Skip to content
EU AI Regulation DecodedKnowledge Platform

Articles & annexes

Each article and annex, linked to the obligations it creates and the evidence they require.

Article 5: Prohibited AI practices

What AI you may not build or use at all

Article 6: Classification rules for high-risk AI systems

How to tell if your system is high-risk

Article 9: Risk management system

The risk-management system you must run for the whole lifecycle

Article 10: Data and data governance

Proving your training data is governed

Article 11: Technical documentation

The technical file you must keep current

Article 26: Obligations of deployers of high-risk AI systems

What you must do when you deploy someone else's high-risk AI

Article 15: Accuracy, robustness and cybersecurity

Proving your system is accurate, robust and secure

Article 43: Conformity assessment

The assessment you pass before going to market

Article 49: Registration

Registering your system in the EU database

Article 50: Transparency obligations for providers and deployers of certain AI systems

Telling people when they're dealing with AI

Article 53: Obligations for providers of general-purpose AI models

What GPAI model providers must document and share

Annex III: High-risk AI systems referred to in Article 6(2)

High-risk AI systems referred to in Article 6(2)

Annex IV: Technical documentation

Technical documentation

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.