Home / Obligations

Obligations database

One record per discrete duty, tagged by role, risk class, lifecycle phase and post-Omnibus date. A deployer who substantially modifies a system becomes its provider (Art. 25) — check both roles if in doubt.

ROLE
RISK
Showing 120 of 120 obligations Derived from the consolidated text, one record per discrete duty · schema OBL-nnnn · verified 2026-07-16
OBL-0001 Art. 4 Ensure AI literacy of staff Providers and deployers must ensure people operating AI systems have sufficient AI literacy for their role and context. Provider · Deployer All systems IN FORCE national
OBL-0005 Art. 5 Refrain from prohibited practices No social scoring, manipulative techniques exploiting vulnerabilities, untargeted face scraping, or real-time remote biometric ID in public (narrow exceptions). Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0005b Art. 5 Do not place or use AI generating NCII / CSAM Omnibus addition: systems for non-consensual intimate imagery or CSAM are prohibited; providers must build refusal and filtering safeguards. Provider · Deployer Prohibited DEC 2, 2026 €35M / 7%
OBL-0009 Art. 9 Run a risk management system A continuous, documented lifecycle process — identify foreseeable risks, test mitigations, update as the system evolves. Feeds the QMS. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0010 Art. 10 Data governance for training, validation, testing Datasets must be relevant, representative and examined for bias — with documented governance across collection and preparation. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0011 Art. 11 Maintain technical documentation (Annex IV) Drawn up before market placement and kept current — the file that proves conformity to authorities and notified bodies. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0012 Art. 12 Enable automatic event logging Systems must log events across their lifetime for traceability, post-market monitoring and incident investigation. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0014 Art. 14 Design for effective human oversight Humans must be able to understand, monitor, intervene in or stop the system — with measures matched to the risk. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0017 Art. 17 Operate a quality management system A documented QMS covering strategy, design controls, data management, monitoring and accountability. prEN 18286 is the standard to watch. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0023 Art. 23 Verify conformity before import Importers confirm the conformity assessment was done, documentation exists, CE marking is affixed — and keep records ten years. Importer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0024 Art. 24 Check compliance before distribution Distributors verify CE marking and documentation, protect compliance in storage and transport, and act on non-conformity. Distributor High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0026 Art. 26 Deploy per instructions, with oversight Deployers use systems per instructions, assign trained human oversight, monitor operation and keep logs they control. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0027 Art. 27 Fundamental-rights impact assessment Public bodies and certain private deployers (credit, insurance) assess impact on rights before first use — and notify the authority. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0043 Art. 43 Complete conformity assessment Internal control (Annex VI) for most Annex III systems; notified-body assessment for remote biometric ID and Annex I products. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0049 Art. 49, Art. 71 Register in the EU database Providers register high-risk systems before market placement. Omnibus reinstated lighter registration for systems self-assessed as non-high-risk. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0050 Art. 50(2) Mark AI-generated output machine-readably Watermark or metadata so machines can detect synthetic content. New systems Aug 2; systems already on the market get to Dec 2, 2026. Provider Transparency AUG 2, 2026 €15M / 3%
OBL-0051 Art. 50(1) Disclose AI interaction to users People must know they are interacting with an AI system unless it is obvious from context. Provider Transparency AUG 2, 2026 €15M / 3%
OBL-0053 Art. 50(4) Label deepfakes and AI public-interest text Disclose artificially generated or manipulated media, and AI-written text published to inform the public. Deployer Transparency AUG 2, 2026 €15M / 3%
OBL-0060 Art. 53 GPAI documentation, copyright policy, data summary Model documentation for downstream providers, a copyright-respecting policy, and a public training-data summary. Enforcement powers begin Aug 2, 2026. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0061 Art. 55 Systemic-risk model duties Models above 10²⁵ FLOP (or designated): evaluations, adversarial testing, incident reporting, cybersecurity. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0100 Art. 8 Meet all high-risk requirements Providers must satisfy every Chapter III requirement, calibrated to the system's intended purpose and to what is currently technically achievable. The bar moves as the field advances, so compliance is judged against the state of the art at the time. Findings from the risk management system feed directly into how each requirement is met. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0101 Art. 8 Align AI duties with product legislation Where AI sits inside a regulated product, providers must make the whole product compliant with both the AI Act and the applicable Union harmonisation law. To avoid duplicated effort, they may fold AI testing, reporting and documentation into the procedures already run for that product. Provider · Product mfr High-risk III AUG 2, 2028 AUG 2, 2027 €15M / 3%
OBL-0102 Art. 9 Test against defined metrics before launch Providers must test high-risk systems to find the right risk controls and to confirm consistent performance for the intended purpose. Testing runs during development and, without exception, before the system reaches the market or goes into service. Metrics and probabilistic thresholds are fixed in advance. Real-world testing is permitted only under the sandbox conditions of Article 60. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0103 Art. 9 Bring residual risk to an acceptable level Each identified hazard, and the system overall, must be left with residual risk judged acceptable. Providers eliminate or reduce risk through design first, add mitigation and control measures for what remains, and close the gap with clear information and, where useful, deployer training. Only risks addressable through design or technical information count here. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0104 Art. 9 Assess impact on minors and vulnerable groups When running the risk management system, providers must ask whether the intended purpose makes an adverse effect on under-18s likely, and weigh other vulnerable groups where relevant. The question is part of risk analysis, not a separate filing, and its answer shapes the mitigation measures chosen. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0105 Art. 10 Ensure dataset quality and representativeness Training, validation and testing data must be relevant, sufficiently representative, and as complete and error-free as reasonably achievable for the intended purpose, with statistical properties suited to the people the system will be used on. Geographic, behavioural and contextual particulars of the deployment setting count too. The criteria may be satisfied across a combination of datasets rather than each one alone. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0106 Art. 10 Safeguard special-category data used for bias work Sensitive personal data may be processed only where strictly necessary to detect and correct bias, and only if no other data, including synthetic or anonymised data, would work. Providers must apply pseudonymisation and state-of-the-art security, log and restrict access, keep the data from being shared onward, and delete it once the bias is corrected. Data protection law continues to apply. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0107 Art. 11 Use the SME simplified documentation form Small businesses and start-ups may present the Annex IV elements in condensed form. A provider that takes this route must use the simplified form the Commission publishes rather than a format of its own, and notified bodies must accept it for conformity assessment. The relief covers presentation only, not the substance of what has to be documented. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0108 Art. 11 Produce one documentation set for regulated products Where the high-risk system belongs to a product already covered by Union harmonisation legislation, providers must merge the AI Act documentation and the sectoral documentation into a single file covering both. Two parallel dossiers are not permitted. Provider · Product mfr High-risk III AUG 2, 2028 AUG 2, 2027 €15M / 3%
OBL-0109 Art. 12 Log required fields for biometric identification Remote biometric identification systems must capture a defined minimum in their logs: the start and end of every use, the reference database queried, the input data that produced a match, and who verified the result. This sits on top of the general logging duty and reflects the traceability such systems demand. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0110 Art. 13 Design so deployers can interpret outputs High-risk systems must be built to be legible in operation: a deployer should be able to read the output and act on it correctly. The degree of transparency is set by what the provider and the deployer each need in order to discharge their own duties, not by a fixed technical standard. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0111 Art. 13 Supply complete instructions for use Every high-risk system ships with instructions a deployer can actually follow. They must name the provider and any authorised representative, set out intended purpose, capabilities and limits, state tested accuracy, robustness and cybersecurity levels, flag foreseeable misuse risks, describe pre-agreed changes, explain the human oversight measures, and cover lifetime, maintenance, compute needs and how to read the logs. Digital delivery is acceptable. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0112 Art. 14 Require two-person verification of biometric matches For remote biometric identification, providers must build in a control so that no deployer decision rests on a match until two competent, trained and authorised people have each confirmed it independently. Union or national law may waive the second pair of eyes for law enforcement, migration, border control and asylum uses where it would be disproportionate. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0113 Art. 15 Achieve appropriate accuracy Providers must design high-risk systems to reach a level of accuracy suited to their purpose and to hold that level consistently over the system's life. There is no single numeric threshold; the Commission is to encourage benchmarks and measurement methods, and harmonised standards will supply the reference points. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0114 Art. 15 Declare accuracy levels and metrics The accuracy a high-risk system achieves, and the metrics used to measure it, must be stated in the accompanying instructions. Deployers are entitled to know the numbers behind the claim rather than a general assurance of performance. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0115 Art. 15 Build for robustness and fail-safe operation Systems must withstand errors, faults and inconsistencies, including those arising from interaction with people or other systems, backed by technical and organisational measures such as redundancy or fail-safe fallbacks. Where a system keeps learning after release, providers must design against biased outputs feeding back into later inputs, and treat any such loop as a risk to be mitigated. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0116 Art. 15 Defend against AI-specific attacks High-risk systems must resist third parties trying to alter their use, outputs or performance through system vulnerabilities. Defences are scaled to the risk and, where relevant, must address AI-specific attack routes: poisoning of training data or pre-trained components, adversarial inputs that force errors, confidentiality attacks and exploitation of model flaws. Prevention, detection, response and control all count. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0117 Art. 16 Show provider identity and contact details Providers must put their name or registered trade mark and a contact address on the high-risk system itself. Where that is impractical, the details go on the packaging or in the accompanying documentation instead, so authorities and deployers always have a traceable point of contact. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0118 Art. 16, Art. 47 Draw up the EU declaration of conformity Once conformity assessment is complete, providers must issue a written EU declaration of conformity for each high-risk system, keep it available to authorities, and update it as the system changes. Signing it is the formal assumption of responsibility for compliance. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0119 Art. 16, Art. 48 Affix the CE marking Providers must apply the CE marking to signal conformity with the AI Act, placing it on the system where possible and otherwise on the packaging or accompanying documentation. For digital-only systems the marking appears in machine-readable form. It may be affixed only after the applicable conformity assessment is finished. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0120 Art. 16 Meet EU accessibility requirements High-risk systems must also comply with the Union accessibility rules for public sector websites and applications and with the European Accessibility Act. Accessibility is a standing design requirement for providers, not an optional add-on, and applies alongside the AI Act's other Chapter III duties. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0121 Art. 18 Retain compliance documentation for ten years For ten years after a high-risk system is placed on the market or put into service, providers must keep the technical documentation, quality management system records, the EU declaration of conformity and any notified body decisions or approved changes available to national authorities. Member States set the rules for who holds the file if the provider ceases trading. Financial institutions may keep it within their sectoral records. Provider · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0122 Art. 19 Retain automatically generated logs Providers must keep the logs their high-risk systems produce, so far as those logs are within their control, for a period matched to the intended purpose and never shorter than six months. Other Union or national law, particularly data protection law, can set a different period. Financial institutions may hold the logs inside their sectoral record-keeping. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0123 Art. 20 Take corrective action on non-conformity A provider that believes a system already on the market fails the AI Act must act at once, bringing it back into conformity or else withdrawing, disabling or recalling it as the situation demands. Distributors must be told, along with deployers, importers and any authorised representative. Suspicion is enough to trigger the duty; certainty is not required. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0124 Art. 20 Investigate risks and notify authorities Where a high-risk system presents a risk in the market surveillance sense and the provider learns of it, the causes must be investigated immediately, working with the deployer who reported it. Market surveillance authorities must be informed of the nature of the non-compliance and the corrective steps taken, as must any notified body that certified the system. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0125 Art. 21 Demonstrate conformity on request When a competent authority asks with reasons, providers must hand over whatever information and documentation proves the system meets Chapter III requirements, written in an official Union language the authority has designated. What authorities receive is covered by the confidentiality protections of the AI Act. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0126 Art. 21 Grant authorities access to system logs On a reasoned request, providers must open the automatically generated logs of a high-risk system to the competent authority, so far as those logs are under their control. This sits alongside the documentation duty and lets authorities examine actual operation rather than paperwork alone. Confidentiality rules govern what the authority does with the material. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0127 Art. 22 Appoint an EU authorised representative Providers established outside the Union must appoint an authorised representative inside it, by written mandate, before making a high-risk system available on the Union market. The provider has to put the representative in a position to carry out the mandated tasks, which means real access to documentation and cooperation, not a nameplate arrangement. Provider · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0128 Art. 22 Carry out the authorised representative mandate The representative must check that the declaration of conformity and technical documentation exist and that conformity assessment was carried out, hold those records plus provider contact details and any certificate for ten years, answer reasoned authority requests including log access, cooperate on risk mitigation, and handle registration duties. Authorities may address it instead of, or as well as, the provider. Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0129 Art. 22 Terminate the mandate on provider breach An authorised representative that concludes, or has grounds to suspect, that the provider is breaching the AI Act must end the mandate. It then has to inform the relevant market surveillance authority and any notified body without delay, explaining why. The obligation makes the representative a check on the provider rather than only its agent. Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0130 Art. 23 Confirm the provider's authorised representative Importers must check that a provider established outside the Union has appointed an authorised representative inside it. Without that appointment, the system cannot lawfully be placed on the market. Importer · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0131 Art. 23 Hold back non-conforming or falsified systems Where an importer has grounds to suspect non-conformity, or falsified paperwork, the system stays off the market until it is put right. If it also presents a risk, the importer alerts the provider, the authorised representative and market surveillance authorities. Importer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0132 Art. 23 Put importer name and contact on the system Importers must show their name or trade mark and a contact address on the system itself, or on its packaging or accompanying documentation, so buyers and authorities can trace who brought it into the Union. Importer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0133 Art. 23 Protect conformity in storage and transit While a high-risk system sits under an importer's control, warehousing and shipping conditions must not erode its compliance with the high-risk requirements. Importer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0134 Art. 23 Answer authorities and cooperate on risk On a reasoned request, importers must hand competent authorities the information and documentation that proves conformity, in a language those authorities read easily, and make the technical file reachable. They must also cooperate with any action taken to reduce the system's risk. Importer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0135 Art. 24 Withhold supply when conformity is in doubt Distributors must not make a high-risk system available where the information they hold points to non-conformity, and must wait until it is corrected. Where the system also presents a risk, the provider or importer has to be told. Distributor High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0136 Art. 24 Evidence distributor checks to authorities On a reasoned request, distributors must document the verification and corrective steps they took, and cooperate with authorities working to reduce risk from systems they supplied. Distributor High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0137 Art. 25 Recognise when you become the provider A distributor, importer, deployer or other third party takes on the full provider role, and every provider duty, by putting its own brand on a high-risk system, substantially modifying one, or repurposing a non-high-risk system so that it becomes high-risk. Contracts can reallocate the branding case. The original provider then leaves the role for that system. Deployer · Distributor · Importer · Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0138 Art. 25 Support the operator who takes over as provider When another operator becomes the provider, the original one must cooperate closely — supplying the information, technical access and assistance needed to meet the Act, especially for conformity assessment. That duty drops away where the original provider clearly ruled out conversion into a high-risk system. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0139 Art. 25 Product manufacturer carries the provider duties Where a high-risk system is a safety component of a product covered by Annex I Section A, the product manufacturer bears the provider's obligations — whenever the system reaches the market with the product under that manufacturer's brand, or is put into service under it later. Product mfr · Provider High-risk III AUG 2, 2028 AUG 2, 2027 €15M / 3%
OBL-0140 Art. 25 Agree supplier terms in writing Providers and the third parties supplying tools, services, components or processes built into a high-risk system must set out in writing the information, capabilities and technical access compliance requires. Suppliers releasing under a free and open-source licence are outside this, unless what they release is a general-purpose AI model. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0141 Art. 26 Keep input data relevant and representative Where a deployer controls what goes into a high-risk system, that input data must be relevant and sufficiently representative for the system's intended purpose. The duty reaches only as far as the deployer's actual control. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0142 Art. 26 Suspend use when a risk emerges A deployer who concludes that using the system as instructed may still create a risk must stop using it without undue delay, and tell the provider or distributor and the market surveillance authority. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0143 Art. 26, Art. 73 Report serious incidents up the chain On identifying a serious incident, deployers must inform the provider immediately, then the importer or distributor and the market surveillance authority. Where the provider cannot be reached, the provider's own reporting route applies. Sensitive operational data of law-enforcement deployers is excluded. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0144 Art. 26 Inform workers before workplace deployment Employers must tell affected workers and their representatives that a high-risk system will be used on them, before it is put into service at the workplace. National and Union rules on informing workers set the manner. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0145 Art. 26, Art. 49 Public deployers register their use Public authorities and Union institutions deploying Annex III high-risk systems must register themselves, select the system and record its use in the EU database. Critical-infrastructure systems under Annex III point 2 fall outside. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0146 Art. 26, Art. 71 Do not use an unregistered system A public-sector deployer that finds the system it intends to use missing from the EU database must leave it unused and notify the provider or distributor. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0147 Art. 26, Art. 13 Feed provider information into the DPIA Where a data protection impact assessment is owed under EU data protection law, deployers must build it on the instructions and system information the provider supplies, rather than assessing blind. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0148 Art. 26 Authorisation for post-remote biometric identification Deployers using post-remote biometric identification in a criminal investigation must obtain authorisation from a judicial or independent administrative authority — before use, or without undue delay and no later than 48 hours after. If authorisation is refused, use stops and the resulting data is deleted. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0149 Art. 26, Art. 50 Tell people a high-risk system decides about them Deployers using an Annex III high-risk system to take or support decisions about individuals must tell those individuals the system is being applied to them. Transparency duties elsewhere in the Act still apply on top. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0150 Art. 27 Keep the rights assessment current The assessment attaches to first use. Deployers may lean on an earlier one, or on the provider's, in comparable cases, but must refresh any element that changes or goes stale. Where a data protection impact assessment already answers part of it, the rights assessment sits alongside and completes that work. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0151 Art. 43 Re-assess conformity after substantial modification A substantial modification sends a high-risk system back through conformity assessment, whether or not it will be distributed further or simply stays with the current deployer. Changes the provider pre-defined in its technical documentation, including for systems that keep learning after release, are not substantial. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0152 Art. 43, Art. 40 Use a notified body where standards are missing For biometric systems under Annex III point 1, the self-assessment route is open only to providers that applied harmonised standards or common specifications in full. Where none exist, or they were applied partly or not at all, a notified body must assess the quality management system and the technical documentation. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0154 Art. 47 Keep one declaration, and keep it current Where other Union law demands its own declaration of conformity, a single combined document must cover everything and name each act it answers to. Signing it means the provider owns the compliance claim and must keep the declaration up to date. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0156 Art. 48 Display the notified body's number Where a notified body ran the assessment, its identification number follows the CE marking, affixed by that body or on its instructions. The number must also appear in any promotional material claiming the system meets CE requirements. Provider · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0157 Art. 49, Art. 6 Register systems self-assessed as not high-risk A provider concluding under Art. 6(3) that its Annex III system carries no significant risk must still register itself and that system in the EU database before market placement. The Omnibus kept this lighter registration in place; it is the paper trail behind the exemption claim. Provider · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0158 Art. 49, Art. 71 Restricted registration for policing and migration Systems for law enforcement, migration, asylum and border control register into a secure non-public section of the EU database, with a reduced set of fields. Only the Commission and designated national authorities can see those entries. Provider · Deployer · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0159 Art. 49 Register critical-infrastructure systems nationally High-risk systems used as safety components in critical infrastructure, listed at Annex III point 2, are registered at national level instead of in the EU database. Provider · Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0160 Art. 50(3) Tell people when emotion or biometric categorisation AI is used Deployers running emotion recognition or biometric categorisation must tell the people exposed to it that the system is operating, and handle any personal data under EU data protection law. Law-enforcement uses permitted for detecting, preventing or investigating crime are carved out, provided safeguards for rights and freedoms apply. Deployer Transparency AUG 2, 2026 €15M / 3%
OBL-0161 Art. 50(5) Give transparency notices early and accessibly Every Article 50 disclosure must reach the affected person clearly and distinctly, no later than the first interaction or exposure. Wording and delivery must meet EU accessibility requirements. Burying the notice in terms of service, or serving it after the fact, does not discharge the duty. Provider · Deployer Transparency AUG 2, 2026 €15M / 3%
OBL-0162 Art. 52 Notify the Commission when a model crosses the threshold Providers must tell the Commission within two weeks once a general-purpose AI model reaches high-impact capability — presumed above 10^25 training FLOP — or once it becomes clear it will. The notice must evidence the trigger. A provider may argue alongside it that the model still poses no systemic risk; the Commission decides. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0163 Art. 53(1)(a) Maintain GPAI model documentation (Annex XI) Providers must build and keep current a technical file on the model, covering how it was trained and tested and what evaluation showed, with at least the Annex XI contents. It is produced for the AI Office and national authorities on request. Fully open-source models are exempt, unless they carry systemic risk. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0164 Art. 53(1)(b) Inform downstream providers (Annex XII) Providers must supply and keep updated documentation for AI system builders integrating the model, so those builders understand its capabilities and limits and can meet their own duties. Annex XII sets the minimum contents. Trade secrets and IP stay protected. Fully open-source models are exempt, unless they carry systemic risk. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0165 Art. 53(1)(c) Operate a copyright compliance policy Providers must run a policy for complying with EU copyright law, including detecting and honouring machine-readable rights reservations made under the 2019 copyright directive, using current technology. The duty applies to every general-purpose AI model, open-source included, and covers training material gathered through text and data mining. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0166 Art. 53(1)(d) Publish a training-content summary Providers must write and publish a sufficiently detailed account of the content used to train the model, following the AI Office template. It is a public document, not an authority-only filing, and the open-source carve-out does not reach it. Detail must be enough for rightsholders and the public to understand what was used. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0167 Art. 53(3) Cooperate with the Commission and authorities Providers of general-purpose AI models must give the Commission and national competent authorities the cooperation they need to exercise their powers under the AI Act. Material handed over, trade secrets included, is covered by the confidentiality rules in Article 78. The duty is continuing and is not limited to formal enforcement proceedings. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0168 Art. 54(1) Appoint an EU authorised representative Providers based outside the EU must appoint, by written mandate, a representative established in the Union before the model reaches the EU market, and must put that representative in a position to carry out the mandate. Providers of fully open-source models are exempt unless the model presents systemic risk. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0169 Art. 54(3), Art. 54(4) Carry out the authorised representative mandate The representative must check that the Annex XI file exists and that the provider met its Chapter V duties, hold a copy of that file for ten years after market placement, answer reasoned requests from the AI Office, and cooperate with authorities. It also acts as the contact point, alongside or instead of the provider. Authorised rep GPAI IN FORCE €15M / 3%
OBL-0170 Art. 54(5) End the mandate if the provider is non-compliant An authorised representative that believes, or has grounds to believe, the provider is breaching its AI Act duties must end the mandate. It must then inform the AI Office immediately and explain why. The representative cannot stay in place while shielding a non-compliant provider from scrutiny. Authorised rep GPAI IN FORCE €15M / 3%
OBL-0171 Art. 55(1)(a) Evaluate systemic-risk models to state of the art Providers of models with systemic risk must evaluate them using standardised protocols and tools that reflect the state of the art, and record the results. Evaluation is ongoing rather than a launch gate. Codes of practice, and later harmonised standards, are the recognised route to showing the protocols used were adequate. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0172 Art. 55(1)(a) Run and document adversarial testing Providers of models with systemic risk must probe them adversarially — red-teaming for the failure modes that create systemic risk — and document what the testing found. Findings must feed mitigation, not sit in a file. The exercise sits inside the wider evaluation duty and is expected to repeat as the model changes. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0173 Art. 55(1)(b) Assess and mitigate systemic risk Providers of models with systemic risk must identify where Union-level systemic risks come from and reduce them, covering risks arising in development, in market placement and in downstream use. Mitigation must be proportionate to how severe and how likely each risk is, and must be revisited as capabilities and deployment patterns shift. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0174 Art. 55(1)(c) Track and report serious incidents Providers of models with systemic risk must monitor and document serious incidents and report them to the AI Office without undue delay, notifying national authorities where relevant. Reports must also set out the corrective measures planned or taken. This requires an internal detection and escalation route that works before an incident occurs. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0175 Art. 55(1)(d) Secure the model and its infrastructure Providers of models with systemic risk must maintain adequate cybersecurity for the model itself and for the physical infrastructure supporting it. Weight exfiltration, tampering and unauthorised access are the concerns. What counts as adequate scales with the risk profile of the model rather than being a fixed control set. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0176 Art. 53(4), Art. 55(2) Show an alternative route to compliance Providers may lean on codes of practice until harmonised standards exist, and conformity with those standards brings a presumption of compliance. A provider that follows neither must instead demonstrate other adequate means of meeting its Chapter V duties, for the Commission to assess. The alternative route carries the evidential burden. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0177 Art. 56 Report on code of practice commitments Providers that sign up to a code of practice must report to the AI Office at regular intervals on how commitments are being implemented and what the results were, measured against agreed indicators where those apply. Reporting expectations flex with the size and capacity of the participant. Adherence itself remains voluntary. GPAI provider GPAI IN FORCE €15M / 3%
OBL-0190 Art. 5(1)(a) Do not deploy subliminal or manipulative techniques Providers and deployers must not put out systems that steer behaviour through cues below conscious awareness, or through purposefully deceptive or manipulative design, where the effect is to strip away informed choice and push someone toward a decision likely to cause them or another person significant harm. The ban turns on material distortion of behaviour, not on persuasion as such. No exceptions apply. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0191 Art. 5(1)(b) Do not exploit age, disability or social vulnerability Providers and deployers must not build or operate systems that trade on a person's age, disability, or particular social or economic situation to materially distort their behaviour where significant harm is likely. The vulnerability has to be the lever the system pulls; ordinary targeting that does not exploit such a trait falls outside the ban. No exceptions apply. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0192 Art. 5(1)(c) Do not run social scoring systems Providers and deployers must not score or classify people over a period of time from their social behaviour or personal characteristics where the score then drives unfavourable treatment. Two situations are caught: treatment in a context unconnected to where the data was gathered, and treatment that is unjustified or out of proportion to the conduct scored. Both public and private actors are covered. No exceptions apply. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0193 Art. 5(1)(d) Do not predict criminality from profiling alone Providers and deployers must not use systems that estimate how likely a person is to commit a crime where the judgement rests only on profiling or on an assessment of personality traits and characteristics. Tools that support a human assessment already grounded in objective, verifiable facts tied directly to criminal activity stay permitted. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0194 Art. 5(1)(e) Do not build face databases by untargeted scraping Providers and deployers must not create or enlarge facial recognition databases by harvesting facial images without any targeting, whether pulled from the open internet or lifted from CCTV footage. The prohibition attaches to the indiscriminate collection itself, regardless of the purpose the database later serves. No exceptions apply. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0195 Art. 5(1)(f) Do not infer emotions at work or in education Providers and deployers must not use systems that read a person's emotional state inside a workplace or an educational institution. The ban covers inference of emotions, not the detection of physical states such as posture or movement on its own. Systems installed for genuine medical or safety reasons, such as monitoring fatigue or distress to protect health, remain permitted. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0196 Art. 5(1)(g) Do not categorise people biometrically by sensitive traits Providers and deployers must not use biometric data to sort individuals in order to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. Lawful labelling or filtering of legally acquired biometric datasets sits outside the ban, as does categorisation of biometric data in the law enforcement field. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0197 Art. 5(1)(h) Do not run live remote biometric ID in public spaces Live remote biometric identification in publicly accessible spaces for law enforcement purposes is banned as the default rule, binding both the provider and the deploying authority. A short list of uses survives: searching for abduction, trafficking or sexual exploitation victims and missing persons, averting an imminent threat to life or a foreseeable terrorist attack, and locating suspects in serious crime. Each needs strict safeguards and, as a rule, prior authorisation. Provider · Deployer Prohibited IN FORCE €35M / 7%
OBL-0198 Art. 4 Extend AI literacy to contractors and agents The literacy duty reaches beyond employees. Providers and deployers must cover every person who handles the operation or use of their AI systems on their behalf, including contractors, agency staff and outsourced operators. Measures are calibrated to each person's technical knowledge, experience, education and training, so a single generic briefing rarely satisfies the duty. The standard is best effort, not certification. Provider · Deployer All systems IN FORCE national
OBL-0199 Art. 4 Tailor AI literacy to context and affected people Literacy measures must fit the setting the system runs in and take account of the people or groups it will be used on. A tool aimed at patients, pupils or job applicants calls for different preparation than an internal back-office system. Enforcement runs through national measures rather than the Article 99 bands, but the duty has applied since 2 February 2025. Provider · Deployer All systems IN FORCE national
OBL-0200 Art. 72 Operate a post-market monitoring system Providers must set up and document a monitoring system sized to the technology and the risks of the high-risk system. It has to gather and analyse performance data across the whole service life, from deployers and other sources, so continuing compliance with the Chapter III requirements can be judged, and it must look at interaction with other AI systems where that matters. Sensitive operational data of law enforcement deployers is excluded. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0201 Art. 72 Base monitoring on a documented plan The monitoring system must rest on a written post-market monitoring plan that forms part of the Annex IV technical file, following the Commission template and element list. Where equivalent monitoring already exists under Annex I sectoral legislation, or under financial services rules for Annex III point 5 systems, providers may fold the required elements into those arrangements provided protection stays equivalent. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0202 Art. 73 Report serious incidents within 15 days Providers must notify the market surveillance authority of the Member State where a serious incident happened. The clock starts once a causal link between the system and the incident is established, or is reasonably likely, and the report goes out immediately after that point and in any case within fifteen days of becoming aware. Severity should pull the timing forward. Sectoral regimes and medical device rules narrow what must be notified. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0203 Art. 73 Report widespread or infrastructure incidents in two days A shorter deadline applies to a widespread infringement, and to disruption of the management or operation of critical infrastructure. Providers must report immediately and no later than two days after they, or where relevant the deployer, become aware of the incident. The two-day limit displaces the ordinary fifteen-day window rather than adding to it. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0204 Art. 73 Report a death within ten days Where a person has died, providers must report as soon as a causal link with the high-risk system is established or even suspected, and at the latest ten days after becoming aware of the incident. Suspicion is enough to trigger the duty, so notification should not wait on a completed investigation. An incomplete initial report may be filed first and completed afterwards where that is needed to report in time. Provider · Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0205 Art. 73 Investigate incidents and preserve evidence After reporting, providers must investigate without delay, assess the risk the incident revealed and take corrective action. They cooperate with the competent authorities and, where one is involved, the notified body. Changes to the system that could compromise a later examination of the causes must not be made until the authorities have been told of the intended action. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0206 Art. 74 Cooperate with market surveillance authorities Every operator in the chain, from provider to deployer, must work with the market surveillance authority examining a system, and with the fundamental rights bodies brought in alongside it. Authorities may exercise information and inspection powers remotely where that is appropriate. For products under Annex I Section A, and for regulated financial institutions, the supervising sectoral authority takes the market surveillance role. Provider · Deployer · Importer · Distributor High-risk III AUG 2, 2026 €15M / 3%
OBL-0207 Art. 74 Grant authorities access to documentation and data Providers must give market surveillance authorities full access to the technical documentation and, where needed for the assessment, to the training, validation and testing datasets, through application programming interfaces or other suitable technical means. Source code may be demanded on a reasoned request, but only where documentation and data have proved insufficient to test conformity with the high-risk requirements. Everything obtained is held under the confidentiality rules. Provider High-risk III AUG 2, 2026 €15M / 3%
OBL-0208 Art. 78 Keep sensitive documentation on premises and accessible Where law enforcement, immigration or asylum authorities act as providers of high-risk systems under Annex III points 1, 6 or 7, the Annex IV technical file stays inside their own premises. They must nonetheless let the competent market surveillance authority reach the documentation, or take a copy, immediately on request. Access is confined to staff holding the appropriate security clearance. Provider · Deployer High-risk III IN FORCE €15M / 3%
OBL-0209 Art. 79 Take corrective action when required Where an authority finds a system presents a risk to health, safety or fundamental rights and does not meet the Regulation, the operator must bring it into line, withdraw it or recall it within the period set, generally no more than fifteen working days. Corrective action has to extend to every affected system already made available across the Union market, not only the unit examined. Provider · Deployer · Importer · Distributor High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0210 Art. 80 Fix a wrong non-high-risk classification If an authority concludes that a system self-assessed as outside the high-risk tier is in fact high-risk, the provider must bring it into full compliance and take corrective action within the period set, across all units on the Union market. Fines follow both from missing that deadline and, separately, from having misclassified the system deliberately to escape the Chapter III requirements. Provider High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0211 Art. 83 Cure formal non-compliance promptly Providers must put an end to formal defects once an authority flags them: a missing or improperly affixed CE marking, an EU declaration of conformity that was never drawn up or was drawn up incorrectly, a missing EU database registration, an unappointed authorised representative, or unavailable technical documentation. If the defect persists, the authority can restrict, prohibit, recall or withdraw the system without delay. Provider · Authorised rep High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%
OBL-0212 Art. 85 Answer complaint-driven market surveillance Any natural or legal person with grounds to believe the Regulation has been broken may complain to the relevant market surveillance authority, alongside any other administrative or judicial remedy. Authorities must feed such complaints into their surveillance work and handle them under their own procedures, so operators should expect scrutiny to start from a third party rather than from a scheduled inspection. Provider · Deployer High-risk III AUG 2, 2026 €15M / 3%
OBL-0213 Art. 86 Explain individual decisions on request Deployers must give an affected person clear, meaningful explanations of the part the AI system played in a decision and of the main elements behind it. The right covers decisions based on Annex III high-risk output that carry legal effects or similarly significant adverse impact on health, safety or fundamental rights. Annex III point 2 systems are excluded, as are cases where Union or national law already provides the right or restricts it. Deployer High-risk III DEC 2, 2027 AUG 2, 2026 €15M / 3%

Source: EUR-Lex CELEX 32024R1689 (as amended) · dates per Omnibus final text · verified 2026-07-16 · Not legal advice