EU AI Act reference
Plain-English reference for the EU AI Act
37 pages cited against Regulation (EU) 2024/1689 (CELEX:32024R1689). Each page covers what the regulation says, who's covered, what to do, and how the requirement maps to ISO 42001 and NIST AI RMF.
Pillars — start here
For SaaS vendors, deployers, and lawyers preparing first-pass research.
Articles 6 / 16 / 25 / 53
EU AI Act for SaaS — Are You a Provider, Deployer, or Both?
A pillar guide for B2B SaaS vendors and buyers under Regulation (EU) 2024/1689. Provider vs deployer decision tree, GPAI integration, Article 25 promotion, the August 2026 deadlines.
Article 11 + Annex IV
EU AI Act Article 11 Step-by-Step — How to Build the Annex IV File
A step-by-step build for the EU AI Act Article 11 / Annex IV technical documentation file. Eight sections, eight weeks, evidence pack, and what to do over a weekend if you start late.
Article 27
FRIA Explained — Fundamental Rights Impact Assessment Under Article 27
A pillar guide to the EU AI Act Fundamental Rights Impact Assessment under Article 27. Who is covered, the six elements, FRIA vs DPIA, two worked examples, and the AI Office template.
Articles 51 / 53 / 55
GPAI Compliance — Obligations for General-Purpose AI Model Providers
A pillar guide to general-purpose AI (GPAI) compliance under Regulation (EU) 2024/1689. Article 53 obligations, Article 55 systemic-risk overlay, the 10^25 FLOP threshold, and the AI Office codes of practice.
EU AI Act ↔ NIST AI RMF
EU AI Act vs NIST AI RMF — Crosswalk and Practical Differences
A side-by-side of the EU AI Act and NIST AI Risk Management Framework 1.0. Where they overlap, where they diverge, and how to leverage one to satisfy the other.
EU AI Act ↔ ISO/IEC 42001
EU AI Act vs ISO 42001 — Crosswalk and Integration Pattern
A side-by-side of the EU AI Act and ISO/IEC 42001:2023 AI Management Systems. Where they overlap, where they diverge, and how to leverage one to satisfy the other.
Articles
Per-Article reference: text, who's covered, obligations, common mistakes, penalties.
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Article 11 of Regulation (EU) 2024/1689 requires technical documentation for every high-risk AI system. The eight Annex IV sections, who must produce them, and what regulators look for.
Article 27
EU AI Act Article 27 — Fundamental Rights Impact Assessment (FRIA)
Article 27 of Regulation (EU) 2024/1689 obliges certain deployers to perform a Fundamental Rights Impact Assessment. Who is covered, the six mandatory elements, and a worked example.
Article 14
EU AI Act Article 14 — Human Oversight Requirements
Article 14 of Regulation (EU) 2024/1689 requires effective human oversight of high-risk AI systems. The four oversight outcomes, who designs them, who carries them out, and what regulators look for.
Article 9
EU AI Act Article 9 — Risk Management System Requirements
Article 9 of Regulation (EU) 2024/1689 requires a continuous, documented risk management system for high-risk AI. The five-step process, who runs it, and what evidence regulators ask for.
Article 10
EU AI Act Article 10 — Data and Data Governance
Article 10 of Regulation (EU) 2024/1689 sets data quality, governance and documentation duties for high-risk AI training, validation and testing data. Bias detection, special-category derogation, and lineage requirements.
Article 12
EU AI Act Article 12 — Record-Keeping and Automatic Logging
Article 12 of Regulation (EU) 2024/1689 requires automatic logging in high-risk AI systems. Logging events, deployer access, retention, and the link to Article 19.
Article 13
EU AI Act Article 13 — Transparency and Instructions for Use
Article 13 of Regulation (EU) 2024/1689 requires high-risk AI to be transparent and provide instructions for use to deployers. Required content, format, and enforcement.
Article 15
EU AI Act Article 15 — Accuracy, Robustness and Cybersecurity
Article 15 of Regulation (EU) 2024/1689 requires high-risk AI systems to achieve appropriate accuracy, robustness and cybersecurity throughout their lifecycle. Disaggregated metrics, adversarial testing, and what to document.
Article 16
EU AI Act Article 16 — Provider Obligations Checklist
Article 16 of Regulation (EU) 2024/1689 lists the obligations of providers of high-risk AI systems. The thirteen-point checklist, what each item means, and how to evidence compliance.
Article 17
EU AI Act Article 17 — Quality Management System (QMS)
Article 17 of Regulation (EU) 2024/1689 requires providers to have a quality management system. The thirteen QMS aspects, ISO 9001 / ISO 42001 alignment, and the SME proportionality.
Article 26
EU AI Act Article 26 — Deployer Obligations
Article 26 of Regulation (EU) 2024/1689 sets the obligations on deployers of high-risk AI systems. Use per IFU, human oversight assignment, input-data quality, monitoring, and worker-information duties.
Article 53
EU AI Act Article 53 — General-Purpose AI Model Provider Obligations
Article 53 of Regulation (EU) 2024/1689 sets obligations on providers of general-purpose AI (GPAI) models: technical documentation per Annex XI, downstream provider information, training-data summary, copyright policy.
Article 55
EU AI Act Article 55 — GPAI Models with Systemic Risk
Article 55 of Regulation (EU) 2024/1689 sets additional obligations for general-purpose AI models with systemic risk. Model evaluation, adversarial testing, incident tracking, and the 10^25 FLOP designation threshold.
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Article 79 of Regulation (EU) 2024/1689 sets the procedure for AI systems presenting a risk at national level. Market surveillance powers, evaluation, corrective measures, and the link to serious-incident reporting.
Annex IV — technical documentation
Per-section reference for the Article 11 / Annex IV technical file.
Annex IV §4
Annex IV §4 — Risk Management System Description (EU AI Act)
Annex IV §4 of Regulation (EU) 2024/1689 requires a description of the Article 9 risk management system in the technical file. Structure, evidence, and what regulators expect.
Annex IV §1
Annex IV §1 — General Description of the AI System (EU AI Act)
Annex IV §1 of Regulation (EU) 2024/1689 requires a general description of the AI system: intended purpose, provider, version, interactions, instructions for use, and UI. Structure and what regulators expect.
Annex IV §1(a)
Annex IV §1(a) — Intended Purpose Statement (EU AI Act)
How to write the intended-purpose statement for Annex IV §1(a) under Regulation (EU) 2024/1689. Excluded uses, scope-bounding, and the link to Article 25 promotion risk.
Annex IV §2(d)
Annex IV §2(d) — Data Documentation (EU AI Act)
How to document training, validation and test data under Annex IV §2(d) of Regulation (EU) 2024/1689. Data sheets, lineage, special-category derogation, and bias examination evidence.
Annex IV §2(b) + §3
Annex IV — Accuracy Documentation (EU AI Act)
How to document accuracy, robustness and cybersecurity in the EU AI Act technical file. Disaggregated metrics, adversarial testing, and the link to Article 15.
Annex IV §3 (oversight)
Annex IV — Human Oversight Documentation (EU AI Act)
How to document human oversight measures in the EU AI Act technical file. Operator profile, training, authority, override monitoring, and the link to Article 14.
Annex IV §5
Annex IV §5 — Lifecycle Changes Log (EU AI Act)
How to maintain the Annex IV §5 lifecycle-changes log under Regulation (EU) 2024/1689. Append-only design, what counts as a material change, and the link to Article 43 substantial modification.
Annex IV §8 (Article 72 plan)
Annex IV §8 — Post-Market Monitoring Plan (EU AI Act)
How to document the Article 72 post-market monitoring plan in Annex IV §8 of Regulation (EU) 2024/1689. Performance review cadence, drift, complaints, and incident triage.
Article 43 + Annex VI/VII
Conformity Assessment for High-Risk AI (Article 43 + Annex IV)
How to run the Article 43 conformity assessment under Regulation (EU) 2024/1689. Internal control (Annex VI) vs notified-body (Annex VII), substantial modification, and the link to the Annex IV file.
Annex III — high-risk categories
Each Annex III high-risk category, with examples in/out of scope and the obligations triggered.
Annex III §1
EU AI Act Annex III §1 — Biometrics (High-Risk)
Biometrics AI systems are high-risk under Annex III §1 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §2
EU AI Act Annex III §2 — Critical Infrastructure (High-Risk)
Critical Infrastructure AI systems are high-risk under Annex III §2 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §3
EU AI Act Annex III §3 — Education and Vocational Training (High-Risk)
Education and Vocational Training AI systems are high-risk under Annex III §3 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §4
EU AI Act Annex III §4 — Employment, Worker Management and Self-Employment (High-Risk)
Employment, Worker Management and Self-Employment AI systems are high-risk under Annex III §4 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §5
EU AI Act Annex III §5 — Essential Private and Public Services (High-Risk)
Essential Private and Public Services AI systems are high-risk under Annex III §5 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §6
EU AI Act Annex III §6 — Law Enforcement (High-Risk)
Law Enforcement AI systems are high-risk under Annex III §6 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §7
EU AI Act Annex III §7 — Migration, Asylum and Border Control (High-Risk)
Migration, Asylum and Border Control AI systems are high-risk under Annex III §7 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Annex III §8
EU AI Act Annex III §8 — Administration of Justice and Democratic Processes (High-Risk)
Administration of Justice and Democratic Processes AI systems are high-risk under Annex III §8 of Regulation (EU) 2024/1689. What's covered, the obligations triggered, and what providers and deployers must do.
Reference; not legal advice. Verify with qualified counsel. 10 pages hand-edited; 27 drafted via Sonnet 4.6 with human spot-check. Reg text from Regulation (EU) 2024/1689.