Major obligation families represented in the current front-end registry.
One place to inspect the obligation, actor, evidence, and governance route.
This registry organises the EU AI Act into major requirement families without collapsing legal applicability, operational implementation, evidence, review, and outcome into a single checklist. Each entry shows what must be examined and how TA-14 can structure the corresponding evidence route.
Provider, deployer, supply-chain, GPAI, and public-authority pathways.
Transparency obligations apply from 2 August 2026.
Obligation, evidence, determination, review, execution, and outcome remain distinct.
Filter by family, actor, status, evidence, or article.
Article 5
Identify and prevent prohibited AI practices
Organisations must determine whether an intended or actual AI use falls within a prohibited practice and preserve the basis for that determination.
- Use-case inventory
- Purpose and deployment-context record
- Affected-person analysis
- Prohibited-practice screening
- Exception and legal-basis analysis
- Decision and escalation record
- Applicability route
- Prohibited-use gate
- Evidence-bound determination
- HOLD or DENY outcome record
Article 4
Maintain sufficient AI literacy
Providers and deployers must take measures to ensure an appropriate level of AI literacy among relevant staff and persons operating AI systems on their behalf.
- Role-based competency framework
- Training records
- Assessment results
- System-specific operating guidance
- Refresher and change records
- Responsibility assignment
- Competency record
- Training evidence map
- Role-to-system binding
- Continuity and review record
Articles 6–7 and Annexes I and III
Classify high-risk AI systems
Organisations must determine whether an AI system is high-risk because it is a safety component of a regulated product or falls within an Annex III use case.
- System identity and intended purpose
- Product and sector classification
- Annex I and Annex III analysis
- Materiality and exception analysis
- Versioned classification decision
- Independent review where required
- Classification record
- Rule-bound applicability route
- Exception evidence
- Review and supersession record
Article 9
Operate a continuous risk-management system
High-risk AI providers must establish, implement, document, and maintain a continuous iterative risk-management system throughout the lifecycle.
- Known and foreseeable risk inventory
- Risk estimation and evaluation
- Mitigation decisions
- Residual-risk determination
- Testing and validation evidence
- Post-market feedback loop
- Risk route chain
- Declared thresholds
- Mitigation evidence
- Residual-risk outcome record
Article 10
Govern training, validation, and testing data
High-risk AI systems using model training must apply data-governance and management practices appropriate to the intended purpose.
- Dataset provenance
- Collection and preparation methods
- Relevance and representativeness analysis
- Bias and gap evaluation
- Data quality controls
- Version and lineage records
- Dataset admissibility record
- Provenance chain
- Bias and limitation record
- Version continuity
Article 11 and Annex IV
Create and maintain technical documentation
Technical documentation must demonstrate conformity and provide competent authorities with the information needed to assess the system.
- System description
- Architecture and development methods
- Data and model information
- Performance and limitation evidence
- Risk controls
- Change and version history
- Governed technical record
- Evidence-to-claim mapping
- Versioned architecture route
- Change continuity record
Article 12
Enable automatic event logging
High-risk AI systems must technically allow automatic recording of events over the system lifetime where appropriate to the intended purpose.
- Logging architecture
- Event taxonomy
- Timestamp and identity controls
- Retention configuration
- Integrity and access controls
- Replay and incident evidence
- Admissible execution record
- Continuity chain
- Replay verification
- Tamper-evident outcome record
Article 13
Provide sufficient transparency and instructions for use
High-risk AI systems must be sufficiently transparent to enable deployers to interpret outputs and use them appropriately.
- Instructions for use
- Intended purpose and limitations
- Performance characteristics
- Human oversight instructions
- Input specifications
- Maintenance and update requirements
- Instruction evidence map
- Limitation record
- Operator route
- Interpretation boundary record
Article 14
Design and operate effective human oversight
High-risk AI systems must support effective human oversight appropriate to the risk, autonomy, and context of use.
- Oversight role definition
- Intervention and stop controls
- Competency evidence
- Alert and escalation design
- Automation-bias safeguards
- Override and outcome records
- Authority record
- Intervention gate
- HOLD and ESCALATE routes
- Override accountability record
Article 15
Maintain accuracy, robustness, and cybersecurity
High-risk AI systems must achieve appropriate levels of accuracy, robustness, and cybersecurity and perform consistently throughout their lifecycle.
- Declared performance metrics
- Test and validation results
- Robustness and resilience testing
- Cybersecurity controls
- Failure-mode analysis
- Monitoring and corrective-action record
- Threshold record
- Performance baseline
- Failure-state route
- Post-intervention outcome comparison
Article 17
Operate a quality-management system
Providers of high-risk AI systems must implement a documented quality-management system covering compliance strategy, design, testing, records, accountability, and corrective action.
- Quality policy and procedures
- Responsibility matrix
- Design and development controls
- Testing and validation procedures
- Supplier and change controls
- Corrective-action records
- Governance operating record
- Role and authority map
- Change-control route
- Corrective-action evidence chain
Articles 43, 47–49 and 71
Complete conformity assessment and registration
Applicable high-risk systems require conformity assessment, an EU declaration of conformity, CE marking, and registration before market placement or use.
- Conformity-assessment route
- Assessment evidence package
- Declaration of conformity
- CE-marking record
- Registration record
- Substantial-modification analysis
- Conformity route record
- Evidence completeness gate
- Registration continuity
- Modification re-assessment route
Article 26
Operate high-risk AI under deployer obligations
Deployers must follow instructions, assign competent oversight, monitor operation, preserve logs where under their control, and act when risks or incidents arise.
- Deployment and operating record
- Human oversight assignment
- Input-data relevance analysis
- Monitoring records
- Incident and suspension records
- Worker or affected-person notices where applicable
- Deployment route
- Operator authority record
- Monitoring continuity
- Suspend and escalate outcome record
Article 27
Perform a fundamental-rights impact assessment
Certain deployers of high-risk AI systems must assess effects on fundamental rights before deployment and when material conditions change.
- Process and context description
- Affected-person and group analysis
- Risk and harm pathways
- Oversight and mitigation measures
- Complaint and remedy pathways
- Review and notification record
- Impact-assessment record
- Affected-party evidence
- Mitigation route
- Change-triggered reassessment
Article 50
Meet Article 50 transparency obligations
Providers and deployers of certain AI systems must provide interaction notices, machine-readable marking, detectability, and specified content disclosures.
- Applicability record
- Disclosure wording and timing
- Machine-readable marking evidence
- Detectability testing
- Deepfake or public-interest content record
- Exception and limitation analysis
- Article 50 assessment
- Transparency implementation record
- Detectability evidence route
- Disclosure outcome record
Articles 51–56
Meet general-purpose AI model obligations
Providers of general-purpose AI models must maintain documentation, provide downstream information, implement copyright-policy measures, and publish training-content summaries, with additional duties for systemic-risk models.
- Model technical documentation
- Downstream-provider information
- Copyright compliance policy
- Training-content summary
- Systemic-risk classification
- Evaluation, incident, and cybersecurity records
- Model-governance registry
- Downstream evidence package
- Systemic-risk route
- Incident and mitigation records
Article 72
Operate post-market monitoring
Providers of high-risk systems must establish a proportionate post-market monitoring system that actively and systematically collects and analyses performance data.
- Post-market monitoring plan
- Operational performance data
- Complaint and incident signals
- Trend and drift analysis
- Corrective-action record
- Updated risk-management evidence
- Operational evidence stream
- Drift record
- Corrective-action route
- Updated outcome determination
Article 73
Report and manage serious incidents
Providers must report serious incidents involving high-risk AI systems and preserve investigation, corrective action, and communication records.
- Incident identity and chronology
- Severity assessment
- Authority notification
- Root-cause evidence
- Corrective and preventive action
- Closure and residual-risk record
- Incident route
- Chronology and custody record
- Correction evidence
- Closure determination
Every requirement must remain traceable through the full route.
Legal requirement
The article, annex, guidance, standard, or applicable rule.
Actor and scope
Who is acting, which system is involved, and why the requirement applies.
Evidence package
The records, tests, declarations, logs, controls, and versions supporting the claim.
Determination
A bounded conclusion tied to identified rules and evidence.
Independent review
Challenge, correction, escalation, confirmation, and visible limitations.
Execution and outcome
What was approved, held, denied, changed, reported, or preserved.
The registry is the index. Each requirement needs an operational route.
Article 50 Transparency
Assess actor role, content type, disclosure pathway, marking, and evidence readiness.
02High-Risk Systems
Map classification, lifecycle duties, conformity, deployer responsibilities, and monitoring.
03Fundamental Rights
Structure affected-party analysis, harm pathways, mitigation, oversight, and reassessment.
04AI Governance Registry
Preserve system identity, governance identity, versions, claims, evidence, and stewardship.
05Independent Review
Find professionals through declared expertise, evidence signals, artifacts, and limitations.
A requirement list is only the beginning of the governance route.
The organisation must still establish what applies, what evidence exists, what is missing, who has authority, what was independently reviewed, what changed, and what outcome the evidence can support.