AI Act requirements, mapped to practical software capabilities
Start with the regulatory area or operational control you need to understand. Each page separates statutory obligations from supporting capabilities and links to the tools recorded for that area.
Direct AI Act obligation areas
These pages describe provisions that can create direct obligations when their scope and timing apply. They are not legal determinations for a specific organisation.
AI Literacy & Staff Competency
Article 4 AI literacy measures have applied since 2 February 2025. The 2026 amendment changes implementation details; this page is a screening aid, not legal advice.
GPAI & Foundation Model Compliance
GPAI provider obligations apply from 2 August 2025; Commission enforcement powers apply from 2 August 2026. Screening should distinguish model-provider obligations from downstream system obligations.
AI Transparency & Output Labelling
Article 50 transparency obligations apply from 2 August 2026, with a limited transition to 2 December 2026 for certain pre-existing systems and specific marking/detection duties.
High-Risk AI System Readiness
Following the 2026 amendment, Chapter III Sections 1–3 apply from 2 December 2027 for high-risk systems classified under Article 6(2)/Annex III and from 2 August 2028 for Article 6(1)/Annex I systems.
Continuous Risk Management System
Article 9 risk-management requirements sit within the high-risk framework. The applicable date depends on the system classification and the amended Article 113 transition.
Technical Documentation (Annex IV)
Article 11 and Annex IV technical documentation requirements belong to the high-risk framework; the applicable date depends on Article 6 classification and the amended transition dates.
Human Oversight & Governance Controls
Article 14 human-oversight requirements belong to the high-risk framework; the applicable date depends on Article 6 classification and the amended transition dates.
Supporting governance capabilities
These capabilities can help teams implement, evidence or monitor AI Act work. A capability mapping is not proof that a vendor satisfies a statutory requirement.
AI System Inventory & Shadow AI Discovery
An inventory is a practical governance control and may support multiple AI Act obligations. The existence of an inventory does not itself establish compliance.
Testing, Evaluation & Observability
Testing, evaluation and monitoring capabilities can support several AI Act obligations, but a tool capability should not be treated as proof of legal compliance.
AI Security & Guardrails
Cybersecurity and robustness controls can support Article 15 and related governance work. The applicable high-risk obligations follow the amended Article 113 timeline.
Data Governance & Quality Controls
Data governance and quality controls can support high-risk AI system obligations. Their legal relevance depends on system classification and the specific applicable requirements.
Record-Keeping & Logging
Automatic logging and record-keeping can support high-risk AI system obligations. The required records depend on the system, role and applicable provisions.
Serious Incident Management
Incident intake, escalation and reporting processes can support AI Act obligations where the applicable incident-reporting duties are in scope.
Post-Market Monitoring
Post-market monitoring capabilities can support applicable high-risk provider obligations. The exact monitoring plan depends on the system and role.
Start from the requirement, then inspect the evidence
Open a requirement area to see its scope, applicable provisions, practical checklist and recorded software mappings. For a fact-based preliminary screening across your own system context, use the assessment.
Run assessment