EU AI Act obligations
Every duty, mapped to the evidence an auditor expects and the article it derives from.
Declare accuracy metrics in instructions for use
Provider
Evidence robustness / resilience
Provider
Evidence AI-specific cybersecurity
Provider
Run a lifecycle risk-management system
Provider
Govern training, validation and test data
Provider
Assign human oversight and use per instructions (deployer)
Deployer
Draw up & maintain the Annex IV technical file
Provider
Classify the system against Article 6 / Annex III
Provider, Deployer
Register in the EU database
Provider, Deployer
Complete conformity assessment before market
Provider
Disclose AI interaction to users
Provider
Mark AI-generated content machine-readably
Provider, GPAI model provider
Disclose deepfakes
Deployer
GPAI provider documentation & copyright
GPAI model provider
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.