Obligations Overview
A concise overview of who must comply with what, and under which articles.
High-Risk
High-Risk AI Systems
| Obligation | Who Must Comply | Articles | Deadline |
|---|---|---|---|
| Register high-risk AI system in EU database | Provider | Before placing on market | |
| Conduct conformity assessment and draw up EU declaration of conformity | Provider | Before placing on market | |
| Establish quality management system (QMS) | Provider | Before placing on market | |
| Create and maintain technical documentation | Provider | Ongoing | |
| Implement post-market monitoring system | Provider | After placing on market | |
| Conduct fundamental rights impact assessment (FRIA) | Deployer (public bodies and certain private operators) | Before deployment | |
| Implement human oversight measures | Deployer | During deployment | |
| Inform workers/their representatives about AI use | Deployer | Before deployment | |
| Notify serious incidents and malfunctions to authorities | Provider | Within 15 days |
Transparency Req.
Transparency Obligations
GPAI
General-Purpose AI Models
| Obligation | Who Must Comply | Articles | Deadline |
|---|---|---|---|
| Maintain technical documentation (Annex XI) | GPAI Provider | Ongoing | |
| Publish training data summary | GPAI Provider | Before making model available | |
| Implement copyright compliance policy | GPAI Provider | Ongoing | |
| Conduct adversarial testing (red-teaming) for systemic risks | GPAI Provider (systemic risk) | Before and after release | |
| Report serious incidents to AI Office | GPAI Provider (systemic risk) | Without undue delay | |
| Ensure adequate cybersecurity for model and infrastructure | GPAI Provider (systemic risk) | Ongoing |