Editorial standards & methodology
EU AI Regulation Decoded is a structured reference that maps every EU AI Act obligation to the specific evidence an auditor expects. Every fact is cited to primary legal sources and maintained as the law evolves.
Who this is for
Compliance officers, ML and product engineers, legal teams and auditors preparing high-risk AI systems and GPAI models for the EU AI Act. It is built for audit preparation: not "what does the Article say", but "what document must exist, when, and what fails an audit".
Editorial standards
- Cited to primary sources. Every obligation, deadline and evidence artifact links to the underlying Regulation article/annex or official Commission guidance.
- Contemporaneous over retrospective. Evidence guidance reflects the standard national competent authorities apply — records created when the decision was made.
- Status is explicit. Each obligation shows a review status and a version. Items still being verified against primary text are marked under editorial review rather than presented as settled.
- Corrections are versioned. Legal facts are not overwritten silently; changes are dated and attributed to the source that justified them.
Methodology
The platform is generated from a single canonical knowledge graph — a normalised dataset of articles, annexes, obligations, roles, risk categories, deadlines, evidence artifacts and audit red flags, each with stable identifiers and source citations. Every public page is generated from that dataset, so a change to one fact updates every page that references it. The weekly newsletter is the maintenance layer: each issue that reports a development updates the underlying records.
Update & versioning policy
Deadlines carry their full change history (for example, the stand-alone high-risk obligations deferred by the 7 May 2026 political agreement). Records show a last reviewed date and version number. The open dataset behind the platform is published at /api/graph.json under CC BY 4.0.
Primary sources
- Regulation (EU) 2024/1689 (EU AI Act) Regulation (EU) 2024/1689
- Article 5 — Prohibited AI practices Art. 5 AIA
- Article 6 — Classification rules for high-risk AI systems Art. 6 AIA
- Article 9 — Risk management system Art. 9 AIA
- Article 10 — Data and data governance Art. 10 AIA
- Article 26 — Obligations of deployers of high-risk AI systems Art. 26 AIA
- Article 11 — Technical documentation Art. 11 AIA
- Article 15 — Accuracy, robustness and cybersecurity Art. 15 AIA
- Article 43 — Conformity assessment Art. 43 AIA
- Article 49 — Registration (EU database) Art. 49 AIA
- Article 50 — Transparency obligations for certain AI systems Art. 50 AIA
- Article 53 — Obligations for providers of GPAI models Art. 53 AIA
- Annex III — High-risk AI systems referred to in Article 6(2) Annex III AIA
- Annex IV — Technical documentation Annex IV AIA
- Commission draft guidelines on classification of high-risk AI systems (19 May 2026) Commission draft HRAI guidelines, 19 May 2026
- General-Purpose AI Code of Practice (10 July 2025) GPAI Code of Practice, 10 Jul 2025
- Political agreement revising AI Act timelines (Digital Omnibus, 7 May 2026) AI Act timeline revision political agreement, 7 May 2026
- AI Act — Regulatory framework (European Commission) European Commission — Regulatory framework for AI
Disclaimer
Important
This is a practitioner reference, not legal advice, and does not create a client relationship. It is a starting point for audit preparation; verify against the cited primary sources and take qualified legal advice before relying on it for a compliance decision.
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.