EU AI Act carries 15 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-07-29.
What are the duty tiers under EU AI Act?
Prohibited practice (Art. 5)
Citation: Art. 5 — https://artificialintelligenceact.eu/article/5/
Statutory exceptions exist and require legal review — Art. 5(1)(f) medical/safety purposes, Art. 5(1)(g) lawful dataset labelling and certain law-enforcement uses, Art. 5(1)(h) three authorisation-gated exceptions, Art. 5(1)(d) objective-facts human assessment. Never auto-applied.
High-risk (Annex III) (Art. 6(2), Annex III)
Citation: Art. 6(2), Annex III — https://artificialintelligenceact.eu/article/6/
Emotion recognition outside prohibited settings is Annex III 1(c) high-risk; biometric categorisation by sensitive attributes may be Annex III 1(b) or prohibited under Art. 5(1)(g). May qualify for the Art. 6(3) derogation (narrow procedural task; improving a completed human activity; pattern/deviation detection with human review; preparatory task) — NEVER available where the system profiles natural persons; claiming it requires documented assessment. Flag for review — never auto-applied. This tier is evaluated before Annex I so dual-qualifying systems get the earlier 2 December 2027 date and FRIA evaluation.
High-risk (Annex I) (Art. 6(1), Annex I)
Citation: Art. 6(1), Annex I — https://artificialintelligenceact.eu/article/6/
Transparency duties (Art. 50) (Art. 50)
Citation: Art. 50 — https://artificialintelligenceact.eu/article/50/
Minimal risk (Recital 165)
Citation: Recital 165 — https://artificialintelligenceact.eu/
What should you do about each obligation?
Ensure AI literacy of staff operating the system (Art. 4)
Train and document that staff dealing with the system have sufficient AI literacy for their role and context.
Cease or do not launch the prohibited practice (Art. 5)
The flagged practice is banned outright, with the highest penalty tier. Stop, redesign, or obtain a documented legal opinion that a statutory exception applies before any EU exposure.
Tell people they are interacting with AI (Art. 50(1))
Design the system so users are informed they are interacting with AI at or before first interaction, unless obvious to a reasonably informed person. Law-enforcement carve-outs may apply.
Mark AI-generated content machine-readably (Art. 50(2))
Embed machine-readable markers in synthetic audio, image, video, and text. A visible label alone does not satisfy this duty. Exempt to the extent the system only performs an assistive standard-editing function or does not substantially alter the deployer's input or its meaning.
Disclose deep fakes you deploy (Art. 50(4))
Disclose that image, audio, or video content resembling real people, objects, places, entities, or events — where it could falsely appear authentic — has been artificially generated or manipulated. For evidently artistic, satirical, or fictional works, disclosure may be made in a manner that does not hamper display or enjoyment.
Disclose AI-generated text published to inform the public (Art. 50(4), second subparagraph)
Disclose that published text informing the public on matters of public interest was artificially generated or manipulated. Exempt where the text underwent human review or editorial control and a natural or legal person holds editorial responsibility for its publication.
Notify people subject to emotion recognition or biometric categorisation (Art. 50(3))
Inform exposed people that the system is operating, and process personal data under applicable EU data-protection law (GDPR, EUDPR, Law Enforcement Directive). Law-enforcement carve-outs may apply.
GPAI model documentation and downstream information (Art. 53(1)(a)-(b))
Maintain model technical documentation and provide information to downstream providers integrating the model. Free and open-source models with public weights are exempt from these two duties unless the model has systemic risk (Art. 53(2)).
Copyright policy and public training-content summary (Art. 53(1)(c)-(d))
Adopt a copyright-compliance policy and publish a sufficiently detailed summary of training content. These duties apply to open-source models too.
Systemic-risk model duties: evaluations, incident reporting, cybersecurity (Arts. 52, 55)
Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1), rebuttal possible under 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.
High-risk provider obligations (risk management, data governance, technical docs, logging, oversight, accuracy, QMS, conformity assessment, CE marking, registration, post-market monitoring) (Arts. 8-21, 43, 47-49, 72-73)
Build toward the full conformity package now: Arts. 9-15 systems and documentation, Art. 17 quality management system, Arts. 18-20 record-keeping and corrective actions, Art. 43 conformity assessment, Arts. 47-48 declaration of conformity and CE marking, Art. 49 EU database registration, and Arts. 72-73 post-market monitoring and serious-incident reporting.
High-risk deployer duties (use per instructions, human oversight, monitoring, logs, worker notification) (Art. 26)
Assign trained human oversight, use the system per the provider's instructions, ensure input data under your control is relevant and sufficiently representative, monitor operation, retain logs under your control for at least six months, inform workers and their representatives before workplace deployment, and inform affected natural persons where the system makes or helps make decisions about them.
Fundamental rights impact assessment (FRIA) (Art. 27)
Assess the impact on fundamental rights before first use: processes, categories of affected persons, risks, oversight, and mitigation. Triggered for public bodies and private providers of public services, and for any deployer using high-risk AI for creditworthiness or life/health insurance pricing (Annex III 5(b)-(c)); critical-infrastructure systems are excepted.
Importer duties for high-risk AI systems (Art. 23)
Before placing the system on the EU market, verify the provider completed conformity assessment, drew up the technical documentation, and affixed the CE marking with an EU declaration of conformity; add your name and contact details on the product or packaging; ensure storage and transport do not jeopardise compliance; keep documentation for 10 years; and inform the provider and market-surveillance authorities of any risk.
Distributor duties for high-risk AI systems (Art. 24)
Before making the system available, verify it bears the CE marking, is accompanied by the EU declaration of conformity and instructions, and that provider and importer complied with their obligations; ensure storage and transport do not jeopardise compliance; take corrective action or withdraw where non-conformity appears; and inform providers, importers, and authorities of any risk.