Each entry shows what must be examined and how TA-14 can structure the corresponding evidence route.

Requirements map, not legal advice.

This page is a front-end governance workspace. It does not determine whether a specific organisation or system is legally in scope, replace the official regulation or Commission guidance, or certify conformity.

Requirement records18

Major obligation families represented in the current front-end registry.

Actor categories7

Provider, deployer, supply-chain, GPAI, and public-authority pathways.

Active focusARTICLE 50

Transparency obligations apply from 2 August 2026.

Governance principleSEPARATE LAYERS

Obligation, evidence, determination, review, execution, and outcome remain distinct.

INSPECTABLE REQUIREMENTS

Filter by family, actor, status, evidence, or article.

18 requirement record(s)
Prohibited PracticesEU-AIA-001
IN FORCE

Article 5

Identify and prevent prohibited AI practices

Organisations must determine whether an intended or actual AI use falls within a prohibited practice and preserve the basis for that determination.

ProviderDeployerPublic Authority
Evidence to preserve
  • Use-case inventory
  • Purpose and deployment-context record
  • Affected-person analysis
  • Prohibited-practice screening
  • Exception and legal-basis analysis
  • Decision and escalation record
TA-14 response pathway
  • Applicability route
  • Prohibited-use gate
  • Evidence-bound determination
  • HOLD or DENY outcome record
AI LiteracyEU-AIA-002
IN FORCE

Article 4

Maintain sufficient AI literacy

Providers and deployers must take measures to ensure an appropriate level of AI literacy among relevant staff and persons operating AI systems on their behalf.

ProviderDeployer
Evidence to preserve
  • Role-based competency framework
  • Training records
  • Assessment results
  • System-specific operating guidance
  • Refresher and change records
  • Responsibility assignment
TA-14 response pathway
  • Competency record
  • Training evidence map
  • Role-to-system binding
  • Continuity and review record
High-Risk ClassificationEU-AIA-003
REVIEW TIMELINE

Articles 6–7 and Annexes I and III

Classify high-risk AI systems

Organisations must determine whether an AI system is high-risk because it is a safety component of a regulated product or falls within an Annex III use case.

ProviderDeployerImporterDistributor
Evidence to preserve
  • System identity and intended purpose
  • Product and sector classification
  • Annex I and Annex III analysis
  • Materiality and exception analysis
  • Versioned classification decision
  • Independent review where required
TA-14 response pathway
  • Classification record
  • Rule-bound applicability route
  • Exception evidence
  • Review and supersession record
Risk ManagementEU-AIA-004
REVIEW TIMELINE

Article 9

Operate a continuous risk-management system

High-risk AI providers must establish, implement, document, and maintain a continuous iterative risk-management system throughout the lifecycle.

Provider
Evidence to preserve
  • Known and foreseeable risk inventory
  • Risk estimation and evaluation
  • Mitigation decisions
  • Residual-risk determination
  • Testing and validation evidence
  • Post-market feedback loop
TA-14 response pathway
  • Risk route chain
  • Declared thresholds
  • Mitigation evidence
  • Residual-risk outcome record
Data GovernanceEU-AIA-005
REVIEW TIMELINE

Article 10

Govern training, validation, and testing data

High-risk AI systems using model training must apply data-governance and management practices appropriate to the intended purpose.

Provider
Evidence to preserve
  • Dataset provenance
  • Collection and preparation methods
  • Relevance and representativeness analysis
  • Bias and gap evaluation
  • Data quality controls
  • Version and lineage records
TA-14 response pathway
  • Dataset admissibility record
  • Provenance chain
  • Bias and limitation record
  • Version continuity
Technical DocumentationEU-AIA-006
REVIEW TIMELINE

Article 11 and Annex IV

Create and maintain technical documentation

Technical documentation must demonstrate conformity and provide competent authorities with the information needed to assess the system.

Provider
Evidence to preserve
  • System description
  • Architecture and development methods
  • Data and model information
  • Performance and limitation evidence
  • Risk controls
  • Change and version history
TA-14 response pathway
  • Governed technical record
  • Evidence-to-claim mapping
  • Versioned architecture route
  • Change continuity record
Record-KeepingEU-AIA-007
REVIEW TIMELINE

Article 12

Enable automatic event logging

High-risk AI systems must technically allow automatic recording of events over the system lifetime where appropriate to the intended purpose.

ProviderDeployer
Evidence to preserve
  • Logging architecture
  • Event taxonomy
  • Timestamp and identity controls
  • Retention configuration
  • Integrity and access controls
  • Replay and incident evidence
TA-14 response pathway
  • Admissible execution record
  • Continuity chain
  • Replay verification
  • Tamper-evident outcome record
Transparency and InstructionsEU-AIA-008
REVIEW TIMELINE

Article 13

Provide sufficient transparency and instructions for use

High-risk AI systems must be sufficiently transparent to enable deployers to interpret outputs and use them appropriately.

ProviderDeployer
Evidence to preserve
  • Instructions for use
  • Intended purpose and limitations
  • Performance characteristics
  • Human oversight instructions
  • Input specifications
  • Maintenance and update requirements
TA-14 response pathway
  • Instruction evidence map
  • Limitation record
  • Operator route
  • Interpretation boundary record
Human OversightEU-AIA-009
REVIEW TIMELINE

Article 14

Design and operate effective human oversight

High-risk AI systems must support effective human oversight appropriate to the risk, autonomy, and context of use.

ProviderDeployer
Evidence to preserve
  • Oversight role definition
  • Intervention and stop controls
  • Competency evidence
  • Alert and escalation design
  • Automation-bias safeguards
  • Override and outcome records
TA-14 response pathway
  • Authority record
  • Intervention gate
  • HOLD and ESCALATE routes
  • Override accountability record
Accuracy, Robustness, CybersecurityEU-AIA-010
REVIEW TIMELINE

Article 15

Maintain accuracy, robustness, and cybersecurity

High-risk AI systems must achieve appropriate levels of accuracy, robustness, and cybersecurity and perform consistently throughout their lifecycle.

ProviderDeployer
Evidence to preserve
  • Declared performance metrics
  • Test and validation results
  • Robustness and resilience testing
  • Cybersecurity controls
  • Failure-mode analysis
  • Monitoring and corrective-action record
TA-14 response pathway
  • Threshold record
  • Performance baseline
  • Failure-state route
  • Post-intervention outcome comparison
Provider Quality SystemEU-AIA-011
REVIEW TIMELINE

Article 17

Operate a quality-management system

Providers of high-risk AI systems must implement a documented quality-management system covering compliance strategy, design, testing, records, accountability, and corrective action.

Provider
Evidence to preserve
  • Quality policy and procedures
  • Responsibility matrix
  • Design and development controls
  • Testing and validation procedures
  • Supplier and change controls
  • Corrective-action records
TA-14 response pathway
  • Governance operating record
  • Role and authority map
  • Change-control route
  • Corrective-action evidence chain
Conformity and RegistrationEU-AIA-012
REVIEW TIMELINE

Articles 43, 47–49 and 71

Complete conformity assessment and registration

Applicable high-risk systems require conformity assessment, an EU declaration of conformity, CE marking, and registration before market placement or use.

ProviderAuthorised RepresentativeImporter
Evidence to preserve
  • Conformity-assessment route
  • Assessment evidence package
  • Declaration of conformity
  • CE-marking record
  • Registration record
  • Substantial-modification analysis
TA-14 response pathway
  • Conformity route record
  • Evidence completeness gate
  • Registration continuity
  • Modification re-assessment route
Deployer DutiesEU-AIA-013
REVIEW TIMELINE

Article 26

Operate high-risk AI under deployer obligations

Deployers must follow instructions, assign competent oversight, monitor operation, preserve logs where under their control, and act when risks or incidents arise.

DeployerPublic Authority
Evidence to preserve
  • Deployment and operating record
  • Human oversight assignment
  • Input-data relevance analysis
  • Monitoring records
  • Incident and suspension records
  • Worker or affected-person notices where applicable
TA-14 response pathway
  • Deployment route
  • Operator authority record
  • Monitoring continuity
  • Suspend and escalate outcome record
Fundamental RightsEU-AIA-014
REVIEW TIMELINE

Article 27

Perform a fundamental-rights impact assessment

Certain deployers of high-risk AI systems must assess effects on fundamental rights before deployment and when material conditions change.

DeployerPublic Authority
Evidence to preserve
  • Process and context description
  • Affected-person and group analysis
  • Risk and harm pathways
  • Oversight and mitigation measures
  • Complaint and remedy pathways
  • Review and notification record
TA-14 response pathway
  • Impact-assessment record
  • Affected-party evidence
  • Mitigation route
  • Change-triggered reassessment
TransparencyEU-AIA-015
APPLIES 2026

Article 50

Meet Article 50 transparency obligations

Providers and deployers of certain AI systems must provide interaction notices, machine-readable marking, detectability, and specified content disclosures.

ProviderDeployer
Evidence to preserve
  • Applicability record
  • Disclosure wording and timing
  • Machine-readable marking evidence
  • Detectability testing
  • Deepfake or public-interest content record
  • Exception and limitation analysis
TA-14 response pathway
  • Article 50 assessment
  • Transparency implementation record
  • Detectability evidence route
  • Disclosure outcome record
GPAI ModelsEU-AIA-016
IN FORCE

Articles 51–56

Meet general-purpose AI model obligations

Providers of general-purpose AI models must maintain documentation, provide downstream information, implement copyright-policy measures, and publish training-content summaries, with additional duties for systemic-risk models.

GPAI ProviderProvider
Evidence to preserve
  • Model technical documentation
  • Downstream-provider information
  • Copyright compliance policy
  • Training-content summary
  • Systemic-risk classification
  • Evaluation, incident, and cybersecurity records
TA-14 response pathway
  • Model-governance registry
  • Downstream evidence package
  • Systemic-risk route
  • Incident and mitigation records
Post-Market MonitoringEU-AIA-017
REVIEW TIMELINE

Article 72

Operate post-market monitoring

Providers of high-risk systems must establish a proportionate post-market monitoring system that actively and systematically collects and analyses performance data.

Provider
Evidence to preserve
  • Post-market monitoring plan
  • Operational performance data
  • Complaint and incident signals
  • Trend and drift analysis
  • Corrective-action record
  • Updated risk-management evidence
TA-14 response pathway
  • Operational evidence stream
  • Drift record
  • Corrective-action route
  • Updated outcome determination
Serious IncidentsEU-AIA-018
REVIEW TIMELINE

Article 73

Report and manage serious incidents

Providers must report serious incidents involving high-risk AI systems and preserve investigation, corrective action, and communication records.

ProviderDeployer
Evidence to preserve
  • Incident identity and chronology
  • Severity assessment
  • Authority notification
  • Root-cause evidence
  • Corrective and preventive action
  • Closure and residual-risk record
TA-14 response pathway
  • Incident route
  • Chronology and custody record
  • Correction evidence
  • Closure determination
TA-14 REQUIREMENT ARCHITECTURE

Every requirement must remain traceable through the full route.

01

Legal requirement

The article, annex, guidance, standard, or applicable rule.

02

Actor and scope

Who is acting, which system is involved, and why the requirement applies.

03

Evidence package

The records, tests, declarations, logs, controls, and versions supporting the claim.

04

Determination

A bounded conclusion tied to identified rules and evidence.

05

Independent review

Challenge, correction, escalation, confirmation, and visible limitations.

06

Execution and outcome

What was approved, held, denied, changed, reported, or preserved.

CONNECTED EU AI ACT WORKSPACES

The registry is the index. Each requirement needs an operational route.

NO ADMISSIBLE EVIDENCE. NO ADMISSIBLE EXECUTION.

A requirement list is only the beginning of the governance route.

The organisation must still establish what applies, what evidence exists, what is missing, who has authority, what was independently reviewed, what changed, and what outcome the evidence can support.

TA-14 Exchange Activity

Public activity recorded across the Exchange

Visitors

Page Views